PRIVACY AND PERSONAL DATA PROTECTION POLICY

EXPERIENCE HIKING AGENCY

1. General

This Privacy and Personal Data Protection Policy (hereinafter: the Policy) explains how KochaGuide, Nejc Košnik s.p., operating under the brand name Experience Hiking Agency (hereinafter: the Controller), collects, uses, stores and protects the personal data of individuals.

The Policy applies to the personal data of website visitors, registered programme participants, subscribers, customers and other individuals whose personal data the Controller processes.

The Controller processes personal data in accordance with applicable legislation, in particular Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR), the Personal Data Protection Act (ZVOP-2), and other relevant legislation of the Republic of Slovenia and the European Union.

This Policy does not regulate the use of cookies and similar technologies. Their use is governed by a separate Cookie Policy.

2. Personal data controller

Controller: KochaGuide, Nejc Košnik s.p.
Cesta 1. maja 63
4000 Kranj
Slovenia
Brand: Experience Hiking Agency
E-mail: info@experience-slovenia.com

For questions regarding personal data protection or to exercise your rights, you may contact the Controller at the above e-mail address or postal address.

The Controller does not have a designated Data Protection Officer (DPO), as the conditions for appointing one under applicable legislation are not met.

3. What personal data we process

The scope of personal data depends on the purpose of processing and the services an individual uses or orders.

The Controller may process, in particular:

  • name and surname;
  • address;
  • postal code and city;
  • country;
  • telephone number;
  • e-mail address;
  • information about the registered programme;
  • programme date;
  • data necessary for organising and implementing the programme;
  • payment and invoice data;
  • communication records;
  • data relating to complaints, claims or other enquiries;
  • data voluntarily provided in the application form;
  • date of birth, when required for insurance or another specific purpose;
  • health data or information on health conditions or special circumstances voluntarily provided for safer programme implementation;
  • other data strictly necessary for the execution of a specific programme or for fulfilling legal obligations.

The Controller strives to process only personal data that is adequate, relevant and limited to what is necessary for each specific purpose.

4. Purposes and legal bases for processing personal data

4.1 Programme application and implementation

The Controller processes personal data when necessary for:

  • processing the application;
  • preparing and implementing the agreed programme;
  • communicating with the participant before, during and after the programme;
  • organising transport, accommodation, entrance fees, insurance and other services included in the programme;
  • notifying participants of programme changes, departure times and locations, and other important information;
  • resolving complaints and claims;
  • asserting, exercising or defending legal claims.

The legal basis is typically the performance of a contract or measures taken at the request of the individual prior to entering into a contract.

4.2 Fulfilment of legal obligations

The Controller also processes personal data when necessary to fulfil legal obligations, particularly in the areas of:

  • accounting;
  • tax obligations;
  • issuing and storing invoices;
  • maintaining business records;
  • cooperating with competent authorities when required by law.

The legal basis is the fulfilment of the Controller’s legal obligations.

4.3 Insurance

If an individual orders or requires insurance, the Controller may process the data necessary to conclude and implement the insurance.

The date of birth is collected only when required for a specific insurance policy.

Data may be forwarded to the insurance company or another insurance provider to the extent necessary for the ordered insurance.

4.4 Health information voluntarily provided by the individual

In the application form, individuals may indicate health conditions or special circumstances they believe the guide should be aware of to ensure safer programme implementation.

Health data is a special category of personal data.

The Controller processes such data only to the extent necessary for the safe execution of the specific programme and does not use it for any other purpose.

Processing of health data is carried out on the basis of the individual’s explicit consent, when consent is the legal basis.

Consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

If an individual chooses not to provide health information, this may affect their ability to safely participate in a specific programme when such information is essential for safety.

The Controller does not use health data for marketing, profiling or any unrelated purposes.

4.5 Communication with the individual

The Controller may use contact details for communication necessary to process the application and implement the programme, including:

  • confirmation of application;
  • programme information;
  • pre-departure instructions;
  • changes or important notifications;
  • payment information;
  • resolving questions and complaints.

Such communication is necessary for the performance of the contractual relationship or for exercising the Controller’s rights and obligations.

4.6 Direct marketing and newsletters

The Controller may use an individual’s e-mail address to send newsletters and other marketing messages based on consent, when such consent is required.

Newsletters may include:

  • information about new hikes, treks and via ferratas;
  • special offers;
  • information about new programmes;
  • content related to the activities of Experience Hiking Agency;
  • inspiration and other related content.

Consent is voluntary and is not a condition for registering for a programme.

Individuals may withdraw consent at any time, typically by clicking the unsubscribe link included in each e-mail or by contacting info@experience-slovenia.com.

After withdrawal, newsletters will no longer be sent unless another legal basis applies.

4.7 Legitimate interest

The Controller may process personal data on the basis of legitimate interest when such processing is necessary, lawful, and when the rights and freedoms of the individual do not override the Controller’s interests.

Legitimate interests may include:

  • ensuring the security of information systems;
  • preventing misuse and fraud;
  • protecting the website and business systems;
  • asserting, exercising or defending legal claims;
  • demonstrating the performance of contractual obligations;
  • basic business analytics, where proportionate and lawful.

Individuals may object to processing based on legitimate interest under the conditions set out in the GDPR.

5. Online application form

When applying for a programme via the online form, the Controller processes the data entered by the individual.

Mandatory fields are necessary to process the application and implement the programme. If the required data is not provided, the application or programme implementation may not be possible.

The date of birth is required only when necessary for insurance or another specific purpose.

Health-related information is not intended for general collection but for informing the guide of circumstances relevant to safe programme execution.

6.Transfer of personal data to third parties

The Controller may transfer personal data to third parties to the extent necessary for programme implementation, contract fulfilment or legal obligations.

This may include:

  • hotels and accommodation providers;
  • transport providers;
  • insurance companies;
  • local partners and service providers;
  • payment service providers;
  • accounting or business service providers;
  • IT and online service providers;
  • electronic communication providers;
  • other providers involved in programme execution.

Only data necessary for a specific purpose is shared.

When a third party processes personal data as a processor on behalf of the Controller, processing is regulated in accordance with GDPR requirements.

7. Transfers of personal data to third countries

If programme implementation requires transferring personal data to a country outside the European Union or the European Economic Area, such transfer will be carried out only when an appropriate legal basis and safeguards are ensured in accordance with applicable legislation.

This may include countries to which the individual travels when the transfer is necessary for programme execution or ordered services.

8. Processors and online service providers

In its operations, the Controller may use external providers of information, communication and marketing services.

It uses or may use, among others:

  • Brevo for sending newsletters and electronic communication;
  • Google Analytics for analysing website usage;
  • Google Tag Manager for managing tags on the website;
  • Meta Pixel for measurement and advertising purposes;
  • YouTube for displaying video content;
  • Google Maps for displaying maps and locations;
  • WordPress and related online solutions for operating the website.

Data processing through cookies and similar technologies is described in more detail in the separate Cookie Policy.

Google Analytics and Meta Pixel are activated on the website only after obtaining the user’s consent, when such consent is required.

9. Retention period of personal data

We store personal data only for as long as necessary for the purpose for which it was collected, or for as long as required by applicable legislation.

The retention period depends on the type of data and the purpose of processing.

Data related to programme applications and implementation are generally stored for as long as necessary to carry out the programme, handle any complaints or claims, and assert, exercise or defend legal claims.

Accounting and tax data are stored for the periods specified in applicable tax and accounting regulations.

Data processed on the basis of consent for newsletters are generally stored until consent is withdrawn or until the purpose for which they were collected ceases, unless another legal basis permits continued storage.

Health data are stored only for as long as necessary for the purpose for which they were obtained and in accordance with the principle of data minimisation.

After the retention period expires, personal data are deleted, destroyed or anonymised, unless otherwise required by law.

10. Protection of personal data

The Controller implements appropriate technical and organisational measures to protect personal data against:

  • unauthorised access;
  • loss;
  • destruction;
  • alteration;
  • unlawful disclosure;
  • any other unlawful processing.

Access to personal data is granted only to persons who require it to perform their tasks.

11. Rights of the individual

In accordance with applicable legislation, individuals have the right:

  • to access their personal data;
  • to rectify inaccurate or complete incomplete personal data;
  • to erase personal data, where the legal conditions are met;
  • to restrict processing;
  • to data portability, where the legal conditions are met;
  • to object to processing, where this right applies based on the legal basis and circumstances;
  • to withdraw consent, where processing is based on consent;
  • not to be subject to a decision based solely on automated processing, including profiling, where the conditions set out in the GDPR are met;
  • to lodge a complaint with the competent supervisory authority.

The exercise of individual rights may be restricted where a legal basis for such restriction exists.

12. Right of access

Individuals have the right to obtain confirmation as to whether their personal data are being processed and, where they are, access to the data and information regarding:

  • the purposes of processing;
  • the categories of personal data;
  • the recipients or categories of recipients;
  • the envisaged retention period;
  • the rights of the individual;
  • the right to lodge a complaint with a supervisory authority;
  • the source of the data, where personal data were not obtained directly from the individual;
  • any automated decision-making, including profiling.

Under the conditions of the GDPR, individuals have the right to obtain a copy of their personal data.

13. Right to rectification

Individuals may request the rectification of inaccurate personal data or the completion of incomplete personal data.

The Controller will carry out the rectification without undue delay where the request is justified.v

14. Right to erasure

Individuals may request the erasure of their personal data where the conditions set out in the GDPR are met.

The right to erasure is not absolute. The Controller may continue to store personal data where retention is necessary to comply with a legal obligation, or for the establishment, exercise or defence of legal claims, or where another lawful basis applies.

15. Right to restriction of processing

Individuals may request the restriction of processing where the conditions set out in the GDPR are met, particularly when:

  • they contest the accuracy of the data;
  • the processing is unlawful but they do not wish the data to be erased;
  • the Controller no longer needs the data, but the individual requires it for legal claims;
  • an objection to processing has been lodged, pending verification of which interests prevail.

16. Right to data portability

Where the conditions of the GDPR are met, individuals have the right to receive the personal data they have provided to the Controller in a structured, commonly used and machine-readable format, and to transmit those data to another controller.

17. Right to object

Where personal data are processed on the basis of legitimate interest, individuals have the right to object to such processing on grounds relating to their particular situation, provided the conditions of the GDPR are met.

Where personal data are processed for direct marketing purposes, individuals may object at any time. After an objection to direct marketing, personal data will no longer be used for this purpose.

18. Withdrawal of consent

Where processing is based on consent, individuals may withdraw their consent at any time.

Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.

Consent to receiving newsletters may be withdrawn by using the unsubscribe link included in each e-mail or by contacting: info@experience-slovenia.com

If an individual withdraws consent for the processing of health data, this may affect their ability to participate in a programme when such information is necessary for safe implementation.

19. Exercise of rights

Requests to exercise rights may be sent to:

KochaGuide, Nejc Košnik s.p.
Cesta 1. maja 63
4000 Kranj
Slovenia

or by e-mail to: info@experience-slovenia.com

The Controller generally responds without undue delay and no later than one month from receipt of the request. In cases provided by law, the deadline may be extended by up to two additional months, in which case the Controller will inform the individual in a timely manner.

If there is justified doubt regarding the identity of the person submitting the request, the Controller may request additional information necessary to confirm identity.

20. Right to lodge a complaint with the Information Commissioner

If an individual believes that their personal data are being processed in violation of applicable legislation, they may lodge a complaint with the competent supervisory authority:

Information Commissioner of the Republic of Slovenia

Individuals may submit a request or complaint directly to the supervisory authority without first contacting the Controller.

21. Changes to the Policy

The Controller may amend or supplement this Policy when necessary due to changes in legislation, methods of personal data processing, the use of new technologies, or changes in business operations.

The current version of the Policy is published on the website of Experience Hiking Agency.

Date of last update: 25 August 2026