Legal information
Legal information
Privacy policy
Effective from 8 May 2026.
What data we collect and why
When you book a visit through /prijava.php we collect:
- Full name — to address you and identify your booking.
- Email — for confirmation of receipt, decision notice, day-before reminder, and communication regarding the booking.
- Phone — for contact in case of urgent changes.
- Date and time, number of visitors, tour language, group name, notes — to prepare the visit.
After the visit, the administrator may record a received donation (amount and note) for internal records.
Legal basis
Processing of personal data is based on your consent when submitting the booking (Art. 6(1)(a) GDPR) and on the contractual relationship for carrying out the visit (Art. 6(1)(b) GDPR). For invoicing institutions, processing is also based on tax law (Art. 6(1)(c) GDPR).
How long we keep data
- Booking records: 3 years after the visit, then anonymised or deleted.
- Accounting documents (invoices to institutions): 10 years per tax law.
- Messages via the visitor portal: until booking deletion.
Recipients of data
- The guide assigned to your visit (only: name, time, number of visitors, your notes).
- The server and email service operators (technical processing — sending email).
- Public authorities only when legally required.
We do not transfer data outside the EU.
Your rights
Under the GDPR you have the right to:
- access your data;
- rectify inaccurate data;
- erase data (“right to be forgotten”);
- restrict processing;
- data portability;
- withdraw consent at any time;
- lodge a complaint with the Slovenian Information Commissioner, www.ip-rs.si.
To exercise these rights, please write to kapucini.loka@rkc.si.
Cookies
The site uses only strictly necessary cookies:
kapucini_session— session cookie for the admin interface and CSRF protection; deleted automatically when the browser session ends.lang— stores your chosen language; lifetime 1 year.
The site uses no tracking or advertising cookies.
Own visit analytics
To understand how many visits the site receives and from which countries, we keep our own server-side analytics without cookies. For each public-page visit we record:
- time of visit, page path, language, browser type (User-Agent);
- a hash (SHA-256) of your IP address with a random salt — the raw IP is not stored;
- a two-letter country code, looked up once per IP hash via the external service ip-api.com; the result is cached and not requested again for the same IP.
These records are kept for typically up to 12 months and used only for internal review. We do not use them for profiling, advertising or sharing with third parties.
External services
- Google Fonts — fonts (Cormorant Garamond, Newsreader, Cormorant SC) are loaded from
fonts.googleapis.com; Google may record your IP address in the process. - Google Maps — a link to the parking map opens in a new tab; no map is embedded on this site.
- ip-api.com — on the first visit your IP may be sent once to determine the country (the result is cached; subsequent visits do not trigger external calls).
Changes
We reserve the right to amend this policy. The date of the last change is shown above. Substantial changes will be announced on the website.