Martin Ziermayr, MEd MSc MBA
Birkenstraße 2b, 4540 Bad Hall
Tel.: +43 676 73 01 500
E-Mail: office@hoamatwandern.at
Please see pt. 1 above
I hereby confirm that I am at least 14 years old. If the data subject is younger than 14, they must obtain the consent of their parents/legal guardians before providing us with personal data. Without this consent, the provision of personal data is prohibited. If a minor user nevertheless provides personal data, use of this data will be discontinued immediately upon becoming aware of it.
Legal basis for the processing of personal data Insofar as we obtain the consent of the data subject for processing operations involving personal data, Art. 6(1)(a) of the EU General Data Protection Regulation (GDPR) serves as the legal basis for the processing of personal data.
When processing personal data is necessary for the performance of the contract with the hiking and snowshoe guide, Art. 6(1)(b) GDPR serves as the legal basis. This also applies to processing operations necessary for carrying out pre-contractual measures.
Where processing of personal data is necessary for compliance with a legal obligation to which our company is subject, Art. 6(1)(c) GDPR serves as the legal basis.
In the event that vital interests of the data subject or another natural person make the processing of personal data necessary, Art. 6(1)(d) GDPR serves as the legal basis.
If processing is necessary for the purposes of the legitimate interests pursued by our company or by a third party, and these interests are not overridden by the interests or fundamental rights and freedoms of the data subject, Art. 6(1)(f) GDPR serves as the legal basis for the processing.
We have concluded a GDPR-compliant data processing agreement with our processors, which is continuously monitored and reviewed. Our partners are obliged to delete address data after the mailing has been carried out. Any further transfer or sale of your data to third parties will not take place under any circumstances.
Data Deletion and Retention Period The personal data of the data subject will be deleted or blocked as soon as the purpose of storage no longer applies. Storage may also take place if this has been provided for by the European or national legislator in EU regulations, laws, or other provisions to which the controller is subject. Data will also be blocked or deleted when a storage period prescribed by the aforementioned regulations expires, unless further storage of the data is necessary for the conclusion or performance of a contract.
Rights of the data subject If your personal data are processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller:
You can request confirmation from the controller as to whether personal data concerning you are being processed by us.
If such processing is taking place, you can request information from the controller about the following:
You have the right to request information as to whether personal data concerning you are transferred to a third country or to an international organization. In this context, you may request to be informed of the appropriate safeguards pursuant to Art. 46 GDPR in connection with the transfer.
You have the right to obtain from the controller the rectification and/or completion of personal data concerning you if the processed data are inaccurate or incomplete. The controller must carry out the rectification without undue delay.
Under the following conditions, you can request the restriction of the processing of your personal data:
Where the processing of your personal data has been restricted, such data—apart from being stored—may only be processed with your consent, or for the establishment, exercise, or defense of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or a Member State.
If the restriction of processing has been imposed under the conditions above, you will be informed by the controller before the restriction is lifted.
a) Obligation to erase
You can demand from the controller that personal data concerning you be erased without undue delay, and the controller is obliged to erase such data without undue delay if one of the following grounds applies:
b) Notification to third parties
If the controller has made the personal data concerning you public and is obliged to erase them pursuant to Art. 17(1) GDPR, the controller shall, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to inform controllers which are processing the personal data that you, as the data subject, have requested the erasure of any links to, or copies or replications of, those personal data.
c) Exceptions
The right to erasure does not apply to the extent that processing is necessary:
Right to notification If you have exercised your right to rectification, erasure, or restriction of processing against the controller, the controller is obliged to communicate this rectification or erasure of data or restriction of processing to all recipients to whom the personal data concerning you have been disclosed, unless this proves impossible or involves a disproportionate effort. You have the right to be informed by the controller about those recipients.
You have the right to receive the personal data concerning you that you have provided to the controller in a structured, commonly used, and machine-readable format. You also have the right to transmit those data to another controller without hindrance from the controller to whom the personal data were provided, provided that:
In exercising this right, you also have the right to have the personal data concerning you transmitted directly from one controller to another, where technically feasible. The freedoms and rights of others must not be adversely affected by this.
The right to data portability does not apply to processing of personal data necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
You have the right, on grounds relating to your particular situation, to object at any time to the processing of your personal data which is based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on those provisions.
The controller will no longer process your personal data unless the controller demonstrates compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims.
If your personal data are processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing; this also applies to profiling insofar as it is related to such direct marketing.
If you object to processing for direct marketing purposes, your personal data will no longer be processed for these purposes.
In connection with the use of information society services—and notwithstanding Directive 2002/58/EC—you have the option of exercising your right to object by automated means using technical specifications.
You have the right to withdraw your data protection consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
You have the right not to be subject to a decision based solely on automated processing—including profiling—that produces legal effects concerning you or similarly significantly affects you. This does not apply if the decision:
However, such decisions may not be based on special categories of personal data referred to in Art. 9(1) GDPR unless Art. 9(2)(a) or (g) applies and suitable measures have been taken to safeguard your rights and freedoms and your legitimate interests.
In the cases referred to in (1) and (3) above, the controller shall implement suitable measures to safeguard your rights and freedoms and your legitimate interests, at least the right to obtain human intervention on the part of the controller, to express your point of view, and to contest the decision.
Right to lodge a complaint with a supervisory authority Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, place of work, or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
The supervisory authority with which the complaint has been lodged shall inform the complainant of the progress and the outcome of the complaint, including the possibility of a judicial remedy pursuant to Art. 78 GDPR.
We do everything to protect your data. This includes measures to prevent manipulation, loss, destruction, or access by unauthorized persons. To this end, we implement technical safeguards (such as access controls, locked storage, password policies, etc.), organizational safeguards (such as training and usage policies), and legal safeguards (confidentiality agreements, data protection agreements, data processing agreements). All data are stored on our servers or on the servers of our service providers with whom data processing agreements have been concluded. All our systems and data processing activities are recorded and described in detail in a record of processing activities.
If you tick the respective service, your email address/telephone number/postal address will be used for our own promotional purposes and for those of our partner organizations until you unsubscribe.
This use takes place exclusively at your separate request and with your consent and is not a prerequisite for your membership.
You can withdraw this declaration of consent at any time and free of charge. This can be done by email (office@hoamatwandern.at), by phone (+43 676 73 01 500), or by post (Birkenstraße 2b, 4540 Bad Hall). In addition, each newsletter includes a way to contact us to withdraw your consent.
Use of embedded media (Facebook, Instagram, YouTube) To deliver content, our website uses media such as Facebook, Instagram, and YouTube by embedding their sites on our pages. In doing so, the providers may use tracking functions and cookies. If you are logged in to the respective service, your own profile may be linked to your visit. ps://de-de.facebook.com/policy.php
This website uses the social plugins (“plugins”) of various social networks listed here. These plugins allow users to share content or recommend articles. To best protect users, these plugins are integrated on the website as simple links rather than as “iframes,” as is standard with social networks. This means the user’s browser does not establish any direct connection to the servers of the respective social network unless the user actively interacts with the plugin, for example by clicking the “Like,” “Share,” or “Tweet/X” buttons (collectively, “buttons”).
If the user clicks one of the buttons, a new window will prompt them to log in to the respective social network. In this case, one or more cookies from the corresponding social network will also be placed on the user’s device. By pressing the button, the browser sends these cookies to the social network’s servers in the USA without being asked, and the social network at least receives the information that the user has accessed the relevant page of the website—even if the user does not have a profile on that social network or is not currently logged in. In addition, data such as the user’s IP address, date, time, URL and a unique ID of the website, screen resolution, etc., may be transmitted and stored.
If the user has previously visited a social network’s website with their browser (regardless of whether they have registered there), that network may already have placed a cookie with a unique user identifier on their computer, which is used to recognize the user during any communication with that network. If the user now interacts with the plugin (clicks one of the buttons), this cookie is also sent. This enables the social network, in principle, to create a profile of which websites have been visited by the user associated with that identifier. It may also be possible to later link this identifier to a person—for example, when the user subsequently logs in to the social network.
If the user is registered and logged in to the social network whose plugin they interact with on the website, that network can directly associate the visit to the website with the user’s profile. The information listed here will be transmitted by the user’s browser directly to a server of the respective provider in the USA and stored there. The information is also published on the social network and displayed to other users. Exactly which users receive this information depends on the privacy settings the user has configured on the respective social network.
The controller has no influence over the scope or content of the data that social networks collect and/or store and/or further process and/or share in connection with interaction with their plugins. The publisher relies on the information provided by the respective social networks.
The current purpose and scope of data collection and the further processing and use of data by social networks, as well as the related rights and settings options to protect the user’s privacy, can be found in detail in the privacy notices of the respective networks and websites. A concise overview of all relevant information can be found summarized under the respective sections.
If the user does not want social networks to receive information about visits to the website and directly associate it with the user’s profile in the respective service, they must refrain from interacting with the plugins. If the user interacts with a plugin on the website (i.e., clicks the “Like,” “Share,” or “X” button), the user agrees to the use of the data collected about them by the respective social network in the manner described and for the stated purpose, and consents to their data being transferred to and used in third countries outside the EU with inadequate data protection (e.g., the USA). To avoid cookies being set and sent to the providers’ servers even in the case of accidental (unintentional) interaction with a plugin, the user can select the “Block third-party cookies” option in their browser settings. However, this setting may also impair other cross-site functions of the website.
The social network is operated by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (“Facebook”) and serves for user interaction. Its plugins are marked with a Facebook logo (“Facebook button”) and allow posting on one’s own timeline as well as activating “Like” for the respective page.
The purposes of data collection and processing by Facebook, as well as the types of data (scope of data), can be found in Facebook’s own privacy policy: https://www.facebook.com/policy.php.
For maximum transparency, the publisher summarizes the key points for users:
The data collected are used to analyze usage behavior and to provide, select, evaluate, and understand advertisements that Facebook provides on and off Facebook (including ads provided by Facebook subsidiaries or on their behalf), as well as to compile user statistics. Facebook also uses the available data to improve its advertising and measurement systems so it can show users relevant ads on and off Facebook services and measure the effectiveness and reach of ads and services. If the user is registered with Facebook, Facebook can use the collected data to provide services to the user, personalize content, and make direct links and suggestions the user may be interested in. The collected data are also used to send marketing communications, to communicate with the user about its services, and to inform the user about Facebook’s policies and terms.
If the user holds a Facebook account and uses the Facebook button, they have consented to their information being collected, transferred, stored, disclosed, and used in accordance with Facebook’s Privacy Policy.
In the account settings, users can change the privacy settings of their Facebook account.
Photos and videos are generally processed for journalistic purposes (§§ 27 et seq. DSG, Art. 85 GDPR).
Where consent is required, it is given for both the processing and the publication of the images (photos and/or videos) in accordance with the respective consent declaration or event information.
If the images were processed on the basis of consent, this consent can be withdrawn at any time in writing, unless implementing the withdrawal is not reasonably possible for the controller (e.g., the image appears in a printed brochure, in a commercial, or has been shared by third parties), or other legal grounds prevent implementation. Where appropriate, instead of deleting the image, the controller may render the data subject unrecognizable.
Photos or videos may be published on the controller’s website, on social media (in particular Facebook and Instagram), and in print products.
The controller points out that published images—especially online—can be distributed worldwide, associated with the data subject, and potentially analyzed by third parties (e.g., facial recognition), and that complete deletion from the internet cannot be guaranteed.
Effective: Mai 2026