Data Protection

Privacy statement & data protection officer

We appreciate your interest in our website.

 

This privacy statement informs you about the processing activities of your personal data in the context of our website.

 

The protection of your personal data and of your privacy is very important to us. Therefore, we process your data exclusively on the basis of the existing legal provisions [Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of data, and repealing Directive 95/46/EC (GDPR), Data Protection Act 2018 (DSG 2018), ePrivacy Directive, Telecommunications Act 2003 (TKG 2003)].

 

1.  Controller and data protection officer

 

Pursuant to Article 4 (7) of the GDPR, the controller for this website is VAMED Standortentwicklung & Engineering GmbH (VAMED).

 

If you have any questions about the processing of your data by VAMED, you can contact us as indicated below:

 

  • by mail to: VAMED Standortentwicklung & Engineering GmbH (VAMED), Sterngasse 5, 1230 Vienna, Austria
  • by email to: datenschutz@vitality-world.com

 

The contact details of the VAMED Data Protection Officer are:

Mag. Per-Oliver Gustavson

Sterngasse 5, 1230 Vienna, Austria

Tel: +43 1 60127 0

datenschutz@vitality-world.com
 

2.  Processing of personal data when visiting the website

2.1  Processing of access data

 

When you visit our website, we store the access data in so-called web server log files. In addition, log entries are created in the Drupal 8 system. We collect the following data from you:

 

  • IP address
  • Date and time of access
  • Browser
  • Language settings
  • Operating system
  • Referrer URL
  • Your Internet service provider

 

Purpose of data processing

These data are statistically evaluated to further improve our online offer and make it more user-friendly, to find and fix bugs faster, and to control server capacity. Only in case of a concrete indication of illegal use of our website, we will use this data in a personal form for the purpose of prosecution.

 

Duration of storage

Your data will only be stored for a period of 3 years.

 

Legal basis

The legal basis for the processing of access data is the legitimate interest of VAMED (online service offer & data security) pursuant to Article 6 (1) (f) of the GDPR.

2.2  Cookies

 

2.2.1  Use of cookies

 

In order to make the visit to our website as attractive as possible and to enable the use of certain functions, we use so-called cookies on various pages. These are small files that are stored on your device. They allow us to recognize your browser on your next visit. The cookies are set in accordance with EU and Austrian law (Art. 5 (3) E-Privacy Directive and Art. 96 (3) TKG 2003). You can set your browser in the way that you are informed about the setting of cookies and individually decide on their acceptance or exclude the acceptance of cookies for specific cases or in general. However, disabling cookies may limit the functionality of our site.

 

Legal basis
The legal basis for setting cookies is for cookies that are required to display the website or to offer a service you have requested, pursuant to Article 6 (1) f GDPR, VAMED's legitimate interest in providing this website to you and the corresponding offers (Section 96 (3) 3rd sentence of the Telecommunications Act). For all other cookies, the data processing is based on your express consent in the cookie banner (Article 6 (1) lit a GDPR; Section 96 (3) 2nd sentence TKG), which you can change or revoke at any time using the link below entitled "My data protection settings". You can find more information about the cookies on our website here:

 

More information on cookies

 

2.2.2  Individual data protection settings

 

MY DATA PROTECTION SETTINGS

 

3.  Linking

The website includes links to other websites. These references to websites of other Internet users are provided as a service to cover wider information needs of the accessing party. VAMED has no influence on their content. VAMED assumes no liability for this content. The provider of the linked website is exclusively responsible for the content and correctness of the information provided there.

 

4.  VAMED Vitality Club

 

Data processing
The following personal data from participation in the VAMED VitalityClub (in short: "the data")

  • Name
  • Salutation
  • Title
  • Number of persons living in household
  • Address
  • E-Mail address
  • Telephone number
  • Date of birth
  • Sprache
  • Information on the newsletter
  • VVW Club account data
  • VVW Resort at which the customer has registered
  • Registration date

will be processed by VAMED Standordentwicklung and Engineering GmbH or the VAMED Vitality World Resort (VVW Resorts) at which the customer registered, and will be shared with the other resorts participating in the VAMED VitalityClub (which include:) Aqua Dome Tirol Therme Längenfeld GMBH & CO KG, TAUERN SPA WORLD Betriebs GmbH & Co KG, TBG Thermenzentrum Geinberg Betriebs GmbH, TBL Therme Laa a.d. Thaya – Betriebsgesellschaft m.b.H, Therme Wien GmbH & Co KG, Heilbad Sauerbrunn Betriebsgesellschaft m.b.H., Therme Seewinkel Betriebsgesellschaft m.b.H., Gesundheitsresort Gars Betriebs GmbH, as well as VAMED Standortentwicklung and Engineering GmbH).  

 

The management of the VAMED VitalityClub participation program and customers’ VAMED VitalityClub accounts requires the electronic processing of the respective data and their exchange with other VVW resorts (e.g. for crediting bonus points, for customers using them at other VVW resorts). If these data are not provided, membership in the VAMED VitalityClub is not possible.

 

Purpose of data processing
The purposes of the data processing are

  • the management of the customers’ VAMED VitalityClub accounts,
  • the administration of benefits from the VAMED VitalityClub card
  • customer care
  • and  - provided the customer has agreed to it – the marketing of VVW Resorts’ products and services, special offers and events, including the VVW Resorts’ news (by means of marketing material sent by regular mail, e-mail, text message, and telephone calls).


Legal basis
The processing of data for the membership administration of the VAMED VitalityClub is based on Art. 6 (1) (b) of the EU General Data Protection Regulation (performance of a contract). The processing of data for marketing purposes is based on Art. 6 (1) (a) of the Regulation (consent by data subject).


Data transmission
The data is forwarded on behalf of the respective VVW Resort for the purpose of providing the electronic system for the VAMED VitalityClub card and for marketing purposes to Cards & Systems EDV-Dienstleistungs GmbH, mediasupport GmbH, kb-endlos Kroiss & Bichler GmbH and AUSTRIACARD AG, protel hotelsoftware GmbH, TravelClick, Inc., hi.one digital marketing OG. The data are not transferred to third parties other than the ones above.


Duration of storage
The data are stored for the duration of the customer's participation in the VAMED VitalityClub. In addition, the data is only stored as long as there are statutory retention periods, legal claims from the contractual relationship can be asserted, or other legitimate reasons justify further storage.

 

5.  Online-Shop
 

Data processing
As part of the business relationship when purchasing a VAMED Vitality World gift card/voucher, VAMED processes the following personal data (in short: "the data")

  • First name
  • Last name
  • Address
  • E-Mail address
  • Telephone number
  • Company, if applicable
  • Password, if applicable
  • Payment data (encrypted)
  • Customer account data (orders placed (articles, prices, IP addresses)
  • Any text or images or photos entered for print@home vouchers
  • Prepaid card queries (voucher number, date, IP address).

 

Purpose of data processing
The purpose of processing data are

  • the processing of the respective business case
  • and – provided the CUSTOMER has agreed to it – the marketing of VVW Resorts’ products and services, special offers and events, including the VVW Resorts’ news (by means of marketing material sent by regular mail, e-mail, text message, and telephone calls).


Legal basis
The processing of data for the respective business case is based on Art. 6 (1) (b) of the EU General Data Protection Regulation (“GDPR”) (performance of a contract). The processing of data for marketing purposes is based on Article 6 (1) (a) of the GDPR (consent).


Data transmission
The data will be sent to styleflasher GmbH (KR Martin Pichler-Str. 1, A-6300 Wörgl), Cards & Systems EDV-Dienstleistungs GmbH (Landstraßer Hauptstraße 5, 1030 Vienna), mediasupport GmbH (Lerchenfelder Straße 124/Top 6, 1080 Vienna) Usercentrics GmbH (Sendlinger Str. 7, 80331 Munich) and Datatrans AG (Kreuzbühlstraße 26, CH-8008 Zurich) on behalf of VAMED for the purpose of processing the business case, as well as for marketing purposes to hi.one digital marketing OG (Gurkgasse 43/ Top 2, 1140 Vienna), kbprintcom.at Druck + Kommunikation GmbH, (Gutenbergstraße 2, 4840 Vöcklabruck) and TravelClick (Via Augusta, 117, Barcelona 08006, Spain). The data are not transferred to third parties other than the ones above.


Duration of storage
The data are stored for the duration of the customer's participation in the VitalityClub. In addition, the data is only stored as long as there are statutory retention periods, legal claims from the contractual relationship can be asserted, or other legitimate reasons justify further storage.

 

6.  Request form for seminars

We look forward to hearing from you.
 

Data processing
When you contact us using the request form, VAMED processes your personal information indicated below:

  • VAMED Vitality World resort
  • number of participants
  • Company
  • Date
  • E-mail adress
  • notes (optional)

 

Purpose of data processing
The personal data that you provide when you contact us are processed for the purposes of

  • contacting you and
  • preparing an offer for an event inquiry.

 

Legal basis
The processing of your personal data for the purpose of contacting you is based on taking the necessary steps prior to entering into a contract pursuant to Article 6 (1) (b) of the GDPR.

 

Data transmission
The data will be transmitted to the VAMED Vitality World Resorts (AQUA DOME – Tirol Therme Längenfeld, TAUERN SPA Zell am See – Kaprun, SPA Resort Therme Geinberg, la pura women’s health resort kamptal, Therme Laa – Hotel & Silent Spa, Therme Wien, St. Martins Therme & Lodge, Gesundheitszentrum Bad Sauerbrunn) for the indicated purposes.

 

Duration of storage
The data will be stored until the end of the interest (e.g. by withdrawal of consent with one of the companies of the group), and in addition, until the expiry of the statutory retention and limitation periods and as long as other legitimate interests in retention exist.
 

7.  Registration for the newsletter

We look forward to your registering for our newsletter.
 

Data processing
As part of your registration for the newsletter, VAMED processes your personal data, as follows:

  • Salutation
  • Title
  • First name
  • Last name
  • E-mail adress

 

Purpose of data processing
The personal data you provide when registering for the newsletter will be processed for the purpose of sending you information about offers, services and invitations to events. 

 

Legal basis
The processing of data for marketing purposes is based on Article 6 (1) (a) of the GDPR (consent)

 

Data transmission
The data will be transmitted to hi.one digital marketing OG (Gurkgasse 43/Top 2, 1140 Vienna) on behalf of VAMED for the purpose of processing. The data are not transferred to third parties other than the ones above. These data are forwarded for the stated purposes.

 

Duration of storage
The data will be stored until the end of the interest (e.g. by withdrawal of consent with one of the companies of the group), and in addition, until the expiry of the statutory retention and limitation periods and as long as other legitimate interests in retention exist.
 

8.  Data security

The security of your personal data is very important to us.

 

Taking into account the state of the art in terms of technology, the implementation costs and the nature, scope, circumstances and purposes of the data processing, as well as the likelihood and severity of the risk to the rights and freedoms of natural persons, VAMED implements appropriate technical and organizational measures within the meaning of Article 32 of the GDPR.

 

In this sense, the following measures, inter alia, are taken to protect your data and to protect against loss, destruction, access, modification and distribution by unauthorized persons:

 

  • Ensuring the confidentiality, integrity, availability and resilience of systems and services related to data processing;
  • Ensuring rapid restoration of the availability of personal data in the event of a physical or technical incident;
  • Implementation of procedures for the periodic review, assessment and evaluation of the effectiveness of the technical and organizational measures to ensure the safety of the data processing.

 

Please note that we do not accept any liability for the disclosure of information due to errors that are not attributable or attributable to us in data transmission and/or unauthorized access by third parties.

 

9.  Your rights

You have the following rights as a user of our website:

 

  • Right of access to information (Article 15 of the GDPR): You have the right to obtain confirmation from VAMED as to whether your personal data are being processed. In addition, you have the right to further information about the specific purposes of the processing, the categories of the personal data concerned, the recipients or categories of recipients of the personal data concerned, the storage period, the right to erasure or rectification of your personal data or restriction of processing and the right to object to such processing, the right to lodge a complaint and the right to any available information as to their source.
  • Right to rectification (Article 16 of the GDPR): You have the right to obtain from VAMED the immediate rectification of your personal data. This right includes the rectification of inaccurate data and the completion of incomplete personal data.
  • Right to erasure (Article 17 of the GDPR): You have the right to obtain from VAMED the immediate erasure of your personal data, provided that the reasons stated in Article 17 (1) (a) to (f) of the GDPR (e.g. the purpose for processing no longer applies) and the processing of your personal data is no longer required.
  • Right to restriction of processing (Article 18 of the GDPR): In the cases mentioned in Article 18 of the GDPR (e.g. inaccuracy of the processed personal data, unlawfulness of the processing, etc.), you also have the right to obtain from VAMED the restriction of processing.
  • Right to data portability (Article 20 of the GDPR): You have the right to receive your personal data that you have provided to VAMED in a structured and commonly used format and to have VAMED transmit this data to another controller (e.g. to another law firm).
  • Right to object (Article 21 of the GDPR): You have the right to object at any time to the processing of your personal data on this website.
  • Withdrawal of consent (Article 7 of the GDPR): You have the option of withdrawing any consent given to VAMED at any time.
  • Right to lodge a complaint In addition, you can lodge a complaint at any time with the

    Austrian Data Protection Authority at:

    Österreichische Datenschutzbehörde [Austrian Data Protection Authority)
    Wickenburggasse 8
    1080 Vienna, Austria

    Telephone: +43 1 521 52-25 69
    E‑mail: dsb@dsb.gv.at

    With the exception of the right to lodge a complaint with the Austrian Data Protection Authority, you can assert your rights with VAMED at the following address:
    datenschutz@vitality-world.com