Skip to main content

PRIVACY POLICY

Note: This English translation is provided for convenience only. The German version is legally binding.

1. Data Protection at a Glance

General Information

The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data by which you can be personally identified. For detailed information on the subject of data protection, please refer to our privacy policy set out below this text. In addition, sections 6 to 11 inform you about how we process your data in connection with enquiries, bookings and the conduct of our expeditions.

Data Collection on This Website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. You can find the operator's contact details in the section “Information on the Controller” in this privacy policy.

How do we collect your data?

On the one hand, your data is collected when you provide it to us. This may, for example, be data you enter into a contact form.

Other data is collected automatically or with your consent by our IT systems when you visit the website. This is primarily technical data (e.g. internet browser, operating system, or time of the page view). This data is collected automatically as soon as you enter this website.

What do we use your data for?

The data is collected to ensure error-free provision of the website and to process your enquiries. We only evaluate how our website is used if you have agreed to this in the privacy banner (see “Reach Measurement (Consent Only)” and “Google Analytics 4 (Consent Only)”).

What rights do you have regarding your data?

You have the right at any time to obtain, free of charge, information about the origin, recipients, and purpose of your stored personal data. You also have the right to request the rectification or erasure of this data. If you have given consent to data processing, you can revoke this consent at any time with effect for the future. You also have the right, under certain circumstances, to request the restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.

You can contact us at any time regarding this and any other questions on the subject of data protection.

2. Hosting

We host the content of our website with an external provider.

External Hosting

This website is hosted externally. The personal data collected on this website is stored on the servers of the host(s). This may include, in particular, IP addresses, contact requests, meta and communication data, contract data, contact details, names, website accesses, and other data generated via a website.

External hosting is carried out for the purpose of fulfilling contracts with our potential and existing customers (Art. 6(1)(b) GDPR) and in the interest of a secure, fast, and efficient provision of our online offering by a professional provider (Art. 6(1)(f) GDPR). Where corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and § 25 Abs. 1 TDDDG, insofar as the consent covers the storage of cookies or access to information on the user's device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.

Our host(s) will process your data only to the extent necessary to fulfill their service obligations and will follow our instructions with regard to this data.

This website is delivered via our host's data centre in Frankfurt am Main. Where the provider accesses data from outside the European Union in individual cases, for example for support or maintenance, this is safeguarded by the EU-US Data Privacy Framework and the European Commission's standard contractual clauses. We will provide you with the name of the provider and a copy of the safeguards on request.

Server Log Files

With every request, our host necessarily processes your IP address, browser type and version, operating system, the requested address, the referring page (domain only) and the time in log files. The purpose is delivering the website and protecting it against attacks and disruptions; the data is not merged with other data. The legal basis is Art. 6(1)(f) GDPR. Our host retains these logs only briefly, after which they are deleted automatically.

Data Processing Agreement

We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract required by data protection law, which ensures that this provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

Database Hosting (Supabase)

The data submitted via the contact form and the newsletter sign-up is stored in a database hosted by Supabase. The provider is Supabase, Inc., 3500 S Dupont Hwy, Dover, DE 19901, USA (hereinafter “Supabase”).

The data is stored on servers within the European Union (Frankfurt am Main data centre). The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the secure and reliable storage of your enquiries) or Art. 6(1)(a) GDPR where consent has been obtained. A data processing agreement (DPA) is in place with Supabase. Where access from the USA cannot be ruled out in the course of support or maintenance, such transfers are based on the European Commission's standard contractual clauses.

Further information can be found in Supabase's privacy policy: https://supabase.com/privacy.

3. General Information and Mandatory Disclosures

Data Protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

When you use this website, various personal data is collected. Personal data is data by which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.

We would like to point out that data transmission over the internet (e.g. when communicating by email) may be subject to security vulnerabilities. Complete protection of data against access by third parties is not possible.

Information on the Controller

The controller responsible for data processing on this website is:

Global Pioneers

Milan Binder

Bischofsweg 28

01099 Dresden

info@globalpioneers.de

+4915225930279

The controller is the natural or legal person who, alone or jointly with others, decides on the purposes and means of the processing of personal data (e.g. names, email addresses, etc.).

Storage Period

Unless a more specific storage period has been stated within this privacy policy, your personal data will remain with us until the purpose for the data processing no longer applies. If you assert a legitimate request for erasure or revoke your consent to data processing, your data will be deleted unless we have other legally permissible grounds for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, the data will be deleted once these grounds no longer apply.

General Information on the Legal Bases for Data Processing on This Website

If you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR, insofar as special categories of data pursuant to Art. 9(1) GDPR are processed. In the case of explicit consent to the transfer of personal data to third countries, data processing is also carried out on the basis of Art. 49(1)(a) GDPR. If you have consented to the storage of cookies or to access to information on your device (e.g. via device fingerprinting), the data processing is additionally carried out on the basis of § 25 Abs. 1 TDDDG. Consent can be revoked at any time. If your data is required for the fulfillment of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. Furthermore, we process your data insofar as this is necessary for the fulfillment of a legal obligation, on the basis of Art. 6(1)(c) GDPR. Data processing may also be carried out on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR. Information on the legal bases relevant in each individual case is provided in the following paragraphs of this privacy policy.

Recipients of Personal Data

In the course of our business activities, we work together with various external parties. In some cases, a transfer of personal data to these external parties is also necessary. We only pass on personal data to external parties if this is necessary in the context of fulfilling a contract, if we are legally obliged to do so (e.g. passing on data to tax authorities), if we have a legitimate interest in the transfer pursuant to Art. 6(1)(f) GDPR, or if another legal basis permits the transfer of the data. When using processors, we only pass on our customers' personal data on the basis of a valid data processing agreement. In the case of joint processing, a joint processing agreement is concluded.

Revocation of Your Consent to Data Processing

Many data processing operations are only possible with your express consent. You can revoke consent you have already given at any time. The lawfulness of the data processing carried out until the revocation remains unaffected by the revocation.

Right to Object to Data Collection in Special Cases and to Direct Advertising (Art. 21 GDPR)

IF THE DATA PROCESSING IS CARRIED OUT ON THE BASIS OF ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENSE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21(1) GDPR).

IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF DIRECT ADVERTISING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH ADVERTISING; THIS ALSO APPLIES TO PROFILING INSOFAR AS IT IS RELATED TO SUCH DIRECT ADVERTISING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR THE PURPOSE OF DIRECT ADVERTISING (OBJECTION PURSUANT TO ART. 21(2) GDPR).

Right to Lodge a Complaint with the Competent Supervisory Authority

In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work, or the place of the alleged violation. The right to lodge a complaint exists without prejudice to any other administrative or judicial remedies. As the controller is based in Saxony, Germany, the competent authority for us is the Sächsische Datenschutz- und Transparenzbeauftragte (Saxon Data Protection and Transparency Commissioner), Maternistraße 17, 01067 Dresden, Germany (postal address: Postfach 11 01 32, 01330 Dresden, Germany), phone +49 351 85471-101, email post@sdtb.sachsen.de, https://www.datenschutz.sachsen.de. You may also contact the supervisory authority at your own place of residence or work.

Right to Data Portability

You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a commonly used, machine-readable format. If you request the direct transfer of the data to another controller, this will only take place insofar as it is technically feasible.

Information, Rectification, and Erasure

Within the framework of the applicable statutory provisions, you have the right at any time to obtain, free of charge, information about your stored personal data, its origin and recipients, and the purpose of the data processing and, where applicable, a right to rectification or erasure of this data. You can contact us at any time regarding this and any other questions on the subject of personal data.

Right to Restriction of Processing

You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this purpose. The right to restriction of processing exists in the following cases:

If you have restricted the processing of your personal data, this data may – apart from its storage – only be processed with your consent or for the establishment, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or a Member State.

SSL or TLS Encryption

For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line.

If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

4. Data Collection on This Website

Cookies and Local Storage

Without your consent, this website sets no cookies and does not integrate any advertising services. Only Google Analytics 4 sets cookies, and only if you have agreed to this in the privacy banner (see “Google Analytics 4 (Consent Only)”). Our own reach measurement likewise only runs with your consent and does not use cookies.

Without your consent, two entries are stored in your browser's local storage, both without any personal data and never transmitted to us or to third parties: first, your decision in the privacy banner, consisting of the version of the service list, the time and your choice per category — it serves solely to avoid asking you again on every visit, and is valid for six months; if the list of services changes, we ask again. Second, if you close the newsletter window, a note that it should not appear again.

The legal basis for both entries is Section 25(2)(2) TDDDG, as this storage is strictly necessary to keep a decision you have already made. No consent is required for it. You can delete your local storage at any time via your browser settings; the banner will then ask again.

The fonts used on this website are also served locally from our own server. No connection to Google Fonts or any other external provider is established when the website is accessed. The Trustpilot rating shown on the homepage is fetched by our server itself once a day; no Trustpilot code runs in your browser.

Reach Measurement (Consent Only)

We would like to know how often each page is viewed. We only do so if you allow the “Statistics” category in the privacy banner. Without this consent, no counting script is loaded and no page view is reported; no cookies are set and no information is read from your device for this purpose.

With your consent, two counts run. First, our own: when a page is accessed, the path of the page (e.g. “/kontakt”), the time, the rough device type (mobile, tablet or desktop) and the referring site at domain level (e.g. “google.com”, without the full address) are stored in our database at Supabase (server location Frankfurt am Main). No IP address or browser identifiers are stored; the IP address is only checked briefly in our server's memory to prevent mass requests. These entries contain no personal reference. They are automatically deleted after 14 months at the latest.

Second, our marketing evaluation “GP-Automations” – a system of the controller's own, operated at our host and at Supabase Inc. (see section “Hosting”). A script from gp-automations-seven.vercel.app reports the page path, the referring site (domain only), the UTM parameters of the link you arrived through, and the rough device type. The recipient determines the country from your IP address and derives a check value (SHA-256) from IP address, browser identifier, date and a secret value, by which requests on the same day are counted as one visit. The IP address itself is not stored; the check value is useless the next day and cannot be reversed without the secret value. Processing takes place in Frankfurt am Main. Raw data is deleted after 90 days; daily totals without any personal reference are kept.

The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time with effect for the future via “Privacy settings” in the footer of every page, with immediate effect and without reloading. Our host and Supabase are US companies; processing takes place in Frankfurt am Main, and the safeguards named in the section “Hosting” (EU-US Data Privacy Framework, standard contractual clauses) apply in addition.

Google Analytics 4 (Consent Only)

If you allow the “Statistics” category in the privacy banner, we additionally use Google Analytics 4. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics sets the cookies “_ga” and “_ga_VGK3KDC0GD” on your device, each of which, according to Google, is stored for up to two years, and records how you use our website, for example the pages viewed, time spent, where your visit came from, your approximate location, and your device and browser. The cookies contain a randomly generated identifier (client ID) by which Google recognises your browser on later visits; Google does not receive your name or any other information that directly identifies you. Under this client ID, Google combines your visits into a pseudonymous usage profile. When the script is loaded, your IP address is transmitted to Google. According to Google, it uses the IP address only to determine your approximate location and does not store it in Google Analytics 4. From this, Google prepares evaluations of the use of our website for us. We have deactivated Google Signals and the sharing of data with other Google services.

The legal basis is your consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG). You can withdraw it at any time with effect for the future via “Privacy settings” in the footer of every page.

We have concluded a data processing agreement with Google; it is based on Google’s data processing terms (Google Ads Data Processing Terms, https://business.safety.google/adsprocessorterms/). A transfer to Google LLC in the USA cannot be ruled out. Google LLC is certified under the EU-US Data Privacy Framework; the European Commission's standard contractual clauses apply in addition.

User-level event data collected by Google Analytics is automatically deleted after 2 months. Aggregated statistics that do not relate to individuals are retained.

Protecting Our Forms Against Abuse

To prevent automated abuse of our contact form and newsletter sign-up, we limit how often each connection may submit them (five submissions within ten minutes, twenty within 24 hours). Your IP address is not stored for this rate limit: it is immediately converted on our server into an irreversible check value (HMAC-SHA256 using a secret key), and only that check value is stored, together with which form was used and the time of submission. For the rate limit, the database never receives the IP address itself. These entries are deleted after 24 hours at the latest. The newsletter sign-up is different: there we additionally store your IP address in plain text as proof of your consent — see the section “Newsletter data”.

The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in protecting our forms against automated abuse. No cookies are set and no information is stored on or read from your device for this purpose.

Whatsapp

For communication with our customers and other third parties, we use, among other things, the instant messaging service WhatsApp. The provider is WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

Communication takes place via end-to-end encryption (peer-to-peer), which prevents WhatsApp or other third parties from gaining access to the communication content. However, WhatsApp does gain access to metadata created in the course of the communication process (e.g. sender, recipient, and time). We would also like to point out that, according to its own statements, WhatsApp shares personal data of its users with its parent company Meta, which is based in the USA. Further details on data processing can be found in WhatsApp's privacy policy at: https://www.whatsapp.com/legal/#privacy-policy.

WhatsApp is used on the basis of our legitimate interest in communicating as quickly and effectively as possible with customers, prospective customers, and other business and contractual partners (Art. 6(1)(f) GDPR). Where corresponding consent has been requested, the data processing is carried out exclusively on the basis of this consent; it can be revoked at any time with effect for the future.

The communication content exchanged between you and us on WhatsApp remains with us until you request us to delete it, revoke your consent to storage, or the purpose for the data storage no longer applies (e.g. after your inquiry has been fully processed). Mandatory statutory provisions – in particular retention periods – remain unaffected.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt00000011sfnAAA&status=Active

We use WhatsApp in the “WhatsApp Business” variant.

If you use WhatsApp, we will usually contact you via WhatsApp before and during your expedition. If you do not use WhatsApp or do not wish to be contacted that way, we will reach you by email.

Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.whatsapp.com/legal/business-data-transfer-addendum.

Contact Form

If you send us inquiries via the contact form, your details from the inquiry form, including the contact data you provide there, will be stored by us for the purpose of processing the inquiry and in the event of follow-up questions. We do not pass on this data without your consent.

This data is processed on the basis of Art. 6(1)(b) GDPR if your inquiry is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of the inquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if this has been requested; consent can be revoked at any time.

The data you enter in the contact form remains with us until you request us to delete it, revoke your consent to storage, or the purpose for the data storage no longer applies (e.g. after your inquiry has been fully processed). Mandatory statutory provisions – in particular retention periods – remain unaffected.

The data submitted via the contact form – your name, your email address and the content of your message – is stored in our database at Supabase (see the section “Database Hosting (Supabase)”). It is not passed on to any other third parties. Regardless of any deletion request, this data is automatically deleted after 12 months at the latest, unless a longer statutory retention obligation applies.

Inquiry by Email, Telephone, or Fax

If you contact us by email, telephone, or fax, your inquiry, including all personal data resulting from it (name, inquiry), will be stored and processed by us for the purpose of handling your request. We do not pass on this data without your consent.

The data you send to us via contact inquiries remains with us until you request us to delete it, revoke your consent to storage, or the purpose for the data storage no longer applies (e.g. after your request has been fully processed). Mandatory statutory provisions – in particular statutory retention periods – remain unaffected.

Our email mailboxes are operated by the provider one.com on servers within the European Union. A data processing agreement (DPA) is in place with the provider.

5. Newsletter

Newsletter Data

If you would like to receive the newsletter offered on the website, we require an email address from you as well as information that allows us to verify that you are the owner of the email address provided and that you agree to receive the newsletter. Further data is not collected, or is collected only on a voluntary basis. We use this data exclusively for sending the requested information and do not pass it on to third parties.

The data entered into the newsletter registration form is processed exclusively on the basis of your consent (Art. 6(1)(a) GDPR). You can revoke the consent you have given to the storage of the data, the email address, and its use for sending the newsletter at any time, for example via the “unsubscribe” link in the newsletter. The lawfulness of the data processing operations already carried out remains unaffected by the revocation.

The data you provide to us for the purpose of receiving the newsletter is stored by us until you unsubscribe from the newsletter and is deleted from the newsletter distribution list after you unsubscribe from the newsletter or after the purpose no longer applies. We reserve the right to delete or block email addresses from our newsletter distribution list at our own discretion within the scope of our legitimate interest pursuant to Art. 6(1)(f) GDPR.

Data stored by us for other purposes remains unaffected by this.

After you unsubscribe from the newsletter distribution list, your email address may be stored by us in a blacklist, insofar as this is necessary to prevent future mailings. The data from the blacklist is used only for this purpose and is not merged with other data. This serves both your interest and our interest in complying with the statutory requirements when sending newsletters (legitimate interest within the meaning of Art. 6(1)(f) GDPR). Storage in the blacklist is not limited in time. You can object to the storage if your interests outweigh our legitimate interest.

Registration takes place via a form on this website — as a pop-up, on the expedition and blog pages, and on the “Newsletter” page. We store your name, your email address, the time of registration, the time of your consent given via the mandatory field “I would like to receive the newsletter.”, the IP address used at that moment, and the information about which form and which page of this website the registration came from. We do not currently send a confirmation email (double opt-in); this record of your consent takes its place. The legal basis for storing the IP address and the timestamps is Art. 6(1)(f) GDPR — our legitimate interest lies in being able to demonstrate the consent given. Storage takes place in our database at Supabase (see the section “Database Hosting (Supabase)”). An external newsletter delivery service is not currently used. The IP address stored in plain text is automatically deleted 3 years after your consent at the latest; your subscription as well as your name and the time of consent remain unaffected and continue unchanged.

6. Enquiries via Our Application Process and Introductory Call

If you express interest in an expedition via our application process, we process the information you provide there. We use it to handle your enquiry, to arrange an introductory call with you and to clarify together with you whether the expedition is right for you. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures).

We store the information in our database at Supabase on servers within the European Union (see the section “Database Hosting (Supabase)”).

We hold the introductory call by video call. The provider of the video service processes the data required for the connection.

If no booking results, we delete your information no later than 12 months after our last contact.

7. Booking and Conduct of Your Expedition

Expedition Questionnaire

We accept your booking via the expedition questionnaire. We process the information you provide there in order to conclude the travel contract with you and to prepare and conduct the expedition. The legal basis is Art. 6(1)(b) GDPR. Without the information marked as mandatory, we cannot conclude the contract. We store the information in our database at Supabase on servers within the European Union. We retain invoices and booking records because we are legally obliged to do so (Art. 6(1)(c) GDPR in conjunction with Section 147 of the German Fiscal Code (AO) and Section 257 of the German Commercial Code (HGB)).

Health Information

In the questionnaire, we also ask for information about your health. We process this information only with your explicit consent (Art. 9(2)(a) GDPR), which you give separately in the questionnaire. We use the information exclusively to assess together with you whether the expedition is suitable for you and to be able to care for you properly in an emergency during the trip. Only the expedition leadership of your tour receives the information. If you are unable to give consent in an emergency, we pass on the necessary information to rescue services and treating doctors in order to protect your life and health (Art. 9(2)(c) GDPR). You can withdraw your consent at any time by email to info@globalpioneers.de. Without this information, however, participation in the expedition is not possible. We delete your health information no later than 30 days after the end of the expedition, unless an incident on the expedition still needs to be clarified.

Passport

For expeditions on which authorities, checkpoints, accommodation providers or transport companies require your passport data, we collect a copy of your passport. The legal basis is Art. 6(1)(b) GDPR. We keep the copy separately from our other records and delete or destroy it no later than 7 days after the end of the expedition.

Payments

You pay the travel price by bank transfer to our business account. To match incoming payments to your booking, we retrieve our account transactions via the account information service Enable Banking Oy, Finland. The legal basis is Art. 6(1)(b) and (c) GDPR.

Disclosure to Our Local Partners

To conduct the expedition, we work with partners in the destination country, such as accommodation providers, drivers, local guides and authorities. Each partner receives only the data it needs for its task:

Accommodation providers, transport companies and authorities process the data under their own responsibility in accordance with the law applicable to them. Data may remain stored there under their rules even after your expedition has ended.

Destination Countries Outside the European Union

Some of our expeditions lead to countries outside the European Union. For Canada and Argentina, the European Commission has determined an adequate level of data protection (Art. 45 GDPR). For Mauritania, Morocco, Iraq (Kurdistan Region) and Costa Rica, there is no such decision. The level of data protection there may be lower than in the European Union, and it may be more difficult for you to enforce your rights. We transfer your data to these countries only insofar as this is necessary for the performance of your travel contract (Art. 49(1)(b) GDPR), and health information only with your explicit consent or in an emergency (Art. 49(1)(a) and (f) GDPR).

Paper and Offline Records

During the trip, we carry a participant list and emergency sheets on paper or offline on a device, because there is often no internet connection in the expedition areas. These records are kept by the expedition leadership. We destroy all remaining copies no later than 7 days after the end of the expedition, unless an incident on the expedition still needs to be clarified.

Storage Period

We store your booking data until the limitation periods for claims arising from the travel contract have expired. In addition, we retain invoices and booking records for the duration of the statutory retention periods under commercial and tax law. The shorter periods stated above apply to health information, passport copies and paper records.

8. Emergencies and Emergency Devices

On some expeditions, we carry a satellite-based emergency device. If an emergency call is triggered, the device provider and an emergency response centre commissioned by it receive the location and the information required for the rescue. The emergency response centre may be located outside the European Union. The legal basis is the protection of your vital interests (Art. 6(1)(d), Art. 9(2)(c) and Art. 49(1)(f) GDPR).

9. Photos and Videos

We take photos and film on our expeditions. We only use recordings in which you can be recognised for our website, our social media channels, advertisements and printed material if you have given your separate and voluntary consent to this in the expedition questionnaire (Art. 6(1)(a) GDPR). Your consent has no effect on your booking. You can withdraw it at any time, in full or for individual purposes, by email to info@globalpioneers.de. After that, we will no longer use the recordings anew and will remove them from our own online channels within 30 days. We cannot retrieve materials that have already been printed or content that third parties have shared.

10. Our Presence on Social Networks

We maintain our own profiles on Instagram, Facebook and TikTok. When you visit these profiles, the operators of the networks process your data in accordance with their own privacy policies, including in the USA.

Instagram and Facebook are operated by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. We are joint controllers with Meta for the statistics on our pages (Insights) (Art. 26 GDPR). The corresponding agreement can be found at https://www.facebook.com/legal/terms/page_controller_addendum. You can assert your rights against both us and Meta.

TikTok is operated by TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland.

If you write to us via these networks, we process your message in order to respond to your enquiry. The legal basis is our legitimate interest in up-to-date communication (Art. 6(1)(f) GDPR), or Art. 6(1)(b) GDPR for enquiries relating to a booking.

11. Applications to Work With Us

If you apply via our “Jobs” page as a guide or for another role with us, we process the information and documents you send us in order to decide on your application (Art. 6(1)(b) GDPR). If no collaboration results, we delete your documents no later than six months after our rejection, so that we can defend ourselves against any claims. If you would like us to keep your application for future tours, we will ask for your consent beforehand.

Last updated: 7 October 2026

Source:
https://www.e-recht24.de