+43 5517 54 140

Privacy policy

Privacy policy

The protection of your personal data is of particular concern to us. We therefore process your data exclusively on the basis of the legal provisions (GDPR, TKG 2021). This privacy policy informs you about the type, scope, and purpose of the collection and processing of your personal data by our company.

Controller for data processing:
Naturhotel Chesa Valisa
GmbH & Co. KG
Gerbeweg 18
A-6992 Hirschegg
T +43 5517 54 140
F +43 5517 51 08
E info@naturhotel.at


Purposes of data processing

This privacy information applies to all processing activities relevant to you as an interested party, guest, website visitor, newsletter subscriber, or applicant.

The purposes for which we process your personal data can be summarized as follows:

  • Our business operations (hotel and restaurant services)

  • Voucher purchases

  • Newsletter

  • Contact form on the website and other inquiries (e.g., via email)

  • Job applications

  • Cookies and website tracking

  • Social media


Business operations (hotel and restaurant services)

We process your personal data in connection with your interest in or use of our services, including:

  • Basic data (e.g., last name, first name, address, email, telephone number, date of birth, gender, country of origin, allergies, and intolerances)

  • Data from presented travel documents (e.g., passport, ID card, driver’s license: document type, number, date of issue, issuing authority, validity, nationality, etc.)

  • Payment details (e.g., payment method, amount, card number, cardholder)

  • Booking and service-related data (e.g., arrival and departure dates, requested or booked rooms, language, car license plate number, number of guests)

  • Other details related to your booking or request (e.g., fellow travelers, destinations, contacts, conditions, special services, frequent flyer number, personal preferences, guides, gastronomy, car rentals, transfers, registration, insurance, events, tours, accreditations, vouchers, billing and verification – B2B, B2C, FIT – ticket bookings)

We may also receive personal data from third parties, such as a person making a booking on your behalf, travel agencies, or booking platforms. In such cases, we assume that the data subject has already been informed about our data processing (e.g., via the person making the booking) or that a separate notification would be disproportionate.


Legal basis for data processing

We rely on the following legal bases:

  • Performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR)

  • Your consent, if given (Art. 6(1)(a) GDPR)

  • Legal obligations (e.g., accounting, tax, customs, contractual and registration requirements) (Art. 6(1)(c) GDPR)

  • Our legitimate interests (Art. 6(1)(f) GDPR), such as improving customer service or defending legal claims


Data retention

  • Where legal retention obligations apply (e.g., under tax or commercial law), we store your data accordingly. Accounting documents and guest registry data (pursuant to § 132 Austrian Fiscal Code and § 10 Registration Act) are stored for 7 years.

  • Where processing is based on your consent, data will be stored in accordance with your consent and deleted no later than 3 years after the last contact.

  • Data from interested parties or inquiries not resulting in bookings will be stored for up to 3 years.

  • All other data will be deleted after 3 years at the latest.

  • If necessary to assert or defend legal claims, we may store data beyond this period until final resolution.


Contacting us

You can contact us via our website contact form or by email to inquire about our services or for general inquiries. Inquiries may also be forwarded to us by third parties (e.g., booking platforms).

The contact data you provide and any other data disclosed will be processed to respond to your request. Legal basis:

  • Art. 6(1)(b) GDPR (pre-contractual/contractual communication)

  • Art. 6(1)(f) GDPR (our legitimate interest in seamless communication and documentation)

Data from such contact will be stored for up to 3 years, unless a contract results (see section “Business operations”).


Cookies

Our website uses so-called cookies. These are small text files that are stored on your device via your browser. They do not cause any damage.

We use cookies to make our offering more user-friendly. Some cookies remain stored on your device until you delete them. They allow us to recognize your browser on your next visit.

If you do not want this, you can configure your browser to inform you when cookies are set and allow them only on a case-by-case basis.

Disabling cookies may limit the functionality of our website.


Google Maps

Our website uses the map service “Google Maps”, provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (for users in the European Economic Area: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland).

To display interactive maps and provide geographic orientation, a connection to Google’s servers is established. In the process, personal data such as your IP address and location data (if enabled) may be transmitted to Google. The use of Google Maps takes place only with your explicit consent under Art. 6(1)(a) GDPR via our cookie banner. Without your consent, no connection to Google servers is established and the map is not displayed.

Further information on data processing by Google:
Privacy Policy: https://www.google.com/policies/privacy/
Ad Settings (Opt-Out): https://adssettings.google.com/authenticated


Google Fonts

Our website uses Google Fonts to ensure consistent font display. This is a service of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (for users in the EEA: Google Ireland Limited).

When you access a page, your browser loads the necessary fonts directly from Google servers. In doing so, your IP address and other technical information (e.g. browser type, operating system, screen resolution) may be transmitted to Google. This data transmission occurs only with your explicit consent under Art. 6(1)(a) GDPR via the cookie banner.

Further information:
Privacy Policy: https://www.google.com/policies/privacy/
Ad Settings (Opt-Out): https://adssettings.google.com/authenticated


Google reCAPTCHA

We use the “reCAPTCHA” service from Google LLC (or Google Ireland Limited) to protect our website. It ensures that data entries (e.g. in forms) are made by a human and not by automated bots. This service supports the integrity and functionality of our online offerings – especially in terms of abuse and spam prevention.

Since reCAPTCHA is essential for secure website operation, it is used without prior consent via the cookie banner. Legal basis: our legitimate interest under Art. 6(1)(f) GDPR.

During use, data such as your IP address, mouse movements, time spent on the site, screen resolution, and browser data may be transmitted to Google.

More information:
Google Privacy Policy: https://www.google.com/policies/privacy/
Ad settings / opt-out: https://adssettings.google.com/authenticated


Google Analytics

Our website uses Google Analytics, a web analytics service provided by Google LLC (or Google Ireland Limited).

Google Analytics uses cookies to help analyze how users interact with the website. The information generated by the cookie (including your IP address) is transmitted to Google servers. IP anonymization is activated on our website: your IP address is shortened within the EU or EEA before transmission to the USA. Only in exceptional cases will the full IP address be sent and then shortened in the USA.

Google Analytics is only used based on your explicit consent under Art. 6(1)(a) GDPR, obtained via the cookie banner. Consent can be revoked at any time.

We have signed a data processing agreement with Google in accordance with Art. 28 GDPR. Google processes data on our behalf to evaluate website use, generate activity reports, and provide related services.

Google LLC is certified under the EU-U.S. Data Privacy Framework (DPF), ensuring adequate protection for data transfers to the USA.

Google Analytics data is stored for 14 months and then automatically deleted.

More information:
https://www.google.com/intl/en/policies/privacy/partners
https://policies.google.com/technologies/ads
https://adssettings.google.com/authenticated


Google Marketing Services / Remarketing

This website uses the marketing and remarketing services (“Google Marketing Services”) of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (or for users in the European Economic Area: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland).

These services are used exclusively on the basis of your explicit consent in accordance with Art. 6(1)(a) GDPR, obtained via the cookie banner. You can revoke your consent at any time.

Google Marketing Services enable us to target visitors of our website with interest-based advertisements, shown within the Google advertising network. Google uses technologies such as remarketing tags and stores a unique cookie in the user’s browser to determine which content has been accessed. This information can be linked with data from other Google services – if the user has a Google account and has consented to such linking.

When users later visit other websites in the Google ad network, interest-based ads related to previously accessed content may be displayed. These ads are pseudonymized and not based on direct identification of individuals.

Google Analytics may also be used in conjunction with Google Marketing Services. In this case, users’ IP addresses are anonymized (e.g., shortened by the last 8 bits) so that only a rough geographical location is possible. Google states that IP addresses are not combined with other Google data.

Google LLC is certified under the EU-U.S. Data Privacy Framework (DPF), which ensures the lawful transfer of personal data to certified entities in the USA under Art. 45 GDPR.

We use the following Google Marketing Services, among others:

  • Google Ads (formerly AdWords) for conversion tracking and remarketing

  • Google AdSense for displaying third-party ads

  • Google Tag Manager for centralized integration and management of these services

More about Google’s advertising-related data processing:
https://policies.google.com/technologies/ads
Google’s privacy policy:
https://www.google.com/policies/privacy/


Mouse Tracking (Hotjar)

This website uses the web analytics service Hotjar, provided by Hotjar Ltd., Dragonara Business Centre, 5th Floor, Dragonara Road, Paceville St Julian’s STJ 3141, Malta, to better understand user behavior and improve usability and content offerings.

Hotjar enables us to record anonymized user interactions – such as mouse movements, clicks, scroll behavior, and time spent – and to visualize them. This helps us optimize our website for user-friendliness. Data processing is based on your explicit consent in accordance with Art. 6(1)(a) GDPR, obtained via the cookie banner. Without consent, Hotjar is not activated.

Hotjar uses cookies and similar technologies to collect data on users and their devices, such as anonymized IP addresses, screen size, device type, browser used, location (country only), and language preferences.

This information is stored in a pseudonymized user profile and not used to identify individuals. It is not combined with other personal data.

More information on Hotjar’s privacy practices:
https://www.hotjar.com/legal/policies/privacy

To revoke your consent or opt out of Hotjar tracking:
https://www.hotjar.com/policies/do-not-track


Newsletter

You can subscribe to our newsletter via our website. To send you tailored information, we may also collect optional additional details provided voluntarily by users.

To send the newsletter, we require your email address and your confirmation that you wish to receive the newsletter. After signing up, you will receive a confirmation email with a link to confirm your subscription.

You can cancel the newsletter subscription at any time. To do so, please email: info@naturhotel.at. Each newsletter also contains instructions on how to unsubscribe. Data processing until the point of withdrawal remains lawful.

After unsubscribing, we will promptly delete your data related to newsletter delivery.


Job Applications

You may submit job applications to us via upload on our website, email, or by other means (e.g., by post).

Personal data provided (e.g., contact details, CV, certificates, other information relevant to the application) is processed solely for the purpose of reviewing your application and within the application process. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (our legitimate interest in efficient and thorough processing).

Application data is generally stored for up to six months after completion of the application process. If your application results in employment, your data will be processed further as part of the employment relationship (see section “Business Operations”). Longer storage is possible with your explicit consent (Art. 6(1)(a) GDPR), e.g., for inclusion in our applicant pool.


Voucher Purchase

If you purchase vouchers through our website, we process the personal data you provide (e.g., name, address, email, payment details) in order to process your order and issue the voucher.

The legal basis for this processing is Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures). Without this data, we cannot process your order.

Your payment information is transmitted directly to the payment service provider used by us (e.g., PayPal, Klarna, or others). Processing is governed by the privacy policy of the respective provider. Please refer to the data protection information of your selected payment provider.

If the voucher is sent by post, your address data will be passed on to the relevant shipping provider.

We retain data relevant to the purchase and processing of the voucher in accordance with legal retention obligations (e.g., tax and commercial law) for a period of 7 years.


Online Presence in Social Media

We maintain online presences within social networks and platforms in order to communicate with users, potential customers, and clients who are active there.

In some cases, we act as joint controllers with the respective social media provider for specific data processing activities. If you interact with our social media pages or have questions, feel free to contact us directly.


Facebook

Facebook is operated by Meta Platforms Inc. (formerly Facebook Inc.), 1601 S. California Ave, Palo Alto, CA 94304, USA. For users in the EU, the responsible entity is Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

When visiting our Facebook profile, the privacy policy of Facebook applies:
http://www.facebook.com/policy.php

Collected data may be used by Facebook for analytics, ad selection, evaluation, measuring campaign effectiveness, personalizing content, and communication. If you have a Facebook account, your consent to this data processing is part of your user agreement with Facebook.

More information:
https://www.facebook.com/about/privacy
GDPR & Facebook: https://www.facebook.com/business/gdpr


Instagram

Instagram is part of Meta Platforms Inc. For EU users, data controller is also Facebook Ireland Ltd., Dublin.

The privacy policy of Instagram applies when visiting our profile:
https://help.instagram.com/519522125107875
Instagram Cookie Policy: https://www.facebook.com/policies/cookies

Information may be linked to your Instagram profile if you are logged in.


LinkedIn

We link to LinkedIn and maintain a company profile there. Provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland.

By visiting LinkedIn or interacting with our page (likes, comments, etc.), data is processed based on LinkedIn’s privacy policy:
https://www.linkedin.com/legal/privacy-policy
Opt-out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out


XING

Our website links to XING, operated by XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany.

If you follow the link and are logged in, XING may associate the visit with your profile. Privacy policy:
https://privacy.xing.com


Twitter

Twitter is operated by Twitter Inc., 795 Folsom Street, Suite 600, San Francisco, CA 94107, USA. When clicking on our Twitter profile link, Twitter’s privacy policy applies:
http://twitter.com/privacy


YouTube

YouTube is operated by YouTube LLC, a subsidiary of Google LLC. Headquarters: 901 Cherry Avenue, San Bruno, CA 94066, USA.

YouTube’s privacy policy:
https://policies.google.com/privacy?hl=en
Google cookie policy:
https://policies.google.com/technologies/cookies


Pinterest

Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland operates the platform.

Privacy policy:
https://policy.pinterest.com/en/privacy-policy
Cookies:
https://policy.pinterest.com/en/cookies


Use of Facebook Social Plugins

Our website may use social plugins (“plugins”) from Facebook, operated by Meta Platforms Ireland Ltd.

You can recognize Facebook plugins by the “f” logo, thumbs-up “Like” button, or the label “Facebook Social Plugin”. An overview is available here:
https://developers.facebook.com/docs/plugins/

When visiting a page with such a plugin, your browser may automatically connect to Facebook’s servers, even without direct interaction. Personal data such as your IP address, browser details, pages visited, and timestamp may be transmitted to Facebook.

Facebook plugins are only activated with your explicit consent via the cookie banner in accordance with Art. 6(1)(a) GDPR. Without consent, no data is transmitted to Facebook.

If you’re logged in to Facebook, Facebook can link the visit to your profile even without you interacting with the plugin.

Facebook’s privacy policy:
https://www.facebook.com/about/privacy


Your Rights

You have the right to access, rectification, erasure, restriction of processing, data portability, and the right to object or withdraw consent. To exercise these rights, please contact:
info@naturhotel.at

If you believe that your data is being processed unlawfully, you can lodge a complaint with the supervisory authority. In Austria, this is the Data Protection Authority (Datenschutzbehörde).


Contact:

Naturhotel Chesa Valisa
GmbH & Co. KG
Gerbeweg 18
A-6992 Hirschegg
T +43 5517 54 140
F +43 5517 51 08
E info@naturhotel.at
UID: ATU35896508
Company reg. no.: FN 15352b
Commercial court: Landesgericht Feldkirch