Data controller
Sunshine Adventures Inc. determines the purposes and the means of the processing described in this policy. It acts as data controller within the meaning of the Swiss Federal Act on Data Protection (FADP) and, where it applies, of the EU General Data Protection Regulation (GDPR).
Swiss office: Route de Ferney 198B, 1218 Le Grand-Saconnex, Geneva, SwitzerlandRegistered office: 8 The Green, Dover, DE 19901, United States
Privacy email: contact@sunshine-adventures.net
Data we process
Depending on your relationship with Sunshine Adventures, we may process:
- your first name, last name, email address, telephone number and postal address;
- information relating to your project: destination, dates, budget, number and identity of the travelers, preferences, occasion, accessibility needs and free-text message;
- the data required for bookings and formalities: date of birth, nationality, travel document references and any relevant information you provide;
- correspondence, contracts, invoices, payments and the history of the client relationship;
- technical connection data: IP address, browser type, device, timestamp, URL visited and security logs.
We ask that you provide sensitive data, in particular medical data, only where it is strictly necessary for the safety or the accessibility of the trip. When you provide another traveler’s data, you confirm that you are authorized to do so and that you have informed that person of this policy.
Purposes and legal bases for processing
- responding to a request, preparing an itinerary and drawing up an offer: pre-contractual measures requested by the traveler;
- booking and carrying out the trip, providing the concierge service and handling complaints: performance of the contract;
- keeping accounts, complying with tax obligations and responding to the authorities: legal obligation;
- securing the website, preventing abuse and improving the quality of the service: legitimate interest of Sunshine Adventures and of its users;
- sending promotional communications or enabling non-essential tools: only with your consent where it is required.
Sunshine Adventures neither sells nor rents personal data and takes no decision producing legal effects solely on the basis of automated processing.
Recipients and processors
The data is accessible, within the limits of their respective duties, to the following recipients:
- authorized personnel of Sunshine Adventures;
- accommodation providers, carriers, guides, local ground operators, insurers and other service providers required to prepare or carry out the trip;
- Vercel Inc., for hosting, delivering and securing the website;
- Plus Five Five, Inc. (Resend), for the routing of forms and emails, which involves processing the address, the metadata and the content of the message;
- Bleeze, for occasional technical work, solely on instruction and where access is necessary;
- professional advisers and authorities where the law requires it.
The technical service providers act in accordance with their contractual commitments and their own security obligations. See the policies of Vercel and Resend.
International transfers
Sunshine Adventures is incorporated in the United States and works with service providers in the destinations visited. Some data may therefore be processed in the United States or in a country whose level of protection differs from that of Switzerland or of the European Economic Area.
Where the law requires it, these transfers rely on an adequacy decision, on recognized contractual clauses, on appropriate contractual and technical safeguards, or on a statutory exception relating to the conclusion or the performance of the requested trip. Only the data that is necessary is passed on to travel partners.
Retention periods
- request without a booking: up to 24 months after the last exchange, unless you object or a pre-contractual need persists;
- travel file: for the duration of the performance of the contract, then for as long as necessary to handle complaints and to defend legal claims;
- contracts, invoices and accounting records: 10 years, subject to any different statutory period;
- identity documents and sensitive data: deleted or anonymized as soon as they are no longer necessary for the bookings, unless the law requires otherwise;
- technical logs: for as long as necessary for security, diagnostics and the prevention of abuse, according to the host’s configuration.
Embedded video and audio players
The Radio Sunshine and Travel films pages give access to content hosted by third parties: the podcast episodes by Spotify AB, the films by YouTube (Google Ireland Limited).
These players are not loaded when the page opens. Until you start listening or watching, no request is made to those services and no data is sent to them: the thumbnails you see are served from our own servers.
When you start playback, the player loads from the host’s servers, which then receive your IP address, information about your browser and the address of the page, and may store cookies or identifiers on your device. The films are served through youtube-nocookie.com, a mode that restricts such storage. This loading follows from your action alone: not starting playback is enough to prevent it. See the privacy policies of Spotify and Google.
Security and confidentiality
Sunshine Adventures implements organizational and technical measures proportionate to the risks: access control, limitation of recipients, encryption of communications, backups and the selection of service providers offering appropriate safeguards. As no system can be absolutely invulnerable, incidents are handled and notified in accordance with applicable law where they create a risk for the individuals concerned.
Your rights
Depending on the applicable legislation, you may request access to your data, its rectification, its erasure, the restriction of its processing, its delivery in a portable format, or you may object to certain uses. You may withdraw your consent at any time, without affecting processing already lawfully carried out.
Send your request to contact@sunshine-adventures.net. Proof of identity may be requested where this is necessary to protect your data. You may also refer the matter to the Federal Data Protection and Information Commissioner (FDPIC) or, if the GDPR applies, to the competent supervisory authority in your country.
Data relating to minors
The website is not aimed directly at minors. The data required for a minor’s trip must be provided by their legal representative or with that representative’s authorization. We may request the supporting documents required for travel formalities and for the protection of the child.
Updates and questions
This policy may change in order to reflect a modification of the website, of the service providers or of the applicable law. The date shown at the top of the page indicates the version in force. Any material change will be communicated by appropriate means.
For any question relating to this policy, write to contact@sunshine-adventures.net or consult our legal notice.