Privacy Information According to Art. 13 & 14 GDPR Zell am See-Kaprun

1. General

The protection of your personal data is of particular concern to us. We therefore process your data exclusively in a lawful manner on the basis of the statutory provisions (especially GDPR, DSG 2018, TKG 2021). In this privacy policy, we inform you about the most important aspects of data processing – type, scope and purposes of the collection and use of personal data – in the context of the use of our website and in the context of other services of our company.
Only the German version of our privacy policy is legally binding text. The English translation serves as a legally non-binding information. Deviations of the English text or how it could be understood do not affect the exclusive legal validity of the German text and its meaning.

 

1.1. Responsibility for the Processing of your Data 
 

The responsible person (“controller” within the meaning of Art. 4 no. 7 GDPR) of the processing of your personal data (“personal data” within the meaning of Art. 4 no. 1 GDPR) is:
ZELL AM SEE-KAPRUN TOURISMUS GMBH
Brucker Bundesstr. 1a
A-5700 Zell am See
Tel: +43 6542 770
Email: welcome@zellamsee-kaprun.com
https://www.zellamsee-kaprun.com/en/imprint


Data protection officer:


We take the protection of personal data seriously and have appointed an external data protection officer for this purpose. Our data protection officer is MMag. Martin Zeppezauer, Thurnbichlweg 50, A-6353 Going am Wilden Kaiser (www.zepedes.com). You can contact our data protection officer at the email address martin@zepedes.com.

 

1.2. Purposes, Categories of Data and Lawfulness of the Processing of Personal Data
 

Purposes of the processing of personal data

The purposes of processing your personal data generally result from our business activities as a tourism organization: making our online offers available, processing customer inquiries / orders / bookings, accounting, communication with business partners and customers. Detailed information on the purposes of processing and, if necessary, further processing for other compatible purposes as well as the processed data categories can be found in the detailed descriptions of the individual data processing processes.
 

General categories of data

  • Personal master data (e.g. name, date of birth and age, address)
  • Contact details (e.g. email address, telephone number, fax number)
  • Communication data (time and content of communication)
  • Order or booking data (e.g. ordered goods or commissioned services and invoice data such as service period, payment method, invoice date, tax identification number ...)
  • Payment details (e.g. account number, credit card details)
  • Contract data (content of contracts of any kind)
  • Web usage data (e.g. server data, log files and cookies)
  • Geodata (e.g., when using the Zell am See-Kaprun app) 

 

Processing of special categories of personal data according to Art. 9 GDPR 

  • Health data (only if you have given us your explicit consent to process your order (e.g. mediation of a hotel specializing in guests with food intolerances or allergies))

 

Lawfulness of the processing of personal data

There is basically no obligation to provide the data for the data processing described in this data protection declaration. Failure to provide this data simply means that we cannot offer these services. The legal basis for the processing of your personal data, which is necessary for the fulfilment of a contract with you or an order from you to us, is Art. 6 (1) lit. b GDPR. Insofar as the processing of personal data is necessary on our part to fulfil a legal obligation (accounting obligation, bookkeeping obligation or other legal documentation obligations), Art. 6 (1) lit. c GDPR serves as the legal basis. If the processing of the data takes place in your own vital interest, the legal basis for the data processing is Art. 6 (1) lit. d GDPR. If we process your data to carry out the task assigned to us in the public interest (“sovereign action”), the legal basis is Art. 6 (1) lit. e GDPR. If processing is necessary to safeguard a legitimate interest of our company or a third party and your interests, fundamental rights and freedoms do not outweigh our interests, Art. 6 (1) lit. f GDPR (“legitimate interest”) serves as the legal basis for processing. In this case, we will also inform you about our legitimate interests. Unless we have any other legal basis explained above for the processing of personal data, we will ask for your consent to data processing, whereby in these cases we refer to Art. 6 (1) lit. a GDPR or in the case of the processing of special categories of data based on Art. 9 (2) lit. a GDPR as the legal basis. You can revoke this consent at any time free of charge without affecting the legality of the processing carried out on the basis of the consent until the revocation.

 

1.3. Transfers of Personal Data to Data Processors and Third Parties
 

We process your personal data with the support of data processors who support us in providing our services. These data processors are through a corresponding agreement within the meaning of Art. 28 GDPR with us obliged to strictly protect your personal data and may not process your personal data for any purpose other than to provide our services. You can find out which data processors are involved in the detailed descriptions of the individual data processing processes.
Your personal data will be passed on to companies other than our data processors to typical economic service providers such as banks, tax consultants or auditors. Transfer of personal data to state institutions and authorities only takes place within the framework of mandatory national legal provisions.
Depending on your order (e.g. for bookings and inquiries), your personal data will only be transmitted to hotel partners or other tourist service providers (members of our organization) to the extent necessary to fulfil your order. The transmitted personal data vary depending on the service.

 

1.4. Transfers of Personal Data to Third Countries or International Organisations
 

In principle, we process your personal data in the EU. If we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)) or if we use the services of our data processors or third parties, this will only take place if the requirements of Art. 44 ff. GDPR are available for the transfer to third countries: i.e. on the basis of special guarantees, such as the officially recognized determination of a data protection level corresponding to the EU or in compliance with officially recognized contractual obligations, the so-called "EU standard contractual clauses". If we rely on the EU standard contractual clauses as the legal basis for the transmission of your personal data, we will also check the admissibility of this data transmission as part of a comprehensive risk assessment. If we come to a negative result, we will not transfer these data without your explicit consent in accordance with Art. 49 (1) lit. a GDPR to a third country.

 

1.5. Data Erasure and Period of Data Storage
 

Your personal data will be deleted by us as soon as the purpose for which we collected your data no longer applies. Storage can also take place if we process the data for a purpose that is compatible with the original purpose. It can also take place if this is provided for by laws, ordinances or other provisions to which our company is subject.

 

1.6. Data Sources
 

In principle, we collect your personal data from you. Exceptionally, we also receive information about your purchases or bookings made there from our partner websites of Kitzsteinhorn Bergbahnen AG (www.kitzsteinhorn.at) and Schmittenhöhebahn AG (www.schmitten.at), provided that we forward you there from our Zell am See-Kaprun app, our website or our newsletter and you agree to the setting of corresponding marketing cookies on these partner websites. We use this information to be able to show you individualized offers/information on our website, in our app or our newsletter.

 

1.7. Profiling
 

We do not use any automated decision-making or profiling processes that have a legal effect on you or that significantly affect you in a similar manner. With your consent, however, we will use your usage data to get to know your interests better and thus to be able to display information of interest to you or to be able to make you tailor-made offers or to be able to display corresponding information to you on third-party websites or social media platforms.

 

1.8. Safeguarding your Data Protection Rights
 

In principle, you have the right to information, correction, deletion and restriction of the processing of personal data in accordance with the GDPR. If the legal basis for the processing of your personal data is your consent or a contract concluded with you, you also have the right to data portability. You have the right to revoke any consent you may have given to the processing of your personal data. The lawfulness of the processing of your personal data up to the time of revocation is not affected by this. You have the right to object to the processing of your personal data for the purpose of direct marketing. In the event of an objection, your personal data will no longer be processed for the purpose of direct marketing. A detailed explanation of these rights can be found here in Chapter III.

 

Right of complaint

If you believe that the processing of your data violates data protection law or your data protection claims have otherwise been violated in any way, you can complain to the competent supervisory authority. In Austria, this is the data protection authority (Wickenburggasse 8, 1080 Vienna, email: dsb@dsb.gv.at).

 

2. Visiting our Website

In this section we inform you how we process your personal data when you visit our website.

 

2.1. Presentation of the Website
 

Server data

For technical reasons, based on the legal basis of § 165 (3) S 3 TKG 2021 (required for the operation of our website), the following data, which your internet browser transmits to us or to our web space provider, will be processed (so-called "server log files"):

  • Browser type and version
  • Operating system and device type used (e.g. desktop / mobile)
  • Website from which you are visiting us (referrer URL)
  • Website you visit
  • Date and time of your access
  • Your internet protocol address (IP address)

This data, which is anonymous to us, is stored separately from any personal data you may have provided and therefore does not allow us to draw any conclusions about a specific person. They are evaluated for statistical purposes in order to be able to optimize our website and our offers.


SSL or TLS encryption

For security reasons and to protect the transmission of confidential content, such as B. Orders or inquiries that you send to us as the website operator, an SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from “http: //” to “https: //” or by the lock symbol in your browser line. If the SSL or TLS encryption is activated, the data that you transmit to us cannot be read by third parties.


Technical service providers

We create and edit the content of our website with the help of the following service provider. With this service provider we have concluded a corresponding agreement according to Art. 28 GDPR to process your data exclusively to the extent of our order:

 

2.2. Cookies
 

Cookie Banner - Cookies on our website

Our website uses cookies, which help us to make our website more user-friendly and efficient for you, to carry out statistical analyses of the use of our website and also to show you content that is of interest to you on other websites. Cookies are small text files that are used to store information when visiting websites and are stored on the website visitor's computer. The legal basis for cookies, which are absolutely necessary for the proper operation of our website (e.g. shopping cart cookie), is § 165 (3) S 3 TKG 2021. Cookies that are not necessary for the function of our website (e.g. analysis or marketing cookies) are deactivated and will only be activated by your consent in accordance with Art 6 (1) lit. a GDPR in our cookie banner ("Accept"). By clicking on "Settings" you can activate or deactivate individual cookies or cookie groups. If you restrict the use of cookies on our website, you may no longer be able to use all functions of our website to their full extent. You can find detailed information about the cookies used on our website in our cookie banner.

Edit cookie settings
 


Change the cookie settings in your web browser

How the web browser you are using handles cookies, i.e. which cookies are allowed or rejected, can be determined in the settings of your web browser. You can delete cookies already stored on your computer / device yourself at any time. Where exactly these settings are located depends on the respective web browser. Detailed information on this can be called up using the help function of the respective web browser.

In addition, it is possible to generally object to cookies and similar tracking technologies using the services listed below by setting your individual preferences - which technologies you want to allow for usage and interest-based advertising:

 

2.3. Communication with us
 

Contact form and email

On our website, we offer you the option of contacting us by email and / or using a contact form. In this case, the information you provide will be processed for the purpose of processing your contact based on the legal basis of contract fulfilment in accordance with Art. 6 (1) lit. b GDPR. There is a legitimate interest on our part pursuant to Article 6 (1) lit.  f GDPR for the use of a contact form. The legitimate interest lies in offering our website visitors an opportunity to contact us that does not require them to call up their own e-mail client. There is no legal or contractual obligation to provide this personal data. Failure to provide it simply means that you do not submit your request and we cannot process it. The data will only be passed on to third parties if this is stated on the website or in this data protection declaration or is necessary for the fulfilment of the contract or if this is required by statutory provisions. We only save your data for as long as is expedient for processing your inquiries or for any queries you may have.

 

2.4. Online Shop (s) / Booking Portal (s)
 

For the purpose of providing contractual services as well as their payment and execution in the context of online purchases, bookings and prospectus orders, we process your personal master data, contract and payment data and communication data (IP address and server log files) on the basis of the legal bases of Art. 6 (1) lit. b GDPR (fulfilment of the contract) as well as Art. 6 (1) lit. c GDPR (legal obligation for invoicing and archiving).

We store this data as long as the purpose requires it, statutory provisions provide for this (retention period of invoices according to § 132 BAO for 7 years; voucher orders until the expiry of the redemption period for 30 years) or we store this data on the basis of the legal basis of Art. 6 (1) lit. f GDPR (legitimate interest) to defend against possible liability claims. If you cancel the order process, we will save the data to clarify possible problems during the order process for 14 days.

There is no legal or contractual obligation to provide personal data. Failure to provide them simply means that we cannot process your bookings / orders.


Feratel DESKLINE online bookings, booking requests and brochure orders

For the processing of online bookings, brochure orders and inquiries, we process your personal data in order to be able to provide you with the booked services with the help of our service provider feratel Media Technologies AG (Maria-Theresien-Straße 8, A-6020 Innsbruck). For this purpose, we store and process inventory data, communication data, contract data, payment data of our customers, interested parties and other business partners. The processing takes place for the purpose of providing contractual services or for the fulfilment of pre-contractual services on the basis of the legal basis of Art. 6 para. 1 lit. b GDPR (booking processes, answering requests for quotations and sending brochures) as well as Art. 6 (1) lit. c GDPR (legally required retention periods of bookings or invoices). For this purpose, the data fields marked as required are required for the establishment and fulfilment of the contract. We disclose your personal data in the context of this data processing to third parties (hotel partners or other tourist service providers) on the basis of the legal basis of Art. 6 (1) lit. b GDPR (if it is necessary for the processing of a booking process), or on the basis of our legitimate interest according to Art. 6 (1) lit. f GDPR for the use of appropriate booking software. We have concluded a corresponding agreement with feratel in accordance with Art. 28 GDPR as a data processor, which ensures that your data is processed exclusively within the scope of our order. Further information on the data protection of feratel under: https://www.feratel.com/en/privacy-policy.html


INCERT voucher system and merchandising articles

To process the order of holiday vouchers and merchandising articles, we use the system of the company INCERT eTourismus GmbH & Co KG (Leonfeldner Strasse 328, A-4040 Linz) as our data processor. It enables the automated sale of vouchers by means of "print@home" as well as the individual personalization of vouchers with dedications, designs and barcodes. For the processing of orders, the following information is required: title, first and last name, address, e-mail address. We have concluded a corresponding agreement with the company INCERT in accordance with Art. 28 GDPR as a data processor, which ensures that your data is processed exclusively within the scope of our order. Further information on INCERT's data protection can be found at: https://www.incert.at/en/data-protection/


Ticket shop vouchercube

To process the order of ski-, event- and experience tickets in our online shop, we use the system of the service provider Vouchercube Software GmbH (Lange Gasse 32, 1080 Vienna). For orders in our online shop, we need title, first and last name, e-mail address, date of birth and details of the desired tickets (e.g., period, type of tickets, etc.) and we process your payment data (payment method and Transaction.ID) during the payment process. The processing takes place for the purpose of providing contractual services or for the fulfilment of pre-contractual services on the basis of the legal basis of Art. 6 (1) lit. b GDPR (ordering of tickets) and Art. 6 (1) lit. c GDPR (legally required retention periods of accounting documents). There is no legal obligation on your part to provide this data. Failure to provide the data only means that we cannot provide you with the desired tickets via our online shop. The use of corresponding online booking software is based on the legal basis of our legitimate interest acc. Art. 6 (1) lit.  f GDPR. Our legitimate interest lies in a fast, location-independent possibility to make our ski and event tickets available to our customers. We have concluded a corresponding agreement with the company Vouchercube Software GmbH in accordance with Art. 28 GDPR as a processor, which ensures that your data is processed exclusively within the scope of our order. Further information on the data protection of Vouchercube Software GmbH can be found at: https://vouchercube.com/contact-imprint/

 

External payment service providers

To pay for the order processes / bookings, we use external payment service providers on the legal basis of Art. 6 (1) lit. b GDPR (fulfilment of the contract), via whose platforms you can make your payments. The payment data entered by you as part of the order (e.g. account numbers, credit card numbers including check digits, passwords / TANs, etc.) are processed exclusively by our payment service providers and are not visible to us. We only receive a confirmation of the payment made or information from our payment service providers that the payment could not be made. Further information on the data protection and terms and conditions of our payment service providers can be found at:

 

 

2.5. Email Newsletter
 

E-Mail-Newsletter (Droid Creator)

On our website you have the possibility to register for our newsletter. The legal basis for sending the newsletter is your consent according Art. 6 (1) lit. a GDPR. The registration for our newsletter takes place in the so-called double opt-in procedure. In this way, we ensure that no one can register with other people's e-mail addresses (e.g., with your e-mail address). Your consent can be revoked at any time free of charge by clicking on the "unsubscribe link" at the end of each mailing. The legality of the data processing operations already carried out up to that point remains unaffected by the revocation. After unsubscribing your e-mail address, we will store it for another 3 years on the basis of our legitimate interest (Art. 6 (1) lit. f GDPR) in order to be able to prove your originally given consent, if necessary. To send out our newsletter, we use the "Droid Creator" service, a tool of Droid Marketing GmbH (Ungargasse 64-66/2/405, A-1030 Vienna). With the help of Droid Creator we can analyze our newsletter campaigns. When you open an email sent with the Droid Creator newsletter tool, a connection is established with Droid Creator's servers. In this way, we can determine whether a newsletter message has been opened and which links, if any, have been opened. were clicked. The purpose of these analyses is to better adapt future newsletters to the interests of the recipients. In addition, technical information such as the time of retrieval, IP address, browser type and operating system of the recipient are registered. We have entered into a processor agreement with Droid Marketing GmbH within the meaning of Droid Marketing GmbH. Kind. 28 GDPR to ensure that your data is only processed to the extent requested by us and permitted by you. General data protection information of Droid Marketing GmbH can be found at: https://droidmarketing.com/datenschutz.html

 

2.6. Digital Information Services / Registration
 

Digital holiday companion PIA

For the use of our digital holiday companion PIA (Personal Interest Assistant), provided by our service provider feratel Media Technologies AG (Maria-Theresien-Straße 8, A-6020 Innsbruck), it is possible to register on our website via a terminal device (e.g. smartphone or PC) on the respective Progressive Web App (abbreviated PWA) of the Digital Holiday Companion on our website. With a registration or identification, the services of the Digital Holiday Companion can be used by the user. For the use of the information offers and the receipt of service offers of the operator, it is necessary to register by providing the e-mail address. In this context, we collect your name and e-mail address, the duration of the planned stay and the booked accommodation, insofar as this is necessary for the use of the offers of the digital concierge. In addition, cookies and web analysis tools collect and store data that provide information about your interest in products. We use this information for the purpose of advertising offered products through marketing campaigns of various kinds, such as sending a newsletter by email and short messages when activating the Digital Holiday Companion. The legal basis for this data processing is your consent in accordance with Art. 6 (1) lit a GDPR. You can revoke this consent at any time free of charge. The legality of the data processing operations already carried out up to that point remains unaffected by the revocation. There is no obligation to provide this data. If you do not want to provide this data, it will only mean that we will not be able to offer you this service. Your data will only be transferred to third parties if this is necessary for the processing of reservations. If the above data is changed and/or supplemented by you in the course of registration or identification, these supplemented/changed data will also be stored and processed. We only store your data for as long as this is necessary for the purpose or due to legal obligations on our part. We have concluded a data processing agreement with feratel in accordance with Art. 28 GDPR, which ensures that your data is processed exclusively within the scope of our order. Further information on feratel's data protection can be found at: https://www.feratel.com/en/privacy-policy.html

 

2.7. Web Analysis - Statistical Analyses of our Website
 

Google Tag Manager

We use the service of the provider Google Ireland Limited ("Google") (Gordon House, Barrow Street, Dublin 4, Ireland) to be able to manage website tags via a common tool of Google. The Google Tag Manager tool itself (which implements the tags) is a domain that does not set cookies and does not collect any other personal data. The tool triggers other tags, which in turn may collect data. Google Tag Manager does not access this data. If a deactivation has been made at the domain or cookie level, it will remain in place for all tracking tags implemented with Google Tag Manager. Google is a certified partner of the EU-US Data Privacy Framework. The legal basis for (at least a case-by-case) data transfers to the USA is thus an adequacy decision of the European Commission within the meaning of Art. 45 (3) GDPR, with which the European Commission certifies that the USA has an adequate level of data protection. Further information on Google's data protection can be found at: https://policies.google.com/privacy?hl=en-GB

Google Analytics

This website uses functions of the web analysis service Google Analytics. The provider of this service is Google Ireland Limited ("Google") (Gordon House, Barrow Street, Dublin 4, Ireland). The legal basis for the use of this service is your consent in accordance with Art. 6 (1) lit a GDPR. Google Analytics uses cookies that are stored on the website visitor's computer and that enable an analysis of the use of our website by the site visitor. The information generated by the cookie about your use of our website is usually stored on European servers and only in exceptional cases transmitted to a Google server in the USA and stored there. We use Google Analytics with activated IP anonymization. This means that your IP address is usually shortened by Google within the European Union and only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. Google is a certified partner of the EU-US Data Privacy Framework. The legal basis for (at least a case-by-case) data transfers to the USA is thus an adequacy decision of the European Commission within the meaning of Art. 45 (3) GDPR, with which the European Commission certifies that the USA has an adequate level of data protection. The IP address transmitted by the corresponding browser as part of Google Analytics will not be merged with other Google data. On our behalf, Google will use the resulting information to evaluate the use of the website in order to compile reports on website activity. The collection by Google Analytics can be prevented by the site visitor adjusting the cookie settings for this website. The collection and storage of the IP address and the data generated by cookies can also be objected to at any time with effect for the future. The corresponding browser plugin can be downloaded and installed under the following link: https://tools.google.com/dlpage/gaoptout. Further information on the use of data by Google, setting and objection options, can be found in Google's privacy policy (https://policies.google.com/privacy?hl=en-GB) as well as in the settings for the presentation of advertisements by Google (https://adssettings.google.com/authenticated).
 

Google Ads Conversion Tracking

Our website uses the service "GoogleAds Conversion Tracking" of the provider Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland). When we place advertising ads on Google, we use so-called conversion tracking. When you click on an ad placed by Google, a cookie is set for conversion tracking (storage period 30 days). This is how we recognize that you clicked on one of our ads and were redirected to our website. However, we do not receive any personal information, but only learn the total number of users who clicked on one of our ads and were redirected to our page with a conversion tracking tag. We use Google Ads Conversion Tracking on the legal basis of your consent (settings via our cookie banner) in accordance with Art. 6 (1) lit. a GDPR. Google is a certified partner of the EU-US Data Privacy Framework. The legal basis for (at least case-by-case) data transfers to the USA is thus an adequacy decision of the European Commission within the meaning of Art. 45 (3) GDPR, with which the European Commission certifies that the USA has an adequate level of data protection. Further information on the use of data by Google, setting and objection options, can be found in Google's privacy policy (https://policies.google.com/privacy) as well as in the settings for the presentation of advertisements by Google (https://adssettings.google.com/authenticated).

 

2.8. WEBMARKETING
 

Google Remarketing

On the legal basis of your consent pursuant to Art. 6 (1) lit. a GDPR, our website uses the functions of "Google Analytics Remarketing" in conjunction with the cross-device functions of Google AdWords and Google DoubleClick. The provider is Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland). This feature makes it possible to link the advertising target groups created with Google Analytics Remarketing with the cross-device functions of Google AdWords and Google DoubleClick. In this way, interest-based, personalized advertising messages that have been adapted to you depending on your previous usage and surfing behavior on one device (e.g. mobile phone) can also be displayed on another of your devices (e.g. tablet or PC). If you have given your consent, Google will link your web and app browsing history to your Google Account for this purpose. In this way, the same personalized advertising messages can be displayed on every device on which you sign in with your Google Account. To support this feature, Google Analytics collects Google-authenticated user IDs, which are temporarily linked to our Google Analytics data to define and create audiences for cross-device advertising. Cookies are deleted after 1 year. Google is a certified partner of the EU-US Data Privacy Framework. The legal basis for (at least case-by-case) data transfers to the USA is thus an adequacy decision of the European Commission within the meaning of Art. 45 (3) GDPR, with which the European Commission certifies that the USA has an adequate level of data protection. You can permanently object to cross-device remarketing/targeting by deactivating personalized advertising in your Google Account; follow this link here: https://www.google.com/settings/ads/onweb/. The summary of the collected data in your Google Account takes place exclusively on the basis of your consent, which you can give or revoke with Google (Art. 6 (1) lit. a GDPR). Further information on Google's data protection can be found at: https://www.google.com/policies/privacy/

 

Facebook-Pixel

In order to place target group-directed advertisements on Facebook and to be able to track the actions of users after they have seen or clicked on a Facebook advertisement, we use the Facebook pixel of Meta Platforms Ireland Ltd. (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland). This allows us to display and evaluate or optimize our Facebook advertisements on Facebook that is of interest to you on Facebook with the data collected anonymously for us (we do not see any personal data of individual users, but only the overall effect). Storage period max. 12 months. According to their data protection information, Facebook links this data to the Facebook account of Facebook users and can thus display content that corresponds to their interests. Meta is a certified partner of the EU-US Data Privacy Framework. The legal basis for (at least case-by-case) data transfers to the USA is thus an adequacy decision of the European Commission within the meaning of Art. 45 (3) GDPR, with which the European Commission certifies that the USA has an adequate level of data protection. For specific information about how the Facebook pixel works, see the Facebook Help Center at: https://de-de.facebook.com/business/help/651294705016616. You can make settings regarding usage-based advertising on Facebook yourself in your Facebook account: https://www.facebook.com/settings?tab=ads. Further information can be found in Facebook's privacy policy at: https://www.facebook.com/privacy/explanation
 

Pinterest Tag (Pinterest Conversion Tracking)

In order to optimize our Pinterest campaigns and to measure their conversion (effectiveness), we set the Pinterest Tag (Pinterest Conversion Tracking Pixel) of Pinterest Europe Ltd. (Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland) on the legal basis of Art. 6 (1) lit. a GDPR (consent). This allows us to display advertisements of interest to our website visitors, who are also Pinterest members, on Pinterest. It also allows us to track the actions of Pinterest members after they have seen or clicked on one of our Pinterest ads. The following personal data is processed: information about the type of hardware and operating system used, its IP address, the time of access to our website, the type and content of the advertisements we place and the reaction to our advertisements.  These data are anonymous to us and do not allow us to draw any conclusions about the identity of the respective user. Pinterest may, according to its own information, connect this data to your Pinterest account and also use it for its own advertising purposes. We process this data with Pinterest Europe as "Joint Controller" and have concluded an agreement with Pinterest Europe in accordance with Article 26 GDPR (JCA – Joint Controller Agreement), which obliges all partners to provide you with the corresponding information about this joint processing within the meaning of Articles 12 to 14 GDPR, to ensure appropriate protection of this data and to enable you to exercise your rights as a data subject within the meaning of the Art. 15-21 GDPR. We have agreed with Pinterest Europe that Pinterest Europe is responsible for asserting data subject rights pursuant to Articles 15-20 GDPR with regard to the personal data processed / stored by Pinterest Europe in the context of joint processing. If personal data is processed by Pinterest Europe in the context of joint processing on the legal basis of legitimate interest (Art. 6 (1) lit. f GDPR), you are entitled to the right to object acc.  Art. 21 GDPR. A possible transfer of data to certain members of the Pinterest family of companies and to third parties in countries without an adequate level of protection is based on the EU standard contractual clauses. Further information on exercising your rights as a data subject and general information on data protection at Pinterest Europe Ltd. can be found at: https://policy.pinterest.com/de/privacy-policy#section-residents-of-the-eea. Information on the individual setting of the data collected by Pinterest can be found at: https://help.pinterest.com/de/article/personalization-and-data
 

Microsoft Advertising

On the legal basis of your consent pursuant to Art. 6 (1) lit. a GDPR, our website uses the functions of Universal Event Tracking (UET) from Microsoft Advertising (formerly Bing Ads) of Microsoft Corporation (One Microsoft Way, Redmond, WA 98052-6399, USA). Via UET, Microsoft stores a cookie in the browser of website visitors in order to enable an analysis of the use of the website, provided that the user has reached our website via an advertisement from Microsoft Advertising. This allows Microsoft and us to recognize whether a website visitor has previously clicked on an ad and was redirected to our website as a result. No IP addresses are stored. No other personal information about the identity of website visitors is stored. Microsoft is a certified partner of the EU-US Data Privacy Framework. The legal basis for (at least on a case-by-case) basis for data transfers to the USA is thus an adequacy decision of the European Commission within the meaning of Art. 45 (3) GDPR, with which the European Commission certifies that the USA has an adequate level of data protection. You can prevent the collection of data generated by the cookie and related to your use of the website and the processing of this data by Microsoft by using the opt-out option under the following link: https://account.microsoft.com/privacy/ad-settings/signedout?lang=de-DE. Further information on data protection by Microsoft and Bing Ads can be found at: https://privacy.microsoft.com/de-de/privacystatement.
 

Marketing Automation (Acoustic) 

On the legal basis of your consent pursuant to Art. 6 (1) lit. a GDPR, our website uses the marketing automation functions of the providers Dialogschmiede GmbH (Fernkorngasse 10/B1/Top N401, A-1100 Vienna, datenschutz@dialogschmiede.com). These functions enable us to analyse your usage behaviour on our website and, based on this, to show you certain content preferentially. In this way, we can provide you with interest-based, personalized content both within our website and in our newsletter or in our Zell am See-Kaprun app, provided that you use our app or have subscribed to our newsletter. We have a corresponding agreement with the provider of the service acc. Art. 28 GDPR as a processor, which ensures that your data is processed exclusively within the scope of our order. When processing this data, data may (at least partially) also lead to data transfers to the USA. However, our processor Dialogschmiede GmbH has agreed corresponding EU standard contractual clauses (in their current form) with its subcontractors in this case, which ensure that your data protection rights in accordance with European standards remain guaranteed in this case. Further information can be found in the privacy policy of Dialogschmiede GmbH: https://dialogschmiede.com/datenschutz/.

In addition, on the basis of your consent pursuant to Art. 6 (1) lit. a GDPR, we receive information from the websites of our partners Kitzsteinhorn Bergbahnen AG (www.kitzsteinhorn.at) and Schmittenhöhebahn AG (www.schmitten.at) in case we forward you to the websites of these partners. In this way, we can also use this information to be able to show you individualized information and offers on our website. The prerequisite for this is, on the one hand, that you agree to the necessary marketing cookies when using these partner websites and, on the other hand, that you are logged in to your app or in your user account of our website, or have subscribed to our newsletter. We process this data as "joint controllers" with the partners named here and have also concluded an agreement with these partners within the meaning of Art. 26 GDPR, which obliges all partners, among other things, to provide you with the corresponding information about this joint processing within the meaning of Art. Articles 12 to 14 GDPR, to ensure appropriate protection of this data and to exercise your rights as a data subject within the meaning of the GDPR. Art. 15-21 GDPR. To exercise your rights as a data subject, you can contact us (Zell am See-Kaprun Tourismus GmbH) as well as our partners Kitzsteinhorn Bergbahnen AG (Kitzsteinhornplatz 1a, A-5710 Kaprun, Tel. +43 (0)6547/8700, E-Mail: office@kitzsteinhorn.at) or Schmittenhöhebahn AG (Salzachtal-Bundesstraße 7, Postfach 8, 5700 Zell am See, Tel. +43 (0) 6542 789 211, E-Mail: datenschutz@schmitten.at).
 

Microsoft Clarity

This website uses functions of the web analysis service Microsoft Clarity. The provider of this service is Microsoft Corporation (One Microsoft Way, Redmond, WA 98052-6399, USA). The legal basis for the use of this service is your consent pursuant to Art. 6 (1) lit a GDPR. We use Microsoft Clarity to analyze our website usage (reach measurement, recognition of returning users), to be able to display content of interest to our website visitors on third-party platforms (cross-device tracking / remarketing) and for conversion measurement (measurement of the effectiveness of our marketing activities on third-party platforms). The user analysis takes place on the basis of a pseudonymous user ID and thus on the basis of pseudonymous data. In doing so, we process usage data in pseudonymised form (when did you visit which pages of our website, mouse movements, scrolling movements), meta or communication data (your IP address, data about the device you are using) and location data (approximately where you were at the time of visiting our website). Through appropriate settings, we have ensured that data collection by Microsoft is already pseudonymous through so-called IP masking (shortening your IP address). Microsoft is a certified partner of the EU-US Data Privacy Framework. The legal basis for data transfers to the USA is thus an adequacy decision of the European Commission within the meaning of Art. 45 (3) GDPR, with which the European Commission certifies that the USA has an adequate level of data protection. You can generally prevent the collection of data relating to your use of the website and the processing of this data by Microsoft by using the opt-out option under the following link: https://account.microsoft.com/privacy/ad-settings/signedout?lang=de-DE. Further information on Microsoft's data protection can be found at: https://privacy.microsoft.com/de-de/privacystatement.

 

2.9. Integration of other Third-Party Services and Content
 

We integrate content or functions of third parties within our website. This always presupposes that the providers of this content or functions perceive the IP address of the users. Without the IP address, they would not be able to send the content to the browser of the respective user. The IP address is therefore required for the presentation of this content. We endeavor to use only such content whose respective providers use the IP address only for the delivery of the content. However, we have no influence on whether the third-party providers store the IP address, e.g. for statistical purposes. The legal basis for the use of these services, insofar as they are necessary for the functioning of our website, is our legitimate interest in accordance with Art. 6 (1) lit. f GDPR, otherwise your consent according to Art. 6 (1) lit a GDPR. Information on the purpose and scope of the further processing and use of the data by the providers of the embedded services/content as well as further information within the meaning of the Art. 13 and 14 GDPR can be found under the information links listed below. The following services/content are embedded in our website:
 

Google Maps

Our website uses the Google Maps service of the provider Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland). This function makes it possible to display corresponding map material within our website. Your IP address as well as information about the browser version and language settings are transmitted to the servers of Google Ireland Ltd. According to Google's own information, the data is stored by Google for 1 year. There is a legitimate interest on our part within the meaning of the Art. 6 (1) lit. f GDPR for the use of Google Maps. Our legitimate interest lies in an appealing presentation of our online offer or the geographical presentation of the offers of our region. However, we only use Google Maps if you have given your consent. The legal basis for the processing of your data is therefore your consent in accordance with Art. 6 (1) lit. a GDPR. Google is a certified partner of the EU-US Data Privacy Framework. The legal basis for (at least case-by-case) data transfers to the USA is thus an adequacy decision of the European Commission within the meaning of Art. 45 (3) GDPR, with which the European Commission certifies that the USA has an adequate level of data protection. For more information about Google's privacy policy, please visit: https://policies.google.com/privacy
 

VIMEO

We integrate videos of the platform "Vimeo" of the provider Vimeo Inc. (555 West 18th Street, New York 10011, USA). The implementation takes place on the basis of Art. 6 (1) lit. f GDPR, whereby our legitimate interest lies in the smooth integration of the videos and the thus appealing design of our website. However, we only use Vimeo if you have given your consent. The legal basis for the processing of your data is therefore your consent in accordance with Art. 6 (1) lit. a GDPR. When you visit a page in which we have embedded a Vimeo video, a connection to the Vimeo servers is established and the content is displayed on the website by notifying your browser. According to Vimeo, your data (in particular which of our websites you have visited) as well as device-specific information including the IP address will only be transmitted to the Vimeo server when you watch the video. Since Vimeo also processes personal data outside the EU in the USA, we have agreed the EU standard contractual clauses with Vimeo. By clicking on the video, you consent to this transmission. For more information on Vimeo's privacy policy, please visit: https://vimeo.com/privacy


YouTube

We integrate videos from the platform "YouTube" of the provider Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland) in extended data protection mode. The implementation takes place on the legal basis of Art. 6 (1) lit. f GDPR, whereby our interest lies in the smooth integration of the videos and the thus appealing design of our website. However, we only use YouTube if you have given your consent. The legal basis for the processing of your data is therefore your consent in accordance with Art. 6 (1) lit. a GDPR. When you visit a page in which we have embedded a YouTube video, a connection to the Google servers is established and the content is displayed on the website by notifying your browser. According to Google's information, in the extended data protection mode, your data (in particular which of our websites you have visited) as well as device-specific information including the IP address will only be transmitted to the YouTube server when you watch the video. Google is a certified partner of the EU-US Data Privacy Framework. The legal basis for (at least case-by-case) data transfers to the USA is thus an adequacy decision of the European Commission within the meaning of Art. 45 (3) GDPR, with which the European Commission certifies that the USA has an adequate level of data protection. If you are logged in to Google at the same time, this information will be assigned to your Google member account. You can prevent this by logging out of your member account before visiting our website or by making individual settings in your Google account under the following link: https://adssettings.google.com/authenticated. Further information on YouTube's privacy policy can be found at: https://www.google.com/policies/privacy/ 


Facebook Messenger

On our website we offer the possibility to communicate directly with us via the Facebook Messenger service of the provider Meta Platforms Ireland Ltd. (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland). The legal basis for the processing of your data is therefore your consent in accordance with Art. 6 (1) lit. a GDPR, which you can revoke at any time for the future. Meta is a certified partner of the EU-US Data Privacy Framework. The legal basis for (at least case-by-case) data transfers to the USA is thus an adequacy decision of the European Commission within the meaning of Art. 45 (3) GDPR, with which the European Commission certifies that the USA has an adequate level of data protection. If you already use Facebook Messenger, you can communicate with us via your own Facebook account. But you also have the opportunity to communicate with us "as a guest" anonymously for us. If you use your own Facebook account to communicate with us, Facebook links your data from the use of our Facebook Messenger service with your Facebook account and can thus display content on Facebook in the future that corresponds to your interests. Facebook will also use this data in this way, provided that you communicate with us "as a guest" but are logged into your Facebook account via your browser at the same time. Further information on the data protection of Facebook Messenger can be found at: https://www.facebook.com/help/messenger-app/1064701417063145?helpref=hc_global_nav. Further information on Meta's data protection can be found at: https://www.facebook.com/privacy/policy/?entry_point=data_policy_redirect&entry=0.


Cloudflare

We use the Content Delivery Network (CDN) "Cloudflare" of the provider Cloudflare Germany GmbH (Rosental 7, c/o Mindspace, 80331 Munich, Germany) to increase the security and delivery speed of our website. A CDN is a network of (worldwide) distributed servers that is able to deliver optimized content to the website user. For this purpose, personal data may be processed in server log files of Cloudflare. We use this service on the basis of our legitimate interest in accordance with Art. 6 (1) lit. f GDPR. Our legitimate interest lies in increasing the security of our website and in our interest in being able to make this content available in the shortest possible loading times. You have the right to object to the processing. Whether the objection is successful must be determined in the context of a balancing of interests. For more information on objection and removal options to Cloudflare, please visit: https://www.cloudflare.com/cloudflare-customer-dpa/. Cloudflare is a recipient of your personal data and acts as a processor for us. This corresponds to our legitimate interest within the meaning of Art. 6 para. 1 sentence 1 lit. f GDPR not to operate a content delivery network ourselves. The processing of the data provided under this section is neither required by law nor by contract. The functionality of the website is not guaranteed without the processing. Your personal data will be stored by Cloudflare for as long as is necessary for the purposes described. Cloudflare has implemented compliance measures for international data transfers. These apply to all global activities in which Cloudflare processes personal data of natural persons in the EU. These measures are based on the EU Standard Contractual Clauses (SCCs). For more information, see: https://www.cloudflare.com/cloudflare-customer-scc/
 

ClickCease™

Our website uses the ClickCease™ service of the provider CHEQ AI Technologies Ltd.  (HaArba'a St 18, Tel Aviv-Yafo, Israel) as an automatic ads and click fraud protection.  ClickCease™ processes information that your browser transmits when you visit our website in order to recognize conspicuous, particularly frequent advertising calls from a specific IP address. This protects us from malicious programs calling up our paid advertisements many times and thus causing financial damage. In order to enable this protection function, information from your browser (browser type, browser version, the operating system used, host name of the accessing computer and referrer URL, the time of thewebsite visit and the IP address), your length of stay on our website, the number of page views and any viewed pages as well as used search words transmitted to the ClickCease™ server. The legal basis for the use of this service is our legitimate interest in accordance with Art. 6 (1) lit. f GDPR. Our legitimate interest lies in protecting against financial damage caused by malicious programs. However, we only use ClickCease™ if you have given your consent. The legal basis for the processing of your data is therefore your consent in accordance with Art. 6 (1) lit. a GDPR, which you can revoke at any time for the future. The European Commission has certified that Israel has a level of protection that is essentially equivalent to that enjoyed in the European Union. The legal basis for the transfer of data to Great Britain is therefore Art. 45 GDPR. We have concluded with CHEQ AI Technologies Ltd. conclude a corresponding agreement pursuant to Art. 28 GDPR as a data processor (data processum addendum https://www.clickcease.com/dpa.html), which ensures that your data is processed exclusively within the scope of our order. Further information on ClickCease's™ data protection can be found at: https://www.clickcease.com/privacy.html.

 

Webcams


For the current presentation of the weather in our region, we integrate webcams from other websites of providers in our region into our website. The implementation takes place on the basis of our legitimate interest in accordance with Art. 6 (1) lit. f GDPR, whereby our interest lies in information on the current weather in our region within our website. When you visit a page in which we have embedded webcams, a connection to the servers of the providers is established and the content is displayed on the website by notifying your browser. For this purpose, it is necessary that your IP address including some browser information (browser type, browser version, etc.) including information about when you accessed these pages is transmitted to the servers of the providers.
 

3. Other Data Processing in Business and Customer Contact

In this section we inform you about other data processing processes outside our website.

 

3.1. Job Applications
 

The contact data and application documents transmitted to us in the course of a job application will be processed by us exclusively internally for the purpose of selecting suitable candidates for an employment relationship. There is no legal or contractual obligation to provide the personal data. Failure to do so will only result in you not submitting your request and we will not be able to process it. The personal data transmitted in this way will be stored by us in accordance with the statutory provisions for a maximum of 6 months, in the case of the explicit consent of the applicant to keep the documents in evidence, for a maximum of 2 years.

 

3.2. Online Presence in Social-Media
 

In addition to our website, we maintain online presences within social networks and platforms: Facebook, Twitter, Instagram, TikTok, Pinterest and YouTube in order to communicate with customers and business partners and to connect to them via these networks to be able to inform about our services. When accessing the respective networks and platforms, the terms and conditions and the data protection guidelines of the respective operators of these networks apply.

 

3.3. Guest Card System

GuestCard Zell am See-Kaprun: Guest card system feratel

For the use of our regional guest card, we process your personal data (first name, last name, date of birth, period of stay and country of origin/postal code) with the help of our service provider feratel Media Technologies AG (Maria-Theresien-Straße 8, A-6020 Innsbruck) for the purpose of providing you with the advantages of the costfree guest card. Furthermore, it is necessary to store your usage data for the purpose of internal billing and to make it available to our service providers for the control of internal billing. The legal basis of the processing is your consent in accordance with Art. 6 (1) lit a GDPR, which you give us as part of your guest report in your accommodation establishment. You can revoke this consent at any time free of charge. Uses that have already been made remain unaffected for billing purposes. There is no legal or contractual obligation to provide the personal data. Failure to do so will only result in us not being able to provide you with the guest card. We have concluded a corresponding data processing agreement with feratel in accordance with Art. 28 GDPR as a data processor, which ensures that your data is processed exclusively within the scope of our order. Further information on feratels privacy policy can be found at: https://www.feratel.com/en/privacy-policy.html
 

Summer Card Zell am See-Kaprun: CapCorn guest card system

For the use of our regional guest card, we process your personal data (first name, last name, date of birth, period of stay and country of origin/postal code) with the help of our service provider CapCorn (CapCorn Company Software GmbH, Flugplatzstraße 52/17, A-5700 Zell am See) for the purpose of providing you with the advantages of the free card. Furthermore, it is necessary to store your usage data for the purpose of internal billing and to make it available to our service providers for the control of internal billing. The legal basis of the processing is your consent in accordance with Art. 6 (1) lit a GDPR, which you give us as part of your guest report in your accommodation establishment. You can revoke this consent at any time free of charge. Uses that have already been made remain unaffected for billing purposes. There is no legal or contractual obligation to provide the personal data. Failure to do so will only result in us not being able to provide you with the guest card. We have concluded a corresponding data processing agreement with CapCorn in accordance with Art. 28 GDPR as a data processor, which ensures that your data is processed exclusively within the scope of our order. Further information on CapCorn's data protection can be found at: https://www.capcorn.at/CapCorn_Datenschutzrichtlinien_DE.pdf

 

3.4. Customer and business databases
 

CRM-System von Salesforce

We use the CRM system of the provider Salesforce (Salesforce Germany GmbH, Erika-Mann-Str. 31, 80636 Munich) as a tool for maintaining B2B contacts (e.g. with tour operators, travel agencies, incentive agencies, incentive departments of companies) on the legal basis of our legitimate interest acc. Art. 6 (1) lit. f. GDPR. A transfer of these contacts (names, company name, address data, contact data and interests in holiday topics) to partners in our region (accommodation and other tourist service providers) takes place only at the request of the business partner on legal basis of the consent acc. Art. 6 (1) lit. a GDPR. You can revoke this consent at any time by sending us an e-mail free of charge. We have concluded a corresponding agreement with Salesforce in accordance with Art. 28 GDPR as a processor, which ensures that your data is processed exclusively within the scope of our order. For more information about Salesforce privacy, please visit: https://www.salesforce.com/de/company/privacy/

 

3.5. Guest/Visitor WiFi
 

We offer freely accessible visitor Wi-Fi in public places as well as in our offices. In order to provide the services of the hotspot for you, the use of personal data of your end device is required. In this context, the MAC addresses (Media Access Control Address) of end devices may also be stored temporarily. Furthermore, we may store log data ("log files") about the type and scope of use of the services for 7 days. This data cannot be assigned directly to your person, but directly to your used device and thus also indirectly to your person. To provide this offer, we use the services of Unwired Networks GmbH (Gonzagagasse 11/25, A-1010 Vienna) as our data processor. We have concluded a corresponding agreement with our processor in accordance with Art. 28 GDPR, which ensures that your data is processed exclusively within the scope of our order.

 

3.6. Registration for Events and Guest Programme
 

It is possible to register for events of different providers in our region in our information offices. For this purpose, we process your personal data (name, e-mail address and telephone number). This data will be processed by us on the basis of the legal basis of Art. 6 (1) lit. b GDPR (contract fulfilment/pre-contractual measures) and also passed on to the respective organizer. This data will be deleted or destroyed by us after the event.

 

3.7. Zell am See-Kaprun App
 

For the use of our "Zell am See-Kaprun App", provided by our service provider Dialogschmiede GmbH (Fernkorngasse 10/B1/Top N401, A-1100 Wien), it is possible to install the app on a mobile phone or tablet and register as a user. By registering, you can use the services of our app to the full extent. We process your data as part of your registration in order to give you your individual access to the Zell am See-Kaprun app, to be able to provide you with individualized information and offers and, as a result, to give you the opportunity to easily use offers from our region via the Zell am See-Kaprun app (e.g. to buy ski tickets, to use public transport for free and much more). For this purpose, we process the following data: first name, surname, e-mail address, operating system and device type used (e.g. Android/IOS), the date and time of your access as well as your mobile user ID and geodata. For the booking, reservation of the services of our partners (hotels, mountain railways or other providers of tourist services of our region), we will ask you for further personal data such as date of birth, age, address, your holiday address, your contact details (e.g. your telephone number for queries), information about the desired services (e.g ordered goods or commissioned services and invoice data (such as service period, method of payment, invoice date), payment data (e.g. account number, credit card data). In addition, we analyze your use of our app in order to be able to show you interest-based, individual offers. The legal basis for this data processing is basically the fulfilment of the contract in accordance with Art. 6 (1) lit. b GDPR or your consent in accordance with Art. 6 (1) lit a GDPR (e.g. use of geodata or subscription to our newsletter). You can revoke these consents at any time free of charge. The legality of the data processing operations already carried out up to that point remains unaffected by the revocation. There is no obligation to provide this data. If you do not want to provide this data, it only has the consequence that we can not offer you this service, or not in full extent (e.g. geodata for the navigation function). We only store your data as long as this corresponds to the purpose or is necessary due to legal obligations on our part. We have concluded a corresponding agreement with Dialogschmiede GmbH in accordance with Art. 28 GDPR as a processor, which ensures that your data is processed exclusively within the scope of our order. Further information on data protection of Dialogschmiede GmbH can be found at: https://www.dialogschmiede.com/datenschutz. Further detailed information on data protection when using our app can be obtained when you register for the app.

 

Current version of the privacy policy of 04.10.2023