Privacy & data protection

Privacy policy & GDPR information

We care about privacy and about using your personal data in a transparent, fair way. On this page we explain what data we collect, why we collect it, how long we keep it, who we share it with, and which rights you have under the EU General Data Protection Regulation (GDPR).

This privacy policy is intended as a clear summary for guests and website visitors. It does not replace tailored legal advice. If you have questions about how we handle your data, contact us using the details below.

1. Who we are and contact details

Who is responsible for your data and how to reach them.

This website is operated under the brand Dolomites Mountain Guides. For the purposes of the GDPR, the data controller is:

Dolomites Mountain Guides

Operated by: Luca Trubbiani

Website: www.dolomitesmountainguides.com

Data controller: Luca Trubbiani, Strada ai Matonari 7, 38045 Civezzano (TN), Italy. VAT 02778180220. Email info@dolomitesmountainguides.com.

Email: info@dolomitesmountainguides.com

No Data Protection Officer is appointed: the conditions of Article 37 GDPR are not met for an individual professional processing data on this scale. The contact point for every request about your data is the controller named above.

2. Scope of this privacy policy

Which of our activities this notice covers.

This privacy policy applies to:

  • • Visits to our website and use of our online content.
  • • Enquiries sent via contact forms and booking forms on this website.
  • • Subscription to any newsletter or similar updates we may offer.
  • • Direct communication with us by email, phone, messaging apps or social media in relation to our guiding services.
  • • Online payments related to bookings (when offered), including card payments via Stripe.

This policy does not apply to websites or services operated by third parties, even if we link to them from our pages (for example accommodation, rental shops, transport providers). Please consult their privacy policies separately.

3. What personal data we collect

Everything collected, including health data and the data of your emergency contact.

3.1 Data you provide directly

  • Contact and enquiry forms: name, email address, telephone number, message, preferred dates, type of activity, number of participants and any other information you choose to share.
  • Booking forms: in addition to the above, we may ask for further details needed to organise the trip (e.g. approximate level/experience, language preferences, logistics). If you book for other people you provide personal data of third parties: you must be entitled to do so and you must inform each participant about this privacy notice. We provide the notice to participants at the first direct contact (Art. 14 GDPR).
  • Account / portal (if used): email, authentication details (e.g. login tokens), and booking-related preferences.
  • Newsletter / marketing communications (if available): email address and your communication preferences.
  • Participant form: for each participant we also collect height and weight (used to size equipment correctly and to plan the day with the risk kept low), sex (optional), mountain experience and expectations, and the name and telephone number of an emergency contact. Emergency contact details are used only if we need to reach someone in connection with the activity. If you provide another person's details, you must be entitled to do so and you must inform them about this notice.
  • Availability alerts: if you ask to be told when a new public group date is published, we keep your email address, your name if you give it and your language, on the basis of the consent you give with the dedicated checkbox (Art. 6(1)(a) GDPR). We send one email for that purpose and every email carries an unsubscribe link.

3.2 Payments, orders and transaction records (important)

When you pay online, we must keep a record of your order and the related transaction for operational, customer-service, accounting and legal purposes. These records may include:

  • • Booking/order identifier, date/time and status (pending/paid/failed/refunded).
  • • Amount, currency, payment purpose (deposit/balance/full) and payment method (e.g. card, bank transfer).
  • • Transaction references and technical identifiers provided by Stripe (e.g. payment intent ID, checkout session ID).
  • • Billing email and basic customer reference needed to match the payment to a booking.

We do not store your card details. Card payments are processed by Stripe. We do not receive, store or have access to your full card number, CVV, or similar card security data. Stripe processes your payment data according to their own privacy and security standards.

3.3 Data collected automatically when you visit the site

When you browse our website, certain technical data are collected automatically, for example:

  • • IP address and approximate location (country/region).
  • • Device and browser type, operating system, language settings.
  • • Pages visited, time and duration of visit, referring page/URL.
  • • Interactions with the website (clicks, forms, error pages).
  • • Anti abuse data: the IP address of a request is used, for a short time and in memory only, to limit how often the same source can submit forms, and Cloudflare Turnstile issues a one time token to tell a person from a bot. Links sent to you for a booking (payment links, participant forms) carry a token whose use can be recorded together with the address it was used from.

Server logs record technical data about requests. Cookies and similar technologies are described in section 5. Google Analytics 4 is loaded only after you consent through the cookie banner and runs in Consent Mode: before consent no measurement identifier is set. Cloudflare Turnstile runs on the contact, newsletter and booking forms to keep automated abuse out.

3.4 Special categories of data

For guided activities we do collect health information about participants: relevant medical conditions, allergies and dietary notes. These are special categories of data under Article 9 GDPR and we process them only on the basis of your explicit consent (Art. 9(2)(a) GDPR), given with the dedicated checkbox in the participant form. we do not collect data on religion or political opinions via the website. we ask only for what is strictly necessary to plan the activity with the risk kept low and we treat it with particular care.

Health notes are deleted within 30 days after the end of the activity, unless an incident or a dispute requires keeping them to establish, exercise or defend legal claims (Art. 9(2)(f) GDPR) within the statutory limitation periods. The deletion runs automatically. You can withdraw your consent at any time by writing to info@dolomitesmountainguides.com, without affecting the processing already carried out.

4. Why we use your data (purposes and legal bases)

Why each piece of data is used, and the legal basis for each purpose.

We process your personal data only when we have a valid legal basis under Article 6 of the GDPR. In practice, this means:

Purpose
Examples
Legal basis
Handling enquiries & bookings
Replying to messages, preparing offers, confirming trips, communicating practical information.
Pre-contractual steps & performance of a contract (Art. 6(1)(b) GDPR).
Payments & transaction administration
Recording orders and payments (deposit/balance), issuing receipts/invoices, payment reconciliation, fraud prevention, handling disputes/chargebacks where applicable.
Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)); in some cases legitimate interest (Art. 6(1)(f)).
Managing customer relationships
Follow-ups, service continuity, keeping a record of trips taken for future planning.
Legitimate interest in providing good service (Art. 6(1)(f) GDPR).
Newsletter & marketing (if active)
Sending trip updates, new program announcements or seasonal information.
Consent (Art. 6(1)(a) GDPR). You can withdraw consent at any time.
Website analytics & improvement
Understanding which pages are most useful, detecting usability issues and improving content.
Consent (Art. 6(1)(a) GDPR and Art. 122 of the Italian Privacy Code). No analytics tool is loaded before consent.
Security, anti-spam & abuse prevention
Preventing misuse, protecting forms from automated spam, keeping logs for investigations.
Legitimate interest (Art. 6(1)(f) GDPR).
Legal obligations
Accounting, tax obligations, responding to lawful requests by authorities.
Compliance with legal obligations (Art. 6(1)(c) GDPR).
Health information about participants
Assessing suitability for the objective, planning pace, breaks and prudential margins, informing rescue services if needed, catering for allergies and dietary needs on hut based programs.
Your explicit consent (Art. 9(2)(a) GDPR), given with the dedicated checkbox in the participant form. If an incident or a dispute arises, the same data may be kept to establish, exercise or defend legal claims (Art. 9(2)(f) GDPR). Providing the information is necessary: without it the booking cannot be confirmed (Art. 13(2)(e) GDPR).
Emergency contact
Reaching a relative or friend during or after an incident, or when a participant cannot be reached.
Protection of vital interests (Art. 6(1)(d) GDPR) and legitimate interest in being able to act in an emergency (Art. 6(1)(f) GDPR). The person you name is informed of this notice at the first direct contact (Art. 14 GDPR).

5. Cookies, analytics & similar technologies

Cookies: nothing non essential loads before you consent.

Our website may use cookies and similar technologies to make the site work, remember your preferences and understand how visitors use our pages.

  • Necessary cookies: required for basic security and functionality (e.g. session cookies).
  • Preference / functional cookies: remembering language or other minor preferences.
  • Analytics cookies: measuring traffic and usage patterns in an aggregated way.
  • Anti abuse technology: Cloudflare Turnstile places a short lived token on the public forms (contact, newsletter, booking request). It is used only to tell a person from an automated script and it does not profile you or follow you across sites.

Strictly necessary technical cookies are exempt from consent under Art. 122 of the Italian Privacy Code (Legislative Decree 196/2003); this notice still applies to them. Analytics cookies require your consent: no Google tool is loaded before you give consent via the cookie banner. You can change your choice at any time and delete or block cookies from your browser settings. You can change your choice at any time from the cookie settings link in the footer.

6. How long we keep your data

How long each category is kept, category by category.

We keep personal data only for as long as needed for the purposes described above, or to comply with legal obligations. As an indication:

Data Retention Why
Enquiries and contact messages without a booking 24 months from the last message Legitimate interest in following up an enquiry (Art. 6(1)(f))
Bookings, participant lists and guiding records For the duration of the contract, then 10 years Performance of the contract, then Art. 2220 of the Italian Civil Code
Payment and transaction records, invoices 10 years, longer while a dispute or chargeback is open Art. 2220 of the Italian Civil Code, tax law, defence of legal claims
Participants' health notes (medical conditions, allergies, dietary notes) 30 days after the end of the activity, automatically. Longer only where an incident or dispute requires it. Consent, Art. 9(2)(a); afterwards Art. 9(2)(f) only in the incident case
Emergency contact details Deleted together with the health notes of the same booking They serve one activity only
Newsletter subscriptions Until you unsubscribe. After that we keep your address on a suppression list so you are not contacted again, and nothing else is used Consent (Art. 6(1)(a)); the suppression list rests on the legitimate interest in honouring your opt out (Art. 6(1)(f))
Waiting lists and availability alerts Until the notification is sent or you unsubscribe, then 30 days The purpose is exhausted once you have been told
Server logs and anti abuse data Server and application logs a few weeks. Rate limiting counters live in memory only, are cleared automatically within two hours of the last request they counted, and are discarded in any case when the application restarts. Form submissions are not stored with an IP address. Where a portal link records the address it was opened from, that entry is erased 30 days after the link expires Security and abuse prevention (Art. 6(1)(f))
Database backups 14 days for the nightly rotation. Occasional manual backups taken before a technical change are kept until that change is verified, then deleted Business continuity. Data deleted from the live system disappears from backups by the end of the cycle and is never used for anything else in the meantime
Records of consent and acceptance (terms, health data). Your cookie choice is stored in your browser, not on our servers For as long as the related processing lasts, and then for the limitation period Accountability, Art. 5(2) and Art. 7(1) GDPR

7. Who we share data with

The named providers who see your data, and what each one sees.

We do not sell your data. We may share personal data only when necessary with:

  • Service providers: OVHcloud (France, EU) for website hosting; Aruba S.p.A. (Italy) for sending emails; Cloudflare Inc. (USA) for anti-spam protection of the forms (Turnstile); Google Ireland Ltd and Google LLC (USA) for Google Analytics 4, acting as our processor and only after your consent.
  • Payment processor (Stripe): if you pay by card, your payment is processed by Stripe Payments Europe Ltd (Ireland) and Stripe Inc. (USA). Stripe acts as our processor to deliver the payment service, and as an independent controller for fraud prevention and its own regulatory obligations. We receive and store only the information needed to reconcile and manage the transaction (e.g. status, amount, currency and Stripe identifiers). We do not store card data.
  • Other recipients: banks handling bank transfers (acting as independent controllers), accounting/tax advisors and legal counsel, and public authorities where required by law.
  • Who does not receive your data: huts, lifts, rental shops and transport providers are not our recipients. Where a program involves them, you contract with them directly and any data they need you give them yourself. We do not pass your booking data to them and we do not book on your behalf.

When we use external providers who process personal data on our behalf, we use appropriate contractual safeguards (e.g. data processing agreements) where required by law.

8. Transfers outside the EU/EEA

What leaves the EU, and on which legal safeguard.

Some providers (Stripe Inc., Google LLC, Cloudflare Inc.) process data in the United States. These transfers are based on the EU-US adequacy decision (EU-US Data Privacy Framework, Decision 2023/1795), under which these providers are certified (you can verify this at www.dataprivacyframework.gov) and, as a fallback, on the Standard Contractual Clauses under Art. 46 GDPR included in their data processing agreements. You can obtain a copy of the safeguards at the providers' links or by writing to info@dolomitesmountainguides.com. Data sent to the United Kingdom is covered by the EU-UK adequacy decision, renewed until 2031. The website is hosted on servers in the European Union.

9. Your rights under the GDPR

Your rights, how to use them and where to complain.

As a data subject you have rights, subject to certain conditions:

  • • Right of access and to receive a copy of your data.
  • • Right to rectification of inaccurate or incomplete data.
  • • Right to erasure in certain cases.
  • • Right to restriction of processing in certain cases.
  • • Right to data portability, where applicable.
  • • Right to object to processing based on legitimate interests, including direct marketing.
  • • Right to withdraw consent at any time where processing is based on consent.

To exercise your rights, contact us at info@dolomitesmountainguides.com .

We answer requests without undue delay and within one month, extendable by two further months for complex requests, of which we would inform you (Art. 12(3) GDPR). Exercising your rights is free. You also have the right to lodge a complaint with a supervisory authority. In Italy: Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma, www.garanteprivacy.it. You can also apply to a court.

For cookies and analytics, and to change a choice you have already made, see section 5.

10. Children & minors

Minors: a parent provides the data and gives the consent.

Our website and services are primarily aimed at adults. We do not knowingly collect personal data from children under 16 for marketing purposes. For participants who are minors, their data (including health information) is provided by the person holding parental responsibility, who gives consent on their behalf and declares this in the participant form. Under Italian law, autonomous digital consent from age 14 applies only to information society services offered directly to a minor, which is not the case here.

11. Changes to this privacy policy

How changes to this notice are published.

We may update this privacy policy from time to time (for example when we add new services such as online payments or when laws change). The latest version is always available on this page and replaces previous versions.

Last updated: August 2026 (version 2026-08).