This English version is provided for convenience. The German version remains legally authoritative.
Last updated: 12 August 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection legislation is:
InterAlpen Holding GmbH
Bahnhofstr. 27
83684 Tegernsee
Germany
Email: info@interalpenholding.com
Managing Director authorised to represent the company: Henrik Streblow
2. General information on data processing
Protecting your personal data is important to us.
Personal data means any information relating to an identified or identifiable natural person. This may include, for example, a name, contact details, an IP address or information about the use of our website.
We process personal data solely in accordance with applicable legislation, in particular the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and – where information is stored on or read from terminal equipment – the German Telecommunications Digital Services Data Protection Act (TDDDG).
As a rule, personal data is retained only for as long as necessary for the relevant purpose of processing or for as long as statutory retention obligations apply.
3. Hosting and server log files
This website is hosted by
IONOS SE
Elgendorfer Straße 57
56410 Montabaur
Germany
.
When you access our website, the web server processes connection and access data that is technically necessary. This may include in particular:
- IP address,
- date and time of access,
- page or file accessed,
- amount of data transferred,
- referrer URL,
- browser type and browser version,
- operating system used,
- access status or HTTP status code.
The processing is carried out to make our website technically available, ensure its stability and security, detect attacks and abusive access, and analyse technical errors.
The legal basis is Article 6(1)(f) GDPR.
Our legitimate interest lies in providing our online service securely, reliably and in full working order.
Where IONOS processes personal data on our behalf, it does so under a data processing agreement pursuant to Article 28 GDPR.
Server log data is retained only for as long as necessary for operation, security and error analysis. A longer retention period may be necessary in particular where there are specific indications of unlawful use or a security incident, or where statutory retention obligations so require.
4. SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, this website uses SSL/TLS encryption.
You can recognise an encrypted connection, in particular, by the fact that your browser's address bar begins with “https://”.
As a rule, encryption prevents third parties from readily reading data that you transmit to us.
5. Cookies and similar technologies
Our website may use cookies and similar technologies.
Cookies are small pieces of information that may be stored on or read from your terminal equipment.
Where storing information on your terminal equipment or accessing information already stored there is strictly necessary for technical reasons, this takes place on the basis of section 25(2) TDDDG.
Technically necessary technologies may be used in particular to ensure the basic functions and security of our website and to store your privacy preferences.
Where storage or access is not strictly necessary for technical reasons, it takes place only with your prior consent pursuant to section 25(1) TDDDG.
Where personal data is subsequently processed in connection with these technologies, the processing is based in particular on Article 6(1)(a) GDPR, provided that you have given the relevant consent.
You may withdraw consent at any time with effect for the future.
You can change your preferences through the cookie or privacy settings provided on our website.
6. Consent management with Complianz
We use the Complianz consent management solution on our website to manage your choices concerning services that require consent and services that are technically necessary, and to document consent that has been given.
In particular, the following information may be stored or processed:
- consent status,
- categories selected,
- time of selection,
- version of the underlying privacy or cookie settings,
- information technically necessary to store your selection.
Under our current configuration, Complianz is operated locally within our WordPress installation.
Where Complianz stores information on or reads information from your terminal equipment and this is strictly necessary to store your privacy selection, it does so on the basis of section 25(2) TDDDG.
Personal data is processed to manage and document your selection on the basis of Article 6(1)(c) GDPR, to the extent that this enables us to comply with statutory evidential and accountability obligations.
Article 6(1)(f) GDPR may also provide a legal basis. Our legitimate interest lies in managing privacy settings in a legally compliant, transparent and user-friendly manner.
Where processing is based directly on your consent, the legal basis is Article 6(1)(a) GDPR.
As a rule, stored consent settings are retained for no more than twelve months, unless a longer retention period is required for legal reasons.
You may change or withdraw your selection at any time through our website’s cookie or privacy settings.
7. Enquiry form
If you contact us using the enquiry form on our website, we process the information you enter in order to handle your enquiry.
This may include in particular:
- name,
- email address,
- telephone number, where provided,
- company, where provided,
- subject or nature of the enquiry,
- content of your message,
- any other information that you provide voluntarily.
Under the current configuration, information submitted via the form is forwarded by email to a mailbox operated by our company and processed there. Under the current configuration, the form content is not stored permanently in our website database.
Where your enquiry concerns entering into or performing a contract, processing takes place on the basis of Article 6(1)(b) GDPR.
Other general enquiries are processed on the basis of Article 6(1)(f) GDPR. Our legitimate interest lies in responding to and handling business and other enquiries.
Where we expressly obtain your consent for a particular processing activity, that processing takes place on the basis of Article 6(1)(a) GDPR.
You may withdraw consent at any time with effect for the future.
This does not affect the lawfulness of processing carried out before consent was withdrawn.
8. Protection of the enquiry form against misuse
We use technical security measures to protect our enquiry form against automated, abusive or excessively frequent submissions.
Under the current technical setup, these measures include an invisible check field, a security mechanism preventing submission from external sources and temporary rate limiting.
To the extent that the IP address is processed for technical purposes, it is used solely to detect misuse. Under the current configuration, the complete IP address is not stored by the form; it is processed only as a verification value that cannot readily be reverse-calculated and expires after one hour.
The legal basis is Article 6(1)(f) GDPR.
Our legitimate interest lies in protecting our website, technical systems and communication channels against spam, automated attacks and other misuse.
9. Retention period for enquiries
As a rule, we retain data from contact enquiries only for as long as necessary to handle the relevant enquiry.
Where the communication forms part of steps taken before entering into a contract or of a contractual relationship, the data may be retained for the duration of the contractual relationship and beyond that for the applicable statutory limitation and retention periods.
Business correspondence and documents relevant under tax or commercial law, in particular, may be subject to statutory retention obligations.
Once the applicable retention period has expired, the data is erased unless another legal basis permits its continued retention.
10. Communication by email
When you contact us by email, we process the personal data you provide in order to handle your enquiry and for further communication.
Where your message relates to entering into or performing a contract, the legal basis is Article 6(1)(b) GDPR.
Other business or general enquiries are processed on the basis of Article 6(1)(f) GDPR. Our legitimate interest lies in efficient and appropriate communication.
When emails are sent and received, the email, hosting and telecommunications service providers we use may process the technical data required for that purpose.
The principles described under “Retention period for enquiries” apply to the retention period.
11. Locally hosted fonts, scripts and design files
Under the current technical setup, the fonts, design files, scripts and animations used on our website are served locally from our web server.
Accessing this content therefore does not establish an automatic connection to Google Fonts or comparable external font providers.
Technically necessary connection data is processed when our website is provided, in accordance with the principles described under “Hosting and server log files”.
12. Images and videos
Under the current technical setup, the images and videos displayed on our website are served directly from our web server.
Accordingly, loading our website does not establish an automatic connection to external video portals, image services or comparable media platforms.
If external media services are integrated in future, this Privacy Policy will be amended accordingly and, where required, your consent will be obtained before the relevant service is loaded.
13. Privacy-friendly audience measurement with WP Statistics
We use the WP Statistics analytics tool, which is operated locally within our WordPress installation, to evaluate the use and reach of our website in aggregated form.
In particular, the following information may be processed:
- pages and content accessed,
- time of the page view,
- referrer or origin of a visit,
- browser type,
- device type,
- technical usage information,
- approximate geolocation at country level.
The analysis helps us understand the use and reach of our online service and improve the content, usability, stability and technical operation of our website.
Under the current technical setup, we do not use Google Analytics or personal marketing tracking for this purpose.
14. Data protection configuration of WP Statistics
Under our current configuration, WP Statistics processes analytics data exclusively locally in our WordPress database on our web server. Under the current configuration, analytics data is not transmitted to the tool's developer or any other third party.
IP addresses are truncated before storage and are additionally converted into a verification value that cannot readily be reverse-calculated.
Under the current configuration, no detailed visitor log is kept and the complete browser identifier (user agent) is not stored.
Approximate geolocation is performed using a database held locally on our server. Your IP address is not transmitted to an external service for this purpose.
Your browser's “Do Not Track” setting and the “Global Privacy Control” signal are respected.
Visits by logged-in administrators of our website are excluded from measurement.
Under the current configuration, detailed analytics data is automatically erased or consolidated into aggregate statistical values after 180 days. Aggregated overall statistics that are no longer personal data may be retained beyond that period.
15. Legal basis for WP Statistics
Under our current configuration, audience measurement using WP Statistics is carried out only after you have consented to the “Statistics” category via our consent banner.
In this respect, the legal basis for storing information on your terminal equipment or accessing information stored on it is section 25(1) TDDDG; the legal basis for the subsequent processing of personal data is Article 6(1)(a) GDPR.
You may withdraw consent at any time with effect for the future via the privacy settings on our website.
To the extent that processing for audience measurement exceptionally takes place without consent despite the data protection measures used and remains attributable to an individual, we base it on Article 6(1)(f) GDPR. Our legitimate interest lies in data-minimising, locally operated audience measurement and in improving, optimising and securing our online offering.
You have the right to object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR.
16. Protection of the login area
We limit failed login attempts to protect our website's login area against automated login attempts.
The IP address and username used for a failed login attempt are stored temporarily so that further attempts from the same address can be blocked for a limited period.
Under the current configuration, this processing takes place exclusively locally in our WordPress database. Transmission to a cloud service operated by the developer or to other third parties is not enabled.
The legal basis is Article 6(1)(f) GDPR.
Our legitimate interest lies in protecting our systems against unauthorised access.
17. Backups
We regularly create backups of our website and the associated database so that operations can be restored in the event of a fault or damage.
These backups may also contain personal data that was present in our system when the backup was created.
Under the current configuration, the backups are stored on the same webspace with our hosting service provider. Under the current configuration, they are not transferred to external storage services.
Older backups are automatically overwritten once a set number of backups has been reached.
In addition, a non-public copy of our website may be operated on the same webspace for testing and development purposes.
The legal basis is Article 6(1)(f) GDPR.
Our legitimate interest lies in operational resilience, data security and the orderly further development of our online offering.
18. No automated decision-making
No decision-making based solely on automated processing, including profiling within the meaning of Article 22 GDPR, takes place in connection with the use of the website described here.
19. Recipients of personal data
Within InterAlpen Holding GmbH, access to personal data is generally restricted to those persons who need it to perform their respective duties.
Personal data may also be disclosed to external recipients where this is necessary and legally permissible.
This may include in particular:
- hosting and IT service providers,
- email and telecommunications providers,
- technical service providers and processors,
- tax advisers, lawyers or other professional advisers, where necessary,
- public authorities, courts or other public bodies where there is a legal obligation,
- contracting parties or other recipients, where this is necessary to perform a contract.
Where external service providers process personal data on our behalf, they are engaged under an agreement pursuant to Article 28 GDPR where required by law.
20. Transfers of data to third countries
The website functions that we actively use under the current technical setup generally do not result in personal data being transferred to countries outside the European Union or the European Economic Area.
This applies in particular to the local provision of fonts, scripts and media, locally operated audience measurement and locally operated consent management.
If we use services in future that involve the transfer of personal data to third countries, such transfers will take place only in compliance with the statutory requirements of Articles 44 et seq. GDPR. This Privacy Policy will be amended accordingly in that event.
21. Legal bases for processing
Depending on the processing operation concerned, the following legal bases may apply in particular:
Article 6(1)(a) GDPR – consent, where you have given us your express consent for a particular processing activity.
Article 6(1)(b) GDPR – contract and steps prior to entering into a contract, where processing is necessary to perform a contract or, at your request, to take steps prior to entering into a contract.
Article 6(1)(c) GDPR – legal obligation, where processing is necessary for compliance with a legal obligation.
Article 6(1)(f) GDPR – legitimate interests, where processing is necessary for the purposes of our legitimate interests or those of a third party and those interests are not overridden by your interests, fundamental rights and freedoms.
The requirements of section 25 TDDDG also apply where information on your terminal equipment is accessed or stored.
22. Retention period
Unless a more specific retention period is stated in this Privacy Policy, we retain personal data only for as long as necessary to fulfil the relevant purpose.
The data is then erased or anonymised unless statutory retention obligations, legitimate interests or other legal bases justify its continued retention.
Statutory retention obligations under commercial and tax law remain unaffected.
23. Withdrawal of consent
You may withdraw consent given under data protection law at any time with effect for the future.
Withdrawal does not affect the lawfulness of processing based on your consent before it was withdrawn.
Where your consent relates to cookies or similar technologies, you may change or withdraw it in particular through our website’s cookie or privacy settings.
24. Right to object
Where we process personal data on the basis of Article 6(1)(f) GDPR, Article 21 GDPR gives you the right to object to the processing at any time on grounds relating to your particular situation.
As a rule, we will then no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing is required to establish, exercise or defend legal claims.
Where personal data is processed for direct marketing purposes, you may object to that processing at any time without giving specific reasons.
This also applies to profiling to the extent that it is related to such direct marketing.
25. Your rights as a data subject
Where the statutory requirements are met, you have the following rights in particular:
Right of access
Under Article 15 GDPR, you may request information as to whether we process personal data about you and, if so, what personal data we process.
Right to rectification
Under Article 16 GDPR, you may request the rectification of inaccurate personal data and the completion of incomplete personal data.
Right to erasure
Subject to the requirements of Article 17 GDPR, you may request the erasure of your personal data.
Right to restriction of processing
Subject to the requirements of Article 18 GDPR, you may request the restriction of processing.
Right to data portability
Where the statutory requirements are met, Article 20 GDPR allows you to request that personal data you have provided to us be supplied to you in a structured, commonly used and machine-readable format or transmitted to another controller.
Right to object
Subject to the requirements of Article 21 GDPR, you have the right to object to certain processing activities.
Right to withdraw consent
Under Article 7(3) GDPR, you may withdraw consent at any time with effect for the future.
26. Right to lodge a complaint with a supervisory authority
Under Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes data protection legislation.
The following authority in particular is responsible for our company:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Germany
As a rule, you may also contact another data protection supervisory authority with jurisdiction in your case.
27. Obligation to provide personal data
As a rule, merely using our website does not give rise to any statutory or contractual obligation to provide us with personal data, unless the data concerned is technically necessary.
When you contact us or take steps towards entering into a contract, certain information may be required so that we can handle your enquiry or perform a contract.
Without this required information, it may not be possible to handle the enquiry or perform a contract.
28. Security of processing
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, we implement appropriate technical and organisational measures to protect personal data.
In particular, these measures are designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
29. Changes to this Privacy Policy
We reserve the right to amend this Privacy Policy if our website, the technical services used or statutory or regulatory requirements change.
The current version published on this website applies.
Last updated: 12 August 2026