Legal
Privacy Policy
Information pursuant to the EU General Data Protection Regulation (GDPR) and the Austrian Data Protection Act
1. Controller
Christian RiedlspergerPostal address: see Imprint
Phone: +43 677 61701082
Email: [email protected]
2. Data collected when visiting the website
When you access this website, technical data is automatically stored in so-called server log files by our hosting provider (ALL-INKL.COM – Neue Medien Münnich, Germany) and by the upstream CDN/proxy provider (Cloudflare, see § 5):
- IP address (truncated / anonymised)
- Date and time of the request
- URL requested
- Browser type and version
- Operating system
- Referrer URL (previously visited page)
Purpose: ensuring trouble-free operation, CDN delivery and protection against misuse.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
Retention: at ALL-INKL.COM a maximum of 30 days; at Cloudflare in accordance with their privacy policy (typically less than 7 days).
3. Enquiries and booking requests
When you contact us through the enquiry form or by email, the following data is processed:
- First and last name
- Email address
- Phone number (optional)
- Arrival and departure dates
- Number of guests
- Language preference (used to pick the auto-reply template)
- The message you send
- Confirmation that you have read this privacy policy (mandatory checkbox)
- Your IP address at the time of submission (for anti-abuse purposes; included in the notification email to the host)
Workflow: the form is processed by a server-side PHP script (anfrage.php) on our hosting at ALL-INKL.COM. We send two emails: a notification to ourselves ([email protected]) and an automatic confirmation to the address you provided. Delivery uses the SMTP infrastructure of ALL-INKL.COM. To prevent spam waves, your IP address is temporarily stored (max. 10 minutes) in a rate-limit directory on the server and discarded automatically thereafter.
Purpose: handling your enquiry and preparing or fulfilling a lodging contract.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual / contractual measures); Art. 6(1)(f) GDPR for the anti-abuse element.
Retention: until your enquiry has been finally processed. In the event of a booking, until the expiry of statutory retention periods (in particular 7 years under § 132 of the Austrian Federal Fiscal Code).
4. Processors
The following service providers process personal data on our behalf:
- ALL-INKL.COM – Neue Medien Münnich – web hosting & email delivery. Server location: Germany. ALL-INKL.COM privacy information
- Cloudflare, Inc. – CDN, TLS termination, DDoS protection, email address obfuscation, web analytics and network error logging. Registered office: 101 Townsend St, San Francisco, CA 94107, USA. Transfer to the USA is secured by EU Standard Contractual Clauses (SCC) and the EU-US Data Privacy Framework (Commission adequacy decision of 10 July 2023). Cloudflare privacy policy
- Booking.com B.V. – we use the open iCal interface (read-only pull) to retrieve availability data from our own host profile on Booking.com and show the resulting blocked dates in our calendar. No personal data of yours is transmitted to Booking.com. Booking.com privacy policy
- Feratel media technologies AG (TOSC5) – in the "Book online instantly" section we embed the official booking and payment widget of the Zell am See – Kaprun region directly (domain
deskline.net). For its mere functionality, 4 technical cookies and 4 local-storage entries are set (shopping basket, search/tab synchronisation). These are classified under GDPR as technically necessary (Art. 6 (1) (b) – contract initiation) and are not tracking. Only when you actively submit a booking are the data you entered (name, address, travel dates, payment data) transmitted to Feratel and – exclusively for payment processing – to Datatrans AG (Switzerland). Feratel's seat: Maria-Theresien-Straße 8, 6020 Innsbruck, Austria. Feratel privacy policy
5. Third-party services embedded
Cloudflare as CDN/proxy
All traffic to this website is delivered through Cloudflare's infrastructure. This means every request – including your IP address, the path requested and HTTP headers – is first processed by a Cloudflare edge server (usually within the EU, e. g. Frankfurt) before being forwarded to our hosting server. Cloudflare uses this data to provide CDN, caching, security and performance services and for "Network Error Logging" (NEL), which produces anonymised reports on network or connectivity failures.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, fast and reliable operation).
Transfer to the USA: based on SCC and the EU-US Data Privacy Framework.
Cloudflare Web Analytics
For reach measurement we use Cloudflare Web Analytics. This service operates without cookies and without fingerprinting. Only anonymised data on pages viewed, approximate location (country/region), dwell time and referrer is collected. Individual visitors cannot be identified. Data is evaluated in aggregate only.
Legal basis: Art. 6(1)(f) GDPR. cloudflare.com/web-analytics
Cloudflare Email Address Obfuscation
On every page of this website Cloudflare automatically replaces our email address with an encrypted placeholder, which is decrypted by a short JavaScript snippet only when a visitor clicks. This is for spam protection; no additional visitor data is transmitted to Cloudflare.
Fonts
The fonts used on this site ("Cormorant Garamond" and "Jost") are self-hosted on our server. No data is transmitted to third parties when loading them.
Google Maps
A Google Maps embed (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company Google LLC, USA) is used on this site. The map only loads after your active confirmation ("Load map" button). Only then is data (including your IP address) transmitted to Google. If you have given consent, your choice is remembered client-side in your browser's LocalStorage under the key maps-consent-v1, so you don't have to confirm again on future visits. You can revoke this consent at any time via your browser settings (clearing site storage). Legal basis: Art. 6(1)(a) GDPR (consent). Transfer to the USA: SCC and EU-US Data Privacy Framework. Google privacy policy
External platform links (Google & Booking.com)
The footer and the testimonials section contain links to our verified Google Business profile, the Google Maps location page and our Booking.com listing. These links are embedded statically — no automatic data transfer takes place when you simply load our page. Only when you actively click one of these links will you be redirected to the respective platform, where their own privacy policies apply: Google privacy policy · Booking.com privacy policy.
Legal basis: Art. 6(1)(a) GDPR (consent by active click).
Publication of guest reviews
In the "What our guests say" section we quote publicly accessible reviews that our guests themselves posted on Booking.com or Google. For each review we display the (first) name chosen by the reviewer, the country, the platform and the date together with the original review text. The data is copied directly from the respective profiles and updated manually (no automatic API fetch).
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in transparent external representation). Reviewers have agreed to general visibility by publishing on the platform in question.
Objection: Should you wish to have your review removed from this website, an informal message to [email protected] is enough — we will delete the review from our site without delay (the original on Booking/Google remains untouched).
WhatsApp link
The booking form and the mobile footer contain a link to a direct WhatsApp chat (wa.me/4367761701082). Only if you actively click this link will you be redirected to WhatsApp Ireland Ltd. (4 Grand Canal Square, Dublin 2, Ireland; parent company Meta Platforms, Inc., USA). How WhatsApp processes the data transmitted in this case (at least: IP address, phone number when a message is sent, device information) is set out in the WhatsApp privacy policy for the EEA. Legal basis: Art. 6(1)(a) GDPR (consent by active click).
6. Cookies and browser storage
This website does not set any cookies – neither technical nor tracking or analytics cookies. The only data stored in your browser's LocalStorage are the following technically necessary entries:
fk-cookie-ok— remembers that you have acknowledged the cookie-notice banner so it doesn't reappear on every visit.maps-consent-v1— remembers your consent to load the Google Maps embed (see § 5 "Google Maps"). Only set when you actively click "Load map".
Both entries are purely client-side, are never transmitted to our server and can be removed by you at any time via your browser settings (clear site data).
6a. Data transfer to third countries
Where personal data is transferred to the USA through the third-party services listed above (Cloudflare, Google Maps, WhatsApp), this is based on:
- EU Standard Contractual Clauses (Commission Decision 2021/914)
- The EU-US Data Privacy Framework (Commission adequacy decision of 10 July 2023)
Cloudflare, Google and Meta have subscribed to these safeguards. Nevertheless, it cannot be entirely ruled out that US authorities may demand access to personal data on the basis of US legislation (e. g. FISA 702, CLOUD Act).
7. Your rights
You have the following rights with regard to the data we hold about you:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to lodge a complaint with the supervisory authority
To exercise your rights, an informal message to [email protected] is sufficient.
8. Right to complain to the supervisory authority
Österreichische Datenschutzbehörde (Austrian Data Protection Authority)Barichgasse 40-42
1030 Vienna
Phone: +43 1 52 152-0
Email: [email protected]
Web: www.dsb.gv.at
9. Data security
Data is transmitted via a TLS/SSL-encrypted connection (HTTPS), recognisable by the padlock symbol in your browser bar.
10. Changes to this privacy policy
We reserve the right to adapt this privacy policy, for instance when the legal situation or our processing operations change. The version published on this page applies.
Last updated: 16 May 2026