BONJOUR BUCHAREST
Your privacy.
Last updated: 14 September 2026
This notice explains how Bonjour Bucharest uses information connected with your enquiries and reservations. We do not sell your data, and making a booking does not subscribe you to a newsletter.
Contact us
For a question or request about your data, use our contact form.
What we use, and why
- Bookings: the contact’s name, email, departure, language, party size, reference, status, and record of acceptance of the terms. We use these to provide the requested walk and practical messages, based on performance of the contract or steps taken at your request (GDPR Article 6(1)(b)).
- Enquiries: the contact details and message you send. We respond to booking-related requests on the same basis; for general enquiries, our legitimate interest is responding to people who contact us (Article 6(1)(f)).
- Security: technical information needed to operate the website, such as an IP address, request time, and errors. Our legitimate interest is preventing abuse and maintaining a reliable service (Article 6(1)(f)).
- Payments, when a paid service is offered: payment reference, amount, currency, and status. Applicable accounting or tax record duties rely on a legal obligation (Article 6(1)(c)). Card details are handled by Stripe, not stored in our booking database.
Required form fields are needed to reserve and receive walk details. We do not ask for identity documents or the names of other participants. For accessibility needs, describe practical adjustments rather than medical information.
Who receives this information?
Elena and people authorised to manage the walks use the information they need. Technical providers support hosting and security (Netlify), the database, images and owner login (Supabase), and service emails (Resend). Stripe is involved only for payments. Authorities or professional advisers may receive information where a legal duty or the defence of a claim requires it.
Netlify · Supabase · Resend · Stripe
These providers and their subprocessors may process some data outside the European Economic Area, including for their services and support. Contact us for information about processing locations and the applicable transfer safeguards, including standard contractual clauses where used.
How long information is kept
- Free bookings and associated contact information: removed from the active database 90 days after departure.
- Contact enquiries: 180 days after submission.
- Completed email delivery records: 90 days after sending, or earlier when the associated booking or enquiry is removed.
Information needed for an ongoing dispute or legal obligation may be retained longer, with access limited to that purpose. Paid-service records follow applicable accounting and tax retention duties. Deletion from the active database does not instantly erase all copies in restricted backups or providers’ systems.
Your rights
Subject to GDPR conditions, you can request access, correction, erasure, restriction and portability of your data, and object to processing based on legitimate interests. If processing relies on your consent, you can withdraw it without affecting earlier lawful processing.
We normally respond within one month; if an extension permitted by the GDPR is needed, we will explain it. We may verify your identity proportionately. You may also complain to Romania’s ANSPDCP or the supervisory authority where you habitually live, work, or believe an infringement occurred.
Contact ANSPDCP · Read the GDPR
We do not use your data for advertising profiling or an individual decision based solely on an automated personal profile.