1. General Information
This Privacy Policy explains which personal data we process when you visit this website, contact us, make a booking or stay at one of our properties. Personal data means any information relating to an identified or identifiable person. We process personal data confidentially, for specific purposes and in accordance with Swiss data protection law. Where the European Union General Data Protection Regulation applies, we also comply with its provisions.
2. Data Controller
The controller responsible for processing personal data is Cristina Würgler, c/o WUMASO AG, Weidstrasse 2c, 8607 Aathal-Seegräben, Switzerland. Questions regarding data protection and requests for access, rectification or deletion may be sent by email to info@hapiplaces.com or by telephone to +39 333 141 6264.
3. Applicable Data Protection Law
Personal data is processed in particular in accordance with the Swiss Federal Act on Data Protection and the corresponding Data Protection Ordinance. Where the European Union General Data Protection Regulation applies to particular processing activities, the processing is carried out, in particular, for the performance of a contract or pre-contractual measures, compliance with legal obligations, the pursuit of legitimate interests or on the basis of consent.
4. Personal Data Processed
Depending on how our website and services are used, we may process names, addresses, telephone numbers, email addresses, dates of birth, nationalities, booking and stay details, the number and composition of accompanying guests, payment and billing information, messages and correspondence, information from identity documents, technical access data and other information voluntarily provided to us or submitted as part of a booking.
5. Website Visits and Technical Access Data
When this website is accessed, technical data may be collected automatically. This may include the IP address, date and time of access, pages viewed, the previously visited page, information about the browser, operating system and device used, and technical error and security information. This data is required to provide the website technically, ensure its stability and security, detect errors and prevent unauthorised access. Technical data is stored only for as long as required for these purposes or for as long as statutory retention obligations apply.
6. Contacting Us
When you contact us through the contact form, by email, by telephone or through a messaging service, we process the contact details provided and the content of the enquiry. This processing is carried out to respond to the enquiry, provide information about a property, prepare a possible booking or manage an existing booking. The data is stored until the enquiry has been fully processed. It is retained for longer only where required for the performance of a contract, documentation of communications, the assertion or defence of claims or compliance with legal obligations.
7. Bookings and Contract Administration
When a booking is made, we process the data required to prepare, conclude and perform the rental agreement. This includes, in particular, the identity and contact details of the person making the booking, travel dates, the selected property, the number of guests, accompanying persons, the booking price, the selected payment method and any special messages relating to the stay. The rental agreement cannot be concluded or performed without the information required for the booking.
8. Booking and Management Software
We use booking and channel management systems to manage availability, bookings, guest data, messages and payments. This may include Smoobu GmbH, Pappelallee 78/79, 10437 Berlin, Germany. The service providers used process personal data on our behalf or under their own responsibility under data protection law. In particular, contact, booking, stay, communication and payment information may be processed.
9. Bookings Through Intermediary Platforms
If a property is reserved through an external booking or intermediary platform, we receive from the relevant platform the information required to perform the booking. This may include names, contact details, travel dates, guest details, payment status, messages and booking numbers. The relevant platform’s own privacy policy also applies to the processing of data by that platform.
10. Payment Processing
Banks, credit card companies and other payment service providers may be used to process payments. The information required for the selected payment method is transmitted to the relevant service provider. This may include the name, billing address, booking number, payment amount, currency and payment status. The relevant payment service provider may be independently responsible for processing complete bank account or credit card details. The privacy policy of the respective provider also applies to its processing activities.
11. Online Check-in and Statutory Guest Registration
To prepare the stay and comply with statutory reporting obligations, we process the required information relating to all arriving guests. This may include the guest’s name, gender, date of birth, place of birth, nationality, arrival date, length of stay and the type, number and place of issue of an identity document. Where required by law, this information is transmitted to the competent police, security, tourism, statistical or municipal authorities. Access to the property cannot be guaranteed unless the required guest data is provided completely and on time.
12. Identity Documents
Information from identity documents is processed only to the extent required to identify guests and comply with statutory reporting obligations. Images or copies of identity documents are not retained for longer than necessary to transmit the guest data as required by law. Images and copies that are no longer required are deleted or destroyed after the information has been transmitted. Legally required transmission confirmations and supporting records may be stored for the applicable retention period.
13. Communication and Support During the Stay
For the organisation and management of the stay, contact details, booking information and messages may be shared with local contact persons, cleaning staff, property managers, tradespeople or other persons required to provide the booked services. Only the information required for the relevant task is disclosed. The persons and service providers involved are required to treat the information received confidentially.
14. Cookies and Similar Technologies
This website may use cookies and similar technologies. Technically necessary cookies are used in particular to provide essential website functions, language settings, the booking process, security and the display of content. Where analytics, convenience or marketing technologies are used, they are activated only on the basis of the consent required for this purpose. Consent may be changed or withdrawn at any time with future effect through the cookie settings provided on the website. Cookies may also be deleted or blocked through the settings of the browser used. This may restrict certain functions of the website.
15. Embedded Content and External Services
This website may include services provided by external providers, such as booking forms, maps, fonts, videos, security services or payment functions. When such content is accessed or used, technical data, particularly the IP address, and other usage information may be transmitted to the relevant provider. Services that are not strictly necessary for the operation of the website are activated only where the required consent has been given. The external provider’s own privacy policy may apply to its further processing of the data.
16. Recipients of Personal Data
To the extent required, personal data may be disclosed to hosting and IT service providers, booking and management providers, payment service providers, banks, intermediary platforms, communication providers, local contact persons, cleaning staff, tax and legal advisers, insurers and competent authorities. Data is disclosed only where required to provide the website, process an enquiry, perform a booking, comply with legal obligations, protect legitimate interests or assert or defend legal claims.
17. Disclosure of Data Abroad
Personal data may be processed in Switzerland, the European Union, the European Economic Area and other countries in which the service providers used or their subcontractors are located. If data is disclosed to a country without a legally recognised adequate level of data protection, we take the measures required under the applicable data protection law. These may include recognised standard contractual clauses, contractual safeguards or legally permitted exceptions.
18. Retention Period
Personal data is retained for as long as required for the relevant processing purpose. Booking, contractual, payment and billing data may also be retained for the applicable statutory retention periods. Data may additionally be stored for as long as claims arising from a contractual relationship may be asserted or where retention is required for evidentiary purposes, security or compliance with official requirements. Once the processing purpose no longer applies and the relevant retention periods have expired, the data is deleted or anonymised.
19. Data Security
We take appropriate technical and organisational security measures to protect personal data against loss, unauthorised access, misuse, alteration or unlawful disclosure. These measures include access restrictions, secure login credentials, encrypted data transmission, regular updates to the systems used and limiting access to persons who require the data for their tasks. Despite these measures, complete security cannot be guaranteed when data is transmitted over the internet.
20. Rights of Data Subjects
Within the scope of the applicable data protection law, data subjects may request information as to whether and which personal data concerning them is being processed. They may also request the rectification of inaccurate data, deletion or restriction of processing, the release or transfer of certain data and object to certain processing activities. Consent may be withdrawn at any time with future effect. These rights may be restricted where legal obligations, overriding interests, the performance of a contract or the assertion, exercise or defence of legal claims prevent their exercise.
21. Complaints to a Supervisory Authority
Data subjects may submit a complaint to the competent data protection supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner. Where the European Union General Data Protection Regulation applies, a complaint may also be submitted to the competent data protection supervisory authority in a member state of the European Union or the European Economic Area. For processing activities relating to properties in Italy, the Garante per la protezione dei dati personali may be the competent authority.
22. Automated Decision-Making
As a general rule, we do not make decisions based solely on automated processing that produce legal effects concerning a data subject or similarly significantly affect that person. Individual service providers may carry out automated security or fraud checks. Where this results in a legally relevant automated decision, the information and rights described in the privacy policy of the relevant service provider apply.
23. Data Relating to Children and Young People
When bookings are made for families, personal data relating to minor guests may also be processed. This information is used exclusively to perform the booking, prepare the stay and comply with statutory reporting obligations. The data must be provided by a person with parental responsibility or another appropriately authorised person.
24. Changes to This Privacy Policy
This Privacy Policy may be amended if the services offered, the systems used, legal requirements or data processing activities change. The version published on this website at the relevant time applies. Significant changes will be communicated in an appropriate manner.
Last updated: July 2026
