DATA PRIVACY POLICY

[1.] Data privacy statement

We process personal data exclusively within the framework of the provisions of the General Data Protection Regulation (GDPR) and the Data Protection Act. On this page, we will inform you about us, as well as the type, scope and purpose of data collection and how the data is used:

 

[2.] About us

Hotel Nesslerhof GmbH is responsible for processing your personal data on our website. You can find company data on our legal notice page.

 

[3.] Collection and processing of data

We process personal data that you, as a user of the website and/or as a customer, provide to us by submitting information; for example in the context of an enquiry or registration, or to conclude a contract. Data is processed for the following purposes:

  • to process updates to a customer’s file
  • to process reservations
  • to process your request/enquiry
  • to process your booking
  • to customise your stay to meet your wishes and interests
  • for billing and payment processing
  • for contract processing
  • for targeted information (marketing) regarding new offers/products
  • to allow for the future possibility of offering services that match your interests

 

The legal basis for data processing is:

• Entering into and fulfilment of contracts pursuant to Article 6 Par. 1 b GDPR. We need your data in order to process your request to your complete satisfaction.
• Marketing and advertising pursuant to Article 6 Par. 1 f DSGVO. If you are interested in our offers, we would like to provide you with up-to-date, specific information about new offers and products.

 

[4.] Use and disclosure of personal data

If you have provided us with personal data as a user of our website and/or customer, we will only use this to answer your enquiries, to process contracts and for technical administration. We pass on or transmit personal data to third parties if it is necessary for the purpose of processing your contract or for billing purposes, or if you, as a user of the website and/or customer, have given your prior consent. This includes instances in which we transmit your personal data to service providers and their assistants who offer cloud-based software and data processing solutions for the hotel, and who evaluate and process your data (for the purposes above) on behalf of the hotel. Users of the website and/or customers have the right to revoke your consent at any time with effect for the future. Stored personal data will be deleted if you, as a user of the website and/or customer, revoke your consent to its storage, if your data is no longer required to fulfil the purpose for which it was stored, or if its storage is or will become inadmissible for other legal reasons. Data for billing and accounting purposes are not affected by a request for deletion.

 

[5.] Disclosure, correction, deletion

Upon receiving a written request, we will be happy to inform you at any time about the data stored about your person. Please contact info@nesslerhof.at or Hotel Nesslerhof GmbH, Unterbergstrasse 50, 5611 Grossarl, Austria, for enquiries on this matter. If your data processed is not correct, please inform us; we will correct this immediately and inform you of the change(s). If you no longer want us to process your data, we ask you to contact us informally at info@nesslerhof.at or Hotel Nesslerhof GmbH, Unterbergstrasse 50, 5611 Grossarl, Austria to inform us. We will delete your data immediately and inform you accordingly. If there are compelling legal reasons that prevent its deletion, we will inform you immediately.

You also have the right to file a complaint with the supervisory authority (Österreichische Datenschutzbehörde (Austrian Data Protection Authority), Wickenburggasse 8, 1080 Vienna, Austria, dsb@dsb.gv.at).

 

[6.] Cookies

Our website uses cookies. Cookies are small text files that are sent when a website is visited and that are temporarily stored on the hard drive of the website user and/or customer. If the corresponding server of our website is called up again by the user of the website and/or customer, the user of the website and/or customer’s browser sends the previously received cookie back to the server. The server can then evaluate the information obtained through this procedure in various ways. Cookies can be used, for example, to control advertisements or to make it easier to navigate a website. If the user of the website and/or customer wants to prevent cookies from being used, they can do this by making local changes to their settings in their chosen internet browser, i.e. the program for opening and displaying internet pages (e.g. Internet Explorer, Mozilla Firefox, Opera or Safari).

Our website uses the following cookies:

  • necessary cookies to ensure basic functions of the website,
  • CookieConsent to store consent to the use of cookies,
  • functional cookies to ensure website performance, and
  • performance cookies to improve user experience.

 

Detailed cookies information:

  • _dc_gtm_UA-19240050-1: Google Analytics cookie to measure user behaviour.
  • PRUM_EPISODES: Pingdom Real User Monitoring to measure access times.
  • cookiesAllowed: recognises if the cookie dialogue has been confirmed.
  • Neos_Session from Neos Framework: to identified logged-in users.

 

[7.] E-mail newsletter

By ticking the box, you consent to the processing of personal data you have entered for the purpose of informing you about:

  • new offers
  • current holiday package deals
  • company news
  • contests

via an e-mail newsletter by the data controller under data protection law until revoked or objected to.

There is no legal or contractual obligation to provide personal data. The only consequence of non-consent is that you will not receive an e-mail newsletter.

You have the right to revoke your consent at any time by providing written notification, or by clicking on the unsubscribe link in the e-mail newsletter, without affecting the legality of the processing carried out on the basis of consent up until consent was revoked. 

You can also object to the use of your personal data for the purpose of direct advertising in the same way. In the event of an objection, your personal data will no longer be processed for the purpose of direct advertising in the form of an e-mail newsletter.

 

[8.] Google Analytics

This website uses Google Analytics, a web analysis service of Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”) on the legal basis of the predominant legitimate interest (analysis of website usage). We have concluded a contract data processing agreement with Google for this purpose.

When you visit our website, software is used to establish a connection to Google’s servers and transmit data to Google’s servers, some of which are located in the US. Google Analytics also uses cookies to store information about website users and to analyse website users’ use of the website.

This website uses the “IP anonymisation” function. This means your IP address will be shortened and thus made anonymous by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will your full IP address be transmitted to a Google server in the US and shortened there.

According to Google, Google only uses data collected to evaluate the use of the website, to compile reports on website activity and to provide other services relating to website activity and internet usage.

Google may also transfer this information to third parties if this is required by law, or if third parties process this data on behalf of Google.

Find more information on how user data is handled by Google Analytics in Google’s data privacy statement.

 

[8.1.] Deactivate Google Analytics

You can prevent the collection of your user data on our website by activating the “Do Not Track” setting in your web browser. Our website takes into account the “Do Not Track” signal, which your web browser then sends to all websites.

You can prevent Google Analytics from collecting your user data in general on all websites by downloading and installing the browser plug-in available at the following link:
https://tools.google.com/dlpage/gaoptout?hl=en

You can prevent Google Analytics from collecting your user data on this website only by clicking the following link. An opt-out cookie will be placed which prevents your data from being recorded on future visits to this website.

[9.] Facebook Pixel

This website uses Facebook Pixel, a web analysis service of Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland (“Facebook”) on the legal basis of predominant interest (analysis of website usage). We have concluded a contract data processing agreement with Facebook for this purpose. Some data is transmitted to the US. The data is transmitted to the US on the basis of the Privacy Shield.

When you visit our website, software is used to establish a connection to the Facebook servers and data is transmitted to Facebook servers, some of which are located in the US. Facebook Pixel also uses cookies to store information about the website user and to analyse the use of the website by the website user.

According to Facebook, Facebook uses data collected to evaluate the use of the website, to compile reports on website activity and to provide other services relating to website activity and internet usage.

Facebook may also transfer this information to third parties if this is required by law, or if third parties process this data on behalf of Facebook.

Find more information on how user data is handled by Facebook in Facebook’s privacy policy.

 

[9.1.] Deactivate Facebook Pixel

You can prevent the collection of your user data on our website by activating the “Do Not Track” setting in your web browser. Our website takes into account the “Do Not Track” signal, which your web browser then sends to all websites.

You can prevent Facebook Pixel from collecting your user data on this website only by clicking the following link. An opt-out cookie will be placed which prevents your data from being recorded on future visits to this website.

[10.] LinkedIn

This website uses tracking technology and the retargeting function of LinkedIn Corporation.

This technology helps visitors to this website to display personalised advertising on LinkedIn. It is also possible to generate anonymous reports on the performance of the advertisements and information on website interaction. For this purpose, the LinkedIn Insight Tag has been integrated into the website. This establishes a connection to the LinkedIn server as soon as you visit the nesslerhof.at website and are logged into your LinkedIn account at the same time.

Find more information on data collection and usage, as well as privacy protection rights, in LinkedIn’s privacy policy. If you are logged into LinkedIn, you can deactivate data collection at any time by clicking the following link: www.linkedin.com/psettings/enhanced-advertising

 

[11.] Enquiry form

Upon submitting your enquiry form, the personal data you have entered will be processed by the data controller under data protection law for the purpose of processing your enquiry on the basis of your consent given by sending the form.

There is no legal or contractual obligation to provide your personal data. Failure to provide personal data simply means that you do not submit your enquiry and we cannot process it.

You have the right to revoke your consent at any time by means of written notification, without affecting the legality of the processing carried out on the basis of the consent up until the time consent was revoked.

Further processing of the data which is consistent with the original purpose for processing is done on the same legal basis for the purpose of direct marketing in forms that do not require consent, such as addressed postal advertising, unless there is an objection. In this case, data will be transmitted to the delivery service provider.

You have the right to object to the use of your personal data for the purpose of direct advertising at any time by means of written notification. If you object, your personal data will no longer be processed for the purpose of direct advertising.

 

[12.] Contests

When you participate in a contest, the data you provide will be processed by the data controller for the purpose of carrying out the contest on the basis of a contest contract concluded when the contest is finished.

There is no legal or contractual obligation to provide personal data. However, it is required to take part in the contest. Failure to provide personal data simply means that you cannot take part in the contest.

You have the right to object to the use of your personal data for the purpose of direct advertising at any time by means of written notification. If you object, your personal data will no longer be processed for the purpose of direct advertising.

 

[13.] ADDITIVE+ marketing automation

In order to increase customer loyalty and to sell our services and additional services we use software provided by ADDITIVE s.n.c., 39011 Lana (BZ), Italy (“ADDITIVE”). 

Therefore your data, which we gather and process in connection with your request, reservation, order, activation, registration or the transmission of other contact forms on our website, will be analysed and used to provide you with automatically generated offers for our services and additional services. Through the use of these services and systems your data will be processed and stored, at least in part, also outside of the EU or the EEC. The adequate level of data protection is based on an adequacy decision taken by the European Commission (“Privacy Shield”) or on data processing agreements. 

  • You can deny the use of your data for this purpose anytime by clicking on the “unsubscribe” link in the respective message.
  • The data processing takes place in accordance with the requirements of art. 6 para. 1 lit f (legitimate interests) of the GDPR.
  • Our objective in accordance with the GDPR (legitimate interests) is the prevention of competitive disadvantages, the increase in brand awareness and the maximization of our economic success through an optimal use of the acquired contacts.

 

[14.] ADDITIVE+ Landingpage -  Online Marketing and Landing Pages

Beside our website we do also operate optimized landing pages for means of hotel online marketing. To process your request, reservation, order, activation, registration or the transmission of other contact forms on our website as well as to save and store your data we use cloud services, CRM systems and software provided by ADDITIVE Srl, 39011 Lana (BZ), Italy (“ADDITIVE”), our partner in the field of hotel digital marketing. The adequate level of data protection is based on data processing agreements with the respective company. 

Our landing pages use Google Analytics, a web analytics service provided by Google Inc. (“Google”). Google Analytics enables website operators to analyse the user behavior of the visitors. The information about the user behavior is transmitted to and stored by Google on its servers.

Your IP address is collected but immediately anonymised (for example by deleting the last 8 bits). As a result, the geolocation data is less accurate. You can prevent the data collection connected to your use of our online services through cookies and the processing of this data by Google, by installing the browser-plugin available at the following link: https://chrome.google.com/webstore/detail/google-analytics-opt-out/fllaojicojecljbmefodhfapmkghcbnh

ADDITIVE has an insight into data gathered through Google Analytics. This data will be used only to analyse the use of our websites and to evaluate our marketing and distribution strategies.

Our website and landing pages also use functions provided by ADDITIVE for the multi-channel monitoring of the use of our websites as well as marketing and distribution strategies like landing pages, newsletter and social media presence. Information about your visits and submitted forms on our websites are also transmitted to ADDITIVE in order to evaluate and optimize our marketing and sales measures.

The data processing takes place in accordance with the requirements of art. 6 para. 1 lit f (legitimate interests) of the GDPR. Our objective in accordance with the GDPR (legitimate interests) is the improvement of our products and services and our web presence through the analysis of the use of our website as well as marketing and distribution strategies. 

Our website and our landing pages also use remarketing functions provided by Google Inc. (“Google”) and by Meta Platforms Inc. (“Meta”). Therefore, Meta and Google will know that you have visited our website. This way visitors of our website and of our landing pages will find ads adapted to their interests on Google’s advertising platforms and on the social media platforms Facebook and Instagram.

The data processing takes place in accordance with the requirements of art. 6 para. 1 lit a (consent) of the GDPR.

When you visit our landing pages a banner will inform you about the use of cookies for remarketing functions. If you continue using the website or click on the respective button you consent to the use of cookies. You can deny your consent anytime, by visiting the page containing the cookie information and denying the use in the banner that will be displayed.

 

[15.] ADDITIVE+ Newsletter

On our website you have the possibility to subscribe to our newsletter. For the subscription we need your email address and your consent to receive our newsletter through ADDITIVE, our provider for hotel e mail marketing. To provide you with relevant information we also gather and process voluntary information concerning interests, name, date of birth and country/region of origin in our hotel newsletter tool.

After signing up for our newsletter you will receive an email containing a link to confirm the subscription. Your subscription can be cancelled any time by clicking on the cancellation link in the respective newsletter.

To process your subscriptions and to send our newsletters we use software provided by ADDITIVE Srl, 39011 Lana (BZ), Italy (“ADDITIVE”). Through the use of these services and systems your data will be processed and stored, at least in part, also outside of the EU or the EEC. The adequate level of data protection is based on data processing agreements.