✦ Legal

Privacy Policy

How LOKA collects, uses and protects your personal data — under the EU General Data Protection Regulation (GDPR) and Dutch national implementation (UAVG).

Last updated: 26 May 2026 · Version 1.0
In this policy
  1. Who we are
  2. What data we collect
  3. Why we use it
  4. Legal bases
  5. Who we share it with
  6. International transfers
  7. How long we keep it
  8. Your rights
  9. Security
  10. Children
  11. Changes
  12. Contact

01Who we are

This service ("LOKA", "we", "us") is operated by Amphi Labs BV (in formation) — a private limited company being constituted in the Netherlands. Until the Dutch incorporation deed is signed (expected 1 July 2026), the service is operated on behalf of the company-in-formation by its founder, in line with Dutch law on the BV i.o. ("in oprichting"). Full identification of the operator behind the company-in-formation is available on written request.

For all data-protection matters: amo@amphilabs.com.

The data controller is the operator named above. We have not appointed a Data Protection Officer because the scale of processing does not meet the thresholds set out in Article 37 GDPR — but the contact above answers all data-protection requests directly.

Heads-up — change of controller, 1 July 2026. On incorporation of Amphi Labs BV (expected 1 July 2026), the data controller will formally become the incorporated company, retaining the same contact email and the same processing practices. Active customers will be notified by email. The contract you have with the company-in-formation transfers to the incorporated BV by operation of Dutch corporate law.

02What data we collect

We only collect what we need to build your itinerary and run the service. In practice:

CategoryExamplesSource
Identification & contactFirst name, email addressYou — via the quiz / sign-up form
Travel profileAge range, gender (optional), travel companions, destinations of interest, trip length, budget band, food preferences, activity preferences, climate preferences, Spanish-language level, country of originYou — via the quiz
Transactional dataPurchase amount, currency, timestamp, last 4 digits of card, billing countryStripe (our payment processor) — we never see full card numbers
CommunicationsEmails you send us, our replies, satisfaction-survey responses (NPS)You
Technical dataIP address (truncated), browser type, device type, referrer, pages visited, timestampsAutomatically — server logs and analytics (with consent)

We do not deliberately collect special-category data (health, religion, political opinions, biometrics). Please do not send us such data in free-text fields.

03Why we use it

Under Article 6 GDPR, every use of your data has a specific legal basis. Ours are:

ActivityLegal basis
Building and delivering your travel plan; processing your paymentContract — Article 6(1)(b). The processing is necessary to perform the service you bought.
Customer support; service emailsContract — Article 6(1)(b).
Marketing emails, newsletters, optional analytics cookiesConsent — Article 6(1)(a). You can withdraw consent any time.
Tax, accounting, anti-fraud, lawful requestsLegal obligation — Article 6(1)(c).
Service improvement on pseudonymised data; defending legal claimsLegitimate interests — Article 6(1)(f). We balance these against your rights and you can object at any time.

05Who we share it with

LOKA does not sell your personal data. We share it only with the service providers we need to run the service ("processors"). Each one is bound by a contract that limits what they can do with your data.

ProviderPurposeLocation
Netlify, Inc.Hosting the LOKA website and form submissionsUnited States (with EU sub-processors)
Stripe Payments Europe Ltd.Processing card paymentsIreland (EU) — with US sub-processors
Google Ireland Ltd. (Google Workspace / Gmail)Sending and receiving operational email at amo@amphilabs.comIreland (EU) — with US sub-processors
Local guides, eco-stays and partnersOnly when you explicitly book or request to be contacted by them — we share your name and request, never your payment detailsMexico

We may also share data with public authorities if required by law (tax, court order, anti-fraud).

06International transfers

Some of our processors store data in or transfer it to the United States or to Mexico. When that happens, we rely on:

You can request a copy of the safeguards in place by emailing us.

07How long we keep it

DataRetention
Quiz answers + delivered itinerary3 years from purchase, then deleted or fully anonymised. Kept to support customer service and re-bookings.
Account email + marketing consentUntil you unsubscribe or request deletion.
Invoices, receipts and accounting records7 years (Dutch tax law / equivalent EU accounting requirements).
Server logs30 days, then deleted.
Support emails3 years after the conversation closes.

08Your rights

Under GDPR you have the right to:

To exercise any right, email amo@amphilabs.com. We respond within one month (extendable by two months for complex requests, with notice).

Identity check. If your request comes from an email address we have not seen before, or if it concerns sensitive operations like deletion of paid records, we may ask you to confirm your identity before we act.

09Security

We protect your data with HTTPS encryption in transit, encrypted storage with our processors, access controls limited to the operator, and a documented incident response process. In the event of a personal data breach likely to result in a high risk to your rights, we will notify both our lead supervisory authority (the Dutch Autoriteit Persoonsgegevens, within 72 hours of becoming aware) and you, in line with Articles 33–34 GDPR.

10Children

LOKA is not aimed at people under 16. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.

11Changes to this policy

We may update this policy as the service evolves or to reflect legal changes. The "Last updated" date at the top of the page always reflects the current version. Material changes will also be notified by email to active customers.

12Contact

Questions, requests, or complaints — please write to amo@amphilabs.com.