Data Protection

Privacy Policy
Last updated on: August 11, 2025
We attach great importance to the transparent handling of personal data. This privacy policy provides information about what personal data we collect, for what purpose, and to whom we disclose it. To ensure a high level of transparency, this privacy policy is regularly reviewed and updated.
1. What Services We Use
- WordPress
2. Contact Information
If you have any questions or concerns regarding our data protection practices, you can reach us at any time via email at . The party responsible for data processing carried out via this website is:
Andrea Schnidrig
Matte 718
3925 Grächen
Switzerland
Data Protection Officer:
Andrea Schnidrig
+41 78 713 71 67
3. General Principles
3.1 What Data Do We Collect from You and from whom Do We Receive this Data
Primarily, we process personal data that you transmit to us or that we collect when operating our website. Under certain circumstances, we may also receive personal data about you from third parties. These may include the following categories:
- Personal master data (name, address, date of birth, etc.);
- Contact information (mobile number, email address, etc.);
- Financial data (e.g., account details);
- Online identifiers (e.g., cookie identifiers, IP addresses);
- Location and traffic data;
- Audio and video recordings;
- special categories of personal data (e.g., biometric data or information about your health).
3.2 under What Conditions Do We Process your Data?
We treat your data confidentially and in accordance with the purposes set out in this privacy policy. We ensure transparent and proportionate processing.
If, exceptionally, we are unable to comply with these principles, data processing may still be lawful if there is a legal justification. Specifically, a legal justification may include:
- Your consent;
- the performance of a contract or pre-contractual measures;
- our legitimate interests, provided your interests do not override them.
3.3 how Can You Withdraw your Consent?
If you have given us consent to process your personal data for specific purposes, we will process your data within the scope of this consent, unless we have another legal justification.
You have the option to withdraw your consent at any time by sending an email to the address provided in the imprint. Data processing that has already occurred is not affected by this.
3.4 in What Cases Can We Disclose your Data to Third Parties?
A. Principle
Under certain circumstances, we may rely on the services of third parties or affiliated companies and commission them with the processing of your data (so-called processors). Categories of recipients include:
- Accounting, fiduciary, and auditing firms;
- Consulting firms (legal advice, taxes, etc.);
- IT service providers (web hosting, support, cloud services, website design, etc.);
- Payment service providers;
- Providers of tracking, conversion, and advertising services.
We ensure that these third parties and our affiliated companies comply with data protection requirements and treat your personal data confidentially.
Under certain circumstances, we may also be obliged to disclose your personal data to authorities.
B. Visiting our Social Media Channels
We may have embedded links to our social media channels on our website. This is visible to you (typically via corresponding icons). If you click on the icons, you will be redirected to our social media channels.
In this case, the social media providers will know that you are accessing their platform from our website. The social media providers may use the data collected in this way for their own purposes. Please note that we do not receive any information about the content of the transmitted data or its use by the operators.
C. Transfer Abroad
Under certain circumstances, your personal data may be transferred to companies abroad as part of order processing. These companies are obliged to protect data to the same extent as we are. The transfer can take place worldwide.
If the level of data protection does not correspond to that of Switzerland, we conduct a prior risk assessment and contractually ensure that the same level of protection as in Switzerland is guaranteed (e.g., by means of the new standard contractual clauses of the EU Commission or other legally prescribed measures). Should our risk assessment be negative, we take additional technical measures to protect your data. You can access the standard contractual clauses of the EU Commission via the following link. https://commission.europa.eu/publications/standard-contractual-clauses-controllers-and-processors-eueea_de
3.5 how Long Do We Store your Data?
We store personal data only for as long as necessary to fulfill the individual purposes for which the data was collected.
Data that we store during your visit to our website is retained for twelve months. An exception applies to analytics and tracking data, which may be retained longer.
We store contract data longer, as we are obliged to do so by legal regulations. In particular, we must retain business communications, concluded contracts, and booking receipts for up to 10 years. Insofar as we no longer require such data from you for the performance of services, the data will be blocked, and we will only use it for accounting and tax purposes.
3.6 how Do We Protect your Data?
We will keep your data secure and take all reasonable measures to protect your data from loss, access, misuse, or alteration.
Our contractual partners and employees who have access to your data are obliged to comply with data protection regulations. In some cases, it will be necessary for us to forward your inquiries to affiliated companies. In these cases too, your data will be treated confidentially.
Within our website, we use the SSL (Secure Socket Layer) procedure in conjunction with the highest encryption level supported by your browser.
3.7 What Rights Do You Have?
A. Right of Access
You can request information about the data we store about you at any time. We ask you to send your request for information along with proof of identity to .
You also have the right to receive your data in a common file format if we process your data automatically, and if:
- You have given your consent for the processing of this data; or
- You have disclosed data in connection with the conclusion or performance of a contract.
We may restrict or refuse access to or disclosure of data if this conflicts with our legal obligations, legitimate own or public interests, or the interests of a third party.
The processing of your request is subject to the statutory processing period of 30 days. However, we may extend this period due to high request volume, legal or technical reasons, or because we require further information from you. You will be informed of the extension of the period in good time, at least in text form.
B. Erasure and Rectification
You have the option to request the erasure or rectification of your data at any time. We may reject the request if legal regulations oblige us to retain the data for a longer period or unchanged, or if a permissible circumstance conflicts with your request.
Please note that the exercise of your rights may, under certain circumstances, conflict with contractual agreements and may have corresponding effects on the performance of the contract (e.g., premature termination of contract or cost implications).
C. Legal Recourse
If you are affected by the processing of personal data, you have the right to enforce your rights in court or to file a complaint with the competent supervisory authority. The competent supervisory authority in Switzerland is the Federal Data Protection and Information Commissioner: https://www.edoeb.admin.ch
3.8 Changes to the Privacy Policy
We may amend this Privacy Policy at any time. The changes will be published on www.ferienwohnungen-graechen.ch; you will not be separately informed about them.
4. Individual Data Processing Operations
4.1 Provision of the Website and Creation of Log Files
What Information Do We Receive and how Do We Use it?
By visiting www.ferienwohnungen-graechen.ch, certain data is automatically stored on our servers or on servers of services and products that we obtain and/or have installed, for purposes of system administration, for statistical or backup purposes, or for tracking purposes. This includes:
- the name of your internet service provider;
- Your IP address (under certain circumstances);
- the version of your browser software;
- the operating system of the computer used to access the URL;
- the date and time of access;
- the website from which you visit the URL;
- the search terms you used to find the URL.
Why are We Allowed to Process this Data?
This data cannot be assigned to any specific person, and no merging of this data with other data sources takes place. Log files are stored to guarantee the functionality of the website and to ensure the security of our information technology systems. This constitutes our legitimate interest.
How Can You Prevent Data Collection?
The data is stored only for as long as necessary to achieve the purpose of its collection. Accordingly, the data is deleted after each session. The storage of log files is absolutely necessary for the operation of the website, so you have no possibility to object to it.
4.2 WordPress
Our website is based on the WordPress platform, a content management system developed by Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA. WordPress allows us to create, manage, and publish content.
When using our WordPress-based website, various data, including your IP address, date and time of access, and information about the browser you are using, may be collected and stored. This data is primarily used for administrative purposes and to ensure the smooth operation of the website.
Some WordPress features, such as comments or contact forms, may collect additional personal data if you use them.
BrainBox Generatoren
BrainBox Generatoren is a service of BrainBox Solutions GmbH to identify all privacy-relevant services on a website and, among other things, to assist in the creation of the privacy policy. No personal data is collected or processed in this process.