Protecting your data
Privacy policy
This policy explains which personal data is processed when you visit our website and use its functions.
Controller
Hotel Styrolerhof KGWalchen 46, 6655 Steeg, Austria
Phone: +43 5633 20088
Email: office@styrolerhof.at
1. Principles and scope
Personal data is information relating to an identified or identifiable person. We process such data only where a legal basis applies, in particular to perform a contract, comply with legal obligations, pursue a legitimate interest or where you have given consent.
This privacy policy applies to hotel-styrolerhof.at, including its German and English pages and the protected editorial area. Linked third-party services are governed by their own privacy policies.
2. Hosting and server logs
When the website is accessed, the web server processes connection data required for technical operation. This may include the IP address, date and time, requested file or URL, referrer URL, browser and operating system, HTTP status and amount of data transferred.
The data is processed to provide the website securely and reliably, analyse errors and prevent attacks on the basis of our legitimate interests under Article 6(1)(f) GDPR. Log data is erased or anonymised once it is no longer required for these purposes, unless a legal retention duty or a specific security incident requires longer storage. The hosting provider processes this data on our behalf.
3. Contact, enquiries and applications
If you contact us by email, telephone or a linked communication service, we process the information you provide, particularly your name, contact details, message content and, where applicable, booking or application documents.
The legal basis is Article 6(1)(b) GDPR where processing is required to enter into or perform a contract; otherwise it is our legitimate interest in responding to enquiries under Article 6(1)(f) GDPR. General enquiry data is erased after the matter has been completed unless statutory retention or evidence requirements apply. Application data is generally erased no later than six months after the recruitment process ends, unless you consent to longer retention or the data is required to establish, exercise or defend legal claims.
4. Room booking and availability checks
Room booking buttons and search forms lead to external booking pages under officialbookings.com. The booking solution is provided by Seekda or Kognitiv. When these pages are opened and a booking is made, the provider processes technical connection data and the booking information you enter, such as name, contact details, travel dates, occupancy, requests and any required payment and billing data.
The data you enter is transferred in order to take pre-contractual steps and perform the booking contract under Article 6(1)(b) GDPR. The provider's own privacy information also applies on the external platform: Seekda Privacy Policy and Kognitiv Legal & Privacy.
5. Table reservations, orders and WhatsApp
We use services of DISH Digital Solutions GmbH, Metro-Straße 1, 40235 Düsseldorf, Germany for table reservations and online orders. An external reservation widget is embedded on the restaurant page; order buttons lead to a DISH page. Technical data may be processed when the widget loads, and the contact, reservation, order and, where applicable, payment data you enter is processed when you make a reservation or order.
Reservation and order data is processed under Article 6(1)(b) GDPR. Loading an external widget that is not technically necessary generally requires your prior consent under Article 6(1)(a) GDPR. Further information is available in the DISH privacy policy.
A WhatsApp link lets you open a chat with us. You leave our website only when you click the link; WhatsApp or Meta then processes your data under its own terms. You may use telephone or email instead if you do not wish to communicate via WhatsApp. Information: WhatsApp Privacy Policy.
6. Vimeo videos
Some pages contain videos from Vimeo.com, Inc., 330 West 34th Street, 5th Floor, New York, NY 10001, USA. When an embedded player is loaded, data such as your IP address, device and browser information, the page visited, usage data and cookies or similar identifiers may be transferred to Vimeo.
We rely on your consent under Article 6(1)(a) GDPR to load this optional content. You may withdraw consent at any time with effect for the future. Transfers to the United States may require additional safeguards under Articles 44 et seq. GDPR. Further information: Vimeo Privacy Policy.
7. Social Wall, Instagram and Facebook
The Social Wall displays local copies of selected Instagram media stored on our web server, together with the publicly visible caption and publication date. Merely displaying this local content does not connect to Meta. Data is transferred to Meta only when you open a linked post or our Instagram or Facebook profile.
For editorial maintenance, the protected editor uses the Instagram API with Facebook Login. Following authorisation by an authorised administrator, it retrieves data including the Instagram account ID, username, media, captions, permalinks and timestamps. Access tokens are stored securely on the server and are not exposed to public website visitors. The legal basis is our legitimate interest in maintaining our public communications under Article 6(1)(f) GDPR. Information on Meta's processing: Meta Privacy Policy.
8. DeepL in the protected editor
The protected editor uses the DeepL API Pro from DeepL SE, Maarweg 165, 50825 Cologne, Germany to translate website content. Only website text selected for translation by authorised editors is transferred. Input from public website visitors is not sent to DeepL.
Processing is based on our legitimate interest in providing a multilingual website under Article 6(1)(f) GDPR. Editors are instructed not to include personal data in translation text. Further information: DeepL Privacy Policy.
9. Cookies and local storage
According to the current technical implementation, we do not use our own analytics or marketing cookies on the public pages. The accessibility module stores your selected display preferences only in your browser's local storage. They remain on your device until you reset them in the module or delete them in your browser.
The protected editor uses a technically necessary session cookie with security attributes to authenticate signed-in editors. The legal basis is Article 6(1)(f) GDPR. External content such as DISH or Vimeo may use its own cookies or similar technologies, as described above. Where these are not strictly necessary, they may be loaded only after you have given consent.
10. Recipients and transfers to third countries
We transfer data only where this is required for the purposes described, a legal obligation applies, you have consented or a legitimate interest justifies the transfer. Recipients may include hosting and IT providers, booking and reservation providers, payment and communication services, public authorities and professional advisers.
If data is processed outside the European Economic Area, this takes place only subject to Articles 44 et seq. GDPR, for example on the basis of an adequacy decision, appropriate safeguards such as EU standard contractual clauses or explicit consent. Country-specific risks cannot be completely excluded for some external services despite such safeguards.
11. Retention periods
We retain personal data only for as long as it is required for the respective purpose. It is then erased or anonymised unless statutory retention duties, particularly under commercial and tax law, warranty and limitation periods or the safeguarding of legal claims require longer retention.
12. Your rights
Subject to the applicable legal requirements, you have the right of access, rectification, erasure, restriction of processing, data portability and objection. You may withdraw consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
To exercise your rights, contact office@styrolerhof.at or write to the postal address stated above. Where there are reasonable doubts, we may request additional information to verify your identity.
You also have the right to lodge a complaint with the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, Austria, email: dsb@dsb.gv.at, website: www.dsb.gv.at.
13. Security and updates
We take appropriate technical and organisational measures to protect personal data against loss, unauthorised access and misuse. This website does not carry out solely automated decision-making, including profiling, that produces legal or similarly significant effects.
We update this privacy policy when the law, website functions or services used change. The version published on this page is the current version.
