GDPR Data Protection Notice

Moravia Bike Tours s.r.o.

1. Data Controller

Moravia Bike Tours s.r.o.
Sadová 1209, Pohořelice, 69123, Česká republika
Email: info@moraviabiketours.com
IČO: 24060739

2. What Personal Data We Process

We process personal data that you provide when contacting us, enquiring, or booking a cycling tour. This may include:

  • Name and surname

  • Email address

  • Phone number

  • Country of residence

  • Date of birth / age confirmation

  • Emergency contact details

  • Dietary and accommodation preferences

  • Bike skill level

  • Booking details (tour selection, dates, group information)

  • Payment data (bank transfer details — we do not store card information)

We also collect limited technical data through Hostinger’s built-in analytics (device type, browser, usage statistics).

We do not collect passport details unless required by a specific accommodation provider, in which case you will be informed separately.

3. Why We Process Your Data (Legal Basis under GDPR)

Your data is processed for the following purposes and legal grounds:

  • To provide the tour and related services (Article 6(1)(b) – contract performance)

  • To comply with legal obligations such as accounting and invoicing (Article 6(1)(c))

  • To ensure safety, including emergency contact processing (Article 6(1)(d))

  • To improve website functionality and service quality (Article 6(1)(f) – legitimate interests)

  • With your consent, where applicable (Article 6(1)(a))

4. How Your Data Is Used

We use your data to:

  • Respond to enquiries

  • Confirm and manage bookings

  • Organise accommodation, luggage transfer, and bike rental

  • Provide GPX routes and tour information

  • Communicate essential updates before and during the tour

  • Process payments via bank transfer

  • Keep legally required records

We do not use automated decision-making or profiling.

5. Sharing of Personal Data

Your data may be shared with:

  • Accommodation providers (to secure your booking)

  • Luggage transfer partners

  • Bike servicing or rental partners (if required during your tour)

  • IT and hosting providers (Hostinger)

We only share the minimum data necessary to deliver our services. We never sell or trade personal data.

All partners operate within the EU or follow GDPR-compliant standards.

6. Cookies and Analytics

Our website uses essential cookies and Hostinger’s analytics tools for basic traffic and performance monitoring. If additional analytics are introduced (e.g., Google Analytics), this notice will be updated.

7. Data Retention

  • Booking and invoicing data: 10 years (legal requirement)

  • Email enquiries without booking: 12 months

  • Emergency contact data: deleted immediately after your tour

  • Analytics data: according to Hostinger’s default retention policy

We retain only what is necessary.

8. Safety, Alcohol & Conduct

To ensure safe participation in cycling activities, we may document relevant safety-related information, including incidents caused by intoxication.

Moravia Bike Tours does not encourage the consumption of alcohol before or during cycling. You are solely responsible for ensuring your sobriety. We accept no liability for incidents arising from alcohol consumption, as detailed in our Terms & Conditions.

9. Your Rights

You have the following rights under GDPR:

  • Right of access (to know what data we hold)

  • Right to rectification (correct inaccurate data)

  • Right to erasure (in certain circumstances)

  • Right to restrict processing

  • Right to object

  • Right to data portability

  • Right to withdraw consent at any time

  • Right to lodge a complaint with the Czech Data Protection Authority
    (Úřad pro ochranu osobních údajů – ÚOOÚ)

To exercise any rights, email: info@moraviabiketours.com

10. Security

We protect personal data with:

  • HTTPS encryption

  • Secure Hostinger hosting

  • Controlled access to systems

  • Minimised data collection

  • Regular reviews of security measures

11. International Transfers

We process and store data within the EU. If future partners operate outside the EU, we will ensure GDPR-compliant safeguards (Standard Contractual Clauses, adequacy decisions).

12. Updates to This Notice

We may update this GDPR Notice as our services or legal requirements change. The latest version will be published on our website.