Legal
Privacy Policy
As of 31 August 2026. This statement explains which personal data we process when you use our website and our services.
Data protection at a glance
1. Responsible party
The controller within the meaning of the Swiss Data Protection Act (DSG) is Hotel & Eventcenter der Meilenstein GmbH, Lotzwilstrasse 66, 4900 Langenthal, Switzerland. Privacy inquiries should be directed to [email protected] or +41 62 919 18 18.
2. Principles and purposes
We process personal data lawfully, in good faith, proportionately and for specific purposes. Purposes include in particular operation and security of the website, responding to inquiries, initiating and processing reservations as well as hotel, restaurant and event services, fulfilling legal obligations and protecting legitimate business interests.
3. Data when visiting the website and hosting
When the site is accessed, technically required data such as IP address, date and time, requested address, referrer, browser, operating system and device information are processed in server logs. This serves delivery, stability, error analysis and protection against abuse. The website is operated on infrastructure provided by Hetzner Online GmbH in Germany. The regular technical rotation of web server logs is set to 14 days; in security incidents individual records may be retained longer.
4. Contact and event inquiries
If you use forms or contact us, we process in particular your name, email address, telephone number, message, event requirements and voluntary information for handling, communication, preparing offers and, where applicable, contract processing. Mandatory fields are marked as such.
5. Reservations and external booking systems
Hotel, restaurant or voucher bookings may lead to external booking services. After you access them, the respective provider processes data in its own responsibility and according to its privacy policy. Before concluding a contract, the contract and privacy information displayed there also apply.
6. Cookies and similar technologies
In the public area we currently do not use our own analytics or marketing cookies. For protected administration sessions a technically necessary, securely configured session cookie is used. Embedded services may use their own technologies. Browsers allow deleting or blocking cookies; this may limit functionality.
7. Embedded content and badges
The website may load content from third-party providers, in particular the TrustScore from TrustYou and maps or media. In doing so, IP address, browser data and the accessed page may be transmitted to the provider. HotelsCombined and event venue pages are only accessed when clicked. Third-party providers process data according to their own statements.
8. Recipients
Personal data may be disclosed to carefully selected IT, hosting, communications, booking, payment and other service providers where required. These include in particular the hosting provider Hetzner, the hotel or restaurant booking systems you access and, for embedded guest reviews, TrustYou. Processors may only process data for the specified purpose and with appropriate security measures. Disclosure to authorities takes place where required by law.
9. Transfers abroad
Individual service providers may process data abroad. For countries without an adequate level of data protection we use a legally recognised safeguard, in particular appropriate standard contractual clauses, or rely on a legal exception. Where possible, we prefer processing in Switzerland or in the European Economic Area.
10. Retention and security
We store personal data only as long as the processing purpose, contractual claims or legal obligations require; thereafter they are deleted or anonymised. We take appropriate technical and organisational measures against unauthorised processing, loss, alteration or disclosure. Absolute security cannot be guaranteed.
11. Your rights
Under applicable law you can in particular request access, rectification, deletion, the handover or transfer of your data, as well as restriction or cessation of certain processing. Consent can be revoked for the future. Statutory retention obligations remain reserved. You may contact the Federal Data Protection and Information Commissioner.
12. Updates
We update this statement when processing, service providers or the legal situation change. The published version at any given time is authoritative.