Privacy Policy
Last updated: 25 August 2026
This Privacy Policy explains how FERDI Operations GmbH processes personal data when you visit ferdi.love or ferdistays.com, make a reservation, complete online check-in, stay at a FERDI property, or otherwise communicate with us.
1. Data Controller
The controller responsible for the processing of your personal data is:
FERDI Operations GmbH
Wasagasse 24/15
1090 Vienna
Austria
Company registration number: FN 592244 y
Commercial Register Court: Handelsgericht Wien
VAT ID: ATU78772945
Represented by:
Maximilian Sammer, Managing Director
Hereinafter referred to as “FERDI”, “we” or “us”.
2. What Personal Data We Process
Depending on how you interact with FERDI, we may process the following categories of personal data.
Booking and contact information
This may include:
- first and last name;
- email address;
- telephone number;
- home address or country of residence;
- arrival and departure dates;
- apartment or property booked;
- number of guests;
- booking reference;
- booking preferences; and
- correspondence relating to the reservation.
Guest registration information
Where required for guest registration or other statutory purposes, we may process information such as:
- full name;
- date of birth;
- nationality;
- home address;
- travel-document information where legally required;
- arrival and departure information; and
- information concerning accompanying guests.
The exact information collected depends on the legal requirements applicable to the relevant property.
Identity verification information
Where identity verification is required, we or a service provider acting on our behalf may process:
- identification-document details;
- images of identification documents;
- verification status and results; and
- fraud-prevention or security information generated during the verification process.
We seek to process only information reasonably necessary for the applicable verification purpose.
Payment information
Payments may be processed by external payment providers.
Depending on the payment method, we may receive or process:
- transaction amount;
- payment status;
- payment method;
- payment-provider reference;
- limited card information such as card type and last digits; and
- security-deposit or payment-authorisation information.
Full payment-card credentials are generally processed by the relevant payment provider rather than stored directly by FERDI.
Stay and property information
During a stay we may process information relating to:
- check-in and check-out;
- digital access credentials and access events where necessary for operation and security;
- requests for assistance;
- maintenance incidents;
- damage reports;
- house-rule violations;
- complaints; and
- communications with FERDI.
Website and technical information
When you use ferdi.love, ferdistays.com or our booking services, technical information may be processed, including:
- IP address;
- browser and device information;
- operating system;
- date and time of access;
- pages visited;
- referring website;
- cookie or similar identifiers; and
- technical log information.
Where analytics or marketing technologies are used, additional information may be processed as described in our cookie settings or consent interface.
3. Why We Process Personal Data
We process personal data for the following purposes.
Managing bookings and providing accommodation
We process booking, contact and stay information to:
- process reservations;
- provide accommodation;
- manage payments;
- communicate before, during and after a stay;
- provide self check-in;
- handle guest requests; and
- administer cancellations, changes, refunds or claims.
The principal legal basis is Article 6(1)(b) GDPR, where processing is necessary to enter into or perform a contract.
Compliance with legal obligations
Certain guest information must be collected, retained or disclosed because FERDI is subject to Austrian legal obligations, including applicable guest-registration, tourism, tax, accounting and commercial requirements.
The legal basis is Article 6(1)(c) GDPR.
Security, fraud prevention and protection of property
We may process information to:
- verify guest identities;
- prevent fraudulent bookings;
- protect guests, employees, neighbours and property;
- investigate security incidents;
- enforce house rules; and
- establish, exercise or defend legal claims.
Depending on the circumstances, the legal basis is Article 6(1)(f) GDPR, our legitimate interests in operating safe and secure accommodation and protecting our legal and economic interests, or another applicable legal basis.
Website operation
Technical data necessary to provide and secure our website and booking functionality may be processed on the basis of Article 6(1)(f) GDPR, insofar as we have a legitimate interest in providing a secure and functional online service.
Analytics and marketing
Where legally required, non-essential analytics, advertising or marketing technologies are used only after obtaining your consent.
The legal basis is Article 6(1)(a) GDPR.
You may withdraw your consent at any time with effect for the future through the available cookie or privacy settings.
4. Booking Platforms
FERDI accommodation may be offered through third-party platforms such as Airbnb and Booking.com.
Where you make a booking through a third-party platform, that platform processes personal data under its own privacy policy and may transmit information necessary to manage your reservation to FERDI.
FERDI and the relevant platform may act as separate controllers for their respective processing activities.
Please consult the privacy policy of the platform through which you make your reservation for information about its processing practices.
5. Direct Booking and Property-Management Systems
FERDI uses digital systems to manage reservations, guest communication, online check-in and accommodation operations.
This may include Uplisting as a property-management and/or booking technology provider.
Where a service provider processes personal data on FERDI’s behalf, we seek to ensure that appropriate data-processing arrangements and safeguards are in place as required by the GDPR.
6. Payment Providers
Payments for direct bookings may be processed by external payment-service providers.
Payment providers may receive information necessary to process transactions, verify payments, prevent fraud and manage refunds or payment disputes.
Some payment providers may process certain information as independent controllers under their own privacy policies.
The identity of the relevant payment provider is generally displayed during the payment process.
7. Identity Verification Providers
FERDI may use specialist technology providers to perform guest identity verification and fraud-prevention checks.
Where such a provider is used, information necessary for verification may be transmitted to that provider.
The provider may process identification-document information and other verification data according to the applicable contractual arrangements and its role under data-protection law.
We encourage Guests to review any privacy information presented during the identity-verification process.
8. Digital Access and Smart Locks
FERDI properties may use electronic access-control systems, digital keys, PIN codes or smart locks.
For the operation and security of these systems, FERDI and its technology providers may process information such as:
- apartment or door identifier;
- access credential;
- validity period;
- time of access events;
- technical device information; and
- security or error logs.
This information is used to provide access, troubleshoot technical issues, protect the property and investigate security incidents where necessary.
The applicable legal basis may include Article 6(1)(b) GDPR and Article 6(1)(f) GDPR.
9. Guest Communications
FERDI may communicate with Guests by email, SMS, telephone, messaging services or through booking platforms.
Booking and stay-related communications are processed where necessary to perform the accommodation contract.
Where FERDI sends optional promotional communications, these are sent only where permitted by applicable law. Where marketing is based on consent, consent can be withdrawn at any time.
10. Cookies and Similar Technologies
ferdi.love and ferdistays.com may use cookies and similar technologies.
Some technologies are necessary for:
- website functionality;
- security;
- booking functionality;
- maintaining sessions; and
- remembering essential settings.
These may be used where permitted without consent.
Optional technologies—for example certain analytics, advertising or tracking cookies—will be activated only where an appropriate legal basis exists and, where required, after consent has been obtained.
You can manage available choices through the cookie-consent interface on the website.
11. Recipients of Personal Data
Where necessary for the purposes described above, personal data may be shared with categories of recipients including:
- property-management and booking-system providers;
- hosting and IT service providers;
- payment processors;
- identity-verification and fraud-prevention providers;
- digital access and smart-lock providers;
- guest-communication providers;
- cleaning, maintenance or property-management personnel where necessary;
- accountants, auditors and professional advisers;
- booking platforms through which a reservation is made; and
- public authorities where disclosure is required by law.
We do not sell Guest personal data.
12. International Data Transfers
Some service providers may process personal data outside Austria or the European Economic Area.
Where personal data is transferred to a country outside the EEA that does not benefit from an applicable adequacy decision, FERDI seeks to ensure that appropriate safeguards are used as required by Chapter V GDPR, such as European Commission Standard Contractual Clauses, together with supplementary measures where appropriate.
13. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected and to comply with applicable legal obligations.
Retention periods depend on the type of information and may include statutory retention requirements relating to:
- accounting and taxation;
- guest registration;
- contractual documentation;
- payment records; and
- legal claims.
Information required for Austrian accounting or tax purposes may generally need to be retained for statutory periods applicable to the relevant records.
Identity-verification information is retained only for as long as necessary for the relevant purpose or as required by applicable law, taking into account the retention practices of the relevant verification provider.
Technical logs and access information are retained for an appropriate period having regard to operational and security requirements.
14. Data Security
FERDI takes appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
No online system can provide absolute security, but we regularly seek to use safeguards appropriate to the nature of the information and associated risks.
15. Your GDPR Rights
Subject to the requirements and limitations of applicable law, you may have the right to:
- access personal data we hold about you;
- rectify inaccurate or incomplete personal data;
- request erasure of personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive certain information in a portable format;
- withdraw consent at any time where processing is based on consent; and
- lodge a complaint with a supervisory authority.
Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
We may need to verify your identity before responding to a data-protection request.
16. Austrian Data Protection Authority
You have the right to lodge a complaint with the competent data-protection supervisory authority.
For FERDI in Austria, the relevant authority is generally:
Österreichische Datenschutzbehörde
Austrian Data Protection Authority
Current contact details can be found on the authority’s official website.
You may also have the right to contact another competent EU/EEA supervisory authority depending on your place of residence.
17. Children
FERDI accommodation is not intended to be booked independently by persons who do not have legal capacity to enter into the relevant accommodation agreement.
Where information concerning children or minors is required as part of a family or group reservation, it is processed only where necessary for the booking, accommodation or applicable legal requirements.
18. Automated Decision-Making
FERDI does not intend to make decisions producing legal or similarly significant effects solely through automated processing unless this is specifically disclosed to the affected person or otherwise permitted by law.
Fraud-prevention, payment or identity-verification providers may use automated systems as part of their services. Where relevant, additional information may be provided by the respective provider.
19. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, technology, service providers or legal requirements.
The current version will be published on ferdi.love and ferdistays.com together with its last-updated date.
20. Contact and Data Protection Requests
For questions about this Privacy Policy or to exercise your data-protection rights, please contact:
FERDI Operations GmbH
Wasagasse 24/15
1090 Vienna
Austria
Please use the contact details published on ferdi.love and ferdistays.com for privacy and data-protection enquiries.
