Data protection

Privacy policy - ALPENBAHNEN-SPITZINGSEE.DE

Thank you for visiting our website and for your interest in the topic of data protection. Please take note of the following information so that you know when we collect which personal data and how we use this data.

Responsible body

The controller pursuant to Art. 4 (7) of the EU General Data Protection Regulation (GDPR) is

Alpenbahnen Spitzingsee GmbH
Spitzingsee Str. 12
83727 Schliersee-Spitzingsee

Telephone: +49 8026 929223-0
Fax: +49 8026 71156
E-mail: info@alpenbahnen-spitzingsee.de

You can reach our data protection officer using the following contact details

Felix Gebhard
FX DATA UG (limited liability)
Ottobrunner Str. 28
82008 Unterhaching
E-mail: dsb@fx-data.de

Collection, processing and use of personal data

The legal basis for the collection, storage and processing of personal data can be found in particular in the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG). Personal data is information that relates to an identified or identifiable natural person (Art. 4 No. 1 GDPR). This includes, in particular, names, address data, telephone numbers or email addresses. However, information about preferences, memberships or, for example, previously visited websites can also constitute personal data.

Making contact

If you contact us (e.g. by email), the data you provide will be stored for the purpose of processing your request and for possible follow-up questions. The legal basis for the processing is the necessity to carry out pre-contractual measures in accordance with Art. 6 para. 1 b) GDPR. We delete the data arising in this context after storage is no longer necessary, or restrict processing if there are statutory retention obligations.

Your rights

You have the following rights vis-à-vis us with regard to the personal data concerning you

- Right to information,
- Right to rectification or erasure,
- Right to restriction of processing,
- Right to object to processing,
- right to data portability.

You also have the right to complain to a data protection supervisory authority about the processing of your personal data by us.

Objection or revocation against the processing of your data

We would like to point out that you can revoke any consent you have given to the processing of your data at any time. Your revocation does not affect the data processing that has already taken place, but only has an impact on the processing in the future.

Insofar as we base the processing of your personal data on a balancing of interests within the meaning of Art. 6 para. 1 f) GDPR, you can object to the processing. A balancing of interests takes place in particular if the processing is not necessary for the performance of a contract with you. The legal basis for the respective data processing operations can be found in this privacy policy. When exercising such an objection, we ask you to explain the respective reasons. In the event of a justified objection, we will examine the situation and either cease or adapt the data processing or point out to you our compelling legitimate grounds on the basis of which we will continue the processing.

You can also object to the processing of your personal data for advertising and data analysis purposes at any time. You can inform us of your objection to advertising using the contact details above.

Data processing for contract processing

If you provide personal data when concluding contracts with us, for example when purchasing lift tickets or using mountain carts, this data will be processed exclusively for the purpose of processing the contract. The legal basis is Art. 6 para. 1 lit. b GDPR. The data will be deleted as soon as it is no longer required for the execution of the contract and any related follow-up questions and insofar as there are no statutory retention periods.

Transfer to third parties

We transfer your personal data to third parties if this is necessary for the execution of contracts. The legal basis for the transfer is the necessity to fulfill a contract in accordance with Art. 6 para. 1 b) GDPR. Personal data will not be passed on to third parties for marketing or advertising purposes without your express consent.

Server log files

Each time our website is accessed, information is stored in a log file by our hosting provider.These so-called log files contain information about retrieved files, status codes, time stamps and system information. This data is not personal and does not allow any conclusions to be drawn about a specific person.

IP addresses are also stored in log files. We cannot easily assign these to a specific person.

If you wish to view our website, we collect the aforementioned data, which is technically necessary for us to display our website to you and to ensure stability and security. The legal basis for the processing is the necessity to safeguard our legitimate interests in accordance with Art. 6 para. 1 f) GDPR.

Use of cookies

Our website uses so-called cookies. These are small files that are stored on your access device (computer, smartphone, tablet, etc.) and saved by your browser. They serve to increase the user-friendliness, effectiveness and security of our website. Cookies can also be used to collect statistical data on website usage and analyze it to improve the website. Cookies do not contain viruses and do not cause any damage to your access device.

You can block the storage of cookies in your browser. Most web browsers allow a certain amount of control over most cookies via the browser settings. However, we would like to point out that certain functions of our website may no longer be available to you or only to a limited extent if you block them.

In order to delete/deactivate all cookies stored on your computer, most browsers offer you the option of completely preventing the use of cookies or deleting cookies generated by specific domains/websites. You can find instructions on how to do this on your browser's help page:
- Chrome: https://support.google.com/chrome/answer/95647?hl=de
- Internet Explorer: https://support.microsoft.com/de-de/help/278835/how-to-delete-cookie-files-in-internet-explorer
- Firefox: https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen
- Safari on IOS: https://support.apple.com/de-de/HT201265
- Opera: http://help.opera.com/opera/Windows/2393/de/controlPages.html#manageCookies

MATOMO

This website uses the open source web analysis service Matomo. Matomo uses technologies that enable the cross-page recognition of the user to analyze user behavior (e.g. cookies or device fingerprinting). The information collected by Matomo about the use of this website is stored on our server. The IP address is anonymized before storage.

With the help of Matomo, we are able to collect and analyze data about the use of our website by website visitors. This enables us to find out, among other things, when which pages were accessed and from which region. We also record various log files (e.g. IP address, referrer, browser and operating system used) and can measure whether our website visitors perform certain actions (e.g. clicks, purchases, etc.).

The use of this analysis tool is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the anonymized analysis of user behavior in order to optimize both its website and its advertising. If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG, insofar as the consent includes the storage of cookies or access to information in the user's terminal device (e.g. device fingerprinting) within the meaning of the TTDSG. Consent can be revoked at any time.

IP anonymization

We use IP anonymization for the analysis with Matomo. Your IP address is shortened before the analysis so that it can no longer be clearly assigned to you.

Hosting

We host Matomo exclusively on our own servers so that all analysis data remains with us and is not passed on.

Facebook Pixel

This website uses the "Facebook pixel" of Facebook Inc, 1 Hacker Way, Menlo Park, CA 94025, USA ("Facebook"). If explicit consent is given, this allows the behavior of users to be tracked after they have seen or clicked on a Facebook ad. This process is used to evaluate the effectiveness of Facebook ads for statistical and market research purposes and can help to optimize future advertising measures.

The data collected is anonymous to us and does not allow us to draw any conclusions about the identity of the user. However, the data is stored and processed by Facebook so that a connection to the respective user profile is possible and Facebook can use the data for its own advertising purposes in accordance with the Facebook Data Usage Policy(https://www.facebook.com/about/privacy/). You can enable Facebook and its partners to place advertisements on and outside of Facebook. A cookie may also be stored on your computer for these purposes. These processing operations are only carried out with your express consent in accordance with Art. 6 para. 1 lit. a GDPR.

Consent to the use of the Facebook pixel may only be given by users over the age of 13. If you are younger, we ask you to ask your legal guardian for permission.

Facebook Inc., based in the USA, is certified for the US-European data protection agreement "Privacy Shield", which guarantees compliance with the level of data protection applicable in the EU.

To deactivate the use of cookies on your computer, you can set your Internet browser so that no more cookies can be stored on your computer in the future or cookies that have already been stored are deleted. However, disabling all cookies may mean that some functions on our website can no longer be carried out. You can also deactivate the use of cookies by third-party providers such as Facebook on the following Digital Advertising Alliance website: https://www.aboutads.info/choices/

Social media plugins

Plugins from social networks are integrated on some of our pages. We currently use the Facebook plugin.

We use plugins with the so-called two-click solution. This means that when you visit our site, no personal data is initially passed on to Facebook. The plugin gives you the opportunity to communicate directly with Facebook or your Facebook contacts via the button. Only if you click on the "Like" button and thereby activate it will Facebook receive the information that you have accessed the corresponding subpage of our website. By activating the plugin, personal data is therefore transmitted from you to Facebook and stored on servers in the USA.

We offer you the opportunity to interact with social networks and other users via the plugins so that we can improve our offering and make it more interesting for you as a user. The legal basis for the use of the plug-ins is Art. 6 para. 1 f) GDPR.

We have no influence on the data collected and data processing operations, nor are we aware of the full scope of data collection, the purposes of processing or the storage periods. We also have no information on the deletion of the data collected by the respective network. Further information on this can be found in the privacy policy of the respective network.

Data is passed on regardless of whether you have an account with Facebook and are logged in there. If you are logged in to Facebook, the data collected in this way will be assigned directly to your Facebook account. If you click the activated button and, for example, mark the page with "Like", Facebook also stores this information in your Facebook account and shares it publicly with your contacts. We recommend that you log out regularly after each use of Facebook.

Addresses of the respective network or plug-in providers and URL with their data protection notices:
- Facebook Inc, 1601 S California Ave, Palo Alto, California 94304,
USA; http://www.facebook.com/policy.php;
Further information on data collection:
http://www.facebook.com/help/186325668085084, http://www.facebook.com/about/privacy/your-info-on-other#applications
and http://www.facebook.com/about/privacy/your-info#everyoneinfo

Facebook has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework.

Integration of YouTube videos

We have integrated YouTube videos into our website, which are stored on http://www.YouTube.com and can be played directly from our website. These are integrated in "extended data protection mode", i.e. no data about you as a user is transferred to YouTube if you do not play the videos. Only when you play the videos will the data mentioned in the next paragraph be transmitted. We have no influence on this data transfer.

When you visit the website, YouTube receives the information that you have accessed the corresponding subpage of our website. This occurs regardless of whether YouTube provides a user account through which you are logged in or whether no user account exists. If you are logged in to Google, your data will be assigned directly to your account. If you do not wish your data to be associated with your YouTube profile, you must log out before activating the button. YouTube stores your data as usage profiles and uses them for the purposes of advertising, market research and/or the needs-based design of its website. You have the right to object to the creation of these user profiles, whereby you must contact YouTube to exercise this right.

Further information on the purpose and scope of data collection and processing by YouTube can be found in the privacy policy at this link: https://policies.google.com/privacy?hl=en.

Integration of Google Maps

We use the Google Maps service on this website. This allows us to show you interactive maps directly on the website and enables you to use the map function conveniently. The legal basis is Art. 6 para. 1 f) GDPR.

When you visit the website, Google receives the information that you have accessed the corresponding subpage of our website. In addition, further data such as your IP address is transmitted to Google. This occurs regardless of whether Google provides a user account through which you are logged in or whether no user account exists. If you are logged in to Google, your data will be assigned directly to your account. If you do not wish your data to be associated with your Google profile, you must log out before activating the button. Google stores your data as usage profiles and uses them for the purposes of advertising, market research and/or the needs-based design of its website. Such an evaluation is carried out in particular (even for users who are not logged in) to provide needs-based advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, whereby you must contact Google to exercise this right.

Further information on the purpose and scope of data collection and its processing by Google can be found in Google's privacy policy. There you will also find further information on your rights in this regard and setting options to protect your privacy: http://www.google.de/intl/de/policies/privacy.

Google also processes your personal data in the USA and has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework

Hotjar

This website uses Hotjar, an analysis software from Hotjar Ltd ("Hotjar") (http://www.hotjar.com, 3 Lyons Range, 20 Bisazza Street, Sliema SLM 1640, Malta, Europe). Hotjar makes it possible to measure and evaluate user behavior (clicks, mouse movements, scroll heights, etc.) on our website. The information generated by the "tracking code" and "cookie" about your visit to our website is transmitted to the Hotjar servers in Ireland and stored there. The following information is collected by the tracking code

Device-dependent data
- The IP address of your device (collected and stored in an anonymized format)
- Your email address, including your first and last name, if you have provided this to us via our website
- Screen size of your device
- Device type and browser information
- Geographical location (country only)
- The preferred language to display our website

Log data

- Referring domain
- Pages visited
- Geographical location (country only)
- The preferred language to display our website
- Date and time when the website was accessed

Hotjar will use this information for the purpose of evaluating your use of our website, compiling reports on website activity and providing other services relating to website activity and internet analysis. Hotjar also uses third-party services, such as Google Analytics and Optimizely, to provide its services. These third-party companies may store information that your browser sends when you visit the website, such as cookies or IP requests. For more information on how Google Analytics and Optimizely store and use data, please refer to their respective privacy policies.

If you continue to use this website, you consent to the aforementioned processing of data by Hotjar and its third-party providers in accordance with their privacy policies.

The cookies that Hotjar uses have different "lifespans"; some remain valid for up to 365 days, some remain valid only during the current visit.

You can prevent the collection of data by Hotjar by clicking on the following link and following the instructions there: www.hotjar.com/opt-out.

Links to other websites

Our online offer may contain links to other websites. We have no influence on whether their operators comply with data protection regulations.

Status: May 2022

Video surveillance

To ensure the safety of passengers and cable car operations and to prevent the misuse of tickets, the access areas are also monitored at times by a video system. This is indicated by signs. Recording is carried out exclusively to safeguard domiciliary rights and operational security interests. The legal basis is Art. 6 para. 1 lit. f GDPR. The data will be deleted immediately if it is no longer required to achieve the purpose. Further information on the processing of personal data can be found in the data protection information.