Legal
Privacy policy
This page explains which personal data is processed when you visit this website or contact us.
Last updated: 12 August 2026
01
Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Christine Kunz GesmbH & Co. Tourismusbetriebe KGMax-Lauritsch-Straße 55
9523 Villach, Austria
VAT ID: ATU12505207
Company register number: FN 6841k
Company register court: Commercial Court of Vienna
Telephone: +43 4254 2145
E-Mail: info@inselhotel.at
No data protection officer has been appointed. Please send privacy-related enquiries directly to the email address shown above.
02
Provision of the website and hosting
This static website is delivered through Cloudflare Pages. The provider is Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. When you access the website, the technical infrastructure processes data automatically transmitted by your browser. This may include in particular:
- IP address and time of the request,
- address requested and volume of data transferred,
- referrer address, if transmitted by the browser,
- browser type, browser version and operating system, and
- status code, routing, security and error data.
This processing is necessary to deliver the website, prevent attacks and abusive access, identify errors and ensure secure technical operation. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure, stable and efficient provision of our website.
Cloudflare processes data on our behalf and may also process technical data outside the European Economic Area. For restricted transfers, our agreement with Cloudflare provides appropriate safeguards, in particular the EU Standard Contractual Clauses. Further information is available in the Cloudflare Privacy Policy and the Cloudflare Data Processing Addendum .
03
Contact, table enquiries and voucher requests
This website has no contact form. If you contact us by email, telephone or post, we process the information you provide—such as your name, contact details, the substance of your enquiry, preferred travel dates or information about an event—to respond to your request.
Where your enquiry concerns a booking, reservation, voucher or another service, processing is necessary for pre-contractual steps or performance of a contract under Art. 6(1)(b) GDPR. For general enquiries, we rely on our legitimate interest in reliable communication under Art. 6(1)(f) GDPR. Where statutory retention duties apply, the legal basis is Art. 6(1)(c) GDPR.
Providing the information required for the relevant request is necessary for us to handle your enquiry. No automated decision-making or profiling takes place.
04
Direct booking and island day
The buttons “Find a room”, “Availability” and “Book an island day” lead to the separate booking platform at buchung.inselhotel.at, which is technically provided by Seekda. The booking platform is not embedded in this website. A connection is established only when you open the corresponding link.
The privacy information provided within the booking platform applies to booking and payment data entered there. Additional information is available in the Seekda Privacy Policy . Where we receive booking data to process your reservation, we process it under Art. 6(1)(b) GDPR. Booking and accounting records required by law are retained under Art. 6(1)(c) GDPR for the applicable statutory period.
05
Maps and the 360° island tour
The website links to Google Maps for route planning and to the existing 360° island tour. These services are not embedded in the new website. Only when you open a link does your browser access the relevant service and transmit the technically necessary connection data to its operator.
For Google Maps, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, is responsible for further processing. More information is available in the Google Privacy Policy . The privacy information of each linked service applies to activity on that service. You decide whether to open an external link.
07
Recipients and data transfers
Within our company, personal data is available only to those who need it to handle your request. Carefully selected processors may also receive data, in particular providers of hosting, IT operations, email and booking services. These providers may process data only on our instructions and for the agreed purposes.
Data is disclosed to authorities, courts or other public bodies where we are legally required to do so. Other disclosures take place only where necessary to perform a contract, where another legal basis applies or where you have consented.
If a recipient processes data in a country outside the EEA, the transfer takes place only on the basis of an adequacy decision or appropriate safeguards such as the European Commission’s Standard Contractual Clauses, unless a statutory exception applies.
08
Retention periods
We retain personal data only for as long as necessary for the relevant purpose or as required by statutory duties and legitimate claims. Enquiries that do not lead to a contract are deleted once fully handled, provided there is no legal reason for further retention.
Contract, booking and accounting records are routinely subject to statutory retention periods; documents relevant under tax and company law are generally retained for seven years. Data may also be retained until the expiry of applicable limitation periods where necessary to establish, exercise or defend legal claims. Technical log data is retained only for as long as required for security, error analysis and operation of the hosting service.
09
Your rights
Subject to the statutory requirements, you have in particular the right to:
- access your personal data (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure of your data (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR), and
- object to processing based on Art. 6(1)(e) or (f) GDPR (Art. 21 GDPR).
You may withdraw consent at any time with effect for the future. This does not affect the lawfulness of processing carried out before withdrawal. To exercise your rights, simply send a message to info@inselhotel.at. To ensure that we can securely assign your request, we may ask for suitable proof of identity where necessary.
Right to lodge a complaint
If you believe that the processing of your data infringes data-protection law, you may lodge a complaint with a supervisory authority. In Austria, this is:
Austrian Data Protection AuthorityBarichgasse 40–42
1030 Vienna
E-Mail: dsb@dsb.gv.at
Information on complaints
10
Data security and changes
The website is transmitted in encrypted form via HTTPS. We use appropriate technical and organisational measures to protect personal data against loss, unauthorised access and misuse. Complete protection during transmission cannot, however, be guaranteed when communicating by email.
We update this privacy policy if the website, the services used or legal requirements change. The version published on this page at the relevant time applies.