Privacy Policy

1. Controller

The controller responsible for the processing of personal data on this website is:

Bad Rock GmbH
Bahnhofplatz 5
5640 Bad Gastein
Austria

Registered office: 5020 Salzburg
Company Register Number: FN 564037 t
Company Register Court: Salzburg
VAT ID: ATU78953018

Owner: Nataliya Bunova

Telephone: +43 664 944 6215
Email: reservierung@nati-ivo.com

2. General Information

We take the protection of your personal data seriously.

We process personal data exclusively in accordance with applicable data protection legislation, in particular the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).

This Privacy Policy explains which personal data may be processed when you use our website, for what purposes this takes place and which rights you have as a data subject.

3. Visiting Our Website

When you visit our website, technical data may be processed where this is necessary for the secure and technically proper operation of the website.

This may include:

  • IP address
  • date and time of access
  • pages visited
  • browser used
  • operating system
  • technical access data

This processing is carried out primarily to ensure the technical operation and security of our website.

4. Contacting Us

If you contact us by email or via a contact form provided on our website, we process the personal data you provide in order to handle your enquiry and communicate with you.

This may include your name, email address, telephone number and any other information you voluntarily provide.

5. Reservation and Booking Enquiries

If you contact us regarding accommodation or a stay, personal data may be processed where this is necessary to handle your enquiry and, where applicable, to arrange a booking.

This may include:

  • name
  • contact details
  • dates of stay
  • number of guests
  • other information you provide as part of your enquiry

The processing takes place for the purpose of handling your enquiry and, where applicable, taking pre-contractual measures or performing a contract.

6. Cookies

Our website uses cookies and similar technologies.

Cookies are small text files that may be stored on your device.

We distinguish between technically necessary cookies and cookies or similar technologies for which your consent is required.

Technically necessary cookies may be used where they are required for the operation of the website. For technically non-essential cookies and similar technologies, your consent is obtained in advance where legally required.

You can change your cookie settings or withdraw previously given consent at any time.

7. Cookie Consent Management

We use Complianz on our website to manage consent for cookies and similar technologies.

This may involve storing information about the cookie settings you have selected.

This information is used to respect your decision and to ensure that the relevant technologies are activated or not activated according to your preferences.

8. Google Fonts

Google Fonts may be used to display fonts on our website.

We use OMGF (Optimize My Google Fonts) to optimise the integration of Google Fonts.

Required font files are intended to be provided locally from our own web server where possible, in order to avoid unnecessary transmission of data to external servers.

The fonts actually used on the published website depend on the design and content of the website.

9. WordPress and Beaver Builder

Our website is based on WordPress and is designed and managed using Beaver Builder.

As part of the technical operation of the website, data may be processed where this is necessary for the provision, security and functionality of the website.

10. Multilingual Website

Our website is available in several languages.

We use Polylang to manage and display the different language versions of the website.

Technical information may be processed where this is necessary to select and display the appropriate language version.

11. Data Security

We implement appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access and other security breaches.

12. Legal Bases for Processing

Depending on the specific purpose, personal data may be processed on the following legal bases:

  • Article 6(1)(a) GDPR – consent
  • Article 6(1)(b) GDPR – performance of a contract or pre-contractual measures
  • Article 6(1)(c) GDPR – compliance with a legal obligation
  • Article 6(1)(f) GDPR – legitimate interests

The applicable legal basis depends on the specific purpose of the processing.

13. Disclosure of Personal Data

Personal data will only be disclosed to third parties where this is necessary for the performance of a contract, compliance with a legal obligation, based on your consent or where there is another legally permissible basis for doing so.

Where external service providers are used, they are engaged in accordance with applicable data protection requirements.

14. Retention Period

Personal data is stored only for as long as necessary for the respective purpose.

In addition, statutory retention obligations may require certain data to be stored for longer periods.

After the applicable retention periods have expired, the data will be deleted unless there is another legal obligation to retain it.

15. Your Rights

Subject to the applicable legal requirements, you have the following rights in particular:

  • right of access
  • right to rectification
  • right to erasure
  • right to restriction of processing
  • right to data portability
  • right to object
  • right to withdraw consent

The Austrian Data Protection Authority confirms these data subject rights under the GDPR, including the rights of access, rectification, erasure, restriction, data portability and objection.

If you have given consent to the processing of your personal data, you may withdraw that consent at any time with effect for the future.

16. Right to Lodge a Complaint

If you believe that the processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with the competent data protection supervisory authority.

Austrian Data Protection Authority
Barichgasse 40–42
1030 Vienna
Austria

Telephone: +43 1 52 152-0
Email: dsb@dsb.gv.at

17. Changes to This Privacy Policy

We reserve the right to amend this Privacy Policy if legal requirements, technical circumstances or the services used on our website change.

The current version published on this website shall apply.

Last updated: October 2026