Pension Leuprecht
Privacy Policy
In case of discrepancies, the German version prevails. Deutsch
This privacy policy explains which personal data is processed when you visit this website, for which purposes and on which legal basis. It is governed by the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG) and the Austrian Telecommunications Act 2021 (TKG 2021).
Controller
The controller for data processing on this website is Hotel zum Mohren GmbH, operator of Pension Leuprecht, Rosenau 3, 6600 Lechaschau / Reutte, Austria. You can reach us through our contact form, by phone at +43 5672 62345 or by post at the address above. Further details are given in the legal notice.
Hosting and server log files
Each time the website is accessed, the web server processes technically required access data: IP address, date and time, requested address, amount of data transferred, status code, the previously visited page (referrer), and browser and operating system. We need this data to deliver the website, to keep it secure and stable, and to investigate faults or attacks. The legal basis is our legitimate interest in secure and reliable website operation (Art. 6(1)(f) GDPR). The website is run by a hosting provider that processes this data as a processor on our behalf.
The fonts, scripts and design elements of this website are stored on our own server. Visiting the website does not establish a connection to Google Fonts or any other font provider. Only the booking system loads a font from Google Fonts, after your consent (see “Online booking”).
Inquiry form
When you send us an inquiry through the inquiry form, we process the data you enter: first and last name, email address, phone number (optional), arrival and departure dates, number of adults and children, children’s ages, preferred room and your message. Required fields are marked in the form; without this information we cannot handle your inquiry. The purpose is to answer your inquiry and prepare an offer. The legal basis is taking steps at your request prior to entering into a contract (Art. 6(1)(b) GDPR). As confirmation, you will receive an automatic e-mail with a summary of your details at the address you provided.
Transmission to our booking system
Our server transmits your inquiry directly to the property’s booking and guest management system at Interalp Touristik. Interalp Touristik processes the data as a processor exclusively on our behalf. If the inquiry cannot be accepted there, it is forwarded to the property by email instead so that it is not lost. For each transmission we log only technical delivery information (time and outcome), not the content of your inquiry.
Protection against abuse
To protect against automated spam, the form uses ALTCHA: when you submit it, your browser solves a small computational task (proof of work) that is issued and verified by our own server. No data is transmitted to third parties and no cookies are set. We also limit the number of inquiries per sender; for this we store pseudonymised check values (hash values) of the IP address and the email address. The legal basis is our legitimate interest in secure operation of the form free of abuse (Art. 6(1)(f) GDPR).
Online booking (Interalp Touristik)
On the “Online booking” page you can check availability and book directly. For this we embed the booking system of Interalp Touristik. It loads only after you have consented to the “Online booking” category, in the cookie settings or with the button on the booking page. Until then, no connection is established to Interalp Touristik or to the services named below. Alternatively, you can always send a request through the inquiry form or by phone.
When it loads, the booking system’s program code and content are retrieved from Interalp Touristik servers (including webbox3.interalp-touristik.com, webbox3-api.interalp-touristik.com and a media server for room photos). Your IP address, device and browser information and your entries in the booking system (for example travel dates, number of guests, room and rate selection) are transmitted to Interalp Touristik. The booking system also loads a font from Google Fonts (fonts.googleapis.com, fonts.gstatic.com) provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; this transmits your IP address to Google. For the payment step, the booking system embeds the payment service provider Datatrans AG, Zurich, Switzerland (pay.datatrans.com), which processes the payment data.
When you complete a booking, the data required for it is processed, in particular your contact and travel details, the selected services, your comments and the payment information. The purposes are checking availability, the booking and its payment. The legal basis for loading the booking system and for accessing your device is your consent (Art. 6(1)(a) GDPR, section 165(3) TKG 2021). Processing to carry out your booking is necessary for the performance of a contract or for steps prior to entering into a contract (Art. 6(1)(b) GDPR). The booking system creates entries in your browser’s local storage (see “Cookies and local storage”).
External media (YouTube and Vimeo)
Videos on this website open in a video window. We embed YouTube videos in privacy-enhanced mode via youtube-nocookie.com, and Vimeo videos via player.vimeo.com. A video loads only when you start it and have consented to the “External media” category, in the cookie settings or with “Accept and play” in the video window. Without consent, no connection to the provider is established.
YouTube is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Vimeo is provided by Vimeo.com, Inc., New York, USA. During playback, in particular your IP address, device and browser information, the referring page and playback data (for example start, duration and player settings) are transmitted to the respective provider. The providers may store cookies or similar technologies on your device; the possible identifiers are listed in the cookie settings. Whether a provider links this data to an existing user account is beyond our control. The legal basis is your consent (Art. 6(1)(a) GDPR; for access to your device, section 165(3) TKG 2021). Data may be transferred to Google LLC or Vimeo.com, Inc. in the USA (see “Transfers to third countries”).
Cookies and local storage
This website uses only the following cookies and browser storage entries. Necessary entries are strictly required to operate the website (section 165(3) TKG 2021; Art. 6(1)(f) GDPR); all others are set only after your consent.
- PHPSESSID (cookie, necessary, own service): session identifier set when you access the website. It protects the forms against submission by third-party sites and against duplicate submission, and shows the confirmation after you submit. Duration: until the end of the browser session.
- cookie_consent (cookie, necessary, own service): stores your choice in the cookie settings. Duration: 1 year.
- ia_auth (local storage, “Online booking” category, Interalp Touristik): signs the booking system in to the Interalp Touristik interface. Duration: until deleted in the browser.
- wb3Persist (local storage, “Online booking” category, Interalp Touristik): the booking system’s cache for the state of the booking process. Duration: until deleted in the browser.
- Video provider cookies (“External media” category, YouTube or Vimeo): set by the respective provider when a video is played. Names, purposes and durations are listed in the cookie settings.
We do not use analytics, statistics or marketing services such as web analytics tools or advertising pixels on this website.
You can change or withdraw your consent at any time with effect for the future through “Cookie settings” in the footer of every page. Withdrawal does not affect the lawfulness of processing carried out before it. You can also delete cookies and locally stored data in your browser at any time.
Transfers to third countries
With YouTube, Vimeo and Google Fonts, data may be transferred to the USA. For companies certified under the EU-US Data Privacy Framework (for example Google LLC), an adequacy decision of the European Commission applies. Where a provider is not certified, the transfer is based on your explicit consent (Art. 49(1)(a) GDPR); in that case there is a risk that US authorities may access the data and that you may not have the same legal remedies against this as in the EU. For Switzerland (Datatrans AG), an adequacy decision of the European Commission applies.
Retention and rights
We keep personal data only for as long as required for the relevant purpose or by statutory retention duties.
You have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR), and the right to object to processing based on legitimate interests (Art. 21 GDPR). You can withdraw any consent you have given at any time with effect for the future. To do so, please contact us through the contact form or by phone.
If you believe that the processing of your data infringes data protection law, you may lodge a complaint with the supervisory authority. In Austria this is the Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at.