Privacy policy

1. Controller


Responsible for the processing of your personal data within the meaning of the Swiss Data Protection Act (DPA) and the EU General Data Protection Regulation (GDPR) are:


Bronze / Weltrich

Neubachstrasse 40, 7050 Arosa

Email: sottolagoarosa@gmail.com


We rent the holiday apartment privately. There is no data protection officer.


2. What Data We Process


Booking and contract data: name, address, email address, telephone number, number of guests, as well as names and dates of birth of all accompanying persons, arrival and departure dates, payment details, correspondence with us.


Communication data: content and timing of your inquiries by email, contact form, telephone, or the messaging function of the booking system.


Technical website data: IP address, date and time of access, pages accessed, browser type and operating system, referring website. This data arises automatically when the website is visited.


Access data: The numeric code belonging to the apartment is provided to you before arrival and changed after your departure. We do not use any cameras, recording doorbells, or sound sensors — neither inside nor outside the apartment.


3. For What Purposes and on What Basis


Processing your booking. We need your data to conclude the rental contract, provide the apartment, communicate with you, handle payment, and organize cleaning. The basis is contract performance (Art. 31 para. 2 lit. a DPA, Art. 6 para. 1 lit. b GDPR).


Fulfillment of legal obligations. The municipality of Arosa requires the reporting of the names, addresses, and dates of birth of all overnight guests for the levying of the visitor's tax. We are also subject to retention obligations under the Swiss Code of Obligations (Art. 6 para. 1 lit. c GDPR).


Legitimate interests. We process data to ensure the technical operation and security of the website, to handle any damage cases, and to assert or defend legal claims (Art. 6 para. 1 lit. f GDPR).


Consent. Where, with your express consent, we occasionally send you information about our holiday apartment, this is done on the basis of your consent, which you may withdraw at any time (Art. 6 para. 1 lit. a GDPR).


We do not use your data for profiling, automated individual decisions, or third-party advertising, and we do not sell data.


4. To Whom We Disclose Data


We disclose data only insofar as this is necessary for the stated purposes:


Smoobu GmbH, Berlin (Germany) — operation of the booking system and this website. A data processing agreement is in place.

Stripe Payments Europe Ltd., Dublin (Ireland) — processing of the deposit and remaining payment. Your payment data is collected and processed directly by Stripe; we do not receive or store full credit card numbers, only the information whether and when a payment was made. Stripe's privacy provisions additionally apply.

Municipality of Arosa / Arosa Tourism — guest registration and visitor's tax accounting, based on legal obligation.

On-site cleaning and service staff — exclusively name, number of persons, and arrival and departure times.

Booking platforms — if you booked via a platform, their privacy provisions additionally apply.

Fiduciary, tax, and legal advisors as well as insurers — only on a case-by-case basis and only as far as necessary.

Authorities and courts — insofar as we are legally obliged to do so.


5. Disclosure Abroad


Our website and the booking system are operated in Germany. According to the assessment of the Swiss Federal Council, the European Economic Area has an adequate level of data protection.


Within the scope of payment processing via Stripe, data may be transferred to group companies in the United States. This transfer is based on the Standard Contractual Clauses of the European Commission as well as on further appropriate safeguards of the provider.


Should, in individual cases, further data be transferred to countries without an adequate level of protection, we likewise rely on the Standard Contractual Clauses or on one of the statutory exceptions.


6. How Long We Retain Data


Booking and payment records: ten years from the end of the financial year, in accordance with commercial law retention obligations.

Inquiries that did not lead to a booking: twelve months.

Website server log files: only as long as necessary for secure operation, but at most twelve months.

Payment-related data at Stripe: in accordance with the provider's retention periods and provisions.

Data we process on the basis of your consent: until withdrawal.


Afterwards we delete or anonymize the data, provided there is no legal obligation for further retention.


7. Cookies and Website Analysis


Our website uses cookies — small text files that are stored on your device.


Technically necessary cookies are required for the operation of the website and in particular for the booking and payment function. Without them, booking does not work. For these cookies, no consent is required under applicable law; we base them on our legitimate interest in the proper operation of the website.


Analysis and marketing cookies we use only if you have previously consented via the cookie banner. You can withdraw your consent at any time with effect for the future by calling up the cookie settings again or deleting the cookies in your browser.


Within the scope of payment processing, Stripe sets its own cookies, among other things for fraud detection. These are necessary for a secure payment.


You can also generally block or delete cookies in your browser settings. The booking function may thereby be restricted or fail.


8. Your Rights


You have the right to access the data processed about you, to have inaccurate data corrected, to erasure, to restriction of processing, to object to certain processing, and to the release or transfer of your data in a common format. You can withdraw any consent given at any time for the future.


To do so, contact us informally at sottolagoarosa@gmail.com. For security, we may request proof of identity.


If you are not satisfied with our response, you can lodge a complaint:


in Switzerland, with the Federal Data Protection and Information Commissioner (FDPIC), Bern;

in the EU, with the data protection authority of your country of residence.


9. Data Security and Changes


We take appropriate technical and organizational measures to protect your data, in particular encrypted transmission via this website. Complete protection against any unauthorized access is technically not possible.


We may adapt this Privacy Policy. The version published on this website at any given time is authoritative.


Last updated: August 2026