Data Privacy | Bürgenstock Hotels AG | EN

Page 1


6.1

1 CONTACTS

1.1 RESPONSIBLE

We, the following companies:

Bürgenstock Hotels AG, Bürgenstock 17, 6363 Obbürgen, Switzerland (CHE105.841.711), operator of the websites www.burgenstockresort.com and www.buergenstock-waldhotel.ch

are responsible for the collection, processing and use of your personal data and the compliance of the data processing with the applicable data protection law on the respective website.

Bürgenstock Bahn AG, Bürgenstock 17, 6363 Obbürgen, Switzerland (CHE108.107.719) and the

Hammetschwand Lift AG, Bürgenstock 2c, 6363 Obbürgen, Switzerland (CHE106.643.533)

are responsible for the collection, processing and use of your personal data and the compatibility of the data processing with the applicable data protection law with the services provided by these companies.

We handle your data confidentially.

The protection of your personality data and your privacy is important to us. We guarantee that your personal data will be processed in accordance with the applicable provisions of data protection law.

To summarise, we process personal data exclusively in accordance with the following principles:

You yourself decide on the processing of your personal data.

Within the legal framework, you can refuse data processing or withdraw your consent or have your data deleted at any time.

We offer you added value when processing your data.

We use your data exclusively in the context of providing our services and to offer you added value (e.g. customised offers, information and support). We therefore only use your data for the development, provision, optimisation and evaluation of our services or for maintaining the customer relationship.

Your data will not be sold.

Your data will only be disclosed to selected third parties listed in this privacy policy and only for the purposes explicitly stated. If we commission third parties to process data, they are obliged to comply with our data protection standards.

We guarantee the security and protection of your data.

We guarantee careful handling of your data as well as its security and protection. We take the necessary organisational and technical precautions to ensure this. Below you will find detailed information on how we handle your data.

1.2 DATA PROTECTION CONSULTANT / DATA PROTECTION OFFICER

For questions in connection with data protection and for information regarding your rights and how to assert them, please contact our data protection officer:

data-privacy@burgenstockresort.com

1.3 NAME AND ADDRESS OF THE EU REPRESENTATIVE

We have the following data protection representation in the European Economic Area (EEA) including the European Union (EU) and the Principality of Liechtenstein as an additional point of contact for supervisory authorities and data subjects for enquiries in connection with the General Data Protection Regulation (GDPR): VGS Datenschutzpartner UG, Am Kaiserkai 69, 20457 Hamburg, Germany, INFO@DATENSCHUTZPARTNER.EU

2 DATA PROCESSING IN CONNECTION WITH OUR WEBSITE

2.1 ACCESS TO OUR WEBSITE

When you visit our website, our servers temporarily store every access in a log file. As with every connection to a web server, the following technical data is recorded without any action on your part and stored by us until it is automatically deleted after 12 months at the latest:

• the IP address of the requesting computer,

• the name of the owner of the IP address range (usually your Internet access provider),

• the date and time of access,

• the website from which the access was made (referrer URL) with the search term used, if applicable,

• the name and URL of the retrieved file,

• Country from which access is done;

• the status code (e.g. error message),

• Time zone difference to Greenwich Mean Time (GMT)

• the operating system of your computer,

• the browser you are using (type, version and language),

• the transmission protocol used (e.g. HTTP/1.1) and

• If applicable, your username from a registration/authentication.

This data is collected and processed for the purpose of enabling the use of our websites (establishing a connection), ensuring system security and stability in the long term and enabling the optimisation of our website as well as for internal statistical purposes. This constitutes our legitimate interest in data processing.

The IP address is also analysed together with the other data in the event of attacks on the network infrastructure or other unauthorised or abusive use of the website for clarification and defence purposes and, if necessary, used in the context of criminal proceedings for identification and for civil and criminal proceedings against the users concerned. This is our legitimate interest in data processing.

We use Google reCaptcha on our websites to protect the technical systems and to prevent abusive automated entries in web forms. reCaptcha is an offer from Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland).

When you visit one of our websites in which reCaptcha is integrated, a connection to the Google servers is established. A reCaptcha cookie is set. Your IP address is transmitted to Google. In addition, reCaptcha collects the following data (fingerprinting):

• the date

• the browser language

• CSS information for the requested page

• Javascript objects

• Browser plugins used

• Number of mouse clicks and touches you have made on this screen

• the cookies set by Google in the last 6 months

The data is stored and analysed based on our legitimate interest in protecting our website from abusive automated spying and SPAM. Insofar as personal data is transferred to Google in the USA, this is done based on EU standard contractual clauses.

2.2 USE OF OUR CONTACT FORM

Where you have the option of using a contact form on our website to get in touch with us, we generally require the following information:

• Salutation

• First name and surname

• E-mail address

• Telephone number

• Communication

Those entries that are necessary for the smooth processing of your enquiry are marked as mandatory. The entry of other information is optional. We only use this data and the address you provide voluntarily to answer your contact request in the best possible and personalised way. The processing of this data is therefore necessary for the implementation of pre-contractual measures or is in our legitimate interest.

2.3 ENQUIRIES ABOUT MEETINGS, CONFERENCES AND EVENTS

• You have the option of making an enquiry on our website to book a meeting, conference or event. We generally require the following information:

• For which hotel the enquiry applies

• Type of event, description of the event, number of guests

• Event date

• Salutation

• First name and surname

• Company

• Postal address

• E-mail address

• Telephone number

• Event details (VIP participation, catering requirements, conference technology requirements, additional services (flowers, photographer, music, tablecloth, transport, spa time and activities, budget))

Those entries that are necessary for the smooth processing of your enquiry are marked as mandatory. The entry of other information is optional. We only use this data and the address you provide voluntarily to answer your enquiry in the best possible and personalised way. The processing of this data is in our legitimate interest.

Please note that we may pass on your data to third parties if this is necessary in the context of using the websites and processing the contract.

2.4 MICROSOFT TEAMS

We use the "Microsoft Teams" tool to conduct telephone conferences, online meetings, video conferences and/or online seminars (hereinafter: "Online Meetings")

"Microsoft Teams" is a product of Microsoft Corporation, Way, Redmond, WA 980526399, USA

Various types of data are processed when using "Microsoft Teams". The scope of the data also depends on what data information is provided before or during participation in an "online meeting". These are, for example

• User details: e.g. display name, e-mail address if applicable, profile picture (optional), preferred language

• Meeting metadata: e.g. date, time, meeting ID, telephone numbers, location

• Text, audio and video data:

It is possible to use the chat function in an "online meeting". In this respect, the text entries made by the respective user are processed in order to display them in the "online meeting". In order to enable the display of video and the playback of audio, the data from the microphone of your end device and from any video camera of the end device are processed accordingly for the duration of the meeting. The camera or microphone can be switched off or muted by the user at any time via the "Microsoft Teams" applications.

If "online meetings" are to be recorded, this is communicated transparently in advance and, if necessary, consent is requested.

The chat content is logged when using Microsoft Teams. If it is necessary for the purposes of logging the results of an online meeting, we will log the chat content. As a rule, however, this will not be the case.

The processing of this data is in our legitimate interest. In these cases, we are interested in the effective organisation of online meetings. Otherwise, the legal basis for data processing when conducting "online meetings" is the contract, insofar as the meetings are conducted within the framework of contractual relationships.

2.5 SUBSCRIBE TO OUR NEWSLETTER

Wherever you have the option of subscribing to our newsletter on our website, registration is required. The following data must be provided as part of the registration process:

• Salutation

• First name and surname

• E-mail address

The above data is necessary for data processing. We process this data exclusively in order to personalise the information and offers sent to you and to better tailor them to your interests.

By registering, you give us your consent to process the data provided for the regular dispatch of the newsletter to the address you have provided and for the statistical evaluation of user behaviour and the optimisation of the newsletter. This consent constitutes our legal basis for processing your e-mail address. We are authorised to commission third parties with the technical processing of the newsletter and are entitled to pass on your data for this purpose.

Registration for the newsletter takes place in a so-called double opt-in procedure. This means that after registering and clicking on the corresponding checkbox, you will receive an e-mail in which you must click on a link to confirm your registration.

The newsletters contain a so-called "web-beacon", i.e. a pixel-sized file that is retrieved from the server of the dispatch service provider when the newsletter is opened. As part of this retrieval, technical information, such as information about the browser and your system, as well as your IP address and time of retrieval, is initially collected. This information is used for the technical improvement of the services based on the technical data or the target groups and their reading behaviour based on their retrieval locations (which can be determined with the help of the IP address) or the access times. The surveys also include determining whether the newsletters are opened, when they are opened, and which links are clicked. For technical reasons, this information can be assigned to individual newsletter recipients. However, it is neither our endeavour nor that of the mailing service provider to observe individual users. Instead, the analyses help us to recognise the reading habits of our users and to adapt our content to them or to send different content according to the interests of our users.

At the end of each newsletter, you will find a link that you can use to unsubscribe from the newsletter at any time. When unsubscribing, you can voluntarily inform us of the reason for your cancellation. After unsubcribed, your personal data will be deleted. To optimize our newsletter, your data will only be used in anonymized form after the deletion.

You can also send your request to unsubscribe to the following e-mail address: data-privacy@burgenstockresort.com

2.6 ORDER VOUCHERS

You have the option of ordering vouchers on our website. We generally require the following information for this:

• Salutation

• Title

• Company name

• First name and surname

• E-mail address

• Number of persons

• Telephone number

• Voucher type

• Dedication, greeting message and salutation for voucher recipient

• Payment method

The entries that are necessary for the smooth processing of your enquiry are marked as required. Entering other information is optional. We only use this data and the address you provide voluntarily to answer your enquiry in the best possible and personalised way. The processing of this data is in our legitimate interest.

Please note that we may pass on your data to third parties insofar as this is necessary in the context of using the websites and processing the contract.

2.7 OPENING A CUSTOMER ACCOUNT

Wherever you have the option of making bookings on our websites, you can order as a guest or open a customer account. When you register for a customer account, we generally collect the following data:

• Salutation

• First name and surname

• Postal address

• Telephone number

• E-mail address

• Password and security question

The entries that are necessary for the smooth processing of your customer account opening are marked as mandatory. The entry of other information is optional. The purpose of collecting this data and other data you provide voluntarily (e.g. company name) is to provide you with password-protected direct access to your basic data stored with us. You can view your previous and current bookings or manage or change your personal data.

The legal basis for processing the data for this purpose is the consent you have given.

2.8 BOOKING ON THE WEBSITE, BY CORRESPONDENCE OR BY TELEPHONE CALL

If you make bookings for overnight stays, restaurant reservations, leisure activities, wellness services and/or medical services either via our websites, by correspondence (e-mail or letter post) or by telephone call, we generally require the following data to process the contract:

• Salutation

• First name and surname

• Postal address

• Telephone number

• Credit card information

• E-mail address

We will process the data by name in order to record your booking/reservation as requested, to provide the booked services, to contact you in the event of ambiguities or problems and to ensure correct payment.

Those entries that are necessary for the smooth processing of your booking are marked as mandatory or - in the case of telephone bookings - requested by you in person. The entry of other information is optional. We will only use other information that you provide voluntarily (e.g. date of birth, expected arrival time, motor vehicle licence plate, preferences, comments) to process the contract, unless otherwise stated in this data protection declaration or unless you have given your separate consent.

Please note that we may pass on your data to third parties insofar as this is necessary in the context of using the websites and processing the contract.

The legal basis for data processing for this purpose is the fulfilment of a contract.

2.9 ORDERS IN OUR ONLINE SHOP

If you have to register when ordering in our online shop and set a username and a personal password, you can log in with your user name and password on future visits to the website and do not have to re-enter your address and payment information each time you place an order. Your password is stored in encrypted form and cannot be viewed by us.

You must enter the following data when registering:

• Salutation

• First name and surname

• Postal address (billing address)

• Delivery address

• E-mail address

• Telephone number

• Shipping and payment method

The entries that are necessary for the smooth processing of your customer account opening are marked as required. Entering other information is optional.

Your order data is also stored in your customer account.

We use the personal data collected during registration and ordering exclusively for the proper processing of your order. The legal basis for data processing for this purpose is the fulfilment of a contract.

You can view and change the data in your customer account, such as the payment method and delivery address you have selected, at any time. If you update information, we will keep a copy of your original details in order to be able to clarify any questions between you and us.

You have the option of deleting your customer account at any time as soon as there are no more open orders. You can also send your deletion request to the following email address:

data-privacy@burgenstockresort.com

To verify your identity, please send the request directly via e-mail from your user account.

2.10 SERVICES OF THE BÜRGENSTOCK RAILWAY

The Bürgenstock Railway is responsible for the processing of your data. As a public transport company, we are obligated by law to provide transport services together with other transport companies and associations ("direct transport", Art. 16 and 17 of the Passenger Transport Act). In order to make this possible, data that originates from contacting you or from your purchased services, for example, is passed on at national level within the National Direct Transport (NDV), an association of over 240 transport companies (TU) and public transport networks. The individual transport companies and associations are listed here.

The data is stored in the central database NOVA (network-wide public transport connection), which is managed by SBB on behalf of the NDV and for which we are responsible together with the other companies and associations of the NDV. NOVA is a technical platform for the sale of public transport services. It contains all the central elements for the sale of public transport services, such as the customer database. The scope of access to the shared databases by the individual transport companies and associations is governed by a joint agreement. The forwarding of data and its processing by the transport companies and associations in connection with centralised storage is limited to the following purposes:

2.10.1

PROVISION OF THE TRANSPORT SERVICE

To ensure that your journey runs smoothly, your travel and purchase details are forwarded within the NDV.

2.10.2

CONTRACT PROCESSING

We process this data for the establishment, administration and processing of contractual relationships.

2.10.3

MAINTAINING CUSTOMER RELATIONSHIPS AND SUPPORT

We process your data for purposes related to communication with you, in particular to respond to enquiries and assert your rights and to identify and provide you with the best possible support in the event of concerns or difficulties across the entire public transport network, as well as to process any claims for compensation.

2.10.4

TICKET CONTROLAND REVENUE PROTECTION

Customer and season ticket data is required and processed to secure revenue (checking the validity of travel or discount cards, collection, combating abuse). Incidents of travelling without a valid or partially valid ticket can be recorded via the national fare dodger register.

2.10.5

REVENUE DISTRIBUTION

The office of the Alliance SwissPass, managed by ch-integral, fulfils the legal mandate defined in the Swiss Passenger Transport Act to collect travel data for the correct distribution of revenue [https://www.allianceswisspass.ch/de/informationenov-nutzende/kundenbefragungen]. The office acts as the mandate holder for revenue distribution in national direct transport on behalf of the companies that are members of the NDV.

2.10.6

IDENTIFICATION AS PART OF THE AUTHENTICATION OF THE SWISSPASS LOGIN (SSO)

For services that you purchase using the SwissPass login, the data is then stored in the central customer database (NOVA). To enable single sign-on (SSO) (one login for all applications that offer use of their services with the SwissPass login), the aforementioned login, card, customer and service data are also exchanged between the SwissPass central login infrastructure and us as part of the authentication process.

2.10.7

JOINT MARKETING AND MARKET RESEARCH ACTIVITIES

In addition, the data collected when purchasing public transport services (https://www.allianceswisspass.ch/de/informationen-ov-nutzende/Datenschutz) is also processed for marketing purposes in certain cases. If you have given your consent and your data is processed or you are contacted for this purpose, this will only be carried out by the transport company or association from which you purchased the corresponding public transport service. Processing or contact by the other transport companies and networks involved in the NDV will only take place in exceptional cases and under strict conditions, and only if the evaluation of the data shows that a particular public transport service could provide added value for you as a customer. An exception to this is processing and contacting by SBB. SBB manages the marketing mandate for NDV services (e.g. GA travelcard and Half-Fare travelcard) on behalf of NDV and can contact you regularly in this role. We also process your data for market research, to improve our services and for product development.

2.10.8

FURTHER DEVELOPMENT OF PUBLIC TRANSPORT SYSTEMS WITH ANONYMOUS DATA

We analyse their data anonymously in order to be able to further develop the overall public transport system in line with their needs.

2.10.9

CUSTOMER INFORMATION

[For cross-border journeys, we will notify you by e-mail or text message about the upcoming journey and any delays or cancellations. You can unsubscribe from these notifications]. For group travel, we will notify you via SMS about your group

reservation and any delays or cancellations. You can decide for yourself whether you wish to receive these notifications when you book a group trip.

Why do we collect personal data?

We are aware of how important it is for you to handle your personal data with care. All data processing is only carried out for specific purposes. These may arise, for example, from technical necessity, contractual requirements, legal regulations, overriding interest, i.e. for legitimate reasons, or from your consent. We collect, store and process personal data insofar as this is necessary, for example for

• sales and invoicing,

• answering questions and concerns,

For more detailed information on which data is processed for which purposes, please read the following sections.

Where is the data stored?

Your data is generally stored in databases within Switzerland. In some cases listed in this privacy policy, however, the data will also be passed on to third parties based outside Switzerland. If the country in question does not have an adequate level of data protection, we ensure through contractual arrangements with these companies that your data is adequately protected by these companies.

2.11 APPLICATION FOR A JOB ADVERTISEMENT

Wherever you have the opportunity to apply for jobs on our websites, you must submit a complete application. As a rule, the following data must be provided:

• Salutation

• First name and surname

• Language

• Postal address

• Date of birth

• E-mail address

• Telephone number

• Application documents (CV, letter of motivation etc.)

Those entries that are necessary for the smooth processing of your application are marked as mandatory. This data and other information you provide voluntarily will be used to process the application process. Your data will be deleted after 6 months following the respective application process, unless you have given us your consent to use your details for further application processes with us.

The legal basis for data processing is therefore the implementation of pre-contractual measures and our legitimate interest. The legal basis for further data processing is the consent you have given.

We partly use the talent management software "Recruitment App" from Abacus Umantis AG, based in St. Gallen. The recruiting app is integrated into the websites via iFrame and shows vacancies and the option to apply via a form.

When you apply for a job with us, your personal data will be stored and processed on the systems of Abacus Umantis AG.

We have taken the necessary organisational and technical measures with HaufeUmantis AG to ensure the confidentiality of your application. All employees in the HR department and our software partner are obligated to maintain confidentiality regarding personal data as part of their employment contract.

Thanks to automatically activated 128-bit encryption, secure transmission of your data is ensured. The general standards for data security in accordance with the current latest technology are taken into account when processing data.

Further information can be found in the privacy policy:

Privacy Policy | Job Service Maltech AG (Umantis.com)

You can object to this data processing at any time. If you object, we will no longer process your personal data for this purpose. Please send your objection to the following e-mail address:

data-privacy@burgenstockresort.com

2.12 COOKIES

Cookies help in many ways to make your visit to our website easier, pleasant and more meaningful. Cookies are information files that your web browser automatically saves on your computer's hard drive when you visit our website.

For example, we use cookies to temporarily save your selected services and entries when you fill out a form on the website so that you do not have to repeat the entry when you access another subpage. Cookies may also be used to identify you as a registered user after you have registered on the website without you having to log in again when you access another subpage.

The most common types of cookies are explained below for your understanding:

2.12.1SESSION COOKIES:

While you are active on a website, a session cookie is temporarily stored in your computer's memory, in which a session identifier is stored, e.g. to prevent you from having to log in again each time you change pages. Session cookies are deleted when you log out or lose their validity as soon as your session has automatically expired.

2.12.2PERMANENT OR PROTOCOL COOKIES:

A persistent or protocol cookie stores a file on your computer for the period of time specified in the expiry date. These cookies allow websites to remember your information and settings on your next visit. This leads to faster and more convenient access, as you do not have to set your language preferences for our portal again, for example. Once the expiry date has passed, the cookie is automatically deleted when you visit the website that generated it.

2.12.3THIRD-PARTY COOKIES:

Third-party cookies originate from providers other than the operator of the website. They can be used, for example, to collect information for advertising, customised content and web statistics.

You can configure your browser so that no cookies are stored on your computer or so that a message always appears when you receive a new cookie. On the following pages you will find explanations of how you can configure the processing of cookies in the most common browsers:

MICROSOFTS WINDOWS INTERNET EXPLORER

MICROSOFTS WINDOWS INTERNET EXPLORER MOBILE

MOZILLA FIREFOX

GOOGLE CHROME FOR DESKTOP

GOOGLE CHROME FOR MOBILE

APPLE SAFARI FOR DESKTOP

APPLE SAFARI FOR MOBILE

If you deactivate cookies, you may not be able to use all the functions of our website.

2.13 TRACKING-TOOLS

2.13.1

FRIENDLY ANALYTICS

We use Friendly Analytics to analyse the use and reach of our website. Friendly Analytics is a service of Friendly GmbH from Switzerland, which enables web tracking without the processing and storage of personal data and without the setting of cookies. Friendly Analytics stores all data collected and processed by us in Switzerland with providers headquartered in Switzerland. Information on the type, scope and purpose of data processing can be found in Friendly Analytics' privacy policy.

2.13.2

RE-TARGETING

Re-targeting technologies may be used on the websites. This involves analysing your user behaviour on our websites in order to be able to offer you individually tailored advertising on partner websites. Your user behaviour is recorded pseudonymously. Most re-targeting technologies work with cookies. You can prevent re-targeting at any time by rejecting or switching off the relevant cookies in the menu bar of your web browser.

2.13.3

GOOGLE ANALYTICS 4

We use Google Analytics 4 to evaluate the use and reach of our website. Google Analytics 4 is a web analysis service provided by Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland (‘Google’). This service processes data on the basis of your consent in accordance with Art. 6 (1) point a GDPR. Google Analytics 4 will not be used during your visit to our website without your consent. If you wish to withdraw your consent, you can opt out of this service with effect for the future via the ‘Manage Cookies’ button on the bottom left of the browser window on our website.

To enable analysis of the website, Google uses technologies such as cookies or device fingerprinting. The information obtained includes data such as IP addresses, location information, device information and user behavior on our website (such as clicks, page views or session duration). Please note that Google Analytics 4 anonymises users' IP addresses by default.

This means that the corresponding IP addresses within the member states of the European Union or in other states that are party to the Agreement on the European Economic Area are shortened (i.e. anonymised) before they are stored on or transmitted to Google's servers in the United States.

Only in exceptional cases will full IP addresses be transferred and shortened in the USA. The Swiss-U.S. Data Privacy Framework and the EU-U.S. Data Privacy Framework ensure an adequate level of data protection.

Google processes your data on our behalf in order to analyse your use of our website, to compile reports on your activities and user behaviour and to provide further services related to your use. Your abbreviated IP address that is transmitted to Google is not merged with other data and services from Google.

Google Analytics 4 also offers the ‘demographic characteristics’ function. This is used to compilestatistics including information about the age, gender and interests of

visitors to our website, with information about interest-based advertising and additional data from third-party providers. This serves to optimise target groups by distinguishing between user groups on the website and enables us to improve our marketing measures. This function does not allow any assignment to individuals, including you.

We also use Google Signals service in connection with Google Analytics 4. This service also allows the above-mentioned reports to be created across devices (‘cross-device tracking’). This feature is enabled if you have activated ‘personalized ads’ in your device settings for the Google account and linked your devices to your Google account. For more information on using a Google account, click on this link: https://policies.google.com/technologies/partner-sites?hl=en-GB. This service will also be activeted if you have given your consent in addition to the activated settings and links. Without this, Google Signals will not be activated during your visit to our website. We only receive statistics from this service that are generated based on processed data and no personal data from Google. You can find out how to disable cross-device analysis by Google Signals here:https://support.google.com/My-AdCenter-Help/answer/12155764?hl=en-GB&visit_id=6386406227615627522836788885&rd=1&sjid=5759109998233134905-EU

You can find more information about Google Signals here: https://support.google.com/analytics/answer/9445345?sjid=13642400169738779467EU&hl=en#zippy=%2Cthemen-in-diesem-artikel%2Cin-this-articleFurther information: Google's privacy policy: https://policies.google.com/privacy?hl=en&gl=en

2.13.4

GOOGLE MARKETING PLATFORM

We may use Google's marketing platform to display adverts based on the use of previously visited websites. Google uses the so-called DoubleClick cookie for this purpose, which enables your browser to be recognised when you visit other websites. The information generated by the cookie about your visit to our website (including your IP address) will be transmitted to and stored by Google on servers in the United States.

Google will use this information to analyse your use of the website with regard to the advertisements to be placed, to compile reports on website activities and advertisements for the website operators and to provide further services associated with website and Internet use. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google's behalf. However, Google will not associate your IP address with any other data held by Google.

2.13.5

FACEBOOK PIXEL

Based on your consent, we use so-called "Facebook pixels" Facebook Pixel is a service of Facebook Inc, 1601 S California Ave, Palo Alto, CA 94304, USA or, if you are resident in the EU, Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

With the help of the Facebook pixel, the behaviour of site visitors can be tracked after they have been redirected to our website by clicking on a Facebook ad. This allows

the effectiveness of Facebook ads to be evaluated for statistical and market research purposes and future advertising measures to be optimised.

The data collected in this way is anonymous to us, so it does not allow us to draw any conclusions about your identity. However, the data is stored and processed by Facebook so that a connection to the respective user profile is possible and Facebook can use the data for its own advertising purposes in accordance with the Facebook Data Policy [Facebook]. This enables Facebook to place adverts on Facebook pages and outside of Facebook. We cannot influence this use of the data.

Through the use of cookies, i.e., text files that are stored on your end device, Facebook can subsequently recognise you in the Facebook member area and optimise the efficiency of advertisements, e.g. offer target group-oriented advertisements, in accordance with Facebook's data usage policy.

You can revoke the collection by the Facebook pixel and use of your data to display Facebook ads. To do this, you can go to the page set up by Facebook and follow the instructions on the settings for usage-based advertising. You must be logged in to Facebook to do this. If you do not have a Facebook account, you can also object to the use of cookies for reach measurement and advertising purposes via the deactivation page of the network advertising initiative (http://optout.networkadvertising.org/) and also the US website (http://www.aboutads.info/choices) or the European website (http://www.youronlinechoices.com/uk/your-ad-choices/).

General information on the use of data by Facebook, your rights in this regard and options for protecting your privacy can be found in Facebook's data policy at https://www.facebook.com/policy. Specific information and details about the Facebook pixel and how it works can be found in the Facebook help section.

2.14 LINKS ON OUR SOCIAL MEDIA PRESENCES

We have included links to our social media profiles on our websites. The links may lead to the following networks:

Facebook Inc, 1601 S California Ave, Palo Alto, CA 94304, USA, Twitter Inc, 1355 Market Street, Suite 900, San Francisco, CA 94103, USA, Instagram Inc, 1601 Willow Road, Meno Park, CA 94025, USA, YouTube, a service operated by Google Inc, Tripadvisor Inc, 400 1st Avenue, Needham, 02494 MA, USA, Pinterest Inc, 635 High Street, Palo Alto, CA, 94301, USA, LinkedIn Irleand Unlimited Company, Dublin 2, Ireland, Xing SE, Dammtorstrasse 30, 20354 Hamburg, Germany

Kununu GmbH, Neutorgasse 4-8, A - 1010 Vienna

If you click on the relevant social network icons, you will be automatically redirected to our profiles on the relevant networks. In order to use the functions of the relevant

network there, you must log into your user account in some cases. When you click on a link to one of our social media profiles, a direct connection is established between your browser and the server of the relevant social network. This provides the network with the information that you are visiting our websites with your IP address and have accessed the link. If you access a link to a network while you are logged into your account with the network in question, the content of our site may be linked to your profile on the network, which means that the network can directly associate your visit to our website with your user account. If you wish to prevent this, you should log out before clicking on the corresponding links. An assignment will take place in any case if you log in to the relevant network after clicking on the link.

3 DATA PROCESSING IN CONNECTION WITH YOUR STAY

3.1 DATA PROCESSING FOR THE FULFILMENT OF LEGAL REPORTING OBLIGATIONS

On arrival at our hotels, we require the following information from you and your travelling companions:

• First name and surname

• Gender

• Postal address and canton

• Date of birth

• Nationality

• Official identification card and number

• Arrival and departure day

• Number of persons, including children

Insofar as this information is required to fulfil legal reporting obligations, which arise in particular from hospitality or police law, we are obligated to collect it. If we are obligated to do so under the applicable regulations, we will forward this information to the competent police authority.

Entering further details is optional. We only use this data to personalise your stay in the best possible way.

3.2 DATA PROCESSING FOR THE PROVISION OF BOOKED SERVICES IN GENERAL

On arrival at our hotels, we require the following information from you and your travelling companions:

• First name and surname

• Postal address and canton

• Date of birth

• Nationality

• Official identification card and number

• Arrival and departure day

• Room number, room type

• Telephone number

• E-mail

• Comment (background note)

We collect this information to fulfil our contractual and post-contractual obligations towards you.

The processing of this data is necessary for the fulfilment of the contract with us. For further data processing, it is in our legitimate interest in the provision of the service and/or in the consent you have given.

3.3 DATA PROCESSING FOR THE PROVISION OF SPAAND WELLNESS SERVICES

If you receive services from our spa and wellness area as part of your stay in our hotels, we will record and process the subject of the service (e.g. single entry) and the time of the service purchase for billing purposes and to provide the booked service. As a rule, we require the following information for this purpose:

• First name and surname

• Postal address

• E-mail address

• Telephone number

• Room number at the Bürgenstock Resort (if available)

You also have the option of joining our Member's Alpine Spa Club. In order to process your membership enquiry and, in particular, to contact you, we require the following information:

• First name and surname

• E-mail address

• Telephone number

The processing of this data is necessary for the fulfilment of the contract with us. For further data processing, it is in our legitimate interest in the provision of the service and/or in the consent you have given.

3.4 DATA PROCESSING FOR THE PROVISION OF LEISURE SERVICES AND BOOKED ACTIVITIES

If you purchase leisure services or book activities as part of your stay in our hotels, we will record and process the type of the service (e.g. fitness analysis or cinema visit) and the time of the service purchase for billing purposes and to provide the booked service. As a rule, we require the following information for this purpose:

• Salutation

• First name and surname

• Telephone number

• Room number at the Bürgenstock Resort (if available)

• Language

• Contact person

The processing of this data is necessary for the fulfilment of the contract with us. For further data processing, it is in our legitimate interest in the provision of the service and/or in the consent you have given.

3.5 DATA PROCESSING FOR THE PROVISION OF MEDICAL SERVICES

If you receive medical services during your stay in our hotels, we will record and process the subject matter of the service (e.g. diagnostics, therapy) and the time at which the service is received for billing purposes and to provide the booked service and prepare the treatment plans. As a rule, we require the following information for this purpose:

• Salutation

• Name

• First name

• Gender

• Date of birth

• Nationality

• Complete address (incl. street, postcode, town/city, country/canton)

• E-mail

• Contact person

• Referring doctor / family doctor First and last name

• Information on health status

• Room number at the resort (if available)

• For patients/guests from Switzerland:

• Additionally the insurance incl. policy, VEKA and AHV no.

• Can be filled in optionally:

• Telephone

• Marital status

• Denomination

• Language

The processing of this data is necessary for the fulfilment of the contract with us. Further data processing is in our legitimate interest and is based on your consent.

3.6 DATA PROCESSING IN THE CONTEXT OF SURVEYS

If you take part in surveys (on site or online) to evaluate your stay in our hotel, the following personal data will generally be processed:

• First name and surname

• Postal address

• E-mail address

• Telephone number

• Room number at the Bürgenstock Resort (if available)

Processing this data enables us to improve our services and customer relationships. For this purpose, we use the software from Qualtrics, 250 N University Pkwy, 48-C, Provo, Utah 84604, USA. Information on data protection at Qualtrics can be found at HTTPS://WWW.QUALTRICS.COM/PRIVACY-STATEMENT/.

We also use Revinate, Revinate, Inc, One Letterman Drive, Bldg. C, Suite CM100, San Francisco, CA 94129, United States. Information on data protection at Revinate can be found at: https://www.revinate.com/

The legal basis for data processing lies in the consent you have given.

The personal data processed as part of the customer survey is stored in pseudonymised form for five years after completion of the customer survey and then deleted.

3.7 SAFETY

For the protection and safety of guests, employees, visitors, our hotels, railway and Hammetschwand lift and assets entrusted to us and to safeguard domiciliary rights, we use surveillance systems (e.g. security cameras) that can capture and record

images (precautionary and to preserve evidence and clarify incidents). Surveillance systems are signposted at the relevant locations.

The person responsible for the monitoring systems is the respective operator of the hotel or the railway and the Hammetschwand lift (see section 1).

3.8 DATA PROCESSING FOR THE PROVISION OF OTHER SERVICES

If you use other services in our hotels during your stay (e.g. from the mini-bar or the Wi-Fi), we will record the subject matter of the service and the time of use for billing purposes. The processing of this data is necessary to fulfil the contract with us.

4 EXPRESSION OF INTEREST IN BUYING A BÜRGENSTOCK RESIDENCE AND/OR LAKEVIEW VILLA

4.1 EXPRESSION OF INTEREST

If you are interested in our Bürgenstock Residences and/or Lakeview Villas, you can express your interest in conversation with us, by telephone, via e-mail, via the link we have sent you or via the website. The purpose of this is to let us know your preferences regarding the property you are looking for.

We collect the following personal data for this purpose:

• Details of the property

• Interest (purchase, rent)

• Salutation

• First name and surname

• Company

• Postal address

• Nationality

• Telephone number

• E-mail address

• Type of contact desired (e-mail, telephone)

If you express your interest on our website, the following data will also be stored at the time the message is sent:

• IP address

• Date and time of the submission process of the page on which the form was completed.

We use this data exclusively to provide you with the services you have requested, customised advice regarding the purchase of a Bürgenstock Residence and/or Lakeview Villa and the resort offers available on site. The legal basis for processing the data is consent and our legitimate interests.

In addition, the establishment of contact is aimed at the conclusion of a contract and therefore data processing is also necessary for the purpose of implementing precontractual measures and for the fulfilment and execution of the contract.

You can revoke your consent or object to the processing of your personal data at any time. In the event of revocation or objection, your data will be deleted immediately, unless statutory provisions only provide for the blocking of the data.

4.2 CUSTOMER NEEDS ANALYSIS

If you are interested in our Bürgenstock Residences and/or Lakeview Villas, we will contact you and have a personal discussion with you to analyse your requirements.

For this purpose, we collect the following categories of personal data in addition to the above-mentioned data:

• Personal data (language, nationality, employer, pets, hobbies (if relevant), health data, intolerances, etc.)

• Living requirements (area (m2), number of rooms, view, location (in the resort), outdoor area, furnishings, parking spaces, etc.)

• Financial motives (e.g. advice on financing, taxes and legal issues);

• Asking price;

• Special categories of data / particularly sensitive data, e.g. health data in the context of a consultation on local medical services.

You can decide which personal data you make available. The provision of this personal data is voluntary. We only collect the personal data that you disclose to us. Consequently, you are responsible for the content of your message, and it is up to you to decide what information you send us.

The personal data collected during the analysis is used exclusively for personal information regarding suitable property offers.

If there are any property offers matching your search criteria, we can inform you by email, post or telephone.

The legal basis for processing the data is consent and our legitimate interests.

In addition, the needs analysis is aimed at the conclusion of a contract and therefore data processing is also necessary for the purpose of implementing pre-contractual measures and for the fulfilment and execution of the contract.

You can revoke your consent to the processing of personal data at any time. You can also object to the processing of personal data at any time. In the event of revocation

or objection, your data will be deleted immediately, unless statutory provisions only provide for the blocking of the data.

4.3 FORWARDING TO THIRD PARTIES

The personal data collected from you will be shared with Bader Immobilien Luzern AG.

The legal basis for disclosure to Bader Immobilien Luzern AG is consent.

Your personal data will not be passed on beyond this.

5 STORAGE AND EXCHANGE OF DATA WITH THIRD PARTIES

5.1 CENTRALISED STORAGE AND LINKING OF DATA

The personal data collected from you is stored centrally in our CRM system. We process the data in the central CRM system to manage the customer relationship and for advertising purposes, in particular to be able to offer you personalised services and products.

The legal basis for data processing in the context of customer management is the fulfilment of the contract. With regard to data processing in the context of advertising activities, the legal basis also lies in the fulfilment of the contract (the existing customer relationship justifies data processing for the purpose of advertising activities) and in the consent you have given.

5.2 STORAGE PERIOD

We only store personal data for as long as is necessary to use the above-mentioned tracking services and other processing within the scope of our legitimate interest. We store contractual data for longer, as this is required by statutory retention obligations. Retention obligations that oblige us to retain data result from regulations on reporting law, accounting and tax law. According to these regulations, business communications, concluded contracts and accounting documents must be stored for up to 10 years.

5.3 DISCLOSURE OF DATA TO THIRD PARTIES

We only pass on your personal data if you have expressly consented to this, if there is a legal obligation to do so or if this is necessary to enforce our rights, in particular to enforce claims arising from the contractual relationship. In addition, we pass on your data to third parties if this is necessary or expedient in the context of using the website and processing the contract (including outside the website), in particular processing your bookings, e.g. when purchasing vouchers.

We disclose your personal data to the following categories of recipients:

• Group companies

• IT service provider

• Third parties to whom we have outsourced services such as sending newsletters, translation work or document checks

• Third parties that we engage to provide other services that we provide to our guests,

• Third parties involved in the implementation or organisation of events and seminars

• Consultants, trust companies, law firms

• Authorities and courts, if applicable

If the level of data protection in a country in which the data is processed does not correspond to the applicable data protection provisions, we contractually ensure that the protection of your personal data corresponds to that in Switzerland or the EU/EEA at all times. Finally, we forward your credit card information to your credit card issuer and the credit card acquirer when you pay by credit card on the website. If you decide to pay by credit card, you will be asked to enter all mandatory information. The legal basis for passing on the data is the fulfilment of a contract. With regard to the processing of your credit card information by these third parties, we ask you to also read the General Terms and Conditions and the Privacy Policy of your credit card issuer.

When passing on personal data to third parties, the legal regulations on passing on personal data to third parties are of course complied with. If we use processors to provide our services, we take suitable legal precautions and appropriate technical and organisational measures to ensure that your personal data is protected in accordance with the relevant statutory provisions.

5.4 COLLECTION OF DATA VIA BOOKING PLATFORMS

If you make bookings via a third-party platform, we will receive the booking information from the respective platform operator. In addition, we may receive enquiries about your booking. We will process this data by name in order to record your booking as requested and provide the booked services. The legal basis for data processing for this purpose is the fulfilment of a contract.

Finally, we may be informed by the platform operators about disputes in connection with a booking. We may also receive data on the booking process, which may include a copy of the booking confirmation as proof of the actual completion of the booking. We process this data to safeguard and enforce our claims. This is our legitimate interest.

Please also note the data protection information of the respective provider.

5.5 TRANSFER OF PERSONAL DATAABROAD

If we also transfer your personal data to third parties abroad (i.e. outside Switzerland), they are obligated to comply with data protection to the same extent as

we are. If the level of data protection in the country concerned is not adequate, we will ensure that your personal data is protected to such a level.

We ensure this in particular by concluding so-called standard contractual clauses of the EU Commission with the companies concerned and/or by the existence of further guarantees that comply with the applicable law. Where this is not possible, we base the transfer of data on your express consent or the necessity of the transfer for the fulfilment of the contract.

6 FURTHER INFORMATION

6.1 RIGHT OF ACCESS, RECTIFICATION, ERASURE AND RESTRICTION OF PROCESSING; RIGHT TO DATA PORTABILITY, RIGHT TO WITHDRAW CONSENT AND RIGHT TO OBJECT TO THE USE OF DATA

You have certain rights in connection with our data processing. In accordance with applicable law, you may in particular request information about the processing of your personal data, have incorrect personal data corrected, request the erasure of personal data, object to data processing, request the disclosure of certain personal data in a commonly used electronic format or its transfer to other controllers or withdraw your consent with effect for the future, provided that our processing is based on your consent.

If you wish to exercise your rights us, please contact us at data-privacy@burgenstockresort.com

We must identify you (e.g. with a copy of your ID, if necessary) so that we can rule out misuse

6.2 DATA SECURITY

We use suitable technical and organisational security measures to protect your personal data stored by us against manipulation, partial or complete loss and against unauthorised access by third parties. Our security measures are continuously improved in line with technological developments.

You should always treat your access data confidentially and close the browser window when you have finished communicating with us, especially if you share the computer with others.

We also take data protection within the company very seriously. Our employees and the service companies commissioned by us are obligated to maintain confidentiality and to comply with data protection regulations.

6.3 RIGHT TO LODGE A COMPLAINT WITH A DATA PROTECTION SUPERVISORY AUTHORITY

You have the right to lodge a complaint with a data protection supervisory authority at any time. In Switzerland, this is the Federal Data Protection and Information Commissioner.

Date: 28 11.2024

Turn static files into dynamic content formats.

Create a flipbook
Issuu converts static files into: digital portfolios, online yearbooks, online catalogs, digital photo albums and more. Sign up and create your flipbook.