Privacy policy
The protection of your personal data is important to us. In this privacy policy, we inform you about which personal data is processed when you visit our website, contact us, and in connection with our offers and services, for what purposes this is done, and what rights you have.
Responsible
The entity responsible for data processing is:
Denis Schimmeyer / GC-Tours
Calle el Río, 4C
35216 Tenteniguada, Las Palmas
Spain
E-mail: gc-tours@proton.me
Phone: +34 664 202 674
The information provided so far in your privacy policy names the same responsible body and the same contact details.
Processing of personal data
Visit our website
When you access our website, technically necessary connection data is processed. This may include, in particular, the IP address of the device used, the date and time of access, the page or file accessed, referrer information, browser type and version, operating system used, and technical status information.
The processing is carried out to technically provide our website, to ensure secure and stable operation, and to be able to detect technical errors and abusive access.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the secure, reliable and functional operation of our website.
Technical log data is stored only as long as necessary for operation, security, or the investigation of specific malfunctions. Statutory retention obligations remain unaffected.
Contact
You can contact us via our contact form, by email, by telephone or via other communication channels we offer.
We process the personal data you provide solely for the purpose of processing your request and for further communication with you.
If your request relates to booking a tour or another service offered by us, the processing is carried out for the purpose of carrying out pre-contractual measures or fulfilling the contract on the basis of Art. 6 para. 1 lit. b GDPR.
For other inquiries, processing is based on Article 6(1)(f) GDPR. Our legitimate interest lies in being able to respond to inquiries addressed to us.
The data will be deleted as soon as your request has been fully processed and there are no contractual, legal or other legitimate reasons for further storage.
Contact form
You can use our contact form to send us the information required for your inquiry. This may include, in particular, your name, contact details, the desired period, the number of people, the pick-up location or your accommodation, and the content of your message.
Required fields are necessary if we cannot process your request effectively without them. Providing additional information is voluntary.
For booking-related inquiries, processing is based on Article 6 Paragraph 1 Letter b GDPR, and for other inquiries, processing is based on Article 6 Paragraph 1 Letter f GDPR.
The confirmation of the privacy policy provided in the contact form serves to inform you about the processing of your data before you submit your request.
The contact form currently in use is provided within your website; in the verified source code, the scripts required for this are loaded from your own domain.
Communication via email
When you contact us by email, we process your email address, the content of your message, and any other information you voluntarily provide.
For pre-contractual or contractual inquiries, processing is based on Article 6(1)(b) GDPR. For other business communication, processing is based on Article 6(1)(f) GDPR.
For our business email communication, we use an external email service provider based in Switzerland.
Insofar as this third party processes personal data on our behalf, the processing is carried out in accordance with the legal requirements for data processors. For Switzerland, there is an adequacy decision by the European Commission pursuant to Article 45 GDPR.
Contact by telephone
When you contact us by telephone, we process the information you provide during the conversation to the extent necessary to process your request.
For pre-contractual or contractual matters, the legal basis is Article 6(1)(b) GDPR. For other inquiries, processing is based on Article 6(1)(f) GDPR.
Communication via WhatsApp
You can contact us via WhatsApp if you wish.
In particular, your telephone number, your name used on WhatsApp, your messages and content you transmit may be processed.
For communication relating to bookings or contracts, processing is based on Article 6(1)(b) GDPR. For other inquiries, it is based on Article 6(1)(f) GDPR.
For users in the European Economic Area, WhatsApp is provided by WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland provided.
As part of WhatsApp's operation, personal data may also be processed outside the European Economic Area. Such transfers are subject to the data protection guarantees implemented by the provider.
Using WhatsApp is voluntary. Alternatively, you can contact us via contact form, email, or telephone.
Bookings and execution of our services
Booking and customer data
When you request or book a tour or other service with us, we process the personal data required for the preparation and execution of the service.
This may include, in particular, name, contact details, desired tour or service, date, number of people, pick-up location or accommodation, as well as other organizational information required for the specific execution.
The legal basis is Article 6(1)(b) GDPR.
Insofar as certain data or documents must be retained due to tax, commercial or other legal regulations, further processing is carried out on the basis of Art. 6 para. 1 lit. c GDPR.
Special personal needs
For individually planned excursions, it may be necessary or useful to consider the special needs of our guests, for example regarding mobility, accessibility or health-related support.
Please only share particularly sensitive information to the extent that it is necessary for the safe and appropriate planning or execution of the service you have requested.
Insofar as special categories of personal data within the meaning of Article 9 GDPR are processed, this will only be done to the extent necessary and on a legally permissible basis. Where explicit consent is required, it will be obtained separately.
We do not use such information for advertising, profiling or other purposes unrelated to the specific request.
External content and services
Customer reviews
On our website we display publicly published customer reviews and rating information.
This may include, in particular, the publicly used name or username, rating, rating text, publication date and, if applicable, a publicly used profile picture.
To display this content, connections may be established with external rating or technical service providers. For technical reasons, this may involve transmitting information such as the IP address of the device used, browser information, time of access, and the page visited to the respective provider.
The processing is based on Article 6(1)(f) GDPR. Our legitimate interest lies in transparently presenting the experiences of previous customers and enabling prospective customers to better assess our services.
The homepage currently being reviewed displays review content via Trustindex; this includes resources from Trustindex and profile pictures from Google servers.
Technically integrated external resources
Individual technical components of our website may be provided via external servers.
When such a resource is accessed, the IP address of the device used is transmitted to the respective server for technical reasons. In addition, standard technical connection information such as browser type, referrer, and time of access may be processed.
The processing is based on Article 6(1)(f) GDPR. Our legitimate interest lies in the technically reliable and functional operation of our website.
The homepage under review currently includes, among other things, a JavaScript resource about code.jquery.com loaded.
External links and social networks
Our website contains links to external websites and platforms, in particular Google Maps, Facebook, Instagram, YouTube, X, TikTok, Tripadvisor, HolidayCheck and WhatsApp.
With ordinary external links, the respective external service is not accessed simply by the link being displayed on our website.
Only when you click on such a link yourself will a connection to the respective external provider be established. From this point on, the further processing of personal data is the sole responsibility of the provider in question.
Our social media links are implemented as normal links in the verified source code.
Google Maps
Google Maps is not embedded as an interactive map on our publicly accessible website.
We only provide a link in the legal notice that allows you to open our location on Google Maps. A connection to Google Maps is therefore only established when you click on the link yourself.
fonts
The fonts used to display our website are provided by our own web server.
Loading these locally hosted fonts does not require a connection to Google Fonts' servers. The tested website loads the corresponding font files from its own upload directory.
Photo and video recordings
Photos taken during our excursions
We generally do not take identifiable photographs or videos of our guests for advertising or publication purposes without informing the individuals concerned beforehand.
If recognizable images of a person are to be used for our website, social media, advertising materials or other public purposes, we will obtain their consent beforehand.
The legal basis is Article 6 paragraph 1 letter a GDPR.
Consent can be withdrawn at any time with effect for the future. The lawfulness of the processing up to the point of withdrawal remains unaffected.
When recording minors, we also take into account the necessary consents of their legal guardians.
Your previous statement also required prior consent for such recordings.
Recipients and data transfers
Recipients of personal data
Personal data will only be disclosed to the extent necessary for the purposes stated in this privacy policy, where there is a legal obligation to do so, or where another legal basis permits disclosure.
Possible recipients or recipient categories include, in particular:
- Hosting and technical IT service providers
- Email and communication service provider
- Payment and credit institutions
- Tax and legal advisors
- Authorities, insofar as a legal obligation exists
- external platforms and services, insofar as these are accessed within the scope of the described functions
Service providers who process personal data exclusively on our behalf are used in accordance with data protection requirements.
Personal data will not be passed on to third-party advertising purposes.
Transfers outside the European Economic Area
Individual external service providers or platforms may also process personal data outside the European Economic Area.
Insofar as we initiate such a transfer, it will only take place under the conditions of Art. 44 et seq. GDPR.
In particular, an adequacy decision by the European Commission or suitable guarantees such as the standard contractual clauses approved by the European Commission are suitable for this purpose.
Storage of personal data
Storage duration
We generally only store personal data for as long as is necessary for the respective processing purpose.
Inquiries that do not result in a contractual relationship will be deleted as soon as they have been fully processed and there are no legitimate or legal reasons for further storage.
Data from bookings and contractual relationships will be stored for as long as is necessary for the execution of the contract and for compliance with legal commercial, tax or other retention obligations.
Insofar as personal data are required for the establishment, exercise or defense of legal claims, they may be stored until the expiry of the respective applicable limitation periods.
Data processed solely on the basis of consent will be deleted as soon as the consent has been effectively withdrawn and no other legal basis permits or requires further processing.
Your data protection rights
Rights of affected persons
Subject to the legal requirements, you have in particular the following rights:
- Right to information pursuant to Article 15 GDPR
- Right to rectification pursuant to Article 16 GDPR
- Right to erasure pursuant to Article 17 GDPR
- Right to restriction of processing pursuant to Article 18 GDPR
- Right to data portability pursuant to Article 20 GDPR
- Right to object pursuant to Article 21 GDPR
If processing is based on your consent, you can withdraw this consent at any time with effect for the future in accordance with Article 7(3) GDPR.
If processing is based on Article 6(1)(f) GDPR, you may object to the processing on grounds relating to your particular situation.
To exercise your rights, simply send a message to:
Right to complain
According to Article 77 of the GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes data protection regulations.
In particular, you can contact the data protection supervisory authority of your habitual residence, your place of work or the place of the alleged infringement.
In Spain, you can especially refer to:
Agencia Española de Protección de Datos (AEPD)
Paseo de la Castellana, 141
28046 Madrid
Spain
turn around.
Security and up-to-dateness
Data security
We take appropriate technical and organizational measures to protect personal data from loss, manipulation, unauthorized disclosure and unauthorized access.
Data transmission between your browser and our website is encrypted via HTTPS/TLS.
Our security measures are reviewed and adapted according to the respective risk and technological developments.
Automated decision-making
Purely automated decision-making, including profiling as defined in Article 22 GDPR, does not take place.
Changes to this privacy policy
We will update this privacy policy if our data processing practices, services used, or legal requirements change.
The version published on this website at any given time is the applicable one.
As of August 2026