Firmenlogo

Notice

The following privacy policy applies to the use of this booking page, which is operated via the bookingbird platform. The data controller is the respective provider operating this booking page (see Imprint). bookingbird, as the technical platform operator, provides the infrastructure and processes personal data solely as a data processor on behalf of the provider. bookingbird assumes no liability for the data protection compliance of the services offered through this booking page. Responsibility for compliance with data protection regulations rests solely with the respective provider.

1. Data Controller

The data controller within the meaning of the General Data Protection Regulation (GDPR) and other applicable data protection laws is the provider operating this booking page (hereinafter "Data Controller"). The contact details of the Data Controller can be found in the imprint of this booking page.<br/><br/>The Data Controller independently determines the purposes and means of processing personal data. bookingbird is not the data controller for the data collected through this booking platform.

2. Data Processor

For the operation of the online booking platform, the data controller engages bookingbird as a data processor within the meaning of Art. 28 GDPR. bookingbird processes personal data exclusively on behalf of and in accordance with the instructions of the data controller. Processing is based on a Data Processing Agreement (DPA) pursuant to Art. 28(3) GDPR.<br/><br/>vondot GmbH<br/>Contact: support@bookingbird.io<br/><br/>bookingbird provides the technical infrastructure for booking management but does not make independent decisions regarding the purposes and means of data processing. Data protection responsibility remains with the data controller named above.

3. Data Collected

The following personal data is collected and processed in connection with the use of the booking platform:<br/><br/><strong>a) Personal Information:</strong><br/>First and last name, email address, phone number (if provided by the user).<br/><br/><strong>b) Booking Data:</strong><br/>Type of service booked, date and time of booking, selected options, booking status, cancellation information.<br/><br/><strong>c) Payment Data:</strong><br/>Payment method, transaction identifiers, time of payment. Complete credit card or bank account details are processed exclusively by the payment service provider Stripe and are not stored on bookingbird or the data controller's servers.<br/><br/><strong>d) Technical Data:</strong><br/>IP address (anonymised), browser type and version, operating system, date and time of access. This data is collected solely to ensure the technical operation of the platform and to prevent misuse.

4. Legal Basis for Processing

The processing of personal data is based on the following legal grounds:<br/><br/><strong>a) Art. 6(1)(b) GDPR (Performance of a Contract):</strong><br/>The processing of personal and booking data is necessary for the performance of the contract between the user and the data controller or for the implementation of pre-contractual measures. Without this data, the booking cannot be processed.<br/><br/><strong>b) Art. 6(1)(f) GDPR (Legitimate Interests):</strong><br/>The processing of technical data is based on the legitimate interest of the data controller in ensuring the safe and stable operation of the booking platform and in preventing misuse.<br/><br/><strong>c) Art. 6(1)(c) GDPR (Legal Obligation):</strong><br/>Where statutory retention obligations exist (in particular tax and commercial law requirements), storage is based on legal obligations.

5. Purposes of Processing

The personal data collected is processed for the following purposes:<br/><br/><ul><li>Execution and management of bookings and provision of the services requested by the user</li><li>Processing of payments in connection with the booking</li><li>Communication with the user in the course of booking management (booking confirmations, reminders, cancellations)</li><li>Ensuring the technical operation and security of the platform</li><li>Fulfilment of statutory retention obligations</li><li>Where enabled by the provider: facilitating participant selection for bookings, whereby registered users can be searched by their first and last name by other signed-in registered users and added as participants to bookings</li></ul>

6. Participant Feature and Visibility

The booking platform may provide a participant feature that allows additional persons to be added to a booking. Where this feature is enabled by the provider, the following applies:<br/><br/>Registered users may be searched by other registered users of the same provider by their <strong>first and last name</strong> and added as participants to bookings. A search requires at least three typed letters; a match shows only the first and last name and, if present, the profile picture, never the email address, phone number, postal address or any other data. The search function is available exclusively to signed-in registered users of the respective provider and serves to facilitate the booking process for group bookings.<br/><br/>The legal basis for this processing is Art. 6(1)(b) GDPR (performance of a contract), insofar as participant selection is necessary in the context of the booking, as well as Art. 6(1)(f) GDPR (legitimate interest of the provider in efficient booking management).<br/><br/>By registering on this booking page, the user consents to their first and last name and their profile picture being visible to other registered users in the context of the participant search, where this feature has been enabled by the provider.

7. Third-Party Service Providers

The following third-party service providers are engaged to provide the booking service, to which personal data may be transmitted to the extent necessary:<br/><br/><strong>a) bookingbird (Platform Operator):</strong><br/>bookingbird provides the technical platform for online booking and processes data as a data processor pursuant to Art. 28 GDPR on behalf of the data controller. Servers are located within the European Union.<br/><br/><strong>b) Stripe (Payment Service Provider):</strong><br/>For the processing of online payments, the payment service provider Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, is engaged. Stripe processes payment data as an independent data controller. Stripe's privacy policy applies: <a href="https://stripe.com/privacy" target="_blank" rel="noopener noreferrer">https://stripe.com/privacy</a>.<br/><br/><strong>c) Email Services:</strong><br/>For the dispatch of booking confirmations and booking-related communications, email service providers may be engaged who act as data processors on behalf of the data controller.

8. Cookies and Tracking

The booking platform uses only technically necessary cookies that are required for the proper operation of the platform. These cookies serve in particular for session management and the storage of user preferences.<br/><br/><strong>No tracking cookies</strong> or analytics tools that monitor user behaviour beyond the booking platform are employed. No usage data is shared with advertising networks or other third parties for marketing purposes.<br/><br/>If the data controller uses their own analytics or tracking tools on their website that also affect the booking platform, the data controller is obligated to inform users separately and, where applicable, to obtain the necessary consent from users.

9. Data Retention

Personal data is retained only for as long as is necessary for the fulfilment of the stated purposes or as required by statutory retention obligations.<br/><br/><strong>Booking Data:</strong> For the duration of the business relationship and subsequently for the duration of statutory retention periods (typically 7 years under Austrian tax and commercial law, § 132 BAO, § 14 UGB).<br/><br/><strong>Payment Data:</strong> For the duration of statutory tax retention periods (typically 7 years under § 132 BAO).<br/><br/><strong>Technical Data:</strong> Typically deleted within 90 days of access, unless security incidents require longer retention.<br/><br/>Upon expiry of the respective retention periods, data is routinely deleted or anonymised.

10. Rights of Data Subjects

Data subjects have the following rights vis-a-vis the data controller regarding their personal data:<br/><br/><strong>a) Right of Access (Art. 15 GDPR):</strong><br/>You have the right to obtain information about the personal data processed concerning you.<br/><br/><strong>b) Right to Rectification (Art. 16 GDPR):</strong><br/>You have the right to request the rectification of inaccurate personal data or the completion of incomplete personal data.<br/><br/><strong>c) Right to Erasure (Art. 17 GDPR):</strong><br/>You have the right to request the erasure of your personal data, provided the conditions of Art. 17 GDPR are met. This right does not apply where processing is necessary for compliance with a legal obligation.<br/><br/><strong>d) Right to Restriction of Processing (Art. 18 GDPR):</strong><br/>You have the right to request the restriction of processing of your personal data under the conditions of Art. 18 GDPR.<br/><br/><strong>e) Right to Data Portability (Art. 20 GDPR):</strong><br/>You have the right to receive the personal data concerning you, which you have provided to the data controller, in a structured, commonly used, and machine-readable format.<br/><br/><strong>f) Right to Object (Art. 21 GDPR):</strong><br/>You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is based on Art. 6(1)(f) GDPR. The data controller shall no longer process the personal data unless they demonstrate compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject.<br/><br/>To exercise your rights, please contact the data controller named above. bookingbird, as a data processor, is not the appropriate point of contact for the exercise of your data subject rights but will forward any such requests to the data controller.

11. Right to Lodge a Complaint with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing of personal data relating to you infringes the GDPR (Art. 77 GDPR).<br/><br/>The competent supervisory authority in Austria is the Austrian Data Protection Authority: <a href="https://www.dsb.gv.at" target="_blank" rel="noopener noreferrer">www.dsb.gv.at</a>.