Data Protection
Data protection
Privacy Policy
Personal data is processed when you visit this website. Below, we provide a brief and clear explanation of which data is processed, for what purposes, and the rights to which you are entitled under the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).
Contact Information
If you have any questions or suggestions regarding this information, or if you wish to contact us to exercise your rights, please send your inquiry to:
Postal address:
Amadee Appartements
Karin und Alfred Hummer
Hochosterwitzer Str. 1
9300 St. Veit an der Glan
Austria
E-Mail: [JavaScript erforderlich]
A data protection officer has not been appointed, as there is no legal obligation to do so.
General information on the legal basis, storage period, recipients and data transfer to third countries
Legal basis
We process personal data in compliance with applicable data protection regulations, in particular the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG). Processing takes place only on a legal basis:
Consent (Art. 6(1)(a) GDPR)
Performance of a contract or steps prior to entering into a contract (Art. 6(1)(b) GDPR)
Compliance with a legal obligation (Art. 6(1)(c) GDPR)
Legitimate interests of the controller or a third party, unless the interests of the data subject requiring protection override such interests (Art. 6(1)(f) GDPR)
Duration of storage
We store personal data only for as long as is necessary to achieve the respective processing purpose or to fulfill statutory or contractual obligations. Statutory retention periods—such as those arising from commercial or tax law regulations—remain unaffected. Data that is no longer required is deleted or anonymized.
Categories of recipients of the data
We engage data processors to carry out processing activities. These processors handle tasks such as hosting, email transmission and storage, IT infrastructure, server log processing, as well as maintenance and security. Data processors act exclusively on our behalf and are contractually obligated to comply with technical and organizational data protection measures. Furthermore, data may be transmitted to service providers—such as postal and delivery services, banks, tax advisors, or public authorities—to the extent necessary to fulfill the stated purposes.
Data transfer to third countries
Personal data is not transmitted to countries outside the EU/EEA.
Web Hosting, Email Services & Server Log Files
Provider
Our website, email infrastructure, and databases are hosted by easyname GmbH, Canettistraße 5/10, 1100 Vienna, Austria (hereinafter "easyname").
Processing & Data Categories
When you access our website or communicate with us via email, easyname automatically collects and stores technical operational data in server log files.
Website Access (Webserver Logs):
Your browser automatically transmits the following technical data:IP address of the accessing device
Date and time of the server request
Referrer URL (the page previously visited)
Browser type and browser version
Operating system used and the name of your access provider
Email Communication (Mailserver Logs):
When you send an email to our hosted email addresses, or when we send an email to you, the mail servers log the following connection data:Email addresses of the sender and recipient
IP address of the sending mail server/device
Date and time of the transmission
Size of the email and delivery status (e.g., successful, rejected)
Message ID
The contents of your emails are stored securely on the mail servers of easyname for the duration of our business relationship or until legal retention periods expire. This technical log data is never merged with other data sources.
Purpose & Legal Basis
The data is processed to ensure the technical stability, error analysis, and security of the website and email systems (e.g., defense against cyber attacks, detection of spam or malware). The legal basis is Art. 6(1)(f) GDPR (legitimate interest).
Data Processing Agreement
We have concluded a Data Processing Agreement (DPA) according to Art. 28 GDPR with easyname. This contract ensures that the provider processes our website visitors' and email contacts' data strictly in accordance with our instructions and EU data protection standards.
Retention Period
Website Logs: IP addresses of website visitors are anonymized within 24 hours. The log data is automatically and completely deleted after 3 months at the latest.
Email Logs: Mailserver logs are stored by easyname for technical security purposes and are automatically deleted or anonymized after a maximum of 14 days, unless a security incident requires a longer investigation.
Contact via Email and Contact Form
Processing & Data Categories
If you contact us via the contact form on our website or by sending us an email, the information you provide will be processed by us to handle your inquiry and in the event of follow-up questions. This data typically includes:
First name and last name
Email address
Telephone number (if provided)
Your personal message or specific request details
Purpose & Legal Basis
The processing of this data is carried out to respond to your request and maintain customer relations. The legal basis is Art. 6(1)(b) GDPR if your inquiry is related to a booking contract or an offer, or Art. 6(1)(f) GDPR (our legitimate interest in responding effectively to messages from website visitors and protecting our legal position).
Retention Period
The data sent via email or the contact form will remain with us for a period of 48 months. This retention period is based on our legitimate interest to handle recurring inquiries and to defend against potential legal or recourse claims under Austrian law, which generally lapse after 3 years. In the case of a binding booking, data is transferred to our guest administration system and kept according to statutory tax retention periods. No data will be shared with third parties without your consent.
Online Booking on our website
Provider
We use the online booking tool and property management system provided by book-in Hotelsoftware, Wilfried Reiter, Bahnhofstraße 429, 8970 Schladming, Austria (hereinafter "book-in manager") on our website to enable convenient direct bookings for our holiday apartments.
Processing & Data Categories
When you make a booking or inquiry through the integrated booking interface, the data you enter is transmitted directly to book-in manager and stored in our guest administration system. This data includes:
First name and last name of the main guest and accompanying persons
Contact details (address, telephone number, email address)
Date of birth (required for the registration system and tourist tax calculation)
Booking details (arrival and departure dates, number of guests, type of apartment)
Payment information and billing data
Purpose & Legal Basis
The collection and processing of this data are essential for the initiation, processing, and management of your booking contract, as well as for fulfilling local registration laws (Meldegesetz/Kurtaxe). The legal basis is Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (compliance with a legal obligation).
Data Processing Agreement
We have concluded a Data Processing Agreement (DPA) according to Art. 28 GDPR with book-in manager. This contract guarantees that the provider processes our guests' data strictly in accordance with our instructions and complies with all European data protection standards.
Retention Period
Your personal data will be stored for the duration of the business relationship. Financial data and billing records will be archived for 10 years in accordance with Austrian tax and corporate retention regulations (Unternehmens- und Steuerrecht) before being deleted.
Required Disclosures
We may disclose your personal data if required by law, court order, or at the request of law enforcement or government authorities. Furthermore, we reserve the right to disclose information if necessary to protect the rights, property, or safety of Amadee Appartements or third parties, or to take legal action against individuals causing intentional or unintentional interference with our operations.
Cookies
Purpose
Our website uses exclusively technically necessary cookies and local storage technologies (Session Storage and Local Storage). These are essential for the operation, core functionalities, and security of our website. We do not use any analytics, tracking, or marketing cookies.
Legal basis
The legal basis for technically necessary cookies and storage elements is Article 6(1)(f) GDPR (legitimate interest) in maintaining a functional, secure website and fulfilling your requested services, such as processing a booking.
What are Cookies, Session Storage, and Local Storage?
Cookies are small text files that are stored on your end device by your browser. Some cookies are deleted after your browser session ends (session cookies). Others remain on your device to recognize your browser settings on your next visit (persistent cookies).
Session Storage is a temporary storage location in your browser. Data saved here is automatically and completely deleted as soon as you close the specific browser tab or window. It is used to keep data active while navigating between different pages of our website.
Local Storage is a persistent storage location in your browser. Unlike Session Storage, data in Local Storage does not expire automatically when the browser is closed. It remains saved until your browser cache is cleared or until the specific function deletes it (for example, when you change your privacy preferences).
You can configure your browser settings to block cookies and storage data, or to delete them automatically. Please note that disabling these technical elements may restrict the functionality of our website.
The following technically necessary elements are used on our website:
Name: Ibe-Bookin-Session
Domain: hausamadee.at
Storage: session cookie / session storage
Description: Required for the book-in manager booking system to function, specifically for storing temporary booking configurations and search parameters during your visit.
Name: matomo_cookieless_optout
Domain: hausamadee.at
Storage: local storage / persistent
Description: Stores your choice if you actively opt out of our cookieless Matomo web analytics, ensuring your future visits remain excluded from server-side statistics.
Web analysis with Matomo (cookieless)
Purpose & Scope
We use the open-source software tool Matomo on our website to analyze the surfing behavior of our users. This helps us to continuously improve our website and optimize our online services.
Processing & Anonymization
Matomo is configured to operate completely without cookies. No data is stored on your terminal device. Analytics are performed exclusively on the server side. IP addresses are immediately truncated and anonymized by 2 bytes (e.g., 192.168.xxx.xxx) upon collection. Only anonymized technical and statistical data is processed (e.g., visited pages, time of visit, browser type, approximate region). No user profiling or cross-site tracking takes place.
Data Recipient / Hosting
The Matomo instance is hosted on our webspace provided by easyname GmbH (Austria). The data remains entirely within our control on infrastructure located in the EU. No data is transferred or shared with the official Matomo company or any other third parties.
Legal Basis
The processing of users' personal data is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the web analysis, optimization, and economic operation of our website.
Retention Period
The anonymized statistical reports are automatically deleted after 180 days.
Right to Object (Opt-Out)
You have the right to object to this data processing at any time. If you wish to opt-out, you can do so by using the option below:
Data Security
We implement technical and organizational measures to protect your personal data against unauthorized access, loss, or misuse. To ensure secure data transmission, this website uses industry-standard SSL/TLS encryption. You can recognize an encrypted connection by the "https://" prefix and the padlock symbol in your browser bar, which prevents third parties from reading data you transmit to us.
Links
Our website contains links to external websites. We are not responsible for their content or privacy practices. Please review the privacy policies of any website you visit.
Notification of Changes
We reserve the right to amend this Privacy Policy to reflect legal, technical, or organizational changes. Any changes affecting your contractual relationship with us or requiring your consent will only be implemented with your explicit agreement. We encourage you to review the current version of this Privacy Policy regularly.
Rights of Data Subjects & Right to Lodge a Complaint
As a data subject, you have the following rights under the GDPR:
Access (Art. 15 GDPR): Request information about whether and how your personal data is processed.
Rectification and Erasure (Arts. 16 & 17 GDPR): Request correction or deletion of your personal data.
Restriction of Processing (Art. 18 GDPR): Request that processing of your personal data be limited.
Data Portability (Art. 20 GDPR): Receive your data in a structured, commonly used, machine-readable format and transfer it to another controller.
Withdrawal of Consent (Art. 7(3) GDPR): Withdraw your consent at any time. This does not affect the lawfulness of processing carried out before withdrawal.
Right to Object (Art. 21 GDPR): Object to processing based on Art. 6(1)(e) or (f) GDPR, including processing for direct marketing purposes.
Right to Lodge a Complaint
If you believe your personal data is being processed unlawfully, you may lodge a complaint with a supervisory authority pursuant to Art. 77 GDPR. In Austria, this is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, Vienna).