PRIVACY NOTICE · UPDATED 2 OCTOBER 2026
Your privacy matters.
How A&S Expeditions handles enquiries, adventure requests and personal information.
1. Who to contact
A&S Expeditions operates asexpeditions.com. For questions about personal information or to exercise your privacy rights, email info@asexpeditions.com. A&S Expeditions is responsible for the enquiry and booking information described in this notice.
2. Information you provide
When you contact us, we receive the details you submit, such as your name, email address, optional phone number, subject and message. Private-adventure enquiries can also include your preferred activity, region, dates, group size and experience.
When event requests are available, we receive the group contact’s details, requested adventure, number of places, optional message and booking status. We may later request the participant information needed to organise the activity. You do not need a participant account, and this website does not collect online card payments.
If you enquire on behalf of others, share only information you are authorised to provide and make this notice available to them. Please do not include passport details, payment-card details or medical records in ordinary forms or messages.
3. Technical and communication information
Operating the website and delivering email involves technical information such as IP addresses, request times, browser or device information, delivery records and security logs. We use relevant records to maintain the service, diagnose faults and address misuse.
Enquiries are stored in WordPress through Fluent Forms. Event requests are managed through Events Manager. Email notifications create additional copies in our Hostinger mailbox and our designated Gmail notification inbox. FluentSMTP also records email activity for troubleshooting; its current log-retention setting is 14 days.
4. Why we use information
We use enquiry and booking details to reply, assess an adventure request, discuss suitability, organise the agreed service and communicate changes. Where you are the prospective or actual customer, this is processing needed to take steps at your request or perform our contract.
Routine business correspondence, security, handling complaints and protecting legal claims may rely on legitimate interests. Those interests are running and protecting our service and resolving issues, balanced against the rights of the people concerned. Accounting or other records required by applicable law are processed to meet legal obligations.
Optional promotional communications or marketing use of identifiable photographs require a separate lawful basis and, where required, your specific consent. Sending an enquiry or acknowledging this notice does not subscribe you to marketing. You can withdraw consent without affecting processing already lawfully carried out.
5. Information relevant to safe participation
If information about health or other sensitive circumstances is necessary for planning an activity, we will explain what is needed, who needs it and how to provide it privately. We will establish the required legal basis and any additional condition for sensitive information, such as explicit consent where appropriate. A general form acknowledgement is not consent to unrestricted health-data processing.
In an emergency, necessary information may be shared with rescue or medical services where legally justified. We do not need a general medical history to answer an ordinary enquiry.
6. Who receives information
Access is limited to people who need information to respond, organise the activity or administer the business. Hostinger provides website hosting and mailbox services, and Google provides the Gmail inbox receiving notification copies. WordPress, Fluent Forms, Events Manager and FluentSMTP are the software used for the website workflow; installing a plugin does not by itself mean its developer receives every submission.
Where a professional guide or partner company helps deliver an adventure, we share only the participant and logistical information needed for that role. We will identify the relevant provider and explain any separate privacy notice where that provider handles information independently. Information may also be disclosed to professional advisers, insurers, authorities or emergency services where necessary and lawfully justified.
We do not sell enquiry or participant information.
7. International processing
Our hosting and email providers operate internationally. Information may be processed outside the European Economic Area, including in the United States. Operating trips in Norway or Austria does not mean every website or email record is stored there.
Hostinger publishes information about its processing and transfer safeguards, including standard contractual clauses where applicable, in its Data Processing Addendum. Google describes its use of adequacy decisions, the EU–US Data Privacy Framework and standard contractual clauses, as applicable, in its data transfer information. The applicable arrangement depends on the relevant service and transfer. Contact us for further information or to request details of safeguards relevant to your information.
8. How long we keep information
We retain information for as long as it is needed to answer your enquiry, organise and administer the activity, meet applicable record-keeping obligations or deal with a complaint or legal claim. Relevant criteria include whether your enquiry is still active, whether the trip has taken place, outstanding payments or disputes, and applicable accounting requirements and limitation periods.
Retention reviews cover WordPress entries and notification copies in Hostinger and Gmail. Information no longer needed should be deleted or anonymised. A restricted backup copy may remain until overwritten under the provider’s backup cycle. FluentSMTP email troubleshooting logs use a separate 14-day retention setting. You can contact us to request deletion; we will explain if information needs to be retained for a specific lawful purpose.
9. Cookies, links and third-party content
WordPress and supporting services may use functional cookies or similar storage for login sessions, security and other necessary features. You can manage cookies through your browser, although blocking necessary storage may affect functionality.
The website also loads a Hostinger Reach integration resource. Loading an external resource can disclose technical request information, such as an IP address and browser details, to its provider. Sending an enquiry does not subscribe you to a mailing list. If we introduce optional analytics, advertising or similar services that require consent, we will provide the relevant information and choice before enabling them.
Links to external websites take you to services with their own privacy practices. This notice covers our handling of information and does not replace their notices.
10. Your choices and rights
Depending on the circumstances and applicable law, you may request access, correction, deletion, restriction or a portable copy of your information, and you may object to processing based on legitimate interests. Where we rely on consent, you may withdraw it. These rights are not absolute; we will explain any relevant limitation.
Email info@asexpeditions.com. We may ask for proportionate information to verify your identity, but please do not send an identity document unless specifically requested through an appropriate channel. Where GDPR applies, we normally respond within one month and explain any permitted extension.
You may complain to a competent data-protection authority, including the authority in the country of your habitual residence, workplace or the alleged infringement. A list of EEA authorities is available from the European Data Protection Board. You do not have to contact us first.
11. Required fields and human review
Fields marked as required allow us to respond to the relevant request. If necessary details are missing, we may be unable to answer fully or arrange an adventure. Optional fields can be left blank. Booking requests are reviewed by people; this workflow does not use solely automated decisions with legal or similarly significant effects.
12. Security and updates
We use measures appropriate to the information and the service, including encrypted website connections and access-controlled administration. No website or email service can promise absolute security. Do not use ordinary email for unnecessary sensitive information.
We will update this notice when our practices change and communicate significant changes where appropriate. This notice was last updated on 2 October 2026.
