Last updated: August 26, 2026
While geyser-lynx operates primarily in Canada, we recognize that some of our guests are residents of the European Union. We commit to handling all personal data in accordance with GDPR principles regardless of where our guests reside.
We process personal data under several legal bases. When you book an experience, processing is necessary for contract performance. For marketing communications, we rely on consent, which you can withdraw at any time. Certain data retention is required by legitimate business interests and legal obligations.
Geyser-lynx acts as the data controller for personal information collected through this website and booking processes. Our registered address is 327 Wilderness Drive, Banff, Alberta T1L 1A2, Canada.
You have the right to access personal data we hold about you and receive a copy in a structured, commonly used format. You can request correction of inaccurate information or deletion of data when it is no longer necessary for the purposes it was collected.
You may object to processing based on legitimate interests or restrict processing in certain circumstances. Where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing performed before withdrawal.
If you wish to transfer your data to another service provider, we will provide your personal information in a portable format upon request. This applies to data you have provided to us and that we process based on consent or contract performance.
We do not use automated decision-making or profiling that produces legal effects or similarly significant impacts on individuals. Guide assignments and experience recommendations are made through human review of your preferences and requirements.
Personal data is stored on servers located in Canada. If you are located in the European Union, your data is transferred outside the EU. We ensure appropriate safeguards are in place to protect your information during such transfers.
Booking information is retained for seven years to comply with business record requirements. Marketing communication preferences are kept until you withdraw consent. Website analytics data is retained for 24 months before being deleted or anonymized.
If you believe we have not handled your data in accordance with GDPR requirements, you have the right to lodge a complaint with your local data protection authority. We encourage you to contact us first so we can address your concerns directly.
For questions about how we process personal data or to exercise your GDPR rights, contact us at [email protected] with "GDPR Request" in the subject line. We will respond to requests within 30 days.
We implement technical and organizational measures appropriate to the risks posed by processing. This includes encryption of data in transit, access controls limiting who can view personal information, and regular security assessments of our systems.
In the event of a data breach that poses risks to your rights and freedoms, we will notify affected individuals within 72 hours of becoming aware of the breach, as required by GDPR. Notifications will include information about the nature of the breach and steps being taken to address it.