Privacy Policy

A. General Information

1. Responsible Party and Content of this Privacy Policy

We, the company Betriebsgesellschaft Vitznauerhof AG, operate the Vitznauerhof Hotel and the website  www.vitznauerhof.ch  and are, unless otherwise stated, responsible for the data processing listed in this privacy policy.

To inform you about which personal data we collect from you and for what purposes we use it, please take note of the information below. We primarily adhere to the legal requirements of Swiss data protection law, particularly the Federal Act on Data Protection (DSG), as well as the EU GDPR, whose provisions may apply in individual cases.

Please note that the following information will be reviewed and changed from time to time. We therefore recommend that you regularly review this privacy policy. Furthermore, for certain data processing listed below, other companies may be legally responsible for data protection or jointly responsible with us, so in these cases, the information from these providers is also relevant.

2. Contact Person for Data Protection

 If you have questions about data protection or wish to exercise your rights, please contact our data protection officer by sending an email to the following address: raphael.herzog@vitznauerhof.ch

3. Your Rights

 If the legal requirements are met, you have the following rights as a data subject:

Right to Access: You have the right to request free access to your personal data stored with us at any time if we process it. This allows you to check which personal data we process about you and that we use it in accordance with applicable data protection regulations.

Right to Rectification: You have the right to have inaccurate or incomplete personal data rectified and to be informed about the rectification. In this case, we will inform the recipients of the affected data about the adjustments made, unless this is impossible or involves disproportionate effort.

Right to Deletion: You have the right to have your personal data deleted under certain circumstances. In individual cases, particularly in the case of legal retention obligations, the right to deletion may be excluded. In this case, if the conditions are met, a restriction of the data may take the place of deletion.

Right to Restriction of Processing: You have the right to request that the processing of your personal data be restricted.

Right to Data Portability: You have the right to receive the personal data you provided to us free of charge in a readable format.

Right to Object: You can object to data processing at any time, particularly for data processing related to direct marketing (e.g., promotional emails).

Right to Withdraw Consent: You generally have the right to withdraw any consent given at any time. However, the processing activities based on your consent in the past will not be deemed unlawful due to your withdrawal.

To exercise these rights, please send us an email to the following address: info@vitznauerhof.ch

Right to Lodge a Complaint: You have the right to lodge a complaint with a competent supervisory authority, e.g., regarding the manner in which your personal data is processed.

4. Data Security

We use appropriate technical and organizational security measures to protect your personal data stored with us against loss and unlawful processing, namely unauthorized access by third parties. Our employees and the service providers we engage are obligated to maintain confidentiality and to uphold data protection. Furthermore, access to personal data is granted to these individuals only to the extent necessary to fulfill their tasks.

Our security measures are continuously adapted in accordance with technological developments. However, the transmission of information over the Internet and electronic communication always involves certain security risks, and we cannot guarantee absolute security for information transmitted in this manner.

5. Contacting Us

If you contact us via our contact addresses and channels (e.g., by email, phone, or contact form), your personal data will be processed. The data processed includes the information you provide, such as your company name, your name, your position, your email address or phone number, and your inquiry. Additionally, the time of receipt of the request is documented. Mandatory information is marked with an asterisk (*) in contact forms.

We process this data solely to address your inquiry (e.g., providing information about our hotel, assisting with contract processing such as questions about your booking, incorporating your feedback into the improvement of our services, etc.).

6. Use of Your Data for Marketing Purposes

 

6.1 Central Data Storage and Analysis in the CRM System

 If a clear assignment to your person is possible, we will store and link the data described in this privacy policy, i.e., in particular your personal details, your contact interactions, your contract data, and your

browsing behavior on our websites in a central database. This serves the efficient management of customer data and allows us to adequately respond to your inquiries and enables the efficient provision of the services you requested and the processing of the associated contracts.

We analyze this data to further develop our offerings based on needs and to display and suggest the most relevant information and offers to you. We also employ methods that predict possible interests and future orders based on your website usage.

6.2 Email Marketing and Newsletter

If you register for our email newsletter (e.g., at the opening or within your customer account), the following data will be collected. Mandatory information is marked with an asterisk (*) in the registration form:

  • Email address
  • Salutation
  • First and last name

To prevent misuse and to ensure that the holder of an email address has indeed given their consent, we use the so-called double opt-in for registration. After submitting the registration, you will receive an email from us containing a confirmation link.

To definitively subscribe to the newsletter, you must activate this link. If you do not click on the confirmation link within the specified period, your data will be deleted, and our newsletter will not be sent to that address.

By registering, you consent to the processing of this data to receive messages from us about our hotel and related information about products and services. This may also include requests to participate in competitions or to evaluate one of the aforementioned products and services. The collection of the salutation and name allows us to verify the assignment of the registration to any existing customer account and to personalize the content of the emails. Linking with a customer account helps us make the offers and content in the newsletter more relevant to you and better tailored to your potential needs.

We use your data for email marketing until you withdraw your consent. A withdrawal is possible at any time, particularly via the unsubscribe link in all our marketing emails.

Our marketing emails may contain a so-called web beacon or 1x1 pixel (tracking pixel) or similar technical tools. A web beacon is an invisible graphic linked to the user ID of the respective newsletter subscriber. For each marketing email sent, we receive information about which addresses have not yet received the email, to which addresses it was sent, and to which addresses the sending failed. It is also shown which addresses opened the email for how long and which links they clicked on. Finally, we also receive information about which addresses have unsubscribed. We use this data for statistical purposes and to optimize the marketing emails regarding frequency, timing, structure, and content of the emails.

This way, we can better tailor the information and offers in our emails to the individual interests of the recipients.

The web beacon will be deleted when you delete the email. To prevent the use of the web beacon in our marketing emails, please set the parameters of your email program so that HTML is not displayed in messages, if this is not already the default setting. In the help sections of your email software, you will find information on how to configure this setting, e.g.,  here for Microsoft Outlook.

By signing up for the newsletter, you also consent to the statistical evaluation of user behavior for the purpose of optimizing and adjusting the newsletter.

We use the email marketing software Mailchimp from The Rocket Science Group LLC d/b/a Mailchimp for marketing emails. Therefore, your data is stored in a database of Mailchimp, allowing Mailchimp to access your data when necessary for providing the software and supporting its use.

7. Disclosure to Third Parties and Access by Third Parties

Without the support of other companies, we could not provide our services in the desired form. To utilize the services of these companies, it is also necessary to share your personal data to a certain extent. Such disclosure occurs in particular to fulfill the contract you requested, i.e., for example, to restaurants or other third-party providers for which you have made a reservation.

Disclosure also occurs to selected service providers and only to the extent necessary for providing the service. Various third-party service providers are also explicitly mentioned in this privacy policy, such as in the sections on marketing. These include, for example, IT service providers (such as software solution providers), advertising agencies, consulting firms.

Furthermore, your data may be disclosed, particularly to authorities, legal advisors, or collection agencies, if we are legally obligated to do so or if it is necessary to protect our rights, particularly to enforce claims arising from our relationship with you. Data may also be shared if another company intends to acquire our company or parts thereof, and such disclosure is necessary for conducting a due diligence review or for executing the transaction.

8. Transfer of Personal Data Abroad

 We are entitled to transfer your personal data to third parties abroad if this is necessary for the execution of the data processing mentioned in this privacy policy (see in particular sections  1215). In doing so, we will of course comply with the legal provisions regarding the disclosure of personal data to third parties. If the respective country does not have an adequate level of data protection, we ensure through contractual arrangements that your data is adequately protected with these companies.

9. Retention Periods

We only store personal data as long as necessary to carry out the processing described in this privacy policy within the framework of our legitimate interests. For contract data, storage is required by legal retention obligations. Requirements that obligate us to retain data arise from accounting regulations and tax law provisions. According to these provisions, business communication, closed contracts, and booking documents must be retained for up to 10 years. As long as we no longer need this data to provide services for you, the data will be blocked. This means that the data may only be used if this is necessary to fulfill retention obligations or to defend and enforce our legal interests. Deletion of the data occurs as soon as there are no longer any retention obligations or legitimate interests in retaining it.

B. Special Notes for Our Website

 

10. Logfile Data

When you visit our website, the servers of our hosting provider temporarily store each access in a log file (so-called logfile). The following data is collected without your intervention and stored by us until automated deletion:

  • the IP address of the requesting computer,
  • the date and time of access,
  • the name and URL of the retrieved file,
  • the website from which the access occurred, with the search term used,
  • the operating system of your computer and the browser you are using (including type, version, and language setting),
  • device type in the case of accesses via mobile phones,
  • the city or region from where the access occurred,
  • the name of your internet access provider.

The collection and processing of this data is for the purpose of enabling the use of our website (connection establishment), ensuring the system's security and stability in the long term, as well as for error and performance analysis, and allows us to optimize our website (see also the last points in section  13).

In the event of an attack on the website's network infrastructure or if there is suspicion of other unauthorized or abusive use of the website, the IP address and other data will be evaluated for clarification and defense and may be used in the context of criminal proceedings to identify and take civil and criminal action against the respective users.

Finally, we use cookies and applications and tools based on the use of cookies when you visit our website. In this context, the data described here may also be processed. For further details, please refer to the subsequent sections of this privacy policy, particularly section  11.

11. Cookies

Cookies are information files that your web browser stores on the hard drive or RAM of your computer when you visit our website. Cookies are assigned identification numbers, which allow your browser to be recognized and the information contained in the cookie to be read.

Cookies help make your visit to our website easier, more pleasant, and more meaningful. We use cookies for various purposes that are necessary for the use of the website you desire, i.e., "technically necessary". For example, we use cookies to identify you as a registered user after logging in, so that you do not have to log in again when navigating through the various subpages. The provision of the shopping cart and ordering function is also based on the use of cookies. Furthermore, cookies also take on other technical functions necessary for the operation of the website, such as load balancing, which distributes the performance load of the site across different web servers to relieve the servers. Cookies are also used for security purposes to prevent unauthorized posting of content. Finally, we also use cookies in the design and programming of our website, for example, to enable the uploading of scripts or codes.

Most internet browsers automatically accept cookies. When accessing our website, however, we ask for your consent to the technically non-essential cookies we use, particularly when using third-party cookies for marketing purposes. You can make the desired settings via the corresponding buttons in the cookie banner. Details about the services and data processing associated with each cookie can be found within the cookie banner and in the subsequent sections of this privacy policy.

You can also configure your browser so that no cookies are stored on your computer or that you receive a notification each time you receive a new cookie. The following pages provide explanations on how to configure cookie processing in selected browsers.

Disabling cookies may result in you not being able to use all the features of our website.

12. Google SiteSearch / Google Custom Search Engine

 On this website, we use the Google SiteSearch/Google Custom Search Engine from Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). This allows us to provide you with an efficient search function on our website.

When using our search fields, your browser may transmit the logfile data listed in section  10 (including IP address) and the search term you entered to Google, provided you have JavaScript installed in your browser. If you wish to prevent the transmission of data, you can disable JavaScript in your browser settings (usually in the "Privacy" menu). Please note that the search function and other functions of the website may be impaired in this case.

For the further processing of the data by Google, please refer to Google's privacy policy: www.google.com/intl/de_de/policies/privacy.

13. Tracking and Web Analysis Tools

 

13.1 General Information on Tracking

For the purpose of needs-based design and ongoing optimization of our website, we use the web analysis services listed below. In this context, pseudonymized usage profiles are created and cookies are used (see also section  11). The information generated by the cookie about your use of this website is usually transmitted together with the logfile data listed in section  10 to a server of the service provider, stored there, and processed. This may also involve a transfer to servers abroad, e.g., the USA (see particularly the guarantees taken, section  8).

Through the processing of the data, we receive the following information, among others:

  • Navigation path taken by a visitor on the site (including viewed content and selected or purchased products or booked services),
  • Duration of stay on the website or subpage,
  • The subpage from which the website is exited,
  • The country, region, or city from which access occurs,
  • End device (type, version, color depth, resolution, width, and height of the browser window), and
  • Returning or new visitor.

On our behalf, the provider will use this information to evaluate the use of the website, compile reports on website activities for us, and provide further services related to website use and internet use for market research and needs-based design of these internet pages. For these processes, we and the providers may be considered jointly responsible for data protection to a certain extent.

You can withdraw your consent at any time or refuse processing by rejecting or disabling the relevant cookies in your web browser settings (see section  11) or by using the service-specific options described below.

For the further processing of the data by the respective provider as the data protection (sole) responsible party, particularly any potential disclosure of this information to third parties such as authorities due to national legal provisions, please refer to the respective privacy notices of the provider.

13.2 Google Analytics

 We use the web analysis service Google Analytics from Google Ireland Limited (Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland) or Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) ("Google").

In this context, the described data about the use of the website may be transmitted to the servers of Google LLC in the USA for the explained processing purposes (see section  13.1). The IP address is shortened by activating IP anonymization ("anonymizeIP") on this website before transmission within the member states of the European Union or in other contracting states of the agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a server of Google in the USA and shortened there.

Users can prevent the collection of data generated by the cookie and related to the website usage (including the IP address) by Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de. For more information on data protection at Google, see  here.

14. Social Media

 

14.1 Social Media Profiles

 On our website, we have embedded links to our profiles on the social networks of the following providers:

  • Meta Platforms Inc., 1601 S California Ave, Palo Alto, CA 94304, USA;
  • Instagram Inc. 1601 Willow Road, Menlo Park, CA 94025, USA;
  • Linkedin Unlimited Company, Wilton Place, Dublin 2, Ireland.

If you click on the icons of the social networks, you will be automatically redirected to our profile on the respective network. This establishes a direct connection between your browser and the server of the respective social network. As a result, the network receives the information that you have visited our website with your IP address and clicked the link.

If you click on a link to a network while logged into your user account with that network, the content of our website can be linked to your profile, allowing the network to directly associate your visit to our website with your account. If you wish to prevent this, you should log out before clicking the corresponding links. A connection between your access to our website and your user account occurs in any case if you log in to the respective network after clicking the link. The respective provider is responsible for data protection regarding the associated data processing. Please therefore refer to the information on the website of the network.

14.2 Social Media Plugins

 On our website, you can use social plugins from the following providers:

  • Meta Platforms Inc., 1601 S California Ave, Palo Alto, CA 94304, USA, Privacy Policy;
  • Instagram Inc., 1601 Willow Road, Menlo Park, CA 94025, USA, Privacy Policy;
  • Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA, Privacy Policy;
  • Linkedin Unlimited Company, Wilton Place, Dublin 2, Ireland, Privacy Policy.

We use the social plugins to facilitate sharing content from our website. The social plugins help us increase the visibility of our content in social networks and thus contribute to better marketing.

The plugins are disabled by default on our websites and therefore do not send any data to the social networks when merely visiting our website. To enhance data protection, we have integrated the plugins so that a connection to the servers of the networks is not automatically established. Only when you activate the plugins and thereby give your consent to the transmission and further processing of data by the providers of the social networks does your browser establish a direct connection to the servers of the respective social network.

The content of the plugin is transmitted directly from the social network to your browser and integrated into the website. This way, the respective provider receives the information that your browser has accessed the corresponding page of our website, even if you do not have an account with that social network or are not currently logged in. This information (including your IP address) is transmitted directly from your browser to a server of the provider (usually in the USA) and stored there. We have no influence on the extent of the data that the provider collects with the plugin, although we may be considered jointly responsible with the providers from a data protection perspective to a certain extent.

If you are logged into the social network, it can directly associate your visit to our website with your user account. If you interact with the plugins, the corresponding information is also transmitted directly to a server of the provider and stored there. The information (e.g., that you like a product or service from us) may also be published on the social network and displayed to other users of the social network. The provider of the social network may use this information for the purpose of displaying advertisements and tailoring the respective offer to your needs. This may involve creating usage, interest, and relationship profiles, for example, to evaluate your use of our website in relation to the advertisements displayed to you on the social network, inform other users about your activities on our website, and provide further services related to the use of the social network. The purpose and extent of data collection and the further processing and use of the data by the providers of the social networks, as well as your related rights and options for protecting your privacy, can be found directly in the privacy notices of the respective provider.

If you do not want the provider of the social network to associate the data collected about our website with your user account, you must log out of the social network before activating the plugins. You can withdraw your consent at any time by declaring your withdrawal to the provider of the plugin according to the information in its privacy notices.

15. Online Advertising and Targeting

 

15.1 In General

We use services from various companies to present you with interesting offers online. In doing so, your user behavior on our website and the websites of other providers is analyzed to subsequently display online advertisements tailored specifically to you.

Most technologies for tracking your user behavior ("tracking") and for targeted advertisement display ("targeting") work with cookies (see also section  11), which allow your browser to be recognized across different websites. Depending on the service provider, it may also be possible for you to be recognized online even when using different devices (e.g., laptop and smartphone). This may be the case if you have registered with a service that you use across multiple devices.

In addition to the data already mentioned that is generated when accessing websites ("logfile data", see section  10) and when using cookies (section  11), which can be transmitted to the companies involved in the advertising networks, the following data is particularly relevant for selecting the advertisements that may be most relevant to you:

  • Information about you that you provided when registering or using a service from advertising partners (e.g., your gender, age group);
  • User behavior (e.g., search queries, interactions with advertisements, types of websites visited, products or services viewed and purchased, subscribed newsletters).

We and our service providers use this data to determine whether you belong to the target group we are addressing and take this into account when selecting advertisements. For example, after visiting our site, you may see advertisements for the products or services you consulted when visiting other pages ("re-targeting"). Depending on the extent of the data, a user profile may also be created that is evaluated automatically, and the advertisements are selected according to the information stored in the profile, such as belonging to certain demographic segments or potential interests or behaviors. Such advertisements may be presented to you across various channels, including our website or app (as part of onsite and in-app marketing), as well as advertisements delivered through the online advertising networks we use, such as Google.

The data may then be evaluated for the purpose of billing with the service provider and assessing the effectiveness of advertising measures, to better understand the needs of our users and customers and improve future campaigns. This may also include information indicating that a specific action (e.g., visiting certain sections of our websites or submitting information) can be traced back to a specific advertisement. Furthermore, we receive aggregated reports from the service providers regarding advertising activities and information about how users interact with our website and our advertisements.

You can withdraw your consent at any time by rejecting or disabling the relevant cookies in your web browser settings (see section  11). Further options for blocking advertisements can also be found in the information provided by the respective service provider, such as at  Google.

15.2 Google Ads

This website uses the services of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google") for online advertising. Google uses cookies for this purpose, such as the so-called DoubleClick cookie, which allows your browser to be recognized when visiting other websites. The information generated by the cookies about the visit to these websites (including your IP address) is transmitted to a server of Google in the USA and stored there (see also section  8). For more information on data protection at Google, see  here.

You can withdraw your consent at any time by rejecting or disabling the relevant cookies in your web browser settings (see section  11). Further options for blocking advertisements can be found  here.

16. Use of Our Chat Function 

If you contact us via chat, your personal data will be processed. The data processed includes the information you provide, such as your company name, your name, your position, your email address, and your inquiry. Additionally, the time of receipt of the request is documented. Mandatory information is marked with an asterisk (*) in the form.

We process this data solely to address your inquiry (e.g., providing information about our hotel, assisting with contract processing such as questions about your booking, incorporating your feedback into the improvement of our services, etc.). For the provision of the chat function, we use a tool from SuperX GmbH Berlin, Berlin 10178, Germany. Therefore, your data is stored in a database of Superchat, which may allow Superchat to access your data when necessary for providing the software and supporting its use.

17. Registration for a Customer Account

 If you open a customer account on our website, we collect the following data, with mandatory information marked with an asterisk (*) in the corresponding form:

  • Personal details:
    • Salutation
    • Last name
    • First name
    • Billing and delivery address
    • Date of birth
    • Company, company address, and UID number for corporate customers
  • Login data:
    • Email address
    • Password
  • Additional information:
    • Languages
    • Gender

We use the personal details to verify your identity and check the requirements for registration. The email address and password serve together as login data and thus ensure that the correct person uses the website under your details. We also need your email address for verification and confirmation of the account opening and for future communication necessary for contract processing with you. Furthermore, this data is stored in the customer account for future bookings or contract conclusions. For this purpose, we also allow you to store additional information in the account (e.g., your preferred payment method).

We also use the data to provide an overview of the ordered products and made bookings (see particularly section  Error! Reference source not found.  and 19) and a simple way to manage your personal data, to administer our website and contractual relationships, i.e., for the establishment, content design, processing, and modification of the contracts concluded with you via your customer account (e.g., in connection with your booking with us).

The information regarding language and gender is processed to display offers tailored as best as possible to your profile or personal needs on the website, for statistical recording and evaluation of the selected offers, and thus to optimize our proposals and offers.

To prevent misuse, you must always treat your login data confidentially and should close the browser window when you have finished communicating with us, especially if you share the computer with others.

18. Ordering via Our Online Shop

 On our website, you have the opportunity to order a wide selection of products and vouchers. For this, we collect the following data, with mandatory information marked with an asterisk (*) in the corresponding form:

  • Salutation
  • First name
  • Last name
  • Company
  • Street and house number
  • Address addition
  • Postal code
  • City
  • Country
  • Phone number
  • Email
  • Payment method
  • Shipping method
  • Yes, I would like your newsletter
  • I confirm the accuracy of the information provided and have read and accept the terms and conditions and the privacy policy

We use this data, as well as any additional data you voluntarily provide, solely to fulfill your order according to your wishes.

19. Booking on the Website, by Correspondence, or by Phone Call

 If you make bookings or order vouchers either through our website, via correspondence (email or postal mail), or by phone call, we collect the following data, with mandatory information marked with an asterisk (*) in the corresponding form:

  • Salutation
  • First name
  • Last name
  • Street and
  • Postal code
  • City
  • Country
  • Date of birth
  • Email address
  • Phone number
  • Language
  • Credit card information

This data, as well as any additional information you voluntarily provide (e.g., expected arrival time, vehicle registration number, preferences, comments), will only be used to process the contract unless otherwise stated in this privacy policy or you have separately consented to this. We will specifically process the data to record your booking as requested, provide the booked services, contact you in case of ambiguities or problems, and ensure correct payment. Your credit card data will be automatically deleted after your departure from us.

20. Online Payment Processing

 If you make paid bookings or purchase products on our website, depending on the product or service and the desired payment method, in addition to the information mentioned in section  Error! Reference source not found.  or section 19, the provision of additional data may be required, such as your credit card information or login with your payment service provider. This information, as well as the fact that you have purchased a service from us for the respective amount and time, will be forwarded to the respective payment service providers (e.g., providers of payment solutions, credit card issuers, and credit card acquirers). Please always pay attention to the information of the respective company, particularly the privacy policy and the general terms and conditions.

21. Reserving a Table

 On our website, you have the opportunity to reserve a table at one of the restaurants listed on our website. For this, we collect the following data, with mandatory information marked with an asterisk (*) in the corresponding form:

  • First name
  • Last name
  • Number of guests
  • Email address
  • Phone number
  • Comment
  • Date and time of the reservation
  • I accept the terms and conditions
  • I would like to receive information about special promotions and offers

We collect and process the data solely for the purpose of processing the reservation, particularly to compile your reservation request according to your wishes, make the reservation, and contact you in case of ambiguities or problems.

For processing reservations, we use a tool from ALENO. Therefore, your data is stored in a database of ALENO, which may allow ALENO to access your data when necessary for providing the software and supporting its use. Information about the disclosure and processing of data by third parties can be found in section  7 of this privacy policy.

22. Bookings via Booking Platforms

 If you make bookings through a third-party platform (i.e., via booking.com, Hotel, Escapio, Expedia, Holidaycheck, Hotel Tonight, HRS, Kayak, Mr. & Mrs. Smith, Splendia, Tablet Hotels, Tripadvisor, Trivago, Weekend4Two), we receive various personal information related to the booking from the respective platform operator. This usually includes the data listed in section  19 of this privacy policy. Additionally, inquiries regarding your booking may be forwarded to us. We will specifically process this data to record your booking as requested and provide the booked services.

Finally, we may be informed by the platform operators about disputes related to a booking. In this case, we may also receive data regarding the booking process, including a copy of the booking confirmation as proof of the actual booking completion. We process this data to protect and enforce our claims.

Please also refer to the privacy notices of the respective booking platform.

23. Submitting Reviews

 To assist other users in their purchasing decisions and to support our quality management (particularly the processing of negative feedback), you have the opportunity to review your stay with us on our website. The data you provide, i.e., in addition to your review and its timing, possibly also a comment you attached to your review, or the name you provided, will be processed and published on the website.

We reserve the right to delete unlawful reviews and to contact you in case of suspicion and request your statement.

24. Application for a Job Opening

 You have the opportunity to apply to us spontaneously or via a specific email address for a specific job advertisement. For this, we collect the following data, with mandatory information marked with an asterisk (*) in the corresponding form:

  • First name
  • Last name
  • Email address
  • Application documents (e.g., CV, cover letter, certificates)

We use this and other data you voluntarily provide to review your application. Application documents from unsuccessful candidates will be deleted after the application process unless you explicitly agree to a longer retention period or we are legally obligated to retain them longer.

C. Data Processing in Connection with Your Stay

 

25. Data Processing to Fulfill Legal Reporting Obligations

 Upon arrival at our hotel, we may require the following information from you and your companions (mandatory *):

  • First and last name
  • Postal address and canton
  • Date of birth
  • Nationality
  • Official identification document and number
  • Date of arrival and departure

We collect this information to fulfill legal reporting obligations, which arise particularly from hospitality or police law. If we are obligated to do so under applicable regulations, we will forward this information to the competent police authority.

26. Recording of Services Used

 If you use additional services during your stay (e.g., wellness, restaurant, activities), we will record the service item and the time of service use for billing purposes.

27. Guest Feedback

If you provided us with your email address in connection with your booking, you will receive an electronic form after your departure. For this, we collect the following data, with mandatory information marked with an asterisk (*) in the corresponding form:

  • First and last name
  • Age
  • Nationality
  • Duration of stay

The information is voluntary and serves to continuously improve our offerings and services and adapt them to your needs. The information provided to us will be used exclusively for statistical purposes unless otherwise stated in this privacy policy or you have separately consented to this. We will specifically process the data to contact you in case of ambiguities.

28. Video Surveillance

 To prevent misuse and to take action against unlawful behavior (particularly theft and property damage), the entrance area and publicly accessible areas of our hotel are monitored by cameras. Review of the image data occurs only if there is suspicion of unlawful behavior. Otherwise, the recordings will be automatically deleted after 72 hours.

For the provision of the video surveillance system, we rely on a service provider who may have access to the data if necessary for providing the system. Should suspicion of unlawful behavior arise, the data may then be disclosed to the necessary extent for enforcing claims or reporting to consulting firms (particularly our law firm) and authorities.

29. Use of Our WiFi Network

 In our hotel, you have the opportunity to use the WiFi network operated by Hotel Vitznauerhof free of charge. To prevent misuse and to take action against unlawful behavior, prior registration is required. In doing so, you will provide the following data to Hotel Vitznauerhof:

  • Mobile phone number
  • MAC address of the device (automatically)

In addition to the above data, data regarding the hotel visited, along with time, date, and device, will be recorded with each use of the WiFi network. The customer can revoke their registration at any time by notifying us.

Hotel Vitznauerhof must comply with the legal obligations of the Federal Act on the Surveillance of Post and Telecommunications (BÜPF) and the associated ordinance. If the legal requirements are met, the operator of the WiFi must monitor internet usage or data traffic on behalf of the competent authority. The operator of the WiFi may also be required to disclose the contact, usage, and ancillary data of the customer to the authorized authorities. The contact, usage, and ancillary data will be stored for 6 months in a personally identifiable manner and then deleted.

30. Payment Processing

 If you purchase products or services in our hotel using electronic payment methods or pay for your stay, the processing of personal data is required. By using the payment terminals, you transmit the information stored in your payment method, such as the name of the cardholder and the card number, to the involved payment service providers (e.g., providers of payment solutions, credit card issuers, and credit card acquirers). They also receive the information that the payment method was used in our hotel, the amount, and the time of the transaction. Conversely, we only receive the credit of the amount of the payment made at the corresponding time, which we can assign to the respective receipt number, or information that the transaction was not possible or was canceled. Please always pay attention to the information of the respective company, particularly the privacy policy and the general terms and conditions.

31. Privacy Policy of heyteo AG

Use of Virtual Concierge

If you provide us with your mobile number in connection with your booking and you already use the communication platform "WhatsApp", we may contact you via WhatsApp and ask if you would like to communicate with our virtual concierge "Teo". Consent to the use of our virtual concierge is voluntary. Of course, our staff is also personally available for all your concerns.

The virtual concierge Teo is intended to assist you with questions and concerns from the moment you book a service with us, provide you with tailored suggestions and offers based on your interests and needs, and evaluate your feedback.

Our virtual concierge creates a profile of you, which is processed and enriched using artificial intelligence. Your communication with the virtual concierge and its responses are recorded, processed, and linked with existing or future datasets, allowing you to decide which data you want to share with us. We process the following personal data for the virtual concierge:

  • First and last name
  • Address
  • Phone number
  • Language
  • Date of birth
  • Check-in date and check-out date
  • Booked room category
  • Booked extras
  • Questions asked and feedback provided
  • Analytics, meta, and connection data

We are responsible for this personal data and transmit it for processing to heyteo AG. heyteo AG qualifies as a processor in the sense of Art. 5 lit. k DSG or Art. 4 No. 8 GDPR and processes this personal data on our behalf. We have concluded a data processing agreement with heyteo AG to ensure that your personal data is processed in compliance with the law.

However, heyteo AG cannot offer the virtual concierge without involving other companies. For this purpose, your personal data will also be transferred abroad in compliance with legal provisions, whereby heyteo AG has concluded data processing agreements with these subprocessors and has taken appropriate protective measures when transferring personal data to countries without an adequate level of data protection (including the USA).

In addition to the purpose of providing the virtual concierge service as described above, your personal data will also be used by the following companies as responsible parties for the purposes stated in the privacy policies of the respective companies. Your personal data will primarily be used for security, analysis, maintenance, support, and improvement of the systems used. Detailed information about the companies, the affected personal data, and their purposes can be found here:

You have the right to request information about your personal data or its deletion at any time. You can also withdraw your consent to the use of your personal data for the virtual concierge at any time or refuse processing. Please contact our data protection officer for this.