Privacy Policy
Last updated: 3 July 2026
This Privacy Policy explains how your personal data is collected, used, stored, shared and protected when you visit our websites, contact us, subscribe to our writing, or apply for and travel on one of our journeys. It also sets out your rights and how to exercise them.
We are committed to handling your personal data lawfully, transparently and securely, in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the Latvian Personal Data Processing Law (Fizisko personu datu apstrādes likums), and other applicable data protection legislation.
1. Who we are (Data Controller)
The data controller responsible for your personal data is:
SIA “i-Dā”
Registration number: 40203066558
Tourism operator licence: T-2019-4
Registered in Latvia, European Union
Email: rolands@escaperies.com
SIA “i-Dā” (“we”, “us”, “our”) is the legal entity that operates two distinct travel brands:
- Escaperies — our international small-group nature and adventure journey platform, at escaperies.com.
- Baltic Nature Adventures — our Latvia- and Baltics-focused guided nature tours brand, at balticnatureadventures.com.
This Privacy Policy applies to both brands and to all of our associated channels, including the social media and publishing accounts listed in Section 3. Where this policy refers to “our Services”, it means our websites, journeys, tours, enquiry and booking processes, newsletters, and editorial publications across both brands.
Given the nature and scale of our processing, we are not required to appoint a Data Protection Officer under Article 37 GDPR. For all data protection matters, please contact us directly at the email above.
2. The personal data we collect
Depending on how you interact with us, we may collect the following categories of personal data:
2.1 Information you provide directly
- Identity and contact details — first and last name, email address, telephone number, country of residence, and postal address where relevant.
- Enquiry and application details — the journey or topic you are interested in, your questions, travel experience, and any information you choose to include in your message via our contact or application forms.
- Booking and travel details — where you confirm a place on a journey, information necessary to deliver the trip safely, which may include passport details, date of birth, nationality, emergency contact details, travel insurance details, dietary requirements, and relevant medical or fitness information.
- Newsletter and subscription details — the email address you provide when you subscribe to our newsletter or to our editorial channel on Substack.
- Correspondence — records of your communication with us by email, social media, or web form.
2.2 Special category data
To run nature and adventure journeys safely, we may need to process limited special category data — in particular health, dietary, fitness or accessibility information that you choose to share so that we can accommodate you and ensure your safety during a trip. We process this data only where you have given your explicit consent, or where processing is necessary to protect your or another person’s vital interests (Article 9(2)(a) and 9(2)(c) GDPR). We collect only what is necessary, and we do not use this information for any purpose other than the safe and appropriate delivery of your journey.
2.3 Information collected automatically
- Usage data — including your IP address, browser type and version, device identifiers, the pages you visit, time and date of visit, time spent on pages, referring website, and similar diagnostic data.
- Cookies and similar technologies — small data files stored on your device. See Section 9 and our separate Cookie information for full details, including the categories of cookies and how to control them.
We do not knowingly collect more data than we need for the purposes described in this policy.
3. Where we collect data — our websites and channels
Your personal data may be collected through any of the following, all operated by SIA “i-Dā”:
- Websites: escaperies.com and balticnatureadventures.com, including contact forms, application forms, newsletter sign-ups, and comment fields.
- Editorial channel: our Substack publication (substack.com/@escaperies), including free and paid subscriptions.
- Social media accounts: Escaperies on Facebook, Instagram and other platforms where we maintain an official presence, and Baltic Nature Adventures on its associated social media accounts. When you contact us, comment, or message us through these platforms, we receive the information you choose to share, and the platform also processes your data under its own privacy policy.
- Direct correspondence: email, telephone, and messaging.
When you interact with us on a third-party platform (such as a social network or Substack), that platform is an independent data controller of your data on its own service. We encourage you to review the privacy policy of any platform you use to reach us.
4. How and why we use your data, and our legal bases
Under the GDPR we must have a lawful basis for each processing activity. The table below sets out what we do with your data and why.
| Purpose | Legal basis (GDPR) |
|---|---|
| Responding to your enquiries and applications, and discussing whether a journey is right for you | Pre-contractual steps at your request (Art. 6(1)(b)); our legitimate interest in answering enquiries (Art. 6(1)(f)) |
| Organising, confirming and delivering a journey or tour you have booked, including logistics, safety and supplier arrangements | Performance of a contract with you (Art. 6(1)(b)) |
| Processing health, dietary, fitness or accessibility information to keep you safe and accommodate your needs on a trip | Your explicit consent (Art. 9(2)(a)); protection of vital interests (Art. 9(2)(c)) |
| Sending you our newsletter, journey announcements, and editorial updates | Your consent (Art. 6(1)(a)), which you may withdraw at any time |
| Managing payments and keeping accounting and tax records | Compliance with a legal obligation (Art. 6(1)(c)) |
| Operating, securing and improving our websites and understanding how they are used | Your consent for non-essential cookies (Art. 6(1)(a)); our legitimate interest in a secure, functional website (Art. 6(1)(f)) |
| Preventing fraud, resolving disputes, and enforcing our terms | Our legitimate interests, and compliance with legal obligations (Art. 6(1)(f) and 6(1)(c)) |
Where we rely on consent, you are free to refuse or withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. Where we rely on legitimate interests, you have the right to object (see Section 10).
5. Who we share your data with
We do not sell your personal data. We share it only where necessary, and only with parties who are bound to protect it. These may include:
- Local partners and suppliers who help deliver a journey to our standard — for example local guides, accommodation providers, and transport operators in the destination — where this is necessary to fulfil your booking.
- Service providers (data processors) who operate our infrastructure on our behalf under written agreements, including:
- Our website host, Hostinger.
- Our email provider, Zoho Mail, used to send and receive correspondence.
- Our forms tool, used to receive enquiries and applications.
- Our newsletter and editorial platform, Substack.
- Our analytics provider, where you have consented (see Section 9).
- Our security and bot-protection provider, Cloudflare, whose Turnstile service helps us protect our forms from automated abuse and spam (see Section 7).
- Payment processors, where applicable (see Section 6).
- Professional advisers such as accountants, where required for legal or accounting purposes.
- Public authorities where we are required to disclose data by law, court order, or valid request from a competent authority.
Each processor acting on our behalf may only use your data to provide their service to us, and is contractually obliged not to use it for any other purpose.
6. Payments
Where a journey or service requires payment, we may use third-party payment processors. We do not store your full payment card details on our systems; those are handled directly by the payment processor, whose use of your data is governed by their own privacy policy. Reputable payment processors comply with the Payment Card Industry Data Security Standard (PCI-DSS).
7. Bot protection and website security
To protect our contact and application forms from automated abuse, spam and fraudulent submissions, our websites use Cloudflare Turnstile, a security service provided by Cloudflare, Inc. Turnstile runs silently in the background and may collect and process technical information about your device and browsing session — such as your IP address, browser characteristics and interaction signals — to distinguish genuine visitors from automated bots. This processing is necessary for our legitimate interest in keeping our websites and forms secure (Article 6(1)(f) GDPR). Cloudflare acts as our service provider for this purpose. Cloudflare’s handling of this data is governed by the Cloudflare Turnstile Privacy Addendum, available at https://www.cloudflare.com/turnstile-privacy-policy/, and the Cloudflare Privacy Policy.
8. International transfers of data
We are based in Latvia and primarily process your data within the European Economic Area (EEA). Because our journeys take place internationally and we work with local partners and suppliers abroad, some of your data may be transferred to and processed in countries outside the EEA in order to deliver a trip you have booked.
Where we transfer personal data outside the EEA, we ensure an appropriate level of protection through one or more of the following safeguards: a European Commission adequacy decision; Standard Contractual Clauses; or, where necessary to perform your booking, the specific contractual derogation under Article 49(1)(b) GDPR. You may request more information about the safeguards we apply by contacting us.
9. Cookies and analytics
Our websites use cookies and similar technologies. Cookies are small text files placed on your device that help the site function, remember your preferences, and (where you consent) measure how the site is used.
We use the following broad categories:
- Strictly necessary cookies — required for the website to function. These do not require consent.
- Preference cookies — remember choices such as your language or settings.
- Statistics/analytics cookies — help us understand how visitors use the site, for example through Google Analytics. These run only with your consent.
- Marketing cookies — used only where you have given consent.
When you first visit our websites, our consent banner lets you accept or reject non-essential cookies and change your preferences at any time. You can also control or delete cookies through your browser settings, though disabling some cookies may affect how the website works.
Where we use Google Analytics, data is processed in accordance with Google’s privacy policy. You may opt out by declining analytics cookies in our consent banner, or by installing the Google Analytics opt-out browser add-on (https://tools.google.com/dlpage/gaoptout).
Because our travellers come from around the world, you can also manage interest-based advertising cookies through the regional opt-out programmes that apply to you:
- Europe (EEA and UK): https://www.youronlinechoices.eu
- United States: the Network Advertising Initiative (https://optout.networkadvertising.org) and the Digital Advertising Alliance (https://optout.aboutads.info)
- Canada: the Digital Advertising Alliance of Canada (https://youradchoices.ca)
You can also control or delete cookies at any time through your browser settings. Regardless of your location, our consent banner lets you accept or reject non-essential cookies and change your preferences whenever you wish.
10. Your rights
If you are in the EEA, or your data is otherwise protected by the GDPR, you have the following rights in relation to your personal data:
- Right of access — to obtain confirmation of whether we process your data and a copy of it.
- Right to rectification — to have inaccurate or incomplete data corrected.
- Right to erasure (“right to be forgotten”) — to have your data deleted where there is no overriding reason to keep it.
- Right to restriction — to limit how we use your data in certain circumstances.
- Right to data portability — to receive your data in a structured, commonly used, machine-readable format, and to have it transferred to another controller where technically feasible.
- Right to object — to object to processing based on our legitimate interests, and to object to direct marketing at any time.
- Right to withdraw consent — where we rely on your consent, you may withdraw it at any time, including by using the unsubscribe link in any of our emails.
- Right to lodge a complaint — with a supervisory authority (see Section 13).
To exercise any of these rights, contact us at rolands@escaperies.com. We will respond within one month, as required by the GDPR. We may ask you to verify your identity before acting on a request. Exercising your rights is free of charge, unless a request is manifestly unfounded or excessive.
11. How long we keep your data
We keep your personal data only for as long as necessary for the purposes for which it was collected, including to satisfy any legal, accounting or reporting requirements. As a general guide:
- Enquiries and applications that do not lead to a booking: up to 24 months from your last contact, after which they are deleted.
- Confirmed bookings and related financial records: retained for as long as the accounting and tax obligations under Latvian law require, generally up to 5–7 years.
- Newsletter and subscription data: until you unsubscribe or withdraw consent.
- Special category (health, dietary, fitness) data: deleted promptly after the relevant journey is completed, unless we are legally required to keep it longer.
- Website usage and analytics data: retained for a limited period for security and analysis, then deleted or anonymised.
We review the data we hold periodically and delete what we no longer need.
12. How we protect your data
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, misuse or alteration — including encrypted connections, access controls, and trusted, GDPR-compliant service providers. However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority, and you where required, in line with the GDPR.
13. Complaints and supervisory authority
If you have a concern about how we handle your data, please contact us first at rolands@escaperies.com so we can try to resolve it.
You also have the right to lodge a complaint with a data protection supervisory authority. Our lead authority is:
Data State Inspectorate of Latvia (Datu valsts inspekcija)
Website: www.dvi.gov.lv
If you are located in another EEA country, you may also contact your local data protection authority.
14. Children’s privacy
Our Services are directed at adults and are not intended for children. We do not knowingly collect personal data from anyone under the age of 18 without the consent of a parent, guardian or legal representative. Where a minor travels on a journey, their data is provided and managed by the accompanying responsible adult. If you believe we have collected data from a child without appropriate consent, please contact us and we will delete it.
15. Links to other websites
Our Services may contain links to websites we do not operate. We are not responsible for the content or privacy practices of those sites. We encourage you to read the privacy policy of every website you visit.
16. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal reasons. When we do, we will revise the “Last updated” date at the top of this page, and where the changes are significant we will take reasonable steps to inform you. We encourage you to review this page periodically.
17. Contact us
For any question about this Privacy Policy or your personal data, contact:
SIA “i-Dā” — operating Escaperies and Baltic Nature Adventures
Email: rolands@escaperies.com
Websites: escaperies.com · balticnatureadventures.com
Last updated: 3 July 2026
