Privacy Policy

Note: This is a translation for convenience. In case of doubt, the German version of this privacy policy prevails.


1. Controller

The controller responsible for data processing is:

CoyHomes e.U., owner Cemal Yildiz, Raxstraße 26/1/6, 1100 Vienna, Austria

Email: info@coyhomes.com · Phone: +43 676 9503887

For any questions about data protection, please contact us at info@coyhomes.com. We are not legally required to appoint a data protection officer.


2. Overview

We only process personal data to the extent necessary to provide our website, handle bookings and stays, comply with legal obligations, or on the basis of your consent. The legal bases are the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG) and the Austrian Telecommunications Act 2021 (TKG 2021).


3. Visiting the website and hosting

Our website is operated with the website builder of Hostaway (Hostaway Opco Oy, Finland); the technical service provider is Duda Inc., USA. When you visit the website, the following data is automatically stored in server log files: IP address, date and time, page visited, browser and operating system, referrer URL.

Purpose: secure and stable operation of the website, defence against attacks.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation).

Retention: generally no longer than 30 days, except in the event of security incidents.

All data is transmitted in encrypted form (SSL/TLS).


4. Cookies and consent

On your first visit, a cookie banner with the equally prominent buttons "Accept" and "Decline" is shown. Without your consent, no statistics cookies are set and Google Analytics is not loaded.

We use technically necessary cookies and storage entries (e.g. for bookings, language selection and storing your cookie choice for 12 months) without consent (Section 165(3) TKG 2021, Art. 6(1)(f) GDPR).

We only set statistics cookies (Google Analytics) if you select "Accept" in the cookie banner (Section 165(3) TKG 2021, Art. 6(1)(a) GDPR). Consent is voluntary. You can withdraw it at any time with effect for the future by clicking "Cookie settings" in the footer and selecting "Decline"; any Analytics cookies already set will then be deleted. You can also block or delete cookies in your browser settings.


5. Google Analytics

With your consent, we use Google Analytics 4 provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics analyses how the website is used (e.g. pages visited, time spent, approximate location, device type). IP addresses are shortened within the EU and not stored.

Legal basis: Art. 6(1)(a) GDPR.

Retention: 14 months.

Data may be transferred to Google LLC in the USA, which is certified under the EU-US Data Privacy Framework. Further information: policies.google.com/privacy.


6. Google reCAPTCHA

To protect our contact and enquiry forms against spam, we use Google reCAPTCHA (Google Ireland Limited). Among other things, your IP address, mouse movements and browser data are transmitted to Google to check whether the input comes from a human.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in protection against misuse).


7. Map service

On our contact pages we embed a map from Mapbox (Mapbox Inc., USA). When the map loads, your IP address is transmitted to Mapbox.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in showing our location in an easy-to-find way). The transfer to the USA is based on EU Standard Contractual Clauses.


8. Contact via form, email, phone and WhatsApp

When you contact us, we process the data you provide (e.g. name, email, phone number, company, dates, message) to answer your enquiry and prepare an offer.

We use Hostinger (Hostinger International Ltd., Cyprus) for email.

If you contact us via WhatsApp, WhatsApp Ireland Limited (Meta) also processes your data. We only use WhatsApp Business for conversations that you start. You can always reach us by email or phone instead.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (answering general enquiries).

Retention: enquiries that do not lead to a booking are deleted after 12 months at the latest.


9. Booking via our website

For direct bookings, we use the booking and management system Hostaway (Hostaway Opco Oy, Finland). We process: name, address, email, phone number, travel dates, number of guests, special requests, booking and payment status, and booking-related communication.

Purpose: conclusion and performance of the accommodation contract, sending the booking confirmation, arrival information and invoice.

Legal basis: Art. 6(1)(b) GDPR (contract); for invoices Art. 6(1)(c) GDPR (legal obligation).


10. Payment

Payments are processed by Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland. Stripe processes your card details, name, email and billing address as well as data for fraud prevention. We do not receive full card numbers.

Legal basis: Art. 6(1)(b) GDPR; for fraud prevention Art. 6(1)(f) GDPR. Stripe may also transfer data to the USA (EU-US Data Privacy Framework).


11. Online check-in, guest registration and local tourist tax

Under the Austrian Registration Act (Meldegesetz) and its implementing regulation, we are required to keep a guest register. For this we use the online check-in service Chekin (Spain). The following is recorded: first and last name, date of birth, nationality, sex, home address, type, number and issuing authority of the travel document, arrival and departure date and, where applicable, a photo of the ID document for verification.

We also use this data to calculate and pay the local tourist tax (Ortstaxe) to the respective municipality.

Legal basis: Art. 6(1)(c) GDPR (Registration Act, regional tourism laws).

Retention: 7 years from the last entry (Section 19 MeldeV), then deleted. On request, we pass the data on to the competent authorities (police, municipality, Statistics Austria).


12. Security deposit and Damage Protection

During online check-in, a security deposit is pre-authorised on your payment card or you take out Damage Protection. Chekin and its payment service providers process your payment data for this purpose. For Damage Protection, the data needed to handle a claim is transmitted to Chekin's insurance partner (Waivo).

Legal basis: Art. 6(1)(b) GDPR; in the event of damage Art. 6(1)(f) GDPR (asserting claims).


13. Self check-in and access

For contactless access you receive personal access details (code or key box). With electronic locks, the times at which access is used are logged. We use these logs only for security and to clarify damage or incidents, and delete them after 90 days at the latest.

Legal basis: Art. 6(1)(b) and (f) GDPR.


14. Video surveillance

We use video surveillance at two properties:

  • Purkersdorf (Bahnhofstraße 11): cameras in the garden area.
  • Mautern an der Donau (Sankt Pöltner Straße 18): three cameras in the shared indoor areas of the building (two on the ground floor, one on the upper floor).

There are no cameras inside the apartments themselves (living, sleeping and sanitary rooms). The cameras do not record the inside of apartments, public ground or neighbouring properties, as far as technically avoidable. No audio is recorded.

Purpose: protection of property and persons, prevention of burglary, theft and vandalism, and clarification of incidents and securing of evidence.

Legal basis: Art. 6(1)(f) GDPR in conjunction with Sections 12 and 13 DSG (legitimate interest in protecting property and persons).

Signage: the monitored areas are marked with clearly visible signs.

Retention: recordings are automatically overwritten after 72 hours at the latest. Only if a specific incident occurs (e.g. burglary, damage to property) are the relevant recordings kept until the matter is clarified or proceedings are concluded.

Access: only the owner has access to the recordings. They are only reviewed when there is a specific reason. In the event of incidents, recordings may be passed on to the police, public prosecutor, courts or insurers.

There is no monitoring of the performance or behaviour of guests or staff.


15. Bookings via platforms

If you book via Airbnb, Booking.com or Vrbo, we receive your booking data from the platform (name, contact details, travel dates, number of guests, messages) and process it via Hostaway to manage your stay. The platform's own privacy policy applies to its processing.

Legal basis: Art. 6(1)(b) GDPR.


16. Business customers

For company bookings we additionally process the company name, contact person, billing address, VAT number and the names and dates of stay of the employees accommodated.

Legal basis: Art. 6(1)(b) and (c) GDPR; for the employees' data Art. 6(1)(f) GDPR (performance of the contract with the company) and (c) (registration obligation).


17. Reviews and guest communication

Before and during your stay we automatically send you information about arrival, access and departure. After your stay we may ask you for a review. You can object to this at any time. We only send marketing emails with your express consent.

Legal basis: Art. 6(1)(b) GDPR; for review requests Art. 6(1)(f) GDPR in conjunction with Section 174 TKG 2021.


18. Recipients and processors

We only pass on your data where this is necessary for the purposes stated or required by law:

  • Hostaway Opco Oy (booking system, website, guest communication)
  • Duda Inc. (technical operation of the website)
  • Stripe Payments Europe Ltd. (payments)
  • Chekin (Spain) and Waivo (online check-in, security deposit, Damage Protection)
  • Google Ireland Limited (Analytics only with consent, reCAPTCHA)
  • Mapbox Inc. (map display)
  • Hostinger International Ltd. (email)
  • WhatsApp Ireland Limited (if you use WhatsApp)
  • Airbnb, Booking.com, Vrbo (only for bookings made via these platforms)
  • Cleaning and maintenance staff (only arrival and departure dates and number of guests)
  • Tax advisors and accountants
  • Authorities (registration authority, municipality for tourist tax, tax office, Statistics Austria) to the extent required by law
  • In the event of incidents: police, public prosecutor, courts and insurers (e.g. video recordings as evidence)

Where our service providers act as processors, we have concluded agreements with them under Art. 28 GDPR.


19. Transfers to third countries

Some service providers (in particular Google, Stripe, Duda, Mapbox, Meta) also process data in the USA. Transfers are based on an adequacy decision (EU-US Data Privacy Framework, Art. 45 GDPR) or on EU Standard Contractual Clauses (Art. 46 GDPR).


20. Retention periods at a glance

  • Guest register (registration data): 7 years from the last entry
  • Booking, invoice and payment data: 7 years (Section 132 BAO), longer in the case of ongoing proceedings
  • Booking-related communication: until the end of the retention period for the booking
  • Enquiries without a booking: 12 months at most
  • Access logs of electronic locks: 90 days at most
  • Video recordings: 72 hours at most, in the event of incidents until clarified
  • Cookie choice: 12 months
  • Google Analytics data: 14 months
  • Server log files: generally 30 days at most


21. Obligation to provide data

The information required for the booking and guest registration is necessary to conclude the contract and under the Registration Act. Without it, we cannot accept a booking or grant access. All other information is voluntary.


22. No automated decision-making

We do not make decisions based solely on automated processing within the meaning of Art. 22 GDPR. Our payment service providers use automated checks for fraud prevention.


23. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You can withdraw any consent given at any time with effect for the future (Art. 7(3) GDPR).

Right to object: Where we process data on the basis of a legitimate interest, you can object at any time on grounds relating to your particular situation. You can object to the use of your data for review requests or marketing at any time without giving reasons.

To exercise your rights, write to info@coyhomes.com. We will reply within one month and may ask for proof of identity.

Right to lodge a complaint: You can lodge a complaint with the Austrian Data Protection Authority: Barichgasse 40–42, 1030 Vienna, phone +43 1 52 152-0, dsb@dsb.gv.at, www.dsb.gv.at.


24. Data security

We protect your data through technical and organisational measures, in particular encrypted transmission, access restricted to authorised persons, secure passwords and, where available, two-factor authentication for our systems.


25. Changes

We update this privacy policy when our services or the legal situation change. The version published on this website at the relevant time applies.

Last updated: October 2026