Data protection declaration and general terms and conditions
Status: June 22nd, 2021
We ("we", "us", "our") take the protection of the data of the users ("users" or "you") of our website and / or our mobile app (the "website" or the " Mobile app ”) and we undertake to protect the information that users provide to us in connection with the use of our website and / or our mobile app (collectively:“ digital assets ”). Furthermore, we undertake to protect and use your data in accordance with applicable law.
How we collect data
What data we collect
Why we collect this data
Who we pass the data on to
Where the data is stored
How long the data will be kept
How we protect the data
How we deal with minors
What data do we collect?
Below is an overview of the data we can collect:
Unidentified and unidentifiable information that you provide during the registration process or that is collected through the use of our services ("non-personal data"). Non-personal data does not allow any conclusions to be drawn about who collected it. Non-personal information that we collect consists primarily of technical and aggregate usage information.
Individually identifiable information, ie all those that can be used to identify you or that could identify you with reasonable effort (“personal data”). The personal information we collect through our services may include information that is requested from time to time, such as names, email addresses, addresses, phone numbers, IP addresses, and more. If we combine personal data with non-personal data, we will treat these as personal data as long as they exist in combination.
How do we collect data?
Below are the main methods we use to collect data:
We collect data when you use our services. So when you visit our digital assets and use services, we can collect, record and store the usage, sessions and related information.
We collect data that you provide to us yourself, for example when you contact us directly via a communication channel (e.g. an email with a comment or feedback).
We may collect data from third party sources as described below.
We collect data that you provide to us when you log into our services via a third party provider such as Facebook or Google.
Why do we collect this data?
We can use your data for the following purposes:
to provide and operate our services;
to develop, customize and improve our services;
to respond to your feedback, inquiries and requests and offer help;
to analyze requirement and usage patterns;
for other internal, statistical and research purposes;
to improve our data security and fraud prevention capabilities;
to investigate violations and to enforce our terms and conditions and to comply with applicable law, regulations or government orders;
to provide you with updates, news, promotional materials and other information related to our services. In the case of promotional emails, you can decide for yourself whether you want to continue to receive them. If not, just click the unsubscribe link in those emails.
Who do we share this data with?
We can pass on your data to our service providers in order to operate our services (e.g. storage of data via third-party hosting services, provision of technical support, etc.).
We may also disclose your information in the following circumstances: (i) to investigate, detect, prevent or take action against illegal activities or other misconduct; (ii) to establish or exercise our rights of defense; (iii) to protect our rights, property, or personal safety, and the safety of our users or the public; (iv) in the event of a change of control at us or at one of our affiliated companies (by way of a merger, acquisition or purchase of (essentially) all assets, etc.); (v) to collect, hold and / or manage your data using authorized third-party providers (e.g. cloud service providers), insofar as this is appropriate for business purposes; (vi) to work with third parties to improve your user experience. To avoid misunderstandings, we would like to point out that we can transmit or pass on or otherwise use non-personal data to third parties at our own discretion.
Please note that our services enable social interactions (e.g. post content, information and comments publicly and chat with other users). We would like to point out that any content or data that you provide in these areas can be read, recorded and used by other people. We do not recommend posting or sharing any information that you do not want to make public. If you upload content to our digital assets or otherwise make it available as part of the use of a service, you do so at your own risk. We cannot control the actions of other users or members of the public with access to your data or content. You acknowledge and confirm that copies of your data can still be accessed by third parties even after they have been deleted on cached and archived pages or after a copy / storage of your content has been made.
When you visit or access our services, we authorize third parties to use web beacons, cookies, pixel tags, scripts and other technologies and analysis services (“tracking technologies”). These tracking technologies can enable third parties to automatically collect your data in order to improve the navigation experience on our digital assets, to optimize their performance and to guarantee a tailor-made user experience, as well as for security and fraud prevention purposes.
We will not pass on your email address or other personal data to advertising companies or advertising networks without your consent.
We may serve advertising through our services and our digital assets (including websites and applications that use our services) that may also be tailored to you, such as: B. Ads based on your recent browsing habits on websites, devices or browsers.
Where do we store the data?
Personal data may be maintained, processed and stored in the United States, Ireland, South Korea, Taiwan, Israel and to the extent necessary for the proper provision of our services and / or required by law (as further explained below) in other jurisdictions.
How long will the data be kept?
Please note that we keep the collected data for as long as is necessary to provide our services, to comply with our legal and contractual obligations to you, to resolve disputes and to enforce our agreements.
We can correct, supplement or delete incorrect or incomplete data at our own discretion at any time.
How do we protect the data?
The hosting service for our digital assets provides us with the online platform through which we can offer you our services. Your data can be stored via the data storage, databases and general applications of our hosting provider. It stores your data on secure servers behind a firewall and offers secure HTTPS access to most areas of its services.
All payment options offered by us and our hosting provider for our digital assets comply with the regulations of the PCI-DSS (data security standard of the credit card industry) of the PCI Security Standards Council. This is a collaboration between brands such as Visa, MasterCard, American Express and Discover. PCI-DSS requirements help to ensure the secure handling of credit card data (including physical, electronic and procedural measures) by our shop and the service providers.
Regardless of the measures and efforts taken by us and our hosting provider, we cannot and will not guarantee the absolute protection and security of the data that you upload, publish or otherwise pass on to us or others.
For this reason, we would like to ask you to set secure passwords and, if possible, not to provide us or others with confidential information, the disclosure of which, in your opinion, could cause you significant or lasting damage. Since e-mail and instant messaging are not considered secure forms of communication, we also ask you not to pass on any confidential information via any of these communication channels.
How do we deal with minors?
The services are not intended for users who have not yet reached the legal age of majority. We will not knowingly collect information from children. If you are under the age of majority, you should not download or use the Services or provide any information to us.
We reserve the right to request proof of age at any time so that we can verify that minors are using our services. In the event that we become aware that a minor is using our services, we can prohibit these users from accessing our services and block them, and we can delete all data we have stored about this user. If you have reason to believe that a minor has disclosed data to us, please contact us as explained below.
Children may be able to use certain of our services. However, if you want access to certain functions, you may need to provide certain information. Some data (including data collected through cookies, web beacons, and other similar technologies) may be collected automatically. If we knowingly collect, use, or disclose information we have collected from a child, we will notify it and obtain parental consent in accordance with applicable law. We do not make a child's participation in an online activity conditional on the child providing more contact information than is reasonably necessary to participate in that activity. We only use the information we collect in connection with the services that the child has requested.
We may also use a parent's contact details to communicate about the child's activities on the Services. Parents can view information we have collected from their child, prohibit us from collecting any other information about their child, and request that any information we collect be deleted from our records.
Please contact us to view, update or delete your child's data. To protect your child, we may ask you to provide proof of your identity. We can deny you access to the data if we believe that your identity is questionable. Please note that certain data cannot be deleted due to other legal obligations.
the use of your personal data is necessary to perform or conclude a contract (e.g. to provide you with the services yourself or to provide customer service or technical support);
the use of your personal data is necessary to comply with relevant legal or regulatory obligations, or
the use of your personal data is necessary to support our legitimate business interests (provided that this is done at all times in a manner that is proportionate and respects your data protection rights).
As an EU resident, you can:
request confirmation as to whether or not personal data relating to you is being processed and request access to your stored personal data and certain additional information;
request the receipt of personal data that you have provided to us in a structured, common and machine-readable format;
request the correction of your personal data that is stored by us;
request the deletion of your personal data;
object to the processing of your personal data by us;
request the restriction of the processing of your personal data, or
submit a complaint to a supervisory authority.
Please note, however, that these rights are not unlimited and may be subject to our own legitimate interests and regulatory requirements. If you have general questions about the personal information we collect and how we use it, please contact us as detailed below.
In the course of providing the services, we can transfer data across borders to affiliated companies or other third parties and from your country / legal system to other countries / legal systems worldwide. By using the services, you consent to the transfer of your data outside of the EEA.
If you are based in the EEA, your personal data will only be transferred to locations outside the EEA if we are convinced that there is an adequate or comparable level of protection of personal data. We will take appropriate steps to ensure that we have adequate contractual arrangements with our third parties to ensure that appropriate security measures are in place so that the risk of unlawful use, alteration, deletion, loss or theft of your personal data is minimized and that these third parties act in accordance with applicable law at all times.
California Consumer Law Rights
If you use the Services as a California resident, you may be entitled under the California Consumer Privacy Act ("CCPA") to request access to and deletion of your information.
To exercise your right to access and delete your data, please read below how to contact us.
We do not sell users' personal information for the intentions and purposes of the CCPA.
Users of the Services who are California residents and are under the age of 18 can request and obtain the deletion of their published content by email at the address provided in the “Contact Us” section below. These requests must all be marked with "California Removal Request". All requirements must include a description of the content that you wish to be deleted and sufficient information to enable us to locate the material. We will not accept communications that are not flagged or improperly delivered, and we may not be able to respond if you do not provide sufficient information. Please note that your request does not ensure that the material will be completely or completely deleted. For example, material you post may be republished or reposted by other users or third parties.
Part 2: General Terms and Conditions of Hotel Ermitage Kandersteg AG
Cancellation policy for overnight stays
Cancellation conditions: up to 48 hours before arrival, cancellation is free of charge, after that we charge 100% of the first night (booking total for the first night). In the case of prepayment, a corresponding credit will be automatically refunded to the credit card (appears on the credit card statement max. 10 working days after cancellation).
If you have general questions about the Services or the information we collect about you and how we use it, please contact us at:
Name: Hotel Ermitage Kandersteg AG
Address: Oeschinenstrasse 49, CH-3718 Kandersteg
Email address: firstname.lastname@example.org