Holidayplanner Please select holiday themes and months
JAN FEB MÄR APR MAI JUN JUL AUG SEP OKT NOV DEZ
Hiking
Childcare
Skiing
Babycare
Swimming course
Fitness
Wellness
Wine & Culinary
Single with child
Golf
Book now

Familux ONE Privacy Policy

Information on the processing of personal data in the Familux ONE loyalty programme pursuant to Art. 13 and 14 GDPR

Mayer family hotels GmbH

Version 1.5 – As at 18 August 2026

Table of contents

0. At a glance

This Privacy Policy describes how we process your personal data when you participate in the Familux ONE loyalty programme – in the member portal, to a limited extent in the Familux App, and when registering at one of our resorts.

What we do in any case, because the Programme would otherwise not work. We keep your member account, record your eligible spend from the Familux Resorts, credit you with ONE-Credits, determine your status level and handle the redemption of rewards. For this we need no separate consent – this processing is the performance of our contract with you.

What you decide yourself. Whether we may send you advertising by e-mail or push notification, whether we may use tracking technologies and – as soon as we offer this function – whether we may analyse your data for personalised offers. Each of these consents is voluntary, can be given individually and can be withdrawn at any time.

One exception you should be aware of. If you have already been our guest, we may send you offers relating to similar own services by e-mail even if you have not given consent – the law permits us to do so. You can object to this at any time, and every single message states how. After that you will receive no further advertising from us. Details in Clause 8.

What a withdrawal does not do. Your participation in the Programme, the ONE-Credits you have already collected and your status level remain entirely unaffected – regardless of which consent you withdraw and which processing you object to. We do not make participation in the Programme dependent on any consent. You cannot switch off the processing operations that support the Programme itself: keeping your account, crediting and redeeming your ONE-Credits, the records required by law and the protection of the Programme against misuse. Without them we could not offer you the Programme.

What we do not do. We do not sell your data. We do not buy in data about you. We do not link your profile with data from social networks. We do not target advertising at children and do not build advertising profiles of children. We never use health or dietary information for advertising. Without your consent we do not combine your stay and usage data into an interest profile (Clause 6).

You switch off advertising via the unsubscribe link in every message or by an informal e-mail to datenschutz@familux.com.

1. Controller and contact

The controller for the processing described within the scope of the Familux ONE programme is:

Mayer family hotels GmbH
Lussparkweg 2, 6631 Lermoos, Austria
Commercial register no. FN 397754h, Regional Court Innsbruck
Telephone +43 5673 24245000
E-mail info@familux.com

Data Protection Officer:

Sven Lenz
Datenschutzkanzlei Lenz GmbH & Co. KG
Bahnhofstraße 50, 87435 Kempten, Germany
E-mail datenschutz@familux.com

For all questions on data protection and the exercise of your rights, you can reach us at datenschutz@familux.com.

2. Who is responsible for what

The Familux Resorts are operated by legally independent companies. It is therefore important for you to know who is responsible for which data:

Area Controller What this means
Familux ONE loyalty programme – member account, ONE-Credits, status level, rewards, programme communication Mayer family hotels GmbH alone This Privacy Policy applies.
Your stay – booking, check-in, on-site services, invoice, statutory registration form the respective resort company (see below) as an independent controller The privacy information of the respective resort applies in addition.
Central IT – hosting, portal and app backend, CRM, e-mail dispatch service providers as processors for us Contractually bound under Art. 28 GDPR; no purpose determination of their own.

All resorts operated under the “Familux Resorts” brand by us or by companies affiliated with us participate in the Programme. Which resorts these currently are and which company operates the respective resort follows from the list of participating businesses in our Participation Terms; we provide the full details with address, register data and data protection contact on request, free of charge, in text form. If a new resort is added, we include it in this list; nothing changes in the processing described here as a result.

Data flow between resort and Programme. So that we can credit you with ONE-Credits, the resort at which you were a guest transmits to us your membership number, the arrival and departure date and the amount of your eligible spend. The legal basis for this transmission is the performance of your participation contract with us (Art. 6(1)(b) GDPR). Further stay data – such as which services you used in detail – flow into your Familux ONE profile only if you have consented to personalisation under Clause 6.

3. Which data we process

Master data: form of address, first and last name, date of birth, address, e-mail address, telephone number, language, country.

Access and account data: membership number, username, encrypted password, time of registration, consent and approval logs.

Programme data: balance and history of your ONE-Credits with the respective expiry date, status level and its development, redeemed rewards, bonus promotions.

Stay and spend data: resort, arrival and departure date, number of nights, amount of eligible spend, booking and invoice number.

Details of accompanying family members: first name, date of birth or age, relationship to you.

Voluntary details: preferences (e.g. preferred resort, travel period, room request), interests, and – only with your express consent – dietary and health information (Clause 14).

Usage data: IP address, date and time of access, pages and functions accessed, browser and device type, operating system, referrer; in the App additionally installation ID, push token, App version, crash reports.

Communication data: your enquiries to us and our replies, dispatch and – where you consent to personalisation – opening and click data of our e-mails.

4. Purposes, legal bases and storage periods

Purpose What we specifically do Data categories Legal basis Storage period
Establish and keep the membership Registration, creation and administration of the member account, login, authentication, contact in programme matters Master, access and account data Art. 6(1)(b) GDPR (performance of the participation contract) Duration of the membership, thereafter 3 years to year-end
Credit ONE-Credits Receipt of the resort’s spend report, calculation and crediting, keeping the transaction history with expiry date Stay and spend data, programme data Art. 6(1)(b) GDPR Duration of the membership, thereafter 3 years; tax-relevant records kept separately per Clause 12
Determine status level Automated comparison of your spend or nights with fixed thresholds (Clause 7) Status Points from spend Art. 6(1)(b) GDPR, Art. 22(2)(a) GDPR as above
Status level from an Invest participation Allocation of a status level based on the amount of the participation Participation status, amount of participation, term of the level Art. 6(1)(b) GDPR Duration of the membership + 3 years
Redeem rewards Checking the balance, offsetting, booking or provision of the reward at the resort Programme data, booking data where applicable Art. 6(1)(b) GDPR as above
Inform you about your account Credit confirmations, status notifications, reminders before the expiry of your ONE-Credits, notifications of amendments to the Participation Terms Master, programme and communication data Art. 6(1)(b) GDPR (contract communication, not advertising) as above
Prevent programme misuse Detection of multiple accounts, manipulated or duplicate credits and unauthorised access; comparison of account and device characteristics Usage data, device/installation ID, transaction patterns Art. 6(1)(f) GDPR – legitimate interest: protecting the integrity of the Programme and the claims of honest members against the abusive obtaining of ONE-Credits 24 months; in case of suspicion until clarification
IT security and operation Server and access logs, attack detection, error analysis without personal reference (Clause 11) Usage data, IP address Art. 6(1)(f) GDPR – legitimate interest: secure and trouble-free operation 7 to 30 days; in the event of security incidents until resolved
Evaluate and further develop the Programme Aggregated analyses of the use of ONE-Credits, rewards and status tiers pseudonymised programme data Art. 6(1)(f) GDPR – legitimate interest: needs-based design and economic operation of the Programme raw data 24 months, thereafter only anonymised
Personalised offers Combining your stay, booking and usage history into an interest profile and offers tailored to it (Clause 6) Stay history, preferences, click and opening behaviour Art. 6(1)(a) GDPR – your consent until withdrawal, at most 24 months after the last stay or login
Newsletter and advertising e-mails Sending of offers and programme information E-mail address, form of address, status level Art. 6(1)(a) GDPR; for existing guests additionally Section 174(4) TKG 2021 or Section 7(3) UWG (Clause 8) until withdrawal or unsubscription; proof of consent 3 years thereafter
Advertising push notifications in the App Sending of offers and promotions Push token, installation ID Section 165(3) TKG 2021 or Section 25(1) TDDDG + Art. 6(1)(a) GDPR until withdrawal
Postal advertising Sending of catalogues and offers by post Name, address, status level Art. 6(1)(f) GDPR – legitimate interest: direct marketing (Recital 47); right to object under Clause 16 until objection
Reach measurement and tracking Analysis of the use of portal and App (Clause 11) Usage data, cookie/SDK identifiers Section 165(3) TKG 2021 or Section 25(1) TDDDG + Art. 6(1)(a) GDPR see cookie notices; consent log 3 years
Handle enquiries Answering your messages, complaint handling Communication data Art. 6(1)(b) or (f) GDPR 3 years
Fulfil data subject rights Processing and documenting your requests all affected data Art. 6(1)(c) in conjunction with Art. 5(2) GDPR 3 years
Legal claims Assertion, exercise and defence of legal claims as required Art. 6(1)(f) GDPR until expiry of the respective limitation period
Statutory registration Keeping the guest record or registration form (Clause 12) registration data Art. 6(1)(c) GDPR in conjunction with Section 10 MeldeG 1991 or Sections 29, 30 BMG AT 7 years; DE 1 year from departure, destruction within 3 months
Accounting and taxes Invoicing and retention invoice and payment data Art. 6(1)(c) GDPR in conjunction with Section 132 BAO, Section 212 UGB or Section 147 AO, Section 257 HGB AT 7 years; DE 8 years for accounting vouchers, 10 years for annual financial statements
Objection and suppression list Keeping a minimal suppression list so that an advertising objection is permanently observed e-mail address in hashed form, date Art. 6(1)(c) in conjunction with Art. 21(3) GDPR indefinite – deletion would render the objection ineffective

Periods to year-end. Where a period is stated in years, it begins at the end of the calendar year in which the triggering event occurred.

Inactive member accounts. If you have for 36 months neither had a stay at a participating resort nor logged in to the Portal or the App, we ask you by e-mail whether you wish to continue participating. If we receive no reply within three months, we can end the participation. Your member account then remains for a further twelve months so that you can redeem your ONE-Credits (Clause 15.4 of the Participation Terms). Only after these twelve months have elapsed do we delete or anonymise the member account, unless a statutory retention obligation precludes this.

Blocking instead of deletion. Data that we must retain for legal reasons but no longer need for the original purpose are blocked from further processing and kept exclusively to fulfil the respective retention obligation.

5. How the Programme works – ONE-Credits, status level, rewards

For your stays at the participating resorts we credit you with ONE-Credits. For this we process the spend and stay data reported by the resort. Your current balance and the underlying transactions can be viewed by you in the Portal.

ONE-Credits without spend. In addition, we credit you with ONE-Credits when you answer our guest questionnaire after a stay and on the occasion of your birthday and the birthday of your accompanying family members. For this we process your answer to the questionnaire, your date of birth and the stay data. Purchases in the Familux Shop also lead to a credit; for this we process the associated order data. The legal basis in each case is the performance of the participation contract (Art. 6(1)(b) GDPR). We do not use your answers to the guest questionnaire for advertising.

ONE-Credits expire three years after the day they are credited. So that you do not overlook this, we remind you three months and again four weeks before expiry by e-mail to the address you have stored and by a notice in the Portal. These messages are contract communication and not advertising; you receive them regardless of whether you have consented to advertising. You cannot unsubscribe from them as long as you are a member – please therefore keep your e-mail address up to date.

Balances from the predecessor programme. If your balance from the Familux Resorts’ previous loyalty programme was carried over into your member account, it retains the expiry date that already applied to it. The carry-over has not shortened any expiry date. We also remind you before expiry for these balances (Clause 13.7 of the Participation Terms).

The details on earning, redeeming and expiry of the ONE-Credits are set out in the Familux ONE Participation Terms.

6. Personalisation – only if you agree

The principle. Personalisation takes place exclusively if you have expressly consented. Without your consent we do not combine your stay and usage data into a profile and do not derive any preferences from them. Whether we offer this function is shown in the Portal in each case; we currently do not offer it. This Clause describes what would happen if you consented – so that you know it before the question is put to you.

What we would combine with your consent. At which of our resorts you were a guest, when and for how long; which room categories, arrangements and additional services you booked; the amount of your stays and what you redeemed your ONE-Credits for; which of our e-mails you opened and which offers you viewed in the Portal or App; the preferences and interests you provided voluntarily.

For what purpose. We would derive from this which travel times, resorts, room types and additional services are likely to be of interest to you, and tailor the offers accordingly. This is profiling within the meaning of Art. 4(4) GDPR. An automated decision with legal effect for you would not be associated with it: neither your status level nor your claim to ONE-Credits nor the prices offered to you would depend on this profile.

What we do not do even then. We do not link your profile with data from social networks or with data bought in from third parties. We do not use any dietary or health information or any data of children for this. We do not sell your profile, and we do not pass it on to anyone for their own use.

Legal basis. Your consent under Art. 6(1)(a) GDPR.

Withdrawal. You can withdraw a consent given at any time with effect for the future – informally by e-mail to datenschutz@familux.com. After the withdrawal we delete any interest profile and show you only general offers. Your participation in the Programme, the ONE-Credits you have already collected and your status level remain entirely unaffected. The lawfulness of the processing carried out up to the withdrawal remains unaffected.

7. Automated decision-making

Status level. Your status level is determined automatically on the basis of objective criteria published in the Participation Terms. Decisive are the eligible spend and the number of your stays in the last five years; the Status Points shown in the Portal merely reflect this progress. In addition, a status level can be reached via a participation in the “Familux Invest” programme; in that case the amount of the participation is decisive. The logic consists exclusively in comparing these values with fixed thresholds; no assessment of your person or conduct takes place. The significance and intended effect are the allocation of the status benefits described in the Participation Terms, which include a higher crediting of ONE-Credits per euro of spend. The legal basis is Art. 22(2)(a) GDPR (necessity for the performance of the participation contract).

Misuse detection. We use automated procedures to detect multiple accounts, manipulated credits and unauthorised access. If such a procedure leads to a suspension of your account, we inform you of this stating the reason.

Your rights in both cases. You have the right to obtain human intervention on our part, to express your own point of view and to contest the decision. A message to datenschutz@familux.com is sufficient.

Within the scope of personalised advertising, no automated decision-making with legal effect or similarly significant impairment takes place.

8. Advertising and communication

Contract communication. Messages about your member account – credit confirmations, status notifications, expiry reminders, changes to the Participation Terms – are not advertising. You receive them regardless of any consent as long as you are a member.

Newsletter and advertising e-mails. We send you our newsletter only if you have consented. We use the double opt-in procedure for this: after your registration you receive an e-mail with a confirmation link; only after confirming it do we add you to the distribution list. We log the time, IP address and wording of the consent in order to be able to prove it under Art. 7(1) GDPR. Offers to existing guests – even without consent. If you have already been our guest, we may, under the strict conditions of Section 174(4) TKG 2021 (Austria) or Section 7(3) UWG (Germany), send you offers relating to our own similar services even without separate consent. This means: even if you have not subscribed to the newsletter, you may receive such offers from us. You can object to this at any time – informally by e-mail or via the unsubscribe link that appears in every single one of these messages. After your objection we send you no further advertising. When sending to recipients in Austria, we check the RTR ECG list before each dispatch.

Push notifications in the App. We send advertising push notifications only with your separate consent in the App. This is independent of your device’s “Allow notifications” system permission and of your e-mail consent; you can switch it off individually at any time in the App settings. Purely transactional push notifications – such as a booking confirmation or check-in information – you receive independently of this, provided you have allowed notifications.

Postal advertising. We send this on the basis of our legitimate interest in direct marketing. You can object at any time (Clause 16).

Success measurement. Whether and when you open our e-mails and which links you click we only analyse if you have consented to personalisation under Clause 6. Without this consent we only record whether a message could be delivered technically.

9. Your choices

You decide on three things, in each case individually.

Newsletter and advertising e-mails. The default is off. You receive them only after express subscription and can unsubscribe at any time via the unsubscribe link in every message or informally by e-mail to datenschutz@familux.com.

Advertising push notifications in the App. The default is off. You control them in your device settings and in the App.

Personalised offers. The default is off. We do not currently offer this function; should we introduce it, we ask you beforehand (Clause 6).

Reach measurement and tracking. The default is off. You control this via the consent banner when accessing the Portal (Clause 11).

Advertising to existing guests by e-mail. If you have already been our guest, we may send you offers relating to similar own services by e-mail even without subscription (Clause 8). You can object at any time – via the unsubscribe link in each of these messages or by e-mail. After that you will receive no further advertising from us.

Postal advertising. An objection is possible at any time, informally.

None of these decisions affects your participation, your ONE-Credits or your status level. We do not tie participation in the Programme to any consent (Art. 7(4) GDPR).

10. Recipients of your data

Within our company, only those units that need it to fulfil the stated purposes have access. Beyond that, we pass data on to:

  • the participating resort companies, to the extent necessary for the crediting of ONE-Credits, the redemption of rewards and the granting of your status benefits on site;
  • processors who act on our behalf – in particular for hosting and operation of portal and App, the booking and guest management system, the administration of the guest club and loyalty points, e-mail and push dispatch as well as error analysis and support. They are contractually bound under Art. 28 GDPR, subject to instructions and may not use the data for their own purposes;
  • providers of analysis and advertising technologies, to the extent you have consented to this (Clause 11);
  • payment service providers, banks, tax advisers and auditors within the scope of accounting and statutory obligations;
  • authorities and courts, to the extent we are legally obliged;
  • legal advisers, debt collection agencies and insurers, to the extent necessary for the assertion or defence of legal claims.

We provide an up-to-date overview of the service providers we use on request, free of charge, in text form.

11. Cookies, tracking and the Familux App

Principle. Storing information on your device and accessing it are permitted only with your prior consent – Section 165(3) TKG 2021 in Austria, Section 25(1) TDDDG in Germany. Without consent we use only what is strictly necessary for you to use the service you have requested.

Without consent – technically necessary. Login and session cookie, security token to protect against attacks on forms, storage of your privacy and cookie decision, language setting.

Only with consent. Reach measurement and statistics, A/B tests, personalisation cookies, advertising and retargeting technologies, recognition across several sessions for analysis purposes. This also applies in the logged-in member area – the fact that you are logged in does not make an analysis of your behaviour necessary.

In the Familux App. The rules apply equally to apps. Without consent we use only an installation identifier to bind your session to your member account and for misuse detection, as well as error logs without personal reference that we need to remedy malfunctions and that cannot be attributed to any person. Access to advertising identifiers (IDFA/AAID), the use of analysis SDKs, crash reports that can be attributed to your member account, and location functions take place only with your consent, which we obtain on first launch of the App before the corresponding components are loaded. Your device’s system dialogs – such as “Allow notifications” or Apple’s App Tracking Transparency prompt – do not replace this consent.

Changing your decision. You can change your cookie and tracking consent at any time via the “Cookie settings” link in the footer of the Portal or under “Settings → Privacy” in the App – just as easily as you gave it.

Details of the technologies used, their providers, purposes, and durations can be found in our cookie notice in the footer, at the bottom of the website under cookie settings.

12. Statutory registration obligations

During your stay, the resorts are obliged under the registration law applicable at the respective location to keep a guest register or registration form. The legal basis is Art. 6(1)(c) GDPR in conjunction with the respective national provision – currently Section 10 of the Registration Act 1991 (MeldeG 1991) for our resorts in Austria and Sections 29, 30 of the Federal Registration Act (BMG) for our resorts in Germany.

This registration data is kept separately from your Familux ONE member account and used exclusively for registration purposes – in particular not for advertising, personalisation or profiling. Only the authorities authorised under the respective national law may inspect it.

The retention period is also governed by the law of the location: seven years from entry in our Austrian resorts, one year from your departure in our German resorts with subsequent destruction within three months. The period applicable to a particular resort is stated in the resort list under Clause 2.

13. Data of children

Only adults can hold a Familux ONE member account.

If you travel with children, we process their first names, date of birth or age and – to the extent you provide these to us – details of childcare. The basis is the performance of the accommodation and care contract (Art. 6(1)(b) GDPR) and our statutory registration obligations (Art. 6(1)(c) GDPR).

Children in your family profile. If you store a child as an accompanying family member in your member account (Clause 6 of the Participation Terms), we store first name, date of birth or age and the relationship to you for the duration of your membership, so that you do not have to provide the details anew for each booking. The legal basis is the performance of your participation contract (Art. 6(1)(b) GDPR). You can remove any entry yourself at any time; we then delete it promptly. No profile of the child arises from these details.

Details going beyond this – in particular preferences, interests, activity history or photos from childcare – we store only if you, as the person with custody, expressly consent (Art. 6(1)(a), for health information Art. 9(2)(a) GDPR). You can withdraw this consent at any time.

We do not target advertising at children and do not use data of children to create advertising profiles or to personalise advertising.

Under Art. 8 GDPR in conjunction with Section 4(4) DSG, minors in Austria can consent to the use of online services themselves from the age of 14, in Germany from the age of 16; below that, the consent of the persons with custody is required. As children do not hold their own member account with us, we always obtain consent from the persons with custody. If several persons hold custody, the approval of each of them is required (Clause 6.2 of the Participation Terms).

14. Dietary and health information

If you provide us with allergies, intolerances, special dietary needs or details of mobility restrictions, we process special categories of personal data in this respect (Art. 9 GDPR). Details of a particular diet may also allow conclusions to be drawn about religious or philosophical beliefs.

This information is always voluntary. We process it exclusively on the basis of your express consent (Art. 9(2)(a) in conjunction with Art. 6(1)(a) GDPR), which you can withdraw at any time with effect for the future.

We process this information exclusively for the specific stay and delete it 30 days after your departure. No permanent storage in your member account takes place; you therefore provide us with your information anew before each stay. If you withdraw your consent beforehand, we delete the information promptly.

This data is never used for advertising, personalisation or profiling and is not passed on to third parties who are not directly involved in your on-site care.

15. Transfer to third countries

Some of the service providers we use process data outside the European Economic Area, in particular in the United States. In these cases we ensure an adequate level of data protection by:

  • an adequacy decision of the European Commission under Art. 45 GDPR, to the extent one exists for the respective country or certification programme – currently for companies in the USA certified under the EU-US Data Privacy Framework; and/or
  • the conclusion of the Standard Contractual Clauses of the European Commission under Art. 46(2)(c) GDPR, supplemented by an assessment of the legal situation in the recipient country and, where necessary, by additional technical measures such as encryption and pseudonymisation.

You can request a copy of the Standard Contractual Clauses or the other appropriate safeguards from us at datenschutz@familux.com.

We point out that in third countries a level of data protection comparable to European law may not be guaranteed and, in particular, access by state authorities cannot be excluded to the same extent.

We provide an overview of the service providers we use with a third-country connection on request, free of charge, in text form.

16. Your right to object

RIGHT TO OBJECT UNDER ART. 21 GDPR

Objection to direct marketing. You have the right at any time and without giving reasons to object to the processing of your personal data for the purposes of direct marketing; this also applies to profiling to the extent it is connected with such direct marketing. If you object, we will no longer process your data for these purposes. You can declare the objection without any formality – by e-mail to datenschutz@familux.com or via the unsubscribe link in every advertising e-mail.

Objection to other processing based on legitimate interests. To the extent we base your data on Art. 6(1)(f) GDPR, you have the right, on grounds relating to your particular situation, to object at any time. We will then no longer process your data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the assertion, exercise or defence of legal claims.

An objection to advertising has no effect whatsoever on your participation in the Familux ONE Programme, on your ONE-Credit balance or on your status level.

17. Your further rights

You have the right to access the data we process (Art. 15 GDPR), to rectification of incorrect data and completion of incomplete data (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18) and to data portability – i.e. the release of the data you have provided in a structured, commonly used and machine-readable format (Art. 20).

Withdrawal of consents. You can withdraw any consent given at any time with effect for the future. The lawfulness of the processing carried out up to the withdrawal remains unaffected. If you have given several consents, you can withdraw each one individually; the withdrawal of one consent does not automatically extend to the others.

You most easily exercise your rights at datenschutz@familux.com. We reply without delay, at the latest within one month. To process your request we must establish your identity; where there are reasonable doubts, we may request additional information.

18. Right to lodge a complaint with a supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your residence, place of work or the place of the alleged infringement (Art. 77 GDPR).

The supervisory authority with lead responsibility for us is the

Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40–42, 1030 Vienna, Austria
Telephone +43 1 52 152-0, dsb@dsb.gv.at, www.dsb.gv.at

You can equally turn to the supervisory authority responsible for the location of the resort you visited. Which one this is is stated for each resort in the resort list under Clause 2. For our current German resorts these are:

Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 27, 91522 Ansbach, www.lda.bayern.de
responsible for the Oberjoch – Familux Resort (Bad Hindelang, Bavaria)

Thuringian Commissioner for Data Protection and Freedom of Information (TLfDI)
Häßlerstraße 8, 99096 Erfurt, www.tlfdi.de
responsible for The Grand Green – Familux Resort (Oberhof, Thuringia)

19. Necessity of provision

Required for participation are: first and last name, a valid e-mail address, your address and your date of birth. Without this information we cannot keep a member account, cannot credit ONE-Credits, cannot remind you before their expiry and cannot check whether you meet the age requirement under Clause 4.1 of the Participation Terms. If you do not provide this data, no participation contract comes about. In the registration form, the required details are marked as mandatory fields.

Voluntary are all other details – in particular telephone number, form of address and language, the details of accompanying family members, preferences and interests, dietary and health information, and every consent to advertising, personalisation and tracking. Declining has no disadvantages for your membership.

During your stay you are legally obliged to provide the details required for the registration form (Clause 12).

20. Data security

We take appropriate technical and organisational measures under Art. 32 GDPR to protect your data against loss, destruction, manipulation and unauthorised access. These include in particular state-of-the-art transport encryption (TLS), the encrypted storage of passwords, a role-based authorisation concept with the principle of minimal rights allocation, logging of access, regular backups and the contractual binding and auditing of our processors.

Please treat your access data confidentially and report to us any suspicion of unauthorised use of your member account.

21. Amendments to this Privacy Policy

We adapt this Privacy Policy when the processing we describe or the legal framework changes. The current version is available in the Portal and bears a version number and date. We inform you in advance in text form of material changes – in particular of new processing purposes. If a change requires your consent, we obtain it separately.

This website uses cookies

We use cookies on our website. Some of them (e.g. for the shopping cart) are absolutely necessary, while others help us to improve our online offering and operate it economically. Essential cookies enable us to run the website smoothly. Statistical cookies analyze information anonymously. Marketing cookies are used, among other things, by third parties to deliver personalized advertising. You can accept this or refuse by clicking on the button "Only accept essential cookies". The settings can be accessed at any time, and cookies can also be deselected at any time. You can find more information in our privacy policy.

Cookies overview

  • Google Analytics
  • Google Tag Manager
Privacy policy | Legal notice