Privacy · Luxalps
Home/Privacy Policy

Privacy Policy

Protecting your personal data matters to us. In line with Articles 13 and 14 of the General Data Protection Regulation (GDPR), the following sections explain which data we process when you use this website and our services, for what purpose, on what legal basis, how long we store it and what rights you have.

Version of July 2026 · This is a translation of the German original. In case of discrepancies, the German version prevails.

1. Controller

The controller within the meaning of Art. 4(7) GDPR is:

Luxalps GmbH
Feldweg 14
A-9562 Himmelberg
Austria

Legal form: limited liability company (Gesellschaft mit beschränkter Haftung)
Company register number: FN 651569 s
Register court: Regional Court of Klagenfurt

Phone: +43 664 3458434
E-mail: info@luxalps.gmbh
Web: www.luxalps.gmbh

You can reach us at any time using the contact details above for questions about data protection or to exercise your rights. We have not appointed a data protection officer, as the conditions of Art. 37 GDPR do not apply.

2. Scope of this policy

This privacy policy applies to the website www.luxalps.gmbh, including all subpages and the English-language version, as well as to the related services – in particular enquiries, bookings, stays in our chalets and the digital ordering area on site.

It does not apply to external websites we merely link to. Their operators are solely responsible for their content and data processing. When you click such a link, you leave our area of responsibility.

We process personal data solely on the basis of statutory provisions. Depending on the processing activity, we rely on:

  • Art. 6(1)(a) GDPR – consent: you have expressly permitted the processing, for example via the cookie notice. Consent can be withdrawn at any time with effect for the future.
  • Art. 6(1)(b) GDPR – contract: processing is necessary to perform a contract (booking, stay, order) or to take pre-contractual steps.
  • Art. 6(1)(c) GDPR – legal obligation: we are required to process data under registration, tax and commercial law.
  • Art. 6(1)(f) GDPR – legitimate interests: processing serves our legitimate interests, such as the secure and reliable operation of this website, where your interests do not override them.

For storing information on your device or accessing it, Section 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021) applies in addition. Under this provision, only information strictly necessary for a service you have expressly requested may be stored or read without your consent.

4. Your rights

You have the following rights regarding your personal data:

  • Access (Art. 15 GDPR) – whether and which data we process about you, for what purpose, for how long, and to whom we disclose it.
  • Rectification (Art. 16 GDPR) – we must correct or complete inaccurate data.
  • Erasure (Art. 17 GDPR) – provided no statutory retention obligation applies.
  • Restriction of processing (Art. 18 GDPR) – for instance while we verify data you have contested.
  • Data portability (Art. 20 GDPR) – receipt of the data you provided in a common, machine-readable format.
  • Objection (Art. 21 GDPR) – against processing based on legitimate interests, on grounds relating to your particular situation.
  • Withdrawal of consent (Art. 7(3) GDPR) – at any time and without giving reasons, with effect for the future. The lawfulness of processing carried out until then remains unaffected.

An informal message to info@luxalps.gmbh is sufficient. We respond free of charge within the statutory period of one month. Where there are reasonable doubts about your identity, we may request additional information.

Right to lodge a complaint

If you believe the processing of your data infringes data protection law, you may lodge a complaint with the supervisory authority, without prejudice to other remedies. In Austria this is:

Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40–42, 1030 Vienna, Austria
Phone: +43 1 52 152-0
E-mail: dsb@dsb.gv.at
Web: www.dsb.gv.at

5. Visiting this website (server log files)

Each time a page is accessed, the web server automatically stores data transmitted by your browser in log files:

  • IP address of the requesting device
  • date and time of access
  • name and URL of the page accessed
  • volume of data transferred and confirmation of whether the request succeeded
  • referrer URL (the previously visited page)
  • browser used, its version and the operating system

Purpose: establishing and maintaining the connection, ensuring system security and stability, analysing technical faults, and detecting and defending against attacks.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the technically sound and secure operation of this website.

Retention: log files are kept for a short period (usually a few days, no longer than 30 days) and then deleted automatically. This data is not merged with other sources, not analysed for marketing purposes and not linked to you personally.

6. Hosting

This website is not hosted on our own servers but with an external provider:

Hostinger International Ltd.
Jonavos g. 60C
44192 Kaunas
Lithuania

Hostinger processes, on our behalf, all data arising when you visit this website – in particular IP addresses, access times, log files and the content and files stored on the server. The provider acts exclusively on our instructions and does not use the data for its own purposes.

We have concluded a data processing agreement pursuant to Art. 28 GDPR with Hostinger, ensuring that your data is processed only for the agreed purposes and in accordance with the GDPR. The provider is established in the European Union; the servers used for this website are located within the EU/EEA.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, fast and professional provision of our online offering) and, where processing serves the initiation or performance of a contract, Art. 6(1)(b) GDPR.

7. Data security

We take technical and organisational measures in line with the state of the art pursuant to Art. 32 GDPR to protect your data against loss, destruction, manipulation and unauthorised access. These include in particular:

  • end-to-end SSL/TLS encryption of all connections to this website. You can recognise it by https:// in the address bar and the padlock symbol in your browser.
  • restricted access to internal areas through personal credentials and protection against request forgery
  • limiting access to personal data to those who need it for their tasks
  • regular updates of the software used and backup of data

Please note that data transmission over the internet – particularly unencrypted e-mail – may have security vulnerabilities. Complete protection against access by third parties is technically not possible.

8. Cookies and local storage

Cookies and comparable techniques are small entries a website stores on your device. They cause no damage and contain no malware. A distinction is made between:

  • Strictly necessary entries – without them the website does not work, or you would have to make a choice again on every visit. They are permitted without consent under Section 165(3) TKG 2021.
  • Non-essential entries – analytics, audience measurement, personalisation, advertising. These may only be set after your explicit consent.

This website uses strictly necessary entries only. We do not use analytics, tracking, advertising or profiling cookies, and no third-party cookies.

Complete overview of the entries used

NameTypePurposeStorage periodCategory
luxalps_cookie_consent Local storage Stores your decision in the cookie notice ("only necessary" or "accept all") so the notice does not reappear on every visit. until you delete it necessary
luxalps_offer_seen Local storage Remembers that a notice about current offers has already been shown so it is not displayed repeatedly. approx. 12 hours necessary
PHPSESSID Session cookie Keeps you signed in during a session. Set only in the password-protected administration area and the guest ordering area, not during a normal visit to the website. until the browser is closed or you log out necessary

No further entries are set. In particular, this overview contains no entries that would allow recognition across multiple websites or the creation of user profiles.

Legal basis

The entries listed are strictly necessary to provide the service you have expressly requested and are therefore permitted without consent under Section 165(3) TKG 2021. The associated processing is based on Art. 6(1)(f) GDPR. Where consent is obtained via the cookie notice, processing is based on Art. 6(1)(a) GDPR.

Changing or withdrawing your choice

You can withdraw consent at any time – just as easily as you gave it. The button below reopens the cookie notice. Under “Show details” you can see every single entry with its purpose and storage period and decide anew. The same link is always available in the footer.

You can also configure your browser to notify you about cookies, allow them only in individual cases, exclude them generally, or delete them automatically when the browser closes. These settings are usually found under "Settings" and then "Privacy and security". Disabling them may limit the functionality of this website.

9. Analytics, tracking and advertising

We consider it important to describe not only what we do, but explicitly also what we do not do.

What does not take place on this website

We currently use no services for analysing your behaviour, measuring reach or advertising purposes. Specifically, the following are not embedded on this website:

  • no web analytics services (no Google Analytics, Google Tag Manager, Matomo, Hotjar, Microsoft Clarity or comparable tools)
  • no advertising or conversion pixels (no Meta/Facebook pixel, no Google Ads conversion tracking, no TikTok pixel, no LinkedIn Insight Tag)
  • no retargeting or remarketing technologies
  • no embedded videos, maps or social media widgets that connect to third parties when a page loads
  • no newsletter distribution and no e-mail advertising via this website
  • no creation of user or interest profiles
  • no disclosure or sale of your data to third parties for advertising purposes
  • no device fingerprinting or comparable recognition techniques

Analysis of how our website is used is limited to the technical server log files (see section 5), which are neither evaluated on a personal level nor combined with other data.

This list reflects the actual technical state of this website. We deliberately keep it specific so that you can understand what happens with your data – and what does not.

If we introduce such services in future

Should we decide to embed analytics, map, video or advertising services, the following binding principles apply to us:

  • We will update this privacy policy beforehand, naming the service, the provider, its location, the data processed, the purpose and the storage period.
  • The service will only be loaded after your explicit consent. Before consent, no connection to the provider is established and no cookie is set.
  • Declining is just as easy as agreeing. Declining causes no disadvantage whatsoever in using this website.
  • You can withdraw your consent at any time with effect for the future.
  • For transfers to third countries we will ensure an appropriate safeguard under Chapter V GDPR.

In these cases the legal basis would be solely your consent under Art. 6(1)(a) GDPR in conjunction with Section 165(3) TKG 2021.

10. Contact by e-mail and phone

We deliberately do not offer a contact form on this website. You can reach us by e-mail, phone or WhatsApp.

When you contact us, we process the details you provide – such as your name, e-mail address, phone number and the content of your enquiry – in order to handle your request and any follow-up questions.

Legal basis: Art. 6(1)(b) GDPR where your enquiry relates to a contract or its initiation; otherwise Art. 6(1)(f) GDPR (legitimate interest in handling enquiries effectively).

Retention: we keep your enquiry until it has been fully dealt with and no further questions are expected. If a contract is concluded, the statutory retention periods apply (see section 21). You may request erasure at any time.

11. Contact via WhatsApp

This website contains buttons allowing you to message us on WhatsApp. These are plain links only – simply visiting our pages transmits no data to WhatsApp and sets no cookie. A connection is established only when you click one of these buttons.

The service is provided by WhatsApp Ireland Limited, Merrion Road, Dublin 4, Ireland (Meta group). If you contact us via WhatsApp, the provider processes both the content of your message and metadata such as your phone number, device information and communication timestamps. We have no influence over this processing, which takes place under the provider's own responsibility. Transfers to third countries, particularly the USA, cannot be ruled out.

We process the content of your WhatsApp message to handle your request on the basis of Art. 6(1)(b) or (f) GDPR. Using it is voluntary and on your own initiative; it also constitutes your consent within the meaning of Art. 6(1)(a) GDPR.

Please do not send us particularly sensitive data within the meaning of Art. 9 GDPR (such as health data) via WhatsApp. If you prefer to avoid this processing, please use e-mail or phone – we are equally available on all channels.

12. Booking and contract handling

For availability enquiries and bookings we redirect you from this website to our booking system, operated at luxalps.gmbh/buchen. You enter your data only there.

In connection with a booking we process in particular:

  • first and last name, address, country
  • e-mail address and phone number
  • arrival and departure dates, chalet booked, number and where applicable names of guests
  • details of additional services and special requests
  • payment and invoicing data

Purpose: checking availability, preparing the offer, concluding and performing the accommodation contract, communication before and during your stay, invoicing, and fulfilling our legal obligations.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract and pre-contractual steps) and Art. 6(1)(c) GDPR for legally required processing.

Providing this data is necessary to conclude the contract. Without it we cannot process a booking.

13. Registration obligations, local tax and guest cards

As an accommodation provider we are subject to statutory registration and record-keeping obligations that we cannot waive.

  • Austria (Turracher Höhe, Carinthia): a guest record must be kept for every guest, covering name, date of birth, nationality, address, travel document details and arrival and departure dates. This is based on registration law (Meldegesetz 1991) and the provincial rules on local tourist tax.
  • Germany (St. Englmar and Inzell, Bavaria): under Sections 29 f. of the Federal Registration Act (BMG), a registration form must be completed and signed by hand. These forms are kept for one year and then destroyed. Registration duties for the local visitor's tax under the applicable municipal statutes apply in addition.
  • Guest cards: if you receive a guest card (for example the Chiemgau-Karte or AktivCard Bayerischer Wald), we transmit the necessary data – name, period of stay and accommodation – to the responsible spa or tourism administration. Issuing the card is linked to the collection of the visitor's tax or local tourist tax.

Legal basis: Art. 6(1)(c) GDPR (compliance with a legal obligation) in conjunction with the applicable registration, tax and tourism provisions.

Recipients: registration authorities, municipalities and spa or tourism administrations, in each case only to the extent required by law.

14. Orders in the chalet (drinks and services)

In our chalets we provide a digital ordering and billing area where you can record drinks and other services and pay for them directly.

The following data is processed:

  • first and last name and billing address
  • e-mail address for delivery of the invoice
  • for business customers, company name and VAT identification number
  • period of stay and chalet concerned
  • items ordered, quantities, prices, tax rates and invoice total
  • payment method chosen and payment status
  • where applicable, a digital signature confirming your order

Purpose: processing your order, issuing an invoice that meets statutory requirements, handling payment, and accounting.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (invoicing and retention obligations, in particular under the Austrian VAT Act, Federal Fiscal Code and Commercial Code).

Invoice delivery: your invoice is sent by e-mail to the address you provide. A copy is sent to us for accounting purposes.

Retention: invoices and related records are kept for seven years due to statutory retention obligations (Section 132 BAO, Section 212 UGB), running from the end of the relevant calendar year.

15. Payment service providers

Several payment options are available. Depending on the method chosen, we pass on the data required for processing to the relevant provider.

Saferpay (card payment)

The provider is Worldline Schweiz GmbH (Saferpay brand), Hardturmstrasse 201, 8005 Zurich, Switzerland.

For card payments you are redirected to a secure Saferpay payment page. You enter your card details there only; we never receive them and do not store them. Only the payment status and a transaction reference are returned to us. The invoice amount, invoice number, currency and your contact and billing details are transmitted.

Following an adequacy decision by the European Commission, Switzerland is deemed to provide an adequate level of data protection, so no additional safeguards are required for the transfer.

PayPal

The provider is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg.

If you pay by PayPal, your payment data is transmitted directly to PayPal. We receive confirmation of payment and the associated transaction number. PayPal also processes your data for its own purposes, in particular fraud prevention; please refer to PayPal's privacy notice for details.

Bank transfer

For bank transfers, your account details are processed by the credit institutions involved as part of the payment process. We process the incoming payment in order to allocate and record it.

The legal basis for all payment methods is Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR for accounting records.

16. Fonts (Google Fonts)

To display fonts consistently, this website embeds Google Fonts. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

The fonts are loaded from Google servers when a page is opened. This establishes a connection to Google and transmits your IP address. Google therefore learns that this website was accessed from your IP address. No cookies are set in the process. We have no influence over any further use of this data.

Processing by Google LLC in the USA cannot be ruled out. The company is certified under the EU-US Data Privacy Framework, so an adequacy decision by the European Commission covers any such transfer.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a consistent and appealing presentation of our online offering). Where consent has been obtained, processing is based solely on Art. 6(1)(a) GDPR and Section 165(3) TKG 2021 and may be withdrawn at any time.

Further information is available in Google's privacy notice at policies.google.com/privacy.

17. QR code generation

In the ordering area of our chalets, QR codes are used to display payment and invoice links. They are generated via an external service (api.qrserver.com). Retrieving the code establishes a connection to the provider's server and transmits your IP address.

The QR code contains only the payment or retrieval link; no personal order details are transmitted. This service is not used on the public website.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in simple, error-free operation) and Art. 6(1)(b) GDPR in the context of payment processing.

18. Social media and external links

This website links to our profiles on Instagram, Facebook, TikTok and YouTube, as well as to partner and tourism websites.

These are plain links, not embedded plugins, widgets or like buttons. Visiting our pages therefore transmits no data to these networks, and no provider cookies are set. A connection to the providers' servers is established only when you deliberately click one of these links.

Once you open one of these platforms, their own privacy policies apply. The controllers are:

  • Instagram and Facebook: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland
  • TikTok: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin 2, Ireland
  • YouTube: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland

If you are logged in to these services, the provider may link your visit to your user account. We have no influence over the nature and scope of this processing. If you wish to avoid it, log out of the relevant services before clicking.

19. Recipients of your data

We disclose your data only where necessary to perform a contract, where we are legally obliged to do so, where a legitimate interest exists, or where you have consented. Recipients may include:

  • our hosting provider (Hostinger International Ltd., Lithuania) as a processor
  • payment service providers and credit institutions for payment processing
  • registration, municipal and tourism authorities in the context of statutory registration duties
  • our tax advisors and accountants
  • service providers for cleaning, maintenance and guest support, where necessary for your stay
  • tax authorities, courts and public bodies where we are legally obliged to provide information
  • legal counsel and debt collection services in the event of a dispute

Agreements pursuant to Art. 28 GDPR are in place with all processors. We expressly do not sell your data or pass it on to third parties for advertising purposes.

20. Transfers to third countries

Your data is generally processed within the European Union or the European Economic Area. In the cases expressly named in this policy, a transfer to a third country may occur. Such transfers are safeguarded by:

  • an adequacy decision of the European Commission (Switzerland; the USA under the EU-US Data Privacy Framework), or
  • the European Commission's standard contractual clauses pursuant to Art. 46(2)(c) GDPR, or
  • your explicit consent under Art. 49(1)(a) GDPR.

Please note that despite these safeguards, a level of protection fully equivalent to European standards cannot always be guaranteed in third countries, particularly with regard to access by public authorities.

21. Retention periods at a glance

We store personal data only for as long as necessary for the relevant purpose or as required by statutory retention obligations:

  • server log files: a few days, no longer than 30 days
  • enquiries without a contract: until fully dealt with, then deleted
  • booking, invoice and payment data: seven years under Section 132 BAO and Section 212 UGB
  • registration forms (Bavaria): one year, then destroyed under Section 30 BMG
  • guest records (Austria): in accordance with registration law requirements
  • data based on consent: until consent is withdrawn
  • cookie choice: until you reset it (see section 8)

Once the relevant period expires, data is deleted or anonymised unless it is exceptionally still required to establish, exercise or defend legal claims.

22. No automated decision-making

No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place. We do not take decisions concerning you based solely on automated processing that produce legal effects for you.

23. Obligation to provide data

Providing your data is partly required by law (for example under registration duties) or necessary to conclude a contract. Without the required information we cannot process a booking or order. Optional details are marked as such; omitting them has no disadvantages for you.

24. Minors

Our offering is aimed at persons of legal age. Persons under 18 should not submit personal data to us without the consent of a parent or guardian. We neither request nor knowingly collect personal data from children and young people, and we do not pass such data on to third parties. Should we become aware that such data has been submitted without the required consent, we will delete it without delay.

25. Liability for content and links, copyright

The content of this website has been compiled with the greatest care. However, we cannot guarantee its accuracy, completeness or timeliness. Information on availability, prices and services is subject to change unless expressly marked as binding.

Our offering contains links to external third-party websites over whose content we have no influence. The respective provider is always responsible for such external content. No legal infringements were apparent at the time of linking. We will remove such links immediately if we become aware of any legal violations.

The content, texts and images published on this website are protected by copyright. Reproduction, adaptation, distribution and any form of exploitation beyond the limits of copyright law require our prior written consent.

26. Changes to this privacy policy

We reserve the right to amend this privacy policy so that it always reflects current legal requirements or changes to our services, for instance when new services are introduced. The version published on this page applies to each new visit. We will not make material changes requiring consent without obtaining your renewed agreement.

27. Questions about data protection

If you have questions about the processing of your personal data or wish to exercise one of your rights, please contact us directly:

Luxalps GmbH · Feldweg 14 · A-9562 Himmelberg · Austria
info@luxalps.gmbh · +43 664 3458434

Message us on WhatsApp