The short version
- We collect what you give us (form fields, email signups) and a small amount of technical data (IP, browser) to keep the service running.
- Booking enquiries are forwarded to the named operator. They become a separate data controller after that.
- Payments are handled by Stripe — we never see card details.
- We don’t sell your data, we don’t use ad-tech, and we don’t track you across the web.
- You have rights: access, correction, deletion, portability, complaint to the ICO. Email privacy@explorelycia.com to use them.
Contents
1. Who’s the data controller
The data controller for personal data collected through this service is Pixelo Mobile Ltd, a company registered in England and Wales (company number 10585806), registered office Demsa Accounts, 565 Green Lanes, Haringey, London, England, N8 0RL.
For data-protection enquiries: privacy@explorelycia.com.
We are not currently required to appoint a Data Protection Officer (DPO) under UK GDPR Article 37. Our ICO registration number is [INSERT once registered].
2. Sites this covers
This policy applies to:
- explorelycia.com — the main directory site, operator signup, operator dashboard, and the four legal documents
- oludenizairgames.co.uk — our independent travel-guide satellite for the Oludeniz Air Games and Babadag paragliding
- api.oludenizairgames.co.uk — our backend API serving both sites
It does not cover third-party sites you reach by clicking a link from us — including operator websites, Stripe, our payment processor, or partner platforms. Each of those has its own privacy policy.
3. What data we collect
3.1 Data you give us directly
3.2 Data we collect automatically
- Server logs: IP address, requested URL, user agent, referrer, timestamp. Used for security, abuse triage, and basic analytics. Held 90 days.
- Functional storage: when you sign in, an auth token and a cached copy of your account profile; for everyone, a few convenience values such as saved trips and in-progress trip-planner selections (all browser localStorage). Not cookies. Cleared by you any time.
- Form submission audit: for booking enquiries we record the submitter’s IP and user-agent string at submit time, for spam triage.
3.3 Data we don’t collect
We do not collect:
- Card details (Stripe handles these; we never see them)
- Passport numbers, ID numbers, or other government identifiers
- Health information beyond what you choose to put in a free-text note (e.g. mentioning a height/weight to an operator)
- Browsing data on other sites — we don’t use cross-site tracking pixels, ad networks, or fingerprinting
4. Why we use it (lawful bases under UK GDPR Art. 6)
- To forward your booking enquiry to the named operator. Lawful basis: legitimate interest (operating a directory matching travellers with operators) plus your consent at the point of submitting.
- To provide the operator dashboard and process subscription payments. Lawful basis: contract performance.
- To send the newsletter (only if you opted in). Lawful basis: consent. You can withdraw at any time via the unsubscribe link.
- To respond to your emails. Lawful basis: legitimate interest.
- To detect and prevent abuse (spam, fraud, scraping, attacks). Lawful basis: legitimate interest in maintaining the security and integrity of the service.
- To comply with legal obligations (accounting records, lawful information requests). Lawful basis: legal obligation.
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects on you.
6. International transfers
The UK is the home base for this service. However, personal data flows internationally in two main scenarios:
- To Turkey, when we forward booking enquiries to Turkish operators. Turkey has not been granted UK adequacy status under UK GDPR Article 45. Transfers rely on (a) your explicit consent at the point of submitting the enquiry, in the knowledge that the operator is in Turkey, and (b) the operator’s contractual obligation under our Operator Listing Terms to handle your data lawfully.
- To the EU and US, where some of our processors are based (Stripe in Ireland, possibly email/CDN services in the US). These transfers are covered by UK Standard Contractual Clauses (SCCs) and, where applicable, the UK Extension to the EU-US Data Privacy Framework.
You can ask us at any time which countries your specific data has been transferred to.
8. How long we keep your data
9. How we protect your data
- Transport encryption: all traffic to our sites and API is over HTTPS (TLS 1.2+) with HSTS preloaded
- Auth: operator dashboard uses short-lived JWTs (15-minute access tokens); magic-link login tokens are single-purpose and expire after 15 minutes
- Payment isolation: Stripe handles all card data inside their PCI-DSS certified environment; we never see it
- Backend access: production database access is restricted to operations staff via SSH key + IP allowlist; no direct customer access
- Backups: encrypted at rest; rotated; kept for [INSERT] days
- Monitoring: we monitor for suspicious patterns (rate limits on booking submit and operator-auth-request endpoints)
No system is perfectly secure. If we discover a breach affecting your personal data, we’ll notify the ICO within 72 hours where required by UK GDPR Art. 33, and notify you directly if it’s likely to result in a high risk to your rights and freedoms.
10. Your rights under UK GDPR
You have the following rights in respect of your personal data:
- Access (Art. 15) — ask for a copy of what we hold about you
- Rectification (Art. 16) — correct inaccurate data
- Erasure (Art. 17) — ask us to delete your data, subject to lawful exceptions
- Restriction (Art. 18) — ask us to pause processing while a dispute is resolved
- Portability (Art. 20) — receive a machine-readable copy of data you gave us
- Objection (Art. 21) — object to processing based on legitimate interest, including direct marketing
- Withdraw consent — for processing based on consent, withdraw it at any time (won’t affect lawfulness of past processing)
- Complain to the ICO — the UK’s data-protection regulator at ico.org.uk/make-a-complaint or 0303 123 1113
How to use a right: email privacy@explorelycia.com from the email address on file (or include enough information to verify your identity). We respond within 30 calendar days. There’s no fee in normal cases; for manifestly unfounded or excessive requests we may charge a reasonable admin fee or refuse, in line with UK GDPR Art. 12(5).
11. Children
The directory and booking-enquiry service are aimed at adult travellers and adult business owners. We don’t knowingly collect personal data from children under 16. If you believe a child has submitted personal data through us, email privacy@explorelycia.com and we’ll delete it.
Adults may, of course, submit booking enquiries on behalf of family members including children — in which case the adult is responsible for the information they provide.
12. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent change. Material changes (e.g. a new processor, a new lawful basis, a new data category) will be flagged with a banner on the home page for at least 14 days before they take effect. We’ll also email registered operators directly about material changes that affect their account.
Old versions are archived for 12 months — available on request from privacy@explorelycia.com.
13. Contact & complaints
For any privacy-related question, request, or concern:
- Primary contact: privacy@explorelycia.com
- General support: hello@explorelycia.com
- Postal: Demsa Accounts, 565 Green Lanes, Haringey, London, England, N8 0RL
If you’re not satisfied with our response, you can complain to the UK Information Commissioner’s Office:
- Online: ico.org.uk/make-a-complaint
- Phone: 0303 123 1113
- Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, SK9 5AF