Privacy Notice
UK GDPR & DPA 2018 compliant · Last updated June 2026
Data Controller: Badr Adventures UK
Contact: enquiries@badradventures.co.uk
ICO Registration: We are not required to register with the ICO because we do not process automated decisions or large-scale profiling. However, we follow all GDPR obligations as a matter of good practice.
| Data | Purpose | Legal Basis |
|---|---|---|
| Name, email, password hash | Account creation & authentication | Contract (art. 6(1)(b)) |
| Contact form data (name, email, message) | Responding to enquiries | Legitimate interests (art. 6(1)(f)) |
| Booking details (party size, dates) | Fulfilling hike bookings | Contract (art. 6(1)(b)) |
| Telegram chat ID | Bot notifications (opt-in only) | Consent (art. 6(1)(a)) |
| Equipment rental data | Fulfilling rental reservations | Contract (art. 6(1)(b)) |
Important: We do not sell, rent, or share your personal data with third parties for marketing purposes. We only share data with service providers needed to run the service (email delivery, payment processing).
Resend (email): We use Resend to send transactional emails. Your email address is only used to communicate with you about bookings and enquiries.
Stripe (payments): Payment processing is handled entirely by Stripe. We never see or store your card details.
Telegram: If you choose to receive notifications via our Telegram bot, your Telegram chat ID is stored. You can revoke this at any time by contacting us.
Render (hosting): Our hosting provider processes data on our behalf under a strict data processing agreement.
- User accounts: Retained until you delete your account, or 2 years of inactivity.
- Contact messages: Deleted after 12 months.
- Booking records: Retained for 7 years for tax and accounting purposes (legal obligation).
- Telegram chat IDs: Deleted on request or account deletion.
- Equipment bookings: Retained for 7 years for accounting purposes.
You have the following rights. To exercise any of them, contact us at enquiries@badradventures.co.uk.
- Right of access (art. 15): Request a copy of all personal data we hold about you.
- Right to rectification (art. 16): Correct any inaccurate or incomplete data.
- Right to erasure (art. 17): Request deletion of your account and associated data (subject to legal retention obligations for financial records).
- Right to restrict processing (art. 18): Request that we limit how we use your data.
- Right to data portability (art. 20): Receive your data in a machine-readable format (JSON).
- Right to object (art. 21): Object to processing based on legitimate interests.
- Right to lodge a complaint: You have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk if you are unsatisfied with how we handle your data.
We use minimal cookies, only what's strictly necessary to run the site:
- Session cookie: Keeps you signed in. HttpOnly, secure, SameSite=Strict. Expires when you close your browser.
- No marketing or analytics cookies — we do not use any tracking or advertising cookies.
For full details, see our Cookie Policy.
We use the following data processors. Each has been vetted and operates under a data processing agreement compliant with Article 28 of UK GDPR:
| Processor | Purpose | Data processed |
|---|---|---|
| Supabase (US) | Database & authentication | Account data, bookings, contact messages |
| Stripe (Ireland/US) | Payment processing | Payment amounts, customer email (no card details) |
| Resend (US) | Transactional email delivery | Email addresses, message content |
| Netlify (US) | Web hosting & CDN | IP addresses, request metadata (server logs) |
Your personal data may be transferred to and processed in countries outside the UK, including the United States and Ireland.
Where transfers occur, we ensure appropriate safeguards are in place:
- UK International Data Transfer Agreement (IDTA) — in place with Supabase, Stripe, Resend, and Netlify.
- Data Processing Agreements (Article 28) — signed with all processors.
- Stripe is certified under the UK-US Data Bridge, which the UK Government recognises as providing adequate protections.
If you would like a copy of the relevant safeguards, contact us at enquiries@badradventures.co.uk.
We take the security of your data seriously:
- All connections are encrypted via TLS (HTTPS).
- Passwords are hashed using bcrypt before storage.
- API endpoints require authentication for personal data access.
- Database access is restricted to authorised services only.
- Server logs are retained for 30 days and then automatically deleted.
Breach notification procedure: In the unlikely event of a personal data breach, we will:
- Notify the ICO within 72 hours of becoming aware (where required under Article 33).
- Notify affected individuals without undue delay if the breach poses a high risk to their rights and freedoms.
- Document all breaches — including facts, effects, and remedial action — as required by Article 33(5).
Our services are intended for individuals aged 18 and over. Hikes may welcome participants as young as 11 when accompanied by a parent or guardian, but the person making the booking must be an adult.
We do not knowingly collect personal data from children under 18. If you believe a child has provided us with personal data without parental consent, please contact us immediately at enquiries@badradventures.co.uk so we can investigate and delete the data.
We are a small business and are not required by law to appoint a Data Protection Officer (DPO). However, all data protection matters are handled directly by the business owner, who is responsible for overseeing GDPR compliance.
For any data protection enquiries, contact: enquiries@badradventures.co.uk.
When you submit a message via our contact form, we record:
- Consent timestamp: The exact date and time you consented to us storing your message.
- Policy version: Which version of this privacy notice applied at the time (currently 2026-06).
This record is stored alongside your message and is never used for any purpose other than demonstrating lawful consent under Article 7(1) of UK GDPR. You can request a copy of this record at any time.
If we change how we use your data, we'll update this page and notify you by email (if you have an account) or via a notice on the website.
