Privacy Information
This English version is a courtesy translation — the German version is legally binding.
Controller
SHH GmbHTriesterstraße 377
8055 Graz, Austria
Phone: +43 316 3410 11
Email: privacy@shh-hotels.com
The controller as defined by the General Data Protection Regulation (GDPR) is SHH GmbH.
General Information on Data Processing
Protecting your personal data matters greatly to us. We process personal data exclusively within the framework of applicable data protection laws, in particular the GDPR, the Austrian Data Protection Act (DSG), and the Austrian Telecommunications Act 2021 (TKG 2021). This privacy notice describes what data we collect, how we process it, and what rights you have. We use technical and organisational measures (TOMs) to protect your data against loss, misuse, unauthorised access, or disclosure.
Purposes and Legal Bases for Processing
We process personal data exclusively for the following purposes:
- Operation, security, and optimisation of our website
- Communication with guests, prospective guests, and partners
- Booking, accommodation, billing, and guest management
- Fulfilment of legal obligations, in particular under registration and tax law
- Marketing, analytics, and advertising purposes (only with consent)
- Safeguarding legitimate interests (e.g. IT security, improving service quality)
Legal bases pursuant to Art. 6(1) GDPR:
- lit. a – consent
- lit. b – contract / pre-contractual measures
- lit. c – legal obligation
- lit. f – legitimate interest
Hosting
Our website is operated by a hosting provider acting as processor (Art. 28 GDPR): Host Europe GmbH, Hansestraße 111, 51149 Cologne, Germany. The servers are located in a data centre within the European Union. Purpose: operation, delivery, and maintenance of the website. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and stable operation). The provider processes data exclusively on our instructions. When you visit the website, server log files are automatically recorded (including IP address, date and time, page accessed, amount of data transferred, HTTP status code, referrer, and browser and operating system type) and are generally deleted after 30 days. More information: hosteurope.de/Datenschutz
Cookie Consent (Consent Banner)
When you first visit our website, a cookie banner is shown that lets you accept or decline optional services (statistics, marketing, maps) individually. Necessary cookies are required for operation and are always active. We store your choice in a cookie (“shh_consent”, retention period approx. 6 months) as evidence of your consent; the respective services are only loaded after you have given your consent. You can change or withdraw your consent at any time via the “Cookie Settings” link in the footer. Legal basis: § 165(3) TKG 2021 and Art. 6(1)(a) GDPR (consent); for necessary cookies, Art. 6(1)(f) GDPR.
Security and Encryption
Our website uses SSL/TLS encryption (HTTPS). Server logs (e.g. IP address, timestamp, browser, referrer) serve security, error analysis, and maintenance purposes. Legal basis: Art. 6(1)(f) GDPR.
Web Analytics and Tag Management
a) Google Analytics 4
Provider: Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland. We use Google Analytics 4 to compile anonymous statistics on the use of our website. IP addresses are anonymised (IP masking). Legal basis: consent (Art. 6(1)(a) GDPR). Transfer to third countries: USA (SCC). More information: policies.google.com/privacy
b) Google Tag Manager
Manages and controls tracking scripts; does not itself process any personal data. Legal basis: Art. 6(1)(f) GDPR.
c) Microsoft Clarity
Provider: Microsoft Corporation, One Microsoft Way, Redmond WA 98052, USA. Collects pseudonymised interaction data (mouse movements, scrolling, clicks) to improve usability. Personal input (form fields, etc.) is masked. Legal basis: consent (Art. 6(1)(a) GDPR). Transfer to third countries: USA (SCC). More information: privacy.microsoft.com
Online Marketing Tools
a) Google Ads / Conversion Tracking
Measurement and optimisation of our advertising campaigns. Legal basis: consent (Art. 6(1)(a) GDPR). Transfer: USA (SCC).
b) Meta-Pixel (Facebook / Instagram)
Provider: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland. Collects pseudonymous usage data for evaluation and campaign optimisation. Legal basis: consent (Art. 6(1)(a) GDPR). Transfer: USA (SCC). More information: facebook.com/privacy/policy
c) TikTok-Pixel
Provider: TikTok Technology Ltd., 10 Earlsfort Terrace, Dublin 2, Ireland. Used to measure the performance of advertisements. Legal basis: consent (Art. 6(1)(a) GDPR). Transfer: outside the EEA (SCC). More information: tiktok.com/legal/privacy-policy
Email Marketing / Newsletter (Brevo)
We use Brevo GmbH, Köpenicker Straße 126, 10179 Berlin, Germany, to send and evaluate newsletters and information emails. Data: email address, name, time of consent (double opt-in), open/click statistics (only with consent). Purpose: sending information and evidencing consent. Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contractual communication). Security: processing within the EU; SCCs for sub-processors in third countries. More information: brevo.com/de/legal/privacypolicy
Fonts (Adobe Fonts / Local)
For a consistent appearance, we use Adobe Fonts (Typekit) or locally stored web fonts. Provider: Adobe Systems Software Ireland Ltd., 4–6 Riverwalk, Citywest Business Campus, Dublin 24, Ireland. Legal basis: Art. 6(1)(f) GDPR. More information: adobe.com/de/privacy/policies/adobe-fonts.html
Booking and Guest Systems
Booking Engine – myIBE (detco GmbH)
For online reservations, we use the “myIBE” booking engine by detco GmbH, Haferwende 36, 28357 Bremen, Germany. The data required for the booking is processed (e.g. name, address, travel dates, contact and payment information). Purpose: carrying out and managing online bookings. Legal basis: Art. 6(1)(b) GDPR (performance of contract). Security: data processing agreement (Art. 28 GDPR). More information: detco.de/datenschutzerklaerungen
Property Management System (PMS) – Apaleo
Apaleo GmbH, Dingolfinger Straße 15, 81673 Munich, Germany. Manages reservations, guest data, invoices, and check-in/check-out. Data: master and billing data, communication information, payment and log data. Purpose: performance of the accommodation contract, legal obligations. Legal basis: Art. 6(1)(b) and (c) GDPR. Security: data processing agreement (Art. 28), SCCs, GDPR and SOC 2 compliance. More information: apaleo.com/privacy
Guest Registration Systems
Feratel Media Technologies AG, Maria-Theresien-Straße 8, 6020 Innsbruck, Austria. Neuhold Datensysteme GmbH, Nordweg 9, 8077 Gössendorf, Austria. Process registration data required by law (name, date of birth, nationality, travel dates). Purpose: fulfilment of the registration obligation under Austrian registration law. Legal basis: Art. 6(1)(c) GDPR. Recipients: authorities and tourism boards. Security: data processing agreement, server location Austria.
AI Concierge (Chat Assistant)
On our website we offer a digital concierge (chat assistant) that answers questions about our houses and services. To generate the answers we use the AI service “Claude” provided by Anthropic PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA. When you actively use the chat and send a message, your input is transmitted to Anthropic for the purpose of generating a reply and processed there. Please do not enter sensitive personal data in the chat. Purpose: answering visitor enquiries. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in an up-to-date service), or Art. 6(1)(b) GDPR for pre-contractual communication. Transfer to third countries: USA (on the basis of Standard Contractual Clauses, SCC). According to the provider, Anthropic does not use content submitted via the API to train its models. A technical IP-based rate limit protects against misuse. If you use “Forward to the team”, your message is sent to us by email via our sending provider (Brevo). More information: privacy.anthropic.com
Recipients of Data
Recipients are exclusively commissioned processors (e.g. Host Europe, detco/myIBE, Apaleo, Brevo, Anthropic) as well as bodies required by law (authorities). All processors are contractually bound under Art. 28 GDPR.
Storage Period and Deletion
Data is stored only for as long as necessary for the respective purpose or as required by law. Once the purpose no longer applies or the relevant periods expire, data is deleted or anonymised. Typical periods: 7 years (accounting), registration data as required by law, technical logs max. 6 months.
Rights of Data Subjects
You have the right to:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing (Art. 21 GDPR)
- Withdraw your consent with effect for the future (Art. 7(3) GDPR)
To exercise your rights, please contact: privacy@shh-hotels.com
Right to Lodge a Complaint
You have the right to lodge a complaint with the competent supervisory authority if you believe that the processing of your data infringes data protection law. The competent authority in Austria:
Austrian Data Protection AuthorityBarichgasse 40–42
1030 Vienna
Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Website: dsb.gv.at
Changes to This Privacy Notice
We reserve the right to amend this privacy notice if changes in the legal situation, technical changes, or new service providers make this necessary.






