Privacy Policy - GDPR
With this data protection declaration we inform you about how we process your personal data. As an affected customer or other individual, we offer you our services (hotel stays, overnight stays, conferences, events, caterings, restaurant and cafe visits, break buffets and related products and services) via our websites, mobile applications, e-mail communication or other means online or offline or make them available to you. This data protection declaration relates to European (GDPR) and Austrian law (DSG).
Responsible according to the GDPR
Is the person responsible within the meaning of the applicable provisions of data protection law
Raphael Zoppoth, Grünwaldweg 20, A-9583 Faak am See, Austria
The following categories of data are processed:
1) In order to fulfill the contract concluded with you, we process:
Customer data - If you contact us, register with us or use our services, we collect general data about you in order to be able to contact you in accordance with your wishes about our offers and in the course of a trip, stay or other service . This information can include your name, e-mail address, telephone numbers, employer and postal address, and if necessary and if necessary also your gender and date of birth.
Guest information - If you book a stay or any other service through us, we collect it directly from you or - if you do not book the stay or the trip yourself - indirectly (via third parties), e.g. through your employer, other intermediary travel agencies, friends and family members or other organizers the details of the trip or stay or other service (such as arrival and departure location and time, airline, hotel, car rental) and other data required to complete your bookings. We may also collect special categories of data in order to provide accessibility, meal requests or other requested services. You can provide additional information on your guest profile, including credentials for loyalty programs, government identification numbers, and emergency contact information.
Payment information - so that you can pay for your bookings and other transactions through our services, we collect information about payment cards or other information that is required to process payments.
2) Due to our legitimate interest in sending you personalized advertising and being able to compile statistics on user behavior during your stay on our website, we process:
Device data - We collect data about how you use our services, including the IP address of your computer and data that can be determined from it (such as the internet provider and general geographic location), the unique device number and other technical information. We also collect information about how you use our websites and mobile applications. We collect some of this data through the use of cookies and similar technologies, as described here.
Duration of the processing of your data:
In any case, your data will be stored for as long as and to the extent required by the contractual basis. After termination of the contract, your data will be stored for a maximum of 7 years in accordance with the accounting obligations imposed on us. In addition, your data will be stored under the following conditions:
- on the basis of our legitimate interest until we receive a justified objection from you, or
- on the basis of your express consent until you revoke this consent.
Your data will be processed for the following purposes:
To provide our offer and our services - We use your data for the provision of tourist and gastronomic services, in particular overnight stays, the organization of meetings and events, for notifications to you regarding your stay or our products and services, for the provision of customer service and for Manage your account.
Operation of mobile applications (APPs), websites and electronic communication - We use device data
- for the security of electronic services,
- to optimize the provision and content of our services,
- for updates,
- for non-personal trend and usage analyzes in connection with our services and
- to determine the effectiveness of our advertisements and offers.
Business operations and business process improvement - We use personal data to comply with our company policies and business processes, for accounting and commercial purposes, to detect or prevent fraudulent or criminal activities, for business operations, to analyze and improve our services and otherwise as required by law.
Marketing & improving our service for you
We use your data in your and our legitimate interests to optimize our services and for future performance. This includes:
- Pre-filling of forms and payment details
- Use of contact details
- for the transmission of service changes
- to contact you in emergencies
- to obtain feedback on the services provided
- for sending information about our products and services electronically and by post
If you do not agree to the storage or use of your data, we ask for appropriate information.
Passing on your data to third parties:
In principle, we do not transmit your data to third parties, either free of charge or against payment, without your consent. This does not apply to transmissions that we carry out on the basis of a legal or contractual obligation or on the basis of our mutual interests mentioned above:
Service partners - We only pass on data to service providers to the extent necessary for the provision of their services, such as meeting and event planners, restaurants, mobile applications and software developers, as well as partners who provide IT support, data hosting, marketing and communication systems and provide debt collection services.
Affiliated companies - We pass on data within our group of companies to the extent permitted by law in order to be able to provide, analyze and optimize their and our products and services.
Courts, authorities and banks - We may pass on data to supervisory authorities, courts, banks and state authorities if we consider this to be absolutely necessary or permissible due to laws or regulations or in the context of legal proceedings.
Business transfer - should we negotiate or conclude a transaction that affects our company in whole or in part (e.g. restructuring, merger, sale or acquisition), data may be passed on to third parties who are involved in this transaction, to the extent permitted by law.
Google Analytics
Our online services use Google Analytics, a web analysis service from Google, Inc. ("Google"). Google Analytics uses so-called cookies, ie text files that are stored on your computer and that enable your use of the website to be analyzed. The information generated by the cookie about your use of this website (including your IP address) is usually transmitted to a Google server in the USA and stored there. On behalf of the operator, Google will use this information to evaluate your use of the website, to compile reports on website activity for the website operator and to provide other services relating to website activity and internet usage. Google may also transfer this information to third parties if this is required by law or if third parties process this data on behalf of Google. Under no circumstances will Google associate your IP address with other Google data. You can prevent the installation of cookies by setting your browser software accordingly; however, we would like to point out that in this case you may not be able to use all functions of this website to their full extent. By using this website, you declare that you agree to the processing of the data collected about you by Google in the manner described above and for the purpose stated above.
For newsletter subscribers: Users who no longer want to receive our newsletter, click a link called Unsubscribe, which is included in all newsletter emails we send.
You have the following rights:
you have the right
- to request confirmation as to whether personal data relating to you are being processed and subsequently the right to receive free information about the personal data stored about you and a copy of this information;
- to revoke the consent to the processing of personal data without affecting the legality of the processing carried out on the basis of the consent until the revocation;
- to request the correction of incorrect personal data concerning you or, if necessary, that your data be deleted immediately, provided that there is no longer a legal reason on our part to store the data concerned;
- to request the restriction of processing;
- To receive the personal data you have provided yourself in a structured, common and machine-readable format and to transmit this data to another person responsible (without our obstruction);
- to have your data transmitted directly from us to another person responsible, as far as this is technically feasible and provided that this does not affect the rights and freedoms of other people;
- In the event of unlawful behavior on our part, the opportunity to lodge a complaint with the Austrian data protection authority.
The protection of your data is important to us!
Appropriate organizational, technical and physical security measures are taken to protect your data from unauthorized access and use. We only store your data for as long as this is necessary for the provision of our services and for legitimate operational purposes (principle of data minimization), unless we are required by laws or regulations or due to legal disputes and official investigations to do so to save a longer period of time.
Technical and organizational measures for data security
We undertake to take appropriate technical and organizational measures both at the time of determining the means for processing and at the time of the actual processing of your personal data - such as. B. tokenization, which are designed to implement data protection effectively and to include the necessary guarantees in the processing in order to meet the requirements of data protection law and to protect your data.
To this end, we take suitable measures to ensure that, by default, only those personal data relating to your person, the processing of which is necessary for the respective specific processing purpose, are processed, and thus above all to ensure that your data is not processed by default without your intervention made available to an indefinite number of natural persons. These measures include, among other things, the pseudonymization and encryption of your data, as well as the ability to ensure the confidentiality, integrity, availability and resilience of the systems and services in connection with the processing in the long term, the ability, the availability of personal data and access to quickly restore them in the event of a physical or technical incident, as well as the regular review, assessment and evaluation of the effectiveness of the technical and organizational measures to ensure the security of the processing.
Special data security measures
Secure Socket Layer (SSL)
All booking forms with which you send us personal information use an encrypted transmission method (SSL) to protect your data. You can see whether you are on a safe page by the fact that the address line (the URL) begins with "https: //" instead of the usual "http: //", as well as by the display of special symbols in the status line ( usually at the bottom of the window) the browser: Internet Explorer, Firefox, Chrome, Safari
The encryption takes place between the server and client (i.e. your computer) in the form of a secure connection via which any data can be transmitted.
Certificates are required for SSL to guarantee secure transmission so that you can be sure where the server is located and who is operating this server.
SSL Certificate Authority: Our secure servers have been certified by the Comodo Group.
ask
If you have any questions or complaints about the processing of your data, please contact us at:
TINY HOMES Villach Faaker See
Grünwaldweg 20
A-9583 Faak am See
office @ tinyhomes. at
We will examine your request and respond in writing within the statutory period.
Online dispute resolution platform
You can find the EU Commission's online dispute resolution platform under the following link: ec.europa.eu/consumers/odr
For the sake of easier readability, we have drawn up our data protection declaration in female or male form. Therefore, if a designation was made only in female or male form, both genders are recorded.