HerzoghofBaden bei Wien · 1910
DE | ENBack to the hotel
Legal

Privacy Policy

Protecting your personal data is important to us. We process your data exclusively on the basis of the applicable law, in particular the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG) and the Austrian Telecommunications Act (TKG 2021). This policy explains how we process data on our website, in our online booking and during your stay. This English version is provided for convenience; in case of doubt the German version applies.

  1. Controller and contact
  2. Definitions
  3. Security of your data
  4. Contact and e-mail
  5. Visiting the website, hosting, server logs
  6. Cookies and consent
  7. Web analytics and marketing (Google, Meta)
  8. Online booking and stay
  9. Payment and card guarantee (Stripe)
  10. Bookings via travel portals
  11. Newsletter and review requests
  12. Google Maps
  13. Contact form (Formspree)
  14. Your rights
  15. Retention periods
  16. Changes to this policy

1. Controller and contact

TKB Hotels GmbH
Garnisongasse 4/11, 1090 Wien, Austria
Place of business: Hotel Herzoghof, Kaiser-Franz-Ring 10, 2500 Baden bei Wien
Commercial register: FN 637452 f, Handelsgericht Wien · VAT ID: ATU81314105
Phone: +43 2252 87297 · E-mail: office@hotel-herzoghof.at

For all questions about data protection and to exercise your rights, please use the contact details above. Under Art. 37 GDPR our company is not required to appoint a data protection officer.

2. Definitions

Personal data means any information relating to an identified or identifiable natural person (Art. 4 (1) GDPR), such as name, address, e-mail address, phone number, date of birth, travel dates or online identifiers. Processing means any operation performed on personal data, such as collection, storage, use, transfer or erasure (Art. 4 (2) GDPR).

3. Security of your data

Under Art. 32 GDPR we take appropriate technical and organisational measures to protect your data against unauthorised access, loss or misuse. The website and the online booking are transmitted exclusively encrypted (TLS/HTTPS). Payment card data are never stored on our systems but processed directly by our PCI-DSS-certified payment provider (section 9). Access to guest data is restricted to staff who need it to perform their duties.

4. Contact and e-mail

If you contact us by e-mail, phone or via our contact form, we process the data you provide (name, e-mail address, phone number, content of the enquiry, travel dates where applicable) to handle your enquiry and any follow-up questions. The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures or performance of a contract) or Art. 6 (1) (f) GDPR (legitimate interest in answering your enquiry). Enquiry data that do not lead to a contract are deleted after three years at the latest.

Our e-mails – including booking confirmations, review requests and newsletters – are sent via our own e-mail hosting with an Austrian hosting provider that processes the data on our behalf under a data processing agreement (Art. 28 GDPR) on servers in the EU.

5. Visiting the website, hosting, server logs

When you visit our website, technical data are processed automatically: IP address, date and time of access, page requested, browser type and version, operating system and the previously visited page (referrer). These data are technically necessary to deliver the website and to defend against attacks. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in secure operation). Server logs are deleted after 30 days at the latest.

The website and the online booking are hosted by Netlify, Inc., 512 2nd Street, San Francisco, CA 94107, USA. Netlify processes the technical data on our behalf under a data processing agreement (Art. 28 GDPR). The transfer to the USA is safeguarded by Netlify's certification under the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023, Art. 45 GDPR) and by standard contractual clauses (Art. 46 (2) (c) GDPR). Further information: netlify.com/privacy.

The fonts of our website are loaded from our own server; no connection to external font providers is made.

6. Cookies and consent

Cookies are small text files stored by your browser; we also use your browser's local storage. Under § 165 (3) TKG 2021 and Art. 6 (1) (a) GDPR we set cookies that are not technically necessary only with your express consent. On your first visit our cookie notice asks for your decision; you can accept all categories, allow only necessary cookies or select individual categories. Until you decide, only necessary cookies are set; statistics and marketing services are loaded only after your consent.

We store your decision for 12 months. As proof of consent (Art. 7 (1) GDPR) we log the time, the version of the cookie notice, the categories chosen and a random identifier – without your IP address. You can change or withdraw your consent at any time with effect for the future:

Open cookie settings – here you can change or withdraw your choice at any time.

Overview of cookies and storage technologies used

NameTypePurposeDurationCategory
hz_consentCookie / Local StorageStores your cookie decision (version, categories, time, random ID).12 monthsNecessary
hz_langLocal StorageSelected language (DE/EN).unlimitedNecessary
__stripe_mid, __stripe_sidCookie (Stripe)Fraud prevention for online payment; booking page only.1 year / 30 minNecessary
_ga, _ga_*Cookie (Google Analytics)Distinguishes visitors, sessions and page views.up to 2 yearsStatistics
_gcl_au, _gcl_awCookie (Google Ads)Conversion measurement and attribution of ad clicks.90 daysMarketing
_fbp, _fbcCookie (Meta)Meta Pixel: measurement and audience building for ads on Facebook and Instagram.90 daysMarketing
NID, CONSENT u. a.Cookie (Google Maps)Set by Google when the directions map is loaded.up to 6 monthsExternal content

Cookies in the categories “Statistics”, “Marketing” and “External content” are set only if you have allowed the respective category. Durations are as stated by the providers.

7. Web analytics and marketing (Google, Meta)

With your consent (Art. 6 (1) (a) GDPR, § 165 (3) TKG 2021) we use the following services. They are integrated via Google Tag Manager and loaded only if you have allowed the “Statistics” or “Marketing” category. Without consent no data are transmitted to these providers; we use Google Consent Mode v2, in which all Google services are set to “denied” by default.

Google Tag Manager

Google Tag Manager (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) is a tool for managing website tags. It sets no cookies for analytics or advertising itself and loads the services below only in line with your consent.

Google Analytics 4 (category Statistics)

Google Analytics collects pseudonymised usage data (pages viewed, time on site, approximate location based on the truncated IP address, device and browser, source of the visit) to understand how our website is used and to improve it. Google Analytics 4 does not store IP addresses. User data retention at Google is set to 14 months. Google Ireland may transfer data to Google LLC in the USA; Google is certified under the EU-US Data Privacy Framework, and standard contractual clauses apply in addition. Further information: policies.google.com/privacy.

Google Ads conversion tracking and remarketing (category Marketing)

With Google Ads we measure whether visitors reached us via a Google ad and whether they completed a booking (conversion), and we can show interest-based ads on Google services and partner sites to users who visited our website (remarketing). Cookies are set and usage data and a click identifier are transmitted to Google. Provider, data transfer and safeguards as for Google Analytics. You can disable personalised advertising from Google at adssettings.google.com.

Meta Pixel (category Marketing)

The Meta Pixel of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland, allows us to measure the success of ads on Facebook and Instagram and to build audiences (e.g. visitors of our website or people with similar interests). Cookies are set and event data (e.g. page view, completed booking) as well as your IP address and browser information are transmitted to Meta; if you are logged in to Facebook or Instagram, Meta can link the data to your account. We and Meta are joint controllers for the collection and transmission of these data (Art. 26 GDPR); the agreement is available at facebook.com/legal/controller_addendum. Meta Ireland may transfer data to Meta Platforms, Inc. in the USA; Meta is certified under the EU-US Data Privacy Framework. Further information and settings: facebook.com/privacy/policy.

Further services

Should we use further analytics or marketing services in future (such as TikTok, LinkedIn or Pinterest), we will update this policy and the cookie notice before the services are activated. Activation takes place exclusively within the categories you have allowed.

8. Online booking and stay

Which data we process

When you book on our website we collect: first and last name, e-mail address and phone number of the person booking; first and last name of all accompanying guests; billing address and – for company bookings – company name and VAT ID; travel dates, selected rooms, rate and extras (breakfast, parking space); your notes on the booking; the selected language; and whether you wish to receive our newsletter. During your stay we additionally process the data required under the Austrian Registration Act (registration form: including date of birth, nationality, travel document) and the data of the services used, for billing.

Purposes and legal bases

Hotel software (apaleo)

To manage bookings, rooms and invoices we use the property management system of apaleo GmbH, Zeltnerstraße 1–3, 90443 Nuremberg, Germany. apaleo processes your booking and stay data on our behalf on servers in the European Union under a data processing agreement (Art. 28 GDPR). Further information: apaleo.com/privacy-policy.

Booking confirmation

After completing your booking you receive a confirmation at the e-mail address provided. This message is part of the performance of the contract and not advertising.

9. Payment and card guarantee (Stripe)

For online payments and for storing a credit card as a booking guarantee we use the payment provider Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (together with Stripe, Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA). You enter your card data directly into an encrypted form provided by Stripe; they are processed exclusively by Stripe and never reach our systems. From Stripe we receive only a reference number, the card brand and the last four digits. Stripe sets technically necessary cookies for fraud prevention (section 6).

Stripe processes data as an independent controller for payment processing and fraud prevention and may transfer them to Stripe, Inc. in the USA; the transfer is safeguarded by Stripe's certification under the EU-US Data Privacy Framework and by standard contractual clauses. The stored payment method is deleted no later than 90 days after your departure, provided no claims are outstanding. Further information: stripe.com/at/privacy.

10. Bookings via travel portals

If you book via a booking portal (e.g. Booking.com, Expedia, HRS), the portal transmits to us the data required to perform the accommodation contract (name, contact details, travel dates, payment guarantee where applicable). We process these data on the basis of Art. 6 (1) (b) GDPR. The portal operator is responsible for the processing carried out by the portal; the portal's privacy notice applies.

11. Newsletter and review requests

Newsletter

If you consent to receiving our newsletter when booking or via our website, we use your name and e-mail address to send you offers and news from Hotel Herzoghof. For sign-ups via the website we first send you a confirmation e-mail (double opt-in); you are added to the list only after clicking the confirmation link. The legal basis is your consent under Art. 6 (1) (a) GDPR in conjunction with § 174 TKG 2021. You can withdraw your consent at any time with effect for the future – via the unsubscribe link in every message or by e-mail to office@hotel-herzoghof.at (Art. 7 (3) GDPR). After withdrawal we delete your data from the list; we keep the record of your consent for evidence purposes. We evaluate whether links in our messages were clicked in order to measure the success and relevance of our mailings.

Review requests after your stay

After your departure we send you once – possibly with one reminder – an e-mail asking you to review your stay (e.g. on Google or on the portal through which you booked). The legal basis is our legitimate interest in feedback from our guests and in improving our services (Art. 6 (1) (f) GDPR) in conjunction with § 174 (4) TKG 2021 (existing customers). You can object to such messages at any time via the unsubscribe link or by e-mail.

12. Google Maps

For directions we embed Google Maps of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The map is loaded only after you have allowed the “External content” category in our cookie notice or expressly requested the map (Art. 6 (1) (a) GDPR). When loaded, Google receives your IP address and usage data and may transfer them to the USA; Google is certified under the EU-US Data Privacy Framework. You can withdraw your consent at any time in the cookie settings. Further information: policies.google.com/privacy.

13. Contact form (Formspree)

Enquiries via our contact form are received on our behalf by Formspree, Inc., 462 1st Ave, New York, NY 10016, USA, and forwarded to us by e-mail. Formspree is certified under the EU-US Data Privacy Framework and processes the data exclusively for transmission to us (Art. 28 GDPR). The legal basis is Art. 6 (1) (b) GDPR. Further information: formspree.io/legal/privacy-policy.

14. Your rights

You have the following rights regarding your personal data:

To exercise your rights, please contact office@hotel-herzoghof.at. If you believe that the processing of your data infringes data protection law, you can lodge a complaint with the Austrian Data Protection Authority: Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb.gv.at.

15. Retention periods

We store personal data only as long as necessary for the respective purpose or as required by statutory retention obligations. Booking and invoice data are retained for seven years under § 132 of the Federal Fiscal Code and § 212 of the Commercial Code; registration forms under the Registration Act for seven years. Enquiries without a contract are deleted after three years, server logs after 30 days, stored payment methods no later than 90 days after departure, cookie consents and their log after three years. Beyond that we store data only as long as necessary to establish, exercise or defend legal claims.

16. Changes to this policy

We update this privacy policy when our data processing or the legal situation changes. The current version is always available at this address.

Last updated: 17 September 2026