A. Overarching information
In order for you to know what personal data we collect from you and for what purposes we use it, please take note of the information below. When it comes to data protection, we are primarily guided by the legal requirements of Swiss data protection law, in particular the Federal Data Protection Act (FADP), as well as the EU GDPR, the provisions of which may be applicable in individual cases.
2. Contact person for data protection
If you have any questions about data protection or would like to exercise your rights, please contact our contact person for data protection by sending an e-mail to the following address: email@example.com
3. Your rights
If the legal requirements are met, you have the following rights as a person affected by data processing:
Right to information: You have the right to request access to your personal data stored by us at any time and free of charge if we process it. This gives you the opportunity to check which personal data we process about you and that we use it in accordance with applicable data protection regulations.
Right to rectification: You have the right to have inaccurate or incomplete personal data rectified and to be informed of the rectification. In this case, we will inform the recipients of the data concerned about the adjustments made, unless this is impossible or involves disproportionate effort.
Right to erasure: You have the right to have your personal data erased under certain circumstances. In individual cases, in particular in the case of statutory retention obligations, the right to deletion may be excluded. In this case, if the conditions are met, the deletion may be replaced by a blocking of the data.
Right to restriction of processing: You have the right to request that the processing of your personal data be restricted.
Right to data portability: You have the right to receive from us the personal data you have provided to us free of charge in a readable format.
Right to object: You can object to data processing at any time, in particular for data processing in connection with direct advertising (e.g. advertising e-mails).
Right of revocation: In principle, you have the right to revoke your consent at any time. However, processing activities based on your consent in the past do not become unlawful as a result of your revocation.
To exercise these rights, please send us an e-mail to the following address: firstname.lastname@example.org
Right to lodge a complaint: You have the right to lodge a complaint with a competent supervisory authority, e.g. against the way in which your personal data is processed.
4. Data security
We use appropriate technical and organizational security measures to protect your personal data stored by us against loss and unlawful processing, namely unauthorized access by third parties. Our employees and the service companies commissioned by us are obliged by us to maintain confidentiality and to protect data protection. In addition, these persons are granted access to the personal data only to the extent necessary to perform their duties.
Our security measures are continuously adapted in line with technological developments. However, the transmission of information via the Internet and electronic means of communication always involves certain security risks, and we cannot guarantee the security of information transmitted in this way.
5. Contacting Us
If you contact us via our contact addresses and channels (e.g. by e-mail, telephone or contact form), your personal data will be processed. The data that you have provided to us, e.g. the name of your company, your name, your function, your e-mail address or telephone number and your request, will be processed. In addition, the time of receipt of the request is documented. Mandatory information is marked with an asterisk (*) in contact forms.
We process this data exclusively in order to implement your request (e.g. Questions about your booking, incorporating your feedback into improving our service, etc.).
6. Use of your data for marketing purposes
6.1 Central data storage and analysis in the CRM system
Store and link surfing behaviour on our websites in a central database. This serves the efficient management of customer data and allows us to answer your concerns adequately, and enables the efficient provision of the services you require and the processing of the associated contracts.
We evaluate this data in order to further develop our offers in line with your needs and to display and suggest information and offers that are as relevant as possible. We also use methods that predict possible interests and future orders based on your use of the website.
6.2 E-mail marketing and newsletters
If you register for our e-mail newsletter (e.g. when opening or within your customer account), the following data will be collected. Mandatory information is marked with an asterisk (*) in the registration form:
- E-mail address
- First and last name
In order to avoid misuse and to ensure that the owner of an e-mail address has actually given her own consent, we rely on the so-called double opt-in for registration. After submitting the registration, you will receive an e-mail from us containing a confirmation link.
In order to definitely subscribe to the newsletter, you must click on this link. If you do not click on the confirmation link within the specified period, your data will be deleted and our newsletter will not be delivered to this address.
By registering, you consent to the processing of this data in order to receive news from us about our hotel as well as related information about products and services. This may also include invitations to participate in competitions or to evaluate one of the aforementioned products and services. The collection of the salutation and name allows us to verify the assignment of the registration to a possibly already existing customer account and to personalize the content of the e-mails. Linking to a customer account helps us to make the offers and content contained in the newsletter more relevant to you and to better tailor them to your potential needs.
We use your data for sending e-mails until you revoke your consent. You can revoke your consent at any time, in particular via the unsubscribe link in all our marketing e-mails.
Our marketing e-mails may contain a so-called web beacon or 1×1 pixel (tracking pixel) or similar technical aids. A web beacon is an invisible graphic that is linked to the user ID of the respective newsletter subscriber. For each marketing email sent, we receive information about which addresses have not yet received the email, to which addresses it has been sent, and which addresses have failed to send. It also shows which addresses opened the email, for how long, and which links they clicked on. Finally, we also receive information about which addresses have unsubscribed. We use this data for statistical purposes and to optimize the advertising e-mails in terms of frequency, time, structure and content of the e-mails.
In this way, we can better tailor the information and offers in our e-mails to the individual interests of the recipients.
The web beacon will be deleted when you delete the email. To prevent the use of the web beacon in our marketing e-mails, please set the parameters of your e-mail program so that HTML is not displayed in messages if this is not already the case by default. Refer to the help sections of your e-mail software for information on how to configure this setting, e.g.
- he for Microsoft
By subscribing to the newsletter, you also consent to the statistical evaluation of user behavior for the purpose of optimizing and adapting the newsletter.
We use the email marketing software Mailchimp from The Rocket Science Group LLC d/b/a Mailchimp for marketing emails. Therefore, your data is stored in a database of Mailchimp, which allows Mailchimp to access your data if this is necessary for the provision of the software and to support the use of the software.
7. Disclosure to third parties and access by third parties
Without the support of other companies, we would not be able to provide our services in the desired form. In order for us to be able to use the services of these companies, it is also necessary to pass on your personal data to a certain extent. Such disclosure takes place insofar as this is necessary for the fulfilment of the contract you have requested, i.e. e.g. to restaurants or other third-party providers for whom you have made a reservation.
In addition, your data may be passed on, in particular to authorities, legal advisors or debt collection agencies, if we are legally obliged to do so or if this is necessary to protect our rights, in particular to enforce claims arising from the relationship with you. Data may also be disclosed if another company intends to acquire our business or parts of it and such disclosure is necessary to conduct a due diligence or to consummate the transaction.
8. Transfer of personal data abroad
We are also entitled to transfer your personal data to third parties abroad if this is necessary to carry out the data processing mentioned in this data protection declaration (see esp. Sections 12-15). Of course, the legal regulations for the disclosure of personal data to third parties are complied with. If the country in question does not have an adequate level of data protection, we guarantee through contractual arrangements that your data is adequately protected by these companies.
9. Retention periods
We only store personal data for as long as it is necessary to carry out the processing explained in this data protection declaration within the scope of our legitimate interest. In the case of contract data, storage is required by statutory retention obligations. Requirements that oblige us to store data result from the provisions on accounting and tax law. According to these regulations, business communication, concluded contracts and accounting documents must be kept for up to 10 years. If we no longer need this data to perform the services for you, the data will be blocked. This means that the data may only be used if this is necessary to fulfil the retention obligations or to defend and enforce our legal interests. The data will be deleted as soon as there is no longer any obligation to retain it and there is no longer a legitimate interest in storing it.
B. Special notes for our website
10. Log file data
When you visit our website, the servers of our hosting provider temporarily store each access in a log file. The following data is collected without any action on your part and stored by us until it is automatically deleted:
- the IP address of the requesting computer,
- the date and time of access,
- the name and URL of the retrieved file,
- the website from which the access was made, with the search term used,
- the operating system of your computer and the browser you are using (including type, version and language setting),
- type of device in case of access by mobile phones,
- the city or region from which the access was made,
- the name of your Internet access
The collection and processing of this data is carried out for the purpose of enabling the use of our website (connection establishment), to ensure system security and stability in the long term, as well as for error and performance analysis and enables us to optimize our website (see also section 13 for the last points).
In the event of an attack on the network infrastructure of the website or in the event of suspicion of other unauthorized or abusive use of the website, the IP address and other data will be evaluated for clarification and defense and, if necessary, used in criminal proceedings for identification and civil and criminal action against the users concerned.
Cookies are information files that your web browser stores on your computer’s hard drive or memory when you visit our website. Cookies are assigned identification numbers that identify your browser and can be used to read the information contained in the cookie.
You may also be able to configure your browser so that no cookies are stored on your computer or so that a message always appears when you receive a new cookie. On the following pages you will find explanations on how to configure the processing of cookies in selected browsers.
Disabling cookies may result in you not being able to use all the functions of our website.
12. Google SiteSearch / Google Custom Search Engine
This website uses the Google SiteSearch/Google Custom Search Engine of Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). This enables us to provide you with an efficient search function on our website.
13. Tracking and web analysis tools
13.1 General information on tracking
For the purpose of needs-based design and continuous optimization of our website, we use the web analysis services listed below. In this context, pseudonymised user profiles are created and cookies are used (see also section 11). The information generated by the website about your use of this website is usually transmitted together with the log file data listed under section 10 to a server of the service provider, where it is stored and processed. this may also result in a transfer to servers abroad, e.g. the USA (cf. in particular, on the guarantees taken, Section 8).
By processing the data, we receive the following information, among others:
- navigation path that a visitor takes on the site (including content viewed and products or services selected or purchased),
- time spent on the website or subpage,
- the subpage on which the website is left,
- the country, region or city from which access is made,
- Device (type, version, color depth, resolution, width and height of the browser window) and
- Returning or new visitor.
On our behalf, the provider will use this information to evaluate the use of the website, to compile reports on website activity for us and to provide other services related to website activity and internet usage for the purposes of market research and needs-based design of these websites. For this processing, we and the providers may be considered joint controllers under data protection law to a certain extent.
You can revoke your consent or refuse processing at any time by rejecting or switching off the relevant cookies in the settings of your web browser (see section 11) or by making use of the service-specific options described below.
For the further processing of the data by the respective provider as the (sole) responsible party under data protection law, in particular any disclosure of this information to third parties such as authorities on the basis of national legal regulations, please note the respective data protection information of the provider.
13.2 Google Analytics
We use the web analysis service Google Analytics provided by Google Ireland Limited (Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland) or Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) (“Google”).
The described data about the use of the website may be transmitted to the servers of Google LLC. in the USA for the processing purposes explained (see section 13.1). The IP address is shortened by activating IP anonymization (“anonymizeIP”) on this website before it is transmitted within the member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there.
Users can prevent the collection of data generated by the cookie and related to the use of the website by the user concerned (including the IP address) to Google and the processing of this data by Google by downloading and installing the browser plug-in under the following link: http://tools.google.com/dlpage/gaoptout?hl=de. Further information on data protection at Google can be found here.
14. Social Media
14.1 Social Media Profiles
On our website we have included links to our profiles in the social networks of the following providers:
- Meta Platforms Inc., 1601 S California Ave, Palo Alto, CA 94304, USA;
- Instagram Inc. 1601 Willow Road, Menlo Park, CA 94025, USA;
- Linkedin Unlimited Company, Wilton Place, Dublin 2, Ireland.
If you click on the icons of the social networks, you will be automatically redirected to our profile in the respective network. A direct connection is established between your browser and the server of the respective social network. As a result, the network receives the information that you have visited our website with your IP address and clicked on the link.
If you click on a link to a network while you are logged into your user account with the network in question, the content of our website can be linked to your profile so that the network can assign your visit to our website directly to your account. If you want to prevent this, you should log out before clicking on the corresponding links. In any case, a connection between your access to our website and your user account takes place when you log in to the respective network after clicking on the link. The respective provider is responsible for the associated data processing under data protection law. Therefore, please refer to the information on the network’s website.
14.2 Social media plugins
On our website you can use social plugins of the following providers:
- Meta Platforms Inc., 1601 S California Ave, Palo Alto, CA 94304, USA, Privacy Notice;
- Linkedin Unlimited Company, Wilton Place, Dublin 2, Ireland, Privacy Notice.
We use the social plugins to make it easier for you to share content from our website. The social plugins help us to increase the perceptibility of our content in the social networks and thus contribute to better marketing.
The plugins are deactivated by default on our websites and therefore do not send any data to the social networks when our website is simply accessed. To increase data protection, we have integrated the plugins in such a way that a connection to the servers of the networks is not automatically established. Only when you activate the plugins and thus give your consent to the transmission and further processing of data by the providers of the social networks does your browser establish a direct connection to the servers of the respective social network.
The content of the plugin is transmitted directly from the social network to your browser, which integrates it into the website. As a result, the respective provider receives the information that your browser has accessed the corresponding page of our website, even if you do not have an account with this social network or are not currently logged in to it. This information (including your IP address) is transmitted directly from your browser to a server of the provider (usually in the USA) and stored there. We have no influence on the scope of the data that the provider collects with the plugin, although from a data protection point of view we can be regarded as jointly responsible with the providers to a certain extent.
If you are logged in to the social network, it can assign your visit to our website directly to your user account. If you interact with the plugins, the corresponding information is also transmitted directly to a server of the provider and stored there. The information (e.g. that you like a product or service from us) may also be published on the social network and may be displayed to other users of the social network. The provider of the social network may use this information for the purpose of placing advertising and tailoring the respective offer to the needs of the customer. For this purpose, usage, interest and relationship profiles could be created, e.g. to evaluate your use of our website with regard to the advertisements displayed to you on the social network, to inform other users about your activities on our website and to provide other services related to the use of the social network. The purpose and scope of the data collection and the further processing and use of the data by the providers of the social networks as well as your rights in this regard and setting options for the protection of your privacy can be found directly in the data protection information of the respective provider.
15. Online Advertising and Targeting
15.1 In general
We use the services of various companies to provide you with interesting offers online. In doing so, your user behaviour on our website and websites of other providers is analysed in order to be able to show you online advertising that is individually tailored to you.
Most technologies for tracking your user behavior (“tracking”) and for the targeted display of advertising (“targeting”) work with cookies (see also section 11), which can be used to recognize your browser across different websites. Depending on the service provider, it may also be possible for you to be recognized online even when using different end devices (e.g. laptop and smartphone). This can be e.g. this may be the case if you have registered with a service that you use with multiple devices.
In addition to the data already mentioned, which is generated when websites are accessed (“log file data”, see section 10) and when cookies are used (section 11) and which may be transferred to the companies involved in the advertising networks, the following data in particular is included in the selection of the potentially most relevant advertising for you:
- Personal information that you have provided when registering or using a service provided by advertising partners (e.g. your gender, age group);
- User behaviour (e.g. search queries, interactions with advertising, types of websites visited, products or services viewed and purchased, newsletters subscribed to).
We and our service providers use this data to determine whether you belong to the target group we are addressing and take this into account when selecting advertisements. For example,
After you have visited our site, you will be shown advertisements of the products or services you have purchased (“re-targeting”) when you visit other pages. Depending on the scope of the data, a profile of a user may also be created, which is automatically evaluated, and the advertisements are selected according to the information stored in the profile, such as belonging to certain demographic segments or potential interests or behavior. Such advertisements may be presented to you on various channels, including not only our website or app (as part of on-site and in-app marketing) but also advertisements that are mediated via the online advertising networks we use, such as Google.
The data can then be evaluated for the purpose of billing the service provider and to assess the effectiveness of advertising measures in order to better understand the needs of our users and customers and to improve future campaigns. This may also include the information that the performance of an action (e.g. visiting certain sections of our websites or sending information) is due to a specific advertisement. We also receive aggregated reports of ad activity and information about how users interact with our website and ads from the service providers.
You can revoke your consent at any time by rejecting or switching off the relevant cookies in the settings of your web browser (see section 11). You can also find further options for blocking advertising in the information provided by the respective service provider, such as Google.
15.2 Google Ads
16. Use of our chat function
If you contact us via chat, your personal data will be processed. The data that you have provided to us will be processed, e.g. the name of your company, your name, your function, your e-mail address and your request. In addition, the time of receipt of the request is documented. Mandatory fields are marked with an asterisk (*).
We process this data exclusively in order to implement your request (e.g. Questions about your booking, incorporating your feedback into improving our service, etc.). To provide the chat function, we use a tool from SuperX GmbH Berlin, Berlin 10178, Germany. Therefore, your data is stored in a database of Superchat, which may allow Superchat to access your data if this is necessary for the provision of the software and for assistance in the use of the software.
17. Registration for a customer account
If you open a customer account on our website, we collect the following data, whereby mandatory information is marked with an asterisk (*) in the corresponding form:
- Billing and delivery address
- Company, company address and VAT number. for corporate customers
- Login data:
- E-mail address
- Further information:
We use the personal data to determine your identity and to check the requirements for registration. The e-mail address and password serve together as login data and thus to ensure that the right person under your details is using the website. We also need your e-mail address to verify and confirm the opening of the account and for future communication with you that is necessary for the execution of the contract. In addition, this data is stored in the customer account for future bookings or contracts. For this purpose, we also enable you to enter further information in the account (e.g. Your preferred means of payment).
We also use the data to provide an overview of the products ordered and bookings made (cf. Mistakes section! Reference source could not be found. and 19) and a simple way to manage your personal data, to administer our website and the contractual relationships, i.e. to establish, design, process and amend the contracts concluded with you via your customer account (e.g. in connection with your booking with us).
We process the information on language and gender in order to provide you with the best possible information on your profile or gender on the website. To display offer proposals tailored to your personal needs, for the statistical recording and evaluation of the selected offers and thus for the optimization of our suggestions and offers.
To avoid misuse, you must always keep your login data confidential and should close the browser window when you have finished communicating with us, especially if you share the computer with others.
18. Ordering via our online shop
On our website you have the opportunity to order a wide selection of products and vouchers. For this purpose, we collect the following data, whereby mandatory information is marked with an asterisk (*) in the corresponding form:
- Street and house number
- Zip code
- Telephone number
- Method of payment
- Yes, I would like to receive your newsletter
- I confirm the correctness of the information provided and have taken note of the terms and conditions and the data protection regulations and accept them
We use this data as well as other data voluntarily provided by you only in order to be able to execute your order according to your wishes.
19. Booking on the website, by correspondence or by phone call
If you make bookings or order vouchers either via our website, by correspondence (e-mail or post) or by telephone call, we collect the following data, whereby mandatory information is marked with an asterisk (*) in the corresponding form:
- Road and
- Zip code
- Date of birth
- E-mail address
- Telephone number
- Credit card
We will only use this data as well as other information voluntarily provided by you (e.g. expected arrival time, motor vehicle license plate, preferences, remarks) to process the contract, unless otherwise stated in this data protection declaration. you have not separately consented to this. We will process the data by name in order to record your booking as requested, to provide the booked services, to contact you in the event of ambiguities or problems and to ensure correct payment. Your credit card details will be automatically deleted after your departure from us.
20. Online payment processing
If you make bookings or purchase products on our website for a fee, depending on the product or service and the desired payment method – in addition to the information specified in para. Error! Reference source could not be found. or Section 19 – the provision of further data is required, e.g. Your credit card information or login to your payment service provider. This information, as well as the fact that you have purchased a service from us at the relevant amount and time, will be forwarded to the respective payment service providers (e.g. providers of payment solutions, credit card issuers and credit card acquirers). Always pay attention to the information
21. Book a table
On our website you have the opportunity to reserve a table in one of the restaurants mentioned on our website. For this purpose, we collect the following data, whereby mandatory information is marked with an asterisk (*) in the corresponding form:
- Number of guests
- E-mail address
- Telephone number
- Date and time of reservation
- I accept the terms and conditions
- I would like to receive information about special promotions and offers
We collect and process the data only for the purpose of processing the reservation, in particular to compile your reservation request according to your wishes, to make the reservation and to contact you in the event of ambiguities or problems.
22. Bookings via booking platforms
If you make bookings via a third-party platform (i.e. via booking.com, Hotel, Escapio, Expedia, Holiday-check, Hotel Tonight, HRS, Kayak, Mr. & Mrs. Smith, Splendia, Tablet Hotels, Tripadvisor, Trivago, Wee- kend4Two), we receive various personal information from the respective platform operator in connection with the booking made. As a rule, these are the data specified in para. 19 of these privacy statements. In addition, inquiries about your booking may be forwarded to us. We will process this data by name in order to record your booking as requested and to provide the booked services.
Finally, we may be informed by the platform operators about disputes in connection with a booking. In doing so, we may also receive data on the booking process, which may include a copy of the booking confirmation as proof of the actual completion of the booking. We process this data to protect and enforce our claims.
Please also note the information on data protection of the respective booking platform.
23. Submission of reviews
In order to help other users with their purchase decision and to support our quality management (in particular the processing of negative feedback), you have the opportunity to rate your stay with us on our website. The data that you have provided to us will be processed and published on the website, i.e. in addition to your review and its timing, possibly also a comment that you have attached to your review or the name you have provided.
We reserve the right to delete illegal reviews and, if there is any suspicion, to contact you and ask you to comment.
24. Applying for an open position
You have the opportunity to apply to us spontaneously or via a corresponding e-mail address for a specific job advertisement. For this purpose, we collect the following data, whereby mandatory information is marked with an asterisk (*) in the corresponding form:
- E-mail address
- Application documents (e.g. curriculum vitae, letter of motivation, certificates, etc.)
We use this and other data voluntarily provided by you to review your application. Application documents from applicants who have not been selected will be deleted at the end of the application process, unless you explicitly agree to a longer retention period or we are not legally obliged to retain them for a longer period of time.
C. Data processing in connection with your stay
25. Data processing for the fulfillment of legal reporting obligations
Upon arrival at our hotel, we may require you and your companions to provide the following information (mandatory*):
- First and last name
- Postal address and canton
- Date of birth
- Government-issued identification card and number
- Day of arrival and departure
We collect this information in order to fulfil legal reporting obligations, which arise in particular from hospitality, trade or police law. Insofar as we are obliged to do so under the applicable regulations, we will forward this information to the competent police authority.
26. Recording of purchased services
If you receive additional services during your stay (e.g. wellness, restaurant, activities), the subject matter of the service and the time of receipt of the service will be recorded by us for billing purposes.
27. Guest feedback
If you have provided us with your e-mail address in connection with your booking, you will receive an electronic form after departure. For this purpose, we collect the following data, whereby mandatory information is marked with an asterisk (*) in the corresponding form:
- First and last name
- Duration of stay
28. Video surveillance
In order to prevent abuses and to take action against unlawful conduct (esp. Theft and damage to property), the entrance area and the publicly accessible areas of our hotel are monitored by cameras. The image data will only be viewed if there is a suspicion of unlawful conduct. Otherwise, the images are automatically deleted after 72 hours.
For the provision of the video surveillance system, we rely on a service provider who can have access to the data if this is necessary for the provision of the system. If the suspicion of illegal conduct is substantiated, the data may then be passed on to consulting firms (in particular our law firm) and authorities to the extent necessary for the enforcement of claims or for filing a complaint.
29. Use of our WiFi network
In our hotel you have the possibility to use the WiFi network operated by Hotel Vitznauerhof free of charge. In order to prevent abuses and to take action against unlawful conduct, prior registration is required. In doing so, you transmit the following data to Hotel Vitznauerhof:
- Mobile phone
- MAC address of the end device (automatic)
In addition to the above data, each time the WiFi network is used, data on the visited hotel with time, date and end device are collected. The customer can revoke his registration at any time by notifying us.
Hotel Vitznauerhof must comply with the legal obligations of the Federal Act on the Surveillance of Postal and Telecommunications Traffic (SPTA) and the associated ordinance. If the legal requirements are met, the operator of the WiFi must monitor the use of the Internet or data traffic on behalf of the competent authority. The operator of the WiFi may also be obliged to disclose the customer’s contact, usage and marginal data to the authorized authorities. The contact, usage and marginal data will be kept for 6 months and then deleted.
30. Payment Processing