Skip to content

Privacy Policy

Last updated: 20 July 2026

AlpinResort Kaprun respects your privacy and handles personal data carefully and transparently. This Privacy Policy explains which personal data we collect, why we process it, how long we retain it, with whom it may be shared and which rights you have under the General Data Protection Regulation (“GDPR”) and applicable Austrian, Dutch and European data-protection legislation.

This Privacy Policy applies to:

https://www.alpinresortkaprun.at/

and to enquiries, direct reservations, guest communication, property-owner enquiries and related accommodation services handled by AlpinResort Kaprun.

1. Data controller

The controller responsible for processing personal data through this website and in connection with direct reservations is:

Limere B.V. / Connect73
Trading as: AlpinResort Kaprun
Kennemerstraatweg 614
1851 NK Heiloo
The Netherlands

Dutch Chamber of Commerce number: 57097585

Email: marcel@alpinresortkaprun.at
Telephone: +31 6 29013501

Official accommodation rental registration number for AlpinResort Kaprun:

50606-007295-2020

This registration number is displayed in accordance with the requirements of the municipality of Kaprun.

Where an individual apartment owner acts as the accommodation provider for a particular reservation, that owner may also act as an independent controller for the personal data required to fulfil the accommodation agreement. Relevant information will be included in the reservation confirmation or other booking documentation where applicable.

Questions about this Privacy Policy or the processing of your personal data may be sent to the email address above.

2. Personal data we process

Depending on how you use our website or services, we may process the following categories of personal data.

Website and technical data

When you visit the website, technical information may be processed automatically, including:

  • IP address;
  • browser type and version;
  • device type and operating system;
  • language settings;
  • date and time of access;
  • pages viewed;
  • referring website;
  • technical log and security information;
  • cookie and consent preferences.

Enquiry and contact data

When you contact us by email, telephone, WhatsApp or through a contact form, we may process:

  • your name;
  • email address;
  • telephone number;
  • the content of your message;
  • requested travel dates;
  • number and composition of guests;
  • accommodation preferences;
  • other information you voluntarily provide.

Please do not send sensitive personal information unless it is necessary for your request.

Reservation and guest data

When you request or make a reservation, we may process:

  • name and contact details of the person making the booking;
  • names and, where legally required, dates of birth or other identification details of accompanying guests;
  • home address and country of residence;
  • arrival and departure dates;
  • selected accommodation;
  • number and composition of guests;
  • booking reference;
  • booking price and payment status;
  • billing information;
  • communication and special requests relating to the stay;
  • guest-registration information required by competent authorities;
  • tourist-tax information;
  • details needed to provide agreed guest services.

We request only the information reasonably necessary to process the reservation, provide the accommodation and comply with applicable legal obligations.

Payment data

Depending on the selected payment method, payment information may be processed by a bank, payment-service provider, credit-card provider, PayPal or booking-system provider.

AlpinResort Kaprun does not normally receive or store complete credit-card details. Payment providers process such details under their own privacy policies and security procedures.

Property-owner enquiries

When an accommodation owner contacts us about rental, marketing or property-management services, we may process:

  • name and contact details;
  • address and details of the property;
  • ownership or authority information;
  • correspondence and meeting notes;
  • financial, tax or contractual information where required to assess or perform a cooperation agreement.

3. Purposes and legal bases

We process personal data only where there is a valid legal basis.

Handling enquiries

We process contact and enquiry data to answer questions, prepare offers and communicate with prospective guests or property owners.

The legal basis is taking steps at your request before entering into a contract and, where applicable, our legitimate interest in responding to enquiries and operating our business.

Processing reservations and providing accommodation

Reservation and guest data may be processed to:

  • check availability;
  • prepare and confirm reservations;
  • perform the accommodation agreement;
  • communicate before, during and after the stay;
  • coordinate check-in and check-out;
  • collect and administer payments;
  • provide booked services;
  • handle changes, cancellations, complaints or damage claims.

The legal basis is the performance of a contract or taking steps before entering into a contract.

Guest registration, tourist tax and legal administration

Certain guest and reservation information must be processed and, where required, submitted to Austrian municipal, tourism, tax or other competent authorities.

The legal basis is compliance with legal obligations.

Website operation and security

Technical data and strictly necessary cookies may be processed to:

  • deliver the website;
  • maintain website functionality;
  • protect the website against fraud, misuse and attacks;
  • diagnose technical errors;
  • maintain backups and system security;
  • remember privacy or language preferences.

The legal basis is our legitimate interest in providing a secure and functional website and, where applicable, compliance with legal obligations.

Analytics and non-essential external services

Where analytics, marketing technologies or non-essential third-party content are used, they are activated only in accordance with your consent preferences.

The legal basis is your consent. You may withdraw or change your consent at any time through the cookie settings on the website.

Withdrawing consent does not affect the lawfulness of processing that took place before the consent was withdrawn.

Accounting and legal claims

Reservation, payment, invoice and correspondence data may be processed and retained for accounting, taxation, auditing, fraud prevention, dispute resolution and the establishment, exercise or defence of legal claims.

The legal basis is compliance with legal obligations and our legitimate interest in protecting our legal and commercial interests.

Marketing communication

We send newsletters or promotional emails only where we have a valid legal basis, normally your separate consent.

Making a reservation does not automatically subscribe you to marketing communication. Marketing consent is voluntary and is not required to complete a booking.

You may withdraw your marketing consent at any time by using the unsubscribe option in the message or by contacting us.

4. Booking system and Smoobu

Direct reservations and availability searches may be processed through technology provided by Smoobu GmbH, a provider of accommodation-management and booking services.

When you use the booking function, personal data required for the enquiry or reservation may be transmitted to and processed within the Smoobu system. This may include:

  • contact details;
  • travel dates;
  • guest information;
  • selected accommodation;
  • booking price;
  • booking and payment status;
  • reservation-related correspondence.

Smoobu processes personal data on our behalf where it acts as a processor. In certain circumstances, Smoobu or an integrated payment or communication provider may process data under its own legal responsibility.

The information requested during the booking process is required to process the requested reservation. Without the required information, we may be unable to complete the booking.

5. Website hosting

The website is hosted using services provided by SiteGround.

For the purpose of making the website available, functional and secure, the hosting provider may process technical information such as:

  • IP addresses;
  • server requests;
  • access and error logs;
  • security events;
  • backup data.

The hosting provider processes this information under contractual data-protection and security obligations. Technical data may also be processed to detect and prevent misuse, malware, unauthorised access and other threats.

6. Cookies and consent settings

The website uses cookies and similar technologies.

Strictly necessary technologies

Strictly necessary cookies may be used without optional consent where they are required for:

  • core website functionality;
  • website and booking security;
  • booking-session functionality;
  • load balancing;
  • remembering language or consent choices;
  • preventing fraud or technical misuse.

These technologies cannot always be disabled through the cookie settings because the website or booking functionality may not work correctly without them.

Preferences, analytics and marketing

Preference, analytics, marketing and other non-essential technologies are used only where permitted by your consent settings.

When you first visit the website, you can accept, reject or manage non-essential categories through the consent banner.

You can change or withdraw your choices at any time through the permanent Cookie Settings or Manage Consent link on the website.

More detailed information about the cookies and services currently active on the website, including their purpose, provider and retention period, is available in the Cookie Policy or consent-management interface.

7. Analytics

Where website analytics are enabled and you have provided the required consent, usage information may be collected to understand how visitors use the website and to improve its content, performance and booking experience.

Depending on the configured service, analytics data may include:

  • an IP address or shortened IP address;
  • approximate location;
  • device and browser information;
  • visited pages;
  • session duration;
  • navigation and interaction information;
  • referral source;
  • conversion or booking interactions.

Analytics services must remain disabled before consent where consent is legally required.

8. Third-party content and external links

The website may contain links to or content from third parties, such as:

  • booking platforms;
  • payment providers;
  • review platforms;
  • map and route services;
  • weather or webcam services;
  • tourism organisations;
  • social-media or messaging services;
  • video or other embedded media.

Opening an external link takes you to a third-party website. That third party is responsible for its own processing of personal data.

Where external content is embedded directly into our website and can transmit information to a third party, that content will, where required, remain blocked until the necessary consent has been provided.

We recommend reviewing the privacy information of the relevant third party before using its services.

9. Google reviews and Trustindex

The website may display guest reviews originating from Google through a review-display service such as Trustindex.

Depending on the technical implementation, loading this content may cause technical information, including an IP address and browser information, to be transmitted to the review-widget provider or Google.

Where this service is not strictly necessary, it will be loaded only after the required consent has been provided.

Alternatively, review information may be displayed locally without establishing a direct connection between the visitor and the third-party provider.

10. WhatsApp, telephone and email communication

When you contact us through WhatsApp, telephone or email, your communication is processed to answer your request and, where relevant, to prepare or perform a reservation or business agreement.

WhatsApp is a service provided by a company within the Meta group. When you use WhatsApp, Meta may process communication metadata and other information under its own privacy terms.

You are not required to use WhatsApp and may contact us by email instead.

Email messages may pass through email and hosting providers. Please do not send complete payment-card details, passport copies or other sensitive documents by unsecured email unless we specifically request them and provide an appropriate transmission method.

11. Recipients of personal data

Where necessary for the purposes described in this Privacy Policy, personal data may be shared with:

  • the owner or accommodation provider responsible for the booked apartment;
  • local hosting, check-in, cleaning or guest-service partners;
  • Smoobu and connected booking-system providers;
  • payment-service providers, banks and credit-card providers;
  • website, hosting, security, backup and IT-service providers;
  • accountants, tax advisers, auditors and legal advisers;
  • email and communication providers;
  • competent municipal, tourism, tax, law-enforcement or other public authorities where legally required;
  • Booking.com, Airbnb or another booking platform when the reservation was made through that platform;
  • providers whose external services you have chosen to activate through your consent settings.

We do not sell personal data.

Service providers that process personal data on our behalf are required to process it only according to our instructions, apply appropriate security measures and comply with applicable data-protection law.

12. International data transfers

Some service providers or their group companies may be located outside the European Economic Area or may process information in countries that do not provide the same level of data protection as the European Union.

Where such a transfer takes place, we use an appropriate transfer mechanism where required, such as:

  • an adequacy decision of the European Commission;
  • EU Standard Contractual Clauses;
  • supplementary contractual, organisational or technical safeguards;
  • another legally permitted transfer mechanism.

Where processing is based on consent, relevant information may also be provided through the consent-management interface.

13. Data retention

We retain personal data only for as long as necessary for the purpose for which it was collected or for as long as required by law.

In general:

  • enquiry data is retained for as long as necessary to answer and follow up the enquiry;
  • unsuccessful booking enquiries are deleted or anonymised when they are no longer required, unless continued retention is justified;
  • reservation, payment and invoice information is retained for applicable accounting and tax-retention periods;
  • guest-registration information is retained for the period required under applicable Austrian legislation;
  • contractual correspondence may be retained for applicable limitation periods;
  • consent records are retained for as long as necessary to demonstrate the consent choice;
  • security logs are retained for a limited period unless an incident requires a longer investigation;
  • marketing data is retained until consent is withdrawn or the information is no longer required for the marketing purpose.

A request for deletion does not require us to erase information that must be retained to comply with a legal obligation or that is necessary for the establishment, exercise or defence of legal claims.

14. Data security

We take appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access.

Measures may include:

  • encrypted website connections;
  • access restrictions;
  • secure passwords and account management;
  • software updates;
  • backups;
  • malware and security monitoring;
  • processor agreements;
  • internal access limitations.

No internet transmission or storage system can be guaranteed to be completely secure. However, we review and improve our safeguards where reasonably necessary.

15. Your data-protection rights

Subject to the conditions and limitations of the GDPR, you may have the right to:

  • receive information about whether we process your personal data;
  • access the personal data we hold about you;
  • correct inaccurate or incomplete personal data;
  • request deletion of personal data;
  • request restriction of processing;
  • receive certain personal data in a structured, commonly used and machine-readable format;
  • object to processing based on legitimate interests;
  • withdraw consent at any time;
  • lodge a complaint with a competent supervisory authority;
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, where applicable.

Where processing is based on legitimate interests, you may object for reasons arising from your particular situation.

You may object to direct marketing at any time without providing a reason.

To exercise a right, contact:

marcel@alpinresortkaprun.at

We may ask for information necessary to verify your identity before responding. We will respond within the periods required by applicable legislation.

16. Supervisory authorities

You have the right to lodge a complaint with a competent data-protection supervisory authority.

Because Limere B.V. is established in the Netherlands, you may contact:

Autoriteit Persoonsgegevens
The Netherlands

You may also contact the Austrian supervisory authority in connection with processing relating to the Austrian accommodation activities:

Österreichische Datenschutzbehörde
Barichgasse 40–42
1030 Vienna
Austria

You may also contact the supervisory authority in the EU or EEA country where you normally reside or work.

17. Children’s data

The website and accommodation-booking service are not directed at children acting independently.

Information about minors may be processed where their details are required as accompanying guests for:

  • a reservation;
  • guest registration;
  • tourist-tax administration;
  • the provision of accommodation services.

Such information should be supplied by a parent, guardian or other authorised adult.

18. Automated decision-making

We do not use personal data to make decisions based solely on automated processing that produce legal effects or similarly significant effects for you.

Automated availability checks, booking confirmations, fraud-prevention checks or price calculations may be used as part of the reservation process, but you may contact us about the reservation at any time.

19. Changes to this Privacy Policy

We may update this Privacy Policy when our website, services, providers or legal obligations change.

The current version is always published on this website. The date at the top shows when the Privacy Policy was last updated.

20. Contact

For privacy questions, requests or complaints, please contact:

Limere B.V. / Connect73
Trading as: AlpinResort Kaprun

Kennemerstraatweg 614
1851 NK Heiloo
The Netherlands

Dutch Chamber of Commerce number: 57097585
Accommodation rental registration number: 50606-007295-2020

Email: marcel@alpinresortkaprun.at
Telephone: +31 6 29013501

No results found...