Information about cookies and data protection
Thank you for your interest in our website hotel-kitzhof.com (‘website’). The website and the app are operated by Hotel Kitzhof GmbH (‘Hotel Kitzhof’) and offer you, the user (‘user’), the option of learning about the room offerings and the various hotel locations , booking a room if you are interested and there is a vacancy, and contacting us if you have questions.
We take the protection of your personal data seriously and abide by the provisions of data protection laws and other relevant data protection requirements. In the sections below we tell you, as a user of our website, how we handle your data and provide you with an overview of the measures we have implemented to protect personal data.
You may revoke any consent you have granted at any time with future effect. If you have any questions regarding our use of your personal data, please contact us.
In addition, you can see our data protection information here:
1. Controller and scope
The controller pursuant to the EU General Data Protection Regulation (‘GDPR’) and other national data protection laws of member states as well as other data protection provisions is:
Hotel Kitzhof GmbH
Tel. +43 5356 632 110
2. Data protection officer
The controller’s external data protection officer is:
Dr Karsten Kinast, LL.M.
KINAST Rechtsanwaltsgesellschaft mbH
Tel.: +49 (0)221 222 183 0
3. Principles of data processing
Personal data refers to all information related to an identified or identifiable natural person. This includes, for example, information such as your name, age, address, telephone number, date of birth, email address, IP address or user behaviour. Information that we cannot use to identify you personally (or that would involve a disproportionate effort to do so), for example, by anonymising the information, does not represent personal data. The processing of personal data (e.g. collecting, accessing, using, storing or transmitting such data) always requires a legal basis or your consent. Personal data that has been processed is deleted as soon as the purpose of the processing has been achieved and there are no further statutory retention obligations.
If we process your personal data in order to provide certain offers, we will subsequently inform you of the specific processes, the scope and the purpose of the data processing activity, the legal basis for the processing activity and the relevant storage period.
4. Individual processing steps
a.) Type and scope of data processing
When you access and use our website, we collect personal data that your browser automatically sends to our server. This information is temporarily saved in a log file. When you use our website, we collect the following information, which we need for technical reasons in order to display our website to you and ensure stability and security:
Every time a user accesses the website or the app and every time a file is accessed, access data related to this action is stored in a log file on our server. This data includes:
- Browser type/version
- Operating system used
- Referring URL (the site previously visited
- Host name of accessing computer (IP adress)
- Time and data of the server request
- Volume of data transmitted and access status (file transmitted, file not found, etc.)
This data is used to generate pseudonymised internal statistics that help us to analyse the use of the website, correct errors and improve our services. It is not used for any other purpose related to you individually. In particular, this data is not merged with other data sources. This data is automatically deleted after the statistical assessment. You can prevent your pseudonymised data being used for statistical purposes at any time by using the corresponding setting in your browser software to prevent cookies from being saved on your computer (see para 9.).
b.) Legal basis
The legal basis of the specified data processing activity is Art. 6 (1f) GDPR. The processing of the specified data is necessary to provide the website and thus serves to safeguard the legitimate interests of our company.
In addition, Hotel Kitzhof generally only collects and uses personal data that the user sends when using the website, for example, when booking a room or using the contact form on the website to make an enquiry.
It is necessary for customers to provide their full name, address and email address when making a reservation and/or booking. This data is required to process the booking. In addition, other information may also be necessary, such as telephone number, company name, tax identification number, account details or credit card details.
c.) Storage period and data deletion
As soon as the specified data is no longer necessary to display the website, it will be deleted. The collection of data to provide the website and the storage of data in log files is necessary for the operation of the website. Consequently, the user does not have the right to object to such use. The data may be stored for longer periods in individual cases if such storage is legally required.
Persons under the age of 18 should not provide us with any personal data without the consent of their parents or guardians. We do not request personal data from children and young people, nor do we collect such data or forward it to third parties.
5. Email correspondence
a.) Evaluation emal following a stay
After staying at Hotel Kitzhof, customers will receive an email asking them to rate their stay and suggest improvements.
The legal basis for the data processing activity carried out in respect of the use of your email address is Art. 6 (1f) GDPR. The processing of email addresses and the collection of evaluations is necessary to ensure the quality of the hotel and to optimise hotel services, and therefore helps to safeguard the legitimate interests of our company. This evaluation e-mail is not used for any other purpose.
As soon as the specified data (email address and evaluation) are no longer required for the specified optimisation purposes, they will immediately be deleted.
When registering for the Hotel Kitzhof newsletter, the user declared his/her consent to regularly receive a newsletter email containing news, campaigns and offers from Hotel Kitzhof. The personal data that Hotel Kitzhof processes to send the newsletter is not disclosed to other companies. Consent regarding use of your email address can be revoked at any time with future effect (email@example.com). In addition, a separate link located at the end of each newsletter can be used to unsubscribe from the newsletter.
You expressly gave the following declaration of consent when you subscribed to the newsletter on our website: https://www.hotel-kitzhof.com/en/newsletter-registration.html and we have logged this consent:
‘I would like to subscribe to the free Hotel Kitzhof newsletter and receive regular news and information about campaigns and offers from Hotel Kitzhof. My email address will not be disclosed to other companies. I can revoke my consent to receive the newsletter with future effect at any time by email firstname.lastname@example.org.’
6. Processing and deletion
Hotel Kitzhof may, of its own initiative or at the request of the user, complete, correct or delete incomplete, erroneous or outdated personal data that Hotel Kitzhof has stored in connection with the operation of this website. If these processes are carried out at the request of the user, Hotel Kitzhof may only do so if the user has sufficiently identified him/herself. Identity is verified using a copy of a photo ID – which will of course be deleted immediately after the authentication has been completed – or using criteria that can only be known by the user. Hotel Kitzhof cannot agree to the user’s request if he/she is not properly identified.
In line with statutory provisions, Hotel Kitzhof deletes personal data immediately upon the user’s request, provided there are no mandatory retention obligations to the contrary.
7. Disclosure of personal data to third parties
a.) Personal data is handled confidentially and in line with the statutory data protection regulations. Data is not disclosed to third parties without the user’s consent, unless doing so is required to carry out orders, process payments or process requests or it is permitted in accordance with the statutory provisions. External service providers are obliged to handle data confidentially and securely, and they may only use the data as required to carry out their duties.
b.) This is particularly true for any payments processed by external service providers as well as the exchange of data with SCHUFA Holding AG, Kormoranweg 5, 65201 Wiesbaden, for the purpose of credit checks if there is a legitimate interest or in the event of non-contractual conduct. SCHUFA Holding AG, Kormoranweg 5, 65201 Wiesbaden, stores and transmits data for credit checks to its contractual partners. The user’s legitimate concerns are taken into account in line with the statutory provisions.
c.) Otherwise, personal data is only disclosed if the user has given his/her express prior consent or if doing so is necessary for the prosecution of criminal offences. Personal data is only transmitted to the authorities or government agencies with the right to receive information if doing so is subject to a statutory obligation to provide information or there has been a court ruling to this effect. Your legitimate concerns are taken into account in line with the statutory data protection provisions. Where necessary, we may disclose your data to third parties on the basis of statutory requirements. We only comply with such requests if we are required to do so in line with statutory obligations.
d.) You may revoke the consent to disclose your data at any time and without the need to provide us with a reason.
8. Protection of data
The protection of personal data is an important corporate principle at Hotel Kitzhof. This is achieved through, among other things, training, a company data protection officer and a written agreement with all employees and external service providers to maintain the confidentiality of data and comply with data protection requirements.
All technical and organisational, physical and computer systems and measures in the area of data protection, IT and information security help to protect stored data from damage, destruction and unauthorised access and to achieve the protection objectives of confidentiality, availability and integrity.
For the sake of security, personal data is collected with the use of an encrypted secure socket layer (SSL) connection (which can be recognised by the use of ‘https://’ at the beginning of the website address in the address bar of the internet browser)
In addition, Hotel Kitzhof takes all reasonable precautions to prevent unauthorised access to users' personal data as well as the unauthorised use or falsification of this data and to minimise the corresponding risks. However, the provision of personal data, whether this is done in person, on the phone or online, always involves risks, and there is no technical system that is completely impervious to manipulation or sabotage.
Most browsers are configured to accept cookies by default. However, you can configure your browser so that it only accepts certain cookies or no cookies at all. Please note, however, that you may not be able to use all of the functions of our website if you deactivate cookies on our website through your browser settings. You can also use your browser settings to delete cookies that have already been stored in your browser or to display the storage period. In addition, you can configure your browser so that you are informed before cookies are saved. As different browsers may vary in terms of their functionality, please see your browser’s help menu for the configuration options.
If you would like a comprehensive overview of all third parties that have access to your internet browser, we recommend that you install a special plug-in for this purpose.
10. Tracking and analysis tools
We use tracking and analysis tools to ensure ongoing optimisation and the need-based design of our website. Tracking also enables us to collect statistics regarding the use of our website, which helps us to enhance our online presence using the resulting findings. Based on these interests, the use of the following tracking and analysis tools is legitimate in accordance with Art. 6 (1f) GDPR.
The following description of tracking and analysis tools also reveals the respective processing purposes and the data processed.
a.) Google Analytics
On behalf of Hotel Kitzhof, Google uses this information to assess your use of the website, to compile reports about website activities and to provide other services related to use of the website and the internet to the website operator. The abbreviated IP address transmitted from your browser as part of the Google Analytics service will not be merged with other Google data. You can prevent cookies from being stored on your device by adjusting the browser settings accordingly; however, if you do this, you may not be able to fully use all of the website’s functions.
You can also prevent the collection of the information generated by the cookie related to your use of the website or app (including your IP address) and the processing of this data by Google by downloading and installing the browser add-on available at the following link: https://tools.google.com/dlpage/gaoptout?hl=en.
Alternatively, you can prevent the collection of data by Google Analytics when you use a mobile device by clicking on the following link. Doing so will save an opt-out cookie that will prevent the future collection of your data when you visit this website: Click here to opt-out of Google Analytics.
Further information about Google Analytics can be found here:
CheckEffect is a tool for successful online-marketing in tourism, developed by tourism experts, according to the requirements within the tourism industry, today. CheckEffect uses so called “cookies”, which are text files placed on your computer to help the website analyse how you use the site. The information generated by the cookie about your use of the website (including IP-address) will be stored on ncm.at company’s server. ncm.at will use this information to evaluate the website’s utilisation. This evaluation will be used in order to give the website’s operator a detailed insight and reports on search keywords, search engines or cost-benefit calculation of certain advertisements, campaigns and paid-for links. CheckEffect compares this data anonymously with websites of similar companies and provides a cross-sectored comparison.
You may refuse the installation of cookies by selecting the appropriate settings on your browser software; however please note that if you do this you may not be able to use the full functionality of this website. By using this website you consent to the processing of data about you by ncm.at, but only in the manner and for the purposes, set out above.
11. Social plug-ins
We use the following plug-ins from Facebook, Instagram. Pinterest and Youtube on our website.
a.) Facebook social plug-ins
The website contains ‘social plug-ins’ (‘plug-ins’) from the social network www.facebook.com, which is operated by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (‘Facebook’). The plug-ins are marked with a Facebook logo or the appendix ‘Facebook Social Plug-in’ (http://developers.facebook.com/plugins). The website contains plug-ins that establish a direct connection between the user’s browser and Facebook’s servers as soon as the user accesses the website. The content of the plug-ins is transmitted directly from Facebook to the user’s browser and integrated into the website by the browser. Motel One has no influence over the scope of the data that Facebook collects with the help of these plug-ins.
As a result of the integration of the plug-ins, Facebook is informed that the user has accessed the corresponding website. If the user is logged into Facebook, Facebook can assign the user to his/her Facebook account. If the user clicks the ‘Like’ button or writes a comment, the corresponding information is transmitted directly from his/her browser to Facebook and stored there.
If the user is a member of Facebook and does not want Facebook to collect data about him/her via Motel One and link it with his/her stored membership data, the user must log out of Facebook before visiting the website. However, even if the user is not logged into Facebook, it is possible that Facebook may learn about and save certain data.
If users want to block Facebook social plug-ins in general, they can install and activate a corresponding extension on their browser, such as ‘Facebook Blocker’ (http://webgraph.com/resources/facebookblocker/).
b.) Instagram social plug-ins
Our website uses social plug-ins (‘plug-ins’) from Instagram, which is operated by Instagram LLC, 1601 Willow Road, Menlo Park, CA 94025, USA (‘Instagram’) The plug-ins are marked with an Instagram logo, e.g. in the form of an ‘Instagram camera’. When the user accesses our website containing such a plug-in, the browser creates a direct connection to Instagram’s servers. The content of the plug-ins is transmitted directly from Instagram to the user’s browser and integrated into the page. As a result of this integration, Instagram is informed when the user has accessed the corresponding page on our website, even if you do not have an Instagram profile or are not logged into Instagram. This information (including your IP address) is transmitted directly from your browser to an Instagram server in the USA and stored there. If the user is logged into Instagram, Instagram can assign the visit to our website to the user’s Instagram account. If the user interacts with the plug-ins, for example by clicking on the Instagram button, this information will also be transmitted directly to an Instagram server and stored there. The information will also be published on your Instagram account and displayed to the user’s contacts there. Motel One has no influence over the scope of the data that Instagram collects with the help of these plug-ins.
c.) Pinterest social plug-ins
Our website uses social plug-ins (‘plug-ins’) from the social network Pinterest, which is operated by Pinterest Inc., 808 Brannan Street, San Francisco, CA 94103, USA (‘Pinterest’). The plug-ins can be seen, for example, on buttons with the ‘Pin it’ icon on a white or red background.[A2] When the user accesses our website containing such a plug-in, the browser creates a direct connection to Pinterest’s servers. The content of the plug-ins is transmitted directly from Pinterest to the user’s browser and integrated into the page. As a result of this integration, Pinterest is informed when the user has accessed the corresponding page on our website, even if you do not have a Pinterest profile or are not logged into Pinterest.
d.) Youtube social plug-ins
This website uses plugins from Youtube.de/Youtube.com that are operated by Youtube, LLC, Cherry Ave, USA, represented by Google Inc.
12. Links to other websites
The website occasionally provides links (interactive references) to third-party websites for which Hotel Kitzhof is not responsible. Hotel Kitzhof has no influence over the content and design of the linked external sites or the websites that the user accesses via these links. The respective providers are solely responsible for the content and design of these websites as well as for compliance with data protection regulations.
13. Rights of data subjects
The GDPR provides you, as the data subject of personal data processing, with the following rights:
•According to Art. 15 GDPR, you can request information from us about your personal data that we process. In particular, you can request information about the purposes of processing, the categories of personal data, the categories of recipients to whom the personal data has been or will be disclosed, the planned storage period, the existence of the right to request correction or deletion of personal data or restriction of processing of personal data or to object to such processing, the right to lodge a complaint, any available information as to its source when personal data is not collected by us, transmission to a third country or to an international organisation, and about the existence of automated decision-making, including profiling and, in such cases, meaningful information about the logic involved.
•According to Art. 16 GDPR, you have the right to request the immediate correction of inaccurate personal data or to have incomplete personal data completed.
•According to Art. 17 GDPR, you can request the deletion of your personal data we have stored if the processing is no longer necessary to exercise the right to freedom of opinion and information, to fulfil a legal obligation, for reasons of public interest or to assert, exercise or defend legal claims.
•According to Art. 18 GDPR, you can request the restriction of the processing of your personal data if the accuracy of the personal data is contested by you, the processing is unlawful, we no longer need the data and you oppose the deletion of the personal data because you need them to assert, exercise or defend legal claims. You also have the rights under Art. 18 GDPR if you have objected to the processing in accordance with Art. 21 GDPR.
•According to Art. 20 GDPR, you can request that your personal data which you have provided to us be given to you in a structured, commonly used and machine-readable format or to have your personal data transmitted to another controller.
•According to Art. 7 (3) GDPR, you can revoke consent which you have granted us at any time. If you do so, we will no longer be able to continue the data processing based on this consent in future.
•According to Art. 77 GDPR, you have the right to lodge a complaint with a supervisory authority. In general, you can contact the supervisory authority in your usual place of residence, your place of work or our corporate domicile for this purpose.
14. Right to object
In the case of the processing of your personal data on the basis of a legitimate interest pursuant to Art. 6 (1f) GDPR, you have the right pursuant to Art. 21 GDPR to object to the processing of your personal data if there are reasons for doing based on your personal situation or if you object to direct marketing. In the case of direct marketing, you have a general right to object which must be adhered to by us without the need to specify a special situation.
15. Data security and security measures
We undertake to protect your privacy and to treat your personal data as confidential. In order to prevent the manipulation, loss or misuse of your data stored with us, we apply comprehensive technical and organisational security measures which are reviewed regularly and which are adapted in line with technical improvements. These include, among other things, the use of recognised encryption methods (SSL or TLS). Please note, however, that because of the structure of the internet it is possible that the data protection regulations and the above-mentioned security measures will not be observed by persons or institutions which are not within our area of responsibility. In particular, data disclosed in an unencrypted manner – e.g. data disclosed by email – may be read by third parties. We have no technical control over this. It is the user’s responsibility to prevent the misuse of the data he/she provides through encryption or another method.
Hotel Kitzhof may change these data protection regulations or the content of the website at any time without prior notice, or it may change or block access to this website.
17. Questions about data protection and contact
Users can contact Hotel Kitzhof at any time if they would like their personal data corrected, blocked or deleted. In addition, Hotel Kitzhof shares information about the user data it has stored as well as the origin and recipients of such data and the purpose for which it has been stored.
For questions about data protection, please contact:
Hotel Kitzhof GmbH
Tel. +43 5356 632 110