Legal

Privacy Policy

The honest version: we designed this site so there is almost nothing to write a privacy policy about.

Last updated: 4 August 2026

The short version

No cookies. No analytics. No advertising. No social media embeds. No accounts, no newsletter, and just one form: a spam-protected contact page. Fonts are served from our own server, not Google's. The trip planner runs entirely in your browser, nothing you enter is ever sent to us. The only data that exists is the standard, short-lived server log every website host keeps, plus whatever you choose to send us through the contact form.

1. Who we are

visit.eu.org is an independent, non-commercial travel guide to the countries of the European Union. For the purposes of the EU General Data Protection Regulation (GDPR), the data controller is the operator of visit.eu.org.

2. What data we process

Server logs, the only personal data we touch

Like virtually every website, our web server automatically records a technical log entry when you request a page. A log line contains:

Purpose: keeping the site secure and available, detecting abuse, diagnosing errors, and defending against attacks.
Legal basis: Article 6(1)(f) GDPR, our legitimate interest in operating a secure website.
Retention: logs are automatically rotated and deleted after a short period (at most a few weeks) unless a specific entry is needed to investigate abuse.

Nothing else

The one place you can hand us personal data is the contact form, described below. Nothing else on the site collects anything.

3. What we deliberately don't do

4. The trip planner

The itinerary planner on our home page runs entirely inside your browser using JavaScript. Your choices, trip length, arrival and departure countries, interests, are processed on your device only. They are never transmitted to our server, never stored, and disappear when you close the tab.

This site links to external websites, official EU information services, national tourism boards, and rail operators, collected on our useful links page. Once you follow such a link, the privacy policy of that website applies. We choose reputable, mostly official sources, but we are not responsible for their content or data practices.

6. The contact form

If you use our contact form, we process the name, email address, and message you enter, solely to read and reply. The submission is delivered to our mailbox and kept only as long as the correspondence needs; it is not added to any list or shared with anyone. Legal basis: Article 6(1)(b) GDPR (taking steps at your request) and 6(1)(f) (answering you).

To block spam, the form uses Cloudflare Turnstile, the only third-party service on this site, loaded only on the contact page. Cloudflare processes technical data including your IP address to distinguish humans from bots; per Cloudflare, Turnstile does not use tracking cookies and the data is not used for advertising. See Cloudflare's Turnstile privacy notice. If you prefer not to use the form, the policy is simple: don't; the rest of the site works identically without it.

7. Your rights under the GDPR

If you are in the European Economic Area (and in many other places too), you have the right to:

In practice: since server logs are the only data we hold and we cannot identify you from an IP address alone without disproportionate effort, some of these rights may be limited by Art. 11 GDPR (processing which does not require identification). We will always tell you honestly what we can and cannot find.

8. International data transfers

The site is hosted within the European Union and we transfer no personal data outside the EU/EEA ourselves. The one caveat: Cloudflare, whose Turnstile widget protects the contact form, is a US company; it participates in the EU-US Data Privacy Framework and processes only the technical data needed for the bot check.

9. Security

The site is served over HTTPS (TLS encryption). Access to the server and its logs is restricted to the site operator.

10. Children

The site is suitable for all ages and collects no data from anyone, children included.

11. Changes to this policy

If we ever add a feature that processes personal data (for example a newsletter), we will update this policy first and note the date at the top of this page. The current version always lives at visit.eu.org/privacy.

12. Contact

Questions, requests, or complaints about privacy can be addressed to the site operator of visit.eu.org. We reply to GDPR requests within one month, as Art. 12(3) requires. If you believe your rights have been infringed, you can also contact your national data protection authority directly.