Privacy Policy
Effective date: November 2025 – This Privacy Policy informs you about the processing of personal data by Pension Mozart Hospitality GmbH in accordance with the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG), the Austrian Telecommunications Act 2021 (TKG 2021) and other applicable provisions. Only the German version of this Privacy Policy is legally binding. Any translations are provided for convenience only and have no legal effect.
1. Controller and Contact
The controller within the meaning of the GDPR is:
Pension Mozart Hospitality GmbH
Theobaldgasse 15/12–14, 1060 Vienna, Austria
E‑mail: info [at] pension-mozart.at
Tel.: +43 1 587 85 05
You may contact us at any time using the contact details above with the subject “Data Protection” if you have questions regarding data protection.
2. Purposes and Legal Bases of Processing
We process personal data in particular for the following purposes and on the following legal bases:
- Initiation and performance of a contract (booking, accommodation, payment, communication): Art. 6(1)(b) GDPR.
- Compliance with legal obligations, in particular under the Austrian Registration Act 1991 (guest register) as well as tax and commercial retention obligations (BAO, UGB): Art. 6(1)(c) GDPR.
- Operation, security and optimisation of our website and systems (log files, error analysis, IT security, abuse prevention): Art. 6(1)(f) GDPR.
- Direct marketing and advertising (e.g., newsletters, remarketing), as permitted by law or based on consent: Art. 6(1)(f) or (a) GDPR in conjunction with Sec. 174 TKG 2021.
- Review management / guest feedback (e.g., sending review requests via third‑party platforms): Art. 6(1)(f) GDPR (legitimate interests) or – where required – Art. 6(1)(a) GDPR (consent).
- Statistics and reach measurement using cookies/tracking technologies (e.g., Google Analytics), where you have given consent: Art. 6(1)(a) GDPR in conjunction with Sec. 165 TKG 2021.
- Establishment, exercise or defence of legal claims, fraud and abuse prevention: Art. 6(1)(f) GDPR.
3. Categories of Data Processed
Depending on the purpose, we process in particular the following categories of data:
- Master data (name, title, salutation, date of birth, nationality, address, contact and communication data).
- Booking and contract data (stay details, room category, number of guests, booked services, prices, correspondence, preferences).
- Registration and ID data pursuant to the Registration Act (e.g., name, date of birth, country of origin, document data, arrival/departure, number of accompanying persons).
- Payment and billing data (payment method, partial masking of card number, validity, transaction and authorisation data, invoices, dunning and collection data).
- Usage and communication data (log files when visiting the website, IP address, date/time, pages accessed, devices/browsers used, cookies, consent status, communication history by e‑mail or other electronic channels).
4. Bookings, Online Check‑in and Guest Data (MEWS, SiteMinder, OTAs)
Online bookings via our website are processed via the booking system of SiteMinder Limited and the property management/payment system of Mews Systems B.V.. Both service providers act on the basis of data processing agreements pursuant to Art. 28 GDPR and process data exclusively on our instructions.
- Information on data processing by MEWS: https://www.mews.com/en/privacy-policy
- Information on data processing by SiteMinder: https://www.siteminder.com/legal/privacy/
If you book via online travel agencies (e.g., Booking, Expedia, etc.), we receive the data required to process the booking from the respective intermediary. These platforms are separate controllers under the GDPR; please also refer to their privacy notices.
5. Registration Data (Registration Act)
As an accommodation provider, we are legally obliged to collect certain guest data pursuant to the Austrian Registration Act 1991 and to maintain a guest register (e.g., name, date of birth, country of origin, passport/ID data, duration of stay, number of accompanying persons). The legal basis is Art. 6(1)(c) GDPR in conjunction with the Registration Act.
The registration data is stored in accordance with statutory requirements and deleted/destroyed after expiry of the statutory retention period (currently generally seven years), unless longer statutory or contractual retention obligations or legitimate interests apply.
6. Payment Processing and Credit Card Data
For payment processing, we use payment service providers and the PCI DSS‑certified property and payment system of MEWS. Credit card data is collected exclusively via secure, encrypted connections and processed directly by the payment service providers used. As a rule, we only store shortened card data (e.g., last digits, card type) and tokens that do not allow conclusions to be drawn about the full card number.
To secure bookings, handle advance payments, deposits, no‑shows, subsequent charges (e.g., additional taxes, damages) and to defend against unjustified chargebacks, payment data is stored for the duration of the stay and thereafter only as long as necessary for these purposes, generally up to 30 days after departure, unless further statutory obligations or outstanding claims exist.
7. Hosting and Log Files (easyname)
Our website is hosted by easyname GmbH, Canettistraße 5/10, 1100 Vienna, Austria. When you access our website, easyname processes technically necessary connection data (e.g., IP address, date/time, requested page, browser information, and, if applicable, error logs) to ensure secure operation of the web server.
The legal basis is our legitimate interest in providing the website securely and reliably (Art. 6(1)(f) GDPR). Further information on easyname’s data protection can be found at: https://www.easyname.at/download/data-protection-policy-de-v4.pdf.
Server log data is stored only as long as necessary for security and documentation purposes, generally up to 12 months, and is then deleted or anonymised.
8. Cookies, Similar Technologies and Consent under TKG 2021
We use cookies and similar technologies on our website. Necessary cookies are required for operation, security and basic functions of the website and booking flow and are used on the basis of Art. 6(1)(f) GDPR in conjunction with Sec. 165(3) TKG 2021.
To redirect you to the booking engine, we store a shortened booking source (for example google_com or OwnSite) in Session Storage for the current browser session. We also send the language, page type and selected booking entry point to SiteMinder. This information is used to correctly attribute direct bookings; advertising and click identifiers are only forwarded with your marketing consent. The session information ends no later than when the browser tab is closed.
For cookies that are not strictly necessary (in particular analytics and marketing cookies as well as third‑party tags), we obtain your consent via our consent banner (Art. 6(1)(a) GDPR in conjunction with Sec. 165 TKG 2021). You can adjust your settings at any time via “Cookie settings” in the footer and withdraw consent with effect for the future.
9. Web Analytics (Google Analytics)
If you consent via the consent banner, we use Google Analytics (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to measure reach and analyse the use of our website. Cookies are set and pseudonymous usage profiles are created. In particular, the following data may be processed: IP address (usually only in truncated form), pages accessed, date and time, time spent, devices and browsers used.
We use Google Analytics only with IP anonymisation enabled. The legal basis is your consent (Art. 6(1)(a) GDPR). Further information on Google’s privacy practices can be found at https://policies.google.com/privacy and on the Google Analytics terms at https://marketingplatform.google.com/about/analytics/terms/de/.
10. Marketing Tools (Google Ads, Meta Pixel, TikTok Pixel)
With your consent (category “Marketing” in the cookie banner), we may use the following services to deliver targeted advertising and measure campaign effectiveness:
- Google Ads / Conversion Tracking (Google Ireland Limited): analysis of conversions and attribution to ad campaigns.
- Meta Pixel (Meta Platforms Ireland Limited): measurement and optimisation of ad campaigns on Meta group platforms.
- TikTok Pixel (TikTok Technology Limited / TikTok Information Technologies UK Limited): measurement and optimisation of ad campaigns on TikTok.
These services use cookies or similar technologies and may transfer data (e.g., truncated IP address, device and usage data, pseudonymous IDs) to servers outside the EU/EEA. The providers typically rely on EU Standard Contractual Clauses and additional safeguards. Processing is carried out exclusively on the basis of your consent (Art. 6(1)(a) GDPR, Sec. 165 TKG 2021). You can withdraw your consent at any time via the cookie banner with effect for the future.
11. Direct Marketing by E‑mail
If we receive your e‑mail address in connection with a booking or service and you have not objected, we may occasionally send you information about similar offers of our own pursuant to Sec. 174 TKG 2021. The legal basis is our legitimate interest in direct marketing (Art. 6(1)(f) GDPR). You may object to this use of your e‑mail address at any time free of charge (e.g., by e‑mail to us or via an unsubscribe link in the newsletter).
If we send newsletters or offers solely on the basis of your explicit consent, the legal basis is Art. 6(1)(a) GDPR; you can withdraw consent at any time with effect for the future.
11a. SMS Communication and SMS Marketing
If we send SMS messages (e.g., for booking processing, service information, or – only with your consent – offers), we process in particular your mobile phone number and consent log data (opt‑in, time, content of consent, if applicable double opt‑in evidence).
No sharing for marketing: mobile phone numbers (“mobile information”) are not shared by us with third parties or affiliated companies (“Affiliates”) for their marketing or advertising purposes.
SMS opt‑in data: data relating to your SMS consent (opt‑in/consent) is not shared with third parties. Any disclosure – where necessary – is made exclusively to processors (Art. 28 GDPR) who support us with support/communication services (e.g., SMS delivery providers, customer service) and who process such data only on our instructions.
11b. Newsletter Management and Newsletter Delivery (Sorwell Media & Events e.U., Mailjet)
For the organisational and technical execution of newsletter campaigns (e.g., creation, recipient management, segmentation, sending, evaluation of delivery and open rates), we use external service providers. In this context, guest data and/or contact and communication data (in particular e‑mail address and – where required – name) is disclosed to the following recipients:
- Sorwell Media & Events e.U., Bäckerstraße 3/10, 1010 Vienna, Austria (marketing/agency services; processing as a processor pursuant to Art. 28 GDPR).
- Mailjet (e‑mail delivery service provider; processing in the context of newsletter delivery as a processor and/or sub‑processor pursuant to Art. 28 GDPR).
In this context, we process in particular contact and communication data (e.g., e‑mail address, name if provided), as well as registration/consent log data (e.g., time, source, content of consent; if applicable double opt‑in evidence) and campaign data (e.g., sending time, delivery status, opens/clicks – where used and legally permissible).
Depending on the setup, the legal basis is your consent (Art. 6(1)(a) GDPR in conjunction with Sec. 174 TKG 2021) or, where permissible, our legitimate interest in direct marketing (Art. 6(1)(f) GDPR in conjunction with Sec. 174 TKG 2021). You can withdraw consent at any time with effect for the future and/or object at any time (e.g., via the unsubscribe link or by contacting us).
If newsletter delivery involves transfers to third countries (outside the EU/EEA), this is carried out only in compliance with the requirements of Art. 44 et seq. GDPR (e.g., Standard Contractual Clauses) and with appropriate additional safeguards.
11c. Review Requests / Review Collection (Tripadvisor)
After a stay, we may share your e‑mail address with Tripadvisor so that a review request can be sent to you and/or the collection of guest reviews can be facilitated. Where necessary for matching, basic details (e.g., name and stay period) may also be transferred.
The purpose is to obtain guest feedback, improve our services and display reviews on the relevant platforms.
The legal basis is – depending on the specific implementation – our legitimate interest in obtaining feedback and displaying reviews (Art. 6(1)(f) GDPR) or, where required, your consent (Art. 6(1)(a) GDPR). You may object to such transfer at any time with effect for the future.
Note on roles: In the context of its services, Tripadvisor generally processes personal data as an independent controller. Please also review Tripadvisor’s privacy notice.
If Tripadvisor processes data outside the EU/EEA, this is done on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR (e.g., Standard Contractual Clauses), where required.
12. Retention Period and Deletion
Personal data is stored only as long as necessary for the purposes stated or as required by statutory retention obligations. Relevant periods arise in particular from:
- tax and duty regulations (in particular Sec. 132 BAO – generally 7 years, longer in individual cases),
- corporate and civil law provisions (in particular limitation periods for legal claims),
- Registration Act 1991 (retention of guest registration forms/guest registers),
- specific security or compliance obligations.
Once the respective purposes and periods no longer apply, the data is deleted or anonymised, unless overriding legitimate interests (e.g., ongoing proceedings) prevent this.
13. Recipients and Transfers to Third Countries
Depending on the processing activity, we transfer data to the following categories of recipients:
- IT service providers, hosters, booking and payment providers (e.g., easyname, MEWS, SiteMinder),
- payment service providers, banks, credit card companies,
- tax advisors, lawyers and other consultants,
- authorities and public bodies (e.g., registration authorities, tax authorities), where we are obliged to do so,
- marketing and analytics service providers (e.g., Google, Meta, TikTok), provided you have given consent,
- marketing/agency service providers and newsletter delivery providers (e.g., Sorwell Media & Events e.U., Mailjet),
- platforms for collecting guest reviews (e.g., Tripadvisor).
Note on mobile numbers/SMS consents: mobile phone numbers and SMS opt‑in/consent data are not transferred to third parties or affiliated companies (“Affiliates”) for their marketing or advertising purposes. An exception applies for transfers to processors (Art. 28 GDPR) where necessary for support/communication services (e.g., SMS sending, customer service).
Where we use service providers as processors (e.g., Sorwell Media & Events e.U., Mailjet), this is based on data processing agreements pursuant to Art. 28 GDPR. Recipients such as Tripadvisor may – depending on the setup – act as independent controllers; in such cases, their privacy notices apply in addition.
Transfers to third countries (outside the EU/EEA) take place only if there is an appropriate legal basis pursuant to Art. 44 et seq. GDPR (e.g., an EU Commission adequacy decision or up‑to‑date Standard Contractual Clauses). Where appropriate, we implement additional technical and organisational measures (e.g., pseudonymisation).
14. Your Rights under the GDPR
Subject to the statutory requirements, you have the following rights:
- right of access (Art. 15 GDPR),
- right to rectification (Art. 16 GDPR),
- right to erasure (“right to be forgotten”, Art. 17 GDPR),
- right to restriction of processing (Art. 18 GDPR),
- right to data portability (Art. 20 GDPR),
- right to object to processing based on legitimate interests (Art. 21 GDPR),
- right to withdraw consent at any time with effect for the future (Art. 7(3) GDPR).
To exercise these rights, you can contact us using the contact details provided in section 1. You also have the right to lodge a complaint with the competent supervisory authority. In Austria, this is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna (www.dsb.gv.at).
15. Updates to this Privacy Policy
We reserve the right to update this Privacy Policy as necessary in order to adapt it to changes in the legal framework, new processing activities or changes in service providers. The current version is available on our website.
Language version: Only the German version of this Privacy Policy is legally binding. Any translations are provided for convenience only and have no legal effect.