Privacy Policy and Information pursuant to the EU General Data Protection Regulation (GDPR)

The following information provides you with a comprehensive overview of the processing of your personal data (hereinafter referred to as "Data") and your associated data protection rights in connection with your visit to our website, the booking of our apartments, as well as our business communication.


1. Data Controller

The controller responsible for data processing on this website is:

Secura Real Consult Vermietung GmbH & Co KG
Christoph Böhmdorfer
Gusshausstraße 6, 1140 Vienna, Austria
Authorized Representative: Christoph Böhmdorfer
E-Mail: office@securareal.at
phone:+436763383385
Legal notice: https://www.vienna-experience.at/impressum//

We process your data strictly in accordance with the provisions of the GDPR as well as the Austrian Data Protection Act (DSG).


2. Legal Bases for Processing

We process your data only if at least one of the following conditions applies:

  • Consent (Article 6(1)(a) GDPR): You have given us your explicit consent to process data for a specific purpose (e.g., via the cookie consent banner or for a contact request).
  • Performance of a contract & pre-contractual measures (Article 6(1)(b) GDPR): We require your personal data for the performance or initiation of an accommodation contract (apartment booking).
  • Legal obligation (Article 6(1)(c) GDPR): If we are subject to legal obligations, such as the retention of invoices for tax purposes or reporting obligations for accommodation establishments.
  • Legitimate interests (Article 6(1)(f) GDPR): To safeguard our legitimate economic and technical interests (e.g., to ensure the secure, stable, and error-free operation of our website).

3. Storage Period and Erasure of Data

We generally retain your personal data only for as long as is strictly necessary for the provision of our services or as long as a legitimate interest persists. Thereafter, the data will be erased, unless statutory retention obligations apply (e.g., a 7-year retention period for accounting records and invoices under Austrian law).

We retain data protection-related correspondence (e.g., data subject access requests) for a period of 3 years for documentation purposes pursuant to Article 6(1)(c) GDPR in conjunction with Article 5(2) GDPR, as well as for the potential defense of legal claims.


4. Your Rights as a Data Subject

Provided the statutory requirements are met, you are entitled to the following rights pursuant to Articles 15 to 22 GDPR:

  • Right of access (Article 15 GDPR): You may request, free of charge and in writing, information as to whether and what personal data we have stored about you. For security reasons, we do not provide information over the telephone, as your identity cannot be unequivocally verified. Please submit your request to us in writing, stating your name and current address.
  • Right to rectification (Article 16 GDPR): You have the right to have inaccurate or incomplete data rectified.
  • Right to erasure (Article 17 GDPR): You may request the erasure of your data, provided that no statutory retention obligations preclude this.
  • Right to restriction of processing (Article 18 GDPR).
  • Right to data portability (Article 20 GDPR).
  • Right to object (Article 21 GDPR): You may object at any time to the processing of your data which is based on our legitimate interests.

If you believe that the processing of your data violates data protection law, you have the right to lodge a complaint with the competent supervisory authority. In Austria, this is the Austrian Data Protection Authority (Barichgasse 40-42, 1030 Vienna, E-Mail: dsb@dsb.gv.at).


5. Security of Data Processing (TLS Encryption)

To best protect your data against unauthorized access, we use secure TLS (Transport Layer Security) encryption throughout our website. You can recognize the active encryption by the closed padlock symbol in your browser's address bar. (Alternatively: "...by the closed lock symbol in the address bar of your browser.")


6. Data Transfer to Third Countries

We process and store data primarily on servers within the European Union (EU). Should data exceptionally be transferred to third countries (such as the USA), we ensure that this is done on the basis of legal safeguards – in particular through the EU-US Data Privacy Framework (provided the provider is certified) or the conclusion of EU Standard Contractual Clauses.


7. Webhosting and Server-Logfiles

When you visit our website, the web hosting provider automatically stores technical connection data (server log files) such as your IP address, browser type, operating system, referring URL, and the time of access. This is technically necessary to ensure the stability and security of the website. The legal basis for this is our legitimate interest pursuant to Article 6(1)(f) GDPR.


8. Cookie-Consent-Tool (Real Cookie Banner)

To manage the cookies and similar technologies used and to obtain the relevant consents, we use the consent tool "Real Cookie Banner". The legal bases for this processing are Article 6(1)(c) GDPR and Article 6(1)(f) GDPR (our legitimate interest in the legally compliant management of consents).

Sie können Ihre einmal getroffenen Privatsphäre-Einstellungen jederzeit über den Link "Privatsphäre-Einstellungen ändern" in der Fußzeile unserer Website anpassen oder widerrufen.


9. WooCommerce Privacy Policy

We use the shop system WooCommerce, provided by Automattic Inc. (60 29th Street #343, San Francisco, CA 94110, USA), on our website. WooCommerce processes personal data necessary for handling bookings (including name, billing address, email address, payment details, and IP address). This processing is carried out for the performance of a contract or in order to take steps prior to entering into a contract pursuant to Article 6(1)(b) GDPR. Automattic is certified under the EU-US Data Privacy Framework, which ensures an adequate level of data protection.


10. Booking System Privacy Policy

To efficiently manage our apartment bookings, we use the booking plugin "Bookings for WooCommerce". In doing so, we process the data you enter (name, email address, phone number, booking period, number of guests) for the processing of the accommodation contract on the basis of Article 6(1)(b) GDPR. The data will be deleted after the statutory tax and registration retention periods have expired.


11. Payment Provider

For the secure and convenient processing of payments, we offer various payment service providers on our website (e.g., credit cards, PayPal, eps). When you make a payment, your payment details are transmitted to the selected provider. The processing is strictly purpose-bound for the performance of a contract pursuant to Article 6(1)(b) GDPR.


12. Web Design, Local Fonts, and Icons

In order to present our website to you in a visually appealing and error-free manner, we use design resources (fonts and icons such as Font Awesome or Google Fonts). To ensure data protection and prevent unwanted data transfers to the USA, all fonts and icons used are hosted and loaded locally on our own server. In this context, no data is transferred to external servers (Article 6(1)(f) GDPR).


13. No Sensitive Data

In the context of operating this website and the booking process, we explicitly do not process or store any sensitive data categories pursuant to Article 9(1) GDPR (such as information regarding health, religious affiliation, or political opinions), nor do we process or store any data relating to criminal convictions and offenses pursuant to Article 10 GDPR.


14. No Automated Decision-Making (Profiling)

We do not use any mechanisms for fully automated decision-making or profiling measures on our website within the meaning of Article 22 GDPR.