Privacy
Privacy policy of Wilderer Group
Here you can read which personal data we process when you use our website and when you make an enquiry - and what rights you have.
Controller (Art. 4 No. 7 GDPR)
- Company
- Wilderer Chalets Tirol GmbH
- Registered office
- Am Anger 14, 6100 Mösern
- Phone:
- +43 664 147 91 23
- Email:
- servus@wilderer.tirol
Controller (Art. 4 No. 7 GDPR)
This body is responsible for the processing of personal data in connection with this website.
- Company
- Wilderer Chalets Tirol GmbH
- Address
- Am Anger 14, 6100 Mösern, Austria
- Phone:
- +43 664 147 91 23
- Email:
- servus@wilderer.tirol
1. General information on data processing
In this privacy policy we explain which personal data are processed when you use our website. Personal data are pieces of information relating to an identified or identifiable natural person (for example a name, an address, an email address, an IP address, user behaviour).
Processing takes place in particular on the basis of Art. 6(1)(a)-(f) GDPR - for instance to perform a contract, to carry out pre-contractual measures, because of legal obligations, vital interests, the performance of a task carried out in the public interest, or to protect legitimate interests, unless overriding rights of the data subject stand in the way.
2. Collection of personal data when you visit our website
If you use our website purely for information - that is, you do not register and do not send us any other information - we only process the data your browser transmits for technical reasons. These data are needed in order to display our site to you reliably and securely (Art. 6(1)(1)(f) GDPR).
These include in particular:
- IP address
- the date and time of the request
- the time-zone difference from Greenwich Mean Time (GMT)
- the content of the request (the specific page or URL)
- access status / HTTP status code
- the amount of data transferred in each case
- the website the request comes from (referrer)
- browser, operating system and its interface
- the language and version of the browser software
3. Contacting us by email or through the contact form
If you contact us by email or through a contact form, we process the data you provide (for example your name, email address, phone number and the content of your message) in order to deal with your request and answer any follow-up questions.
The legal basis is usually Art. 6(1)(b) GDPR (pre-contractual measures or performance of a contract) or - for general enquiries - our legitimate interest in efficient communication (Art. 6(1)(f) GDPR). Where you give your express consent, Art. 6(1)(a) GDPR may also apply.
We delete the data arising in this context as soon as they are no longer needed for the respective purpose, unless statutory retention obligations prevent this.
4. Cookies
Our website uses cookies. These are small text files stored on your device through which certain information flows back to us or to the service concerned. Cookies cannot run programmes or transmit viruses; they serve, for example, to make the site more user-friendly and efficient.
You can configure your browser so that it refuses third-party cookies or all cookies. Please note that not all functions of our website may then be fully available.
We use the following categories in particular:
- Transient cookies (for example session cookies), which are deleted automatically when the browser session ends.
- Persistent cookies, which are deleted automatically after a defined period or which you can remove manually in your browser settings.
5. Further functions, services & recipients
Beyond the purely informational use of our website we offer further services (for example booking enquiries). Additional personal data may be processed for these, for instance in order to handle contracts or to provide particular services. The principles set out in this privacy policy apply to that processing.
For some processing we use external service providers (for example hosting providers and technical service providers) acting as processors under Art. 28 GDPR. We have selected them carefully, bound them contractually and check them regularly.
Personal data are only passed on to third parties for their own purposes where this is legally permitted, where you have consented or where it is necessary in order to handle a contract. Where service providers or partners are based outside the European Economic Area, we provide information about the relevant safeguards under Art. 46 GDPR as part of the respective service.
6. Web analytics (Google Analytics 4) and embedded services
Only if you consent to the “Analytics” category in the cookie banner do we load Google Analytics 4 from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). We use it to evaluate which pages are visited and whether search and booking are used — without advertising features, without Google Signals and without search parameters or guest data in the transmitted addresses. Google Analytics 4 does not store full IP addresses. Transfer to the USA is possible; Google is certified under the EU-US Data Privacy Framework.
The legal basis is your consent (Art. 6(1)(a) GDPR, § 165(3) TKG 2021). You can withdraw it at any time via “Cookie settings” in the footer; from then on nothing is transmitted. We store your choice in a cookie for 180 days.
We also embed the following services; when they are loaded, your IP address is necessarily transmitted to the respective provider:
- Hosting: Amazon Web Services EMEA SARL (AWS Amplify, Frankfurt data centre; delivery via the Amazon CloudFront network) — Art. 6(1)(f) GDPR.
- Images: Cloudinary Ltd. (delivery of photos) — Art. 6(1)(f) GDPR.
- Maps: Google Maps from Google Ireland Limited — only once you load the map with a click (consent, Art. 6(1)(a) GDPR).
7. Children
Our offering is aimed at adults. People under 18 should not send us any personal data without the consent of a parent or guardian.
8. Your rights as a data subject
You have extensive rights regarding the processing of your personal data. An extract of the most important rights under the GDPR follows below.
9. Data security
We use technical and organisational security measures to protect your data against manipulation, loss, unauthorised access and other misuse. This includes in particular the encrypted transmission of content where technically provided for (for example via TLS/SSL).
Our security measures are reviewed regularly and improved continuously in line with technological developments.
10. Currency of this privacy policy
We adapt this privacy policy as soon as changes to the processing we carry out, or to legal requirements, make this necessary. The current version published on this website is the one that applies.
- Withdrawing consent
- You can withdraw consent once given at any time with effect for the future, without affecting the lawfulness of the processing carried out up to that point.
- Access & confirmation
- You have the right to know whether we process data concerning you, and which data these are in detail (Art. 15 GDPR).
- Rectification & completion
- If data are inaccurate or incomplete, you can ask for them to be corrected or completed (Art. 16 GDPR).
- Erasure (“right to be forgotten”)
- Under the conditions of Art. 17 GDPR you can ask for your personal data to be erased, for example when they are no longer needed for the purposes of the processing.
- Restriction of processing
- In certain cases you can ask for the processing of your data to be restricted (Art. 18 GDPR), for instance while your objections are being examined.
- Data portability
- You have the right to receive the data you provided in a structured, commonly used and machine-readable format, or - where technically feasible - to have them transmitted directly to another controller (Art. 20 GDPR).
- Right to object
- Where we process data on the basis of Art. 6(1)(e) or (f) GDPR, you can object at any time on grounds arising from your particular situation. This applies in particular to direct marketing (Art. 21 GDPR).
- Right to lodge a complaint
- You also have the right to lodge a complaint about the processing of your data with a competent data protection supervisory authority (Art. 77 GDPR).
To exercise your rights you can contact us at any time using the contact details given under "Controller".