Privacy

Privacy

Last updated: 20 September 2026

Who handles the data

Maria Nemeth, Roseggerstraße 17, 8850 Murau, Austria. Contact: mu.aktiv@gmail.com

Booking

When you book we handle your name, email address, phone number, the dates of your stay, the number of guests and any message. This is needed to perform the contract (GDPR Article 6(1)(b)): without it we cannot provide accommodation.

Accounting records are kept under the Austrian Federal Fiscal Code (BAO §132) for seven years counted from the end of the calendar year in which the record was created. We delete them once that period ends.

Emails

We send a confirmation and a reminder email about the booking. We keep a log of what was sent (recipient, subject, time, whether it succeeded), so that sending can be proven in case of a dispute.

Guest registration

In Austria the host is obliged to register every guest (Meldegesetz 1991). For this we handle guests' names, dates of birth, nationality, travel document type and number, and home address. The legal basis is compliance with a legal obligation (GDPR Article 6(1)(c)) – without this data we cannot take guests.

For the registration we pass the data to the competent Austrian authority through the feratel Deskline system. We give it to nobody else and do not use it for marketing. Guest register data is deleted once the statutory retention period ends.

Booking.com and calendar sync

If you book through Booking.com, we receive your data from them; their own privacy notice applies to them. Our calendar is linked to Booking.com by a two-way iCal connection, which contains only the dates of the booked periods and an internal identifier. No name, email address, phone number or amount is transferred, in either direction.

Security, protection against abuse

We protect the booking form and the login against automated abuse. For this we derive a fingerprint from the IP address using a secret salt that changes daily, and store only the number of attempts. No raw IP address is saved here either, and by the next day the fingerprint can no longer be tied to the same visitor. Legal basis: legitimate interest in keeping the service working (GDPR Article 6(1)(f)).

Visitor measurement

Two cookieless measurements accompany the running of the site:

  • Our own measurement. We store an identifier derived with a secret salt that changes daily. We do not save raw IP addresses, and identifiers from earlier days cannot be reversed – not even we can look up who was who.
  • Analyzza. Cookieless visitor measurement, a self-hosted system running on European servers. It records page views, referring page and device type, builds no individual profile, and the data does not leave the EU. Legal basis: legitimate interest in improving the service (GDPR Article 6(1)(f)).

We use no cookies for this, so we do not ask for consent either.

Cookies

We use a single cookie: the PHPSESSID session identifier, which is needed for submitting forms securely (CSRF protection). It disappears when you close the browser. It is a technically necessary cookie and needs no consent.

Third parties

The fonts and every script load from our own server – no Google Fonts, no embedded Google Maps, no social pixel, no advertising tracker.

Map: the map background is provided by Tilezza (tilezza.eu) from a server in the EU, using open OpenStreetMap data. When you open the map page your browser downloads images from them, so – as with any internet request – the provider sees your IP address and your browser type. They set no cookies, build no profile, and the map does not track where you go on the site. If the service is unavailable, the map switches by itself to the version served from our own server, and then no data leaves our server at all.

The route planner and the "ask an AI" buttons lead to external sites, but only when you click them. Before you click, no data reaches them, and we do not pass on the referring page address either.

Hosting

The site runs on a server of netcup GmbH (Karlsruhe, Germany), so the data does not leave the European Union. netcup acts as a processor under a data processing agreement. Log files created while running the server serve system security purposes and are deleted shortly afterwards.

Your rights

You can ask for a copy of the data we hold about you, for it to be corrected or deleted, and you can object to the processing. Write to the email address above. If you are not satisfied with the answer, you can complain to the Austrian data protection authority (Datenschutzbehörde, Barichgasse 40–42, 1030 Wien).

from €482.00 / night Book direct from the owner.
Book