This Privacy and Personal Data Protection Policy (hereinafter: the Policy) explains how KochaGuide, Nejc Košnik s.p., operating under the brand name Experience Hiking Agency (hereinafter: the Controller), collects, uses, stores and protects the personal data of individuals.
The Policy applies to the personal data of website visitors, registered programme participants, subscribers, customers and other individuals whose personal data the Controller processes.
The Controller processes personal data in accordance with applicable legislation, in particular Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR), the Personal Data Protection Act (ZVOP-2), and other relevant legislation of the Republic of Slovenia and the European Union.
This Policy does not regulate the use of cookies and similar technologies. Their use is governed by a separate Cookie Policy.
Controller: KochaGuide, Nejc Košnik s.p.
Cesta 1. maja 63
4000 Kranj
Slovenia
Brand: Experience Hiking Agency
E-mail: info@experience-slovenia.com
For questions regarding personal data protection or to exercise your rights, you may contact the Controller at the above e-mail address or postal address.
The Controller does not have a designated Data Protection Officer (DPO), as the conditions for appointing one under applicable legislation are not met.
The scope of personal data depends on the purpose of processing and the services an individual uses or orders.
The Controller may process, in particular:
The Controller strives to process only personal data that is adequate, relevant and limited to what is necessary for each specific purpose.
The Controller processes personal data when necessary for:
The legal basis is typically the performance of a contract or measures taken at the request of the individual prior to entering into a contract.
The Controller also processes personal data when necessary to fulfil legal obligations, particularly in the areas of:
The legal basis is the fulfilment of the Controller’s legal obligations.
If an individual orders or requires insurance, the Controller may process the data necessary to conclude and implement the insurance.
The date of birth is collected only when required for a specific insurance policy.
Data may be forwarded to the insurance company or another insurance provider to the extent necessary for the ordered insurance.
In the application form, individuals may indicate health conditions or special circumstances they believe the guide should be aware of to ensure safer programme implementation.
Health data is a special category of personal data.
The Controller processes such data only to the extent necessary for the safe execution of the specific programme and does not use it for any other purpose.
Processing of health data is carried out on the basis of the individual’s explicit consent, when consent is the legal basis.
Consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
If an individual chooses not to provide health information, this may affect their ability to safely participate in a specific programme when such information is essential for safety.
The Controller does not use health data for marketing, profiling or any unrelated purposes.
The Controller may use contact details for communication necessary to process the application and implement the programme, including:
Such communication is necessary for the performance of the contractual relationship or for exercising the Controller’s rights and obligations.
The Controller may use an individual’s e-mail address to send newsletters and other marketing messages based on consent, when such consent is required.
Newsletters may include:
Consent is voluntary and is not a condition for registering for a programme.
Individuals may withdraw consent at any time, typically by clicking the unsubscribe link included in each e-mail or by contacting info@experience-slovenia.com.
After withdrawal, newsletters will no longer be sent unless another legal basis applies.
The Controller may process personal data on the basis of legitimate interest when such processing is necessary, lawful, and when the rights and freedoms of the individual do not override the Controller’s interests.
Legitimate interests may include:
Individuals may object to processing based on legitimate interest under the conditions set out in the GDPR.
When applying for a programme via the online form, the Controller processes the data entered by the individual.
Mandatory fields are necessary to process the application and implement the programme. If the required data is not provided, the application or programme implementation may not be possible.
The date of birth is required only when necessary for insurance or another specific purpose.
Health-related information is not intended for general collection but for informing the guide of circumstances relevant to safe programme execution.
The Controller may transfer personal data to third parties to the extent necessary for programme implementation, contract fulfilment or legal obligations.
This may include:
Only data necessary for a specific purpose is shared.
When a third party processes personal data as a processor on behalf of the Controller, processing is regulated in accordance with GDPR requirements.
If programme implementation requires transferring personal data to a country outside the European Union or the European Economic Area, such transfer will be carried out only when an appropriate legal basis and safeguards are ensured in accordance with applicable legislation.
This may include countries to which the individual travels when the transfer is necessary for programme execution or ordered services.
In its operations, the Controller may use external providers of information, communication and marketing services.
It uses or may use, among others:
Data processing through cookies and similar technologies is described in more detail in the separate Cookie Policy.
Google Analytics and Meta Pixel are activated on the website only after obtaining the user’s consent, when such consent is required.
We store personal data only for as long as necessary for the purpose for which it was collected, or for as long as required by applicable legislation.
The retention period depends on the type of data and the purpose of processing.
Data related to programme applications and implementation are generally stored for as long as necessary to carry out the programme, handle any complaints or claims, and assert, exercise or defend legal claims.
Accounting and tax data are stored for the periods specified in applicable tax and accounting regulations.
Data processed on the basis of consent for newsletters are generally stored until consent is withdrawn or until the purpose for which they were collected ceases, unless another legal basis permits continued storage.
Health data are stored only for as long as necessary for the purpose for which they were obtained and in accordance with the principle of data minimisation.
After the retention period expires, personal data are deleted, destroyed or anonymised, unless otherwise required by law.
The Controller implements appropriate technical and organisational measures to protect personal data against:
Access to personal data is granted only to persons who require it to perform their tasks.
In accordance with applicable legislation, individuals have the right:
The exercise of individual rights may be restricted where a legal basis for such restriction exists.
Individuals have the right to obtain confirmation as to whether their personal data are being processed and, where they are, access to the data and information regarding:
Under the conditions of the GDPR, individuals have the right to obtain a copy of their personal data.
Individuals may request the rectification of inaccurate personal data or the completion of incomplete personal data.
The Controller will carry out the rectification without undue delay where the request is justified.v
Individuals may request the erasure of their personal data where the conditions set out in the GDPR are met.
The right to erasure is not absolute. The Controller may continue to store personal data where retention is necessary to comply with a legal obligation, or for the establishment, exercise or defence of legal claims, or where another lawful basis applies.
Individuals may request the restriction of processing where the conditions set out in the GDPR are met, particularly when:
Where the conditions of the GDPR are met, individuals have the right to receive the personal data they have provided to the Controller in a structured, commonly used and machine-readable format, and to transmit those data to another controller.
Where personal data are processed on the basis of legitimate interest, individuals have the right to object to such processing on grounds relating to their particular situation, provided the conditions of the GDPR are met.
Where personal data are processed for direct marketing purposes, individuals may object at any time. After an objection to direct marketing, personal data will no longer be used for this purpose.
Where processing is based on consent, individuals may withdraw their consent at any time.
Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.
Consent to receiving newsletters may be withdrawn by using the unsubscribe link included in each e-mail or by contacting: info@experience-slovenia.com
If an individual withdraws consent for the processing of health data, this may affect their ability to participate in a programme when such information is necessary for safe implementation.
Requests to exercise rights may be sent to:
KochaGuide, Nejc Košnik s.p.
Cesta 1. maja 63
4000 Kranj
Slovenia
or by e-mail to: info@experience-slovenia.com
The Controller generally responds without undue delay and no later than one month from receipt of the request. In cases provided by law, the deadline may be extended by up to two additional months, in which case the Controller will inform the individual in a timely manner.
If there is justified doubt regarding the identity of the person submitting the request, the Controller may request additional information necessary to confirm identity.
If an individual believes that their personal data are being processed in violation of applicable legislation, they may lodge a complaint with the competent supervisory authority:
Information Commissioner of the Republic of Slovenia
Individuals may submit a request or complaint directly to the supervisory authority without first contacting the Controller.
The Controller may amend or supplement this Policy when necessary due to changes in legislation, methods of personal data processing, the use of new technologies, or changes in business operations.
The current version of the Policy is published on the website of Experience Hiking Agency.
Date of last update: 25 August 2026