OÖ Thermenholding GmbH takes the protection of your personal data very seriously. We will therefore treat your personal data as confidential and in accordance with the statutory data protection regulations and this privacy statement.
The protection of your privacy when visiting this website is very important to us. Below we provide detailed information about the handling of your data. The use of our website is generally possible without providing personal information. Insofar as personal data (for example name, address or email addresses) is recorded on our sites, this takes place, as far as possible, always on voluntary basis. This data will not be disclosed to third parties without your explicit consent.
Please note that data transmitted via the internet (e.g. via email communication) may be subject to security breaches. Complete protection of your data against access by third-parties is not possible.
You can visit our site without providing personal information. We only store access data without personal reference, for example, the name of your internet service provider, the page from which you are visiting us or the names of the requested file. This data is analysed exclusively for the purpose of improving our offer and permits no personal inference.
Access data / server log files
We (or our webspace provider) collect data on every access to the offer (known as server log files). The access data includes: Name of the accessed website, file, date and time of the access, transmitted data volume, browser type and version, operating system of the user, referrer URL (the previously visited site), IP address and the requesting provider. We only use the log data for statistic evaluation for operation, security and optimisation of the offer. However, we reserve to check the log data retroactively if there are grounds to suspect unlawful use based on concrete evidence. The log data are overwritten after 10 days and all IP addresses are stored anonymously.
Handling of personal data
Personal data is information that can be used to identify a person, i.e. information that can be traced back to a person. This includes your name, email address and phone number. Data on preferences, hobbies, memberships and websites viewed is also considered to be personal data.
We only collect, use and forward personal data insofar as this is permitted by law or when the user consents to the collection of data.
When contacting us (for example, by contact form or email), the user’s information is stored for the purpose of processing the enquiry and in the event that follow-up questions arise.
You will find the following data input fields in the forms offered on this website:
Hotel, arrival (mandatory field), departure (mandatory field), number of adults (mandatory field), number of children, age of children, title (mandatory field), first name, last name (mandatory field), email (mandatory field), phone number, street and house number, postcode, city, country, notes
Title (mandatory field), first name, last name (mandatory field), email (mandatory field), phone number, street and house number, postcode, city, country, notes (mandatory field),
Title (mandatory field), first name, last name (mandatory field), email (mandatory field), notes (mandatory field)
Title (mandatory field), first name, last name (mandatory field), email (mandatory field), phone number (mandatory field), call-back from/until (mandatory field), street and house number, postcode, city, country, call-back reason (mandatory field)
Catalogue order form:
Title (mandatory field), first name (mandatory field), last name (mandatory field), email, phone number, street and house number (mandatory field), postcode (mandatory field), city (mandatory field), country (mandatory field), notes, catalogues (with selection of the individual EurothermenResort catalogues).
After sending a form, the personal data you have entered will be processed by the person responsible for data protection for the purpose of processing your enquiry on the basis of the consent given by sending the form. In the case of catalogue orders, the address data will be forwarded to the delivery service provider.
There is no legal or contractual obligation to provide personal data. The only consequence of not providing data is that you will not be sent information.
You have the right to revoke your consent at any time in writing without affecting the legality of the processing carried out on the basis of your consent until revocation.
Newsletter / Evalanche
We inform you about us and our offers with our newsletters.
If you’d like to receive our newsletter, we need a valid email address from you as well as information that allows us to verify that you are the owner of the email address provided or that the owner agrees to receive the newsletter. Other data will not be collected. This data will only be used for sending the newsletter and will not be forwarded to third parties.
Upon signing up for the newsletter, we will save your IP address and the registration date. This data storage exclusively serves as proof in the event that a third party misuses an email address and registers to receive the newsletter without the knowledge of the authorised person.
You may revoke your consent to the storage of your data and your email address as well as their use for sending the newsletter at any time. You can revoke your consent by clicking on the link in the newsletters themselves, in your profile or by writing to one of the contact options provided at the end of this privacy statement.
Online-Booking System Samera
In order to process enquires and bookings, the personal data entered in the forms and cookie identification are transmitted to the data processor Klar & Leiter GesbR, Maria-Theresien-Strase 21, 6020 Innsbruck, Austria (“samera”).
We would like to point out that the IP data of the connection party are stored as cookies in order to simplify the purchasing process and for the purpose of subsequent contract implementation by samera, as well as name, address, email address and phone number. In addition, the following data is stored by us for the purpose of contract implementation: name, address, email address, phone number.
The data provided by you is necessary for the fulfilment of the contract/for the execution of pre-contractual procedures. We cannot conclude the contract with you without this data. Data will not be forwarded to third parties, with the exception of credit card data to mPAY24 (mPAY24 GmbH, Grüngasse 16, 1050 Vienna, Austria) and the banking institutions for withdrawal of the purchase price and to our accountant to fulfil our tax obligations. After cancelling the purchasing process, all data stored with us will be deleted. In the event of a contract being concluded, all data of the contractual relationships will be stored until the expiry of the tax retention period (7 years).
Data processing is carried out on the basis of the regulations pursuant to Section 96 paragraph 3 of the Telecommunications Act (Telekommunikationsgesetz (TKG) and Article 6 paragraph 1 (a) (consent) and/or (b) (necessary for contract implementation) of the General Data Protection Regulation (GDPR).
You can register on your website, and particularly in our online shop. When you register, we will collect and store the data you enter in the input mask (e.g. last name, first name, email address). Your data will not be forwarded to third parties.
In the event of consent, the legal basis for processing is Article 6 paragraph 1 (a) of the GDPR. If your registration serves the purpose of preparing the conclusion of a contract, Article 6 paragraph 1 (b) of the GDPR serves as an additional legal basis.
Your registration is required in order to use certain contents and services on our website and for concluding a contract or for the execution pre-contractual procedures.
Cookies make websites easier to use and more efficient for the user. A cookie is a small text file used to store information. During a visit to a website, the website can place a cookie on the computer of the website visitor. If the user visits the website again later on, the website can read the data of the previously stored cookie, thus determining whether the user has visited the website previously and which areas of the website the user has shown particular interest in, among other things.
Find more information about cookies on Wikipedia.
Changing the cookie settings
The user can determine how the web browser handles cookies and which cookies are tolerated or rejected in the web browser settings. The exact location of these settings depends on the respective browser. Detailed information about this can be accessed via the help feature of the respective web browser.
You have the option to explicitly activate/deactivate cookies for this website here:
Cookies on this website
This website processes the following cookies:
Essential cookies to ensure basic functions of the website:
- etracker OptOut (et_oi_v2): used to store the etracker opt-out.
Functional cookies to ensure the performance of the website:
- Samera: necessary for the operation of the booking system
- Seam: necessary for the operation of the voucher shop system
Performance cookies to improve the user experience:
- etracker: information on all etracker cookies can be found here
- Google Adwords Conversions
- Bing Conversions
Integration of third-party services and content
It may happen that content by third parties, such as videos from YouTube, maps from Google maps, RSS feeds or graphics from other websites, are incorporated into this website. This always presupposes that the provider of such content (hereinafter referred to as “third-party providers”) detect the IP address of the user, as they would be unable to send content to the browser of the respective user without the IP address. The IP address is therefore required to display such content.
We endeavour to only use contents whose respective providers only use the IP address to deliver the content. However, we have no influence over whether the third-party provider, for example, saves the IP address for statistical purposes. We will inform our users as to this to the best of our knowledge.
Functions and services of the following third-party providers are incorporated on this website:
The service walls.io by “Die Socialisten” Social Software Development GmbH, Andreasgasse 6/1, 1070 Vienna, Austria is used to display social media content on the social wall of the website.
Find the company’s privacy statement here.
Data of the travel website TripAdvisor by TripAdvisor Inc., 400 1st Avenue, Needham, MA 02494 USA is used on this website to display guest ratings.
Find TripAdvisor’s privacy statement here.
This website includes guest ratings by HolidayCheck AG, Bahnweg 8, 8598 Bottighofen, Switzerland.
Find the company’s privacy statement here.
This website displays data from the guest feedback portal TrustYou by TrustYou GmbH, Steinerstrasse 15, 81369 Munich, Germany.
Find TrustYou’s privacy statement here.
Flip-page catalogues and documents are incorporated into this website via the online service issuu by Issuu, Inc. 131 Lytton Ave, Palo Alto, CA 94301 USA.
Find issuu’s privacy statement here.
We currently use the following social media plugins: Facebook and Instagram. In these cases, personal data is transmitted to the respective plugin provider by means of a button and stored there.
The respective plug-in provider stores the data collected about you as a user profile and uses this for the purpose of advertising, market research and/or to design its website to meet the needs of users. Such an assessment is carried out especially to display appropriate advertisements (also for users who are not logged in), in order to inform other users of the social network about your activities on our website. You have the right to object to the creation of this user profile, but you must contact the respective plug-in provider to exercise this right. The plug-ins give you the opportunity to interact with the social networks and other users so that we can improve our offer and make it more interesting to you as a user. The legal basis for the provision and use of the plug-ins is the first sentence of Article 6 paragraph 1 (f) of the GDPR.
The data is forwarded regardless of whether you have an account with the plug-in provider and are logged in there. If you are logged in with the plug-in provider, your data that is collected by us is allocated directly to your account with the plug-in provider. For US providers, data is transmitted to the USA; these providers are subject to the EU-US Privacy Shield: https://www.privacyshield.gov/EU-US-Framework
Additional information regarding the purpose and scope of the data collection and its processing by the plug-in provider is available in the privacy statements of these providers as listed below. Here you also obtain additional information about your rights and settings options to protect your privacy:
- Facebook Inc., 1601 S California Ave, Palo Alto, California 94304, USA https://www.facebook.com/policy.php
- Instagram LLC, 1601 Willow Rd, Menlo Park, California 94025, USA, represented by Kevin Systrom and Mike Krieger https://help.instagram.com/155833707900388
Use of YouTube plugins
Information about Google:
Google Inc., 1600 Amphitheater Parkway, Mountainview, California 94043, USA
More information about Google’s Terms of Service:
https://policies.google.com/privacyMore information about Google Maps’ Terms of Service:
The provider of this website uses the services of etracker GmbH, Hamburg, Germany (www.etracker.com) to analyse usage data. Cookies are used which enable the statistical analysis of the use of this website by its visitors as well as the display of use-related content or advertising. Cookies are small text files that are stored by the internet browser on the user's device. etracker cookies do not contain any information that enables the identification of a user.
The data generated with etracker is processed and stored by etracker solely in Germany on behalf of the provider of this website and is thus subject to strict German and European data protection laws and standards. In this regard, etracker was checked, certified and awarded the ePrivacyseal data protection seal of approval.
The data is processed on the legal basis of Article 6 paragraph 1 (f) (legitimate interest) of the EU General Data Protection Regulation (GDPR).Our legitimate interest is the optimisation of our online offer and our website. As the privacy of our visitors is very important to us, etracker anonymises the IP address as early as possible and converts login or device IDs into a unique key that is not linked to a specific person. etracker does not use this for any other purpose, combine this with other data or pass this on to third parties.
You may object to the aforementioned processing of your data at any time insofar as it is related to your person. Your objection shall have no detrimental consequences for you.
Further information on data protection with etracker can be found here.
Use of Bing Conversion
We use Bing Ads Conversion. Conversion tracking allows us to determine how successful individual advertising measures are. Our purpose is to display advertisements to you that are of interest to you and to make our website more interesting for you. The legal basis for processing your data is Article 6 paragraph 1 (f) of the GDPR.
These cookies allow Bing Ads to recognise your internet browser. If a user has visited certain pages of the website of a Bing Ads customer and the cookie stored on his computer hasn’t expired yet, Microsoft and the customer can see that the user clicked the ad and was forwarded to this page. A different cookie is assigned to each Bing Ads customer. Hence, cookies cannot be tracked via the websites of Bing Ads customers. We ourselves do not collect and process any personal data in the aforementioned advertising measures. Bing Ads only provides us with statistical evaluations. These evaluations allow us to see which of the advertising measures used are particularly effective. We do not receive any further data arising from the use of the advertising media; in particular, we cannot identify users based on this information.
Due to the marketing tools used, your browser automatically establishes a direct connection with the Microsoft server. We have no influence over the extent and further use of data collected by Microsoft via this tool and thus inform you to the best of our knowledge: by integrating Bing Ads Conversion, Microsoft is informed that you have accessed a certain part of our website or clicked one of our ads. If you are registered with a Microsoft service, Microsoft can match the visit to your account. Even if you are not registered with Microsoft or are not logged in, the provider may obtain and store your IP address.
Microsoft participates in the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework. More information about Microsoft: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. Find more information on Microsoft’s privacy statement here: https://privacy.microsoft.com/en-us/privacystatement
Google AdWords conversion tracking
We use Google AdWords to display advertisements on Google and other third-party websites. Conversion tracking helps us determine how successful each ad is. Our purpose is to show you advertisements of interest to you and to make our website more interesting to you. The legal basis for the processing of your data is Article 6 paragraph 1 (f) of the GDPR.
These cookies enable Google to recognise your Internet browser. If a user visits certain pages of an AdWords customer's website and the cookie stored on their computer has not yet expired, Google and the customer will be able to detect that the user clicked on the ad and was redirected to that page. Each AdWords customer is assigned a different cookie. Cookies cannot be tracked via the websites of AdWords customers. We ourselves do not collect and process any personal data in the aforementioned advertising measures. We receive only statistical analyses provided by Google. On the basis of these analyses, we can identify which of the advertising measures used are particularly effective. We do not receive any further data from the use of the advertising material; in particular, we cannot identify the users on the basis of this information.
Due to the marketing tools used, your browser automatically establishes a direct connection to Google's servers. We have no influence over the scope and further use of the data collected by Google and will inform you to the best of our knowledge. By integrating AdWords Conversion Tracking, Google receives the information that you have accessed the relevant part of our website or clicked on an ad from us. If you are registered with a service provided by Google, Google may match the visit to your account. Even if you are not registered with Google or have not logged in, the provider may obtain and store your IP address.
Google participates in the EU-US Privacy Shield: https://www.privacyshield.gov/EU-US-Framework
Use of our online voucher shop
You can purchase goods, vouchers for our services and loungers for the relax chalets at the sauna mountain village “AusZeit” in Bad Schallerbach online on our websites. The service is facilitated by a tailor-made voucher system developed for the EurothermenResorts by our contractual partner, seam media group gmbh, Linzer Strasse 44, A-4221 Steyregg. seam takes all organisational and technical measures to protect your data.
In order to transact business in our online shop, you must create a user account. This user account is protected by a personal login name and a password. You can change your data in this user account yourself at any time. You can also delete the user account yourself. The personal data we receive from you when you visit and use our online shop will only be processed electronically to handle purchases or orders made in the shops and will not be forwarded to third parties under any circumstances.
In order to protect your personal data, we use the encryption technology SSL123 by thawte, Inc., The Gateway Century Lane, Century City, 7441 Cape Town, South Africa, www.thawte.de, for data transfer in order to achieve utmost confidentiality. Data such as your name, address, email address, credit card number, bank code number or account number therefore cannot be read by unauthorised persons during internet transmission.
Shipment of the services and goods purchased in the shop is handled directly by us. No provision is made for forwarding personal data to a shipment company in this context.
Payment by PayPal
You can pay using the payment service provider PayPal on our website. In doing so, payment data is transferred to PayPal in order to process the payment. The legal basis for processing your data is Article 6 paragraph 1 (f) of the GDPR. You have the following payment options: payment via PayPal or credit card via PayPal. PayPal collects information about the transaction as well as other information associated with the transaction such as the amount sent or requested, the amount paid for products or services, merchant information, including information about any payment instruments used to complete the transaction, device information, technical usage data and location data.
PayPal collects this data regardless of whether or not you have a PayPal account. If you have a PayPal account, your data will be linked to your account. PayPal uses the data, among other things, for handling payments, conducting credit checks and for monitoring and improving its services.
You can find a list of companies to which PayPal may transmit your data here: https://www.paypal.com/ie/webapps/mpp/ua/third-parties-list
More information about PayPal: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg
Payment by Sofortüberweisung (immediate transfer)
Among other options, we offer payment by “Sofortüberweisung” on our website.
The provider of this payment service is Sofort GmbH, Theresienhöhe 12, 80339 Munich, Germany (hereinafter “Sofort GmbH”). By using the “Sofortüberweisung” method, we receive a payment confirmation by Sofort GmbH in real time and can start to fulfil our commitments immediately.
If you’ve chosen the payment option “Sofortüberweisung”, submit the PIN and a valid TAN to Sofort GmbH, with which they can log into your online banking account. Sofort GmbH automatically checks your balance after logging in and carries out the transfer to us using the TAN submitted by you. They will then send us a confirmation of transaction immediately. Furthermore, after logging in, your transaction volume, the credit limit of your overdraft facility and the availability of other accounts and their balances are checked automatically. In addition to PIN and TAN, the payment data entered by you and data about your person are forwarded to Sofort GmbH. Data about your person are your first and last name, address, phone number(s), email addresses, IP address and, if necessary, further data needed for processing payments. This data transfer is necessary to verify your identity beyond any doubt and to prevent attempts to defraud.
Your data will be transferred to Sofort GmbH on the basis of Article 6 paragraph 1 (a) of the GDPR (consent) and Article 6 paragraph 1 (b) of the GDPR (processing to fulfil a contract). You have the option to revoke your consent to data processing at any time. Revocation will not affect the effectiveness of data processing procedures in the past.
Details about making payments by Sofortüberweisung can be found at the following links: https://klarna.com/pay-now-with-direct-banking/privacy-statement/ and https://klarna.com/uk/.
Should parts or individual terms of this text not, no longer or not completely conform with the current legal situation, the content and validity of its remaining parts shall remain unaffected.
We will only process and store your data only as long as is necessary for the purpose of processing or compliance with legal obligations. Upon the expiry of the purpose of processing, your data will be blocked or deleted. Insofar as there are further legal obligations regarding the storage of your data, we will block or delete your data upon the expiry of the statutory storage periods.
You have the following legal rights against us with respect to the storage of your personal data:
- Right to information
You have the right to request confirmation as to whether we process personal data concerning you. If this is the case, you have the right to information about this personal data and to other information, e.g. the purposes of processing, the recipients and the planned duration of storage/the criteria for determining this duration.
- Right to correction and completion
You have the right to demand immediate correction of incorrect data. Taking into account the purposes of processing, you have the right to demand that incomplete data be completed.
- Right to deletion (“Right to being forgotten”)
You have the right to deletion insofar as processing is not required. This is the case, for example, if your data is no longer necessary for the original purposes, you rescinded your declaration of consent for data protection reasons or your data was processed unlawfully.
- Right to restriction of processing
You have a right to restrict processing, e.g. if you believe that your personal data is incorrect.
- Right to data transferability
You have the right to receive your personal data in a structured, common and machine-readable format.
- Right of objection
You have the right to object at any time to the processing of certain personal data for reasons arising from your particular situation.
INn the case of direct marketing, you as the affected person have the right to object at any time to the processing of personal data for the purpose of such advertisement; this also applies to profiling insofar as it is performed in the context of such direct marketing.
- Right to revoke your data privacy consent
You may revoke your consent to processing your personal data with future effect at any time. However, this does not affect the legality of processing prior to revocation.
Furthermore, you may lodge a complaint with a supervisory authority for data protection at any time if you are of the opinion that the data processing is not in compliance with data privacy provisions.
Contact person for data privacy:
In you have any questions regarding the collection, processing or use of your personal data, or for information, correction, barring or deletion of data and for revocation of given consent, please contact:
EurothermenResorts - OÖ Thermenholding GmbH
Promenade 1, A-4701 Bad Schallerbach
Phone +43 (0)7249 440-0 / Fax +43 (0)7249 440-590
In order to make it easier for you to receive information in accordance with Article 15 of the GDPR, you will find a form (DE) for download here.
I consent on my own behalf that the EurothermenResorts Bad Schallerbach, Bad Ischl, Bad Hall (below “ETR”) may process my personal data, in particular
- Master data (name, first name, principal place of residence, address, email address, phone and fax number, professional and private contact data including contact persons and their function, place of birth, date of birth, customer number, language and license number plus car model)
- Data in ID documents (e.g. travel document, ID card, driver’s license etc. including issuing authority and validity, nationality)
- Arrival and departure date and booking duration, room number
- The services requested by me and personal preferences I disclose, e.g. food or cushion requests, and allergies, intolerances, special requirements and customer/special wishes, date and type of the services used and consumed including special categories of data
- Data regarding the payment method and in connection with payments, particularly with EC cards, credit cards and debit cards
- Customer feedback
- Data with picture/sound recordings
- Customer relationship management
for the following purposes:
- Reservation of rooms and tables and other services, booking of rooms and services in the hotel and gastronomy sector as well as their execution, processing and invoicing and that of other hotel services (B2B, B2C, FIT)
- Customer service including all necessary correspondence, processing of customer requests, billing of services#
- Booking and planning of events of all kinds
- Organisation and provision of transport services and rental vehicles
- Operation of spa and fitness facilities including setting appointments, group training, booking of additional services, customer advice, use of computer-operated training equipment
- Video surveillance of all access points to the resort, all in-house areas outside the resort and generally accessible premises inside the resort buildings and associated outbuildings, such as parking facilities for security purposes, e.g. to protect persons and goods, in particular the property of guests and the resort.
Furthermore, consent for the transmission of data to
- Group companies
- Cooperation partners
and their vicarious agents is given.
I want my services related to the use of ETR to be as effective and time-saving as possible, and that my special customer wishes may be continue to be taken into account. For the purpose of my optimal customer support, I wish that
- all my data listed in this declaration may be stored beyond the duration of my business relationship with the ETR and
- for a maximum of 3 years beyond the longest legal retention obligation to preserve records applicable to the ETR,
- so that this data can be processed in case of a new use of the ETR desired by me and
- may be transferred to third parties to the required extent.
I have been informed that I am entitled to revoke this consent in whole or in part to the ETR at any time.
I am aware that the data privacy statement of the ETR can be accessed on their web portal on www.eurothermen.at/en/service/data-protection and that I consent to it, UNLESS I DISAGREE IN WRITING.