
Privacy Policy
Data Protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
The use of our website is generally possible without providing personal data. Insofar as personal data (e.g. name, address or email addresses) is collected on our pages, this is always done on a voluntary basis as far as possible. This data will not be passed on to third parties without your express consent.
We would like to point out that data transmission on the Internet (e.g. when communicating by email) may have security gaps. Complete protection of data against access by third parties is not possible.
Data Collection and Processing for Internet Access
When you visit our website, our web servers temporarily store each access in a log file. The following data is recorded and stored until automatic deletion:
- IP address of the requesting computer
- Date and time of access
- Name and URL of the retrieved data
- Amount of data transferred
- Notification of whether the retrieval was successful
- Identification data of the browser and operating system used
- Website from which the access was made
- Name of your Internet access provider
- User behavior
This data is processed for the purpose of enabling the use of the website (connection setup), system security, technical administration of the network infrastructure and optimization of the internet offering.
This log data is automatically deleted after a short retention period. We do not use Hotjar or any comparable session-replay tool on this website.
Booking Requests & Online Booking (Seekda)
For online room bookings we use the booking engine of Seekda GmbH (Maria-Theresien-Straße 49, 6020 Innsbruck, Austria). When you complete a booking, the data you enter (name, contact details, travel dates, payment data) is processed by Seekda on our behalf as a processor pursuant to Art. 28 GDPR. Payment card data is transmitted in encrypted form (TLS) directly to the respective payment service providers and is not stored by us.
Further information: seekda.com
Wine Inquiries (Resend)
When you submit a wine inquiry via our online form, the data entered (name, email, address, order details) is sent via a Supabase Edge Function to Resend (Resend Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA) for transactional email delivery to our reception. Resend acts as a processor pursuant to Art. 28 GDPR. The transfer to the USA takes place on the basis of EU Standard Contractual Clauses.
Hosting, Database & Storage (Supabase)
Inquiry data, image assets and configuration data are stored on the infrastructure of Supabase Inc. (970 Toa Payoh North #07-04, Singapore 318992; EU region hosting). Supabase acts as a processor pursuant to Art. 28 GDPR; a corresponding data processing agreement is in place.
Scope of Data Collection and Storage
In general, it is not necessary to provide personal data to use our website. However, in order for us to actually provide our services, we may need your personal data. This applies in particular to answering individual inquiries.
If you commission us to provide a service, we generally only collect and store your personal data to the extent necessary for the provision of the service or the execution of the order.
e.g. first name, last name, postal address, telephone number, email address.
It may be necessary to pass on your personal data to companies that we use to provide the service or to process the contract.
Your personal data will not be passed on to third parties without your express consent, unless this is necessary to provide the service or to fulfil the contract (as stated above). Data will only be transmitted to state institutions and authorities entitled to information within the scope of mandatory statutory information obligations or if we are obliged to provide information by a court decision. In the latter case, the persons concerned will be informed immediately about the transfer of the data.
After full contract processing, your data will be deleted after the expiry of the purpose and the tax and commercial law retention regulations, unless you have expressly consented to further data use (see right of deletion).
Use and Disclosure of Personal Data
Any use of your personal data is only for the stated purposes and to the extent necessary to achieve these purposes. No data is passed on to third parties. Personal data is only transmitted to state institutions and authorities within the framework of mandatory national legal regulations or if the disclosure is necessary for legal or criminal prosecution in the event of attacks on our network infrastructure. No transfer takes place for other purposes.
Cookies
The internet pages partly use so-called cookies. Cookies do not cause any damage to your computer and do not contain viruses. Cookies serve to make our offering more user-friendly, more effective and more secure. Cookies are small text files that are stored on your computer and saved by your browser.
Most of the cookies we use are so-called "session cookies". They are automatically deleted after your visit. Other cookies remain stored on your terminal device until you delete them. These cookies enable us to recognize your browser on your next visit.
You can set your browser to inform you about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be limited.
Statistics and marketing cookies (in particular Google Analytics 4, Measurement ID G-DDHQWSNJZF) are loaded only after your active consent. We use Google Consent Mode v2 with all tracking categories defaulted to 'denied'. IP addresses are anonymised. You can review or revoke your consent at any time:
Consent Logging (Audit Log)
To prove your consent in accordance with Art. 7 (1) GDPR, we record each cookie decision in an append-only audit log on our processor Supabase (EU region, Frankfurt). Stored data: a pseudonymous consent ID (random UUID stored in your browser, no link to your identity), the chosen categories, the source of the decision (e.g. "Accept all"), the consent version, the page URL, the browser language, the user agent, and a daily-salted SHA-256 hash of your IP address (the plain IP is never stored).
Legal basis: Art. 6 (1) lit. c GDPR in conjunction with Art. 7 (1) GDPR (legal obligation to demonstrate consent). Retention period: 3 years after the last change of your consent (statutory limitation period). The log is not used for marketing or analytics.
Contact Form
If you send us inquiries via the contact form, your details from the inquiry form, including the contact data you provided there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We will not share this data without your consent.
Submissions from the contact form on /kontakt are transmitted via HTTPS to our workflow automation provider Ottokit (webhook.ottokit.com) acting as processor pursuant to Art. 28 GDPR. From there the request is forwarded to our reception (e-mail) for processing. Legal basis: Art. 6 (1) lit. b GDPR (pre-contractual measures) and Art. 6 (1) lit. a GDPR (consent via the privacy checkbox).
Google Maps
We embed maps from the service Google Maps (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Maps are only loaded after your active consent (marketing category). When loading, your IP address and browser data are transmitted to Google; data may be transferred to the USA on the basis of EU Standard Contractual Clauses. Without consent, only a placeholder is displayed.
Newsletter Data
If you sign up for our newsletter via the form in the website footer, we collect your first name and email address as well as the time and source of the sign-up ("footer"). Your active confirmation via the privacy checkbox is recorded as proof of consent.
Sign-up data is transmitted via HTTPS to our newsletter and workflow processor Ottokit (webhook.ottokit.com), acting as processor pursuant to Art. 28 GDPR. Ottokit also handles the dispatch of newsletter emails on our behalf. The data is used exclusively to send the requested newsletter and is not passed on to third parties.
Legal basis: Art. 6 (1) lit. a GDPR (consent via the privacy checkbox at sign-up). Storage period: until you withdraw your consent. You can withdraw your consent at any time — for example via the unsubscribe link in every newsletter email or informally by email to info@pfeffel.at.
If you have given us marketing/analytics consent via the cookie banner, marketing source parameters (UTM parameters, e.g. utm_source, utm_campaign) of the page on which you signed up will additionally be transmitted to allow us to measure the reach of our marketing measures. Without this consent, no UTM data is transmitted.
Privacy Policy for the Use of Google Analytics
This website uses functions of the web analysis service Google Analytics. The provider is Google Inc., 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. Google Analytics uses so-called "cookies". These are text files stored on your computer that enable an analysis of your use of the website. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there.
If IP anonymization is activated on this website, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide other services related to website and internet usage to the website operator. The IP address transmitted by your browser within the scope of Google Analytics will not be merged with other Google data.
You can prevent the storage of cookies by setting your browser software accordingly; however, we would like to point out that in this case you may not be able to use all functions of this website to their full extent. You can also prevent Google from collecting and processing the data generated by the cookie related to your use of the website (including your IP address) by downloading and installing the browser plugin available at: tools.google.com/dlpage/gaoptout
Meta Pixel (Facebook & Instagram Conversions)
On the basis of your consent (Art. 6 (1) lit. a GDPR), we use the Meta Pixel (Pixel ID 1596332181054693) of Meta Platforms Ireland Limited (4 Grand Canal Square, Dublin 2, Ireland) for measuring conversions and audience building for our Facebook and Instagram campaigns. The pixel automatically tracks the events PageView (page visits), Lead (successful wine inquiries) and InitiateCheckout (clicks on "Book now"). Transmitted data includes IP address, browser information, device type and visited pages. Data may be transferred to the USA on the basis of EU Standard Contractual Clauses. The pixel is only loaded after active consent via our cookie banner; you can revoke your consent at any time.
Further information: facebook.com/privacy/policy
Links to Websites of Other Providers
Our website may contain links to websites of other providers. We would like to point out that this privacy policy applies exclusively to the websites of Gartenhotel Pfeffel GmbH. We have no influence on and do not control whether other providers comply with the applicable data protection regulations.
Right of Access, Deletion and Objection & Contact Details
You have the right at any time to free information about your stored personal data, its origin and recipients and the purpose of data processing, as well as a right to correction, blocking or deletion of this data. For this purpose, as well as for further questions on the subject of personal data, you can contact us at any time at the address given in the imprint.
If you are registered as a user with individual services of Gartenhotel Pfeffel GmbH, we partly also offer you the option to view and, if necessary, delete or change the data via a user account.
Every data subject has the right at any time to contact the competent data protection supervisory authority in case of dissatisfaction, discrepancies or suspected irregularities.
Right to Lodge a Complaint with the Austrian Data Protection Authority
Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a supervisory authority if you consider that the processing of personal data relating to you infringes the GDPR. The competent authority in Austria is:
Österreichische Datenschutzbehörde
Barichgasse 40–42
1030 Wien
Österreich
Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Web: www.dsb.gv.at
Objection to Advertising Emails
The use of contact data published within the framework of the imprint obligation for sending unsolicited advertising and information materials is hereby objected to. The operators of the pages expressly reserve the right to take legal action in the event of unsolicited sending of advertising information, such as spam emails.
