Privacy
What we do with the details you give us when you book, and what we do not do with them.
Who is responsible
The company named on the company details page is the controller of your personal data, and the contact address there is where to write about anything on this page.
What we collect
From the booking form: your name, email address, phone number, the country you are writing from and the language you are reading in. Plus what you booked, which is the route, the departure date, the machines, how many people are coming, how many of them ride, how many rooms, the currency and the prices. We also record the moment you accepted each policy, which version you accepted, and the exact wording of the rider declaration you agreed to. Every email we send you about the booking is kept with it. We do not ask for the names or the ages of the other people on your booking, only how many there are. There is no account and no password. We never see a card number, because payment is by bank transfer and happens outside this site.
Do you have to give us this?
There is no legal obligation to give us anything. But the name, email and phone number are what the booking contract needs: without them we cannot confirm a place, send you the bank details or reach you if a departure has to move. If you would rather not enter them here, call us instead and we will take the booking by phone.
Why, and on what legal basis
To arrange and run your booking, which is performance of the contract you asked for, Art. 6(1)(b) GDPR. To keep the accounting records the law requires, Art. 6(1)(c). To keep an audit trail of each reservation and to stop the departure calendar being abused, which is our legitimate interest, Art. 6(1)(f). None of it runs on consent, because none of it is optional extra processing. There is no newsletter, no marketing list, no advertising and no analytics.
Who else sees it
Two service providers, and nobody else. We do not sell your data and we do not share it with advertisers.
- Resend
- Sends the booking emails. Receives your name, your email address and the contents of the message.
- Database host
- To be confirmed
How long we keep it
The retention period is being set with our legal adviser and will be stated here once it is. In the meantime, ask us in writing and we will tell you exactly what we hold about you, and delete it if you want it gone.
Data leaving the EU
Resend is based in the United States. The transfer relies on the EU-US Data Privacy Framework, with the standard contractual clauses in its data processing agreement as a fallback safeguard. The adequacy of that framework is under challenge. If it falls we move to a different arrangement rather than keep sending data under it. Ask us at the contact address on the company details page and we will send you a copy of those clauses.
Your rights
You can ask for a copy of what we hold, have it corrected, have it deleted, have its use restricted, object to the processing we base on our legitimate interest, and receive it in a portable form. Write to the address on the company details page. We answer within one month.
No profiling, no tracking
There is no automated decision-making and no profiling here. A person reads every reservation. No analytics and no advertising pixels run on this site, which is why you were never shown a cookie banner.
Data protection officer
We have not appointed one, and at this scale we are not required to: there is no large-scale monitoring here and no special-category data. Write to the contact address on the company details page and it reaches the people who make these decisions.
If you think we got it wrong
Tell us first, and we will fix it. You also have the right to complain to the Romanian supervisory authority, ANSPDCP, at dataprotection.ro, or to the authority in the EU country where you live.