Engadin Tourismus AG (hereinafter also "we", "us") obtains and processes personal data relating to you or also other persons (so-called "third parties"). We use the term "data" here synonymously with "personal data" or "personal data".
This privacy statement is designed to meet the requirements of the EU General Data Protection Regulation ("GDPR"), the Swiss Data Protection Act ("DSG”) and the revised Swiss Data Protection Act ("revDSG"). However, whether and to what extent these laws are applicable depends on the individual case.
Engadin Tourismus AG, Via Maistra 1, CH-7500 St. Moritz (the "Engadin Tourismus AG") is responsible for the data processing of Engadin Tourismus AG described in this data protection information. Moritz (the " Engadin Tourismus AG "), , unless otherwise communicated in individual cases, e.g. in further data protection declarations, on forms or in contracts . This data protection declaration applies unless otherwise communicated.
You can contact us for your data protection concerns and to exercise your rights in accordance with para. 11 you can reach us as follows:
Engadin Tourismus AG
Via Maistra 1
7500 St. Moritz, Switzerland
We have deployed the following additional posts:
Data protection representative in the EU pursuant to Art. 27 GDPR:
SIDD Datenschutz Deutschland UG (limited liability)
80798 Munich, Germany
You can also contact these offices for data protection concerns .
We process different categories of data about you. The main categories are as follows:
Technical data: When you use our website or other electronic offers (e.g. free WLAN), we collect the IP address of your end device and other technical data to ensure the functionality and security of these offers. This data also includes logs in which the use of our systems is recorded. We generally retain technical data for 6 months. In order to ensure the functionality of these offers, we can also assign an individual code to you or your end device (e.g. in the form of a cookie, cf. 12). The technical data in itself does not allow any conclusions to be drawn about your identity. However, in the context of user accounts, registrations, access controls or the processing of contracts, they can be linked to other data categories (and thus possibly to your person).
Registration data: Certain offers, e.g. of competitions and services (e.g. login areas of our website, newsletter dispatch, free WLAN access, etc.) can only be used with a user account or registration, which can take place directly with us or via our external login service providers. In doing so, you must provide us with certain data and we collect data on the use of the offer or service. If we issue you a voucher for one of our contractual partners, we may transmit certain of your registration data to the respective contractual partner or receive such data (cf. para. 7). Access controls to certain facilities may generate registration data; depending on the control system, biometric data may also be generated. We generally retain registration data for 2 months after the end of the use of the service or the termination of the user account.
Communication data: If you contact us via the contact form, by e-mail, telephone or chat , by letter or by any other means of communication, we collect the data exchanged between you and us, including your contact details and the marginal data of the communication. If we want or need to establish your identity, e.g. in the case of a request for information submitted by you, a request for media access etc., we collect data to identify you (e.g. a copy of an identity document). We usually keep this data for 12 months from the last exchange with you. This period may be longer where this is necessary for reasons of proof or to comply with legal or contractual requirements, or for technical reasons. E-mails in personal mailboxes and written correspondence are usually kept for at least 10 years. Chats are generally kept for 2.5 years.
Master data: We use the term master data to refer to the basic data that we need, in addition to the contractual data (see below), to process our contractual and other business relationships or for marketing and advertising purposes, such as name, contact details and information about, for example, your role and function, your bank account(s), your date of birth, customer history, powers of attorney, signature authorisations and consent forms. We process your master data if you are a customer or other business contact or work for one (e.g. as a contact person of the business partner), or because we want to address you for our own purposes or the purposes of a contractual partner (e.g. as part of marketing and advertising, with invitations to events, with vouchers, with newsletters etc.). We receive master data from you yourself (e.g. when making a purchase or as part of a registration), from bodies for which you work or from third parties such as our contractual partners, associations and address dealers and from publicly accessible sources such as public registers or the Internet (websites, social media etc.). We may also process health data and information about third parties as part of master data. We may also collect master data from our shareholders and investors. We generally keep this data for 10 years from the last exchange with you, but at least from the end of the contract. This period may be longer if this is necessary for reasons of proof or to comply with legal or contractual requirements or for technical reasons. For pure marketing and advertising contacts, the period is usually much shorter, usually no more than 2 years since the last contact.
Contract data: This is data that arises in connection with the conclusion or processing of a contract, e.g. information about contracts and the services to be provided or provided, as well as data from the run-up to the conclusion of a contract, the information required or used for processing and information about reactions (e.g. complaints or information about satisfaction, etc.). This also includes information about third parties. We generally collect this data from you, from contractual partners and from third parties involved in the processing of the contract, but also from third party sources (e.g. providers of creditworthiness data) and from publicly accessible sources. We generally keep this data for 10 years from the last contractual activity, but at least from the end of the contract. This period may be longer if this is necessary for reasons of evidence or to comply with legal or contractual requirements or for technical reasons.
Behavioural and preference data: Depending on our relationship with you, we try to get to know you and better tailor our products, services and offers to you. To do this, we collect and use data about your behaviour and preferences. We do this by evaluating information about your behaviour in our area, and we may also supplement this information with information from third parties, including publicly available sources. Based on this, we can calculate, for example, the probability that you will use certain services or behave in a certain way. Some of the data processed for this purpose is already known to us (e.g. when you use our services), or we obtain this data by recording your behaviour (e.g. how you navigate on our website). We anonymise or delete this data when it is no longer meaningful for the purposes pursued, which may be between 2-3 weeks and 24 months (for product and service preferences) depending on the nature of the data. This period may be longer where necessary for evidential purposes or to comply with legal or contractual requirements, or for technical reasons. We describe how tracking works on our website in para. 12.
Other data: We also collect data from you in other situations. In connection with official or judicial proceedings, for example, data is collected (such as files, evidence, etc.) which may also relate to you. We may also collect data for health protection reasons (e.g. in the context of protection concepts). We may obtain or make photographs, videos and sound recordings in which you may be identifiable (e.g. at events, through security cameras etc.). We may also collect data on who enters certain buildings when or has corresponding access rights (incl. in the case of access controls, based on registration data or visitor lists, etc.), who participates in events or campaigns (e.g. competitions) and when, or who uses our infrastructure and systems. Finally, we collect and process data about our shareholders and other investors; in addition to master data, this includes information for the relevant registers, regarding the exercise of their rights and the holding of events (e.g. general meetings). The retention period for this data depends on the purpose and is limited to what is necessary. This ranges from a few days for many of the security cameras and usually a few weeks for contact tracing data to visitor data, which is usually kept for 3 months, to reports on events with pictures, which can be kept for a few years or longer. Data about you as a shareholder or other investor is kept in accordance with company law, but in any case for as long as you are invested.
Many of the measures described in this para. 3 you disclose to us yourself (e.g. via forms, in the course of communication with us, in connection with contracts, when using the website, etc.). You are not obliged to do so, subject to individual cases, e.g. within the framework of binding protection concepts (legal obligations ). If you wish to conclude contracts with us or claim services, you must also provide us with data, in particular master data, contract data and registration data, as part of your contractual obligation under the relevant contract. When using our website, the processing of technical data is unavoidable. If you wish to gain access to certain systems or buildings, you will need to provide us with registration data. However, in the case of behavioural and preference data, you generally have the option of objecting or not giving consent.
Unless this is inadmissible, we also obtain data from publicly accessible sources (e.g. debt collection registers, land registers, commercial registers, the media or the Internet including social media) or receive data from other companies that provide services for you, from public authorities and from other third parties (such as credit agencies, address dealers, associations, contractual partners, Internet analysis services, etc.).
We process your data for the purposes we explain below. Further information for the online area can be found in para. 12 and 13. These purposes or the underlying objectives represent legitimate interests of us and, if applicable, of third parties. You will find further information on the legal basis for our processing in section 5.5.
We process your data for purposes related to communication with you, in particular to respond to enquiries and to assert your rights (para. 11) and to contact you in the event of queries. For this purpose, we use in particular communication data and master data and, in connection with offers and services used by you, also registration data. We keep this data to document our communication with you, for training purposes, for quality assurance and for enquiries.
We process data for the purpose of establishing, managing and processing contractual relationships.
We process data for marketing purposes and to maintain relationships, e.g. to send our customers and other contractual partners personalised advertising on products and services from us and from third parties (e.g. from advertising contractual partners). This may take the form of e.g. newsletters and other regular contacts (electronically, by post, by telephone), via other channels for which we have contact information from you, but also as part of individual marketing campaigns (e.g. events, competitions etc.) and may also include free benefits (e.g. invitations, vouchers etc.). You can refuse such contacts at any time (see at the end of this section). 4) or refuse or revoke your consent to be contacted by for advertising purposes. With your consent, we can target our online advertising on the internet more specifically to you (see section 12). Finally, we also want to enable our contractual partners to contact our customers and other contractual partners for advertising purposes (see section 7).
We continue to process your data for market research, to improve our services and operations and for product development.
We may also process your data for security and access control purposes.
We process personal data to comply with laws, directives and recommendations from authorities and internal regulations ("Compliance").
We also process data for the purposes of our risk management and as part of prudent corporate governance, including operational organisation and corporate development .
We may process your data for other purposes, e.g. as part of our internal processes and administration or for training and quality assurance purposes.
If we ask you for your consent for certain processing (e.g. for the processing of particularly sensitive personal data, for marketing mailings, and for advertising control and behavioural analysis on the website), we will inform you separately about the corresponding purposes of the processing. You can revoke your consent at any time with future effect by notifying us in writing (by post) or, where not otherwise stated or agreed, by e-mail; you will find our contact details in section 2. 2. For the revocation of your consent in the case of online tracking, see para. 12. Where you have a user account, revocation or contacting us may also be possible via the relevant website or other service. Once we have received notification that you have withdrawn your consent, we will no longer process your data for the purposes to which you originally consented unless we have another legal basis for doing so. The revocation of your consent will not affect the lawfulness of the processing carried out on the basis of the consent until the revocation.
Where we do not ask for your consent to process your personal data, we base the processing of your personal data on the fact that the processing is necessary for the initiation or performance of a contract with you (or the entity you represent) or that we or third parties have a legitimate interest in doing so, in particular in order to fulfil the obligations set out in section 4 above. 4 and related objectives described above and to be able to take appropriate action. Our legitimate interests also include compliance with legal regulations, insofar as this is not already recognised as a legal basis by the respective applicable data protection law (e.g. in the case of the GDPR, the law in the EEA and in Switzerland). However, this also includes the marketing of our products and services, the interest in better understanding our markets and in managing and further developing our company, including operations, safely and efficiently.
If we receive sensitive data (e.g. health data, information on political, religious or ideological views or biometric data for identification purposes), we may also process your data on the basis of other legal grounds, e.g. in the event of disputes due to the necessity of the processing for a possible lawsuit or the enforcement or defence of legal claims. In individual cases, other legal grounds may come into play, which we will communicate to you separately where necessary.
We may add certain of your personal attributes to those listed in para. 4 using your data for the purposes set out in section 4. 3) (" Profiling "), if we want to determine preference data , but also to determine abuse and security risks, to carry out statistical evaluations or for operational planning purposes. For the same purposes, we can also create profiles, i.e. we can combine behavioural and preference data, but also master and contract data and technical data assigned to you, in order to better understand you as a person with your different interests and other characteristics.
In both cases, we pay attention to the proportionality and reliability of the results and take measures against misuse of these profiles or profiling. If these can have legal effects or significant disadvantages for you, we generally provide for a manual review.
In connection with our contracts, the website, our services and products, our legal obligations or otherwise in order to protect our legitimate interests and the other interests set out in section 4. We also transfer your personal data to third parties, in particular to the following categories of recipients:
Service providers: We work with service providers in Germany and abroad who process data about you on our behalf or in joint responsibility with us or who receive data about you from us in their own responsibility (e.g. IT providers, shipping companies, advertising service providers, login service providers, cleaning companies, security companies, banks, insurance companies, debt collection companies, credit agencies or address checkers). This may also include health data. For information on the service providers used for the website, see section 12. Our central service providers are SPOT Werbung AG, XIAG AG, i-Community AG, Payyo - Trekksoft AG, Support Engadin St. Moritz AG, Engadin St. Moritz Mountains AG.
Partners as independent responsible parties: Within the framework of our online offer, you have the possibility to obtain goods and services directly from our cooperation partners. In this context, your data will be transferred to the partner (service provider) for the fulfilment of the contract. The information of the service provider with whom you are entering into a contractual relationship can be seen in the order process. The service providers process the personal data forwarded by us on their own responsibility and inform you about this with their own data protection information.
Contractual partners including clients: This initially refers to our customers (e.g. service recipients) and other contractual partners, because this data transfer results from these contracts. For example, they receive registration data on issued and redeemed vouchers, invitations, etc. If you work for such a contractual partner yourself, we may also transfer data about you to them in this context. This may also include health data. The recipients also include contractual partners with whom we cooperate or who advertise on our behalf and to whom we therefore transfer data about you for analysis and marketing purposes (these may again be service recipients, but also e.g. sponsors and providers of online advertising). We require these partners to only send you advertising or play it out based on your data if you have consented to this (for the online area, cf. para. 12). Our central cooperation partners are listed here https://www.engadin.ch/en/privacy-policy/cooperation/partners/; our online advertising contract partners are listed in para. 12 listed.
Authorities: We may disclose personal data to offices, courts and other authorities in Switzerland and abroad if we are legally obliged or entitled to do so or if this appears necessary to protect our interests. This may also include health data. The authorities process data about you that they receive from us on their own responsibility.
Other persons: This refers to other cases where the involvement of third parties arises from the purposes set out in para. 4 e.g. service recipients, media and associations in which we participate or if you are part of one of our publications.
All these categories of recipients may in turn involve third parties, so that your data may also become accessible to them. We can restrict processing by certain third parties (e.g. IT providers), but not by other third parties (e.g. authorities, banks, etc.).
We reserve the right to make these disclosures even if they concern secret data (unless we have expressly agreed with you that we will not disclose this data to certain third parties, unless we would be legally obliged to do so). Notwithstanding the above, your data will continue to be subject to adequate data protection even after disclosure in Switzerland and the rest of Europe. For disclosure in other countries, the provisions of para. 8. If you do not wish certain data to be disclosed, please let us know so that we can check whether and to what extent we can accommodate you (section 2).
We also allow certain third parties to collect personal data from you on our website and at events organised by us (e.g. media photographers, providers of tools that we have embedded on our website, etc.). Insofar as we are not decisively involved in these data collections, these third parties are solely responsible for them. If you have any concerns or wish to assert your data protection rights, please contact these third parties directly. Cf. para. 12 for the website.
As described in para. 7 we also disclose data to other bodies. These are not only located in Switzerland. Your data may therefore be processed both in Europe and in the USA (United States); in exceptional cases, however, in any country in the world.
If a recipient is located in a country without adequate legal data protection, we contractually oblige the recipient to comply with the applicable data protection (for this purpose, we use the revised standard contractual clauses of the European Commission, which can be accessed here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj? ), insofar as it is not already subject to a legally recognised set of rules to ensure data protection and we cannot rely on an exemption provision. An exception may apply in particular in the case of legal proceedings abroad, but also in cases of overriding public interests or if the performance of a contract requires such disclosure, if you have consented or if it is a matter of data that you have made generally accessible and you have not objected to its processing.
Please also note that data exchanged via the internet is often routed via third countries. Your data can therefore end up abroad even if the sender and recipient are in the same country.
We process your data for as long as our processing purposes, the statutory retention periods and our legitimate interests in processing for documentation and evidence purposes require or storage is technically necessary. Further information on the respective storage and processing duration can be found under the individual data categories in section 3. 3 or for the cookie categories in para. 12. If there are no legal or contractual obligations to the contrary, we will delete or anonymise your data after the storage or processing period has expired as part of our normal processes.
We take reasonable security measures to maintain the confidentiality, integrity and availability of your personal data, to protect it against unauthorised or unlawful processing and to protect against the risks of loss, accidental alteration, unauthorised disclosure or access.
Applicable data protection law grants you the right to object to the processing of your data in certain circumstances, in particular for direct marketing, direct marketing profiling and other legitimate processing interests.
To help you control the processing of your personal data, you also have the following rights in connection with our data processing, depending on the applicable data protection law:
If you wish to exercise any of the above rights against us, please contact us in writing, at our premises or, unless otherwise stated or agreed, by email; you will find our contact details in para. 2. In order for us to be able to exclude abuse, we must identify you (e.g. with a copy of your identity card, unless otherwise possible).
You also have these rights vis-à-vis other bodies that cooperate with us on their own responsibility - please contact them directly if you wish to exercise rights in connection with their processing. You can find details of our important cooperation partners and service providers in section 7. 7Further information can be found in para. 12.
Please note that conditions, exceptions or restrictions apply to these rights under applicable data protection law (e.g. to protect third parties or trade secrets). We will inform you accordingly if necessary.
If you do not agree with our handling of your rights or data protection, please let us know (para. 2). In particular, if you are in the EEA, the UK or Switzerland, you also have the right to complain to the data protection supervisory authority in your country. A list of authorities in the EEA can be found here: https://edpb.europa.eu/about-edpb/board/members_de. You can reach the UK supervisory authority here: https://ico.org.uk/global/contact-us/. You can reach the Swiss supervisory authority here: https://www.edoeb.admin.ch/edoeb/en/home/adresse.html.
We use various technologies on our website that enable us and third parties we have engaged to recognise you when you use our website and, in some circumstances, to track you across multiple visits. We inform you about this in this section.
In essence, this is so that we can distinguish accesses by you (via your system) from accesses by other users, so that we can ensure the functionality of the website and carry out evaluations and personalisations. In doing so, we do not want to infer your identity, even if we can do so insofar as we or third parties engaged by us can identify you through a combination with registration data. Even without registration data, however, the technologies used are designed in such a way that you are recognised as an individual visitor each time you access the site, for example by our server (or the servers of the third parties) assigning you or your browser a specific identification number (so-called "cookie").
We use such techniques on our website and allow certain third parties to do so as well. However, depending on the purpose of these techniques, we may ask for your consent before they are used. You can access your current settings here [ Link ]. You can programme your browser to block or deceive certain cookies or alternative techniques, or to delete existing cookies. You can also enhance your browser with software that blocks tracking by certain third parties. You can find more information about this on the help pages of your browser (usually under the keyword "data protection") or on the websites of the third parties that we list below.
A distinction is made between the following cookies (techniques with comparable functions such as fingerprinting are included here):
Necessary cookies: Some cookies are necessary for the website to function as such or for certain functions. For example, they ensure that you can switch between pages without losing information entered in a form. They also ensure that you remain logged in. These cookies are only temporary ("session cookies"). If you block them, the website may not work. Other cookies are necessary so that the server can save decisions or entries made by you beyond one session (i.e. one visit to the website) if you use this function (e.g. language selected, consent given, the function for automatic login etc.). These cookies have an expiry date of up to 24 months.
We may also integrate further offers from third parties on our website, in particular from social media providers. These offers are deactivated by default. As soon as you activate them (e.g. by clicking a button), the corresponding providers can determine that you are on our website. If you have an account with the social media provider, they can assign this information to you and thus track your use of online offers. These social media providers process this data on their own responsibility.
We currently use offers from the following service providers and advertising contract partners (insofar as they use data from you or cookies set by you for advertising purposes): https://www.engadin.ch/en/privacy-policy/service-providers/
We may operate pages and other online presences ("fan pages", "channels", "profiles", etc.) on social networks and other platforms operated by third parties and use the services described in section 3. 3 and hereinafter described data about you. We receive this data from you and the platforms when you come into contact with us via our online presence (e.g. when you communicate with us, comment on our content or visit our presence). At the same time, the platforms evaluate your use of our online presences and link this data with other data about you known to the platforms (e.g. on your behaviour and preferences). They also process this data for their own purposes under their own responsibility, in particular for marketing and market research purposes (e.g. to personalise advertising) and to control their platforms (e.g. which content they show you).
We process this data for the purposes described in para. 4 in particular for communication, for marketing purposes (including advertising on these platforms, cf. 12) and for market research. You will find information on the corresponding legal basis in section 5. 5. Content published by you yourself (e.g. comments on an announcement) may be disseminated by us (e.g. in our advertising on the platform or elsewhere). We or the operators of the platforms may also delete or restrict content from or about you in accordance with the usage guidelines (e.g. inappropriate comments).
For further information on the processing of the platform operators, please refer to the data protection notices of the platforms. There you will also find out in which countries they process your data, what rights of access, deletion and other data subjects you have and how you can exercise these or obtain further information. We currently use the following platforms:
Facebook: Here we operate the page https://www.facebook.com/engadinstmoritz. The responsible body for operating the platform for users from Europe is Facebook Ireland Ltd, Dublin, Ireland. Their data protection information is available at www.facebook.com/policy. Some of your data will be transferred to the USA. You can object to advertising here: www.facebook.com/settings?tab=ads. With regard to the data collected and processed when visiting our site for the creation of "Page Insights", we are jointly responsible with Facebook Ireland Ltd, Dublin, Ireland. As part of Page Insights, statistics are compiled about what visitors do on our site (comment on posts, share content, etc.). This is described at www.facebook.com/legal/terms/information_about_page_insights_data. It helps us understand how our site is used and how we can improve it. We only receive anonymous, aggregated data. We have regulated our responsibilities regarding data protection in accordance with the information on www.facebook.com/legal/terms/page_controller_addendum.
Instagram: We have a profile on Instagram. The provider of this service is Facebook Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The transfer of data to the USA takes place on the basis of the Standard Contractual Clauses (SCC) of the European Commission. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://help.instagram.com/519522125107875 and https://de-de.facebook.com/help/566994660333381.
This privacy notice does not form part of any contract with you. We may amend this privacy notice at any time. The version published on this website is the current version.
Last updated: 31.08.2023