Skip to content

Legal

Privacy Policy

Information pursuant to the EU General Data Protection Regulation (GDPR) and the Austrian Data Protection Act

1. Controller

Christian Riedlsperger
Postal address: see Imprint
Phone: +43 677 61701082
Email: [email protected]

2. Data collected when visiting the website

When you access this website, technical data is automatically stored in so-called server log files by our hosting provider (ALL-INKL.COM – Neue Medien Münnich, Germany) and by the upstream CDN/proxy provider (Cloudflare, see § 5):

Purpose: ensuring trouble-free operation, CDN delivery and protection against misuse.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
Retention: at ALL-INKL.COM a maximum of 30 days; at Cloudflare in accordance with their privacy policy (typically less than 7 days).

3. Enquiries and booking requests

When you contact us through the enquiry form or by email, the following data is processed:

Workflow: the form is processed by a server-side PHP script (anfrage.php) on our hosting at ALL-INKL.COM. We send two emails: a notification to ourselves ([email protected]) and an automatic confirmation to the address you provided. Delivery uses the SMTP infrastructure of ALL-INKL.COM. To prevent spam waves, your IP address is temporarily stored (max. 10 minutes) in a rate-limit directory on the server and discarded automatically thereafter.

Purpose: handling your enquiry and preparing or fulfilling a lodging contract.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual / contractual measures); Art. 6(1)(f) GDPR for the anti-abuse element.
Retention: until your enquiry has been finally processed. In the event of a booking, until the expiry of statutory retention periods (in particular 7 years under § 132 of the Austrian Federal Fiscal Code).

4. Processors

The following service providers process personal data on our behalf:

5. Third-party services embedded

Cloudflare as CDN/proxy

All traffic to this website is delivered through Cloudflare's infrastructure. This means every request – including your IP address, the path requested and HTTP headers – is first processed by a Cloudflare edge server (usually within the EU, e. g. Frankfurt) before being forwarded to our hosting server. Cloudflare uses this data to provide CDN, caching, security and performance services and for "Network Error Logging" (NEL), which produces anonymised reports on network or connectivity failures.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, fast and reliable operation).
Transfer to the USA: based on SCC and the EU-US Data Privacy Framework.

Cloudflare Web Analytics

For reach measurement we use Cloudflare Web Analytics. This service operates without cookies and without fingerprinting. Only anonymised data on pages viewed, approximate location (country/region), dwell time and referrer is collected. Individual visitors cannot be identified. Data is evaluated in aggregate only.

Legal basis: Art. 6(1)(f) GDPR. cloudflare.com/web-analytics

Cloudflare Email Address Obfuscation

On every page of this website Cloudflare automatically replaces our email address with an encrypted placeholder, which is decrypted by a short JavaScript snippet only when a visitor clicks. This is for spam protection; no additional visitor data is transmitted to Cloudflare.

Fonts

The fonts used on this site ("Cormorant Garamond" and "Jost") are self-hosted on our server. No data is transmitted to third parties when loading them.

Google Maps

A Google Maps embed (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company Google LLC, USA) is used on this site. The map only loads after your active confirmation ("Load map" button). Only then is data (including your IP address) transmitted to Google. If you have given consent, your choice is remembered client-side in your browser's LocalStorage under the key maps-consent-v1, so you don't have to confirm again on future visits. You can revoke this consent at any time via your browser settings (clearing site storage). Legal basis: Art. 6(1)(a) GDPR (consent). Transfer to the USA: SCC and EU-US Data Privacy Framework. Google privacy policy

External platform links (Google & Booking.com)

The footer and the testimonials section contain links to our verified Google Business profile, the Google Maps location page and our Booking.com listing. These links are embedded statically — no automatic data transfer takes place when you simply load our page. Only when you actively click one of these links will you be redirected to the respective platform, where their own privacy policies apply: Google privacy policy · Booking.com privacy policy.

Legal basis: Art. 6(1)(a) GDPR (consent by active click).

Publication of guest reviews

In the "What our guests say" section we quote publicly accessible reviews that our guests themselves posted on Booking.com or Google. For each review we display the (first) name chosen by the reviewer, the country, the platform and the date together with the original review text. The data is copied directly from the respective profiles and updated manually (no automatic API fetch).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in transparent external representation). Reviewers have agreed to general visibility by publishing on the platform in question.
Objection: Should you wish to have your review removed from this website, an informal message to [email protected] is enough — we will delete the review from our site without delay (the original on Booking/Google remains untouched).

WhatsApp link

The booking form and the mobile footer contain a link to a direct WhatsApp chat (wa.me/4367761701082). Only if you actively click this link will you be redirected to WhatsApp Ireland Ltd. (4 Grand Canal Square, Dublin 2, Ireland; parent company Meta Platforms, Inc., USA). How WhatsApp processes the data transmitted in this case (at least: IP address, phone number when a message is sent, device information) is set out in the WhatsApp privacy policy for the EEA. Legal basis: Art. 6(1)(a) GDPR (consent by active click).

6. Cookies and browser storage

This website does not set any cookies – neither technical nor tracking or analytics cookies. The only data stored in your browser's LocalStorage are the following technically necessary entries:

Both entries are purely client-side, are never transmitted to our server and can be removed by you at any time via your browser settings (clear site data).

6a. Data transfer to third countries

Where personal data is transferred to the USA through the third-party services listed above (Cloudflare, Google Maps, WhatsApp), this is based on:

Cloudflare, Google and Meta have subscribed to these safeguards. Nevertheless, it cannot be entirely ruled out that US authorities may demand access to personal data on the basis of US legislation (e. g. FISA 702, CLOUD Act).

7. Your rights

You have the following rights with regard to the data we hold about you:

To exercise your rights, an informal message to [email protected] is sufficient.

8. Right to complain to the supervisory authority

Österreichische Datenschutzbehörde (Austrian Data Protection Authority)
Barichgasse 40-42
1030 Vienna
Phone: +43 1 52 152-0
Email: [email protected]
Web: www.dsb.gv.at

9. Data security

Data is transmitted via a TLS/SSL-encrypted connection (HTTPS), recognisable by the padlock symbol in your browser bar.

10. Changes to this privacy policy

We reserve the right to adapt this privacy policy, for instance when the legal situation or our processing operations change. The version published on this page applies.

Last updated: 16 May 2026