Privacy Policy 


Hotel Mikeli 

Last updated: 31 August 2026 


1. General Information 


The protection of your personal data is particularly important to us. We therefore process your data exclusively in accordance with the applicable legal provisions, in particular the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG), and the Austrian Telecommunications Act 2021 (TKG 2021). 


This Privacy Policy explains which data we process in connection with your use of our website as well as in the context of enquiries, bookings, and stays. 


2. Data Controller 


The controller responsible for data processing is: 


Mikeli Hotel 

Michaeligasse 14 

8230 Hartberg, Austria 

Email: office@mikeli.at 

Phone: +43 3332 90909 


3. Processing When Visiting Our Website 


When you visit our website, certain data is automatically processed for technical reasons. This includes, in particular, your IP address, the date and time of access, pages accessed, the browser used, and your operating system. 


This data is processed to ensure the functionality, stability, and security of our website. 


Legal basis: Art. 6(1)(f) GDPR (legitimate interest in maintaining a secure website) 


4. Contacting Us 


If you contact us (e.g. by email, telephone, or contact form), we process the data you provide, in particular your name, contact details, and the content of your enquiry. 


The data is processed for the purpose of handling your enquiry and taking steps prior to entering into a contract. 


Legal bases: 


  • Art. 6(1)(b) GDPR 

  • Art. 6(1)(f) GDPR 


5. Bookings and Stays 


In connection with bookings and stays, we process the personal data required to perform the accommodation contract. 


This includes, in particular: 


  • Name and contact details 

  • Stay and booking details 

  • Payment and billing information 

  • Correspondence 


This data is processed for the purpose of handling your booking, providing your stay, and processing payments and invoices. 


Legal basis: Art. 6(1)(b) GDPR 


5a. Online Bookings 


For online bookings made through our website or integrated booking systems (Feratel, Mews, Booking.com), the personal data you enter is processed for the purpose of handling your enquiry, processing your booking, initiating the contractual relationship, and performing the contract. 


Where external booking systems are used, they receive the data required for technical processing. 


Legal basis: Art. 6(1)(b) GDPR 


5b. Payment Processing 


For the purpose of processing payments, the necessary data is transmitted to payment service providers (Mews Payments) and banks. 


In particular, your name, payment amount, and billing information may be processed. 


Depending on the payment method selected, payment processing is carried out by external providers. 


Legal basis: Art. 6(1)(b) GDPR 


7. Statutory Registration Obligations 


As an accommodation provider, we are legally required to maintain a guest register. 


In particular, the following data is processed: 


  • Name 

  • Date of birth 

  • Nationality 

  • Address 

  • Arrival and departure dates 

  • For foreign guests: travel document details 


The data is processed exclusively for the purpose of complying with legal obligations. 


Legal basis: Art. 6(1)(c) GDPR 


The data is retained in accordance with the applicable statutory retention requirements and subsequently deleted unless longer retention is necessary for the establishment, exercise, or defence of legal claims. 


8. Use of Cookies and Web Analytics 


Our website uses cookies and similar technologies. 


Cookies are small text files stored on your device that contain certain information. 


Strictly Necessary Cookies 


These cookies are required for the proper functioning of the website and cannot be disabled. 


Legal bases: 


  • Section 165 TKG 2021 

  • Art. 6(1)(f) GDPR 


Analytics and Marketing Cookies 


Where you have given your consent, we use analytics tools (e.g. Google Analytics, Google Maps) to analyse the use of our website and improve our services. 


Usage data such as pages accessed, time spent on the website, or technical information may be processed. 


Such cookies are used only if you have expressly given your consent. 


Legal bases: 


  • Section 165 TKG 2021 

  • Art. 6(1)(a) GDPR 


Social Networks 


Our website may contain links to social networks. Simply visiting our website does not result in any data being transmitted to these providers. Only when you click on the relevant link will you be redirected to the website of the respective provider. 


Google Analytics 4 


Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. 


Purpose: Statistical analysis of website usage in order to improve our services. 


Data transfers to the USA: It cannot be ruled out that data may be transferred to servers in the USA. The USA is currently considered a third country providing an adequate level of data protection on the basis of the European Commission's adequacy decision under the EU-US Data Privacy Framework. Your consent also covers this data transfer. 


Google Maps 


Provider: Google Ireland Limited. 


Purpose: Display of interactive maps for route planning. Data (e.g. your IP address) is transmitted to Google as soon as the map is loaded. 


Legal basis: Your consent (Art. 6(1)(a) GDPR), which you provide before the map is loaded. 


9. External Content (e.g. Maps, Videos) 


Our website may include external content (e.g. maps or videos). When such content is accessed, personal data (in particular your IP address) may be transmitted to the respective provider. 


Such content is integrated only with your consent where this is required by law. 


Legal basis: Art. 6(1)(a) GDPR 


10. Hotel Wi-Fi 


If you use our guest Wi-Fi, technical connection data (e.g. IP address and connection duration) is processed to the extent necessary to provide the service and ensure the security and stability of the network. 


We do not monitor the content of your communications. 


Legal bases: 


  • Art. 6(1)(b) GDPR 

  • Art. 6(1)(f) GDPR 


11. Video Surveillance 


Parts of our hotel premises are monitored by video surveillance for security purposes. 


Video surveillance is carried out to safeguard legitimate interests pursuant to Art. 6(1)(f) GDPR. These interests include, in particular, protecting guests, employees, and property, as well as investigating security incidents and criminal offences. 


Recordings are generally stored for a maximum of 72 hours and are then automatically deleted unless a specific incident requires longer retention. 


Areas subject to video surveillance are appropriately marked. 


Legal basis: Art. 6(1)(f) GDPR 


12. Recipients of Data 


Your data is disclosed to third parties only to the extent necessary for the purposes described above. 


Recipients may include, in particular: 


  • IT service providers: our web hosting provider Framer B.V., Rozengracht 207B, 1016 LZ Amsterdam, the Netherlands 


  • Booking system: the provider of our online booking system, Mews Systems B.V., Wibautstraat 137D, 1097 DN Amsterdam, the Netherlands 


  • Payment providers: the payment service providers selected by you, e.g. Stripe, PayPal 


  • Public authorities: where required by law (e.g. registration authorities, tax authorities) 


  • Online booking platforms: where bookings are made through their systems (e.g. Booking.com); in such cases, these platforms are themselves responsible for data processing (Art. 24 GDPR) 


13. Data Transfers to Third Countries 


Data is transferred to countries outside the European Economic Area (third countries) only where this is necessary for the performance of a contract, required by law, or where you have given your consent and an adequate level of data protection is ensured. 


This applies in particular when using services provided by Google and Meta (see Section 8), where data may be transferred to the USA. Such transfers are based on the European Commission's adequacy decision regarding the EU-US Data Privacy Framework. 


14. Data Retention 


We retain personal data only for as long as necessary for the respective purposes or for as long as statutory retention obligations apply. 


  • Data from the guest register is retained for 7 years in accordance with Section 10 of the Austrian Registration Act (Meldegesetz). 


  • Booking and billing data is retained for 7 years in accordance with Section 132 of the Austrian Federal Fiscal Code (BAO). 


  • Data from enquiries that do not result in a booking is deleted after 6 months. 


15. Data Security 


We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, or misuse. 


Where service providers act as processors on our behalf, we ensure through appropriate agreements (Art. 28 GDPR) that your data is also adequately protected by those providers. 


16. Your Rights 


You have the right at any time to: 


  • Access your data 

  • Rectify your data 

  • Have your data erased 

  • Restrict processing 

  • Data portability 

  • Object to processing 

  • Withdraw your consent 


To exercise your rights, please contact: 


office@mikeli.at 


Where processing is based on legitimate interests pursuant to Art. 6(1)(f) GDPR, you have the right to object to such processing at any time on grounds relating to your particular situation. 


17. Right to Lodge a Complaint 


If you believe that the processing of your data violates data protection law, you may lodge a complaint with the competent supervisory authority: 


Austrian Data Protection Authority (Österreichische Datenschutzbehörde) 


Barichgasse 40–42 

1030 Vienna 

Austria 

www.dsb.gv.at 


This is without prejudice to any other administrative or judicial remedies available to you. 


18. Changes to This Privacy Policy 


We may amend this Privacy Policy in response to changes in the law or our services. The version published on our website at the time your data is collected applies to the respective processing of your data. Where appropriate, we will notify you separately of material changes affecting your rights.



Privacy Policy 


Hotel Mikeli 

Last updated: 31 August 2026 


1. General Information 


The protection of your personal data is particularly important to us. We therefore process your data exclusively in accordance with the applicable legal provisions, in particular the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG), and the Austrian Telecommunications Act 2021 (TKG 2021). 


This Privacy Policy explains which data we process in connection with your use of our website as well as in the context of enquiries, bookings, and stays. 


2. Data Controller 


The controller responsible for data processing is: 


Mikeli Hotel 

Michaeligasse 14 

8230 Hartberg, Austria 

Email: office@mikeli.at 

Phone: +43 3332 90909 


3. Processing When Visiting Our Website 


When you visit our website, certain data is automatically processed for technical reasons. This includes, in particular, your IP address, the date and time of access, pages accessed, the browser used, and your operating system. 


This data is processed to ensure the functionality, stability, and security of our website. 


Legal basis: Art. 6(1)(f) GDPR (legitimate interest in maintaining a secure website) 


4. Contacting Us 


If you contact us (e.g. by email, telephone, or contact form), we process the data you provide, in particular your name, contact details, and the content of your enquiry. 


The data is processed for the purpose of handling your enquiry and taking steps prior to entering into a contract. 


Legal bases: 


  • Art. 6(1)(b) GDPR 

  • Art. 6(1)(f) GDPR 


5. Bookings and Stays 


In connection with bookings and stays, we process the personal data required to perform the accommodation contract. 


This includes, in particular: 


  • Name and contact details 

  • Stay and booking details 

  • Payment and billing information 

  • Correspondence 


This data is processed for the purpose of handling your booking, providing your stay, and processing payments and invoices. 


Legal basis: Art. 6(1)(b) GDPR 


5a. Online Bookings 


For online bookings made through our website or integrated booking systems (Feratel, Mews, Booking.com), the personal data you enter is processed for the purpose of handling your enquiry, processing your booking, initiating the contractual relationship, and performing the contract. 


Where external booking systems are used, they receive the data required for technical processing. 


Legal basis: Art. 6(1)(b) GDPR 


5b. Payment Processing 


For the purpose of processing payments, the necessary data is transmitted to payment service providers (Mews Payments) and banks. 


In particular, your name, payment amount, and billing information may be processed. 


Depending on the payment method selected, payment processing is carried out by external providers. 


Legal basis: Art. 6(1)(b) GDPR 


7. Statutory Registration Obligations 


As an accommodation provider, we are legally required to maintain a guest register. 


In particular, the following data is processed: 


  • Name 

  • Date of birth 

  • Nationality 

  • Address 

  • Arrival and departure dates 

  • For foreign guests: travel document details 


The data is processed exclusively for the purpose of complying with legal obligations. 


Legal basis: Art. 6(1)(c) GDPR 


The data is retained in accordance with the applicable statutory retention requirements and subsequently deleted unless longer retention is necessary for the establishment, exercise, or defence of legal claims. 


8. Use of Cookies and Web Analytics 


Our website uses cookies and similar technologies. 


Cookies are small text files stored on your device that contain certain information. 


Strictly Necessary Cookies 


These cookies are required for the proper functioning of the website and cannot be disabled. 


Legal bases: 


  • Section 165 TKG 2021 

  • Art. 6(1)(f) GDPR 


Analytics and Marketing Cookies 


Where you have given your consent, we use analytics tools (e.g. Google Analytics, Google Maps) to analyse the use of our website and improve our services. 


Usage data such as pages accessed, time spent on the website, or technical information may be processed. 


Such cookies are used only if you have expressly given your consent. 


Legal bases: 


  • Section 165 TKG 2021 

  • Art. 6(1)(a) GDPR 


Social Networks 


Our website may contain links to social networks. Simply visiting our website does not result in any data being transmitted to these providers. Only when you click on the relevant link will you be redirected to the website of the respective provider. 


Google Analytics 4 


Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. 


Purpose: Statistical analysis of website usage in order to improve our services. 


Data transfers to the USA: It cannot be ruled out that data may be transferred to servers in the USA. The USA is currently considered a third country providing an adequate level of data protection on the basis of the European Commission's adequacy decision under the EU-US Data Privacy Framework. Your consent also covers this data transfer. 


Google Maps 


Provider: Google Ireland Limited. 


Purpose: Display of interactive maps for route planning. Data (e.g. your IP address) is transmitted to Google as soon as the map is loaded. 


Legal basis: Your consent (Art. 6(1)(a) GDPR), which you provide before the map is loaded. 


9. External Content (e.g. Maps, Videos) 


Our website may include external content (e.g. maps or videos). When such content is accessed, personal data (in particular your IP address) may be transmitted to the respective provider. 


Such content is integrated only with your consent where this is required by law. 


Legal basis: Art. 6(1)(a) GDPR 


10. Hotel Wi-Fi 


If you use our guest Wi-Fi, technical connection data (e.g. IP address and connection duration) is processed to the extent necessary to provide the service and ensure the security and stability of the network. 


We do not monitor the content of your communications. 


Legal bases: 


  • Art. 6(1)(b) GDPR 

  • Art. 6(1)(f) GDPR 


11. Video Surveillance 


Parts of our hotel premises are monitored by video surveillance for security purposes. 


Video surveillance is carried out to safeguard legitimate interests pursuant to Art. 6(1)(f) GDPR. These interests include, in particular, protecting guests, employees, and property, as well as investigating security incidents and criminal offences. 


Recordings are generally stored for a maximum of 72 hours and are then automatically deleted unless a specific incident requires longer retention. 


Areas subject to video surveillance are appropriately marked. 


Legal basis: Art. 6(1)(f) GDPR 


12. Recipients of Data 


Your data is disclosed to third parties only to the extent necessary for the purposes described above. 


Recipients may include, in particular: 


  • IT service providers: our web hosting provider Framer B.V., Rozengracht 207B, 1016 LZ Amsterdam, the Netherlands 


  • Booking system: the provider of our online booking system, Mews Systems B.V., Wibautstraat 137D, 1097 DN Amsterdam, the Netherlands 


  • Payment providers: the payment service providers selected by you, e.g. Stripe, PayPal 


  • Public authorities: where required by law (e.g. registration authorities, tax authorities) 


  • Online booking platforms: where bookings are made through their systems (e.g. Booking.com); in such cases, these platforms are themselves responsible for data processing (Art. 24 GDPR) 


13. Data Transfers to Third Countries 


Data is transferred to countries outside the European Economic Area (third countries) only where this is necessary for the performance of a contract, required by law, or where you have given your consent and an adequate level of data protection is ensured. 


This applies in particular when using services provided by Google and Meta (see Section 8), where data may be transferred to the USA. Such transfers are based on the European Commission's adequacy decision regarding the EU-US Data Privacy Framework. 


14. Data Retention 


We retain personal data only for as long as necessary for the respective purposes or for as long as statutory retention obligations apply. 


  • Data from the guest register is retained for 7 years in accordance with Section 10 of the Austrian Registration Act (Meldegesetz). 


  • Booking and billing data is retained for 7 years in accordance with Section 132 of the Austrian Federal Fiscal Code (BAO). 


  • Data from enquiries that do not result in a booking is deleted after 6 months. 


15. Data Security 


We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, or misuse. 


Where service providers act as processors on our behalf, we ensure through appropriate agreements (Art. 28 GDPR) that your data is also adequately protected by those providers. 


16. Your Rights 


You have the right at any time to: 


  • Access your data 

  • Rectify your data 

  • Have your data erased 

  • Restrict processing 

  • Data portability 

  • Object to processing 

  • Withdraw your consent 


To exercise your rights, please contact: 


office@mikeli.at 


Where processing is based on legitimate interests pursuant to Art. 6(1)(f) GDPR, you have the right to object to such processing at any time on grounds relating to your particular situation. 


17. Right to Lodge a Complaint 


If you believe that the processing of your data violates data protection law, you may lodge a complaint with the competent supervisory authority: 


Austrian Data Protection Authority (Österreichische Datenschutzbehörde) 


Barichgasse 40–42 

1030 Vienna 

Austria 

www.dsb.gv.at 


This is without prejudice to any other administrative or judicial remedies available to you. 


18. Changes to This Privacy Policy 


We may amend this Privacy Policy in response to changes in the law or our services. The version published on our website at the time your data is collected applies to the respective processing of your data. Where appropriate, we will notify you separately of material changes affecting your rights.


Michaeligasse 14

8230 Hartberg, Austria

+43 3332 61550 1901

office@mikeli.at

© Mikeli 2026 | All rights reserved

| Imprint

Michaeligasse 14

8230 Hartberg, Austria

+43 3332 61550 1901

office@mikeli.at

© Mikeli 2026 | All rights reserved

Imprint