Book now
Choose language
EnglishDeutsch

Dolder Hotel AG privacy policy

This Privacy Notice informs users about the type, scope and purposes of the collection and use of personal data by the responsible provider Dolder Hotel AG, Kurhausstrasse 65, 8032 Zurich, Switzerland, E-Mail: privacy@dolderhotelag.com, Telephone: +41 44 456 60 00.

Cookie-Settings
Terms Of Use WiFi

1. WHAT IS THE SUBJECT OF THIS PRIVACY POLICY?

Dolder Hotel AG, Kurhausstrasse 65, 8032 Zurich («Dolder»), (hereinafter also «we», «us») collects and processes personal data that concern you but also other individuals (so-called «third parties»). We use the word «data» here interchangeably with «personal data».

«Personal data» means data relating to identified or identifiable individuals, and «processing» means any operation that is performed on personal data, such as collection, storage, use, alteration, disclosure and erasure.

In this Privacy Notice, we describe what we do with your data when you use our websites https://www.dolderhotelag.com/, https://www.thedoldergrand.com/, https://www.dolderwaldhaus.ch/, https://career.dolderhotelag.com/, https://www.theepicure.com/, any of our project or event websites or our other websites (in each case including all sub-sites) (collectively «websites»), obtain or use our services or products (such as overnight stays in rooms and suites, gastronomy, bar and catering offers, spa, wellness and beauty treatments, banquet, conference and wedding arrangements, concierge services as well as sports and leisure activities such as golf, tennis and the ice rink), interact with us in relation to a contract, communicate with us or otherwise deal with us, or are a shareholder / investor of ours. In addition, we may inform you about the processing of your data separately (e.g. in forms, terms and conditions or additional privacy notices).

If you disclose data about other persons (e.g. family members, work colleagues) to us, we assume that you are authorized to do so and that the relevant data is accurate. When you share data about others with us, you confirm that. Please make sure that these individuals have been informed about this Privacy Notice.

This Privacy Notice is aligned with the revised Swiss Data Protection Act (revFADP, SR 235.1), the associated Data Protection Ordinance (DPO, SR 235.11) as well as the requirements of the EU General Data Protection Regulation (GDPR, EU 2016/679). However, whether and to what extent these laws apply depends on each individual case.

 

2. WHO IS RESPONSIBLE FOR PROCESSING YOUR DATA?

Dolder is the controller for the processing under this Privacy Notice under data protection law, unless we tell you otherwise in an individual case.

Our address is:

Dolder Hotel AG
Kurhausstrasse 65
CH-8032 Zurich
+41 44 456 60 00
privacy@dolderhotelag.com

We have appointed the following additional positions:
Data Protection Representative in the EU according to Art. 27 GDPR:

VGS Datenschutzpartner GmbH
Am Kaiserkai 69
20457 Hamburg
Germany
info@datenschutzpartner.eu

You can also contact this party for privacy concerns.

 

3. WHAT DATA DO WE PROCESS?

We process various categories of personal data about you. The main categories of data are the following:

Master data: This is the basic data (e.g. name, address, email, phone number), identity and travel document data (e.g. passport or ID number, nationality, date of birth, visa details), additional information about you (e.g. your roles and business functions) as well as your relationship with us (e.g. hotel guest, restaurant or spa visitor, event organizer, supplier, service provider or employee of such etc.), bank details, payment information, photographs, copies of ID cards, guest and booking history, powers of attorney, signature authorizations and declarations of consent, and information about accompanying third parties (e.g. family members, travel companions, contact persons or authorized representatives). This may also include information regarding special needs and health data, such as food intolerances or mobility impairments.

Registration data: This is data that is generated in the course of a registration with us or that you provide to us in this context (e.g. user name, email address for guest or booking portals, Wi-Fi use, loyalty or newsletter programs), but also data that is generated in the course of competitions or when purchasing and redeeming vouchers, and, if applicable, access data in the course of access controls (e.g. access to certain hotel, club or spa areas).

Contract data: This is data that is collected in connection with a contract concluded by us or in the context of the provision of our services, such as travel dates, arrival and departure times, booked room or suite categories, reservations in our restaurants and bars, booked spa or wellness treatments, contractual arrangements for meetings, conferences, galas, celebrations or wedding arrangements including catering, transfer services used, data collected during the period leading up to the conclusion of the contract, information required for processing regarding invoicing, credit card guarantees, deposits or customer service, information about feedback, complaints or satisfaction as well as financial and payment data (e.g. payment terms, creditworthiness checks for major events, reminders and debt collection). In individual cases, this may also include health data (e.g. in the context of treatment agreements in the spa).

Communication data: This is data that is generated in connection with communication between us and with third parties (e.g. via contact form, email, telephone, letter or other means of communication), such as the content of emails or letters, your contact details as well as the metadata of the communication, and, if applicable, a copy of an ID document.

Technical data: This is data that is generated in the course of using our electronic offerings (e.g. website, Wi-Fi), such as the IP address, information about the operating system of your device, the region and the time of use. When using the guest Wi-Fi, technical information such as device name, IP address, network status, frequency band, role, signal quality, usage, Wi-Fi connection and VLAN may be recorded. This data serves the secure and stable operation as well as troubleshooting of the network. Personal content of the device, in particular files, photos, messages, contacts, passwords and browser content, is not read. Individual technical information, in particular the device name and the IP address, may under certain circumstances allow conclusions to be drawn about a person and is therefore processed in accordance with the applicable data protection regulations.

Behavioral and preference data: This is data about your behavior and your preferences, such as reactions to electronic communications, navigation on our website, interactions with our social media profiles, and participation in competitions or events. This also includes information that you or the person making the booking communicate to us in connection with your stay, for example room preferences, dietary habits, other personal preferences as well as information on allergies or intolerances. To the extent that such information allows conclusions to be drawn about your health, we treat it as sensitive personal data and process it only to the extent necessary for the respective purpose and permitted by law. This also applies to medical data that you disclose voluntarily, for example in the context of a medical history questionnaire in the spa. The data may, where applicable, be supplemented with information from publicly accessible sources or from third parties. For tracking, see Section 13.

Applicant data: This is all data that you provide to us as part of your application documents, such as information about education and degrees, grades, your professional experience, employment references and certificates as well as non-professional activities. In addition, we may obtain references from third parties, provided you have specified these references or have otherwise given us your consent to do so.

Other data: This may include, among other things, the following information and data: Data collected in connection with administrative or legal proceedings (e.g. files, evidence, etc.), data collected on the basis of health protection (e.g. as part of protection concepts), photographs, video or audio recordings that we produce or receive from third parties and in which you are recognizable (e.g. at events, through security cameras, etc.), access data or access rights (e.g. according to visitor lists, when you enter certain buildings or what access rights you have), participation in events or campaigns (e.g. competitions and events), when you use our infrastructure and systems. Data in connection with your status as a shareholder or investor of ours (e.g. information for various registers, the exercise of your rights and the holding of events, such as general meetings).

 

4. WHERE DOES THE DATA COME FROM?

From you: Much of the data set out in Section 3 is provided to us by you yourself (e.g. in the course of communicating with us, in connection with contracts or our services, through the use of our website and other services, etc.). You are generally not obliged to disclose your data; however, in individual cases provided for by law (e.g. for legally required identification or in the context of protection concepts), an obligation to disclose may exist. Where processing is based on your consent, you may revoke it at any time with effect for the future (see Section 6).

From third parties: As far as it is lawful, we can also obtain data from publicly accessible sources (e.g. debt collection registers, commercial registers, media or the internet including social media) or receive it from public authorities and from other third parties (e.g. credit agencies, address brokers, associations, contractual partners, internet analytics services, etc.). This includes in particular the following categories: master data, contract data and other data, but also all other data categories pursuant to Section 3 as well as data from correspondence and meetings with third parties. If you work for an employer, client or someone else who has a business relationship or other dealings with us, they may also make data about you accessible to us.

 

5. FOR WHAT PURPOSES DO WE PROCESS YOUR DATA?

Communication: In order to be able to communicate with you (e.g. to answer inquiries, in the context of consulting as well as the execution of contracts), we need to process data (in particular communication and master data, and registration data in connection with the services you use) from you. If we need or want to establish your identity, we collect additional data (e.g. a copy of an ID document). For this purpose, we use in particular communication data and master data, and registration data in connection with the services you use.

Initiation, administration and execution of contracts: In connection with the initiation, conclusion and execution of contracts with our hotel, spa and restaurant guests, event clients (e.g. holding seminars, weddings, galas), suppliers or other business partners, we process related personal data. This includes in particular reservation management for rooms, suites, gastronomy offers, conference and banquet halls as well as spa treatments, the organization of concierge services (e.g. limousine and transfer services, excursions, care services, bookings with external partners), the rental of vehicles and sports equipment (e.g. guest vehicles, e-bikes), the invoicing of consumption and other services or levies, checking creditworthiness and processing advance payments and credit card guarantees, customer care as well as the enforcement of legal claims arising from contracts (debt collection, legal proceedings, etc.), accounting and contract termination. For this purpose, we use in particular master data, contract data and communication data, as well as registration and technical data where applicable.

Marketing purposes and relationship management: For marketing purposes and relationship management, we process data, for example, to send our visitors and other customers, other contractual partners and other interested parties personalized advertising (e.g. in print, by email, on other electronic channels or by telephone) about products, services and other news from us and from third parties (e.g. from product partners), in connection with free services (e.g. invitations, vouchers, etc.) or as part of individual marketing campaigns (e.g. events, competitions, etc.). You can refuse such contacts at any time or refuse or revoke consent to be contacted for advertising purposes by notifying us (Section 2). With your consent, we can target our online advertising on the internet more specifically to you (see Section 13). This also includes interaction with existing customers and their contacts, which can be personalized on the basis of behavioral and preference data. As part of relationship management, we may also operate a customer relationship management (CRM) system in which we store the data of visitors and other customers and other business partners. For marketing purposes and relationship management, we process in particular communication, registration, behavioral and preference data.

Market research, improvement of our services and operations, and product development: In order to continuously improve our products and services (including our website) and to be able to respond quickly to changing needs, we analyze, for example, how you navigate through our website or which products are used by which groups of persons and in what way, and how new products and services can be designed (for further details, see Section 13). This gives us an indication of the market acceptance of existing products and services and the market potential of new products and services. To this end, we process in particular master data, behavioral and preference data, but also communication data and information from customer surveys, polls and studies and other information, e.g. from the media, social media, the internet and other public sources. As far as reasonably practicable, we use pseudonymized or anonymized data for these purposes.

Registration and security purposes as well as technical and physical access controls: In order to use certain offers and services (e.g. Wi-Fi), you must register (directly with us or via our external login service providers); for this purpose, we process data. Furthermore, we also collect additional personal data about you during the use of the offer or service, in particular technical data (e.g. IP address, device information, connection duration and usage behavior) as well as registration data (e.g. login time, services used). We continuously check and improve the appropriate security of our IT and our other infrastructure (e.g. buildings). We therefore process data, for example, for monitoring, controls, analyses and tests of our networks and IT infrastructures, for system and error checks, for documentation purposes and as part of security copies. Access controls include in particular physical access control, but in some cases also the control of access to electronic systems. For security purposes, we use optical video surveillance (CCTV without biometric evaluation) in publicly accessible indoor and outdoor areas, driveways, corridors and lobbies to protect our guests, employees, works of art and real estate from theft, unauthorized access and damage; we draw attention to this by means of signs. Furthermore, we maintain logs of card use via our electronic locking system, which can be assigned via our reservation system if necessary; we do not keep general visitor lists for recording building access. For this purpose, we process registration and technical data in particular, but also other data mentioned in Section 3. Processing is carried out in compliance with applicable technical and organizational measures.

Compliance with laws, directives and recommendations from authorities and internal regulations («Compliance»): We may process personal data as part of our compliance with laws (e.g. fulfillment of any accommodation reporting obligations under cantonal regulations and the Foreign Nationals and Integration Act, tax and levy law obligations, anti-money laundering as well as the implementation of security and protection concepts). In addition, data processing may take place in the course of internal investigations as well as external investigations (e.g. by a law enforcement or supervisory authority or an appointed private body). For this purpose, we process in particular master data, contract data and communication data, but under certain circumstances also behavioral data, technical data and data from the categories of other data. The legal obligations may be Swiss law, but also foreign regulations to which we are subject, as well as self-regulations, industry standards, our own «corporate governance» and official instructions and requests.

Risk management and corporate governance: We may process personal data as part of our risk management (e.g. to protect against fraudulent activities) and corporate governance, including our business organization (e.g. resource planning) and corporate development (e.g. acquisition and sale of business units or companies). For this purpose, we process in particular master data, contract data, registration data and technical data, but also behavioral and communication data.

Job application: If you apply for a position with us, we collect and process the relevant data for the purpose of reviewing the application, conducting the application procedure and, in the case of successful applications, for the preparation and conclusion of a corresponding contract. For this purpose, we process in particular master data and applicant data.

Further purposes: These further purposes include, for example, training and educational purposes, administrative purposes (e.g. master data management or accounting), safeguarding our rights, and evaluating and improving internal processes. The protection of other legitimate interests is also one of the further purposes, which cannot be named exhaustively. We also process data in connection with your position as a shareholder or investor of ours (e.g. information for various registers, the exercise of your rights and the holding of events, such as general meetings).

 

6. ON WHAT BASIS DO WE PROCESS YOUR DATA?

Depending on the situation and processing purpose, our processing of your data is based – to the extent necessary – on the following legal bases:

Contract: Insofar as we process data for the conclusion and execution of contracts that we conclude or have concluded for you or with you or your employer, client or other persons for whom you work, this is also the legal basis on which we process your data.

Legal obligations: We may further process your data based on applicable legal, regulatory and professional requirements with which we must comply. These include, for example, tax law obligations under the Federal Direct Tax Act (FDTA, SR 642.11), accounting retention requirements under the Swiss Code of Obligations (CO, SR 220), the reporting obligation to the cantonal aliens police under the Foreign Nationals and Integration Act (FNIA, SR 142.20) as well as obligations in connection with anti-money laundering under the Anti-Money Laundering Act (AMLA, SR 955.0). The legal obligations may be Swiss law, but also foreign regulations to which we are subject, as well as self-regulations, industry standards, our own «corporate governance» and official instructions and requests.

Legitimate interest: We may process your data based on our legitimate (or overriding) interest or a legitimate (or overriding) interest of a third party. This applies in particular in relation to the achievement of the purposes and objectives set out in Section 5 and for the implementation of related measures. Among other things, we have a legitimate (and overriding) interest in marketing our products and services and in gaining a better understanding of the markets relevant to us and our activities (in particular, in the efficient and secure handling of our processes and the further development of our activities), in the efficient and effective management of our company and in safeguarding the security of our systems, buildings and our interests vis-à-vis third parties.

Consent: If we ask for your consent to process data from you, this is the legal basis on which we process data from you. In doing so, we will inform you of the purpose of the processing. You may revoke consent at any time by notifying us in writing (by post or, unless otherwise specified or agreed, by email) (see Section 2 regarding our contact details). The revocation only takes effect for the future; the lawfulness of the processing carried out until the revocation is not affected thereby. Data that was lawfully collected on the basis of your consent prior to the revocation may continue to be processed by us to the extent that another legal basis (e.g. a legitimate interest or a legal obligation) permits this. Once we have received and processed the notice of revocation, we will no longer process your data for the purposes to which you originally consented, unless another legal basis applies.

Other legal bases: In specific cases, we may also carry out data processing based on other legal bases. If this is the case, we will inform you in each individual case.

 

7. WHAT IS THE SITUATION WITH PROFILING?

«Profiling» means a process by which personal data is processed automatically to analyze personal aspects or make predictions, e.g. to analyze a person’s personal interests, preferences and inclinations, or to predict likely behavior (Art. 5 para. f revFADP; Art. 4 no. 4 GDPR; see Annex A, Ch. 7.2).

For example, we perform profiling in connection with reservations and orders placed on our website (e.g. to determine which other services and products may be of interest to you based on your purchases). In particular, we use behavioral and preference data, technical data, and communication data (e.g. your response to advertisements and other communications) for this purpose. Profiling helps us to continuously improve and better tailor our offerings to your individual needs, plan our business activities, determine the likelihood that a transaction is fraudulent, and better assist you through our customer service. To improve the quality of our analyses and predictions, we may also profile, i.e., combine personal data from different sources to better understand you as an individual with your different interests and characteristics. In both cases, we ensure the proportionality and reliability of the results and take measures against possible abuse.

 

8. WITH WHOM DO WE SHARE YOUR DATA?

In connection with our contracts, the website, our services and products, our legal obligations or otherwise to protect our legitimate interests and the other purposes set out in Section 5, we may also disclose your personal data to third parties, in particular to the following categories of recipients:

 

Service providers: We work with service providers locally and abroad (third parties) who process data about you (i) on our behalf, (ii) under joint responsibility with us or (iii) data they have received from us under their own responsibility (e.g. IT providers, shipping companies, advertising service providers, cleaning companies, security companies, banks, insurance companies, debt collection companies, credit agencies, address checkers, consulting companies or lawyers). For the service providers used for the website, see Section 13.

Contractual partners, including customers: This refers to customers and other contractual partners of ours where transfer of your data arises from the provision of services (e.g. external concierge partners, intermediaries of limousine, transfer and excursion services, care services, external service providers for leisure and sports activities such as golf, tennis or Dolder Eis & Bad, cooperating ticket agencies, event, decoration and technical partners for weddings and banquets, or travel agencies and booking platforms). Recipients further include cooperation partners with whom we bundle offers or who act on our behalf. Insofar as such partners do not act as processors on our behalf, they generally process the data under their own responsibility.

Authorities: We may disclose personal data to offices, courts and other authorities (such as the cantonal aliens police) locally and abroad if we are legally obliged or entitled to do so or if this appears necessary to protect our interests. The recipients process the data under their own responsibility.

Other persons: This refers to other cases where the inclusion of third parties results from the purposes pursuant to Section 5. Other recipients are, for example, delivery addressees or third-party payees specified by you, third parties in the context of agency relationships (e.g. your lawyer or your bank) or persons involved in administrative or legal proceedings. If we cooperate with the media and transmit material to them (e.g. photos), you may also be affected by this under certain circumstances. In the course of business development, we may sell or acquire businesses, operations, assets or companies, or enter into partnerships, which may also result in the disclosure of data (including data about you, for example as a customer or supplier or as their representative) to the persons involved in those transactions. In the course of communication with our competitors, industry organizations, associations and other bodies, data may also be exchanged which may affect you.

All these categories of recipients may in turn involve third parties, so that your data may also become accessible to them. We can restrict processing by certain third parties (e.g. IT providers), but not by other third parties (e.g. authorities, banks, etc.).

We also allow certain third parties to collect personal data from you on our website and at events organized by us (e.g. media photographers, providers of tools that we have embedded on our website, etc.). Insofar as we are not decisively involved in these data collections, these third parties are solely responsible for them. If you have any concerns or wish to assert your data protection rights, please contact these third parties directly. See Section 13 for the websites.

 

9. IS YOUR PERSONAL DATA TRANSFERRED TO OTHER COUNTRIES?

We process and store personal data mainly in Switzerland and the European Economic Area (EEA). Occasionally, however, we may also disclose personal data to service providers and other recipients (see Section 13) that are located or process personal data outside of this area, generally in any country in the world. This includes countries that do not ensure a level of data protection comparable to that of Switzerland or the EEA (Art. 19 para. 4 revFADP; Art. 44 GDPR).

If a recipient is located in a country without adequate statutory data protection, we require that the recipient undertakes to comply with applicable data protection standards (for this purpose, we use the revised European Commission’s standard contractual clauses, which can be accessed here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj), unless the recipient is already subject to a legally accepted set of rules to ensure data protection and unless we cannot rely on an exception. An exception may apply in particular in the event of legal proceedings abroad, but also in cases of overriding public interests, if the performance of a contract requires such disclosure, if you have consented, or if the data has been made generally available by you and you have not objected to its processing.

Please also note that data exchanged via the internet is often routed through third countries. Your data may therefore be sent abroad even if the sender and recipient are in the same country.

 

10. FOR HOW LONG DO WE PROCESS YOUR DATA?

We process your data for as long as our processing purposes, the legal retention periods and our legitimate interests in processing for documentation and evidence purposes require or storage is technically required (e.g. in the case of backups or document management systems). If there are no legal or contractual obligations to the contrary, we will delete or anonymize your data after the storage or processing period has expired as part of our normal processes.

If no legal retention requirements exist in individual cases, we generally process personal data for the duration of the business relationship or contract term and then, depending on the applicable legal basis, for a further five, ten or more years. This corresponds to the period during which we can assert legal claims against third parties or third parties can assert legal claims against us. Ongoing or anticipated legal proceedings may result in processing beyond this period. Under Section 13.B you will find more information on the storage period of cookies.

 

11. HOW DO WE PROTECT YOUR DATA?

We take appropriate security measures to protect the confidentiality, integrity and availability of your personal data, to protect it against unauthorized or unlawful processing and to counteract the risks of loss, accidental alteration, unwanted disclosure or unauthorized access. However, security risks cannot be completely eliminated in general – a certain residual risk is unavoidable.

 

12. WHAT ARE YOUR RIGHTS?

Applicable data protection laws grant you the right to object to the processing of your data in certain circumstances, in particular for direct marketing purposes, for profiling carried out for direct marketing purposes and for other legitimate interests in processing.

To help you control the processing of your personal data, you also have the following rights in connection with our data processing, depending on the applicable data protection law:

  • The right to request information from us as to whether and what data we process from you;
  • the right to have us correct data if it is inaccurate;
  • the right to request erasure of data;
  • the right to request that we provide certain personal data in a commonly used electronic format or transfer it to another controller;
  • the right to withdraw consent, where our processing is based on your consent;
  • the right to receive, upon request, further information that is necessary for the exercise of these rights.

If you wish to exercise the above-mentioned rights against us, please contact us in writing, at our premises or, unless otherwise stated or agreed, by email; you will find our contact details in Section 2. In order for us to rule out misuse, we must identify you (e.g. by means of a copy of an ID document, to the extent that this is not possible by less extensive means).

You also have these rights in relation to other parties that cooperate with us under their own responsibility – please contact them directly if you wish to exercise rights in connection with their processing. Information on our key cooperation partners and service providers can be found in Section 8, further information in Section 13.

Please note that conditions, exceptions or restrictions apply to these rights under applicable data protection law (e.g. to protect third parties or trade secrets). We will inform you accordingly where applicable.

If you do not agree with the way we handle your rights or data protection, please let us or our Data Protection Officers (Section 2) know. In particular if you are located in the EEA, the United Kingdom or in Switzerland, you also have the right to lodge a complaint with the data protection supervisory authority in your country. You can find a list of authorities in the EEA here: https://edpb.europa.eu/about-edpb/board/members_en. You can reach the UK supervisory authority here: https://ico.org.uk/global/contact-us/. You can also contact the Federal Data Protection and Information Commissioner: https://www.edoeb.admin.ch/edoeb/en/home/the-fdpic/contact.html.

 

13. DO WE USE ONLINE TRACKING, ONLINE MARKETING TECHNOLOGIES AND SIMILAR TECHNOLOGIES?

On our website (including newsletter and reservation portal), we use various techniques (e.g. cookies, fingerprinting, tracking pixels and similar techniques) with which we and third parties engaged by us can recognize you during your use and, under certain circumstances, track you over several visits.

We use our own tools and sometimes third-party services, in particular to improve the functionality or content of our website (e.g. integration of videos or maps), to compile statistics and to display advertisements. This enables us and authorized third parties to provide you with a personalized web experience (e.g. personalized advertising, interactions on social media sites, etc.).

Non-essential cookies and comparable technologies are only activated after you have granted us your corresponding consent, provided that consent is required by law or we obtain such consent for the processing in question. You may change your preferences in the Consent Management System at any time with effect for the future or withdraw your consent. Revocation does not affect the lawfulness of the processing carried out up to the revocation.

13.A What are cookies and similar technologies?

A cookie is a small text file with an identifier (a sequence of letters and numbers) that is transmitted between the server and your system. This allows us and the third-party providers we engage or cooperate with to recognize visitors to our website and track them across multiple visits and across different websites. Cookies enable recognition of a specific device or browser and do not necessarily contain information that personally identifies a user. However, personal data that we or third-party providers engaged by us store from you (e.g. if you have a user account with us or these providers) may be linked to the information stored in and obtained from cookies and thus possibly to your person.

In addition to cookies, there are other similar techniques such as pixel tags and social media plug-ins. Pixel tags are small, usually invisible images or a program code that are loaded by a server and provide the server operator with certain information (e.g. access to a web page). We also reserve the right to use fingerprints. Fingerprints consist of information collected during your visit to the website about the configuration of your terminal device or your browser, which makes it possible to distinguish your terminal device from other devices. Social media plug-ins are small pieces of software that establish a connection between your visit to our website and a third party’s social media platform. The social media plug-in tells the third-party provider that you have visited our website and may transmit cookies to the third-party provider that it has previously placed on your web browser. For more information about how these third-party providers use your personal data collected via social media plug-ins, please refer to their respective privacy notices.

13.B What types of cookies do we use?

 

Technically necessary technologies are required for the secure and technically functional operation of our websites or for a function explicitly requested by you.

The cookies and similar technologies we use on our websites serve the following purposes (similar techniques are included in each case):

Necessary cookies: Some cookies are essential for the use of the website and its functions. These cookies ensure the essential functionality of the website, e.g. the ability to navigate from page to page without the products placed in the shopping cart disappearing. They also ensure that you remain connected to the website. These cookies have an expiration time of up to 24 months. The respective specific storage period can be found in the Consent Management System or in the detailed information available there.

Performance and analytics cookies: Performance and analytics cookies collect information about how our website is used and allow us to perform analytics about the use of the website, e.g. which pages are viewed most frequently and how visitors navigate on our website. These cookies are used to make visiting the website easier and faster and generally improve user experience and comfort. For this purpose, we use third-party analytics services. These cookies have an expiration time of up to 24 months.

Marketing cookies: Marketing cookies help us and our advertising partners to show you advertisements on our website for offers or services that may be of interest to you, or to display our advertisements if you continue to browse the internet after leaving our website, i.e. to show you targeted advertisements. These cookies have an expiration time of up to 24 months.

Details about our third-party providers and advertising partners can be found in the Consent Management System, which is available on the respective website you are currently visiting. In the Consent Management System, you also have the option to disable certain categories of cookies by making the appropriate settings. The cookie settings can be adjusted by you at any time.

Some of the third-party providers we use may be located outside of Switzerland. For information on the disclosure of data abroad, please refer to Section 9.

If you consent to the use of cookies, you accept that your data may be transferred to a country that does not have an adequate level of data protection and accept the risk that your data may be exposed to access by foreign authorities in the country of the recipient, who may not adhere to adequate data protection regulations in doing so. You may revoke your consent to cookies at any time, as explained in Section C.

We currently use offers from the following service providers and advertising partners (to the extent that they use data from you or cookies placed on your device for advertising purposes):

Google Analytics: Google Ireland (located in Ireland) is the provider of the service «Google Analytics» and acts as our processor. Google Ireland relies on Google LLC (located in the USA) as its sub-processor (both «Google»). Google tracks the behavior of visitors to our website (duration, frequency of pages viewed, geographic origin of access, etc.) through performance cookies (see above) and on this basis creates reports for us about the use of our website. We have configured the service so that the IP addresses of visitors are truncated by Google in Europe before forwarding them to the USA so they cannot be traced back. We have turned off the «Data sharing» and «Signals» settings. Although we can assume that the information we share with Google is not personal data for Google, it is possible that Google may be able to draw conclusions about the identity of visitors based on this data for its own purposes, create personal profiles and link this data with the Google accounts of these individuals. If you consent to the use of Google Analytics, you explicitly consent to such processing, which also includes the transfer of personal data (in particular website and app usage data, device information and individual IDs) to the USA and other countries, where your data may be accessible to authorities that are not subject to adequate data protection regulations. Information about data protection with Google Analytics can be found here https://support.google.com/analytics/answer/6004245 and if you have a Google account, you can find more details about Google’s processing here: https://policies.google.com/technologies/partner-sites?hl=en.

13.C How can I control the use of cookies and similar technologies?

You can manage your preferences regarding the use of cookies and similar techniques on our website by accessing the Consent Management System, which is available on the respective website you are currently visiting.

Browsers can automatically accept or reject cookies, but allow you to change these settings. You can also disable or delete cookies that you have previously accepted. Note that all settings are lost if you delete all cookies, including the setting that you do not want to accept cookies, as this in turn requires that an opt-out cookie has been set. The settings must be made separately for each browser you use. You can find out how to manage cookies in your browser in the help menu of your browser.

If you choose to decline cookies and similar techniques, you can still use our website, but your access to some features and areas of our website may be limited.

 

14. WHAT DATA DO WE PROCESS ON OUR PAGES ON SOCIAL NETWORKS?

We may operate pages and other online presences («fan pages», «channels», «profiles», etc.) on social networks and other platforms operated by third parties and process the data about you described in Section 3 and below. We receive this data from you and the platforms when you come into contact with us via our online presence (e.g. when you communicate with us, comment on our content or visit our presence). At the same time, the providers of the platforms may analyze your use of our online presences (e.g. how you interact with us, how you use our online presences, what you view, comment on, or «like») and process this data along with other data they have about you (e.g. information about your age and gender and other demographic information). In this way, they create profiles about you and statistics about the use of our online presences. They use this data and profiles to display our or other advertisements and other personalized content on the platform and to steer behavior on the platform, but also for market and user research and to provide us and other parties with information about you and the use of our online presence. To the extent that we are jointly responsible with the provider for certain types of processing, we will enter into a corresponding contract with the provider. You can obtain information about the essential content of this contract from the provider. They also process this data for their own purposes, in particular for marketing and market research purposes (e.g. to personalize advertising) and to manage their platforms (e.g. to decide what content to show you), and act as separate controllers for this purpose.

We are entitled, but not obliged, to review content before or after it is published on our online presences, to delete content without notice and, if necessary, to report it to the provider of the relevant platform. In the event of violations of decency and conduct rules, we may also notify the provider of the platform on which the user account in question is located for blocking or deletion.

For further information on processing by the platform providers, please refer to the privacy notices of the respective platforms. There you can also find out in which countries your data is processed, what rights of access and deletion you have and how you can exercise these or obtain further information. We currently use the following platforms:

15. USE OF ANALYTICS AND TRACKING TECHNOLOGIES IN PARTNERSHIP WITH MICROSOFT

We collaborate with Microsoft Clarity and Microsoft Advertising to record your usage behavior on our website using behavioral metrics, heatmaps and session recordings. This serves to improve and market our products and services. Website usage data is captured using first-party and third-party cookies as well as other tracking technologies to analyze the popularity of products and services and online activity. Additionally, we use this information for website optimization, security and fraud prevention purposes, and advertising purposes. For more information about how Microsoft collects and uses your data, please see the Microsoft Privacy Statement: Microsoft Privacy Statement – Microsoft Privacy.

 

16. CAN THIS PRIVACY POLICY BE CHANGED?

This Privacy Notice is not part of a contract with you. We can adjust this Privacy Notice at any time. The version published on this website is the current version.

 

This page was last modified on October 7, 2026. If you have any questions or comments regarding our legal notices or data protection, please contact us at privacy@dolderhotelag.com.