Last updated: 13 September 2026

Privacy at a glance

This website is deliberately designed to minimise data processing. It is delivered as a static site, uses locally hosted fonts and contains no advertising trackers, marketing pixels, personalised advertising or server-side contact form. During a normal visit, the website itself does not set cookies. A consent platform or cookie banner is therefore not currently required for the features we provide.

Cloudflare processes the technical connection data necessary to deliver the website securely. If you send us an email, it is processed through Microsoft 365. Details are provided in the following sections.

This notice applies to website visitors, people who contact us and our guests. It explains the type, scope, purposes and legal bases of our processing of personal data.

Controller

The controller is:

Greiterhof - Fam. Clemens Margesin
Ultnerstraße 14
39011 Lana near Merano
South Tyrol, Italy
Phone: 0039 0473 564966
Email: fam.margesin@greiterhof.net

Static website and Cloudflare

The website is delivered as a static site through Cloudflare Workers and Cloudflare’s global network. Cloudflare, Inc. processes technically necessary connection and log data, in particular the IP address, requested address, date and time, HTTP information, referrer and browser, device and system characteristics. This is necessary to deliver content, prevent attacks and abuse, and support operation, security and error analysis.

The legal basis is our legitimate interest in providing a secure, fast and reliable website under Art. 6(1)(f) GDPR. Cloudflare states that it processes Customer Logs as a processor. Technical data may be processed across its global network and in the United States and Europe. For international transfers, the Cloudflare Data Processing Addendum includes safeguards such as the EU Standard Contractual Clauses.

We use only the technical traffic and security information that Cloudflare provides as part of operating its network. We have not embedded a Cloudflare Web Analytics beacon, Google Analytics, Meta Pixel or comparable visitor tracking in the website. We do not create individual visitor profiles or use visit data for advertising or marketing. If Cloudflare applies a technically necessary check or security cookie in a specific security situation, it is used solely to protect the website.

More information: Cloudflare Privacy Policy (opens in a new tab) and Cloudflare Data Processing Addendum (opens in a new tab) .

A consent banner is required when a website uses cookies or comparable non-essential tracking technologies that require consent. This website currently uses no such technologies. Cloudflare’s technically necessary security measures are used solely to deliver and protect the website; they are described in this privacy notice and do not require marketing consent.

We have therefore deliberately chosen not to display a cookie banner. A banner without a genuine consent choice would create the false impression that visitor tracking takes place. If we add analytics, advertising, maps, video, booking, chat or other external services in the future, we will reassess the legal position and this notice before activation and obtain consent where required.

Email enquiries

The enquiry buttons on this website only open a prepared message in your own email application. The website does not operate an enquiry form and does not itself transmit the details you add. We receive data only when you deliberately send the email.

We use Microsoft 365 or Microsoft Exchange Online for email. The service processes and stores the sender and recipient addresses, time, subject, message content, technical metadata and any attachments in the mailbox. Processing is necessary to answer your enquiry, prepare or perform a booking, and protect against spam and malicious software. The legal basis is Art. 6(1)(b) GDPR; Art. 6(1)(f) GDPR also applies to general communications and the secure organisation of our correspondence.

Microsoft processes this data as a service provider under the data protection terms applicable to its online services. Microsoft offers regional storage and the EU Data Boundary for European customers; limited international processing or access may nevertheless occur. Such transfers are protected by the contractual safeguards described in the Microsoft Products and Services Data Protection Addendum.

More information: Microsoft Products and Services Data Protection Addendum (opens in a new tab) and Microsoft EU Data Boundary (opens in a new tab) .

Please do not send copies of identity documents, complete payment details or particularly sensitive information in an initial non-binding enquiry. If such information is needed later, we will agree an appropriate transmission method with you.

Email enquiries are retained for as long as necessary to deal with the enquiry, answer follow-up questions and document any resulting business relationship. Messages that no longer serve a purpose are deleted as part of periodic reviews; statutory retention periods apply to correspondence relevant to bookings, accounting or taxation.

Guest data and stays

In accordance with Art. 13 GDPR, we process the following data where required for enquiries, bookings and stays:

  • master data such as first name, surname, address, phone number, email, date and place of birth and language
  • data from travel documents and identity documents
  • payment and bank details where required for booking or billing
  • requested or booked length of stay and related information or personal preferences that you provide to us

The data is stored and processed to provide our services. Where necessary or legally required, it may be disclosed to public authorities, the tourism association, payment or tax service providers and other parties involved in providing the service. IT providers we use may carry out international transfers; these take place only on a valid legal basis and with the necessary safeguards.

If you do not provide required master data, identity document data or payment data, we may not be able to fulfil our contractual obligations and accommodate you. We do not use profiling or automated decision-making.

The legal bases for processing are in particular:

  • performance of pre-contractual and contractual obligations
  • consent given by you
  • legal, contractual or other obligations, for example accounting, tax, registration or contract law obligations
  • legitimate interests, such as improving our guest service or protecting our own legal interests

The storage period depends on the duration of the business relationship, consent given and applicable statutory retention and documentation obligations.

Guest Pass

For the issuing and use of the digital Guest Pass, required personal data may be transmitted to the central coordination office of the Guest Pass.

The recipient is the Mobility Consortium with VAT number 02735170215. As guest-card provider and central coordination office, it acts as an independent controller for the transmitted data. Further information is available by email at privacy@moko.bz.it .

The legal basis for this processing is Art. 6 para. 1 lit. b GDPR.

Your rights

You may request information about the personal data stored by us at any time and free of charge. Where the legal requirements are met, you also have the right to rectification, deletion, restriction of processing, data portability and objection to processing based on legitimate interests. You may withdraw consent with effect for the future.

Where statutory retention obligations apply, deletion can only take place after these obligations have expired.

For questions about your rights, please contact us at fam.margesin@greiterhof.net .

Complaints may be addressed to the Italian supervisory authority, Garante per la protezione dei dati personali: Piazza Venezia n. 11, 00187 Rome, Italy, Phone: (+39) 06.696771, Email: protocollo@gpdp.it .