Data protection declaration information according to Art. 13 and 14 DSGVO
Responsible for data protection:
Attersee 7 - the 4 Star Hotels at Lake Attersee
4852 Weyregg am Attersee
+43 7664 2291
Data processing purposes:
If you contact us using the form on the website or by e-mail, the data you provide will be stored by us for six months for the purpose of processing the enquiry and in case of follow-up questions. We do not pass on this data without your consent. If you fill out the contact form, HEROLD Business Data GmbH will process the data as an order processor on the basis of the General Terms and Conditions (in particular the regulations on order data processing contained therein). HEROLD Business Data GmbH uses a sub-processor (SurveyMonkey Europe UC, 2 Shelbourne Buildings, 2nd Floor, Shelbourne Road, Ballsbridge, Dublin 4, Ireland), which has access to the data contained in the contact form and which stores data in the USA. Any provision of data to the sub-processor is based on an adequacy decision by the European Commission (Privacy Shield self-certification).
ORDER DATA PROCESSORS INVOLVED
Booking system, guest, and Service Partner Data Management
Bookings on our booking platform & direct enquiries
We process the data of our customers within the framework of bookings, brochure or availability requests via our booking system in order to enable them to book the selected services, as well as to pay for or execute them or to send you the requested information.
The processed data includes inventory data, communication data, contract data, payment data. The persons affected by the processing include our customers, interested parties and other business partners. The processing is carried out for the purpose of providing contractual services in the context of operating a booking portal, invoicing, delivery, and customer services. For this purpose, we set session cookies for the storage of the shopping basket contents.
The processing is based on Art. 6 para. 1 lit. b (execution of ordering processes) and c (legally required archiving) GDPR. In this context, the information marked as required is required for the establishment and performance of the contract. We disclose the data to third parties only within the scope of delivery, payment or within the scope of the legal permits and obligations to legal advisors and authorities. The data will only be processed in third countries if this is necessary for the fulfilment of the contract (e.g. on customer request for delivery or payment). Within the framework of the booking, the users are informed of the required mandatory data.
The anonymisation of data from regular online bookings is carried out 18 months after the date of departure. In the case of package bookings, the data will be anonymised after expiry of statutory archiving obligations. Critical data (e.g. credit card data) is deleted 30 days after the date of departure.
In addition, data is collected and used for analysis purposes. This data processing is not personal (see information on cookies below).
When registering, the user's email address and a password are stored. If a purchase is subsequently made, the email address is linked to the data collected during the purchase process. The data provided by you is required to set up the user account. The data is processed for the duration of the existence of the user account. Upon deletion of the user account, the e-mail address and the password as well as the link to the data of the purchase transaction.
When visiting this website, log files are also stored which contain the IP address and other data on access to the website (e.g. date, time, user agent, referrer). Data processing is limited in time (maximum 30 days) and only to protect against DDOS attacks or other interventions in the functionality of the website and any underlying database systems.
Information on cookies
This website uses so-called cookies. These are small text files that are stored on your end device with the help of the browser. They do not cause any damage.
So-called session cookies are used on this site. These are generated when you call up the website and are automatically deleted again. They are used to recognise you when you call up the same website again within a short period of time, in order to take into account any settings you have already made. No personal data is stored or processed.
The purpose of cookies is to make the website user-friendly. Some cookies remain stored on your end device until you delete them. They enable the website operator to recognise your browser the next time you visit the website. If you do not wish this, you can set your browser so that it informs you about the setting of cookies and you only allow this in individual cases. However, if you deactivate cookies, the functionality of the website may be limited.
Google web analysis service (Google Analytics)
This website uses functions of the web analysis service Google Analytics. The provider is Google Inc, 1600 Amphitheatre Parkway Mountain View, CA
94043, USA. We use the function "Activation of IP anonymisation" on this website. This means that your IP address will be shortened by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area before processing/storage. On behalf of the operator of this website, Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity, and measuring the campaign performance of online advertising for analysis and optimisation purposes.
You can prevent the collection of data generated by the cookie and related to your use of the website by Google, as well as the processing of this data by Google, by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=en
Instructions on how you can also prevent Google from storing data can be found at the following link: https://developers.google.com/analytics/devguides/...
The relationship with the web analytics provider is based on commissioned data processing when using Google Analytics. The transfer of data to the processor is based on an adequacy decision of the European Commission (Privacy Shield self-certification). The data is deleted regularly (currently every 26 months).
Use of Google Adwords conversion tracking
This website uses the online advertising programme "Google AdWords" and, as part of Google AdWords, conversion tracking. Google Conversion Tracking is an analysis service provided by Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; "Google"). When you click on an ad placed by Google, a cookie for conversion tracking will be placed on your computer. These cookies lose their validity after a maximum of 90 days. If you visit certain web pages on our website and the cookie has not yet expired, Google and the website operator will be able to recognise that you have clicked on the ad and have been redirected to this page. The information obtained with the help of the conversion cookie is used to create conversion statistics. In doing so, the website operator learns the total number of users who have clicked on an ad and were redirected to a page marked with a conversion tracking tag
and/or have performed various actions on the page. However, the website operator does not receive any information with which users can be personally identified. If you do not wish to participate in the tracking, you can object to this use by preventing the installation of cookies through a corresponding setting in your browser software (deactivation option). You will then not be included in the conversion tracking statistics. Further information as well as Google's data protection declaration can be found at: http://www.google.com/policies/technologies/ads/, http://www.google.com/policies/privacy/
The relationship with the web analytics provider is based on commissioned data processing when using Google Adwords conversion tracking. The transfer of data to the processor is based on an adequacy decision by the European Commission (Privacy Shield self-certification). Google is also obliged to delete the data regularly (currently every 39 months).
If Facebook social plugins are used on this website, they are provided by Facebook Inc. (1 Hacker Way, Menlo Park, California 94025, USA). The integrations can be recognised by the Facebook logo or the terms "Like", "Like", "Share" in Facebook's colours (blue and white). Information on all Facebook plugins can be found in the following link: https://developers.facebook.com/docs/plugins/
The plugins are only activated when you click on the corresponding buttons. If they are greyed out, the plugins are inactive. You have the option of activating the plugins on each visit.
The plugins establish a direct connection between your browser and the Facebook servers. This only takes place after the plugin has been activated. The website operator has no influence on the nature and scope of the data that the plugin transmits to the servers of Facebook Inc. Information on this can be found here: https://www.facebook.com/help/186325668085084
The plugin informs Facebook Inc. that you as a user have visited this website. There is a possibility that your IP address will be stored. If you are logged into your Facebook account during your visit to this website, the aforementioned information will be linked to it.
Legal basis for data processing:
On the website, data is processed exclusively on the basis of the legal provisions (DSGVO, TKG 2003).
Data processing (webshop, product evaluations, booking tool and user account) is based on Art 6 (1) (b) (contract performance purposes) DSGVO.
In the case of the use of analysis tools, the data is used on the basis of Art 6 (1) (f) (legitimate interest) DSGVO. The legitimate interest in the use of data is the improvement of the website and the measurement of the success of online advertising.
The use of IT data security measures is also based on Art 6 (1) (f) (legitimate interest) DSGVO. The legitimate interest in the use of data is the safeguarding of our own IT systems.
The use of social media plugins only takes place after consent. The legal basis is therefore Art. 6 para. 1 lit a) DSGVO. Consent must be given again each time you visit the website.
In principle, you have the rights to information, correction, deletion, restriction of processing, data portability, revocation and objection. If you believe that the processing of your data violates data protection law or your data protection rights have been violated in any other way, you can complain to the supervisory authority. In Austria this is the data protection authority.