Legal

Privacy

Last updated: 10 June 2026

1. Responsible body

The body responsible for processing your personal data is:

Panoramahotel Braunwald AG
Dorfstrasse 3, 8784 Braunwald, Switzerland
Phone: +41 55 653 70 30
Email: info@panoramahotel-braunwald.ch

2. Scope & legal bases

This privacy policy applies to the use of our website panoramahotel-braunwald.ch, our booking and communication processes, and the processing of data of our guests, enquirers and newsletter subscribers.

Legal bases:

  • Swiss Data Protection Act (nFADP) of 1 September 2023
  • EU General Data Protection Regulation (GDPR) for guests from the EU
  • Swiss Code of Obligations (CO) for contract processing

3. What data we collect

3.1 When visiting the website

Each time our website is accessed, the following data is automatically recorded and stored in server logs (for up to 14 days):

  • IP address (truncated / anonymised)
  • Date and time of the request
  • Page accessed (URL)
  • Browser type and version
  • Operating system
  • Referrer URL (previous page)

This data serves exclusively the technical provision and security of the website (legal basis: legitimate interest).

3.2 When booking via our system

To process your booking, we collect the following via the Mews booking system:

  • First and last name, address, date of birth (statutory reporting duty)
  • Email address and phone number
  • Booking details (dates, room, people, special requests)
  • Payment data (processed encrypted, not stored by us)
  • Passport/ID number on arrival (Swiss accommodation reporting duty)

Legal basis: performance of a contract (Art. 6(1)(b) GDPR or Art. 31(2)(a) nFADP) and statutory reporting duties (accommodation statistics, Federal Statistical Office; police ordinance).

3.3 With contact forms and enquiries

For enquiries via our forms (contact, retreat, seminar, eSports), we collect the data you provide:

  • First and last name
  • Email address, phone number (optional)
  • Request / message
  • Preferred date, guest count (depending on the form)

Legal basis: initiation of a contract / legitimate interest. This data is retained for 24 months and then deleted, insofar as no contractual relationship arises.

3.4 With the newsletter subscription

When you subscribe to our newsletter, we collect your email address and the date and time of the subscription (double opt-in procedure). Legal basis: your consent. You can withdraw this at any time via the unsubscribe link in every newsletter.

4. Recipients / processors

We pass data to the following service providers, with whom we have concluded corresponding data-processing agreements (DPAs):

  • Mews Systems s.r.o. (Prague, EU), booking and property-management system
  • Sendinblue / Brevo SAS (Paris, EU), newsletter dispatch and marketing automation
  • Google Ireland Limited (Dublin, EU), web analytics (Google Analytics 4, IP-anonymised)
  • Meta Platforms Ireland Limited (Dublin, EU), conversion tracking (Meta Pixel) when marketing is active
  • Hetzner Online GmbH (Gunzenhausen, DE), server hosting of the website
  • e-guma AG (Switzerland), voucher shop; processing of order and payment data when purchasing gift vouchers
  • OpenStreetMap Foundation (Cambridge, UK), map service on the arrival page; the map only loads after you click (consent), at which point your IP address is transferred
  • TrustYou GmbH (Unterföhring, DE), analysis and aggregation of our guest reviews (TrustScore); the score is embedded in the website as a static value, no data is transferred to TrustYou when you visit the website
  • Swiss Federal Statistical Office, accommodation statistics (legally required)

4.1 Transfer to third countries

Google Analytics and the Meta Pixel may transfer data to the USA. This takes place exclusively on the basis of the EU-US Data Privacy Framework and standard contractual clauses (SCC). We use IP anonymisation and disabled cross-device tracking to minimise the data transferred.

5. Cookies and tracking

5.1 Technically necessary cookies

To operate the website we use necessary cookies (language setting, newsletter-dismiss status, A/B-test variant). These require no consent.

5.2 Analytics & marketing cookies

We use the following analytics and marketing cookies:

  • Google Analytics 4 (storage period: 14 months)
  • Google Tag Manager (intermediary cookie)
  • Meta Pixel (storage period: 90 days)

For visitors from Switzerland we set these cookies without prior consent, based on the Swiss Data Protection Act (revFADP). You may object at any time: use the “Cookie settings” link at the bottom of the page to decline cookies. Visitors from the EU/EEA are shown a consent banner before any such cookies are used (GDPR); there, cookies are only set after your express consent.

You can withdraw a given consent at any time via the “Cookie settings” link in the footer, or delete cookies in your browser.

6. Storage period

  • Booking data: 10 years (statutory retention duty under the CO)
  • Enquiries without a contract: 24 months
  • Newsletter: until unsubscribing, then deletion logs for 3 months
  • Server logs: 14 days
  • Analytics data: 14 months (GA4 standard)
  • Accommodation reporting data: 6 months (police ordinance)

7. Your rights

Under the nFADP and GDPR you have the following rights:

  • Access to the data stored about you (Art. 25 nFADP / Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 32 nFADP / Art. 16 GDPR)
  • Erasure of your data, insofar as no statutory retention duty applies (Art. 32 nFADP / Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 28 nFADP / Art. 20 GDPR)
  • Objection to direct marketing (Art. 30 nFADP / Art. 21 GDPR)
  • Withdrawal of consent with effect for the future

To exercise these rights, write to us at info@panoramahotel-braunwald.ch or by post to the address above. We respond within 30 days.

8. Right to complain

You have the right to lodge a complaint with a supervisory authority:

  • Switzerland: Federal Data Protection and Information Commissioner (FDPIC), edoeb.admin.ch
  • EU: the respective data-protection authority of your member state

9. Data security

We use Transport Layer Security (TLS/SSL) for the transmission of sensitive data. Our booking system (Mews) is PCI-DSS certified for payment data. Access rights to guest data are limited to trained staff who are bound to confidentiality.

10. Changes to this policy

We reserve the right to amend this privacy policy if the legal situation or our processing changes. You can find the current version at /en/datenschutz, with its last-updated date. For material changes we inform active newsletter subscribers by email.

This privacy policy was prepared in accordance with the nFADP (Switzerland) and the GDPR (EU). It does not replace individual legal advice. The UID, the addresses of individual processors and the specific tool selection must be verified and, if necessary, adjusted by the hotel before go-live.

Reserve

Questions about data protection?

Access, correction or deletion of your data: write to us and we will take care of it.

Prefer to talk? +41 55 653 70 30

Availability & rates

Legal

Privacy.

Last updated: 10 June 2026

Availability & Rates