Last updated: 4 August 2026
The short version
No cookies. No analytics. No advertising. No social media embeds. No accounts, no newsletter, and just one form: a spam-protected contact page. Fonts are served from our own server, not Google's. The trip planner runs entirely in your browser, nothing you enter is ever sent to us. The only data that exists is the standard, short-lived server log every website host keeps, plus whatever you choose to send us through the contact form.
1. Who we are
visit.eu.org is an independent, non-commercial travel guide to the countries of the European Union. For the purposes of the EU General Data Protection Regulation (GDPR), the data controller is the operator of visit.eu.org.
2. What data we process
Server logs, the only personal data we touch
Like virtually every website, our web server automatically records a technical log entry when you request a page. A log line contains:
- your IP address,
- date and time of the request,
- the page requested and the HTTP status code,
- the browser and operating system you use (the "user agent" string), and
- the referring page, if your browser sends one.
Purpose: keeping the site secure and available, detecting abuse, diagnosing errors, and defending against attacks.
Legal basis: Article 6(1)(f) GDPR, our legitimate interest in operating a secure website.
Retention: logs are automatically rotated and deleted after a short period (at most a few weeks) unless a specific entry is needed to investigate abuse.
Nothing else
The one place you can hand us personal data is the contact form, described below. Nothing else on the site collects anything.
3. What we deliberately don't do
- No cookies, of any kind. See our cookie policy.
- No analytics or statistics tools, no Google Analytics, no Matomo, no tracking pixels, no fingerprinting.
- No advertising, and therefore no ad networks profiling you.
- No third-party requests, every file on this site (fonts included) is served from our own server, with one disclosed exception: the contact page loads Cloudflare's Turnstile anti-spam widget. It runs only on that page.
- No sale or sharing of data, we have nothing to sell or share.
4. The trip planner
The itinerary planner on our home page runs entirely inside your browser using JavaScript. Your choices, trip length, arrival and departure countries, interests, are processed on your device only. They are never transmitted to our server, never stored, and disappear when you close the tab.
5. External links
This site links to external websites, official EU information services, national tourism boards, and rail operators, collected on our useful links page. Once you follow such a link, the privacy policy of that website applies. We choose reputable, mostly official sources, but we are not responsible for their content or data practices.
6. The contact form
If you use our contact form, we process the name, email address, and message you enter, solely to read and reply. The submission is delivered to our mailbox and kept only as long as the correspondence needs; it is not added to any list or shared with anyone. Legal basis: Article 6(1)(b) GDPR (taking steps at your request) and 6(1)(f) (answering you).
To block spam, the form uses Cloudflare Turnstile, the only third-party service on this site, loaded only on the contact page. Cloudflare processes technical data including your IP address to distinguish humans from bots; per Cloudflare, Turnstile does not use tracking cookies and the data is not used for advertising. See Cloudflare's Turnstile privacy notice. If you prefer not to use the form, the policy is simple: don't; the rest of the site works identically without it.
7. Your rights under the GDPR
If you are in the European Economic Area (and in many other places too), you have the right to:
- access the personal data we hold about you (Art. 15),
- rectification of inaccurate data (Art. 16),
- erasure ("right to be forgotten", Art. 17),
- restriction of processing (Art. 18),
- data portability (Art. 20),
- object to processing based on legitimate interest (Art. 21), and
- lodge a complaint with a supervisory authority (Art. 77), see the list of EU data protection authorities.
In practice: since server logs are the only data we hold and we cannot identify you from an IP address alone without disproportionate effort, some of these rights may be limited by Art. 11 GDPR (processing which does not require identification). We will always tell you honestly what we can and cannot find.
8. International data transfers
The site is hosted within the European Union and we transfer no personal data outside the EU/EEA ourselves. The one caveat: Cloudflare, whose Turnstile widget protects the contact form, is a US company; it participates in the EU-US Data Privacy Framework and processes only the technical data needed for the bot check.
9. Security
The site is served over HTTPS (TLS encryption). Access to the server and its logs is restricted to the site operator.
10. Children
The site is suitable for all ages and collects no data from anyone, children included.
11. Changes to this policy
If we ever add a feature that processes personal data (for example a newsletter), we will update this policy first and note the date at the top of this page. The current version always lives at visit.eu.org/privacy.
12. Contact
Questions, requests, or complaints about privacy can be addressed to the site operator of visit.eu.org. We reply to GDPR requests within one month, as Art. 12(3) requires. If you believe your rights have been infringed, you can also contact your national data protection authority directly.