Data privacy statement
Information in accordance with the EU General Data Protection Regulation (GDPR)
We are very pleased about your interest in our company. Data privacy is particularly important to the Aparthotel Steger, The Steger Family.
By means of this data privacy statement, our company would like to inform the public about the type, scope and purpose of the personal data collected, used and processed by us. Furthermore, the persons concerned are informed about their rights by means of this data privacy statement.
1. Definitions
We use the following terms, among others, in this data privacy statement:
a) Personal data
Personal data is all information relating to an identified or identifiable natural person (hereinafter referred to as the "person concerned"). An identifiable person is a natural person who can be identified directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier or to one or more specific characteristics that are expressions of the physical, physiological, genetic, psychological, economic, cultural or social identity of that natural person.
b) Person concerned
The person concerned is any identified or identifiable natural person whose personal data is processed by the responsible party.
c) Processing
Processing is any procedure or series of procedures involving personal data, carried out with or without the help of automated methods, such as collection, capture, organisation, arrangement, storage, adaptation or alteration, selection, retrieval, use, disclosure by transmission, dissemination or any other form of provision, comparison or linkage, restriction, deletion or destruction.
d) Processing restriction
Processing restriction is the marking of stored personal data with a view to restricting its future processing.
e) Profiling
Profiling is any kind of automated processing of personal data, which consists of using this personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects of the natural person's work performance, economic situation, health, personal preferences, interests, reliability, behaviour, place of residence or relocation.
f) Pseudonymisation
Pseudonymisation is the processing of personal data in such a way that the personal data can no longer be attributed to a specific person concerned without further information, provided that such additional information is stored separately and is subject to technical and organisational measures that ensure that the personal data is not attributed to an identified or identifiable natural person.
g) Responsible party or party responsible for processing
The responsible party or party responsible for processing is the natural or legal person, authority, institution or other body, which, alone or together with others, decides on the purposes and means of processing personal data. If the purposes and means of this processing are prescribed by EU law or by the law of the member states, the responsible party may, in accordance with EU law or the law of the member states, stipulate the specific criteria for its designation.
h) Assigned processor
An assigned processor is a natural or legal person, authority, institution or other body that processes personal data on behalf of the responsible party.
i) Recipient
A recipient is a natural or legal person, authority, institution or other body to which personal data is disclosed, regardless of whether or not it is a third party. However, authorities that may receive personal data in the context of a specific investigation mandate according to EU law or the law of a member state law shall not be considered to be recipients.
j) Third party
A third party is a natural or legal person, authority, institution or other body other than the person concerned, responsible party, assigned processor and those authorised to process personal data under the direct responsibility of the responsible party or assigned processor.
k) Consent
Consent is any declaration or other unambiguous and informed expression of intent given voluntarily by the person concerned in the form of a declaration or any other clear, unequivocal action by the person concerned that he or she agrees to the processing of personal data concerning him or her.
2. Name & address of the party responsible for processing
The responsible party within the meaning of the General Data Protection Regulation, other data protection laws in force in the member states of the European Union and other provisions dealing with data protection is:
Aparthotel Steger
The Steger Family
Wagrainer Straße 33
5602 Wagrain
Austria
Phone: +43 (0)6413 20110
Email: info@steger.co.at
www.steger.co.at/en
3. Cookies
4. Website analysis
This website uses Google Analytics, a web analytics service provided by Google Inc. ("Google"). Google Analytics uses "cookies", which are text files placed on your computer to help the website analyse how visitors use the site. The information generated by the cookie about your use of the website will normally be transmitted to and stored by Google on servers in the USA. If IP anonymisation is activated on this website, your IP address will be truncated beforehand within a member state of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the United States and truncated there. Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage. Google will not associate your IP address transferred within the framework of Google Analytics with any other data held by Google. You may refuse the use of cookies by selecting the appropriate settings on your browser, however, please note that if you do this you may not be able to use the full functionality of this website. Furthermore, you can prevent Google's collection and use of data generated by the cookie and related to your use of the website (including your IP address) by downloading and installing the browser plug-in or alternatively clicking on the following link to opt out of cookies: https://tools.google.com/dlpage/gaoptout?hl=de-DE.
You can prevent Google Analytics from collecting your user data on this website only by clicking on the following link. An opt out cookie is set that prevents any future acquisition of your data when visiting our website: Deactivate Google Analytics.
If you delete the cookies in this browser, you have to set the opt out cookie again.
You will find more information on Google Analytics provisions and privacy policy at https://www.google.com/analytics/terms/de.html.
5. Collecting general data and information
The website of the Aparthotel Steger, The Steger Family collects a range of general data and information each time a person concerned or automated system accesses the website. This general data and information is stored in the server's log files. The following may be recorded: (1) the browser type and version used; (2) the operating system used by the accessing system; (3) the website from which an accessing system reaches our website (so-called "referrer"); (4) the sub-websites visited via an accessing system on our website; (5) the date and time of accessing the website; (6) an Internet protocol address (IP address); (7) the Internet service provider of the accessing system; (8) other similar data and information that is used to prevent threats in the event of attacks on our information technology systems.
6. Contact options on the website
"electronic post" (email address). If a person concerned contacts the party responsible for processing via email or a contact form, the personal data transmitted by the person concerned will be stored automatically. Personal data voluntarily provided by a person concerned to the party responsible for processing will be stored for the purpose of processing or contacting the person concerned. This personal data is not passed on to third parties.
7. Routine deletion & blocking of personal data
The party responsible for processing shall only process and store the personal data of the person concerned for the time required to achieve the storage purpose or to the extent provided for by the European body issuing directives and regulations or another legislator in laws or regulations to which the party responsible for processing is subject.
If the storage purpose ceases to apply or if a storage period prescribed by the European body issuing directives and regulations or another competent legislator expires, the personal data is routinely blocked or deleted in accordance with the statutory provisions.
8. Rights of the person concerned
a) Right to confirmation
Every person concerned has the right granted by the European body issuing directives and regulations to ask the party responsible for processing to confirm whether personal data concerning him or her is being processed. If a person concerned wants to use this right of confirmation, he or she can contact our data protection officer at any time.
b) Right to information
Every person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to obtain, at any time and free of charge, information from the party responsible for processing on the personal data relating to him or her stored and a copy of that information. Furthermore, the European body issuing directives and regulations has granted the person concerned the following information:
c) Right to rectification
Any person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to request the immediate correction of inaccurate personal data concerning him or her. Furthermore, taking into account the purposes of the processing, the person concerned has the right to request the completion of incomplete personal data, including by means of a supplementary statement. If a person concerned wants to use this right to rectification, he or she can contact our data protection officer at any time.
d) Right to deletion (right to be forgotten)
Any person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to ask the responsible party to immediately delete any personal data concerning him or her, provided that one of the following reasons applies and insofar as the processing is not necessary:
If the personal data has been released by the Aparthotel Steger, The Steger Family and our company is responsible for deletion of the personal data as the responsible party according to Article 17 Para. 1 DS-GMO, the Aparthotel Steger, The Steger Family shall take appropriate measures, including technical measures, taking into account available technology and implementation costs, to inform other parties responsible for data processing who process the published personal data, that the person concerned has requested the deletion of all links to this personal data or of copies or replications of this personal data from those other responsible parties, insofar as processing is not necessary. The Aparthotel Steger, The Steger Family's data protection officer or another employee will take the necessary steps in individual cases.
e) Right to restriction of processing
Any person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to request that the responsible party restricts the processing if one of the following conditions is met:
f) Right to data transferability
Any person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to receive personal data relating to him or her, which has been provided by the responsible party, in a structured, common and machine-readable format. They also have the right to transmit this data to another responsible party without any obstruction by the responsible party, to whom the personal data has been provided, provided that the processing is based on the consent according to Article 6 Para. 1 Letter a DS-GMO or Article 9 Para. 2 Letter a DS-GMO or on a contract according to Article 6 Para. 1 Letter b DS-GMO and processing is carried out by means of automated procedures, except where processing is necessary for the performance of a task in the public interest or in the exercise of official authority assigned to the responsible party.
Furthermore, in exercising his or her right to data transferability according to Article 20 Para. 1 DS-GMO, the person concerned has the right to effect that the personal data be transferred directly by a responsible party to another responsible party, provided this is technically feasible and provided that the rights and freedoms of other persons are not affected.
To assert the right to data transferability, the person concerned may contact the data protection officer appointed by the Aparthotel Steger, The Steger Family or another employee at any time.
g) Right to objection
Any person concerned with the processing of personal data shall has right granted by the European body issuing directives and regulations to enter an objection at any time to the processing of personal data concerning them according to Article 6 Para 1 Letters e or f DS-GMO for reasons arising from their particular situation. This also applies to profiling based on these provisions.
In the event of revocation, the Aparthotel Steger, The Steger Family will no longer process the personal data unless we can prove compelling legitimate reasons for processing, which outweigh the interests, rights and freedoms of the person concerned, or the processing serves to assert, exercise or defend legal claims.
If the Aparthotel Steger, The Steger Family processes personal data for direct advertising purposes, the person concerned has the right to object at any time to the processing of personal data for the purpose of this kind of advertising. This also applies to profiling if it is in connection with this kind of direct advertising. If the person concerned objects to the Aparthotel Steger, The Steger Family processing for direct advertising purposes, the Aparthotel Steger, The Steger Family will no longer process the personal data for these purposes.
In addition, the person concerned has the right to enter an objection against the processing of personal data concerning him or her carried out by the Aparthotel Steger, The Steger Family, which is done for academic or historical research purposes or for statistical purposes according to Article 89 Para. 1 DS-GMO for reasons arising from their particular situation, unless this processing is necessary to fulfil a task in the public interest.
To exercise the right to objection, the person concerned may contact the Aparthotel Steger, The Steger Family's data protection officer or another employee directly. The person concerned shall also be free to exercise his or her right of objection in relation to the use of information society services by means of automated procedures for which technical specifications are used, regardless of Directive 2002/58/EC.
h) Automated decisions in individual cases, including profiling
Every person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations not to be subject to a decision based exclusively on automated processing, including profiling, which has legal effect against him or her or significantly affects him or her in a similar manner, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the person concerned and the responsible party, or (2) is admissible under the provisions of EU law or those of the member states to which the responsible party is subject and these provisions contain appropriate measures to safeguard the rights, freedoms and legitimate interests of the person concerned or (3) is made with the express consent of the person concerned.
If the decision (1) is required for the conclusion or performance of a contract between the person concerned and the responsible party or (2) is made with the express consent of the person concerned, the Aparthotel Steger, The Steger Family shall take appropriate measures to safeguard the rights, freedoms and legitimate interests of the person concerned, including at least the right to obtain the intervention of a person by the person responsible, to state his or her own position and to challenge the decision.
If the person concerned wishes to assert his or her right relating to automated decisions, he or she may contact our data protection officer at any time.
i) Right to withdraw consent relating to data privacy
Every person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to withdraw consent given to process personal data at any time.
If the person concerned wishes to assert his or her right to revoke his or her consent, he or she may contact our data protection officer at any time.
9. Legal basis for processing
Article 6 I lit. a DS-GVO serves our company as a legal basis for processing operations for which we obtain consent for a specific processing purpose. If processing personal data is necessary for the performance of a contract to which the person concerned is a party, as is the case, for example, with processing operations necessary for the delivery of goods or the provision of other services or consideration, processing is based on Article 6 I lit. b DS-GMO. The same applies to processing operations that are necessary to carry out precontractual measures, for example, in cases of enquiries about our products or services. If our company is subject to a legal obligation that requires the processing of personal data, for example, to fulfil tax obligations, processing is based on Article. 6 I lit. c DS-GMO. In rare cases, processing personal data may become necessary to protect the vital interests of the person concerned or another natural person. This would be the case, for example, if a visitor was injured at our company and his name, age, health insurance data or other vital information had to be passed on to a doctor, a hospital or other third parties. Processing would then be based on Article 6 I lit. d DS-GVO. Ultimately, processing operations could be based on Article 6 I lit. d DS-GVO. Processing operations that are not covered by any of the aforementioned legal bases are based on this legal basis if processing is necessary to safeguard a legitimate interest of our company or a third party, provided that the interests, fundamental rights and freedoms of the person concerned do not prevail. We are entitled to these kind of processing procedures in particular because they have been specifically mentioned by the European legislator. It advocates the view that a legitimate interest could be assumed if the person concerned is a customer of the responsible party (Recital 47, Sentence 2 DS-GMO).
10. Legitimate interests to processing pursued by the responsible party or a third party
If processing personal data is based on Article 6 I lit. f DS-GMO, it is in our legitimate interest to conduct our business activity for the good of all our employees and our shareholders.
11. Duration for which personal data is stored
The criterion for the duration of personal data storage is the respective legal retention period. After the expiry of this period, the corresponding data will be routinely deleted, provided that it is no longer necessary for the fulfilment or initiation of the contract.
12. Legal or contractual provisions for the provision of personal data; necessity for the conclusion of the contract; obligation of the person concerned to provide the personal data; possible consequences of failure to provide it
We inform you that the provision of personal data is partly required by law (e.g. tax regulations) or may also result from contractual regulations (e.g. information on the contractual partner). From time to time, it may be necessary for a contract to be concluded that a person concerned provides us with personal data that must subsequently be processed by us. For example, the person concerned shall undertake to provide us with personal data if our company enters into a contract with him or her. The only consequence of not providing personal information is that the contract will not be able to be concluded with the person concerned. Prior to the provision of personal data by the person concerned, the person concerned must contact our data protection officer. Our data protection officer will inform the person concerned on a case-by-case basis whether the provision of personal data is required by law or contract or necessary for the conclusion of the contract, whether there is an obligation to provide the personal data and what consequences the failure to provide the personal data would have.
13. Existence of automated decision-making
As a responsible company, we abstain from automatic decision-making or profiling.
14. Competent authority
Österreichische Datenschutzbehörde (Austrian Data Protection Authority)
Wickenburggasse 8
1080 Vienna
Austria
dsb@dsb.gv.at
This data protection declaration was created - with the exception of the cookie settings - by the data protection declaration generator of DGD Deutsche Gesellschaft für Datenschutz GmbH, which acts as external data protection officer Freising, in cooperation with the data protection lawyer Christian Solmecke.
By means of this data privacy statement, our company would like to inform the public about the type, scope and purpose of the personal data collected, used and processed by us. Furthermore, the persons concerned are informed about their rights by means of this data privacy statement.
1. Definitions
We use the following terms, among others, in this data privacy statement:
a) Personal data
Personal data is all information relating to an identified or identifiable natural person (hereinafter referred to as the "person concerned"). An identifiable person is a natural person who can be identified directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier or to one or more specific characteristics that are expressions of the physical, physiological, genetic, psychological, economic, cultural or social identity of that natural person.
b) Person concerned
The person concerned is any identified or identifiable natural person whose personal data is processed by the responsible party.
c) Processing
Processing is any procedure or series of procedures involving personal data, carried out with or without the help of automated methods, such as collection, capture, organisation, arrangement, storage, adaptation or alteration, selection, retrieval, use, disclosure by transmission, dissemination or any other form of provision, comparison or linkage, restriction, deletion or destruction.
d) Processing restriction
Processing restriction is the marking of stored personal data with a view to restricting its future processing.
e) Profiling
Profiling is any kind of automated processing of personal data, which consists of using this personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects of the natural person's work performance, economic situation, health, personal preferences, interests, reliability, behaviour, place of residence or relocation.
f) Pseudonymisation
Pseudonymisation is the processing of personal data in such a way that the personal data can no longer be attributed to a specific person concerned without further information, provided that such additional information is stored separately and is subject to technical and organisational measures that ensure that the personal data is not attributed to an identified or identifiable natural person.
g) Responsible party or party responsible for processing
The responsible party or party responsible for processing is the natural or legal person, authority, institution or other body, which, alone or together with others, decides on the purposes and means of processing personal data. If the purposes and means of this processing are prescribed by EU law or by the law of the member states, the responsible party may, in accordance with EU law or the law of the member states, stipulate the specific criteria for its designation.
h) Assigned processor
An assigned processor is a natural or legal person, authority, institution or other body that processes personal data on behalf of the responsible party.
i) Recipient
A recipient is a natural or legal person, authority, institution or other body to which personal data is disclosed, regardless of whether or not it is a third party. However, authorities that may receive personal data in the context of a specific investigation mandate according to EU law or the law of a member state law shall not be considered to be recipients.
j) Third party
A third party is a natural or legal person, authority, institution or other body other than the person concerned, responsible party, assigned processor and those authorised to process personal data under the direct responsibility of the responsible party or assigned processor.
k) Consent
Consent is any declaration or other unambiguous and informed expression of intent given voluntarily by the person concerned in the form of a declaration or any other clear, unequivocal action by the person concerned that he or she agrees to the processing of personal data concerning him or her.
2. Name & address of the party responsible for processing
The responsible party within the meaning of the General Data Protection Regulation, other data protection laws in force in the member states of the European Union and other provisions dealing with data protection is:
Aparthotel Steger
The Steger Family
Wagrainer Straße 33
5602 Wagrain
Austria
Phone: +43 (0)6413 20110
Email: info@steger.co.at
www.steger.co.at/en
3. Cookies
4. Website analysis
This website uses Google Analytics, a web analytics service provided by Google Inc. ("Google"). Google Analytics uses "cookies", which are text files placed on your computer to help the website analyse how visitors use the site. The information generated by the cookie about your use of the website will normally be transmitted to and stored by Google on servers in the USA. If IP anonymisation is activated on this website, your IP address will be truncated beforehand within a member state of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the United States and truncated there. Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage. Google will not associate your IP address transferred within the framework of Google Analytics with any other data held by Google. You may refuse the use of cookies by selecting the appropriate settings on your browser, however, please note that if you do this you may not be able to use the full functionality of this website. Furthermore, you can prevent Google's collection and use of data generated by the cookie and related to your use of the website (including your IP address) by downloading and installing the browser plug-in or alternatively clicking on the following link to opt out of cookies: https://tools.google.com/dlpage/gaoptout?hl=de-DE.
You can prevent Google Analytics from collecting your user data on this website only by clicking on the following link. An opt out cookie is set that prevents any future acquisition of your data when visiting our website: Deactivate Google Analytics.
If you delete the cookies in this browser, you have to set the opt out cookie again.
You will find more information on Google Analytics provisions and privacy policy at https://www.google.com/analytics/terms/de.html.
5. Collecting general data and information
The website of the Aparthotel Steger, The Steger Family collects a range of general data and information each time a person concerned or automated system accesses the website. This general data and information is stored in the server's log files. The following may be recorded: (1) the browser type and version used; (2) the operating system used by the accessing system; (3) the website from which an accessing system reaches our website (so-called "referrer"); (4) the sub-websites visited via an accessing system on our website; (5) the date and time of accessing the website; (6) an Internet protocol address (IP address); (7) the Internet service provider of the accessing system; (8) other similar data and information that is used to prevent threats in the event of attacks on our information technology systems.
6. Contact options on the website
"electronic post" (email address). If a person concerned contacts the party responsible for processing via email or a contact form, the personal data transmitted by the person concerned will be stored automatically. Personal data voluntarily provided by a person concerned to the party responsible for processing will be stored for the purpose of processing or contacting the person concerned. This personal data is not passed on to third parties.
7. Routine deletion & blocking of personal data
The party responsible for processing shall only process and store the personal data of the person concerned for the time required to achieve the storage purpose or to the extent provided for by the European body issuing directives and regulations or another legislator in laws or regulations to which the party responsible for processing is subject.
If the storage purpose ceases to apply or if a storage period prescribed by the European body issuing directives and regulations or another competent legislator expires, the personal data is routinely blocked or deleted in accordance with the statutory provisions.
8. Rights of the person concerned
a) Right to confirmation
Every person concerned has the right granted by the European body issuing directives and regulations to ask the party responsible for processing to confirm whether personal data concerning him or her is being processed. If a person concerned wants to use this right of confirmation, he or she can contact our data protection officer at any time.
b) Right to information
Every person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to obtain, at any time and free of charge, information from the party responsible for processing on the personal data relating to him or her stored and a copy of that information. Furthermore, the European body issuing directives and regulations has granted the person concerned the following information:
- the purpose of processing
- the categories of personal data being processed
- the recipients or categories of recipients to whom the personal data has been or are still being disclosed, in particular recipients in third countries or international organisations
- if possible, the planned storage duration of the personal data or, if this is not possible, the criteria for determining this duration
- the existence of a right to rectification or deletion of personal data concerning a person or of a restriction on processing by the party responsible or of a right of opposition to this processing
- the existence of a right of appeal to a supervisory authority
- if the personal data is not collected from the person concerned: all available information about the origin of the data
- the existence of automated decision-making, including profiling in accordance with Article 22 Para. 1 and 4 DS-GMO and, at least in these cases, meaningful information on the logic involved and the scope and intended effects of this kind of processing for the person concerned
c) Right to rectification
Any person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to request the immediate correction of inaccurate personal data concerning him or her. Furthermore, taking into account the purposes of the processing, the person concerned has the right to request the completion of incomplete personal data, including by means of a supplementary statement. If a person concerned wants to use this right to rectification, he or she can contact our data protection officer at any time.
d) Right to deletion (right to be forgotten)
Any person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to ask the responsible party to immediately delete any personal data concerning him or her, provided that one of the following reasons applies and insofar as the processing is not necessary:
- personal data has been collected or otherwise processed for purposes for which it is no longer necessary.
- the person concerned withdraws his or her consent on which the processing was based according to Article 6 Para. 1 Letter a DS-GMO or Article 9 Para. 2 Letter A DS-GMO and there is no other legal basis for the processing.
- the person concerned enters an objection against processing according to Article 21 Para. 1 DS-GMO and there are no overriding legitimate grounds for processing or the person concerned enters and objection against processing according to Article 21 Para. 2 DS-GMO.
- the personal data has been processed unlawfully.
- the deletion of personal data is necessary is required to fulfil a legal obligation under EU law or the law of the member states to which the responsible party is subject.
- the personal data was collected in relation to information society services offered according to Article 8 Para. 1 DS-GMO.
If the personal data has been released by the Aparthotel Steger, The Steger Family and our company is responsible for deletion of the personal data as the responsible party according to Article 17 Para. 1 DS-GMO, the Aparthotel Steger, The Steger Family shall take appropriate measures, including technical measures, taking into account available technology and implementation costs, to inform other parties responsible for data processing who process the published personal data, that the person concerned has requested the deletion of all links to this personal data or of copies or replications of this personal data from those other responsible parties, insofar as processing is not necessary. The Aparthotel Steger, The Steger Family's data protection officer or another employee will take the necessary steps in individual cases.
e) Right to restriction of processing
Any person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to request that the responsible party restricts the processing if one of the following conditions is met:
- the accuracy of the personal data is disputed by the person concerned for a period that enables the party responsible to verify the accuracy of the personal data.
- the processing is unlawful, the person concerned refuses deletion of the personal data and instead requests that the use of the personal data be restricted.
- the party responsible no longer needs the personal data for the purposes of the processing, but the person concerned needs them to assert, exercise or defend legal claims.
- the person concerned has entered an objection against the processing according to Article. 21 Para. 1 DS-GMO and it has not yet been determined whether the legitimate reasons of the responsible party outweigh those of the person concerned.
f) Right to data transferability
Any person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to receive personal data relating to him or her, which has been provided by the responsible party, in a structured, common and machine-readable format. They also have the right to transmit this data to another responsible party without any obstruction by the responsible party, to whom the personal data has been provided, provided that the processing is based on the consent according to Article 6 Para. 1 Letter a DS-GMO or Article 9 Para. 2 Letter a DS-GMO or on a contract according to Article 6 Para. 1 Letter b DS-GMO and processing is carried out by means of automated procedures, except where processing is necessary for the performance of a task in the public interest or in the exercise of official authority assigned to the responsible party.
Furthermore, in exercising his or her right to data transferability according to Article 20 Para. 1 DS-GMO, the person concerned has the right to effect that the personal data be transferred directly by a responsible party to another responsible party, provided this is technically feasible and provided that the rights and freedoms of other persons are not affected.
To assert the right to data transferability, the person concerned may contact the data protection officer appointed by the Aparthotel Steger, The Steger Family or another employee at any time.
g) Right to objection
Any person concerned with the processing of personal data shall has right granted by the European body issuing directives and regulations to enter an objection at any time to the processing of personal data concerning them according to Article 6 Para 1 Letters e or f DS-GMO for reasons arising from their particular situation. This also applies to profiling based on these provisions.
In the event of revocation, the Aparthotel Steger, The Steger Family will no longer process the personal data unless we can prove compelling legitimate reasons for processing, which outweigh the interests, rights and freedoms of the person concerned, or the processing serves to assert, exercise or defend legal claims.
If the Aparthotel Steger, The Steger Family processes personal data for direct advertising purposes, the person concerned has the right to object at any time to the processing of personal data for the purpose of this kind of advertising. This also applies to profiling if it is in connection with this kind of direct advertising. If the person concerned objects to the Aparthotel Steger, The Steger Family processing for direct advertising purposes, the Aparthotel Steger, The Steger Family will no longer process the personal data for these purposes.
In addition, the person concerned has the right to enter an objection against the processing of personal data concerning him or her carried out by the Aparthotel Steger, The Steger Family, which is done for academic or historical research purposes or for statistical purposes according to Article 89 Para. 1 DS-GMO for reasons arising from their particular situation, unless this processing is necessary to fulfil a task in the public interest.
To exercise the right to objection, the person concerned may contact the Aparthotel Steger, The Steger Family's data protection officer or another employee directly. The person concerned shall also be free to exercise his or her right of objection in relation to the use of information society services by means of automated procedures for which technical specifications are used, regardless of Directive 2002/58/EC.
h) Automated decisions in individual cases, including profiling
Every person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations not to be subject to a decision based exclusively on automated processing, including profiling, which has legal effect against him or her or significantly affects him or her in a similar manner, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the person concerned and the responsible party, or (2) is admissible under the provisions of EU law or those of the member states to which the responsible party is subject and these provisions contain appropriate measures to safeguard the rights, freedoms and legitimate interests of the person concerned or (3) is made with the express consent of the person concerned.
If the decision (1) is required for the conclusion or performance of a contract between the person concerned and the responsible party or (2) is made with the express consent of the person concerned, the Aparthotel Steger, The Steger Family shall take appropriate measures to safeguard the rights, freedoms and legitimate interests of the person concerned, including at least the right to obtain the intervention of a person by the person responsible, to state his or her own position and to challenge the decision.
If the person concerned wishes to assert his or her right relating to automated decisions, he or she may contact our data protection officer at any time.
i) Right to withdraw consent relating to data privacy
Every person concerned with the processing of personal data has the right granted by the European body issuing directives and regulations to withdraw consent given to process personal data at any time.
If the person concerned wishes to assert his or her right to revoke his or her consent, he or she may contact our data protection officer at any time.
9. Legal basis for processing
Article 6 I lit. a DS-GVO serves our company as a legal basis for processing operations for which we obtain consent for a specific processing purpose. If processing personal data is necessary for the performance of a contract to which the person concerned is a party, as is the case, for example, with processing operations necessary for the delivery of goods or the provision of other services or consideration, processing is based on Article 6 I lit. b DS-GMO. The same applies to processing operations that are necessary to carry out precontractual measures, for example, in cases of enquiries about our products or services. If our company is subject to a legal obligation that requires the processing of personal data, for example, to fulfil tax obligations, processing is based on Article. 6 I lit. c DS-GMO. In rare cases, processing personal data may become necessary to protect the vital interests of the person concerned or another natural person. This would be the case, for example, if a visitor was injured at our company and his name, age, health insurance data or other vital information had to be passed on to a doctor, a hospital or other third parties. Processing would then be based on Article 6 I lit. d DS-GVO. Ultimately, processing operations could be based on Article 6 I lit. d DS-GVO. Processing operations that are not covered by any of the aforementioned legal bases are based on this legal basis if processing is necessary to safeguard a legitimate interest of our company or a third party, provided that the interests, fundamental rights and freedoms of the person concerned do not prevail. We are entitled to these kind of processing procedures in particular because they have been specifically mentioned by the European legislator. It advocates the view that a legitimate interest could be assumed if the person concerned is a customer of the responsible party (Recital 47, Sentence 2 DS-GMO).
10. Legitimate interests to processing pursued by the responsible party or a third party
If processing personal data is based on Article 6 I lit. f DS-GMO, it is in our legitimate interest to conduct our business activity for the good of all our employees and our shareholders.
11. Duration for which personal data is stored
The criterion for the duration of personal data storage is the respective legal retention period. After the expiry of this period, the corresponding data will be routinely deleted, provided that it is no longer necessary for the fulfilment or initiation of the contract.
12. Legal or contractual provisions for the provision of personal data; necessity for the conclusion of the contract; obligation of the person concerned to provide the personal data; possible consequences of failure to provide it
We inform you that the provision of personal data is partly required by law (e.g. tax regulations) or may also result from contractual regulations (e.g. information on the contractual partner). From time to time, it may be necessary for a contract to be concluded that a person concerned provides us with personal data that must subsequently be processed by us. For example, the person concerned shall undertake to provide us with personal data if our company enters into a contract with him or her. The only consequence of not providing personal information is that the contract will not be able to be concluded with the person concerned. Prior to the provision of personal data by the person concerned, the person concerned must contact our data protection officer. Our data protection officer will inform the person concerned on a case-by-case basis whether the provision of personal data is required by law or contract or necessary for the conclusion of the contract, whether there is an obligation to provide the personal data and what consequences the failure to provide the personal data would have.
13. Existence of automated decision-making
As a responsible company, we abstain from automatic decision-making or profiling.
14. Competent authority
Österreichische Datenschutzbehörde (Austrian Data Protection Authority)
Wickenburggasse 8
1080 Vienna
Austria
dsb@dsb.gv.at
This data protection declaration was created - with the exception of the cookie settings - by the data protection declaration generator of DGD Deutsche Gesellschaft für Datenschutz GmbH, which acts as external data protection officer Freising, in cooperation with the data protection lawyer Christian Solmecke.