In briefThe controller is Christian Scotoni Unternehmungen GmbH, which operates the Boutique Hotel Wellenberg. Please send any privacy questions to reservation@hotel-wellenberg.ch.
The controller responsible for processing your personal data is Christian Scotoni Unternehmungen GmbH, Niederdorfstrasse 10, CH-8001 Zurich, operator of the Boutique Hotel Wellenberg (hereinafter “we” or “the hotel”).
For questions, access requests and all data protection matters, you can reach us by email at reservation@hotel-wellenberg.ch, by phone on +41 43 888 44 44 or in writing at the above address.
In briefThis policy applies to the website, your booking and your stay. The Swiss Federal Act on Data Protection applies, supplemented by the GDPR.
This privacy policy describes how we process personal data when you visit our website, make an enquiry, book a room or stay with us.
The Swiss Federal Act on Data Protection (FADP) and the Data Protection Ordinance (DPO) are authoritative. Where the EU General Data Protection Regulation (GDPR) applies in individual cases, we also process personal data in accordance with it.
We process personal data in particular to perform a contract, on the basis of legal obligations, on the basis of our legitimate interest in a safe and well-run hotel or, where necessary, on the basis of your consent.
In briefFor a booking or enquiry we need your contact details, stay details and a payment guarantee — solely to process your reservation.
When you book or make an enquiry directly via our website, by phone or by email, we process in particular:
We use this data to confirm the reservation, prepare and carry out your stay, issue invoices and communicate with you.
Online booking is handled via the SynXis booking engine provided by Sabre Hospitality Solutions. Clicking “Book” takes you to their booking page; Sabre’s privacy provisions also apply.
In briefIf you book via Booking.com, Expedia or similar platforms, we receive from them the details we need for your reservation.
If you book via a booking platform or travel agency, the respective provider sends us the details required for the reservation, in particular name, contact details, stay details, price and, where applicable, payment details or a virtual credit card.
The platform’s own privacy provisions apply to data processing by the platform itself.
In briefAt check-in we are legally required to complete a registration form and send it to the police.
At check-in we record the details required by law for the registration form, in particular name, date of birth, nationality, home address, ID details and arrival and departure dates, for all persons travelling with you.
The registration requirement arises from the regulations of the Canton of Zurich. The details are sent to the competent police authority and used only to the extent provided for by law.
During your stay we also record services used, such as breakfast, minibar or extras, so that they can be billed correctly.
In briefWe process card payments through specialised, certified payment service providers.
We process payments by credit and debit card as well as pre-authorisations through specialised payment service providers. The card data required for payment is transmitted to these providers and the card schemes involved.
Card data is used solely to process payments and to guarantee the booking in accordance with our General Terms and Conditions.
In briefWhatever you send us via the contact form or by email, we use only to answer your enquiry.
When you contact us via the contact form, by email or by phone, we process your details such as name, email address, phone number and the content of your message in order to respond to your request.
The contact form is transmitted via our website provider Webflow. To protect against spam we use Cloudflare Turnstile, which checks technical information from your browser to detect automated access.
We use Microsoft 365 for email communication.
In briefOur guest app is provided by straiv (CODE2ORDER GmbH, Stuttgart). Using it is voluntary.
For digital services such as hotel information, requests during your stay and – as an option – online check-in, we use the straiv guest app, a service of CODE2ORDER GmbH, Stuttgart, Germany.
Using the app is voluntary. It processes the data needed for each function, such as name, room number and your requests. straiv’s privacy notices also apply.
In briefWe collect reviews you publish on platforms in one place so we can respond and improve.
We collect reviews that guests publish on platforms such as Booking.com, Google or Tripadvisor via the TrustYou service (TrustYou GmbH, Munich, Germany) in order to analyse and respond to them.
Your feedback helps us to keep improving what we offer. Leaving a review is voluntary.
In briefThe entrance and public areas are under video surveillance. Recordings are automatically deleted after 72 hours.
To protect guests, staff and property and to investigate incidents, the entrance and publicly accessible areas of the hotel are under video surveillance. Rooms and sanitary facilities are not monitored.
Recordings are automatically deleted after 72 hours. Only in the event of an incident are they kept longer, and they may be handed over to the law enforcement authorities.
In briefOur website does not use analytics or advertising cookies. Only technically necessary data is generated when you visit.
Our website is hosted by Webflow, Inc., San Francisco, USA. When you access it, technically necessary data such as IP address, date and time, page accessed, browser and operating system are recorded in log files in order to run the website securely and reliably.
We do not use analytics, tracking or advertising cookies and do not create user profiles.
For the weather display, your browser retrieves current weather data for Zurich from the Open-Meteo service; your IP address is transmitted to this service. To create PDF documents, a software library is loaded via Cloudflare’s network (cdnjs).
In briefLinks to Google Maps, Instagram, Facebook or the booking engine lead to third parties with their own privacy provisions.
Our website contains links to third-party services, such as Sabre’s booking engine, Google Maps for route planning and our profiles on Instagram and Facebook.
Data is only transmitted to the respective provider once you click such a link. The respective provider is responsible for its data processing, and its privacy provisions apply.
In briefWe do not sell data. We only pass it on if it is necessary for your stay, required by law or requested by you.
We only pass on personal data to the extent necessary to perform the contract, where there is a legal obligation or where you have consented. Recipients may include in particular:
Our service providers process personal data only on our behalf and in accordance with our instructions. We do not sell personal data to third parties.
In briefSome service providers are based in the EU or the USA. We make sure your data is adequately protected there.
Personal data is processed primarily in Switzerland and the European Economic Area. Some service providers, such as Webflow or Sabre, are based in the USA.
We only disclose personal data to countries without an adequate level of data protection if appropriate safeguards are in place, in particular certification under the Swiss-U.S. Data Privacy Framework or standard contractual clauses recognised by the Federal Data Protection and Information Commissioner, or if a statutory exception applies, for example because the disclosure is necessary to process your booking.
In briefWe keep data only for as long as necessary. By law, we must keep accounting records for 10 years.
We keep personal data for as long as necessary for the purposes stated or as required by statutory retention obligations.
We keep business records, invoices and booking vouchers for 10 years in accordance with the Swiss Code of Obligations. Data we no longer need is deleted or anonymised.
In briefWe protect your data with technical and organisational measures, including encrypted connections.
We take appropriate technical and organisational measures to protect personal data against loss, unauthorised access and misuse, including encrypted connections (TLS), access restrictions and a duty of confidentiality for our staff.
In briefYou can request information at any time and have your data corrected or deleted. An email to us is all it takes.
Within the scope of applicable law, you have in particular the right:
Please send your request to reservation@hotel-wellenberg.ch. We may ask for proof of identity. Information is generally provided free of charge within 30 days.
You may also lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC), www.edoeb.admin.ch.
In briefWe update this policy when our processes or the law change. The version published here applies.
We may amend this privacy policy at any time, in particular if our data processing or the legal basis changes. The version published on this website applies. In case of discrepancies, the German version prevails.
As of: October 2026