Versi 1.0 · Terakhir diperbarui 25 Agustus 2026
Dokumen ini belum diterjemahkan ke bahasa Anda. Yang Anda baca adalah versi aslinya.
Privacy Policy
How Alpii Europe GmbH processes personal data on the triploc platform
1. Who is responsible
The controller for the processing described here is:
Alpii Europe GmbH
Franz-Joseph-Straße 11, 80801 Munich, Germany
Amtsgericht München, HRB 308896
Managing Directors: Winitiro Ramadhani, Michael Eheleben, Edho Amarendra Saptiono
Email: [email protected]
Data protection contact: Head of Legal & Compliance, Alpii Europe GmbH
2. Principles we work to
- We collect what a purpose requires and nothing beyond it.
- We say what the purpose is at the point of collection, not only here.
- We do not sell personal data, ever, to anyone.
- We do not use traveller or partner data for marketing that the person has not asked for.
- We delete on a schedule, not when someone remembers.
3. What we process, why, and on what basis
3.1 Booking an experience
| Data | Purpose | Legal basis | Retained |
|---|---|---|---|
| Name, email, phone, country, participant names and party size | Performing your booking; sending confirmation, meeting details and changes | Art. 6(1)(b) — performance of a contract | 8 years from the end of the calendar year of booking for booking receipts and invoices (§ 147(3) AO, § 257(4) HGB, § 14b UStG, as shortened by the Fourth Bureaucracy Relief Act 2024); 10 years where the record forms part of the books or annual accounts |
| Payment reference, amount, currency, payment method type, last four digits | Taking payment, issuing refunds, reconciling, handling chargebacks | Art. 6(1)(b) and Art. 6(1)(c) — legal obligation | As above |
| Pick-up address where applicable | Performing the booking | Art. 6(1)(b) | Deleted 90 days after the experience |
| Booking history in your account | Letting you see and manage bookings | Art. 6(1)(b) | Until you delete your account, then the retention above applies to the booking records only |
We do not store your full card number. Card data is processed directly by our payment service providers (clause 5).
3.2 Participation requirements and health information
Some experiences require information about health, fitness, pregnancy, mobility, allergies or medical conditions — because the activity is physically demanding, because an operator must plan for it, or because the law requires it.
- Legal basis: Art. 9(2)(a) GDPR — your explicit consent. We ask for it separately and specifically, at the point of booking, for that booking.
- We pass only what the operator needs to perform the experience safely.
- Deleted 30 days after the experience. Not retained in your profile, not used for anything else.
- You can refuse. If the information is genuinely necessary for safety, we will tell you honestly that we cannot confirm the booking, and refund you in full.
3.3 Your account
| Data | Purpose | Legal basis | Retained |
|---|---|---|---|
| Email, password (hashed), name, preferences, language | Operating your account | Art. 6(1)(b) | Until you delete the account |
| Login timestamps, IP at login, device | Account security, fraud prevention | Art. 6(1)(f) — our legitimate interest in securing accounts | 12 months |
3.4 Customer support
Correspondence, call notes, complaint files and refund requests, including any evidence you send in support of an emergency refund request. Basis: Art. 6(1)(b) where it concerns your booking, otherwise Art. 6(1)(f). Retained 3 years from the end of the year in which the matter is closed, aligned to the statutory limitation period. Medical certificates submitted for refund requests are deleted 90 days after the decision.
3.4a Affiliate and promotional codes
Where you use a discount code, we record the code, the booking it was applied to, the discount, and the affiliate it is attributed to. Basis: Art. 6(1)(b) — applying the discount you asked for — and Art. 6(1)(f) for paying the affiliate their commission. The affiliate is shown that a booking was made against their code and the commission due. The affiliate is not shown your name, contact details or booking details. Retained for the statutory accounting period applicable to the commission record.
3.5 Reviews
Your review, rating, first name, first letter of your surname, country, and the experience booked. Published on the platform. Basis: Art. 6(1)(b) and Art. 6(1)(f) — our and other travellers' interest in verified reviews. Retained while published; you may withdraw a review at any time.
3.6 Partners and their personnel
| Data | Purpose | Legal basis | Retained |
|---|---|---|---|
| Contact details, business address, register number | Contracting and operating the relationship | Art. 6(1)(b) | Duration of the relationship + 10 years for accounting records |
| Identity document copy | Verifying whom we contract with and pay | Art. 6(1)(c) / Art. 6(1)(f) | 6 months after the relationship ends |
| Licence, permit, insurance certificate | Verifying the right to operate | Art. 6(1)(c) / Art. 6(1)(f) | Duration + 3 years |
| Bank account and holder name | Payouts, mandatory payee name verification | Art. 6(1)(b) / Art. 6(1)(c) | Duration + statutory accounting period |
| Tax number, VAT ID, date of birth | Tax reporting where an obligation applies | Art. 6(1)(c) | As the relevant tax law requires |
3.7 Website and app use
| Data | Purpose | Legal basis |
|---|---|---|
| Server log data: IP address, date and time, page requested, referrer, browser and OS | Delivering the site, security, fault diagnosis | Art. 6(1)(f) — legitimate interest in a secure, working service. Retained 7 days, then deleted or anonymised |
| Strictly necessary cookies: session, security, load balancing, cookie choice | Making the site work | Art. 6(1)(f); no consent required under § 25(2) TDDDG |
| Analytics, advertising and personalisation cookies and similar technologies | Understanding use, measuring campaigns | Consent only — Art. 6(1)(a) and § 25(1) TDDDG |
Nothing that is not strictly necessary is set before you consent. Consent is asked through our cookie banner, refusing is as easy as accepting, and you can change your choice at any time through the Cookie Settings link in the footer of every page.
3.8 Marketing
We send marketing email only where you have subscribed (Art. 6(1)(a)), or, for existing customers, on the narrow basis permitted by § 7(3) UWG for our own similar services, with an opt-out in every message and at the point of collection. Every message carries a one-click unsubscribe. Unsubscribing is immediate and does not affect your bookings.
3.9 Fraud prevention and legal claims
Booking patterns, payment anomalies and chargeback records, on Art. 6(1)(f). Retained 3 years. No automated decision producing legal effects on you is made under Article 22 GDPR. Where a booking is flagged, a person decides.
4. Where the data comes from
Almost all of it comes from you. We also receive booking outcome data from our partners (attendance, no-show, incident reports) and payment outcome data from our payment providers.
5. Who we share it with
We share personal data only where it is needed for a purpose stated above.
| Recipient category | Examples | Role |
|---|---|---|
| Local operators performing your experience | The guide, school or operator named on the experience page | Independent controller. Receives name, party size, contact details, pick-up point, and any participation requirements you have declared. Bound by contract to use it only to perform your booking, never for their own marketing, and to delete it — health information within 30 days of the experience, everything else within 90 days, except where their own tax or limitation law requires longer |
| Payment service provider | Stripe Payments Europe, Ltd. | Independent controller for payment processing |
| Hosting and infrastructure | Cloudflare, Inc. (object storage and CDN), and our cloud hosting provider in the EEA | Processor |
| Email and messaging | Resend | Processor |
| Analytics | Our analytics provider — set only where you have consented | Processor |
| Customer support tooling | Our support desk provider | Processor |
| Software development and technical support | PT Alpii Global Hub, Indonesia | Processor |
| Professional advisers, auditors, insurers | Controllers or processors as applicable | |
| Authorities | Tax authorities, courts, law enforcement | Where legally required |
Every processor is engaged under a data processing agreement meeting Article 28 GDPR.
6. Transfers outside the EEA
Personal data is stored in the EEA.
Some recipients are outside the EEA:
- Switzerland — covered by an EU adequacy decision. No additional safeguard needed.
- United Kingdom — covered by an adequacy decision.
- Indonesia — not covered by an adequacy decision. Transfers to, or access from, Indonesia are made under the European Commission's Standard Contractual Clauses together with a transfer impact assessment and supplementary technical measures.
- Partners outside the EEA performing an experience receive only what clause 5 lists, under appropriate safeguards.
You may request a copy of the safeguards in place at [email protected].
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy (Art. 15);
- rectification of inaccurate data (Art. 16);
- erasure, where the conditions are met (Art. 17);
- restriction of processing (Art. 18);
- data portability for data you provided, in a machine-readable format (Art. 20);
- object to processing based on legitimate interest, on grounds relating to your situation (Art. 21) — and an unconditional right to object to direct marketing at any time;
- withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (Art. 7(3)).
Write to [email protected]. We answer within one month. No charge. We may ask you to confirm your identity where we cannot otherwise be confident.
Where we cannot comply — usually because a retention period is set by tax law — we will tell you which obligation prevents it, rather than declining without explanation.
8. Complaints
You may complain to a supervisory authority, in particular in the Member State of your residence or workplace. Ours is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
www.lda.bayern.de
Complaining to us first is welcome but not required.
9. Is providing data mandatory?
Providing the data needed to make a booking is necessary for the contract; without it we cannot confirm the booking. Everything else — marketing, optional profile details, non-essential cookies — is voluntary and refusing has no consequence for your booking.
10. Children
The Platform is not directed at children and we do not knowingly collect data from a person under 16 through their own account. Children participate in experiences through a booking made by a responsible adult, who provides their details.
11. Security
We use encryption in transit and at rest, access control on a need-to-know basis, access logging for identity documents, and regular review of who holds which permission. No system is perfectly secure; we will notify you and the supervisory authority where a breach is likely to result in a risk to your rights, within the deadlines Articles 33 and 34 set.
12. Changes
We will publish any change here with a new version number and date, and notify registered users of a material change by email before it takes effect.
Switzerland — additional information
Where Swiss law applies, the Swiss Federal Act on Data Protection (revDSG) applies alongside this policy. Your rights are broadly equivalent. The Swiss supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern. Our Swiss group company is Alpii Switzerland GmbH, Jupiterstrasse 3, 3015 Bern (CHE-489.859.612).