Useful information
Privacy notice
Find out how data is processed when you visit our website, send an enquiry or make a booking, and who to contact with questions.
Controller responsible for processing your data
Weinberger Hotelbetriebs GmbH
Turracher Höhe 338864 Stadl-Predlitz
Austria
Phone: +43 4275 8234
Email: info@schlosshotel-seewirt.com
Visiting the website
When you visit the website, connection data such as your IP address and requested content is processed to display the page. The application also logs the request path, time, response status and processing duration. Security measures limit repeated requests using the IP address. This processing supports reliable operation and protection against misuse. Its legal basis is our legitimate interest in these purposes under Article 6(1)(f) GDPR.
Fonts, images and the directions map are loaded from our website. The map is a local graphic; an external route planner opens only when you follow its link. The external booking application uses its own resources.
Contact and enquiries
When you contact us, we process your contact details and message to respond. Room enquiries also include travel dates, room preferences, the number of guests and, where relevant, children’s ages. Event enquiries include the occasion, number of guests, preferred date and, where relevant, company. Information marked as required is needed to process the enquiry. The relevant form cannot be submitted without it; you can also contact us by phone.
Enquiries are stored in our database. When email delivery is configured, the responsible hotel staff receive a message and you receive an acknowledgement. An acknowledgement is not a binding booking confirmation. Our enquiry forms do not make automated booking decisions.
Article 6(1)(b) GDPR applies to enquiries related to a contract. Other enquiries are processed under Article 6(1)(f) GDPR, based on our interest in answering questions addressed to us. Sending an enquiry does not require marketing consent.
Recipients and retention
Your information is handled by the hotel staff responsible for your enquiry. Technical service providers may process data to operate the website, database, email delivery or booking system. Further information about individual services appears below.
Retention depends on the purpose and subsequent course of your enquiry: responding to your request, any resulting booking and, where applicable, legal retention obligations or the establishment and defence of claims. For newsletters, the relevant criteria are your subscription, withdrawal and the necessary evidence of consent. A contact enquiry is not necessarily subject to the same periods as a booking or invoice record. Please contact us for information about the particular data stored about you.
Newsletter
When you subscribe to the newsletter, we store your email address, your name if provided, and subscription and confirmation data. A confirmation link ensures that the subscription is activated only after you confirm it. The legal basis is your separate consent under Article 6(1)(a) GDPR. You can withdraw it at any time by contacting us. Subscribing is independent of making a booking or enquiry.
External booking service
The booking page loads the HUGO booking application through booking.s9.hotellogin.cloud and s9.hotellogin.cloud. The external service receives technical connection data. Travel, contact and booking details entered there are processed in the hotel system to provide availability and booking services. Article 6(1)(b) GDPR applies to information related to a contract.
The booking form is a separate application with its own resources. Its use is independent of consent to advertising or audience measurement. Please contact us with questions about your booking data processed there.
Cookies and your choices
The necessary cookie “cc_cookie” stores your analytics and marketing choices, including the consent record, for 182 days. This allows your decision to be respected on later visits. You can change it at any time through “Cookie settings”.
Analytics and marketing are initially disabled. Optional services are used only when configured and with the consent required for each service. Consent-based processing relies on Article 6(1)(a) GDPR. The exception in section 165(3) of the Austrian Telecommunications Act 2021 applies to technically necessary storage of an expressly requested setting. Recording consent fulfils our evidence obligations under Article 6(1)(c) in conjunction with Article 7(1) GDPR.
Email delivery through Resend, when configured
Resend is supported for form notifications and confirmation emails. When this service delivers an email, Plus Five Five, Inc. receives the recipient address and message content. The purpose and legal basis follow the relevant enquiry or newsletter subscription.
Resend’s processing terms describe primary processing in the United States and standard contractual clauses for relevant transfers. Even if the website is hosted in Europe, emails are not necessarily processed exclusively in Europe.
Cloudflare Turnstile, when configured
Cloudflare Turnstile may be used to protect forms against automated misuse. When enabled, Cloudflare, Inc. processes technical signals such as IP address, browser characteristics and the website visited. Article 6(1)(f) GDPR is the basis for protecting our forms; our interest is preventing automated and abusive requests.
Cloudflare describes processing on our behalf to secure the website and separate processing for its own improvement of bot detection. Details are provided in Cloudflare’s additional privacy notice. Turnstile is a security service and does not constitute marketing consent.
Optional analytics and advertising
Support for Google Analytics, Google Ads, Meta and LinkedIn is prepared for audience measurement and advertising attribution. This does not mean that these services are active on every visit. The relevant requests are not triggered without a configured service and your appropriate consent.
When a service is enabled and you consent, page views, interactions and successful enquiries, together with browser, device and cookie identifiers, may be processed for measurement or advertising attribution. Server-side attribution to Meta may additionally transmit hashed contact details, IP address and browser information. LinkedIn may receive email addresses in hashed form and first and last names in plain text, with company details added for event enquiries. Hashes are not anonymous data.
These services may also process data outside the European Economic Area. The providers’ information on data use, roles and transfer terms is linked below. Our consent-based transfers rely on Article 6(1)(a) GDPR.
Changing or withdrawing consent
You can change your choices in the cookie settings and withdraw consent for the future. Further consent-dependent requests made by our own code are then stopped and technically accessible cookies are deleted. This does not retrieve data already transmitted. Third-party scripts already loaded may remain within the open page; our website cannot fully remove cookies belonging to other domains. Clearing browser data and reopening the page helps apply the changed settings to that session.
Withdrawal does not affect the lawfulness of processing carried out beforehand. For requests concerning personal data already transmitted, you can contact us or the relevant provider.
Your rights
Subject to the applicable legal conditions, you can request access, rectification, erasure, restriction of processing and data portability. You can object to processing based on legitimate interests for reasons relating to your particular situation, and you can object to direct marketing at any time. Please use the contact details above.
You may also complain to a data protection supervisory authority, in particular the Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, Austria, email dsb@dsb.gv.at.