minzi
Terms & Conditions Privacy Policy

Privacy Policy

Last updated: 16 September 2026

1. General information

This Privacy Policy explains how personal data is collected and processed when you use Minzi, an online application for reservations, bookings, payments and gift vouchers.

Minzi is operated by:

Laura Vidal e.U.
Sillgasse 7, 6020 Innsbruck
info@minzi.app
Website: https://minzi.app

Laura Vidal e.U. is the controller responsible for the processing of personal data described in this policy, unless otherwise indicated.

2. Personal data we collect

Depending on the booking form and the service selected, we may process the following information:

  • Name and email address
  • Telephone number, where requested
  • Billing address, where required
  • Names of additional participants, where requested
  • Booking details, including dates, times, selected activities and number of participants
  • Information entered into optional booking fields
  • Booking status, cancellations and changes
  • Payment status and transaction references
  • Gift voucher information, including voucher codes, values, purchases and redemptions
  • Waiting-list registrations
  • Newsletter preferences, where applicable

We also process limited technical information required to operate and secure the application, such as IP addresses, request information and error logs.

You do not need to create a customer account to use Minzi.

Please do not enter sensitive personal information into optional fields unless it is necessary for your request.

3. Purposes and legal bases

We process personal data for the following purposes:

Bookings and reservations

We use your information to create, manage, confirm, modify and cancel reservations and bookings.

Legal basis: Article 6(1)(b) GDPR — performance of a contract or steps taken before entering into a contract.

Payments and gift vouchers

We process information necessary to initiate payments, confirm their status, manage gift vouchers and record transactions.

Legal basis: Article 6(1)(b) GDPR.

Where transaction records must be retained to comply with accounting or tax requirements, processing is based on Article 6(1)(c) GDPR.

Waiting lists

If you register for a waiting list, we use your contact information and the relevant booking details to manage your registration and inform you when a place becomes available.

Legal basis: Article 6(1)(b) GDPR.

Transactional emails

We use your email address to send booking confirmations, payment-related notifications, cancellations, changes and other information directly related to your booking or voucher.

Legal basis: Article 6(1)(b) GDPR.

Newsletter preferences

If you explicitly opt in to marketing communications, we may record your consent and, where a separate newsletter registration or transfer process is implemented, use the relevant information for that purpose.

Legal basis: Article 6(1)(a) GDPR — consent.

You may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.

Minzi does not currently send marketing newsletters or automatically transfer customer data to an external newsletter platform.

Security and technical operation

We process technical information to maintain the application's functionality, investigate errors, prevent misuse and protect the security of the service.

Legal basis: Article 6(1)(f) GDPR — our legitimate interest in providing a secure and reliable application.

4. Payments through Stripe

Online payments are processed using Stripe Checkout and Stripe Connect.

When you select an online payment method, you are redirected to Stripe's payment environment. Stripe processes the payment information required to complete your transaction.

Minzi receives payment-related information necessary to associate the transaction with your booking or voucher, such as payment status and transaction identifiers.

Payments are assigned to the Stripe account of the relevant service provider.

Stripe may process personal data for payment processing, fraud prevention, regulatory compliance and other purposes described in its own privacy documentation.

Further information:

https://stripe.com/privacy

5. Hosting and technical service providers

We use the following external service providers to operate Minzi:

Hetzner

Hetzner provides the hosting infrastructure used to operate the application and store its data.

https://www.hetzner.com/legal/privacy-policy/

SMTP2GO

SMTP2GO is used to deliver transactional emails, such as booking confirmations and notifications.

For this purpose, information required to deliver the email, including the recipient's email address and message content, is transmitted to SMTP2GO.

https://www.smtp2go.com/privacy/

Stripe

Stripe processes online payments as described in Section 4.

These providers process personal data according to their respective roles and applicable contractual arrangements.

Where required, we enter into data processing agreements and implement appropriate safeguards.

6. International data transfers

Some service providers may process personal data outside the European Economic Area.

Where personal data is transferred to a country outside the EEA, we ensure that the transfer is based on an applicable adequacy decision or appropriate safeguards under Chapter V GDPR, such as the European Commission's Standard Contractual Clauses, where required.

You can request further information about applicable safeguards using the contact details in Section 1.

7. Cookies and technical data

Minzi may use technically necessary cookies and similar technologies to maintain session functionality, protect forms against unauthorised requests and support the booking process.

These technologies are used for the operation and security of the application.

Minzi does not use advertising cookies, marketing trackers or analytics tools.

Stripe may use its own cookies and similar technologies within its payment environment. Information about Stripe's processing is available in Stripe's privacy and cookie documentation.

8. Data retention

We retain personal data only for as long as necessary for the purposes described in this Privacy Policy or as required by applicable law.

The following retention principles apply:

  • Booking and reservation data is retained for the period necessary to administer the booking and handle subsequent enquiries or claims.
  • Payment records and other tax-relevant documents are retained for the applicable statutory retention period, generally seven years under Austrian law.
  • Gift voucher records are retained while necessary to administer and redeem the voucher and subsequently for any applicable legal retention period.
  • Waiting-list information is deleted when it is no longer needed for the relevant waiting list.
  • Newsletter consent records are retained as long as needed to administer and demonstrate the consent, subject to applicable legal requirements.
  • Technical logs are retained only for the period necessary for security, maintenance and troubleshooting.

Where personal data is no longer required, it is deleted or anonymised unless further retention is legally necessary.

9. Who can access your information?

Access to personal data is restricted to authorised persons who require it to manage bookings, vouchers, payments or the application itself.

Booking information is made available to the relevant service provider and authorised personnel responsible for the booking.

Access permissions within Minzi are configured to separate booking data between different service providers.

The application administrator may access information where necessary for administration, technical support, security or legal compliance.

We do not sell personal data.

10. Your rights

Under the GDPR, you have the right, subject to the applicable legal requirements, to:

  • Request access to your personal data.
  • Request correction of inaccurate information.
  • Request deletion of your personal data.
  • Request restriction of processing.
  • Receive your data in a portable format where applicable.
  • Object to processing based on legitimate interests.
  • Withdraw consent at any time where processing is based on consent.

To exercise your rights, please contact us using the details provided in Section 1.

You also have the right to lodge a complaint with the Austrian Data Protection Authority:

Österreichische Datenschutzbehörde
https://www.dsb.gv.at

11. Data security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure and loss.

These measures include access restrictions, secure communications and appropriate application and infrastructure security measures.

12. Automated decision-making

Minzi does not use personal data for automated decision-making, including profiling, that produces legal or similarly significant effects within the meaning of Article 22 GDPR.

13. Changes to this Privacy Policy

We may update this Privacy Policy when the application's functionality, our data processing practices or applicable legal requirements change.

The current version will be made available through the application, together with the date of its most recent update.

Confirm