Privacy Policy

Scope of application of the privacy policy
This privacy policy applies exclusively to the use of this online shop and to our newsletter.

Contact details of the responsible person and the company data protection officer
This privacy policy applies to data processing by:

Owner and Data Controller
Hotel Schloss Mönchstein*****s
Mönchsberg Park 26
5020 Salzburg
Austria
salzburg@monchstein.at
+43 (0)662 / 84 85 55-0
www.monchstein.at


Processing of personal data (type, purpose and use)
When you visit the website
When you access this website, information is temporarily stored on the server in log files. This is information that the browser on your device automatically sends. Namely:
  • IP address of the contacting device
  • Date and time
  • URL of the accessed page
  • Referrer URL
  • Browser and other device information
The specified data is processed by us for the following purposes:
  • Establishing a connection to the website
  • Use of our website
  • System security and stability 
Data is processed based on your request and is required for the purposes specified in Art. 6 Para. 1 (1) (b) GDPR for the fulfilment of the contract and pre-contractual measures.

Order processing
The following data is also collected for processing an order:
  • Salutation
  • First and last name
  • Address
  • Telephone
  • E-mail address
  • Credit card data, if applicable
Data is processed based on your request and is required for the purposes specified in Art. 6 Para. 1 (1) (b) GDPR for the fulfilment of the contract and pre-contractual measures.

Newsletter
If you would like to subscribe to the newsletter offered on the website, we require an e-mail address from you as well as information that allows us to verify that you are the owner of the e-mail address provided and that you agree to receive the newsletter. No additional data will be collected. We use this data exclusively for the dispatch of the requested information and do not pass the data on to third parties. You can revoke your consent to the storage of data, your e-mail address and its use for sending the newsletter at any time, for example via the "Unsubscribe" link in the newsletter.

Disclosure of data to third parties (incl. other responsible persons and order data processors)
For the execution of the contract
As far as this is legally permissible according to Art. 6 Para. 1 (1) (b) GDPR and is required for the processing of contractual relationships with you, your personal data will be passed on to third parties. The data passed on may be used by third parties exclusively for the specified purposes.

e-guma voucher and ticket system
The personal data specified above is stored and processed by the software provider e-guma® (Idea Creation GmbH, Walchestrasse 15, CH-8006 Zurich) of our online shop within the scope of contract processing.

Datatrans
Your payment data will be processed by the following service provider in the context of payment processing: Datatrans AG, Kreuzbühlstrasse 26, CH-8008 Zurich.

Shipping companies
Your personal data will also be passed on to the transport company commissioned with the delivery, insofar as this is necessary for the delivery of the goods.

Cookies
We use cookies on our website. Cookies are small files that your browser automatically creates and which are stored on your device (laptop, tablet, smartphone, etc.) when you visit our site. A cookie does not always mean that we can identify you.
On the one hand, cookies are used to record the frequency of use, number of users and behaviour on our website as well as to increase the security of website use and to make the information we provide user-friendly.
In addition, we also use temporary cookies that are stored on your device for a specified period of time to optimise user-friendliness. If you visit our site again to use our services, it will automatically recognise that you have visited us before and what entries and settings you have made so that you do not have to enter them again.
Cookies that are required to carry out the electronic communication process or to provide certain functions desired by you (e.g. shopping basket function), are stored on the basis of Art. 6 Para. 1 (f) GDPR.
You can configure your browser settings so that no cookies are stored on your computer. Completely disabling cookies can result in you not being able to use all the functions of our website.
By continuing to use our website and/or agreeing to this privacy policy, you agree that we may set cookies and thus collect, store and use personal user data, even after the end of the browser session. You can revoke this consent at any time by activating the browser default setting to refuse third-party cookies.

Analysis tools
Google Analytics
Our website uses the web analysis service Google Analytics by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Google Analytics uses cookies (see under Cookies). Cookies allow Google in the USA to analyse the use of our website offer including IP addresses. Please note that the code "gat._anonymizeIp();" has been added for Google Analytics on this website to guarantee anonymised collection of IP addresses (IP masking). If anonymisation is activated, Google shortens IP addresses within member states of the European Union or in other signatory states to the Agreement on the European Economic Area. This means that no conclusions can be drawn about your identity. In exceptional cases only, the full IP address will be sent to a Google server in the USA and shortened there. Google complies with the data protection provisions of the "Swiss-USA Privacy Shield" agreement and thus ensures an adequate level of data protection. Google uses the collected information to evaluate the use of our websites for us, to write reports for us in this regard and to provide us with other related services. You can find out more about this at http://www.google.com/intl/de/analytics/privacyoverview.html, especially regarding the possibility of disabling Google Analytics at http://tools.google.com/dlpage/gaoptout?hl=en.
Google Analytics cookies are stored on the basis of Art. 6 Para. 1 (f) GDPR. We have a legitimate interest in analysing user behaviour in order to optimise both our offers and advertising.

Data protection provisions about the application and use of Google-AdWords

On this website, the controller has integrated Google AdWords. Google AdWords is a service for Internet advertising that allows the advertiser to place ads in Google search engine results and the Google advertising network. Google AdWords allows an advertiser to pre-define specific keywords with the help of which an ad on Google's search results only then displayed, when the user utilizes the search engine to retrieve a keyword-relevant search result. In the Google Advertising Network, the ads are distributed on relevant web pages using an automatic algorithm, taking into account the previously defined keywords.

The operating company of Google AdWords is Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, UNITED STATES.

The purpose of Google AdWords is the promotion of our website by the inclusion of relevant advertising on the websites of third parties and in the search engine results of the search engine Google and an insertion of third-party advertising on our website.

If a data subject reaches our website via a Google ad, a conversion cookie is filed on the information technology system of the data subject through Google. The definition of cookies is explained above. A conversion cookie loses its validity after 30 days and is not used to identify the data subject. If the cookie has not expired, the conversion cookie is used to check whether certain sub-pages, e.g, the shopping cart from an online shop system, were called up on our website. Through the conversion cookie, both Google and the controller can understand whether a person who reached an AdWords ad on our website generated sales, that is, executed or canceled a sale of goods.

The data and information collected through the use of the conversion cookie is used by Google to create visit statistics for our website. These visit statistics are used in order to determine the total number of users who have been served through AdWords ads to ascertain the success or failure of each AdWords ad and to optimize our AdWords ads in the future. Neither our company nor other Google AdWords advertisers receive information from Google that could identify the data subject.

The conversion cookie stores personal information, e.g. the Internet pages visited by the data subject. Each time we visit our Internet pages, personal data, including the IP address of the Internet access used by the data subject, is transmitted to Google in the United States of America. These personal data are stored by Google in the United States of America. Google may pass these personal data collected through the technical procedure to third parties.

The data subject may, at any time, prevent the setting of cookies by our website, as stated above, by means of a corresponding setting of the Internet browser used and thus permanently deny the setting of cookies. Such a setting of the Internet browser used would also prevent Google from placing a conversion cookie on the information technology system of the data subject. In addition, a cookie set by Google AdWords may be deleted at any time via the Internet browser or other software programs.

The data subject has a possibility of objecting to the interest based advertisement of Google. Therefore, the data subject must access from each of the browsers in use the link www.google.de/settings/ads and set the desired settings.

Further information and the applicable data protection provisions of Google may be retrieved under https://www.google.com/intl/en/policies/privacy/.



PayPal as a payment processor

On this website, the controller has integrated components of PayPal. PayPal is an online payment service provider. Payments are processed via so-called PayPal accounts, which represent virtual private or business accounts. PayPal is also able to process virtual payments through credit cards when a user does not have a PayPal account. A PayPal account is managed via an e-mail address, which is why there are no classic account numbers. PayPal makes it possible to trigger online payments to third parties or to receive payments. PayPal also accepts trustee functions and offers buyer protection services.

The European operating company of PayPal is PayPal (Europe) S.à.r.l. & Cie. S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg, Luxembourg.

If the data subject chooses "PayPal" as the payment option in the online shop during the ordering process, we automatically transmit the data of the data subject to PayPal. By selecting this payment option, the data subject agrees to the transfer of personal data required for payment processing.

The personal data transmitted to PayPal is usually first name, last name, address, email address, IP address, telephone number, mobile phone number, or other data necessary for payment processing. The processing of the purchase contract also requires such personal data, which are in connection with the respective order.

The transmission of the data is aimed at payment processing and fraud prevention. The controller will transfer personal data to PayPal, in particular, if a legitimate interest in the transmission is given. The personal data exchanged between PayPal and the controller for the processing of the data will be transmitted by PayPal to economic credit agencies. This transmission is intended for identity and creditworthiness checks.

PayPal will, if necessary, pass on personal data to affiliates and service providers or subcontractors to the extent that this is necessary to fulfill contractual obligations or for data to be processed in the order.

The data subject has the possibility to revoke consent for the handling of personal data at any time from PayPal. A revocation shall not have any effect on personal data which must be processed, used or transmitted in accordance with (contractual) payment processing.

The applicable data protection provisions of PayPal may be retrieved under https://www.paypal.com/us/webapps/mpp/ua/privacy-full.




Your rights
You have the right:
  • To request information about your personal data processed by us. In particular, you may request information about the purposes of processing, the category of personal data, the categories of recipients to whom your data have been or will be disclosed, the planned storage period, the existence of a right to rectification, deletion, restriction of processing or objection, the existence of a right of appeal, the origin of your data, if the data has not been collected by us, and the existence of automated decision-making including profiling and, where applicable, meaningful information of details (Art. 15 GDPR). In the event of disproportionately high costs, we reserve the right to require you to provide us with an identification card and to assume the actual costs in advance.
  • To immediately request the correction of incorrect or the completion of your personal data stored by us (Art. 16 GDPR).
  • To request the deletion of your personal data stored by us, unless processing is necessary to exercise the right to freedom of expression and information, to fulfil a legal obligation, for reasons of public interest or to assert, exercise or defend legal claims (Art. 17 GDPR)
  • To demand the restriction of the processing of your personal data if you dispute the accuracy of the data, if processing is unlawful but you refuse to delete it and we no longer need the data, but if you need it to assert, exercise or defend legal claims, or if, pursuant to Art. 21 GDPR you have filed an objection to processing (Art. 18 GDPR).
  • To receive your personal data, which you have provided to us, in a structured, current and machine-readable format or to request the transmission to another responsible person (Art. 20 GDPR).
  • To revoke your consent to us at any time. As a consequence, we are no longer allowed to continue the data processing based on this consent in the future (Art. 7 Para. 3 GDPR)
  • To complain to a supervisory authority (Art. 77 GDPR)
Right of objection
If your personal data is processed based on legitimate interests according to Art. 6 Para. 1 (1) (f) GDPR, you have the right, in accordance with Art. 21 GDPR to object to the processing of your personal data if there are reasons for this which arise from your particular situation or if the objection is directed against direct advertising. In the latter case, you have a general right of objection, which we will implement without specifying a particular situation.

Data security
Your personal data will be transmitted from this website to us in SSL-encrypted form. We protect our website against unauthorised access by means of technical and organisational measures.

Storage period
We will retain your personal information for as long as we deem necessary or appropriate to comply with applicable laws or as long as it is necessary for the purposes for which it was collected. We will delete your personal data as soon as it is no longer required and in any case after expiry of the legally prescribed maximum retention period of five or ten years. Data that is no longer required and for which there is no legal obligation to keep it will be destroyed once the purpose and reason for justification have ceased to exist.

Up-to-dateness and amendment of this privacy policy
We reserve the right to amend this privacy policy at any time or to adapt it to new processing methods.

Version: 01.09.2023