Privacy Policy
Last updated: [DATE]
1. Who is responsible for your data
The data controller for the personal data described in this policy is:
| Company | Beyond Nepal Expeditions |
|---|---|
| Registered address | Procesional 47, 46317 Villargordo del Cabriel, Valencia, Spain |
| Company registration no. | [NIF / CIF NUMBER] |
| VAT number | [VAT NUMBER, IF APPLICABLE] |
| Represented by | [DIRECTOR / MANAGING DIRECTOR NAME] |
| [PRIVACY@YOURDOMAIN.COM] | |
| Telephone | [PHONE NUMBER] |
Data Protection Officer
[If you have appointed a DPO, give their name and contact details here. Most small businesses are not required to appoint one — a DPO is mandatory only where your core activities involve large-scale regular monitoring or large-scale processing of special category data. If you have not appointed one, replace this paragraph with: "We are not required to appoint a Data Protection Officer. For any privacy question, contact us at the address above."]
2. What data we collect, and why
2.1 Data you give us when you book a call
When you book a call through our calendar we collect the information you enter — typically your name, email address, the time you select, and anything you add about your community or preferred travel window.
| Purpose | To hold the call you booked, assess whether the programme is a fit, and contact you about it. |
|---|---|
| Legal basis | Art. 6(1)(b) GDPR — steps taken at your request prior to entering a contract. Where we later send you programme updates you did not specifically request, Art. 6(1)(a) GDPR — your consent. |
| Retention | Applications that do not lead to a contract are deleted after [24 MONTHS]. Where a contract follows, data is retained for the statutory commercial and tax retention period applicable in our jurisdiction. |
2.2 Data collected automatically when you visit
Our hosting provider records standard server log data for security and stability: your IP address (shortened where technically possible), the date and time of the request, the page requested, the referring URL, and your browser and operating system version.
| Purpose | Delivering the website, defending against attacks, and diagnosing faults. |
|---|---|
| Legal basis | Art. 6(1)(f) GDPR — our legitimate interest in a secure and functional website. |
| Retention | [30 DAYS], unless a security incident requires longer. |
2.3 Cookies and local storage
This site sets no advertising or analytics cookies by default. We store a single entry in your browser's local storage (bne_consent_v1) to remember your cookie choice so we don't ask again on every visit. This is strictly necessary to honour your preference and requires no consent.
Full detail is in our Cookie Policy.
2.4 Embedded third-party content
Two elements of this site are hosted by third parties and load only after you actively allow them:
- The booking calendar, hosted by Calendly (see section 3).
- The explainer video, hosted by Vimeo in do-not-track mode, which loads only when you press play.
Until you act, no request is made to these providers and no data about you reaches them.
3. Who we share your data with
We do not sell your personal data. We share it only with the processors below, each under a data processing agreement as required by Art. 28 GDPR.
| Recipient | Purpose | Location & transfer safeguard |
|---|---|---|
| Calendly LLC | Hosting the booking calendar and processing the details you enter when booking a call. | USA. Safeguarded by the EU Standard Contractual Clauses; Calendly is certified under the EU–US Data Privacy Framework. |
| Cloudflare, Inc. | Website hosting and content delivery. | USA, with edge delivery from EU data centres. Safeguarded by Standard Contractual Clauses where data leaves the EEA. |
| [EMAIL PROVIDER, IF SEPARATE] | Sending and receiving correspondence with you. | [LOCATION AND SAFEGUARD] |
| Vimeo.com, Inc. | Hosting and delivering the explainer video, loaded only after you press play, in do-not-track mode. | USA. Safeguarded by the EU Standard Contractual Clauses. |
| Our local operating partner in Nepal | Only where you proceed to a booked departure — to arrange permits, accommodation and guides. | Nepal. Nepal has no EU adequacy decision; transfers are made under Art. 49(1)(b) GDPR as necessary to perform the contract you have entered into. |
4. International transfers
Some of our processors are located outside the European Economic Area, principally in the United States and Nepal. Where we transfer personal data outside the EEA we rely on one of the following: an adequacy decision of the European Commission; the EU Standard Contractual Clauses; or, for the performance of a contract you have requested, Art. 49(1)(b) GDPR. You may request a copy of the relevant safeguards using the contact details in section 1.
5. Your rights
Under the GDPR and UK GDPR you have the right to:
- Access — obtain confirmation of whether we process your data, and a copy of it (Art. 15).
- Rectification — have inaccurate data corrected (Art. 16).
- Erasure — have your data deleted where one of the grounds in Art. 17 applies.
- Restriction — require us to limit processing in the circumstances set out in Art. 18.
- Data portability — receive the data you gave us in a structured, machine-readable format (Art. 20).
- Object — object at any time to processing based on legitimate interests (Art. 21). Where we process your data for direct marketing, you may object at any time and we will stop immediately.
- Withdraw consent — where processing is based on consent, withdraw it at any time. This does not affect the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, contact us at [PRIVACY@YOURDOMAIN.COM]. We will respond within one month.
Right to lodge a complaint
If you believe we have handled your data unlawfully, you may complain to a supervisory authority — in particular in the EU or UK member state of your habitual residence, your place of work, or the place of the alleged infringement. Our lead supervisory authority is the Agencia Española de Protección de Datos (AEPD), www.aepd.es.
6. Is providing data mandatory?
You are under no statutory or contractual obligation to provide personal data. However, we cannot hold a call with you or contact you about the programme without the details requested at booking. Fields not marked as required are optional.
7. Automated decision-making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. Every enquiry is reviewed by a person.
8. Security
This site is served exclusively over encrypted HTTPS connections. We apply appropriate technical and organisational measures to protect your data against accidental or unlawful destruction, loss, alteration and unauthorised disclosure. No method of transmission over the internet is completely secure, and we cannot guarantee absolute security.
9. Children
This programme is directed at professional adults. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with data, contact us and we will delete it.
10. Changes to this policy
We may update this policy to reflect changes in our processing or in the law. The current version is always available at this URL, and the date at the top shows when it last changed.