Book now
Fleischhaker
Book now

Privacy Policy

Responsible for processing your personal data on our website is the company Hotel Rosenvilla (hereinafter referred to as Rosenvilla, we, us, or the data controller). You can find our contact details in the imprint.

Data Collection and Data Processing

Contact Form
Fields Non-binding Inquiry: Salutation, First Name, Last Name, Street, Postal Code, Country, E-Mail, Phone, Arrival, Departure, Room Category, Number of Adults, Number of Children, Age of Children, Comments

After submitting the contact form, the personal data you entered will be processed by the data protection officer for the purpose of handling your inquiry based on your consent given by submitting the form.

There is no legal or contractual obligation to provide personal data. The non-provision only means that you cannot submit your request and we cannot process it.

You have the right to withdraw your consent at any time by sending a written notice, without affecting the lawfulness of processing based on the consent before its withdrawal.

Server Log File

This website processes the following personal data in a server log file for the purpose of monitoring the technical function and increasing the operational security of the web server based on the predominant legitimate interest of the data controller (technical security measures): IP, directory protection user, date, time, accessed pages, logs, status code, data volume, referrer, user agent, accessed hostname

The IP addresses are anonymized in this process. The anonymized IP addresses are deleted after 60 days. Information about the directory protection user is anonymized after one day.

Error logs, which record faulty page requests, are deleted after seven days. These include, in addition to the error messages, the accessing IP address and, depending on the error, the accessed webpage.

Your Rights

According to the General Data Protection Regulation, you have comprehensive rights, such as:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent (Art. 7 para. 3 GDPR) Right to lodge a complaint (Art. 77 GDPR)

To exercise your rights, please contact us.

Without prior successful identity verification, we cannot process requests from affected individuals. For this reason, we ask you to support the identity verification accordingly and to include a copy of your identification with your request.

If you believe that the processing of your data violates data protection provisions or that your data protection claims have otherwise been infringed in any way, you can lodge a complaint with the supervisory authority. In Austria, this is the Data Protection Authority, Barichgasse 40-42, 1030 Vienna.

Data Protection Officer

We are a private company. To protect your data, we have appointed the following Data Protection Officer:

KOMDAT Datenschutz GmbH
Linzerstrasse 60, 4614 Marchtrenk, Austria
www.komdat.at
privacy@komdat.at

Data Transmission

Data Transmission to Third Parties
A transmission of your personal data to third parties for purposes other than those listed below does not take place.

We only pass your personal data on to third parties if:

  • You have expressly consented to this according to Art. 6 para. 1 lit. a GDPR,
  • The disclosure is necessary according to Art. 6 para. 1 lit. f GDPR to protect legitimate interests and to assert, exercise or defend legal claims, and there is no reason to believe that you have a predominant legitimate interest in not disclosing your data,
  • In the event that there is a legal obligation for the disclosure according to Art. 6 para. 1 lit. c GDPR and
  • This is legally permissible and necessary according to Art. 6 para. 1 lit. b GDPR for the performance of contractual relationships with you.

The controller may share your personal data with suppliers who provide services on our behalf according to our instructions.

The controller may also share your personal data with our affiliates and partners.

Furthermore, the controller may disclose your personal data if we are legally, legally, or administratively required to do so or if we believe that a disclosure is necessary or appropriate to prevent physical harm or financial loss.

The controller reserves the right to transfer personal data we hold about you when we sell or transfer all or part of our business or assets (including in the event of a restructuring, dissolution, or liquidation).

Data Transfers

The controller can also transfer your personal data to countries outside the country in which the information was originally collected. In these countries, the same data protection laws may not apply as in the country where you originally provided the personal data. When we transfer your data to other countries, we protect this data as described in this privacy policy, and these transfers are subject to applicable law.

The countries to which we disclose personal data are located

  • within the European Union or
  • outside the European Union

When we transfer personal data from the European Union to countries or international organizations outside the European Union, the transfer is based on:

  • a decision of adequacy by the European Commission;
  • In the absence of such, based on other legally permissible grounds such as the existence of a legally binding and enforceable document between authorities or public bodies, binding corporate rules, standard data protection clauses, as well as approved or certified codes of conduct.

In exceptional cases, a data transfer may also occur based on Article 49 GDPR:

  • Article 49(1)(a) GDPR
  • the data subject has explicitly consented to the proposed data transfer after being informed of the possible risks to him or her of such data transfers in the absence of a decision of adequacy and without appropriate safeguards,
  • Article 49(1)(b) GDPR
  • the transfer is necessary for the performance of a contract between the data subject and the controller or for the implementation of pre-contractual measures at the request of the data subject,
  • Article 49(1)(c) GDPR
  • the transfer is necessary for the conclusion or performance of a contract in the interest of the data subject concluded between the controller and another natural or legal person.

Cookies

This website uses cookies.
Supplementary information regarding our cookies can be found in the cookie banner.

SSL Encryption

To protect the security of your data during transmission, we use encryption procedures that comply with the current state of the art (e.g., SSL) via HTTPS. You can recognize an encrypted connection by the string "https://" and the lock symbol in your browser's address bar.

Changes or Additions

We reserve the right to make changes or additions to the informational content at any time and without prior notice. If parts or individual phrases of this text do not, no longer, or not completely comply with the applicable legal situation, the remaining parts of the document remain unaffected in their content and validity.

As of 09/2025