Privacy policy

Last updated: September 2026

Controller under Article 13 GDPR

Hotel Villa Flora GmbH
Markus-Pernhart-Straße 5–7
9220 Velden am Wörthersee, Austria
Email: hotel@villa-flora.at
Phone: +43 4274 2130

The operators of these pages (hereinafter only “controller” or “operator”) take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

The use of our website is usually possible without providing personal information. If personal data (for example name, address or e-mail addresses) is raised on our pages, this takes place, as far as possible, on voluntary basis only. This data will not be disclosed to third parties without your explicit consent.

The processing of your personal data, such as your name, address, e-mail address or telephone number, is always in accordance with national and European law, in particular the General Data Protection Regulation (hereinafter referred to as “GDPR”). By means of this privacy policy, our company wishes to inform you about the nature, scope and purpose of the personal data collected, used and processed by us. Furthermore, you will be informed about your rights by means of this privacy policy.

Please note that data transmission over the Internet (for example, when communicating via e-mail) may have security vulnerabilities. A complete protection of your data, from access by third parties, is not possible.

1. Definitions

The privacy policy of these pages is based on the terms of Article 4 of the GDPR, which were defined by the European Union at the time of the order of the General Data Protection Regulation (GDPR). Our privacy policy should be easy to read and should be understandable for the public as well as for our customers and business partners. To ensure this, we would like to explain the terminology used in advance.

We use the following terms in this privacy policy, including but not limited to:

  • a) personal data: Personal data means any information relating to an identified or identifiable natural person (hereinafter referred to as “data subject” or “user”). A natural person is considered to be identifiable who, directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier or one or more special features, expresses the physical, physiological, genetic, mental, economic, cultural or social identity of this natural person can be identified.
  • b) affected person: Affected person is any identified or identifiable natural person whose personal data is processed by the controller.
  • c) processing
  • d) limitation of processing: Restriction of the processing is the marking of stored personal data with the aim to limit their future processing.
  • e) Profiling: Profiling is any kind of automated processing of personal data that consists of using that personal information to evaluate certain personal aspects relating to a natural person, in particular aspects relating to job performance, economic situation, health, personal preferences, interests, reliability, behavior, whereabouts or relocation of that natural person.
  • f) pseudonymisation: Pseudonymisation is the processing of personal data in such a way that personal data can no longer be attributed to a specific data subject without the need for additional information, provided that such additional information is kept separate and subject to technical and organizational measures to ensure that the personal data not assigned to an identified or identifiable natural person.
  • g) controller or person in charge of controlling: The controller or person in charge of controlling is the natural or legal person, public authority, agency or body that, alone or in concert with others, decides on the purposes and means of processing personal data. Where the purposes and means of such processing are determined by Union law or the law of the Member States, the controller or the specific criteria for his designation may be provided under Union or national law.
  • h) processor: The processor is a natural or legal person, public authority, agency or other body that processes personal data on behalf of the controller.
  • i) recipient: Recipient is a natural or legal person, public authority, agency or other body to whom Personal Data is disclosed, whether or not it is a third party. However, authorities which may receive personal data under Union or national law in connection with a particular mission are not considered as beneficiaries.
  • j) third parties: Third is a natural or legal person, public authority, agency or body other than the data subject, the controller, the processor and the persons authorized under the direct responsibility of the controller or the processor to process the personal data.
  • k) consent: Consent is any voluntarily given and unambiguously expressed in the form of a statement or other unambiguous confirmatory act by the data subject for the particular case, by which the data subject indicates that they consent to the processing of the personal data concerning him / her is.

2. Rights of the user

It is also our intention to make you aware of the rights that you have under GDPR with regard to the processing of your data:

  • a) Right to confirm (Article 15 (1) GDPR): Each data subject has the right to ask the person responsible for a confirmation of the processing of the personal data concerned. If an affected person wishes to make use of this confirmation right, they may at any time turn to the address given in the imprint or this data protection declaration or contact another employee of the person in charge.
  • b) Right to information (Article 15 (1) and (3) GDPR): Each person (user) affected by the processing of personal data has the right to receive free information from the person responsible about the personal data stored about him and a copy of this information at any time. Furthermore, the responsible person has to inform the person concerned about the following information:
  • the processing purposes
  • the categories of personal data being processed
  • the recipients or categories of recipients to whom the personal data have been disclosed or are still being disclosed, in particular to recipients in third countries or to international organizations
  • if possible, the planned duration for which the personal data will be stored or, if that is not possible, the criteria for determining that duration
  • the right of rectification or erasure of the personal data concerning them or restriction of processing by the controller or a right to object to such processing
  • the existence of a right of appeal to a supervisory authority
  • if the personal data are not collected from the data subject: all available information on the source of the data
  • the existence of automated decision-making, including profiling, in accordance with Article 22 (1) and (4) of the GDPR and – at least in these cases – meaningful information on the logic involved and the scope and intended impact of such processing on the data subject
  • c) Right to rectification (Art. 16 GDPR): Any person affected by the processing of personal data is entitled to demand the immediate correction of incorrect personal data concerning them. Furthermore, the data subject has the right to request the completion of incomplete personal data, including by means of a supplementary declaration, taking into account the purposes of the processing.
  • d) Right to cancellation (right to be forgotten) (Art. 17 GDPR): Any person affected by the processing of personal data shall have the right to require the controller to immediately delete the personal data concerning him, provided that one of the following reasons is satisfied and the processing is not required:
  • The personal data has been collected or otherwise processed for such purposes for which they are no longer necessary.
  • The person concerned revokes the consent on which the processing was based on Article 6 (1) (a) of the GDPR or Article 9 (2) (a) of the GDPR and lacks any other legal basis for the processing.
  • The data subject submits an objection to the processing pursuant to Art. 21 (1) GDPR, and there are no legitimate reasons for the processing, or the data subject appeals pursuant to Art. 21 (2) GDPR the processing.
  • The personal data were processed unlawfully.
  • The deletion of personal data is required to fulfill a legal obligation under Union or national law to which the controller is subject.
  • The personal data were collected in relation to information society services offered pursuant to Art. 8 (1) GDPR.
  • e) Right to limit processing (Art. 18 GDPR): Any person affected by the processing of personal data shall have the right to require the controller to restrict the processing if any of the following conditions apply:
    • The accuracy of the personal data is contested by the data subject for a period of time that enables the person responsible to verify the accuracy of the personal data.
    • The processing is unlawful, the data subject refuses to delete the personal data and instead requests the restriction of the use of personal data.
    • The data controller no longer needs the personal data for processing purposes, but the data subject requires them to assert, exercise or defend their rights.
    • The person concerned has objection to the processing according to Art. 21 (1) GDPR and it is not yet clear whether the legitimate reasons of the person responsible outweigh those of the person concerned.
  • f) Data transferability (Art. 20 GDPR)
  • g) Right to object (Art. 21 GDPR)
  • h) Automated decisions in individual cases including profiling (Art. 22 GDPR)
  • i) Right to revoke a data protection consent

If you believe that the processing of your personal data violates the GDPR, you also have the right to lodge a complaint with the Austrian Data Protection Authority: Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, phone +43 1 52 152-0, e-mail dsb@dsb.gv.at, www.dsb.gv.at.

3. Cookies

Consent management with Real Cookie Banner

We use Real Cookie Banner to obtain, manage and document your consent to optional cookies and similar technologies. For this purpose, a pseudonymous user identifier (UUID) is generated and documented together with your selection, the time, the language used and technical information about the display of the consent dialog. Your IP address is not stored in the consent documentation. The legal bases are Art. 6 (1) (c) GDPR in conjunction with sec. 165 (3) Austrian TKG 2021 and Art. 6 (1) (f) GDPR. Consent remains valid for no longer than 365 days and may be changed or withdrawn at any time via the cookie settings. Real Cookie Banner runs locally on our web server; no visitor data is transmitted to the plugin manufacturer devowl.io for consent management.

Elfsight review widget

After your explicit consent, we load a review widget supplied by Elfsight, SL, C. de la Constitució 17, AD700 Escaldes-Engordany, Andorra. In particular, your IP address and browser and device information may be processed. According to the provider, technical log data is stored for up to seven days and then analysed in anonymised form. Processing takes place exclusively on the basis of your consent pursuant to Art. 6 (1) (a) GDPR and sec. 165 (3) Austrian TKG 2021. You may withdraw your consent at any time via the cookie settings. Further information is available at elfsight.com/privacy-policy.

When you visit our website, a consent banner (“cookie banner”) asks for your consent to the use of cookies and similar technologies that are not technically necessary (statistics, marketing). Technically necessary cookies are used on the basis of our legitimate interest in the technical operation of the website (Art. 6 (1) (f) GDPR); all other cookies are used exclusively on the basis of your consent (Art. 6 (1) (a) GDPR, sec. 165 (3) Austrian TKG 2021). You can change or withdraw your selection at any time via the “Cookie settings” link in the footer.

The internet pages partly use so-called cookies. Cookies do not harm your computer and do not contain viruses. Cookies serve to make our offer more user-friendly, effective and secure. Cookies are small text files that are stored on your computer and stored by your browser.

Most of the cookies we use are so-called “session cookies”. They are automatically deleted after your visit. Other cookies remain stored on your device until you delete them. These cookies allow us to recognize your browser the next time you visit.

You can set your browser so that you are informed about the setting of cookies and cookies only in individual cases allow, the acceptance of cookies for certain cases or generally exclude and activate the automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of this website.

4. Data processing when using the online booking system (SiteMinder)

For online reservations we use the external booking system of SiteMinder Limited, Bond Store 3, 30 Windmill Street, Millers Point, NSW 2000, Australia (“SiteMinder”). When you click the “Book” link on our website, you are redirected to the SiteMinder booking page (domain direct-book.com). Your browser then communicates directly with SiteMinder’s servers and transmits your IP address as well as other technically necessary information.

On the SiteMinder booking page, the personal data required for the reservation is collected – in particular name, e-mail address, telephone number, billing address, booking details, information on accompanying persons and payment information. All data is transmitted in encrypted form and processed for the purpose of handling your booking.

We have concluded a data processing agreement with SiteMinder pursuant to Art. 28 GDPR; the EU Standard Contractual Clauses have been agreed to ensure an adequate level of data protection for transfers to a third country (Australia). The legal basis for the processing is Art. 6 (1) (b) GDPR (performance of the accommodation contract and pre-contractual measures). If no booking is completed, the data entered is deleted or blocked after a short time; otherwise we store your data within the statutory retention periods.

Further information can be found in SiteMinder’s privacy policy at www.siteminder.com/legal. Alternatively, you can of course make a reservation by phone or e-mail.

5. Registration requirement

The person in charge is obliged, under the respective applicable reporting law, to register all guests resident with the person responsible with the data specified in the Registration Act. This affects, among other things, the following data:

  • surname
  • name of accompanying persons
  • date of birth
  • gender
  • nationality
  • country of origin
  • address
  • travel document (type, number, date of issue, issuing authority, state)
  • date of the travel period

a. Guest directory

According to a legal obligation, the person responsible has to lead all guest data transmitted to him for a booking in a so-called guest directory. This guest directory is subject to the automatic deletion and anonymization periods stored in the system. The providers provide suitable technical and organizational measures to store personal data in the system in accordance with the law. In individual cases, legally prescribed storage and retention periods must be observed and noted. The storage periods set are valid, as long as the data concerned are not processed for any other purposes mentioned in this privacy policy.

The guest directory is managed electronically by the responsible person, whereby the data is forwarded to zadego GmbH. In this case, zadego GmbH acts as a processor, as it stores the data on your servers. A transfer to a third country is not without prior information to those affected.

6. SSL encryption

This site uses SSL encryption for security reasons and to protect the transmission of sensitive content, such as the requests you send to us as the site operator. You can recognize an encrypted connection by changing the address line of the browser from “http: //” to “https: //” and the lock symbol in your browser line.

If SSL encryption is enabled, the data you submit to us can not be read by third parties.

7. Privacy Policy Google Maps

This website uses Google Maps of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to display our location. The map is only loaded after you have given your consent via the cookie banner or the two-click solution (Art. 6 (1) (a) GDPR). Only then is data (including your IP address) transmitted to Google; this may also involve a transfer to the USA (EU-U.S. Data Privacy Framework). Further information: https://policies.google.com/privacy

8. Privacy policy for the use of Google Analytics 4

This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).

Google Analytics 4 uses cookies and similar technologies that enable an analysis of your use of the website. IP addresses are not stored by default; they are only processed in truncated form for rough geolocation and then discarded. The information generated is generally transmitted to Google servers; this may also involve a transfer to the USA. Google LLC is certified under the EU-U.S. Data Privacy Framework.

The processing is carried out exclusively on the basis of your consent pursuant to Art. 6 (1) (a) GDPR and sec. 165 (3) Austrian TKG 2021, which you can give via our cookie banner. You can withdraw your consent at any time with effect for the future via the cookie settings. User data is stored in Google Analytics for 14 months and then deleted automatically.

We have concluded a data processing agreement with Google pursuant to Art. 28 GDPR. Further information: https://policies.google.com/privacy

In addition, we use the analytics tool Metricool of Metricool Software S.L., Madrid, Spain, to analyse the reach of our website. Metricool is likewise only loaded with your consent (statistics category); processing takes place within the EU. Further information: https://metricool.com/privacy/

9. Privacy policy for the use of the Meta pixel (Facebook pixel)

This website integrates the so-called Meta pixel (formerly “Facebook pixel”) of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (“Meta”).

The Meta pixel allows us to measure the effectiveness of our advertising on Facebook and Instagram and to show visitors of our website interest-based advertising (so-called retargeting). For this purpose, information about your visit to this website (pages viewed, device information, truncated IP address) is transmitted to Meta and, if you are logged in to Facebook or Instagram, assigned to your user account.

The Meta pixel is used exclusively on the basis of your express consent pursuant to Art. 6 (1) (a) GDPR and sec. 165 (3) Austrian TKG 2021, which you can give via our cookie banner. Without your consent, the Meta pixel is not loaded. You can withdraw your consent at any time with effect for the future via the cookie settings.

Personal data may also be transferred to Meta Platforms, Inc. in the USA. Meta is certified under the EU-U.S. Data Privacy Framework; in addition, Standard Contractual Clauses are in place. For the data processing in the context of audience measurement, a joint controllership agreement pursuant to Art. 26 GDPR exists with Meta.

Further information: https://www.facebook.com/privacy/policy and https://www.facebook.com/ads/preferences (ad settings).

10. Newsletter

On our website you can subscribe to our newsletter, with which we inform you about offers and news from Villa Flora. For the registration we need your e-mail address. Registration takes place using the double opt-in procedure: after registering, you will receive an e-mail in which you must confirm your registration.

The legal basis for the processing is your consent pursuant to Art. 6 (1) (a) GDPR. You can unsubscribe from the newsletter at any time via the unsubscribe link at the end of each e-mail or by sending a message to hotel@villa-flora.at; your consent is thereby withdrawn with effect for the future.

For sending the newsletter we use the service provider Mailchimp of The Rocket Science Group LLC (an Intuit Inc. company), 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA. Your e-mail address is stored on Mailchimp servers in the USA. Mailchimp is certified under the EU-U.S. Data Privacy Framework; in addition, a data processing agreement pursuant to Art. 28 GDPR is in place. Further information: https://mailchimp.com/legal/privacy/

11. Server log files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:

  • browser type and browser version
  • used operating system
  • referrer URL
  • host name of the accessing computer
  • time of the server request

These data cannot be assigned to specific persons. A merge of this data with other data sources will not be done. We reserve the right to check this data retrospectively, if we become aware of specific indications for illegal use.

12. No automated decision-making

As a responsible company we refrain from automatic decision-making or profiling.

13. Consumer dispute resolution

The European Commission discontinued its platform for online dispute resolution (ODR platform) in July 2025. Consumers may contact the Austrian consumer arbitration board: Schlichtung für Verbrauchergeschäfte, Mariahilfer Straße 103/1/18, 1060 Vienna (www.verbraucherschlichtung.at). We are neither obliged nor willing to participate in dispute resolution proceedings before this consumer arbitration board, but we will endeavour to reach an amicable solution in individual cases.

14. Objection to advertising e-mails

The use of published in the context of the imprint obligation contact information for sending unsolicited advertising and information materials is hereby rejected. The operators of the pages expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, for example through spam e-mails.

15. Changes to this Privacy Policy

We may update our privacy policy from time to time. Therefore, it is recommended that you check this page regularly for changes. We will inform you about changes by posting the new privacy policy on this page. These changes will take effect immediately after publication on this page.

16. How to contact us

If you have any questions, suggestions or concerns regarding this policy or the use of your data, please contact us at the address given in the legal notice.