Privacy policy
This policy applies to the website furx13.com and the services it uses, under the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG). The German version is the authoritative one.
1. Controller
Daniel Mierer, Furx 13, 6835 Zwischenwasser, Austria. Telephone: +43 664 8267484, e-mail: [email protected]. No data protection officer has been appointed, as there is no legal obligation to do so (Art. 37 GDPR).
2. Hosting – Railway, Cloudflare
The website runs at Railway Corp. (USA) on servers in the EU and is delivered through the network of Cloudflare, Inc. (USA). Technically necessary data such as IP address, time and page requested are processed; Railway deletes its server logs after 30 days at the latest. Legal basis: legitimate interest in secure and fast operation (Art. 6(1)(f) GDPR). Any access from the USA is covered by the European Commission’s standard contractual clauses; Cloudflare is also certified under the EU-US Data Privacy Framework.
3. Database & CMS – Railway Postgres / Payload
The database (at Railway, see section 2) stores the website’s content and the CMS accounts. Guest data is not stored there – it is held at Smoobu (section 5). Contact enquiries and booking confirmations are not stored in the database; they are delivered by email only.
4. Statistics
No audience measurement takes place. No analytics tools are used, no visitor profiles are created and no statistics cookies are set.
5. Booking – Smoobu
The booking tool on this website is provided by Smoobu GmbH, Berlin, and embedded directly from its servers. When you book, Smoobu processes your name, email, telephone, address, travel dates, number of guests, your message and your planned arrival time. Purpose: conclusion and performance of the accommodation contract (Art. 6(1)(b) GDPR). A data processing agreement is in place with Smoobu. If the house is also listed on booking portals, Smoobu only synchronises the occupancy with them. After a booking, the website retrieves the booking data from Smoobu to send you a confirmation by email (sent via Resend, section 8); the data is not stored in the process. Retention of booking data: 7 years pursuant to § 132 BAO.
6. Payment
Payment is made by bank transfer against invoice. No online payment services such as credit card or PayPal are used. We only receive your bank details to the extent they are transmitted with your transfer. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
7. Guest registration & local tax
We are legally obliged to register our guests (Meldegesetz 1991, guest registration form) and to remit the local tax to the municipality of Zwischenwasser. Data processed: name, date of birth, nationality, identity document details, arrival and departure. It is collected on arrival or in advance via Smoobu’s online check-in, where offered. Legal basis: legal obligation (Art. 6(1)(c) GDPR). Retention: 7 years (§ 10 Meldegesetz 1991).
8. Contact form & email – Resend, Cloudflare
Messages sent via the contact form (name, email, travel dates, occasion, number of guests, message) are delivered to us by email by Resend, Inc., USA; sending runs via servers in the EU (Ireland). You receive a confirmation at your email address. A data processing agreement is in place with Resend; any access from the USA is covered by standard contractual clauses. Emails to [email protected] are forwarded by Cloudflare (Email Routing) to our mailbox at Google Ireland Limited (Gmail); we send our replies via Resend. Spam protection is provided by Cloudflare Turnstile: it checks whether a human is submitting the form and processes the IP address and browser characteristics without setting cookies. Legal basis: steps prior to entering into a contract (Art. 6(1)(b) GDPR) or legitimate interest (Art. 6(1)(f) GDPR). Data is deleted once handled, at the latest after 12 months, if no booking follows.
9. Google Maps (only with consent)
The map is embedded only after you click “Load map”. Google Ireland Limited then processes your IP address and may set cookies. Legal basis: consent (Art. 6(1)(a) GDPR), revocable at any time via “Cookie settings” in the footer.
10. YouTube videos (enhanced privacy mode)
Videos are embedded via youtube-nocookie.com and load only after you click the preview image. Google Ireland Limited then processes your IP address and usage data. Legal basis: consent through active playback (Art. 6(1)(a) GDPR).
11. Cookies & local storage
We do not set any marketing or statistics cookies. The following are technically necessary and permitted without consent (§ 165(3) TKG 2021):
NEXT_LOCALE – remembers your chosen language – 1 year
furx-consent – remembers your cookie setting (as a cookie and in the browser’s local storage) – 1 year
payload-token – CMS login, for editors only – 2 hours
Smoobu booking tool (embedded from booking.smoobu.com) – cookies set by Smoobu for the booking process, see Smoobu’s privacy policy
Google sets cookies only with your consent: when the map is loaded (section 9) and when a video is played (section 10).
12. Fonts & external resources
The website’s typeface (Sora) is loaded from our own server – in our emails, too. There is no connection to Google Fonts. Without consent, only the Smoobu booking tool (section 5) and Cloudflare’s spam protection (section 8) are loaded; both are technically necessary.
13. Reviews & platforms
We transfer reviews by hand and show them without personal data beyond a first name and place of origin. Bookings made via booking portals are subject to their own privacy terms.
14. Social media
The website does not embed any content or plugins from social networks.
15. Data security
The connection is encrypted throughout (TLS, HSTS). The CMS can only be accessed with a personal login, and the database is backed up regularly.
16. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection, and the right to withdraw any consent given. Contact: [email protected]. You have the right to lodge a complaint with the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, [email protected].
17. Retention periods (overview)
Booking and invoice data 7 years (§ 132 BAO) · guest registration forms 7 years (§ 10 Meldegesetz 1991) · contact enquiries up to 12 months · server logs 30 days at most.
18. Changes
Version: September 2026. This policy is updated whenever the technology used changes.