Zum Inhalt

Privacy Policy

Data controller

The organisation responsible for processing your personal data is:

Gräpplang Hospitality GmbH
Gräpplangstrasse 32
CH-8890 Flums

Email: stay@graepplang.ch
 

Gräpplang Hospitality GmbH operates the Gräpplang Hotel and Restaurant in Flums, as well as the website www.graepplang.ch.

The protection of your personal data is important to us. We process personal data confidentially and in accordance with the Swiss Federal Act on Data Protection (DSG), the associated ordinances and – where applicable – the European Union’s General Data Protection Regulation (GDPR) and other applicable legal provisions.

This privacy policy explains what personal data we collect, the purposes for which we process it, to whom it may be disclosed, and what rights you have.

 

 

Definitions and scope

Personal data refers to any information relating to an identified or identifiable natural person. Processing refers to any handling of personal data, in particular the collection, recording, storage, use, transmission, alteration or erasure.

This Privacy Policy applies to the processing of personal data in connection with:

  • visits to our website
  • room and restaurant bookings
  • events, seminars and banquets
  • enquiries via email, by telephone or via the contact form
  • the use of our services
  • payment processing
  • the sending of newsletters and marketing information
  • statutory reporting and retention obligations

 

Collection and processing of personal data


Visits to our website: When you visit our website, technical data transmitted by your browser to our server is automatically collected. This may include, in particular:

  • IP address
  • date and time of access
  • pages and files accessed
  • previously visited website
  • browser type and version
  • operating system
  • Device information
  • Language settings
  • Access status and volume of data transferred

This data is processed in order to provide the website securely and without technical faults, to analyse errors, detect attacks and misuse, and to improve our service.

Technical log data is generally only stored for as long as is necessary for operation, security and error analysis. It may be retained for longer if specific security incidents need to be investigated or if there are legal obligations.

 

Cookies and similar technologies: Our website uses cookies and similar technologies. Cookies are small files that are stored on your device. We distinguish between:

  • technically necessary cookies, which are required for the website to function
  • functional cookies, which store certain settings
  • analytics and statistics cookies
  • marketing and tracking cookies

Technically necessary cookies may be used without prior consent, insofar as this is permitted by law. Analytics, marketing and tracking technologies are only activated if you have given your consent via the cookie banner, insofar as consent is required.

You can change your selection at any time via the website’s privacy settings or withdraw any consent you have given. Withdrawal does not affect the lawfulness of processing that has already taken place.

Cookies can also be restricted or deleted via your browser settings. If you disable technically necessary cookies, certain functions of the website may be restricted.

 

Contacting us: If you contact us by email, telephone, via the contact form or by any other means, we will process the information you provide. This may include, in particular:

  • Surname and first name
  • Email address
  • Telephone number
  • Address
  • Content and time of your enquiry
  • Further information provided voluntarily

We use this data to process your enquiry, to communicate with you, to prepare quotations, and to prepare for or fulfil a contract.

Enquiries that do not result in a contract being concluded are generally deleted or anonymised as soon as they are no longer required for processing. This is subject to statutory retention obligations and the retention of data for the purpose of asserting, exercising or defending legal claims.

 

Room bookings and hotel stays: To process room bookings and hotel stays, we collect the following data in particular:

  • Surname and first name
  • Address and place of residence
  • Email address and telephone number
  • Date of birth
  • Nationality
  • Date of arrival and departure
  • Number and names of travelling companions
  • Services booked
  • Invoicing and payment details
  • Special requests
  • Information voluntarily provided regarding allergies or intolerances
  • Correspondence relating to the booking

This data is used to process the booking, to fulfil the accommodation contract, to process payments, to provide guest services, to organise the stay and to comply with legal obligations.

 

Bookings via Apaleo

We use the Apaleo hotel management and booking system, provided by apaleo GmbH, Germany, to manage bookings and hotel stays.

When you make a direct booking, the data required for the booking is recorded in Apaleo and processed there on our behalf. This may include, in particular, contact details, booking details, stay details, invoicing information and payment details.

Apaleo may engage further sub-processors to provide its services. In doing so, personal data may be processed in Switzerland, Germany, the Netherlands, Ireland and, in some cases, in the USA or other countries.

We have concluded the necessary contractual data protection agreements with Apaleo. Where data is transferred to countries without a recognised adequate level of data protection, the transfer is carried out in particular on the basis of recognised standard data protection clauses and, where applicable, additional safeguards. Further information can be found at: https://www.apaleo.com/privacy-policy

 

Bookings via external platforms

If you book a room via an external booking platform such as Booking.com, we receive the data necessary to process your booking from the respective platform. This may include, in particular:

  • Name and contact details
  • Stay details
  • Services booked
  • Payment and billing information
  • Special requests
  • Messages and correspondence

The relevant booking platform processes your data under its own responsibility. The platform’s privacy policy and terms of use apply to the collection and processing of data by that platform. We process the data provided in order to fulfil the accommodation contract, to provide guest services and to comply with legal obligations.

 

Restaurant reservations

In the case of restaurant reservations, we process the following in particular:

  • Surname and first name
  • Telephone number and email address
  • Date and time of the booking
  • Number of people
  • Special requests
  • Information voluntarily provided regarding allergies or intolerances
  • Details of deposits or payment methods provided, where necessary

We use this data to process the booking, to prepare for the visit, to communicate any changes and to handle any cancellation fees.

Information regarding allergies and intolerances is used exclusively to ensure the safe preparation and provision of our catering services. Please only provide us with information that is actually necessary for your visit.

 

Events, seminars and banquets

When processing enquiries and bookings for events, weddings, seminars, banquets or exclusive bookings, we process in particular:

  • Contact details of the client
  • Details of the contact and organising persons
  • Information about the event
  • Number of participants
  • Services booked
  • Quotations, contracts and correspondence
  • Invoicing and payment details
  • Specific organisational or catering requirements

This data is processed for the purposes of preparing a quotation, planning and organising the event, communication, invoicing, and fulfilling legal and contractual obligations.

 

Statutory reporting obligations and visitor’s tax

As an accommodation provider, we are obliged to collect certain data from our guests and pass it on to the relevant authorities or tourism organisations. This may include, in particular:

  • Surname, first name and residential address
  • Date of birth
  • Nationality
  • Date of arrival and departure
  • Identity or travel document details, where required by law

Data is processed to fulfil statutory reporting obligations and to collect and account for visitor’s taxes. Only data necessary for the respective statutory purpose is passed on.

 

Payment processing

When processing payments, we process the data required to complete the transaction. Depending on the chosen payment method, this data may be transmitted directly to banks, credit card companies or payment service providers.

We do not usually receive full credit card details, but only the information necessary for allocating and confirming the payment.

Processing by banks, credit card companies and payment service providers is also subject to their respective privacy policies.

 

Newsletters and marketing communications

If you subscribe to our newsletter or other marketing information, we process, in particular, your email address and, where applicable, your name and your preferred language.

These are generally sent only with your consent. Where technically possible, we use a confirmation procedure whereby you must confirm your subscription via a link.

You can withdraw your consent at any time via the unsubscribe link in the newsletter or by sending a message to stay@graepplang.ch.

Once you have unsubscribed, your email address will no longer be used to send marketing information. We may retain proof of your subscription and unsubscription for a reasonable period to document compliance with legal obligations.

Where an external mailing service provider is used for the newsletter, the necessary data will be processed by that service provider on our behalf.

 

Web analytics with Google Analytics

Our website may use Google Analytics, a web analytics service provided by Google Ireland Limited, Ireland, or Google LLC, USA. Google Analytics enables us to statistically analyse the use of our website and improve our offering. In particular, the following information may be processed:

  • pages visited
  • time and duration of the visit
  • approximate location
  • device and browser information
  • Interactions with the website
  • Source of website traffic
  • Technical identifiers

Google Analytics does not store individual IP addresses for users from Switzerland and the European Union. IP addresses may be used temporarily to derive approximate location information and are subsequently discarded.

Google Analytics is only activated if you have given your consent via the cookie banner, insofar as consent is required by law. You can withdraw your consent at any time via the privacy settings on our website.

The data collected via Google Analytics may be processed by Google in Ireland, the USA and other countries. For transfers to countries without an adequate level of data protection, recognised standard data protection clauses and, where necessary, additional safeguards are used.

The retention period for user and event data in Google Analytics is limited to a reasonable period and generally does not exceed 14 months, unless a shorter period has been set. Further information can be found at: https://policies.google.com/privacy

 

Purposes of data processing

We process personal data in particular for the following purposes:

  • Operation and security of our website
  • Processing of enquiries and bookings
  • Preparation of quotations
  • Conclusion and fulfilment of contracts
  • Provision of hotel, restaurant and event services
  • Communication with guests and customer service
  • Payment processing and invoicing
  • Fulfilment of statutory reporting, accounting and record-keeping obligations
  • Quality control and improvement of our services
  • Prevention of misuse and fraud
  • Enforcement or defence of legal claims
  • Sending newsletters and marketing information with the relevant consent
  • Statistical analysis of the use of our website

 

Legal bases

Where the GDPR applies, we base the processing of personal data in particular on the following legal bases:

  • Fulfilment of a contract or the implementation of pre-contractual measures;
  • Compliance with legal obligations
  • Safeguarding our legitimate interests, in particular the secure and efficient operation of our business, the improvement of our services, and the enforcement or defence of legal claims
  • Consent of the data subject
  • Protection of vital interests, insofar as this is necessary in individual cases
  • Consent that has been given may be withdrawn at any time with effect for the future.

 

Disclosure of personal data

We only disclose personal data if this is necessary for the provision of our services, if there is a legal obligation to do so, if there is a legitimate interest, or if you have given your consent. Possible recipients include, in particular:

  • Hotel management and reservation systems
  • Booking platforms
  • Payment service providers, banks and credit card companies
  • Providers of restaurant reservation systems
  • IT, hosting, cloud and support service providers
  • newsletter and communication service providers
  • analytics and tracking providers
  • external service providers for events
  • accountancy, fiduciary and legal advisory services
  • Insurance companies
  • Public authorities, the police and tourism organisations, where required by law

As a general rule, our service providers may only process personal data in accordance with our instructions and for the agreed purposes, unless they themselves act as data controllers under data protection law.

 

Transfer of personal data abroad

Personal data is generally processed in Switzerland, the European Union or the European Economic Area. Where individual service providers are used, processing may take place in other countries. This applies in particular to Germany, the Netherlands, Ireland and the USA, as well as, where applicable, other countries in which the respective service providers or sub-contractors operate.

Where personal data is transferred to a country without a recognised adequate level of data protection, we ensure data protection in particular through recognised standard data protection clauses, additional contractual, organisational or technical safeguards, or through a statutory exemption.

A transfer may also take place if it is necessary for the conclusion or performance of a contract, if you have given your express consent, or if there is another legal justification.

 

Retention period

We only retain personal data for as long as is necessary for the respective purpose or for as long as statutory retention obligations apply. In principle, the following retention principles apply:

  • Booking, contract, invoice and accounting documents are generally retained for ten years.
  • Registration forms and visitor’s tax data are retained in accordance with the applicable legal requirements.
  • Enquiries that do not result in the conclusion of a contract are generally deleted as soon as they have been dealt with and there are no overriding interests or legal obligations requiring further retention.
  • Newsletter data is retained until consent is withdrawn or the subscriber unsubscribes.
  • Analytics and tracking data are stored in accordance with the settings of the respective service and deleted or anonymised as soon as possible.
  • Technical log data are only stored for as long as is necessary for the secure operation of the website and the investigation of specific incidents.

Once the relevant retention period has expired, the data will be deleted or anonymised, provided there are no legal or contractual grounds for further retention.

 

Data security

We implement appropriate technical and organisational security measures to protect personal data against loss, misuse, unauthorised access, alteration or disclosure. Depending on the nature of the processing, these include in particular:

  • encrypted data transmission
  • access restrictions and authorisation policies
  • secure passwords and authentication procedures
  • regular data backups
  • updating and maintaining our systems
  • contractual obligations of external service providers
  • training and awareness-raising for our staff

Despite appropriate security measures, completely risk-free data transmission and storage cannot be guaranteed.

 

Your rights

Depending on the applicable data protection legislation, you are entitled, in particular, to the following rights:

  • Information as to whether and what personal data we process about you
  • Rectification of inaccurate or incomplete personal data
  • Erasure of personal data, provided there are no legal or overriding grounds to the contrary
  • To receive or have certain personal data transferred in a commonly used electronic format, provided the legal requirements are met
  • To restrict certain data processing activities, where the GDPR applies
  • Objection to certain data processing activities, where provided for by law
  • Withdrawal of consent with effect for the future

To exercise your rights, please contact: stay@graepplang.ch

We may request proof of identity if this is necessary to prevent the unauthorised disclosure of personal data. We reserve the right to apply statutory restrictions, in particular statutory retention obligations, overriding interests or the protection of the rights of third parties.

Data subjects also have the right to contact the competent data protection supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC).

 

Data relating to children

Our services are generally aimed at adults. Data relating to children and young people will only be processed to the extent necessary for a booking, a stay, an event or to fulfil legal obligations.

The information is usually provided by a parent or guardian or by the person responsible for the booking.

 

Automated decisions

As a general rule, we do not make any decisions based solely on automated processing that have legal effects on you or affect you in a similarly significant manner. Should such procedures be used in future, we will inform the data subjects in accordance with the legal requirements.

 

Links to other websites

Our website may contain links to websites operated by external providers. The respective operators are responsible for the content and data processing on these external websites. Please refer to the privacy policies of the relevant providers.

 

Changes to this privacy policy

We may amend this privacy policy at any time, in particular if our services, the systems we use or the legal requirements change. The current version published on our website shall apply.

 

Gräpplang Hospitality GmbH
Gräpplangstrasse 32
CH-8890 Flums

Email: stay@graepplang.ch
Website: https://www.graepplang.ch