Skip to content
letsvisitSlovenië

Taal

Privacy

What we hold about you, why, who else sees it, and how to make us forget it.

This document is a draft. It sets out the sections this page will contain and is not yet in force, so nothing on it binds you or us. It will be replaced with the adopted text before any booking or payment is taken through this site. Ask us anything in the meantime at info@letsvisit.si.

1.Who controls your data

To be written. This section must cover:

  • The registered company, as the controller, with its address and registration number
  • A contact point for privacy questions
  • Whether a data protection officer is appointed, and if so who

2.What we hold, and why

To be written. This section must cover:

  • Account: email address and password hash, to let you sign in and own your trips
  • Trips: the places you saved and the days you put them on
  • Messages you send the assistant, and the trip brief extracted from them
  • Reviews and ratings you write, which are public under your chosen name
  • Technical logs needed to run and secure the service
  • The legal basis for each of these, and how long each is kept

3.What the assistant remembers about you

When you are signed in, the assistant keeps a short list of things you have told it about yourself so that it asks you fewer questions next time: how many of you usually travel, the food you ask for, how you get around, and any dietary or access needs you have stated.

Three rules govern it. It only ever records something you said yourself, taken from your own messages; nothing is inferred from what you looked at and nothing is bought in. It counts rather than concludes — each entry is a tally of how many separate conversations mentioned it, and a thing said once is never used. And all of it is visible and deletable, one entry at a time, on your profile.

It is used to ask a better question, never to decide for you. If we have you down as travelling with two children, you will be asked whether it is the four of you again — not quietly planned for.

To be written. This section must cover:

  • The retention period for these entries if an account goes unused

4.Before you make an account

You can plan a trip without signing up. When you do, the trip is held against a random token stored in your browser rather than against a name. That token is still personal data under the GDPR even though we do not know who you are, so it is covered by everything on this page. It lasts a year, it is deleted when you clear your site data, and making an account later attaches the trips you already built to it.

5.Who else sees it

To be written. This section must cover:

  • The hosting provider, and where the servers are
  • The payment provider, once payments are live, and that card details never reach us
  • The model provider used to read your messages, what is sent, and that it is not used for training
  • A business you book with, and exactly which fields it receives
  • That we do not sell personal data, and do not share it for advertising

6.Transfers outside the EEA

To be written. This section must cover:

  • Which processors are outside the EEA
  • The safeguard relied on for each, such as standard contractual clauses

7.Your rights

To be written. This section must cover:

  • Access, rectification, erasure, restriction, portability and objection
  • How to exercise each one and how long we take
  • The right to complain to the Informacijski pooblaščenec, with its address

8.Automated decisions

To be written. This section must cover:

  • That ranking and recommendations are computed, what goes into them, and that they do not produce a legal or similarly significant effect
  • That a language model reads your messages to understand the request, and never chooses the places

Who to contact

The registered company name, address, registration number and VAT number are not published here yet. They are required on this page before the service takes payments, and they will appear here when the company behind LetsVisit is registered.