---
title: Our privacy policy
url: "https://www.quellenviertel.at/en/line/our-privacy-policy.html"
image: "https://www.quellenviertel.at/fileadmin/user_upload/quellenviertel.at/Logos/animated_quellenviertel_logos_typo3_css.svg"
date: 2026-02-06
modified: 2026-07-17
---

# Our privacy policy

**Privacy Policy and information pursuant to Articles 13 and 14 of the GDPR**
=============================================================================

 [ Table of Contents ](#ttgNCECollapse441209)
----------------------------------------------

**1. General**
--------------

The protection of your personal data is of particular importance to us. We therefore process your data exclusively in a lawful manner in accordance with statutory provisions (in particular the GDPR, the Data Protection Act 2018 and the Telecommunications Act 2021). In this privacy notice, we inform you about the most important aspects of data processing – the nature, scope and purposes of the collection and use of personal data – in connection with the use of our website and in connection with other services provided by our company.

### **1.1. Data controller**

The data controller (within the meaning of Article 4(7) of the GDPR) responsible for the processing of your personal data (personal data within the meaning of Article 4(1) of the GDPR) is:

Quellenviertel Tourist Board
Promenade 2
A-4701 Bad Schallerbach
Tel. +43 (0)7249/420710
Email: <info@quellenviertel.at>

**Data Protection Officer:**
We take the protection of personal data seriously and have appointed an external Data Protection Officer for this purpose. Our Data Protection Officer is MMag. Martin Zeppezauer, Thurnbichlweg 54, A-6353 Going am Wilden Kaiser ([www.zepedes.com](http://www.zepedes.com)). You can contact our Data Protection Officer at the email address <martin@zepedes.com> .

### **1.2. Purposes, categories of data and legal bases for the processing of personal data**

**Purposes of processing**
The purposes for which we process your personal data generally arise from our business activities as a tourism organisation: providing our online services, processing customer enquiries, orders and bookings, accounting, and communicating with business partners and customers. Detailed information on the purposes of processing and, where applicable, on further processing for other compatible purposes, as well as on the categories of data processed, can be found in the detailed descriptions of the individual data processing operations.

**General categories of data**

- Personal master data (e.g. name, date of birth and age, address)
- Contact details (e.g. email address, telephone number, fax number)
- Communication data (time and content of the communication)
- Order or booking data (e.g. goods ordered or services commissioned, and invoicing details such as service period, payment method, invoice date, tax identification number, etc.)
- Payment details (e.g. account number, credit card details)
- Contract data (contents of contracts of any kind)
- Web usage data (e.g. server data, log files and cookies)
- CCTV footage

**Special categories of data (‘sensitive data’) in accordance with Article 9 of the GDPR**

- Health data (only where you have provided this to us through your explicit consent to the processing of your request (e.g. booking a hotel specialising in guests with food intolerances or allergies))

**Legal bases for processing**
In principle, there is no obligation to provide the data described in this privacy policy. Failure to provide this data simply means that we cannot offer these services. The legal basis for the processing of your personal data required to fulfil a contract with you or an order placed by you with us is Article 6(1)(b) of the GDPR. Where the processing of personal data is necessary for us to comply with a legal obligation (accounting obligations, bookkeeping obligations or other statutory documentation requirements), Article 6(1)(c) of the GDPR serves as the legal basis. Where the processing of data is carried out in your own vital interests, the legal basis for the data processing is Article 6(1)(d) of the GDPR. If we process your data to carry out a task carried out in the public interest (‘exercise of official authority’), the legal basis is Article 6(1)(e) of the GDPR. If the processing is necessary to safeguard a legitimate interest of our company or a third party, and your interests, fundamental rights and freedoms do not override our interest, Article 6(1)(f) of the GDPR (‘legitimate interest’) serves as the legal basis for the processing. In this case, we will also inform you of our legitimate interests. Where we have no other legal basis for the processing of personal data as explained above, we will ask for your consent to the data processing; in such cases, we will rely on Article 6(1)(a) of the GDPR or, in the case of the processing of sensitive data, on Article 9 (2)(a) of the GDPR as the legal basis. You may withdraw this consent at any time, free of charge, without this affecting the lawfulness of the processing carried out on the basis of your consent prior to its withdrawal.

### **1.3. Disclosure of data to data processors and third parties**

We process your personal data with the assistance of data processors who support us in providing our services. These data processors are bound by a relevant agreement with us within the meaning of Article 28 of the GDPR to strictly protect your personal data and may not process your personal data for any purpose other than the provision of our services. You can find out which data processors are involved in the detailed descriptions of the individual data processing operations.

Your personal data may be disclosed to businesses other than our data processors, such as service providers typical in the business sector, e.g. banks, tax advisers or auditors. Personal data is only transferred to state institutions and authorities where required by mandatory national legislation.

Depending on your request (e.g. for bookings and enquiries), your personal data will be transferred, strictly to the extent necessary, to hotel partners or other tourism service providers (members of our organisation) where this is required to fulfil your request. The personal data transferred varies depending on the service.

### **1.4. Transfers to third countries**

As a general rule, we process your personal data within the EU. Where we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or where this occurs in connection with the use of services provided by our data processors or third parties, this will only take place if the conditions set out in Articles 44 et seq. of the GDPR for transfers to third countries are met: that is, on the basis of specific safeguards, such as an officially recognised determination that the level of data protection is equivalent to that of the EU, or in accordance with officially recognised contractual obligations, the so-called ‘EU Standard Contractual Clauses’. If we rely on the EU Standard Contractual Clauses as the legal basis for the transfer of your personal data, we will also assess the lawfulness of this data transfer as part of a comprehensive risk assessment. Should we reach a negative conclusion in this regard, we will not  transferthis data  to a third countrywithout your explicit consent in accordance with Article  49(1)(a) of the GDPR.

### **1.5. Data erasure and retention period**

We will erase your personal data as soon as the purpose for which we collected your data no longer applies. Data may also be retained if we process it for a purpose compatible with the original purpose. It may also be retained if this is required by laws, regulations or other provisions to which our company is subject.

### **1.6. Data sources**

We generally collect your personal data directly from you. We also receive personal data from some of our partners. You can find further information on this in the relevant sections of this privacy policy.

### **1.7. Profiling**

We do not use any automated decision-making or profiling procedures that have legal effects on you or similarly significantly affect you. However, with your consent, we will use your usage data to gain a better understanding of your interests and thereby be able to display information of interest to you, make tailored offers to you, or display relevant information to you on third-party websites or social media platforms.

### **1.8. Safeguarding your data protection rights**

In accordance with the GDPR, you generally have the right to access, rectify, erase and restrict the processing of your personal data. If the legal basis for the processing of your personal data is your consent or a contract concluded with you, you also have the right to data portability. You have the right to withdraw any consent you may have given to the processing of your personal data. This does not affect the lawfulness of the processing of your personal data up to the point of withdrawal. You have the right to object to the processing of your personal data for the purposes of direct marketing. In the event of an objection, your personal data will no longer be processed for the purposes of direct marketing. A detailed explanation of these rights can be found [here](http://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32016R0679&from=EN) in Chapter III.

**Right to lodge a complaint**
If you believe that the processing of your data infringes data protection law or that your data protection rights have otherwise been infringed, you may lodge a complaint with the competent supervisory authority. In Austria, this is the Data Protection Authority (Barichgasse 40–42, A-1030 Vienna, email: <dsb@dsb.gv.at>).

**2. Visiting our website**
---------------------------

In this section, we explain how we process your personal data when you visit our website.

### **2.1. Website display**

**Server data**

For technical reasons, and on the legal basis of Section 165 (3) S 3 of the TKG 2021 (necessary for the operation of our website), the following data – amongst other things – which your internet browser transmits to us or to our web hosting provider is collected (so-called ‘server log files’):

- Browser type and version
- Operating system and device type used (e.g. desktop / mobile)
- Website from which you are visiting us (referrer URL)
- Website you are visiting
- Date and time of your visit
- Your Internet Protocol address (IP address)

This data, which is anonymous to us, is stored separately from any personal data you may have provided for a period of 7 days and therefore does not allow us to identify any specific individual. It is analysed for statistical purposes to enable us to optimise our website and our services.

**SSL or TLS encryption**

For security reasons and to protect the transmission of confidential content, such as orders or enquiries that you send to us as the website operator, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address bar of your browser changes from ‘http://’ to ‘https://’ or by the padlock icon in your browser bar. When SSL or TLS encryption is enabled, the data you send to us cannot be read by third parties.

**Technical service providers**

We create and edit the content of our website with the help of the following service providers, whom we have bound by a corresponding agreement within the meaning of Article 28 of the GDPR to process your data exclusively within the scope of our mandate:

Technical design:

- TTG Tourismus Technologie GmbH (Freistädter Str. 119, A-4040 Linz). Further information on data protection is available at: <https://www.ttg.at/datenschutz>

Web hosting:

- Mittwald CM Service GmbH & Co.KG (Königsberger Str. 4–6, D-32339 Espelkamp). Further information on data protection is available at: <https://www.mittwald.de/datenschutz>

### **2.2. Cookies**

**Cookie banner – Cookies on our website – Consent Management System**

Our website uses cookies to help us make our website more user-friendly and efficient for you, to carry out statistical analyses of how our website is used, and to display content of interest to you on other websites as well. Cookies are small data files used to store information relating to visits to websites and are stored on the website visitor’s computer. The legal basis for cookies that are strictly necessary for the proper functioning of our website (e.g. shopping basket cookies) is Section 165(3), sentence 3 of the Telecommunications Act 2021 (TKG 2021). Cookies that are not necessary for the functioning of our website (e.g. analytics or marketing cookies) are disabled and are only activated once you have given your consent in accordance with Article 6(1)(a) of the GDPR via our cookie banner (‘Accept’). By clicking on “Settings”, you can enable or disable individual cookies or groups of cookies. If you restrict the use of cookies on our website, you may no longer be able to use all of our website’s functions to their full extent. Detailed information about the cookies used on our website can be found in our cookie banner.

The legal basis for the use of this cookie banner (consent management platform), to manage and document your consent or settings regarding cookies and other tools requiring consent for access to our website, is our legal obligation under Article 6(1)(c) of the GDPR. When you access our website, a connection is established with the server of our cookie banner provider and, as a result, a cookie is stored in your browser to save your cookie settings. The data processed is stored until the specified retention period expires or you delete these cookies.

We use the following cookie banner / provider:

- ‘Consent Management Platform TTG’ by TTG Tourismus Technologie GmbH (Freistädter Str. 119, A-4040 Linz). Further information on data protection is available at: <https://www.ttg.at/datenschutz>

[Cookies anpassen](#)

**Changing your cookie settings in your web browser**

You can specify in your web browser’s settings how your browser handles cookies – in other words, which cookies are accepted or rejected. You can also delete cookies already stored on your computer or device at any time. The exact location of these settings depends on the web browser you are using. Detailed information on this can be found via the help function of the relevant web browser.

In addition, you have the option to opt out of cookies and similar tracking technologies in general via the services listed below by setting your individual preferences – specifying which technologies for usage- and interest-based advertising you wish to allow:

- European Interactive Digital Advertising Alliance (EDAA): <https://www.youronlinechoices.com/de/praferenzmanagement/>
- Network Advertising Initiative (NAI):
    <https://optout.networkadvertising.org/?c=1#!%2F>

### **2.3. Contacting us**

**Contact form and email**
On our website, we offer you the option of contacting us by email and/or via a contact form. In this case, the information you provide will be processed for the purpose of handling your enquiry on the legal basis of the performance of a contract in accordance with Article 6(1)(b) of the GDPR. We have a legitimate interest, in accordance with Article 6(1)(f) of the GDPR, in using a contact form. This legitimate interest lies in offering our website visitors a way to get in touch that does not require them to open their own email client.In the case of contact or order forms where we request your title in addition to your first name and surname, we do so on the basis of our legitimate interest in accordance with Article 6(1)(f) of the GDPR. Our interest here lies in addressing our customers and business partners in a personalised and polite manner. There is no legal or contractual obligation to provide this personal data. Failure to provide it simply means that you will not be able to submit your enquiry and we will not be able to process it. Data will only be disclosed to third parties where this is stated on the website or in this privacy policy, where it is necessary for the performance of a contract, or where required by law. We will only store your data for as long as is necessary to process your enquiries or to deal with any follow-up queries.

### **2.4.** **Online shop(s) / booking portal(s)**

For the purpose of providing contractual services, as well as their payment and fulfilment in connection with online purchases, bookings and brochure orders, we process your personal master data, contractual and payment data, and communication data (IP address and server log files) on the legal basis of Article 6(1)(b) of the GDPR (performance of a contract) and Article 6(1)(c) of the GDPR (legal obligation to keep accounts and archive records).

We store this data for as long as the purpose requires, or as long as statutory provisions so require (retention period for invoices in accordance with Section 132 of the Austrian Federal Tax Code (BAO) for 7 years; voucher orders for 30 years until the expiry of the redemption period) or we require this data on the legal basis of Article 6(1)(f) of the GDPR (legitimate interest) to defend against potential liability claims. Should you cancel the ordering process, we will store the data for 14 days to clarify any issues that may have arisen during the ordering process.

There is no legal or contractual obligation to provide personal data. Failure to provide such data will simply mean that we cannot process your bookings or orders.

**Feratel DESKLINE online bookings, booking enquiries and brochure orders**

To process online bookings, brochure orders and enquiries, we process your personal data in order to be able to provide you with the services you have booked, with the assistance of our service provider feratel Media Technologies AG (Maria-Theresien-Straße 8, A-6020 Innsbruck). To this end, we store and process master data, communication data, contractual data and payment data relating to our customers, prospective customers and other business partners. The processing is carried out for the purpose of providing contractual services or fulfilling pre-contractual obligations on the legal basis of Article 6(1)(b) of the GDPR (booking transactions, responding to enquiries regarding quotations and sending out brochures) and Article 6(1)(c) of the GDPR (statutory retention periods for bookings and invoices). To this end, the data fields marked as required are necessary for the conclusion and performance of the contract. We disclose your personal data to third parties (hotel partners or other tourism service providers) in the context of these data processing activities on the legal basis of Article 6(1)(b) of the GDPR (where necessary to process a booking), or on the basis of our legitimate interest pursuant to Article 6(1)(f) of the GDPR for the use of the relevant booking software. We have entered into a corresponding agreement with feratel as a data processor in accordance with Article 28 of the GDPR, which ensures that your data is processed exclusively within the scope of our mandate. Further information on feratel’s data protection policy can be found at: <https://www.feratel.com/datenschutz.html>.

**INCERT Voucher System and Merchandise**

To process orders for holiday vouchers and merchandising items, we use the system provided by INCERT eTourismus GmbH & Co KG (Leonfeldner Strasse 328, A-4040 Linz) as our data processor. This system enables the automated sale of vouchers via ‘print@home’ as well as the individual personalisation of vouchers with dedications, designs and barcodes. The following details are required to process orders: title, first name and surname, address, email address. This data is processed for the purpose of providing contractual services or fulfilling pre-contractual obligations on the legal basis of Article 6(1)(b) of the GDPR.

In order to gain an overview of visitor numbers and usage data in our INCERT online shop, we use the ‘etracker’ service provided by etracker GmbH (Erste Brunnenstraße 1, 20459 Hamburg, Germany) exclusively for those subpages into which this shop has been integrated into our website, on the basis of our legitimate interest pursuant to Article 6 (1)(f) of the GDPR, we use the ‘etracker’ service provided by etracker GmbH (Erste Brunnenstraße 1, 20459 Hamburg, Germany). Our legitimate interest lies in the anonymised analysis of user behaviour in our online shop in order to optimise our product range (items) and their presentation within this online shop. In doing so, the following data is transmitted to etracker: your IP address, details of your operating system and browser, and information about when you visited which pages of our online shop and which products you were interested in. This data is processed by etracker (as indicated by the [ePrivacyseal](https://www.eprivacy.eu/kunden/vergebene-siegel/firma/etracker-gmbh/)) exclusively in Germany and is anonymised or pseudonymised as soon as possible. The data is not used for any other purpose, combined with other data or passed on to third parties.

By default, we do not use cookies for this web analytics. If you have given us your consent to ‘analytics’ cookies, additional cookies will be set by etracker. This enables returning users to be recognised and their behaviour within our online shop to be ‘analysed’ in more detail. The processing of this analytics cookie data (the data is only stored for as long as is necessary for the purposes mentioned above) is therefore carried out on the basis of Article 6(1)(a) of the GDPR. You may withdraw this consent at any time via the cookie settings on our website. Further information on etracker’s data protection policy can be found at: <https://www.etracker.com/datenschutzerklaerung/>

We have entered into a corresponding agreement with INCERT, in accordance with Article 28 of the GDPR, as a data processor, which ensures that your data is processed exclusively within the scope of our mandate. This also includes data processing by etracker as a sub-processor of INCERT. Further information on INCERT’s data protection policy can be found at: <https://www.incert.at/datenschutz/>.

**External payment service providers**

To process payments for orders and bookings, we use external payment service providers on the legal basis of Article 6(1)(b) of the GDPR (performance of a contract), via whose platforms you can make your payments. The payment details you enter as part of your order (e.g. account numbers, credit card numbers including security codes, passwords / TANs, etc.) are processed exclusively by our payment service providers and are not visible to us. We only receive confirmation from our payment service providers that the payment has been made, or notification that the payment could not be processed. Further information on data protection and the terms and conditions of our payment service providers can be found at:

- Datatrans AG, Kreuzbühlstrasse 26, CH-8008 Zurich.
    Tel. +41 44 256 81 91
    Email: <info@datatrans.ch>
    <https://www.datatrans.ch/de/datenschutzbestimmungen/>
- Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA
    Email: <support@stripe.com>
    <https://stripe.com/at/privacy>
- Unzer Austria GmbH, Columbusplatz 7–8, A-1100 Vienna
    T +43 1 5136633669
    Email: <support@unzer.com>
    <https://www.unzer.com/de/datenschutz>
- hobex AG, Josef-Brandstätter-Straße 2b, A-5020 Salzburg
    Tel: +43 662 2255-0
    Email: <office@hobex.at>
    [https://www.hobex.at/at/service/datenschutz\_kunden](https://www.hobex.at/at/service/datenschutz_kunden)
- PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg

Email: <kundenbetreuung@paypal.com>
[https://www.paypal.com/myaccount/privacy/privacyhub?locale.x=de\_AT](https://www.paypal.com/myaccount/privacy/privacyhub?locale.x=de_AT)

### **2.5.** **Online shop(s) / booking portal(s)**

**Email newsletter (TTG)**

On our website, you have the option to subscribe to our newsletter. The legal basis for sending the newsletter is your consent within the meaning of Article 6(1)(a) of the GDPR. Subscription to our newsletter is carried out using the so-called double opt-in procedure. This ensures that nobody can subscribe using someone else’s email address (e.g. your email address). You may withdraw your consent at any time, free of charge, by clicking on the ‘unsubscribe link’ at the end of each email. The lawfulness of any data processing carried out up to that point remains unaffected by the withdrawal. After you have unsubscribed, we will continue to store your email address for a further 3 years on the basis of our legitimate interest (Article 6(1)(f) of the GDPR), in order to be able to prove your original consent if necessary. We use the service provider TTG Tourismus Technologie GmbH (Freistädter Str. 119, A-4040 Linz) to send out our newsletter. With the help of TTG, we are able to analyse our newsletter campaigns. When an email sent using the TTG newsletter tool is opened, a connection is established with TTG’s servers (server location: Linz, Austria). This enables us to determine whether a newsletter message has been opened and, where applicable, which links have been clicked. The purpose of these analyses is to better tailor future newsletters to the interests of the recipients. In addition, technical information such as the time of access, the IP address, browser type and operating system of the recipient is recorded. We have entered into a data processing agreement with TTG within the meaning of Article 28 of the GDPR to ensure that your data is processed only to the extent we require and to which you have consented. General data protection information from TTG is available at: <https://www.ttg.at/datenschutz/>.

### 2.6. Digital information services / Registration

**Teejit KnowledgeHub e-learning platform (e-learning & knowledge management)**

Tourism businesses and staff in our region can register on our website to participate in our e-learning platform, Teejit KnowledgeHub. Teejit is an application for integrating and operating an online knowledge platform, which enables users to access specialist tourism knowledge from various fields. We use the e-learning platform provided by Teejit GmbH (Am Kugelberg 5, D-85072 Eichstätt). This web-based e-learning platform provides access to micro-learning modules focusing on digitalisation in tourism (e.g. online booking, websites, etc.). To register, you must provide your email address and a personal password. To personalise your account (so that suitable training options can be displayed to programme participants), the following additional data may be provided on an optional (voluntary) basis: Personal details (first name, surname, postal address and telephone number), professional details (company name, position within the company, website and work telephone number), and interests (type of business and services offered). We process this data to fulfil contractual obligations (Article 6(1)(b) of the GDPR) in order to be able to provide the services (training courses) on offer. To this end, we will also send you information by email about the training opportunities on offer or any new ones. The legal basis for processing further information (personal data and interests for the purpose of tailoring the offer) is the user’s consent (Article 6(1)(a) of the GDPR). Where the lawfulness of a specific data processing operation is based on the user’s consent, this consent may be withdrawn at any time, free of charge, by editing the personal profile (deletion). Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent prior to its withdrawal. Usage data may be used on the legal basis of our legitimate interest in accordance with Article 6(1)(f) of the GDPR to develop further training programmes. For this purpose, various data relating to users’ learning progress is made available to us within the legal framework. All user data can be irrevocably deleted at any time by deleting your user data in your account under ‘Account Information’. The personal data provided is stored and processed on the servers of our partner, Teejit GmbH, for the duration of your registration. The servers are located in Germany. Teejit uses external software to provide certain content interactively. Separate provisions apply to this software. These include: YouTube and H5P: The data processed is also stored and processed on Teejit’s servers. We have entered into a corresponding agreement with Teejit GmbH as a data processor in accordance with Article 28 of the GDPR, which ensures that your data is processed exclusively within the scope of our mandate. Further information on Teejit GmbH’s data protection policy can be found at: <https://teejit.io/datenschutz/>.

### 2.7 Web analytics – Statistical analyses of our website

**Google Tag Manager**

We use the service provided by Google Ireland Limited (“Google”) (Gordon House, Barrow Street, Dublin 4, Ireland) to manage website tags via a centralised tool. The Google Tag Manager tool itself (which implements the tags) is a domain that does not set any cookies and does not collect any other personal data. The tool triggers other tags, which may in turn collect data. Google Tag Manager does not access this data. If deactivation has been carried out at domain or cookie level, this remains in effect for all tracking tags implemented via Google Tag Manager. Google is a certified partner of the EU-US Data Privacy Framework. The legal basis for (at least in some cases) data transfers to the USA is therefore an adequacy decision by the European Commission within the meaning of Article 45(3) of the GDPR, by which the European Commission certifies that the USA provides an adequate level of data protection. Further information on Google’s data protection can be found at: <https://www.google.com/policies/privacy/>. Further information on how Google uses personal data: <https://business.safety.google/privacy/>.

**Google Analytics**

This website uses features of the web analytics service Google Analytics. The provider of this service is Google Ireland Limited (‘Google’) (Gordon House, Barrow Street, Dublin 4, Ireland). The legal basis for the use of this service is your consent in accordance with Article 6(1)(a) of the GDPR. Google Analytics uses cookies that are stored on the website visitor’s computer and enable an analysis of the visitor’s use of our website. The information generated by the cookie regarding your use of our website is usually stored on servers in Europe and is only transferred to and stored on a Google server in the USA in exceptional cases. We use Google Analytics with IP anonymisation enabled. This means that your IP address is usually truncated by Google whilst still within the European Union, and only in exceptional cases is the full IP address transferred to a Google server in the USA and truncated there. Google is a certified partner of the EU-US Data Privacy Framework. The legal basis for (at least in some cases) data transfers to the USA is therefore an adequacy decision by the European Commission within the meaning of Article 45(3) of the GDPR, by which the European Commission certifies that the USA provides an adequate level of data protection.The IP address transmitted by the relevant browser as part of Google Analytics is not combined with other data held by Google. On our behalf, Google will use the information collected to analyse the use of the website and to compile reports on website activity. Collection by Google Analytics can be prevented by the website visitor adjusting the cookie settings for this website. You may also object at any time, with future effect, to the collection and storage of your IP address and the data generated by cookies. The relevant browser plug-in can be downloaded and installed via the following link: <https://tools.google.com/dlpage/gaoptout>. Further information on Google’s use of data, as well as options for adjusting settings and opting out, can be found in Google’s Privacy Policy (<https://policies.google.com/privacy>) and in the settings for the display of Google adverts (<https://adssettings.google.com/authenticated>). Further information on how Google uses personal data: <https://business.safety.google/privacy/>.

**Google Ads Conversion Tracking**

Our website uses the ‘Google Ads Conversion Tracking’ service provided by Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland). When we place adverts on Google, we use what is known as conversion tracking. When you click on an advert placed by Google, a cookie is set for conversion tracking (retention period: 30 days). This enables us to recognise that you have clicked on one of our adverts and been redirected to our site. However, we do not receive any personal data; we are only informed of the total number of users who have clicked on one of our adverts and been redirected to a page tagged with a conversion tracking tag. We use Google Ads Conversion Tracking on the legal basis of your consent (settings via our cookie banner) in accordance with Article 6(1)(a) of the GDPR. Google is a certified partner of the EU-US Data Privacy Framework. The legal basis for (at least in some cases) data transfers to the USA is therefore an adequacy decision by the European Commission within the meaning of Article 45(3) of the GDPR, by which the European Commission certifies that the USA ensures an adequate level of data protection. Further information on Google’s use of data, as well as options for adjusting settings and exercising your right to object, can be found in Google’s Privacy Policy (<https://policies.google.com/privacy>) and in the settings for the display of Google adverts (<https://adssettings.google.com/authenticated>). Further information on how Google uses personal data: <https://business.safety.google/privacy/>.

**Matomo (on-premise)**

Our website uses the open-source web analytics service Matomo, provided by Innocraft Inc, 150 Willis ST, 6011 Wellington, New Zealand. This enables us to carry out an anonymised analysis of our website visitors’ behaviour in order to optimise both our website and our advertising. We have installed Matomo on our own servers. This means that no data is passed on to Matomo. We process the following data: your IP address (anonymised by truncation), the previously visited URL (referrer – if transmitted by the browser), the name and version of your operating system, and the name, version and language setting of your browser. The use of the Matomo analytics tool is based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR. Our legitimate interest lies in the anonymised analysis of the user behaviour of our website visitors in order to optimise both our website and our advertising. If you have given us your consent to set ‘analytics’ cookies, additional cookies will be set by Matomo. This enables us to recognise returning users and to ‘analyse’ their behaviour on our website in greater detail. The processing of this data (stored for a maximum of 13 months) is carried out on the basis of Article 6(1)(a) of the GDPR. You may withdraw your consent at any time via the cookie settings. Further information on Matomo’s data protection policy can be found at: <https://matomo.org/gdpr-analytics/>.

### 2.8 Web marketing

**Google Remarketing**

Our website uses the functions of ‘Google Analytics Remarketing’ in conjunction with the cross-device functions of Google AdWords and Google DoubleClick, based on the legal basis of your consent in accordance with Article 6(1)(a) of the GDPR. The provider is Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland). This function enables the advertising target groups created with Google Analytics Remarketing to be linked to the cross-device functions of Google AdWords and Google DoubleClick. In this way, interest-based, personalised advertising messages – which have been tailored to you based on your previous usage and browsing behaviour on one device (e.g. a mobile phone) – can also be displayed on another of your devices (e.g. a tablet or PC). If you have given your consent, Google will link your web and app browsing history to your Google Account for this purpose. This enables the same personalised advertising messages to be displayed on any device on which you sign in with your Google Account. To support this function, Google Analytics collects Google-authenticated user IDs, which are temporarily linked to our Google Analytics data in order to define and create audiences for cross-device advertising. Cookies are deleted after 1 year. Google is a certified partner of the EU-US Data Privacy Framework. The legal basis for (at least in some cases) data transfers to the USA is therefore an adequacy decision by the European Commission within the meaning of Article 45(3) of the GDPR, by which the European Commission certifies that the USA provides an adequate level of data protection. You can permanently opt out of cross-device remarketing/targeting by disabling personalised advertising in your Google Account; to do so, follow this link: <https://www.google.com/settings/ads/onweb/>. The aggregation of the data collected in your Google Account is carried out solely on the basis of your consent, which you may give or withdraw via Google (Article 6(1)(a) of the GDPR). Further information on Google’s data protection practices can be found at: <https://www.google.com/policies/privacy/>. Further information on how Google uses personal data: <https://business.safety.google/privacy/>.

**Meta Pixel**

In order to display targeted adverts on Meta platforms (Facebook and Instagram) and to track user actions after they have viewed or clicked on a Meta advert, we use the Meta Pixel provided by Meta Platforms Ireland Ltd. (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) on our website, based on your consent in accordance with Article 6(1)(a) of the GDPR. This enables us to display information of interest to you on Meta platforms and to evaluate and optimise our Meta adverts using the data collected in this way, which is anonymous to us (we do not see the personal data of individual users, but only the overall impact). Retention period: max. 12 months. According to Meta’s privacy policy, Meta links this data to the Meta accounts of its users and can thereby display content to them that matches their interests. Meta is a certified partner of the EU-US Data Privacy Framework. The legal basis for (at least in some cases) data transfers to the USA is therefore an adequacy decision by the European Commission within the meaning of Article 45(3) of the GDPR, whereby the European Commission certifies that the USA provides an adequate level of data protection. Specific information on how the Meta Pixel works can be found in Meta’s help section at: <https://de-de.facebook.com/business/help/651294705016616>. You can adjust your settings regarding usage-based advertising on Meta platforms yourself in your Meta account: <https://www.facebook.com/settings?tab=ads>. Further information can be found in Facebook’s Privacy Policy at: <https://www.facebook.com/privacy/explanation>.

### 2.9. Integration of other third-party services and content

We integrate third-party content and functions into our website. This always requires the providers of this content or these functions to collect the user’s IP address. Without the IP address, they would be unable to send the content to the user’s browser. The IP address is therefore necessary for the display of this content. We endeavour to use only such content where the respective providers use the IP address solely for the purpose of delivering the content. However, we have no control over whether third-party providers store the IP address, for example for statistical purposes. The legal basis for the use of these services is, insofar as they are necessary for the functioning of our website, our legitimate interest pursuant to Article 6(1)(f) of the GDPR; otherwise, it is your consent pursuant to Article 6(1)(a) of the GDPR. Information on the purpose and scope of the further processing and use of the data by the providers of the embedded services/content, as well as further information within the meaning of Articles 13 and 14 of the GDPR, can be found via the information links listed below. The following services/content are embedded in our website:

**destination.one Maps**

We use the ‘destination.one’ service provided by neusta destination.one GmbH (Münchenerstraße 1, D-86899 Landsberg am Lech) to display the accommodation providers in our region on a map. To do this, the map data is loaded from the destination.one server. In doing so, the following data is transmitted to destination.one: the page visited on our website, the IP address of your device, the content of the request, location data, operating system, and the language and version of your browser software. destination.one uses cookies, which are stored on your browser, to analyse your request. The legal basis for the processing of your data is Article 6(1)(f) of the GDPR (legitimate interest). Our legitimate interest lies in presenting our online offering in an appealing manner and in providing a geographical representation of the attractions in our region. In the case of location data from mobile devices, the legal basis is your consent under Article 6(1)(a) of the GDPR, which you provide by authorising the sharing of location data on your mobile device. Further information on data protection at destination.one can be found at: <https://www.destination.one/datenschutz/>.

**Google reCAPTCHA**

To protect your enquiries submitted via the online form and to safeguard against misuse and spam on our website, we use the [reCAPTCHA](https://www.google.com/recaptcha/intro/v3beta.html) service provided by Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland) as our data processor. The checks carried out serve to distinguish whether an entry (e.g. on a contact form) is made by a human or, in an abusive manner, by automated, machine-based processing (bot). In doing so, Google reCAPTCHA processes the following data: the visitor’s IP address, the website visited, browser and device information (including screen resolution, language settings and time zone), mouse movements, click patterns and keystroke dynamics (behavioural data that distinguishes human behaviour from that of bots). This data is transmitted from our website server to reCAPTCHA in the form of an encrypted reCAPTCHA token. reCAPTCHA subsequently returns information to us via an encrypted token to assess whether the visitor to the protected area (e.g. contact form) is a human or a bot. We have a legitimate interest within the meaning of Article 6(1)(f) of the GDPR as the legal basis for the use of Google reCAPTCHA. Our legitimate interest lies in protecting our website from misuse and spam software (blocking spam, and defending against DDoS attacks and other automated attacks). However, we only use Google reCAPTCHA if you have given your consent. The legal basis for the processing of your data is therefore your consent in accordance with Article 6(1)(a) of the GDPR. Google is a certified partner of the EU-US Data Privacy Framework. The legal basis for (at least in some cases) data transfers to the USA is therefore an adequacy decision by the European Commission within the meaning of Article 45(3) of the GDPR, by which the European Commission certifies that the USA provides an adequate level of data protection. We have concluded a corresponding agreement with the service provider in accordance with Article 28 of the GDPR as a data processor (Google Cloud Data Processing Addendum), which ensures that your data is processed by Google exclusively within the scope of our mandate (protection against misuse and spam) and for no other purposes. Further information on the Google Cloud Data Processing Addendum can be found at: <https://cloud.google.com/terms/data-processing-addendum>

**YouTube**

We embed videos from the “YouTube” platform provided by Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland) in enhanced privacy mode. This is carried out on the basis of Article 6(1)(f) of the GDPR, whereby our interest lies in the seamless integration of the videos and the resulting appealing design of our website. However, we only use YouTube if you have given your consent. The legal basis for the processing of your data is therefore your consent in accordance with Article 6(1)(a) of the GDPR, which you may withdraw at any time with future effect. When you visit a page on which we have embedded a YouTube video, a connection is established with Google’s servers and the content is displayed on the website by being sent to your browser. According to Google’s information, in enhanced privacy mode, your data (in particular which of our web pages you have visited) and device-specific information, including your IP address, are only transmitted to the YouTube server when you watch the video. Google is a certified partner of the EU-US Data Privacy Framework. The legal basis for (at least in some cases) data transfers to the USA is therefore an adequacy decision by the European Commission within the meaning of Article 45(3) of the GDPR, by which the European Commission certifies that the USA provides an adequate level of data protection.If you are logged in to Google at the same time, this information will be associated with your Google account. You can prevent this by logging out of your Google account before visiting our website or by adjusting your individual settings in your Google account via the following link: <https://adssettings.google.com/authenticated>. Further information on YouTube’s data protection policy can be found at: <https://www.google.com/policies/privacy/>. Further information on how Google uses personal data: <https://business.safety.google/privacy/>.

**Webcams**

We embed webcams from other websites operated by providers in our region into our website to display the current weather conditions in our region. This is done on the basis of our legitimate interest pursuant to Article 6(1)(f) of the GDPR, whereby our interest lies in providing information on the current weather in our region via our website. When you visit a page on which we have embedded webcams, a connection is established with the providers’ servers and the content is displayed on the website by being sent to your browser. To do this, it is necessary for your IP address, together with certain browser information (browser type, browser version, etc.) and details of when you accessed these pages, to be transmitted to the providers’ servers.

**3. Other data processing in business and customer relations**
---------------------------------------------------------------

In this section, we provide information about other data processing activities outside our website.

### **3.1. Job applications**

The contact details and application documents sent to us as part of a job application are processed by us exclusively internally for the purpose of selecting suitable candidates for employment. There is no legal or contractual obligation to provide personal data. Failure to provide such data simply means that you will not be able to submit your application and we will not be able to process it. The personal data provided in this context will be stored by us in accordance with legal provisions for a maximum of 6 months; in the event of the applicant’s express consent to retain the documents on file, for a maximum of 2 years.

### **3.2. Online Presence on Social Media**

In addition to our website, we maintain an online presence on social media networks and platforms. The legal basis for using these services is our legitimate interest pursuant to Article 6(1)(f) of the GDPR. Our legitimate interest lies in communicating with customers and business partners who are active on these platforms and in being able to inform them about our services via these networks. When accessing the respective networks and platforms, the terms and conditions and privacy policies of the respective operators of these networks apply. Further information on the processing of your personal data by the respective providers of these services (which personal data is processed for what purposes on what legal basis, how long this data is stored by the respective provider and, where applicable, details on profiling and transfers to third countries) can be found below in the descriptions of the individual services or via the information links provided there.

**Linktree**

In order to provide users of our social media channels with access to our content on the individual platforms via a single page or link (Linktree), we use the ‘Linktree’ service provided by Linktree Pty Ltd (1–9 Sackville St, Collingwood VIC 3066, Australia). The use of this service is in our legitimate interest pursuant to Article 6(1)(f) of the GDPR. Our legitimate interest lies in the clear presentation and linking of all our social media content, which makes it easier for interested users to find us on the individual platforms. Our Linktree page also directs visitors from the individual platforms to our privacy policy. Detailed privacy information regarding Linktree can be found at <https://linktr.ee/s/privacy>.

**Facebook Fan Page**

We operate several Facebook fan pages on the ‘Facebook’ platform operated by Meta Platforms Ireland Ltd. (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland). The legal basis for the processing of the associated personal data is our legitimate interest within the meaning of Article 6(1)(f) of the GDPR. Our legitimate interest lies in providing customers and potential new customers with information about us and our offers via this information channel. Please note that you use this Facebook page and its features at your own risk. This applies in particular to the use of interactive features (e.g. commenting, sharing, rating). When you visit our Facebook page, Facebook collects, amongst other things, your IP address and further information gathered via cookies or other tracking technologies. The data collected about you in this context is processed by Facebook and may be transferred (at least in part) to the USA. Facebook / Meta is a certified partner of the EU-US Data Privacy Framework. The legal basis for (at least in some cases) data transfers to the USA is therefore an adequacy decision by the European Commission within the meaning of Article 45(3) of the GDPR, by which the European Commission certifies that the USA provides an adequate level of data protection. The Court of Justice of the European Union (CJEU) has ruled that ‘Facebook’ and the operators of a Facebook fan page process this personal data as joint controllers within the meaning of Article 26 of the GDPR. Facebook makes the joint data processing agreement available via the following link: [https://www.facebook.com/legal/terms/page\_controller\_addendum](https://www.facebook.com/legal/terms/page_controller_addendum). As the operators of our fan page, we have no influence over the specific content of the agreement. Facebook describes in general terms in its Privacy Policy what information it receives and how it is used (including how Facebook uses data from visits to Facebook pages for its own purposes, the extent to which activities on the Facebook page are attributed to individual users to personalise content or advertising, how long Facebook stores this data, whether data from a visit to the Facebook page is passed on to third parties, and much more) is described in general terms by Facebook in its Data Use Policy. There you will also find information on how to contact Facebook and on the settings options for advertisements. The Privacy Policy is available via the following link: <https://www.facebook.com/privacy/policy/>. As fan page operators, we do not receive any additional (non-public) information about individual Facebook users from Facebook’s analytics; rather, we receive only statistically processed information (e.g. total number of page views, page activity, post reach, etc.), which helps us to make our posts more engaging.

We operate the ‘Innviertel’ Facebook fan page jointly with Meta and other joint controllers within the meaning of Article 26 of the GDPR: LEADER Region Mitten im Innviertel (Stelzhamerpl. 2, A-4910 Ried im Innkreis, email <leader@mitten-im-innviertel.at>), and the Initiative Lebensraum Innviertel association (Dr.-Thomas-Senn-Straße 10, A-4910 Ried im Innkreis, email: <office@innviertel.at>) and the Bierregion Innviertel Association (Dr.-Thomas-Senn-Straße 10, A-4910 Ried im Innkreis, email: <office@bierregion.at>). We have also entered into an agreement with these partners in accordance with Article 26(1) , second sentence, of the GDPR, which obliges all partners, amongst other things, to provide you with the relevant information regarding this joint processing of your personal data when you visit this website, within the meaning of Articles 12 to 14 of the GDPR, to ensure appropriate protection of this data, and to enable you to exercise your rights as a data subject within the meaning of Articles 15 to 21 of the GDPR (see section 1.8 ‘Exercising your data protection rights’ in this privacy notice). To exercise your rights as a data subject in connection with the processing of your personal data when visiting our Facebook fan page, you may contact both us (see section 1.1, ‘Data controller’ in this privacy notice) and the partners mentioned above.

**Instagram**

Instagram is an online service for sharing photos and videos. We have a profile (account) on Instagram. The provider is Meta Platforms Ireland Ltd. (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland). Further information on the processing of your personal data through the use of Instagram, as well as contact details, can be found at: <https://privacycenter.instagram.com/policy/>

**Pinterest**

Pinterest is a combination of a social network and a search engine, with a focus on visual content, i.e. images and videos. We use this service to generate interest in other content of ours on the internet (in particular our website) via so-called ‘Pins’. The provider of this service is Pinterest Europe Ltd. (Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland). Further information on the processing of your personal data through the use of Pinterest, as well as contact details, can be found at: <https://policy.pinterest.com/de/terms-of-service>.

**TikTok**

TikTok is a video platform for short videos that also offers social networking features. We use this service to generate interest in our offerings through short videos. The provider is TikTok Technology Ltd. (10 Earlsfort Terrace, Dublin, D02 T380, Ireland). Further information on the processing of your personal data through the use of TikTok, as well as contact details, can be found at: <https://www.tiktok.com/legal/privacy-policy-eea?lang=de>.

**YouTube**

We use a YouTube channel on the ‘YouTube’ video portal to publish our videos. The service provider is Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Further information on the processing of your personal data through the use of YouTube, as well as contact details, can be found at: <https://www.google.com/policies/privacy/>.

### **3.3. Prize draws**

The personal data you provide to take part in our prize draws (email address, name, postal address) will be used by us solely for the purpose of determining a winner, informing them of their prize and sending the prize to them. Your data will not be passed on to third parties. The legal basis for the processing of your personal data is the performance of a contract in accordance with Article 6(1)(b) of the GDPR. There is no legal or contractual obligation to provide personal data. Failure to provide the data will simply mean that you cannot take part in the competition. Your data will be stored for the duration of the competition and – for the purpose of processing any claims for prizes or compensation – for a maximum of 3 years thereafter, after which it will be deleted. By taking part, you also agree that, should you win, your name will be published on our website and on our public social media channels.

### **3.4. Photo/video documentation at events**

At events, we may take photos and videos of these events, or have them taken by photographers commissioned by us, in which you are recognisable as a participant. We require these photos and videos for the purposes of documenting and promoting our events and will therefore publish them in our media (e.g. printed brochures, our website and social media) and make them available to other media outlets (both print and online) for the promotion of our events. You are under no legal or contractual obligation to provide this data. The legal basis for the processing of your personal data (images and videos in which you are recognisable) is our legitimate interest pursuant to Article 6(1)(f) of the GDPR. Our legitimate interest lies in our right to carry out public relations work (presenting our activities) and to promote our events. You have the right to object to the processing. Please send your objection to the email address provided by us in this privacy policy. However, it can be assumed that our aforementioned interest in using the photographs does not unduly infringe upon your rights as the person depicted. This is particularly the case as we take these photographs and videos in public spaces and provide notice of their creation and use in advance of each event. We also always take care to ensure that the legitimate interests of persons depicted are not infringed. Should your personal rights and freedoms be infringed by an image or video we have produced for reasons warranting special consideration, we will refrain from further processing or publication. It is not possible to remove content from print media that has already been distributed. In such cases, however, we will delete the content from our website or our social media channels. We generally delete photos and videos from events once we no longer require them for the documentation and promotion of those events.

### **3.5 Video surveillance**

For the purpose of protecting our staff and visitors, our property, and for the purpose of preventing or investigating behaviour relevant to criminal law, we have installed video surveillance in the entrance area of our information office in Braunau (24-hour information area) and have clearly marked it as such. These surveillance recordings are only reviewed in the event of an incident and, provided there is no suspicion of wrongdoing, are stored for a maximum of 72 hours before being automatically deleted. Where necessary, the data will be retained for the duration of the proceedings and, where applicable, transferred to the relevant authorities, courts, insurance companies (exclusively for the settlement of insurance claims) and our legal representative (solicitor). The legal basis for this data processing is our legitimate interest pursuant to Article 6(1)(f) of the GDPR in conjunction with Section 12(2)(4) of the DSG, namely the protection of our property. There is no right to object to the processing of this data, nor is there a right to data portability.

### **3.6 Guest card system**

**feratel guest card system**

For the use of our regional guest card, we process your personal data (first name, surname, date of birth, period of stay and country of origin/postcode) with the assistance of our service provider, feratel Media Technologies AG (Maria-Theresien-Straße 8, A-6020 Innsbruck), for the purpose of providing you with the benefits of the free card. Furthermore, it is necessary to store your usage data for billing purposes and to make this data available to our service providers for the purpose of verifying internal billing. The legal basis for this processing is your consent pursuant to Article 6(1)(a) of the GDPR, which you provide to us when you register as a guest at your accommodation. You may withdraw this consent at any time, free of charge. Any usage that has already taken place remains unaffected and is stored for billing purposes. There is no legal or contractual obligation to provide personal data. Failure to provide such data simply means that we cannot provide you with the guest card. We have entered into a corresponding agreement with feratel as a data processor in accordance with Article 28 of the GDPR, which ensures that your data is processed exclusively within the scope of our mandate. Further information on feratel’s data protection policy can be found at: <https://www.feratel.com/datenschutz.html>.

### **3.7. Registration for events**

At our information offices, you can register for events organised by various providers in our region. For this purpose, we process your personal data (name, email address and telephone number). We process this data on the legal basis of Article 6(1)(b) of the GDPR (performance of a contract/pre-contractual measures) and also pass it on to the relevant organiser. We will delete or destroy this data after the event.

Current version of the privacy notice dated 26 January 2026