1. Controller and scope
The controller pursuant to the EU General Data Protection Regulation (‘GDPR’) and other national data protection laws of member states as well as other data protection provisions is:
2. Data protection officer
Rainer Annelies, Bichl 43a, 39040 Racines, Italy, Tel.: +39 0472 659800, firstname.lastname@example.org.
3. Principles of data processing
Personal data refers to all information related to an identified or identifiable natural person. This includes, for example, information such as your name, age, address, telephone number, date of birth, email address, IP address or user behaviour. Information that we cannot use to identify you personally (or that would involve a disproportionate effort to do so), for example, by anonymising the information, does not represent personal data. The processing of personal data (e.g. collecting, accessing, using, storing or transmitting such data) always requires a legal basis or your consent. Personal data that has been processed is deleted as soon as the purpose of the processing has been achieved and there are no further statutory retention obligations.
If we process your personal data in order to provide certain offers, we will subsequently inform you of the specific processes, the scope and the purpose of the data processing activity, the legal basis for the processing activity and the relevant storage period.
4. Individual processing steps
a. Type and scope of data processing
When you access and use our website, we collect personal data that your browser automatically sends to our server. This information is temporarily saved in a log file. When you use our website, we collect the following information, which we need for technical reasons in order to display our website to you and ensure stability and security:
Every time a user accesses the website or the app and every time a file is accessed, access data related to this action is stored in a log file on our server. This data includes: Browser type/version, operating system used, referring URL (the site previously visited), host name of the accessing computer (IP address), time and date of the server request, volume of data transmitted and access status (file transmitted, file not found, etc.).
This data is used to generate pseudonymised internal statistics that help us to analyse the use of the website, correct errors and improve our services. It is not used for any other purpose related to you individually. In particular, this data is not merged with other data sources. This data is automatically deleted after the statistical assessment. You can prevent your pseudonymised data being used for statistical purposes at any time by using the corresponding setting in your browser software to prevent cookies from being saved on your computer (see para 6.).
The data is used for the facilitation and realisation of guest booking; the successful execution of the guest’s stay; to coordinate the hotel stay according to the wishes and interests of the guest; to ensure the provision of future hotel services which correspond with the interests of the guest; for marketing purposes as pertaining to hotel performance and the improvement of this performance.
b. Legal basis
The legal basis of the specified data processing activity is Art. 6 (1f) GDPR. The processing of the specified data is necessary to provide the website and thus serves to safeguard the legitimate interests of our company.
In addition, Hotels Ratschings generally only collects and uses personal data that the user sends when using the website, for example, when booking a room or using the contact form on the website to make an enquiry.
It is necessary for customers to provide their full name, address and email address when making a reservation and/or booking. This data is required to process the booking. In addition, other information may also be necessary, such as telephone number, company name, tax identification number, account details or credit card details.
c. Storage period and data deletion
As soon as the specified data is no longer necessary to display the website, it will be deleted. The collection of data to provide the website and the storage of data in log files is necessary for the operation of the website. Consequently, the user does not have the right to object to such use. The data may be stored for longer periods in individual cases if such storage is legally required.
5. Processing and deletion
Hotels Ratschings may, of its own initiative or at the request of the user, complete, correct or delete incomplete, erroneous or outdated personal data that Hotels Ratschings has stored in connection with the operation of this website. If these processes are carried out at the request of the user, Hotels Ratschings may only do so if the user has sufficiently identified him/herself. Identity is verified using a copy of a photo ID – which will of course be deleted immediately after the authentication has been completed – or using criteria that can only be known by the user. Hotels Ratschings cannot agree to the user’s request if he/she is not properly identified.
In line with statutory provisions, Hotels Ratschings deletes personal data immediately upon the user’s request, provided there are no mandatory retention obligations to the contrary.
6. Disclosure of personal data to third parties
a. Personal data is handled confidentially and in line with the statutory data protection regulations. Data is not disclosed to third parties without the user’s consent, unless doing so is required to carry out orders, process payments or process requests or it is permitted in accordance with the statutory provisions. External service providers are obliged to handle data confidentially and securely, and they may only use the data as required to carry out their duties.
b. The data is disclosed to contracted service providers who supply cloud-based software and data handling solutions to the hotel. These providers operate with the sole purpose of processing and analysing guest data for the aforementioned purposes.
c. Otherwise, personal data is only disclosed if the user has given his/her express prior consent or if doing so is necessary for the prosecution of criminal offences. Personal data is only transmitted to the authorities or government agencies with the right to receive information if doing so is subject to a statutory obligation to provide information or there has been a court ruling to this effect. Your legitimate concerns are taken into account in line with the statutory data protection provisions. Where necessary, we may disclose your data to third parties on the basis of statutory requirements. We only comply with such requests if we are required to do so in line with statutory obligations.
d. You may revoke the consent to disclose your data at any time and without the need to provide us with a reason.
7. Protection of data
The protection of personal data is an important corporate principle at Hotels Ratschings. This is achieved through, among other things, training, a company data protection officer and a written agreement with all employees and external service providers to maintain the confidentiality of data and comply with data protection requirements.
All technical and organisational, physical and computer systems and measures in the area of data protection, IT and information security help to protect stored data from damage, destruction and unauthorised access and to achieve the protection objectives of confidentiality, availability and integrity.
For the sake of security, personal data is collected with the use of an encrypted secure socket layer (SSL) connection (which can be recognised by the use of ‘https://’ at the beginning of the website address in the address bar of the internet browser)
In addition, Hotels Ratschings takes all reasonable precautions to prevent unauthorised access to users' personal data as well as the unauthorised use or falsification of this data and to minimise the corresponding risks. However, the provision of personal data, whether this is done in person, on the phone or online, always involves risks, and there is no technical system that is completely impervious to manipulation or sabotage.
8. Tracking and analysis tools
We use tracking and analysis tools to ensure ongoing optimisation and the need-based design of our website. Tracking also enables us to collect statistics regarding the use of our website, which helps us to enhance our online presence using the resulting findings. Based on these interests, the use of the following tracking and analysis tools is legitimate in accordance with Art. 6 (1f) GDPR.
The following description of tracking and analysis tools also reveals the respective processing purposes and the data processed.