Legal

Privacy notice

Information under Articles 13/14 GDPR and the Austrian Data Protection Act.

1. Controller

C.D Alpengold GmbH Parkring 12A/8/7/13E, 1010 Vienna VAT ID (UID): ATU82530959

Place of business: Hotel Hadrigan, Maroltingergasse 68, 1160 Vienna Phone: +43 1 6040000 · Email: hotel@hadrigan.com

No data protection officer appointed. See also Legal notice.

2. Hosting and server logs

Technically necessary server logs (IP, time, URL, referrer, browser/OS). Purpose: operation, fault analysis, abuse prevention. Legal basis: Article 6(1)(f) GDPR. Hosting in the EU.

Recipient: website/server hosting provider (EU).

3. Reservation and stay

Data: name, email, phone, optional country/notes, arrival/departure, guests, room type, breakfast, payment status. Purpose: contract, confirmation, reception. Article 6(1)(b) GDPR. Retention usually 7 years (Article 6(1)(c) with Austrian fiscal rules).

City tax (Ortstaxe): Shown separately in the booking preview / quote and not part of the room rate. If paid online (PAID) it may be processed with the total (then not collected again at reception); otherwise payable at reception on arrival. Legal basis Article 6(1)(b) or (c) GDPR.

3a. Contact form

Guest enquiries → hotel@ (Article 6(1)(a)/(b)). Demo/pilot → sales@. Consent may be withdrawn by email.

4. Registration law

Guest registration under the Meldegesetz at reception. Article 6(1)(c) GDPR.

5. Payment (Stripe)

Online card payments via Stripe (payment-related personal data). Article 6(1)(b) GDPR. stripe.com/privacy. Without Stripe enabled: internal confirmation, no card data to Stripe.

Recipient: Stripe (possible US transfer with SCCs / Data Privacy Framework where applicable).

6. Cash register / receipts / fiskaly (RKSV)

Where receipts are signed under RKSV, we process required receipt/transaction data and use fiskaly. Article 6(1)(c) and where needed (b) GDPR.

Recipient: fiskaly (personal receipt/register data where processed). Not website tracking; no “LIVE compliant” claim before clearance.

7. Email

Confirmations via easyname (AT/EU). Article 6(1)(b) GDPR. Recipients: easyname; hotel internally.

8. Map (OpenStreetMap)

Embedded on home/location/contact. Article 6(1)(f) GDPR. Recipient: OpenStreetMap when loaded.

9. Browser / cookies

sessionStorage for booking selection. No analytics/ads/tracking cookies.

10. Recipients — overview

RecipientPurposePersonal data
Hosting (EU)Website, logsIP and log data
easyname (EU)EmailName, email, booking content
StripeOnline paymentPayment and contact data
fiskalyRKSV receipt signatureReceipt/register data where processed
OpenStreetMapMapIP/request when loaded
AuthoritiesLegal dutiesUnder registration/tax law

11. Retention / rights / complaint

Logs: a few weeks. Booking data: stay + statutory periods. Rights: access, rectification, erasure, restriction, portability, objection (f), withdraw consent. Contact: hotel@hadrigan.com. Complaint: Austrian DPA, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at.

No automated decision-making including profiling (Article 22 GDPR).