Privacy Policy

1. Data Controller

2. What Personal Data We Collect

  • Full name

  • Email address

  • Phone number

  • IP address & approximate location

  • Billing information (when purchasing gift cards or services)

  • Responses to tour questionnaires

  • Name, email, and phone of gift card recipients

  • Approximate date of planned visit to Ljubljana

3. How We Collect Your Data

  • Website contact and survey forms

  • Online booking systems

  • SMS communications

  • Web chat and chatbot tools

  • Online purchases (gift cards or services)

4. Why We Collect and Process Your Data

  • Managing and confirming tour bookings

  • Sending updates, confirmations, and reminders (via email/SMS)

  • Providing customer support

  • Processing payments

  • Marketing and re-engagement campaigns

  • Internal analysis (e.g., popular tours, time of visits)

  • Automated tagging to customize communication

5. Legal Basis for Processing

  • Your consent (e.g., marketing opt-ins, form submissions)

  • Contract performance (e.g., booking a tour/rental)

  • Legal obligation (e.g., billing retention requirements)

  • Legitimate interests (e.g., improving services, sending reminders)

6. Cookies and Tracking Tools

7. Sharing Your Data with Third Parties

  • uplevelOne™ (CRM, forms, automation – operated on secure third-party infrastructure)

  • Stripe (payment processing)

  • Google & Meta (Facebook) (analytics, retargeting)

  • Embedded scheduling tools (if used)

8. International Data Transfers

9. Your Rights Under GDPR

  • Access your personal data

  • Correct inaccurate or outdated data

  • Delete your data (“right to be forgotten”)

  • Restrict or object to certain processing

  • Withdraw consent at any time (without affecting prior lawful processing)

  • Lodge a complaint with the Slovenian Information Commissioner (Informacijski pooblaščenec): www.ip-rs.si

10. Data Retention

  • Booking & billing data: kept for at least 5 years (per accounting rules)

  • Marketing/contact data: anonymized after 5 years of inactivity

  • Gift card or survey data: stored securely and anonymized once no longer needed

11. Data Security

  • SSL encryption on all website traffic

  • Strong password policies

  • uplevelOne™ infrastructure with secure access controls

12. Policy Updates

  • Email (if you’ve provided it)

  • A banner or pop-up on the website

13. Contact