Skip to content
Legal

Privacy policy

We are two people running a small hiking business, not an advertising company. We ask for the least we can get away with, we use it to plan your week, and we do not sell it to anybody. This page says exactly what that means, in the language the GDPR asks for.

Last updated 2026-09-08

01

Who is responsible for your data

The data controller is the business behind this website. Under Article 4(7) of the General Data Protection Regulation that means we are the ones who decide why and how your personal data is used, and the ones you can hold to account for it.

We are not required to appoint a Data Protection Officer under Article 37 GDPR and we have not appointed one. Anja and Darja handle these questions themselves, at the address above.

02

What this policy covers

It covers www.andara.si and everything that happens when you use it: reading a page, watching one of the two videos, sending the enquiry form, and the email conversation that follows. It also covers the booking itself, if you decide to walk with us.

It does not cover other people's websites. Our Instagram and TikTok profiles, the Google Maps links in the itinerary, the hotels we suggest for your arrival night and the Wikimedia pages behind our image credits all run under their own privacy policies, and we have no control over them.

03

What we collect, why, and for how long

There is no account to create here and no booking engine. Almost everything below starts with you deciding to write to us.

Where it comes fromWhat it isWhy we may use itHow long we keep it
Enquiry formName, email, country, preferred month, group size, anything you write in the message box.To answer your enquiry and prepare a quote. Article 6(1)(b) GDPR, steps taken at your request before entering into a contract. Your browser sends it to the form service listed below, which emails it to us.12 months from our last exchange, unless it turns into a booking. The mail service that delivers it keeps its own copy for up to 3 years, then deletes it automatically.
BookingThe above, plus billing details, the names of everyone walking, arrival and departure details, and the hut nights we reserve for you.To arrange and deliver the trek you booked. Article 6(1)(b) GDPR, performance of a contract.5 years after the trek ends, which is the general limitation period for claims under Slovenian law.
Invoices and accountingName, address, amounts, dates, payment reference.We are required to keep them. Article 6(1)(c) GDPR, legal obligation under Slovenian tax and accounting law.10 years from the end of the financial year the invoice belongs to.
Health and dietary informationOnly what you choose to tell us: allergies, dietary needs, a knee that does not like descents, an emergency contact.So the huts can feed you safely and so we know who to call. Article 9(2)(a) GDPR, your explicit consent. You never have to give it, and you can withdraw it at any time.Deleted within 3 months of the trek ending.
Emails you send usWhatever is in them, plus your email address.To keep a record of what was agreed. Article 6(1)(b) and 6(1)(f) GDPR, our legitimate interest in being able to show what we promised.5 years, then deleted.
Server logsIP address, browser, the page requested, the time of the request. Created automatically by our host.To keep the site up and to stop abuse. Article 6(1)(f) GDPR, our legitimate interest in a working, secure website.Up to 30 days at our host, then deleted.
Spam protection on the formA hidden field a person never fills in, plus a short-lived count of submissions per IP address.To stop bots flooding the inbox. Article 6(1)(f) GDPR, our legitimate interest in a usable inbox.The count is held in memory only and disappears within an hour.
AnalyticsA cookie identifier, approximate location from a truncated IP address, pages viewed, device and browser.To see which pages are read and which are not. Article 6(1)(a) GDPR, your consent. Nothing is loaded until you give it.14 months, then deleted by Google. Withdraw at any time from the cookie settings.

The form asks for very little on purpose. Only your name and email are required, because without them we cannot answer. Country, month, group size and the message are optional, and the answer is simply less precise without them. Nothing on this site asks for a payment card.

04

Cookies and analytics

This website sets no cookies at all until you choose. On your first visit you get one question, with “Only necessary” sitting next to “Accept analytics” and neither one hidden or dressed up to look more attractive than the other.

If you decline, Google Analytics is never downloaded, no analytics cookie is written and no request goes to Google at all. If you accept, Google Analytics 4 counts your visit. Either way we store your answer in your browser's local storage under andara_consent so that we do not ask again for six months.

The full list of what is set, by whom and for how long is on the cookie policy page. You can change your mind at any moment:

05

Who else sees your data

We do not sell personal data, we do not trade it and we do not hand it to advertisers. It reaches other people only in the two situations below.

The companies that run the machinery

These are processors under Article 28 GDPR. They act only on our written instructions and may not use your data for their own purposes.

CompanyWhat it does for usWhereSafeguard for transfers
Vercel Inc.Hosting and delivery of this website, server logs, privacy-friendly traffic measurement. Their privacy policyUnited States, with edge servers in the EUEU-U.S. Data Privacy Framework and EU Standard Contractual Clauses
Web3Creative (Web3Forms)Turns your enquiry into the email that reaches our inbox. Your browser sends the form straight to them, so they also receive your IP address. They keep a copy of the submission for up to three years and then delete it automatically. Their privacy policyRegistered in Kerala, India, with servers in the United StatesEU Standard Contractual Clauses, under their Data Processing Agreement
Resend (Plus Five Five, Inc.)Standby route for the same enquiry email, used only if the one above is unavailable. Their privacy policyUnited StatesEU Standard Contractual Clauses
Google Ireland LimitedGoogle Analytics 4, website statistics. Runs only if you allow analytics cookies. Their privacy policyIreland, with onward transfer to Google LLC in the United StatesEU-U.S. Data Privacy Framework and EU Standard Contractual Clauses
Cloudinary Ltd.Delivery of the two videos on this site. Receives your IP address when a video loads. Their privacy policyIsrael and the United StatesEU adequacy decision for Israel, and EU Standard Contractual Clauses for the United States

The people who host and move you

If you book, we have to tell the mountain huts, the guesthouses and the transfer drivers who is coming, on which night, and anything that affects your safety or your dinner. They receive the minimum needed to do their part and they are independent controllers of what they then hold. We name every one of them in your itinerary before you pay anything, so you always know where your name has gone.

Beyond that, we would only pass data to a public authority, a court, an insurer or mountain rescue where the law requires it or where somebody's safety depends on it.

06

Data leaving the European Economic Area

Our host, our email sender and Google are all reachable from the United States, and our video delivery runs partly from Israel. That makes some transfers outside the EEA unavoidable for a website of this kind.

Where a transfer happens it rests on the EU-U.S. Data Privacy Framework where the company is certified under it, on the European Commission's adequacy decision for Israel, and otherwise on the European Commission's Standard Contractual Clauses under Article 46(2)(c) GDPR. You can ask us for a copy of the clauses that apply to a particular provider by writing to info@andara.si.

07

Your rights, and how to actually use them

All of these are yours under Chapter III of the GDPR. Write one email to info@andara.si and we will deal with it within one month. It is free. We may ask one question back to check you are who you say you are, and nothing more than that.

  • Access, Article 15. Ask us for a copy of everything we hold about you, and what we are doing with it.
  • Rectification, Article 16. Tell us to correct anything wrong or fill in anything missing.
  • Erasure, Article 17. Tell us to delete it. We will, unless we are still legally required to keep a specific record such as an invoice, in which case we will tell you exactly which one and why.
  • Restriction, Article 18. Tell us to freeze it while a dispute or a correction is sorted out.
  • Portability, Article 20. Ask for what you gave us in a machine-readable file, or ask us to send it somewhere else.
  • Objection, Article 21. Object to any use we base on legitimate interest, such as our server logs or our spam protection.
  • Withdrawing consent, Article 7(3). Withdraw analytics consent from the cookie settings, and withdraw consent for health or dietary information by email. Withdrawing does not undo what was lawful beforehand.

There is no automated decision-making and no profiling on this site within the meaning of Article 22 GDPR. Every quote you receive was written by Anja or Darja.

08

If you think we got it wrong

Tell us first, because it is usually a misunderstanding we can fix the same day. But you never have to go through us. Under Article 77 GDPR you can complain directly to the supervisory authority, and in Slovenia that is:

Informacijski pooblascenec Republike Slovenije
Information Commissioner of the Republic of Slovenia
Dunajska cesta 22, 1000 Ljubljana, Slovenia
gp.ip@ip-rs.si · +386 1 230 97 30 · www.ip-rs.si/

If you live in another EU or EEA country you may complain to your own national supervisory authority instead.

09

How we keep it safe

The site is served over HTTPS only. When you press send, the form goes from your browser to the form service named in the table above, which turns it into an email and delivers it to us. That service is the only third party that sees what you wrote, and because your browser talks to it directly, it also sees your IP address. The email lands in a single mailbox that Anja and Darja use, protected by two-factor authentication. We keep no customer database of our own and we hold no payment card details, ever.

If a breach ever occurs that is likely to put your rights at risk we will report it to the Information Commissioner within 72 hours, as Article 33 GDPR requires, and we will write to you directly, as Article 34 requires.

10

Children

This trek crosses demanding alpine terrain and the website is written for adults. We do not knowingly collect data from anyone under 16. Where a child walks with a family group we take their name and any dietary need from the parent or guardian who books, and we use it for nothing else. If you believe a child has sent us something directly, write to us and we will delete it.

11

Changes to this policy

If we add a tool, change a provider or start doing something new with your data, this page changes with it and the date at the top moves. Where the change matters to people who have already booked we write to them, rather than expecting them to re-read a web page. Older versions are available on request.

Email usPlan your dates