Privacy Policy - Vivea Gesundheitshotels
MENÜ
logo menu

Privacy Policy

We are pleased that you use our online offer and inform yourself during or after your stay at one of our health hotels. We take the protection of your privacy and your personal data very seriously. We have implemented technical and organisational measures in place in order to ensure that the provisions on data protection are complied with by us as well as by external service providers. This Data Protection Policy shows which data we collect and for which purpose we use such data. The Data Protection Declaration applies regardless of the domains, systems, platforms and end devices used.  

The processing of your personal data is of course in accordance with the provisions of the General Data Protection Regulation (GDPR) and the Data Protection Act. 

Below we inform you about us the responsible for the data processing as well as type, scale and purpose of the data collection:  

1. The Controller for the data processing is:

Name/co: Mag. Engelbert Künig, Künig GmbH
Address:  Maximilianstraße 7
Postcode, location, country: 6330, Kufstein, Austria
Commercial Register/No. 216022f
Telephone number: +43 5372 90500
E-mail address: info@vivea-hotels.com

Immediately before, during or also after your stay at one of our health hotels, you are welcome to contact the reception and, if you have any questions about the processing of your personal data, the management of the health hotel.

2. Legal Basis for the processing

Within our online offers we process personal data of the users, includes inventory data (e.g. names and addresses of customers), contractual data (e.g. services used, names of clerks, payment information), usage data (e.g. the websites of our online offer visited, interest in our products) and content data (e.g. entries in the contact form).

The term “user” covers all categories of data subjects and includes all genders. “Users” include our customers, business partners and other visitors to our online offer.

The legal basis for the data processing:

  • Agreement (Art. 6 (1) point (a)  GDPR)
  • Processing for performance of our services and execution of contractual measures (Art. 6(1) point (b) GDPR)
  • Compliance with our legal obligation (Art. 6(1) point (c) GDPR)
  • Processing in order to safeguard our legitimate interests of the controller or a third party in which the interests or fundamental rights and freedoms of the data subject do not prevail  (Art. 6(1) point (f) GDPR).

3. SSL Encryptions / Security

This website uses an SSL encryption for security reasons and in the interests of protecting confidential content, such as any orders or enquires you may send to us as the website operator. You can recognise an encrypted connection by the address line in the browser changing from “http://” to “https://” and by the lock symbol in the browser line. Thus, the data you transmit to us cannot be accessed by third parties. Furthermore, in the course thereof, the personal data processed by us is to be protected against accidental or deliberate manipulation, destruction, loss or against access by unauthorised persons. 

4. Forwarding of data to third parties

We will only use your personal data within our company. 

To the extent data is transferred to service providers in the course of data processing, we also oblige such service providers to comply with the GDPR. We disclose your data to bodies entitled to receive such information exclusively if we are obliged thereto by applicable laws or a court orders.

5. Provision of contractually-agreed services

Users can optionally set up a user account in certain areas of our website in which they can access their orders (e.g. vouchers, online bookings etc.). This user account is not public and cannot be retrieved by search engines. If you cancel your user account, the data relating to your account are deleted unless their retention is required based on commercial or tax law.

In case of registration and subsequent log-ins as well as the use of our online services, we save the IP address and the time of the user action.

6. Contacting us

If you contact us (via online contact form or email), your user information shall be processed for the purpose of handling the contact request.

7. Access data and log files

We collect and store information based upon our legitimate interests in server log files which your browser automatically transmits to us. This information includes the following: browser type and version, operating system used, referrer URL, host name of the accessing computer, time of the server request as well as your IP address. 

Log file information shall be stored for a maximum of seven days for security reasons (e.g. clarification of acts of misuse or fraud) and shall be erased afterwards. Data which must be retained for longer periods for the purpose of providing proof are exempted from erasure until the respective incident has been definitively resolved. This data is not combined with other data sources.

8. Cookies

Some of our websites use of “cookies”. Cookies are small text files which allow for storing specific device-related information on the access device of the users (PC, smartphone or the like). On the one hand, their purpose is to improve the user-friendliness of our websites, thus providing a better experience to the users (e.g. storage of log-in data). On the other hand, they are used to allow for storing statistical data on the use of our website and analysing it in order to improve the offer. Cookies do not harm your computer and do not contain any viruses. Cookies serve the purpose of making our website more user-friendly, effective and secure.

Most cookies used by us are “session cookies”. These are deleted automatically at the end of your visit. Other cookies are stored on your end device until you delete them. These cookies allow us to recognise your browser upon your next visit to our website.

You can set your browser to inform you about cookies being placed and to only allow cookies on a case-by-case basis, to refuse cookies in certain cases or in general, and to activate the automatic deletion of cookies when you close the browser. Deactivating cookies may limit the full functionality of this website.

You can manage or deactivate many online display cookies of companies via the US-American page www.aboutads.info/choices or the EU page www.youronlinechoices.com/uk/your-ad-choices/.

9. Analysis Tool – Google Analytics

(1) This website uses functions of Google Analytics, a web analysis service provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. (“Google”). Google Analytics uses "cookies”, small text files that are stored on the users’ computers which enable an analysis of how they use our website.  Information generated by the cookies on the usage of the online services by users is generally transferred to Google servers in the USA where it is saved. The Google Analytics cookies are stored on the basis of Art. 6(1) point (f) GDPR. 

(2) We have a legitimate interest in the analysis of the user behaviour in order to optimise both web offers and advertisements.

(3) Google will use this information on our behalf to analyse the usage of our online services by the users, compile reports on the activities within these online services and to provide further services to us which are connected to the usage of these online services and Internet usage. 

(4) We use Google Analytics to show ads which are provided by Google web services and their partners only to those users who have shown interest in our online services or have certain characteristics (e.g. interest in contents or products which is determined based on visited web pages) which we transmit to Google (referred to as “remarketing” or “Google Analytics audiences”). With the help of remarketing audiences, we would also like to ensure that our ads correspond to users’ potential interest and do not constitute an annoyance.

(5) We have activated the IP anonymisation function on this website. This means that your IP address is abbreviated by Google within European Union member states or other states party to the Agreement on the European Economic Area before it is transmitted to the US. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there.

(6) On behalf of the provider of this website, Google uses this information to analyse your use of the website, to compile reports about the website activity and to provide further services which are connected to the use of this website and of the Internet for its operator. The IP address transmitted by your browser in the context of Google Analytics is not combined with other data from Google.

(7) You can prevent the storage of cookies by changing the settings of your browser software accordingly (browser plug-in: tools.google.com/dlpage/gaoptout. Please note, however, that if you do so, you may not be able to use all of the functions of this website to their fullest extent. 

(8) Further information on Google’s use of data as well as possible ways of objection can be found at the following Google links:

https://www.google.com/intl/de/policies/privacy/partners (Data usage by Google if you use the websites or apps of our partners)
http://www.google.com/policies/technologies/ads (Data usage for marketing purposes)
http://www.google.de/settings/ads (Manage information used by Google to display advertising to you).

(9) Google is certified according to the Privacy Shield Agreement and thus guarantees compliance with the European Data Protection Legislation https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active

10. Marketing Tool – Google Remarketing 

(1) Our websites use the functions of Google Analytics Remarketing in connection with functions of Google AdWords across devices. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. (“Google”)

(2) These functions enable us to display advertising to our users on our website in a more targeted manner so that, for example, interest-based, customised advertising messages which were adjusted based upon your use and surfing behaviour using one device in the past (e.g. mobile phone) can be displayed on another end device used by you (e.g. tablet or PC). 

(3)  If e.g. ads are displayed for products in which a user has already shown interest in on other webpages, this is called remarketing. For these purposes, a web beacon (Google code) is executed and embedded within the website directly by Google when our or other websites on which Google tools are active are accessed. With the help of these tags, an individual cookie, i.e. a small file, is saved on the users’ device (instead of cookies other comparable technologies may also be used). 

(4) Every Google AdWords customer gets a different cookie. These cookies cannot be tracked via the websites of AdWords customers. The information collected in the course thereof (by means of conversion cookies) are used to create conversion statistics. I.e. we only learn the total number of users who clicked on an ad. These statistics, however, do not receive any information which can be used to identify users personally. 

(5) In addition, the users’ IP address is recorded. In this regard, we inform you within the scope of Google Analytics that the IP address is abbreviated in EU member states or other states party to the Agreement on the European Economic Area and is only transmitted as a whole to a Google server in the USA and abbreviated there in exceptional cases. The IP address will not be combined with any user data within other services provided by Google. Google may connect the above information to corresponding information from other sources. If the user subsequently visits other web pages, ads which are adjusted to their interests can be displayed.

(6) If you do not want to participate in the tracking, you can object to this use at any time by simply deactivating the Google conversion tracking cookie via your Internet browser under user settings. Thus, you will not be included in the conversion tracking statistics.

(7) For further information on data use for marketing purposes by Google, please refer to the overview page at: https://www.google.com/policies/technologies/ads, Google’s Privacy Notice can be viewed at https://www.google.com/policies/privacy.

(8) If you wish to object to interest-related advertising by Google Marketing Services, you can use the setting and opt-out options provided by Google at: www.google.com/ads/preferences.

(9) Google is certified according to the Privacy Shield Agreement and thus guarantees compliance with the European Data Protection Legislation

11. Facebook plug-ins (Like & Share buttons)

(1) This website uses plug-ins of the social network Facebook (provider Facebook Inc., 1 Hacker Way, Menlo Park, California 94025, USA). You can recognise these Facebook plug-ins by the Facebook logo or the “Like button” on our website. An overview of the Facebook plug-ins is available at: developers.facebook.com/docs/plugins/.

(2) When you visit our websites, the plug-in establishes a direct connection between your browser and the Facebook server. In this way, Facebook receives the information that you visited our website with your IP address. When you click the Facebook “Like button” while you are logged into your Facebook account, you can link the contents of our websites to your Facebook profile. If you do so, Facebook will be able to assign the visit of our websites to your user account. Please note that as provider of the websites, we have no knowledge of the content of the data transmitted to or of its use by Facebook. For more information, please refer to the Facebook privacy policy at: de-de.facebook.com/policy.php.

(3) If you do not want Facebook to be able to assign the visit to our websites to your Facebook user account, please log out of your Facebook user account and please delete your cookies. 

(4) Facebook is certified according to the Privacy Shield Agreement and thus guarantees compliance with the European Data Protection https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active

(5) Further settings and objections to the use of data for marketing purposes are possible in the Facebook profile settings at:  www.facebook.com/settings;

12. Google+ plug-in – Google+ button

(1) This website uses Google+ functions. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. You recognise the Google+ plug-in by the G+ logo on our website.

(2) By means of the Google+ push button, you can publish information worldwide. Via the Google+ push button, you and other users receive personalised contents from Google and our partners. Google stores both, the information that you gave +1 for a content and information about the website that you viewed when clicking +1. Your +1 can be shown as reference together with your profile name and your photo in Google services, e.g. in search results or in your Google profile, or at other places on websites and advertisements on the Internet.

(3) Google records information about your +1 activities in order to improve the Google services for you and others. In order to be able to use the Google+ push button, you need a globally visible, public Google profile, which must at least contain the name selected for the profile. This name is used in all Google services. In some cases, this name may also replace another name that you used while sharing contents using your Google account. The identity of your Google profile may be shown to users who know your email address or have other pieces of identifying information about you.

(4) In addition to the purposes of use explained above, the information provided by you will be used according to the applicable Google data protection regulations.

13. Instagram plug-in

(1) This website uses Instagram functions. These functions are provided by Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA. You can recognise the Instagram button by the Instagram camera symbol.

(2) If you are logged into your Instagram account, you can link the content of our pages with your Instagram profile by clicking this Instagram button. If you do so, Instagram will be able to assign the visit of our pages to your user account. Please note that as provider of the website, we have no knowledge of the data transmitted to or of its use by Instagram.

(3) For further information, please refer to the Instagram privacy policy at: https://instagram.com/about/legal/privacy/

14. Facebook pixel 

(1) Within our online offer, we use the “Facebook pixel” of the Facebook social network based upon our legitimate interests in analysing and optimising our online offer. Facebook is operated by Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA, or, if you are an EU resident, Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland ("Facebook”). 

(2) Facebook is certified according to the Privacy Shield Agreement and thus guarantees compliance with the European Data Protection Legislation: www.privacyshield.gov/participant

(3) In this way, the behaviour of website visitors can be monitored after they were forwarded to the provider’s website by clicking on a Facebook advert. Thus, the effectiveness of the Facebook adverts can be evaluated for statistical and market research purposes and future marketing measures can be optimised.

(4) We as operator of this website receive the data collected in an anonymous form, we cannot draw any conclusions about the identity of the users. However, the data is stored and processed by Facebook so that a connection with the respective user profile is possible and Facebook can use the data for its own marketing purposes in accordance with Facebook’s data use policy. Thus, Facebook is enabled to show adverts on Facebook pages as well as outside Facebook. We as operator of this website cannot influence such data use.

(5) Facebook processes data based on their data use policy. You can find further information on the protection of your privacy in the Facebook data protection notices at: https://www.facebook.com/about/privacy/

(6) For specific information and details on the Facebook pixel and its function, please refer to the Facebook help area at: https://www.facebook.com/business/help/651294705016616.

(7) You can object to the data collection by the Facebook pixel and to the use of your data for the displaying of Facebook ads at: https://www.facebook.com/settings?tab=ads

15. Newsletter

(1) By subscribing to our newsletter offered on our website, you agree to receive the newsletter and to the described procedure.

(2) We send newsletters, emails and other electronical notifications which include advertising information exclusively with the consent of the recipients or with statutory permission. Furthermore, our newsletters contain information about our current offers, news and promotions of our companies.

(3) Subscriptions to our newsletter are solely based on a double opt-in procedure. This means that after subscription via the contact form, you will receive an email in which you are asked to confirm your subscription. This confirmation is required so that no person can register with another person’s email address or impersonate you. Newsletter subscriptions will be logged to be able to provide proof of the subscription process according to the legal requirements. This includes the saving of the subscription and confirmation time as well as the IP address. In addition, changes to your data which are stored with the marketing service are logged.

(4) Marketing service: Newsletters are sent by “mailingwerk”, an Austrian newsletter distribution platform. The data protection provisions of the distribution service provider can be viewed at: https://www.netwerk.at/datenschutz

(5) Our newsletters contain web beacon (a small file which is requested by the server of the distribution service provider when you open the newsletter). Technical information such as information on your browser and system as well as your IP address and the time of retrieval is recorded therein. This information is used for technical improvement of the services. These statistical purposes also include the determination whether the newsletter is opened, when it is opened and which links within the newsletter are clicked.

(6) The use of the distribution service provider, the performance of the statistical determinations and analyses as well as logging of the subscription process take place on the basis of our legitimate interests in accordance with Art. 6(1) point (f) GDPR. Our interest is oriented towards the use of a user-friendly and secure newsletter system which serves our business interests and meets the expectations of the users.

(7) Unsubscription/withdrawal – you can unsubscribe from our newsletter at any time. Thus, your consents to distribution thereof by the distribution service provider and to the statistical analyses become invalid at the same time. Unfortunately, separate withdrawal of distribution by the distribution service provider or statistical evaluation is not possible. A link to end your subscription to the newsletter can be found at the end of each newsletter. After unsubscribing, your personal data will be deleted.

16. Distribution of brochures 

(1) You can subscribe for free distribution of brochures on our website via a corresponding contact form. Subscriptions for the distribution of brochures will be logged to be able to provide proof of the subscription process according to the legal requirements. This includes the saving of the subscription and confirmation time as well as the IP address. 

(2) The data you provide will be used exclusively for the distribution of brochures as requested by you and not disclosed to third parties. 

(3) After expiry of the guarantee, warranty, limitation and statutory retention periods to which we are subject, and, where applicable, until conclusion of any legal disputes for which such data is needed as legal evidence, your data will be erased. 

17. Non-binding requests or the like 

(1) You can send a non-binding request to the Vivea health hotel you are interested in via our website using a corresponding contact form. The requests will be logged to be able to provide proof of the registration process according to the legal requirements. This includes the saving of the registration and confirmation time as well as the IP address. 

(2) The data you provide will be used exclusively for the request made by you and not disclosed to third parties. 

(3) After expiry of the guarantee, warranty, limitation and statutory retention periods to which we are subject, and, where applicable, until conclusion of any legal disputes for which such data is needed as legal evidence, your data will be erased. 

18. Third-party contents & services

(1) Based on our legitimate interests (i.e. interest in the analysis, optimisation and economic operation of our online services in accordance with Art. 6(1) point (f) GDPR), service offers of third-party providers are embedded on our website. As a prerequisite, the third-party providers of this content need to know the users’ IP address since they would otherwise not be able to send the content to the users’ browser. The IP address is therefore required to display the content. Third parties may use, inter alia, pixel tags (web beacons) for statistical or marketing purposes. Using such pixels, information such as visitor traffic on the pages of this website can be analysed. The pseudonymous information can also be saved as cookies on the users’ device; among other data, they may contain technical information on the browser and operating system, referring web pages, access time and other information on the use of our online services and it can be linked to such information from other sources.

(2) Below, you find an overview of the third-party providers engaged by us as well as their contents and the corresponding links to the respective data protection declarations:

Privacy notice: https://www.google.com/policies/privacy/
Opt-out: https://www.google.com/settings/ads/

  • Maps provided by the “Google Maps” service of the third-party provider Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
  • Videos provided by the “YouTube” platform of the third-party provider Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. 
  • LinkedIn: The provider is LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA. Whenever you access one of our websites that contains functions of LinkedIn, a connection will be established to the LinkedIn servers. LinkedIn is informed that you visited our websites with your IP address. If you click on the “Recommend button” of LinkedIn and are logged into your account with LinkedIn, LinkedIn is able to assign your visit to our website to you and to your user account. Please note that as provider of this website, we have no knowledge of the content of the data transmitted to or of its use by LinkedIn. 
  • XING: The provider is XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany. Whenever you access one of our websites that contains functions of XING, a connection will be established to the XING servers. According to our knowledge, no personal data will be stored in this process. In particular, no IP addresses will be stored and no analysis of the usage behaviour will take place. 
  • Web analysis and optimisation by means of the Hotjar service (third-service provider Hotjar Ltd., Level 2, St Julians Business Centre, 3, Elia Zammit Street, St Julians STJ 1000, Malta, Europe). By means of Hotjar, we can track movements on the websites on which Hotjar is used (“heatmaps”). Thus, for example, we can see how far the users scroll and how often they click on which buttons. Furthermore, technical data such as language chosen, system, screen resolution and browser type are collected. In the course thereof, profiles of the users can be created at least temporarily during the visit to our websites. Furthermore, Hotjar also enables us to obtain feedback directly from the users of the website. In this way, we obtain valuable information in order to make our website even faster and more customer-friendly. 

Data protection declaration: www.hotjar.com/privacy. Opt-out: https://www.hotjar.com/opt-out

  • Web Widgest from the HolidayCheck AG, Bahnweg 8, CH-8598 Bottighofen, Schweiz
    Web widgets (widgets -> things) are small programs, that are integrated into the website and display information from other websites. The content that is displayed on our website (rating / recommendation rate) is always retrieved from the HolidayCheck servers. To ensure that this function works properly, data must be exchanged between the two servers involved, including date and time of the visit; the page from which the query is made; IP adress, browser type and browser version, device type, operating system and similar technical informations. By providing this service, we deliver up-to-date and correct content on our homepage. The processed data is only intended to provide the content or transmission of data that you provide when you submit a rating directly to our website. They are not processed otherwise, in particular not to analyze any usage behavior. The data will not be stored by us as part of this processing.

Privacy notice: www.holidaycheck.de/datenschutz

  1. Web-Widgets from the Customer Alliance GmbH, Ullsteinstr. 118 | Turm B, DE-12109 Berlin, Deutschland

Privacy notice: https://www.customer-alliance.com/de/datenschutzbestimmug

19. User rights

(1) Upon request, users are entitled to obtain free access to information on the personal data we store about them.

(2) With reference to such request for access, we point out that the right to request information on the data processed about you as data subject in accordance with Art. 15 GDPR is a personal right. Accordingly, we are obliged to obtain and document proof of your identity. This shall particularly ensure that only you as data subject are provided with information on your data, thus, helping us in preventing misuse of the right of access.

(3) After receiving your proof of identity, we will comply with your request without undue delay. The legal period under Art. 12 GDPR of one month for the provision of information only starts upon receipt of a valid proof of identity.

(4) In addition, users are entitled to rectification of inaccurate data, restriction of processing and erasure of their personal data, where applicable, assert their rights to data portability and, if unlawful data processing is assumed, lodge a complaint with the competent supervisory authority. 

(5) Moreover, users can, generally with effect for the future, withdraw consents.

20. Erasure of data

(1) The data stored by us will be erased as soon as it is no longer required for its purpose and the erasure does not conflict with any legal storage obligations. If the users’ data is not erased, since it is required for other purposes which are permitted by law, its processing will be restricted. I.e. the data is blocked and not processed for any other purposes. This applies e.g. to data which has to be retained due to commercial law or tax law.

(2) According to statutory provisions, data is retained for 6 years as per Art. 257, para. 1 HGB [Austrian Commercial Code] (trading books, inventories, opening balance sheets, annual financial statements, business letters, accounting records, etc.), for 10 years as per Art. 147, para. 1 AO [Austrian Fiscal Code] (books, records, management reports, accounting records, commercial and business letters, documents which are relevant for taxation, etc.) 

21. Right to object

Users can object to the future processing of their personal data according to the legal requirements at any time. The right to object refers in particular to the processing for direct marketing purposes.

22. Changes to the Data Protection Declaration

(1) We reserve the right to amend this Data Protection Declaration in order to adapt it to amended legal provisions or to changes to the service as well as data processing. However, this only applies with regard to statements on data processing. To the extent consents of the users are required or parts of the Data Protection Declaration contain provisions of the contractual relationship with the users, the changes are exclusively made subject to the consent of users.

23. Disclaimer

(1) Liability for contents 

The contents on our websites were prepared with utmost care. However, we cannot assume any liability for the correctness, completeness and topicality of the contents. As service provider, we are responsible for our own contents on these websites according to the general legislation. Nonetheless, service providers are not obliged to monitor third-party information transferred or retained by them or to search for circumstances indicating any illegal activity. Obligations to remove or block the use of information in accordance with general legislation remain unaffected hereof. However, any liability in this respect can only be assumed as from the date of knowledge of a specific infringement. Once we become aware of such infringements, we will remove these contents immediately.

(2) Liability for links

Our offer contains links to external third-party websites, on the contents of which we do not have any influence. We therefore cannot accept any liability for such third-party content. The provider or operator of linked websites is responsible for their content. The linked websites were reviewed for potential legal violations at the time of linking. No unlawful content was identifiable at the time of linking. However, we cannot reasonably be expected to permanently monitor the content of linked websites without concrete indications of an infringement. If we become aware of infringements, we will remove such links immediately.

rotate