Privacy Policy

Here you can find the current Privacy Policy of NIGHT INN Hotel.
We process your personal data exclusively in accordance with the provisions of the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act 2018. Note: For easier readability, the term “data” is generally used, although personal data is meant. Legal provisions without specific reference relate exclusively to those of the GDPR, unless stated otherwise. Below we inform you, in accordance with the GDPR, about the nature, scope, purpose and use of data collection:

Preamble

With the following privacy policy we would like to inform you about the types of personal data (hereinafter also briefly referred to as “data”) we process, for which purposes and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as the “online offering”).

The terms used are not gender-specific.

Last updated: April 17, 2023 

Table of contents

  • Preamble
  • Data controller
  • Overview of processing activities
  • Applicable legal bases
  • Security measures
  • Disclosure of personal data
  • Data processing in third countries
  • Deletion of data
  • Use of cookies
  • Provision of the online offering and web hosting
  • Contact and request management
  • Web analysis, monitoring and optimization
  • Online marketing
  • Customer reviews and rating procedures
  • Social media presences
  • Plugins and embedded functions and content
  • Changes and updates to the privacy policy
  • Rights of data subjects

Data controller

NIH Feldkirch GmbH & Co KG
Jahnplatz 8
6800 Feldkirch

E-mail: hi@night-inn.com

Overview of processing activities

The following overview summarizes the types of data processed and the purposes of processing and refers to the categories of data subjects.

Types of data processed

  • Master data
  • Location data
  • Contact data
  • Content data
  • Contract data
  • Usage data
  • Meta, communication and procedural data
  • Event data (Facebook)

Categories of data subjects

  • Customers
  • Enquirers / Prospective customers
  • Communication partners
  • Users

Purposes of processing

  • Contact requests and communication
  • Security measures
  • Reach measurement
  • Tracking
  • Conversion measurement
  • Audience building
  • Management and response to enquiries
  • Feedback
  • Marketing
  • Profiles with user-related information
  • Provision of our online offering and user-friendliness
  • IT infrastructure

Applicable legal bases

Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the GDPR, national data protection provisions in your and our country of residence may apply. If more specific legal bases apply in individual cases, we will point this out in this privacy policy.

  • Consent (Art. 6(1)(1)(a) GDPR) – The data subject has given consent to the processing of his or her personal data for one or more specific purposes.
  • Performance of a contract and pre-contractual requests (Art. 6(1)(1)(b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is a party or for pre-contractual measures at the data subject’s request.
  • Legitimate interests (Art. 6(1)(1)(f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party, provided that the interests or fundamental rights and freedoms of the data subject which require protection of personal data do not prevail.

In addition to the GDPR, national data protection rules apply in Austria. These include in particular the Austrian Data Protection Act (Datenschutzgesetz – DSG), which contains special provisions on the right of access, the right to rectification or deletion, the processing of special categories of personal data, processing for other purposes and transfers, as well as automated decision-making in individual cases.

Security measures

We implement appropriate technical and organizational measures in accordance with legal requirements, taking into account the state of the art, implementation costs, the nature, scope, circumstances and purposes of the processing as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, in order to ensure a level of protection appropriate to the risk.

These measures include, in particular, ensuring confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as access, entry, transmission, availability backup and separation of the data concerned. We have furthermore established procedures to ensure the exercise of data subject rights, the deletion of data and responses to data breaches. We also take data protection into account when developing or selecting hardware, software and procedures in accordance with the principle of data protection by design and by default.

TLS encryption (https): To protect data transmitted via our online offering, we use TLS encryption. You can recognize such encrypted connections by the prefix https:// in the address line of your browser.

Disclosure of personal data

In the course of our processing of personal data, it may be necessary to disclose data to other bodies, companies, legally independent organizational units or persons or to make them accessible. Recipients of such data can include, for example, service providers entrusted with IT tasks or providers of services and content that are integrated into a website. In such cases we comply with legal requirements and in particular conclude appropriate contracts or agreements to protect your data with the recipients of your data.

Data processing in third countries

If we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)) or if processing takes place in the context of using third-party services or disclosing or transferring data to other persons, entities or companies, this will only be done in accordance with legal requirements.

Except in cases of explicit consent or contractually or legally required transfers, we only process or have data processed in third countries with an adequate level of data protection, by contractual obligations through so-called Standard Contractual Clauses of the European Commission, where certifications exist, or by binding corporate rules (Art. 44–49 GDPR). For more information see the European Commission’s guidance: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_de.

Deletion of data

The data we process will be deleted in accordance with statutory requirements as soon as the permissions for processing granted are revoked or other permissions cease to apply (e.g., when the purpose of processing no longer applies or the data are no longer required for the purpose). If data are not deleted because they are required for other legally permissible purposes, their processing will be restricted to those purposes. In other words, the data will be blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons or whose storage is necessary for asserting, exercising or defending legal claims or for the protection of the rights of another natural or legal person.

Our privacy notices may contain further information about storage periods and deletion of data which apply primarily to the respective processing operations.

Use of cookies

Cookies are small text files or other storage markers that store information on end devices and read information from end devices, e.g., to store login status in a user account, shopping cart contents in an online shop, visited content or used functions of an online offering. Cookies can also be used for different purposes, such as to ensure the functionality, security and comfort of online offerings and to create analyses of visitor flows.

Notes on consent: We use cookies in accordance with legal requirements. Therefore, we obtain prior consent from users unless this is not legally required. Consent is not required, in particular, if the storage and reading of the information, including cookies, is absolutely necessary to provide a telemedia service explicitly requested by the user (i.e., our online offering). Essential cookies usually include functions necessary for the display and operation of the online offering, load balancing, security, saving user preferences and selection options, or similar purposes related to providing the main and ancillary functions of the online offering requested by users. The revocable consent is communicated clearly to users and contains information on the specific cookie usage.

Notes on legal bases: The legal basis on which we process users’ personal data by means of cookies depends on whether we ask users for consent. If users consent, the processing is based on that consent. Otherwise, data processed via cookies are processed on the basis of our legitimate interests (e.g., in the economic operation of our online offering and improving its usability) or, if cookie use is required to fulfill our contractual obligations, on the basis of contract performance. The purposes for which we process cookies are explained in this privacy policy or in the consent and processing flows.

Storage duration: With regard to storage duration, the following types of cookies are distinguished:

  • Temporary cookies (session cookies): Temporary cookies are deleted at the latest when a user leaves an online offering and closes his or her device (e.g., browser or mobile application).
  • Persistent cookies: Persistent cookies remain stored after closing the device. For example, login status can be saved or preferred content can be displayed directly when a user revisits a website. Data collected via cookies can also be used for reach measurement. Unless we provide users with explicit information about the type and retention period of cookies (e.g., when obtaining consent), users should assume that cookies are persistent and may be stored for up to two years.

General notes on revocation and objection (opt-out): Users may revoke consents they have given at any time and may also object to processing pursuant to the statutory provisions in Art. 21 GDPR. Users may also express their objection via their browser settings, e.g., by disabling the use of cookies (this may restrict the functionality of our online services). Objections to cookies used for online marketing purposes can also be made via https://optout.aboutads.info and https://www.youronlinechoices.com/.

  • Legal bases: Consent (Art. 6(1)(1)(a) GDPR).

Further notes on processing procedures, tools and services:

  • Processing of cookie data based on consent: We use a cookie consent management system that obtains and manages users’ consent to the use of cookies and the processing operations and providers named in the consent management procedure. The consent statement is stored so that it does not have to be requested again and to be able to demonstrate consent as required by law. Storage may take place server-side and/or in a cookie (so-called opt-in cookie) or similar technologies to assign consent to a user or their device. Unless individual providers of cookie management services indicate otherwise, the storage duration of consent can be up to two years. A pseudonymous user identifier is created and stored together with the time of consent, details of the scope of consent (e.g., which categories of cookies and/or providers) as well as browser, system and device used; Legal basis: Consent (Art. 6(1)(1)(a) GDPR).
  • BorlabsCookie: Cookie consent management; Provider: Hosted locally on our server, no data transfer to third parties; Website: https://de.borlabs.io/borlabs-cookie/. Further information: An individual user ID, language and types of consent and the time of consent are stored server-side and in the cookie on the user’s device.

Provision of the online offering and web hosting

We process users’ data in order to provide our online services. For this purpose we process the user’s IP address, which is necessary in order to transmit the contents and functions of our online services to the browser or device of the users.

  • Processed types of data: Usage data (e.g., visited webpages, interest in content, access times); meta, communication and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Provision of our online offering and usability; IT infrastructure (operation and provision of information systems and technical devices such as computers, servers etc.); security measures.
  • Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).

Further notes on processing procedures, tools and services:

  • Provision of the online offering on rented storage space: For providing our online offering we use storage space, computing capacity and software that we rent or otherwise obtain from a server provider (webhost); Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).
  • Collection of access data and log files: No log files are stored.
  • DomainFactory: Services in the field of providing IT infrastructure and related services (e.g., storage and/or computing capacities); Provider: Domainfactory GmbH, c/o WeWork, Neuturmstrasse 5, 80331 Munich, Germany; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://www.df.eu; Privacy policy: https://www.df.eu/de/datenschutz; Data processing agreement: https://www.df.eu/de/support/formulare/.

Contact and request management

When contacting us (e.g., by post, contact form, e-mail, telephone or via social media) and in the context of existing user and business relationships, the information of the enquiring persons is processed to the extent necessary to answer contact requests and any requested measures.

  • Processed types of data: Contact data (e.g., e-mail, telephone numbers); content data (e.g., entries in online forms); usage data (e.g., visited webpages, interest in content, access times); meta, communication and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
  • Data subjects: Communication partners.
  • Purposes of processing: Contact requests and communication; management and response to enquiries; feedback (e.g., collecting feedback via online form); provision of our online offering and usability.
  • Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR).

Further notes on processing procedures, tools and services:

  • Contact form: If users contact us via our contact form, e-mail or other communication channels, we process the data provided for handling the matter; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR), Legitimate interests (Art. 6(1)(1)(f) GDPR).

Web analysis, monitoring and optimization

Web analysis (also called reach measurement) is used to evaluate visitor flows of our online offering and can include behavioural, interest or demographic information about visitors, such as age or gender, in pseudonymous form. With reach analysis we can, for example, determine at what times our online offering, its functions or contents are most frequently used and where optimization is required.

In addition to web analysis, we may use testing procedures to test and optimize different versions of our online offering or its components.

Unless otherwise stated below, profiles (i.e., data aggregated for a specific usage) may be created and information may be stored in and read from a browser or device for these purposes. Collected information includes visited pages and used elements as well as technical data such as the browser used, the operating system and usage times. Where users have consented to the collection of their location data with the providers of the services we use, location data may also be processed.

IP addresses of users are also stored. For protection of users we use an IP masking procedure (i.e., pseudonymization by shortening the IP address). In general, no clear personal data (e.g., e-mail addresses or names) is stored for web analysis, A/B testing and optimization; pseudonyms are used. Thus, neither we nor the providers of the software used know the actual identity of the users, but only the information stored in profiles for the purposes of the respective procedures.

  • Processed types of data: Usage data; meta, communication and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
  • Data subjects: Users (e.g., website visitors).
  • Purposes of processing: Reach measurement (e.g., access statistics, identification of returning visitors); profiles with user-related information (creation of user profiles).
  • Security measures: IP masking (pseudonymization of the IP address).
  • Legal bases: Consent (Art. 6(1)(1)(a) GDPR).

Further notes on processing procedures, tools and services:

Matomo: Matomo is software used for web analysis and reach measurement. When subpages of our website are accessed, the following data are stored:

  • the user’s IP address in anonymised form
  • the subpage accessed and the time of access
  • the page from which the user reached our website (referrer)
  • which browser with which plugins, which operating system and which screen resolution is used
  • the length of time spent on the website
  • the pages that are accessed from the visited page

When Matomo is used, cookies are created and stored on the user’s device. No user profiles are created. Data collected via Matomo are stored within the EU. Except for the service provider (see below), no data are transferred to third parties. The cookies are stored for a maximum period of 365 days: https://matomo.org/faq/general/faq_146/; Legal basis: Consent (Art. 6(1)(1)(a) GDPR); Data retention: Cookies have a retention period of 365 days; Service provider: popup communications gmbh, Werdenbergerstr. 39a, 6700 Bludenz, Austria; Website: https://www.popup.at; Privacy policy: https://www.popup.at/datenschutzerklaerung/.

Online marketing

We process personal data for online marketing purposes, in particular to market advertising space or to display advertising and other content (collectively “content”) according to users’ presumed interests and to measure their effectiveness.

For these purposes, so-called user profiles may be created and stored in a file (a “cookie”) or similar procedures may be used to save information relevant for the representation of the aforementioned content. Such information may include viewed content, visited websites, used online networks, but also communication partners and technical data such as the browser used, the operating system, usage times and used functions. If users have consented to the collection of their location data, such data may also be processed.

IP addresses are also stored. We use IP-masking procedures (pseudonymization by shortening the IP address) to protect users. In general, no clear personal data (such as e-mail addresses or names) are stored in the course of online marketing procedures, but pseudonyms. This means that neither we nor the providers of the online marketing procedures know the actual identity of the users, but only the information stored in their profiles.

The data stored in profiles are usually saved in cookies or by similar procedures. These cookies can later be read on other websites that use the same online marketing procedure and can be analyzed for content display and supplemented with additional data on the provider’s server.

In exceptional cases, clear personal data may be assigned to profiles. This is the case, for example, when users are members of a social network whose online marketing procedures we use and when the network links the users’ profiles with the mentioned data. Please note that users may enter into additional agreements with the providers, e.g., by consent during registration.

We generally only obtain aggregated information on the success of our advertisements. However, in conversion measurements we can check which of our online marketing procedures led to a conversion, i.e., e.g., to a contract conclusion with us. Conversion measurement is used solely for analysing the effectiveness of our marketing measures.

Unless otherwise stated, please assume that cookies used for online marketing are stored for a period of two years.

  • Processed types of data: Usage data; meta, communication and procedural data; event data (Facebook) (event data are data that, e.g., may be transmitted to Facebook via the Facebook pixel and relate to persons or their actions; they include e.g., website visits, interactions with content, app installs, purchases; event data do not include content such as comments, login data or contact information);
  • Data subjects: Users (e.g., website visitors).
  • Purposes of processing: Reach measurement; tracking (interest/behavioural profiling); marketing; creation of user profiles; conversion measurement; audience building; provision of our online offering and usability.
  • Security measures: IP-masking (pseudonymization of IP addresses).
  • Legal bases: Consent (Art. 6(1)(1)(a) GDPR); Legitimate interests (Art. 6(1)(1)(f) GDPR).
  • Opt-out: We refer to the privacy information of the respective providers and the opt-out options they provide. If no explicit opt-out is provided, you can disable cookies in your browser settings; this may restrict functionality. We furthermore recommend the following opt-out choices: a) Europe: https://www.youronlinechoices.eu; b) Canada: https://www.youradchoices.ca/choices; c) USA: https://www.aboutads.info/choices; d) Global: https://optout.aboutads.info.

Further notes on processing procedures, tools and services:

  • Facebook ads: Placement of ads within the Facebook platform and evaluation of ad performance; Provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/about/privacy; Opt-out: See Facebook’s advertising and privacy settings; Further information: Event data are processed for targeted advertising and audience building based on the addendum on joint controllership: https://www.facebook.com/legal/controller_addendum. The joint controllership is limited to the collection and transmission of data to Meta Platforms Ireland Limited. Further processing, including transfer to Meta Platforms, Inc. in the USA, is the sole responsibility of Meta Platforms Ireland Limited, based on Standard Contractual Clauses between Meta Platforms Ireland Limited and Meta Platforms, Inc.
  • Google Ads and conversion measurement: Online marketing for placing ads in the provider’s ad network and measuring conversions. We receive only anonymized information and no personal information about individual users; Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1)(1)(a) GDPR), Legitimate interests (Art. 6(1)(1)(f) GDPR); Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Further info: https://privacy.google.com/businesses/adsservices; Data processing terms and standard contractual clauses: https://business.safety.google/adscontrollerterms.
  • Instagram ads: Placement of ads on Instagram and evaluation of ad performance; Provider: Meta Platforms Ireland Limited; Legal basis: Consent (Art. 6(1)(1)(a) GDPR); Website: https://www.instagram.com; Privacy policy: https://instagram.com/about/legal/privacy; Opt-out: Instagram/Facebook ad settings and consent flows.
  • 360ty.world Virtual Tour: The 360ty.world plugin enables an interactive virtual tour with 360° photos of our restaurant and is integrated into our website for this purpose. The provider collects device data (device type, browser, operating system, etc.) and session data (e.g., dwell time). A cookie is used which is deleted automatically after 2 years.

    To optimize loading times, Cloudflare (https://www.cloudflare.com) is used as a caching provider and CDN. This provider processes IP addresses and device information. Data processing takes place in the USA. Information on Cloudflare’s GDPR compliance can be found here: https://www.cloudflare.com/de-de/trust-hub/gdpr/

    The actual hosting of content is provided by Google Cloud. Data are also processed in the USA. More information on data processing can be found here: https://cloud.google.com/privacy/gdpr?hl=de

    Google Analytics 4 is used for analysing access figures and user behaviour (with IP anonymisation). Data processing takes place in the USA. More information: https://support.google.com/analytics/answer/12017362?hl=de

    Legal basis: Consent (Art. 6(1)(1)(a) GDPR); Service provider: MULTIMEDIAFABRIK GmbH, Schweizerstraße 17a, 6844 Altach, Austria; Website: https://360ty.world/; Privacy policy: https://360ty.world/datenschutz/.

Customer reviews and rating procedures

We participate in review and rating procedures to evaluate, optimise and promote our services. When users rate us via participating review platforms or procedures or otherwise give feedback, the terms and privacy notices of the providers apply. In general, providing a review requires registration with the respective providers.

To ensure that reviewers actually used our services, we may — with the customer’s consent — transmit the data required for verification (e.g., name, e-mail address and order number) to the respective review platform. These data are used solely to verify the authenticity of the reviewer.

  • Processed types of data: Contract data; usage data; meta, communication and procedural data; master data (e.g., names, addresses); contact data (e