Legal
Privacy notice
Information under Articles 13/14 GDPR and the Austrian Data Protection Act.
1. Controller
C.D Alpengold GmbH Parkring 12A/8/7/13E, 1010 Vienna VAT ID (UID): ATU82530959
Place of business: Hotel Hadrigan, Maroltingergasse 68, 1160 Vienna Phone: +43 1 6040000 · Email: hotel@hadrigan.com
No data protection officer appointed. See also Legal notice.
2. Hosting and server logs
Technically necessary server logs (IP, time, URL, referrer, browser/OS). Purpose: operation, fault analysis, abuse prevention. Legal basis: Article 6(1)(f) GDPR. Hosting in the EU.
Recipient: website/server hosting provider (EU).
3. Reservation and stay
Data: name, email, phone, optional country/notes, arrival/departure, guests, room type, breakfast, payment status. Purpose: contract, confirmation, reception. Article 6(1)(b) GDPR. Retention usually 7 years (Article 6(1)(c) with Austrian fiscal rules).
City tax (Ortstaxe): Shown separately in the booking preview / quote and not part of the room rate. If paid online (PAID) it may be processed with the total (then not collected again at reception); otherwise payable at reception on arrival. Legal basis Article 6(1)(b) or (c) GDPR.
3a. Contact form
Guest enquiries → hotel@ (Article 6(1)(a)/(b)). Demo/pilot → sales@. Consent may be withdrawn by email.
4. Registration law
Guest registration under the Meldegesetz at reception. Article 6(1)(c) GDPR.
5. Payment (Stripe)
Online card payments via Stripe (payment-related personal data). Article 6(1)(b) GDPR. stripe.com/privacy. Without Stripe enabled: internal confirmation, no card data to Stripe.
Recipient: Stripe (possible US transfer with SCCs / Data Privacy Framework where applicable).
6. Cash register / receipts / fiskaly (RKSV)
Where receipts are signed under RKSV, we process required receipt/transaction data and use fiskaly. Article 6(1)(c) and where needed (b) GDPR.
Recipient: fiskaly (personal receipt/register data where processed). Not website tracking; no “LIVE compliant” claim before clearance.
7. Email
Confirmations via easyname (AT/EU). Article 6(1)(b) GDPR. Recipients: easyname; hotel internally.
8. Map (OpenStreetMap)
Embedded on home/location/contact. Article 6(1)(f) GDPR. Recipient: OpenStreetMap when loaded.
9. Browser / cookies
sessionStorage for booking selection. No analytics/ads/tracking cookies.
10. Recipients — overview
| Recipient | Purpose | Personal data |
|---|---|---|
| Hosting (EU) | Website, logs | IP and log data |
| easyname (EU) | Name, email, booking content | |
| Stripe | Online payment | Payment and contact data |
| fiskaly | RKSV receipt signature | Receipt/register data where processed |
| OpenStreetMap | Map | IP/request when loaded |
| Authorities | Legal duties | Under registration/tax law |
11. Retention / rights / complaint
Logs: a few weeks. Booking data: stay + statutory periods. Rights: access, rectification, erasure, restriction, portability, objection (f), withdraw consent. Contact: hotel@hadrigan.com. Complaint: Austrian DPA, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at.
No automated decision-making including profiling (Article 22 GDPR).