Privacy policy (GDPR)
MountVacation / MV-Travel
Effective from: 1 July 2026
Data Controller
The controller of personal data within the meaning of Regulation (EU) 2016/679 (GDPR) and applicable national law is:
OBS d.o.o.
Letališka cesta 29
1000 Ljubljana
Slovenia
Email: privacy@mountvacation.com
OBS d.o.o. operates the MountVacation and MV-Travel websites. Throughout the remainder of this Policy, the term “Controller” means OBS d.o.o. in relation to both platforms, except where expressly stated otherwise. This Policy applies equally to users of both platforms.
Scope of Application
This Privacy Policy sets out how the Controller collects, uses, processes, retains and protects the personal data of users of its websites and services, including:
- website visitors,
- registered users,
- customers,
- participants in the Loyalty Program,
- persons who contact customer support.
Categories of Personal Data
We may process the following categories of personal data:
- identification data (first name, last name),
- contact details (email address, telephone number),
- date of birth – not a mandatory item, except where required for performance of the service by a third-party provider (e.g. ski passes, air travel, or other services where age is a condition of booking),
- travel preferences (e.g. themes such as skiing, active holidays, seaside, thermal spa breaks),
- data relating to bookings, trips and transactions,
- data relating to the user account and booking history,
- data relating to Credit, loyalty status (MV Points) and use of benefits,
- communication data (email, SMS, content of communications with customer support),
- technical data (IP address, device data, cookies – governed separately in the Cookie Policy).
Purposes and Legal Bases of Processing
We process personal data for the following purposes:
Performance of the Contractual Relationship (GDPR, Article 6(1)(b))
- carrying out bookings and travel services,
- managing the user account,
- maintaining booking history,
- accounting for payments, Credit and benefits,
- status notifications (e.g. Credit balance, expiry, confirmations),
- providing insolvency protection for packages, where OBS d.o.o. acts as the Organiser.
Compliance with Legal Obligations (GDPR, Article 6(1)(c))
- accounting and tax obligations,
- record-keeping obligations,
- resolving disputes and legal claims.
Legitimate Interests (GDPR, Article 6(1)(f))
- improving our services,
- preventing misuse and fraud,
- security of information systems,
- internal analytics and reporting.
The data subject has the right to object to processing carried out on this legal basis, in accordance with Article 21 GDPR.
Marketing and Communications (GDPR, Article 6(1)(a))
- sending newsletters, offers and promotional content,
- personalised communication based on consent.
Consent is voluntary and may be withdrawn at any time.
Status Notifications and the Loyalty Program
Notifications relating to:
- the status of the user account,
- the status or expiry of Credit,
- loyalty status,
- technical or operational information,
are not considered marketing, but rather notifications necessary for the performance of the contractual relationship. Such notifications may be sent by email, SMS, through the mobile application (push notifications), or within the user’s online account, without a separate marketing consent.
Recipients of Personal Data
Personal data may be disclosed to:
- providers of travel services (e.g. accommodation establishments), only to the extent necessary for performance of the service,
- contracted processors (e.g. CRM, payment processors, IT service providers),
- the insurer with which OBS d.o.o. holds insolvency protection insurance as a package Organiser, to the extent necessary to exercise rights under that insurance,
- competent authorities, where required by law.
Before commencing processing, the Controller enters into an appropriate data processing agreement (DPA) with each processor, in accordance with Article 28 GDPR.
International Data Transfers
Where personal data is transferred outside the EU/EEA, such transfer is carried out only subject to appropriate safeguards (e.g. standard contractual clauses).
Automated Processing and Profiling
Based on the user’s preferences (e.g. selected travel themes) and booking history (e.g. time of booking, booking amount, the time frame of the booking relative to the travel date, type of service, type of traveller), the Controller carries out profiling for the purpose of displaying personalised offers in the mobile application and in the user’s online account on the website. The legal basis for this processing is the Controller’s legitimate interest (GDPR, Article 6(1)(f)) in offering relevant content to users. The data subject has the right to object to this processing in accordance with Article 21 GDPR.
The user may switch off personalised communication at any time in their user profile settings, separately for: communication via the web application, communication via the mobile application, and push notifications via the mobile application. Switching off personalisation does not affect receipt of the status notifications referred to in chapter 5 of this Policy.
Separately from personalised offers, the following applies to price display: the base (public) price of an individual service is, at any given moment, the same for all users and is set by suppliers through their own systems (XML connections); it therefore does not constitute price personalisation. Any “individual” price shown to a specific user represents simply the public price, reduced by transparent, pre-determined discounts (e.g. a promotional benefit, the user’s Credit, MV Points, a gift voucher), which are shown to the user separately and transparently during checkout. Because this involves the use of known discounts visible to the user, rather than an algorithmic assessment of the user’s willingness to pay a higher price, such processing does not constitute automated decision-making within the meaning of Article 22 GDPR, nor does it constitute price personalisation requiring special pre-contractual disclosure under consumer protection law.
The Controller does not carry out automated decision-making within the meaning of Article 22 GDPR that produces legal effects concerning the data subject or similarly significantly affects them.
Personal Data Retention Periods
We retain personal data for no longer than is necessary for the purpose of processing, namely:
- Accounting and tax records (e.g. invoices, payment confirmations): 10 years following the end of the year to which they relate, in accordance with the Tax Procedure Act (ZDavP-2).
- Data relating to a booking and performance of the travel service: 10 years from completion of the trip or service. This period is aligned with the retention period for accounting records under the Tax Procedure Act (ZDavP-2), as booking data also forms part of the accounting records; in addition, during this period booking history data is also processed on the basis of the Controller’s legitimate interest in personalising offers (see chapter 8) and for the defence of any legal claims.
- Data relating to Credit, MV Points and loyalty status: for the duration of the active user account, plus an additional 1 year following closure of the account or the last activity, on account of any claims relating to the Loyalty Program.
- Data processed on the basis of marketing consent: until the data subject withdraws their consent.
- Data disclosed to the insurer for insolvency protection purposes: for the duration of the insurance relationship and to the extent required by the insurance contract or package travel legislation.
- Recordings of telephone calls: a maximum of 12 months from the date of the call, unless the recording is required as evidence in the course of resolving a dispute or complaint, in which case it is retained until the matter is finally resolved.
Upon expiry of the above periods, the Controller deletes or anonymises the data, unless the law requires otherwise for a specific case. The Controller regularly reviews whether continued retention remains justified.
Recording of Telephone Calls
Telephone conversations with customer support may be recorded for the purposes of:
- ensuring service quality,
- resolving disputes,
- security.
The data subject is informed of the recording at the start of the call. Recordings are retained in accordance with the periods set out in chapter 9 of this Policy and are not used for marketing purposes.
Security of Personal Data and Breach Notification
We apply appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access or disclosure.
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects, the Controller:
- notifies the competent supervisory authority (the Information Commissioner of the Republic of Slovenia) of the breach without undue delay, and, as a rule, within 72 hours of becoming aware of it, in accordance with Article 33 GDPR,
- where the breach is likely to result in a high risk to the rights and freedoms of data subjects, also notifies the affected data subjects without undue delay, in accordance with Article 34 GDPR.
The Controller maintains an internal record of all identified personal data breaches, regardless of whether the breach is required to be reported to the supervisory authority.
Record of Processing Activities and Processors
In accordance with Article 30 GDPR, the Controller maintains an internal Record of Processing Activities (RoPA). Before engaging a processor to process personal data on the Controller’s behalf, the Controller enters into an appropriate data processing agreement (DPA) with that processor, in accordance with Article 28 GDPR. The Record of Processing Activities and the agreements concluded are retained internally and are made available to the competent supervisory authority upon request.
Data Subject Rights
The data subject has the right to:
- access their personal data,
- rectification of inaccurate data,
- erasure (where the applicable conditions are met),
- restriction of processing,
- data portability,
- object to processing,
- lodge a complaint with the supervisory authority (see chapter 14).
Requests to exercise the above rights may be sent by the data subject to: privacy@mountvacation.com.
Users may additionally review and manage certain basic data (e.g. contact details, preferences, an overview of booking history) directly within their user account. This option supplements, but does not replace, the right to full access, rectification, erasure or portability of data, which the Controller handles on the basis of a formal request sent to the email address above.
Complaints to the Supervisory Authority
The data subject has the right to lodge a complaint with the competent supervisory authority for the protection of personal data:
Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec Republike Slovenije)
Dunajska cesta 22
1000 Ljubljana
Slovenia
Website: www.ip-rs.si
As the Controller (OBS d.o.o.) is established exclusively in Slovenia, the Information Commissioner of the Republic of Slovenia is, in accordance with the “one-stop-shop” mechanism (Article 56 GDPR), the competent lead supervisory authority for cross-border processing of personal data within the EU/EEA, regardless of the data subject’s country of residence or the language version of the website they use. Notwithstanding the above, the data subject always also has the right to lodge a complaint with the supervisory authority in their own Member State of residence, which will coordinate the matter with the Information Commissioner of the Republic of Slovenia in accordance with the cooperation procedures under the GDPR.
Changes to This Policy
We reserve the right to amend this Policy. An amended Policy takes effect on the date it is published on the Controller’s website. Any given instance of personal data processing is governed by the version of the Policy in effect at the time of that processing.
Final Provisions
This Policy applies to all users of the MountVacation and MV-Travel services and is applied together with the General Terms and Conditions, the Cookie Policy, and other related documents.
