Privacy policy

Privacy Policy Hotel Ascona

Hotel Ascona
Via Signor in Croce 1, 6612 Ascona, Svizzera
Email: info@hotel-ascona.ch

Last updated: 12 August 2026

1. Controller and contact details

The data controller is Hotel Ascona, Via Signor in Croce 1, CH-6612 Ascona, Switzerland.

Privacy contact: info@hotel-ascona.ch. Booking contact: booking@hotel-ascona.ch. Telephone: +41 (0) 91 785 15 15.

2. Data we process

Depending on the service used, we may process identification and contact details; booking and stay data; the content of requests and conversations; preferences voluntarily provided; payment and transaction data to the extent required; technical and usage data, including IP address, online identifiers, browser, device, operating system, pages visited, events, date and time; language and consent preferences; and data required for security and abuse prevention.

Health, allergy, disability, dietary or other particularly sensitive information should only be provided where necessary for the stay. Do not enter sensitive data, identity documents, payment card numbers or confidential information in the AI chatbot.

3. Purposes, legal grounds and retention

Website operation, security and maintenance. We process logs and technical data to deliver the website, diagnose errors, prevent abuse and protect systems and users. We rely on our legitimate interest in security and service continuity and, where applicable, on performance of the service requested. Logs are normally retained for no longer than 6 months, unless they are needed for an incident or legal claim.

Enquiries. Contact details and communications received by email, telephone or WhatsApp are processed to respond and take steps requested before entering into a contract. Enquiries are generally kept for 24 months after closure, unless they become part of a booking or are needed for legal obligations or claims.

Bookings and stays. The Simple Booking engine supplied by QNT S.r.l. collects the information needed to check availability, provide offers, enter into and manage the booking, payment and stay. Processing is necessary for pre-contractual steps and performance of the contract, and for compliance with legal obligations. Operational data are kept for the duration required by the relationship; accounting and tax records are retained for the period required by Swiss law, normally 10 years. Data no longer needed are deleted or anonymised.

Special requirements. Health, allergy, accessibility or dietary data are processed only where voluntarily provided and required for the requested service. Where required, we rely on explicit consent, which can be withdrawn at any time without affecting prior processing. Such data are erased after the stay unless a documented need or legal obligation applies.

AI Kosmo chatbot. When the assistant is opened or used, technical session data, conversation content, questions, contact information and stay preferences voluntarily disclosed may be processed. The purposes are to answer questions, support navigation, check availability, prevent abuse and, where contractually enabled, improve service accuracy through aggregated or anonymised analysis and Hotel Ascona-specific fine-tuning. We rely on steps requested by the user; security and improvement rely on legitimate interests, subject to an objection and balancing assessment. Identifiable conversations are retained only as long as needed and no longer than 24 months, unless a shorter setting or legal requirement applies.

Google Analytics 4 measurement. With the user’s consent, usage data and approximate device and location information are collected to measure traffic and performance. IP addresses are used at collection and are not logged or stored by Google Analytics. Event-level data must be configured not to exceed 14 months; reports that no longer relate to an individual may be retained longer. Consent can be withdrawn through Cookie Settings.

External content. Google Maps, Street View/360 Tours and YouTube are enabled only after consent to display maps, virtual tours and videos. Google may receive IP, technical and interaction data. Remote Google Fonts involve a technical request to Google’s servers; Hotel Ascona favours local font hosting. See the Cookie Policy for tracker details and expiry periods.

Privacy preferences. Iubenda records the user’s choice, time, notice version and a pseudonymous identifier in order to prove and honour preferences. This is based on compliance obligations and the legitimate interest in demonstrating consent. Records are retained for up to 2 years or for the period needed to defend legal rights.

Legal obligations and claims. Data may be processed to prevent fraud, comply with authority requests, handle complaints and establish, exercise or defend legal claims. Retention follows applicable statutory and limitation periods.

4. Whether data are required

Fields marked as required during booking are necessary to provide the service. Failure to provide them may prevent a response or booking. Optional information and preferences may be omitted without affecting essential functions. Consent to measurement and external content is optional; refusal does not prevent browsing or booking, but maps, videos or similar functions may be unavailable.

5. Recipients and service providers

Data may be accessed by authorised Hotel staff and, where required, by providers subject to contractual and confidentiality duties: website hosting, firewall and maintenance providers; IT agencies and advisers; Iubenda for consent management; QNT S.r.l./Simple Booking for the booking engine; payment providers and financial institutions; Google for Tag Manager, Analytics, Maps, YouTube and remotely hosted Fonts; AI KOSMO SRL and its sub-processors; legal, tax and accounting advisers; and competent authorities.

For AI Kosmo, the sub-processors declared as at 25 June 2026 include Google Cloud (EEA/Netherlands processing), Supabase (EEA/Germany processing; entity established in Singapore), Vercel and Railway (US/EEA), OpenAI, Groq and OpenRouter (AI services, US/EEA), Axiom (monitoring, US/EEA) and Google Workspace (EEA/US). The list may change; the current version is available from the Controller or in AI Kosmo’s DPA.

When a user clicks WhatsApp, Facebook, Instagram or X, the user leaves this website and interacts with platforms operating under their own notices and, for their independent processing, as separate controllers. No embedded social widget was observed in the website audit of 12 August 2026.

6. International transfers

Data are processed mainly in Switzerland and the European Economic Area. Some providers may process data in the United States or other countries. Depending on the circumstances, Hotel Ascona relies on Swiss or EU adequacy decisions, Data Privacy Framework participation, standard contractual clauses and supplementary measures. Information on destination countries and safeguards, including a copy where permitted, may be requested from the privacy contact.

7. Automated decisions and artificial intelligence

The chatbot generates answers using language models and may make mistakes. It does not make solely automated decisions producing legal or similarly significant effects. Prices, availability, bookings, payments and material requests must be confirmed by the booking engine or Hotel staff. Users may request human assistance.

8. Security

We apply technical and organisational measures appropriate to the risk, including access controls, authentication, updates, backups, encryption where appropriate, event logging and incident procedures. No system is entirely risk-free; users should not send unnecessary data through unprotected channels.

9. Your rights

Subject to applicable law, users may request access and a copy, rectification, erasure or destruction, restriction, portability, object to processing based on legitimate interests and withdraw consent. Users may object to direct marketing at any time and request information about recipients and international transfers. Withdrawal does not affect processing already carried out lawfully.

Requests should be sent to info@hotel-ascona.ch. We may request proportionate information to verify identity. Users may complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) and, where the GDPR applies, to the competent EEA supervisory authority.

10. Children and third-party data

Bookings must be made by persons capable of entering into the contract. Anyone providing companion data, including children’s data, must be authorised and inform them appropriately. The website and chatbot are not intended to collect data directly from children.

11. Cookies and third-party services

Information on cookies, local storage, scripts, pixels, categories, durations and preference controls is provided in the Cookie Policy, which forms part of this notice. Linked websites and platforms have their own notices and are not controlled by Hotel Ascona.

12. Changes

We may update this notice following legal, technical or organisational changes. The current version is published on this page with its update date. Where a change affects consent-based processing, consent will be requested again when required.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.