Privacy Policy
Hotel Mikeli
Last updated: 31 August 2026
1. General Information
The protection of your personal data is particularly important to us. We therefore process your data exclusively in accordance with the applicable legal provisions, in particular the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG), and the Austrian Telecommunications Act 2021 (TKG 2021).
This Privacy Policy explains which data we process in connection with your use of our website as well as in the context of enquiries, bookings, and stays.
2. Data Controller
The controller responsible for data processing is:
Mikeli Hotel
Michaeligasse 14
8230 Hartberg, Austria
Email: office@mikeli.at
Phone: +43 3332 90909
3. Processing When Visiting Our Website
When you visit our website, certain data is automatically processed for technical reasons. This includes, in particular, your IP address, the date and time of access, pages accessed, the browser used, and your operating system.
This data is processed to ensure the functionality, stability, and security of our website.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in maintaining a secure website)
4. Contacting Us
If you contact us (e.g. by email, telephone, or contact form), we process the data you provide, in particular your name, contact details, and the content of your enquiry.
The data is processed for the purpose of handling your enquiry and taking steps prior to entering into a contract.
Legal bases:
Art. 6(1)(b) GDPR
Art. 6(1)(f) GDPR
5. Bookings and Stays
In connection with bookings and stays, we process the personal data required to perform the accommodation contract.
This includes, in particular:
Name and contact details
Stay and booking details
Payment and billing information
Correspondence
This data is processed for the purpose of handling your booking, providing your stay, and processing payments and invoices.
Legal basis: Art. 6(1)(b) GDPR
5a. Online Bookings
For online bookings made through our website or integrated booking systems (Feratel, Mews, Booking.com), the personal data you enter is processed for the purpose of handling your enquiry, processing your booking, initiating the contractual relationship, and performing the contract.
Where external booking systems are used, they receive the data required for technical processing.
Legal basis: Art. 6(1)(b) GDPR
5b. Payment Processing
For the purpose of processing payments, the necessary data is transmitted to payment service providers (Mews Payments) and banks.
In particular, your name, payment amount, and billing information may be processed.
Depending on the payment method selected, payment processing is carried out by external providers.
Legal basis: Art. 6(1)(b) GDPR
7. Statutory Registration Obligations
As an accommodation provider, we are legally required to maintain a guest register.
In particular, the following data is processed:
Name
Date of birth
Nationality
Address
Arrival and departure dates
For foreign guests: travel document details
The data is processed exclusively for the purpose of complying with legal obligations.
Legal basis: Art. 6(1)(c) GDPR
The data is retained in accordance with the applicable statutory retention requirements and subsequently deleted unless longer retention is necessary for the establishment, exercise, or defence of legal claims.
8. Use of Cookies and Web Analytics
Our website uses cookies and similar technologies.
Cookies are small text files stored on your device that contain certain information.
Strictly Necessary Cookies
These cookies are required for the proper functioning of the website and cannot be disabled.
Legal bases:
Section 165 TKG 2021
Art. 6(1)(f) GDPR
Analytics and Marketing Cookies
Where you have given your consent, we use analytics tools (e.g. Google Analytics, Google Maps) to analyse the use of our website and improve our services.
Usage data such as pages accessed, time spent on the website, or technical information may be processed.
Such cookies are used only if you have expressly given your consent.
Legal bases:
Section 165 TKG 2021
Art. 6(1)(a) GDPR
Social Networks
Our website may contain links to social networks. Simply visiting our website does not result in any data being transmitted to these providers. Only when you click on the relevant link will you be redirected to the website of the respective provider.
Google Analytics 4
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Purpose: Statistical analysis of website usage in order to improve our services.
Data transfers to the USA: It cannot be ruled out that data may be transferred to servers in the USA. The USA is currently considered a third country providing an adequate level of data protection on the basis of the European Commission's adequacy decision under the EU-US Data Privacy Framework. Your consent also covers this data transfer.
Google Maps
Provider: Google Ireland Limited.
Purpose: Display of interactive maps for route planning. Data (e.g. your IP address) is transmitted to Google as soon as the map is loaded.
Legal basis: Your consent (Art. 6(1)(a) GDPR), which you provide before the map is loaded.
9. External Content (e.g. Maps, Videos)
Our website may include external content (e.g. maps or videos). When such content is accessed, personal data (in particular your IP address) may be transmitted to the respective provider.
Such content is integrated only with your consent where this is required by law.
Legal basis: Art. 6(1)(a) GDPR
10. Hotel Wi-Fi
If you use our guest Wi-Fi, technical connection data (e.g. IP address and connection duration) is processed to the extent necessary to provide the service and ensure the security and stability of the network.
We do not monitor the content of your communications.
Legal bases:
Art. 6(1)(b) GDPR
Art. 6(1)(f) GDPR
11. Video Surveillance
Parts of our hotel premises are monitored by video surveillance for security purposes.
Video surveillance is carried out to safeguard legitimate interests pursuant to Art. 6(1)(f) GDPR. These interests include, in particular, protecting guests, employees, and property, as well as investigating security incidents and criminal offences.
Recordings are generally stored for a maximum of 72 hours and are then automatically deleted unless a specific incident requires longer retention.
Areas subject to video surveillance are appropriately marked.
Legal basis: Art. 6(1)(f) GDPR
12. Recipients of Data
Your data is disclosed to third parties only to the extent necessary for the purposes described above.
Recipients may include, in particular:
IT service providers: our web hosting provider Framer B.V., Rozengracht 207B, 1016 LZ Amsterdam, the Netherlands
Booking system: the provider of our online booking system, Mews Systems B.V., Wibautstraat 137D, 1097 DN Amsterdam, the Netherlands
Payment providers: the payment service providers selected by you, e.g. Stripe, PayPal
Public authorities: where required by law (e.g. registration authorities, tax authorities)
Online booking platforms: where bookings are made through their systems (e.g. Booking.com); in such cases, these platforms are themselves responsible for data processing (Art. 24 GDPR)
13. Data Transfers to Third Countries
Data is transferred to countries outside the European Economic Area (third countries) only where this is necessary for the performance of a contract, required by law, or where you have given your consent and an adequate level of data protection is ensured.
This applies in particular when using services provided by Google and Meta (see Section 8), where data may be transferred to the USA. Such transfers are based on the European Commission's adequacy decision regarding the EU-US Data Privacy Framework.
14. Data Retention
We retain personal data only for as long as necessary for the respective purposes or for as long as statutory retention obligations apply.
Data from the guest register is retained for 7 years in accordance with Section 10 of the Austrian Registration Act (Meldegesetz).
Booking and billing data is retained for 7 years in accordance with Section 132 of the Austrian Federal Fiscal Code (BAO).
Data from enquiries that do not result in a booking is deleted after 6 months.
15. Data Security
We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, or misuse.
Where service providers act as processors on our behalf, we ensure through appropriate agreements (Art. 28 GDPR) that your data is also adequately protected by those providers.
16. Your Rights
You have the right at any time to:
Access your data
Rectify your data
Have your data erased
Restrict processing
Data portability
Object to processing
Withdraw your consent
To exercise your rights, please contact:
Where processing is based on legitimate interests pursuant to Art. 6(1)(f) GDPR, you have the right to object to such processing at any time on grounds relating to your particular situation.
17. Right to Lodge a Complaint
If you believe that the processing of your data violates data protection law, you may lodge a complaint with the competent supervisory authority:
Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40–42
1030 Vienna
Austria
This is without prejudice to any other administrative or judicial remedies available to you.
18. Changes to This Privacy Policy
We may amend this Privacy Policy in response to changes in the law or our services. The version published on our website at the time your data is collected applies to the respective processing of your data. Where appropriate, we will notify you separately of material changes affecting your rights.
Privacy Policy
Hotel Mikeli
Last updated: 31 August 2026
1. General Information
The protection of your personal data is particularly important to us. We therefore process your data exclusively in accordance with the applicable legal provisions, in particular the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG), and the Austrian Telecommunications Act 2021 (TKG 2021).
This Privacy Policy explains which data we process in connection with your use of our website as well as in the context of enquiries, bookings, and stays.
2. Data Controller
The controller responsible for data processing is:
Mikeli Hotel
Michaeligasse 14
8230 Hartberg, Austria
Email: office@mikeli.at
Phone: +43 3332 90909
3. Processing When Visiting Our Website
When you visit our website, certain data is automatically processed for technical reasons. This includes, in particular, your IP address, the date and time of access, pages accessed, the browser used, and your operating system.
This data is processed to ensure the functionality, stability, and security of our website.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in maintaining a secure website)
4. Contacting Us
If you contact us (e.g. by email, telephone, or contact form), we process the data you provide, in particular your name, contact details, and the content of your enquiry.
The data is processed for the purpose of handling your enquiry and taking steps prior to entering into a contract.
Legal bases:
Art. 6(1)(b) GDPR
Art. 6(1)(f) GDPR
5. Bookings and Stays
In connection with bookings and stays, we process the personal data required to perform the accommodation contract.
This includes, in particular:
Name and contact details
Stay and booking details
Payment and billing information
Correspondence
This data is processed for the purpose of handling your booking, providing your stay, and processing payments and invoices.
Legal basis: Art. 6(1)(b) GDPR
5a. Online Bookings
For online bookings made through our website or integrated booking systems (Feratel, Mews, Booking.com), the personal data you enter is processed for the purpose of handling your enquiry, processing your booking, initiating the contractual relationship, and performing the contract.
Where external booking systems are used, they receive the data required for technical processing.
Legal basis: Art. 6(1)(b) GDPR
5b. Payment Processing
For the purpose of processing payments, the necessary data is transmitted to payment service providers (Mews Payments) and banks.
In particular, your name, payment amount, and billing information may be processed.
Depending on the payment method selected, payment processing is carried out by external providers.
Legal basis: Art. 6(1)(b) GDPR
7. Statutory Registration Obligations
As an accommodation provider, we are legally required to maintain a guest register.
In particular, the following data is processed:
Name
Date of birth
Nationality
Address
Arrival and departure dates
For foreign guests: travel document details
The data is processed exclusively for the purpose of complying with legal obligations.
Legal basis: Art. 6(1)(c) GDPR
The data is retained in accordance with the applicable statutory retention requirements and subsequently deleted unless longer retention is necessary for the establishment, exercise, or defence of legal claims.
8. Use of Cookies and Web Analytics
Our website uses cookies and similar technologies.
Cookies are small text files stored on your device that contain certain information.
Strictly Necessary Cookies
These cookies are required for the proper functioning of the website and cannot be disabled.
Legal bases:
Section 165 TKG 2021
Art. 6(1)(f) GDPR
Analytics and Marketing Cookies
Where you have given your consent, we use analytics tools (e.g. Google Analytics, Google Maps) to analyse the use of our website and improve our services.
Usage data such as pages accessed, time spent on the website, or technical information may be processed.
Such cookies are used only if you have expressly given your consent.
Legal bases:
Section 165 TKG 2021
Art. 6(1)(a) GDPR
Social Networks
Our website may contain links to social networks. Simply visiting our website does not result in any data being transmitted to these providers. Only when you click on the relevant link will you be redirected to the website of the respective provider.
Google Analytics 4
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Purpose: Statistical analysis of website usage in order to improve our services.
Data transfers to the USA: It cannot be ruled out that data may be transferred to servers in the USA. The USA is currently considered a third country providing an adequate level of data protection on the basis of the European Commission's adequacy decision under the EU-US Data Privacy Framework. Your consent also covers this data transfer.
Google Maps
Provider: Google Ireland Limited.
Purpose: Display of interactive maps for route planning. Data (e.g. your IP address) is transmitted to Google as soon as the map is loaded.
Legal basis: Your consent (Art. 6(1)(a) GDPR), which you provide before the map is loaded.
9. External Content (e.g. Maps, Videos)
Our website may include external content (e.g. maps or videos). When such content is accessed, personal data (in particular your IP address) may be transmitted to the respective provider.
Such content is integrated only with your consent where this is required by law.
Legal basis: Art. 6(1)(a) GDPR
10. Hotel Wi-Fi
If you use our guest Wi-Fi, technical connection data (e.g. IP address and connection duration) is processed to the extent necessary to provide the service and ensure the security and stability of the network.
We do not monitor the content of your communications.
Legal bases:
Art. 6(1)(b) GDPR
Art. 6(1)(f) GDPR
11. Video Surveillance
Parts of our hotel premises are monitored by video surveillance for security purposes.
Video surveillance is carried out to safeguard legitimate interests pursuant to Art. 6(1)(f) GDPR. These interests include, in particular, protecting guests, employees, and property, as well as investigating security incidents and criminal offences.
Recordings are generally stored for a maximum of 72 hours and are then automatically deleted unless a specific incident requires longer retention.
Areas subject to video surveillance are appropriately marked.
Legal basis: Art. 6(1)(f) GDPR
12. Recipients of Data
Your data is disclosed to third parties only to the extent necessary for the purposes described above.
Recipients may include, in particular:
IT service providers: our web hosting provider Framer B.V., Rozengracht 207B, 1016 LZ Amsterdam, the Netherlands
Booking system: the provider of our online booking system, Mews Systems B.V., Wibautstraat 137D, 1097 DN Amsterdam, the Netherlands
Payment providers: the payment service providers selected by you, e.g. Stripe, PayPal
Public authorities: where required by law (e.g. registration authorities, tax authorities)
Online booking platforms: where bookings are made through their systems (e.g. Booking.com); in such cases, these platforms are themselves responsible for data processing (Art. 24 GDPR)
13. Data Transfers to Third Countries
Data is transferred to countries outside the European Economic Area (third countries) only where this is necessary for the performance of a contract, required by law, or where you have given your consent and an adequate level of data protection is ensured.
This applies in particular when using services provided by Google and Meta (see Section 8), where data may be transferred to the USA. Such transfers are based on the European Commission's adequacy decision regarding the EU-US Data Privacy Framework.
14. Data Retention
We retain personal data only for as long as necessary for the respective purposes or for as long as statutory retention obligations apply.
Data from the guest register is retained for 7 years in accordance with Section 10 of the Austrian Registration Act (Meldegesetz).
Booking and billing data is retained for 7 years in accordance with Section 132 of the Austrian Federal Fiscal Code (BAO).
Data from enquiries that do not result in a booking is deleted after 6 months.
15. Data Security
We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, or misuse.
Where service providers act as processors on our behalf, we ensure through appropriate agreements (Art. 28 GDPR) that your data is also adequately protected by those providers.
16. Your Rights
You have the right at any time to:
Access your data
Rectify your data
Have your data erased
Restrict processing
Data portability
Object to processing
Withdraw your consent
To exercise your rights, please contact:
Where processing is based on legitimate interests pursuant to Art. 6(1)(f) GDPR, you have the right to object to such processing at any time on grounds relating to your particular situation.
17. Right to Lodge a Complaint
If you believe that the processing of your data violates data protection law, you may lodge a complaint with the competent supervisory authority:
Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40–42
1030 Vienna
Austria
This is without prejudice to any other administrative or judicial remedies available to you.
18. Changes to This Privacy Policy
We may amend this Privacy Policy in response to changes in the law or our services. The version published on our website at the time your data is collected applies to the respective processing of your data. Where appropriate, we will notify you separately of material changes affecting your rights.