Legal
Privacy policy
Effective as of July 13, 2026
This policy explains, in as much detail as we can manage, what we do with your personal data - including the health information we ask for in order to keep you safe in the mountains. If you would rather ask a person, write to jeff@tsaina.com.
1. Introduction and scope
Valdez Heli-Ski Guides ("VHSG", "we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, how long we keep it, how we protect it, and the rights you have over it.
This Policy applies to: (a) our website at valdezheliskiguides.com and any subdomain of it (the "Site"); (b) the member portal, including account registration, guest profiles, booking requests and electronic contract signature; (c) our email communications, including transactional emails and our newsletter; and (d) any other interaction you have with us in connection with a heli-ski trip, whether online or offline (together, the "Services").
This Policy does not apply to third-party websites that we link to. When you follow a link to a third-party website, that site’s own privacy policy governs.
Please read this Policy carefully. If you do not agree with it, please do not use the Services. If you have any question about it, contact us using the details in Section 24.
The short version
- We do not track you. We use no analytics cookies, no advertising cookies, no Google Analytics, no Meta pixel, and no third-party tracker of any kind.
- We use exactly one cookie: a session cookie that keeps you signed in to your member account. It is strictly necessary and cannot be used to profile you.
- We never sell your personal data. We never share it for cross-context behavioural advertising. We have never done either, and we do not intend to.
- We collect health information because heli-skiing is a mountain activity where your safety may depend on it. We treat that data with the highest level of protection, and only with your explicit consent.
- You can ask us at any time to give you a copy of your data, correct it, or delete it. Write to jeff@tsaina.com.
2. Who we are, and who is responsible for your data
Valdez Heli-Ski Guides is the "controller" of your personal data (under the EU and UK General Data Protection Regulation), the "business" that collects it (under the California Consumer Privacy Act, as amended by the CPRA), and the "controlador" of it (under Brazil’s LGPD). In plain terms: we decide what personal data is collected and why, and we are accountable for it.
Our contact details are:
Valdez Heli-Ski Guides, HC-1 Box 85, Valdez, Alaska 99686, United States of America.
Privacy contact: jeff@tsaina.com. General contact: sonya@vhsg.com. Telephone: +1 (913) 530-5688.
We are a small operator. We do not have a statutory Data Protection Officer, because we are not required to appoint one. Privacy requests are handled directly by our team and answered personally.
3. The personal data we collect
We collect only the personal data we actually need in order to run a safe heli-ski operation and to fulfil our contract with you. We have deliberately kept that set as small as we can. The categories are set out below.
| Category | What it includes | When we collect it |
|---|---|---|
| Account and identity data | Your first and last name, email address, and a password (which we never see in readable form - see Section 15). | When you create a member account. |
| Contact data | Telephone number and mailing address. | When you complete your guest profile. |
| Booking data | The lodge and membership you request, your requested dates, the number of people in your party, and any notes you choose to add to your request. | When you submit a booking request. |
| Travel data | How you will arrive at the lodge, and related arrival details you give us so we can arrange your transfer. | When you complete your guest profile. |
| Health data (special category - see Section 4) | Your height and weight; your health insurance company and policy number; current medications; allergies; food restrictions; whether you are diabetic; cardiovascular conditions; knee or back problems; any other medical condition you tell us about; and your instruction as to whether this information may be shared with a physician or hospital if you are injured. | When you complete the medical section of your guest profile. |
| Emergency contact data | The full name, relationship to you, and telephone number of the person you nominate. This is personal data about someone else - please read Section 5. | When you complete your guest profile. |
| Skiing ability data | Your self-assessed comfort on hardpack, powder and deep powder; your comfort on slopes under 30 degrees, 30-45 degrees and over 45 degrees; and your preferred pace. | When you complete your guest profile. |
| Photograph | A profile photograph, if you choose to upload one. This is optional. We use it only so that your guide and our team can recognise you on arrival. We do not use facial recognition, and we do not process your photograph to identify you biometrically. | If and when you upload one. |
| Contract and signature data | The liability release and other trip documents you sign electronically, the fact and time of signature, and the audit trail generated by our e-signature provider. | When you sign your trip documents. |
| Communications data | The content of emails, contact-form messages and other correspondence you send us, and our replies. | Whenever you contact us. |
| Newsletter data | Your email address, and the record of your consent (including the date and time you confirmed it). | Only if you subscribe, and only after you confirm by clicking the link in our confirmation email. |
| Technical data | A strictly necessary session cookie (see Section 8), and the server logs that our hosting provider keeps for security and reliability, which may include your IP address. | Automatically, when you use the Site. |
4. Health data: why we ask, and how we protect it
This is the most sensitive information we hold, and it deserves its own section.
Heli-skiing takes place in remote, glaciated mountain terrain, a long way from a hospital. If you are injured, the people best placed to help you are your guide and the emergency services - and what they know about you may matter a great deal. Knowing that a guest is diabetic, has a cardiovascular condition, is taking an anticoagulant, or is severely allergic to something can change how a rescue is conducted. We also need your height and weight to fit your equipment, including your avalanche airbag pack and your climbing harness, correctly - which is itself a safety matter. Food restrictions and allergies are passed to our kitchen so that you are fed safely.
Under the EU and UK GDPR, health data is a "special category" of personal data (Article 9), and under the CCPA/CPRA it is "sensitive personal information". These regimes impose the strictest requirements that exist in privacy law, and we apply them.
Our legal basis for processing your health data is your explicit consent (Article 9(2)(a) GDPR). You give that consent when you complete the medical section of your guest profile, having been told - in this Policy - exactly what we do with it. You are not obliged to give it. However, we must be honest with you: if you decline to provide health information, we may be unable to accept you on a trip, because we would be unable to discharge our duty of care to you in the mountains. That is a safety decision, not a commercial one.
Where you are injured or incapacitated and cannot give or confirm consent at that moment, we may also rely on the protection of your vital interests or those of another person (Article 9(2)(c) GDPR) in order to pass relevant medical information to a physician, a hospital, or emergency responders.
You control the sharing of this data with medical professionals. Your profile contains an explicit question asking whether this information may be shared with a physician or hospital if you are injured. We follow your answer. If you answer no, we will not disclose it unless a legal obligation or a genuine emergency threatening life leaves us no alternative.
Your health data is never used for marketing. It is never sold. It is never shared with anyone except: your guides and the members of our operational team who need it to keep you safe; the medical or rescue professionals treating you, in the circumstances described above; and our database provider, which stores it on our behalf under contract (see Section 12).
You may withdraw your consent to our processing of your health data at any time, by writing to jeff@tsaina.com. Withdrawal does not affect the lawfulness of processing carried out before you withdrew. Please note that withdrawing consent before or during a trip may mean we can no longer take you into the field.
5. Information about other people (your emergency contact)
When you nominate an emergency contact, you give us personal data about a third party: their name, their relationship to you, and their telephone number.
That person has privacy rights too, and they have not dealt with us directly. Accordingly, when you provide their details, you confirm to us that you have their permission to do so, and that you have informed them: (a) that you have given their contact details to Valdez Heli-Ski Guides; (b) that we will use those details only to contact them in an emergency concerning you; and (c) that they can read this Policy and exercise their rights under it, including the right to ask us to delete their details.
We use emergency contact data for one purpose and one purpose only: to reach that person if something happens to you. We do not market to them. We do not add them to any list.
6. How we collect your data
- Directly from you, when you create an account, complete your guest profile, submit a booking request, sign your trip documents, subscribe to our newsletter, or write to us. This is by far the main source, and almost everything we hold comes from you.
- Automatically, in a very limited way, when you browse the Site: the strictly necessary session cookie described in Section 8, and the server logs kept by our hosting provider for security and reliability.
- From your travel agent or trip organiser, if you book through one and they pass us your details in order to arrange your trip.
- From members of your own party, where one member of a group completes information on behalf of others - in which case the person doing so is responsible for having their permission, as described in Section 5.
- We do not buy personal data. We do not scrape it. We do not obtain it from data brokers, from advertising networks, or from social media platforms.
7. Why we use your data, and our legal basis for doing so
Under the GDPR, the UK GDPR and similar laws, we must have a valid legal basis for every use of your personal data. The table below sets out each purpose and the corresponding basis.
| Purpose | Data used | Legal basis (GDPR Art. 6 / Art. 9) |
|---|---|---|
| To create and administer your member account | Account and identity data | Performance of a contract (Art. 6(1)(b)) |
| To process your booking request and arrange your trip | Account, contact, booking and travel data | Performance of a contract (Art. 6(1)(b)) |
| To keep you safe in the mountains, fit your safety equipment, and respond appropriately if you are injured | Health data, skiing ability data, height and weight | Explicit consent (Art. 9(2)(a)); and, in an emergency, vital interests (Art. 9(2)(c)) |
| To feed you safely | Allergies and food restrictions | Explicit consent (Art. 9(2)(a)) |
| To assign you to an appropriate group and terrain | Skiing ability data | Performance of a contract (Art. 6(1)(b)); and legitimate interests in operating safely (Art. 6(1)(f)) |
| To contact your nominated person in an emergency | Emergency contact data | Vital interests (Art. 6(1)(d)); legitimate interests in operating safely (Art. 6(1)(f)) |
| To obtain and store your signed liability release and trip documents | Contract and signature data | Performance of a contract (Art. 6(1)(b)); compliance with a legal obligation (Art. 6(1)(c)); establishment or defence of legal claims (Art. 9(2)(f) where health data is involved) |
| To send you transactional emails (booking confirmations, account activation, trip information) | Account and contact data | Performance of a contract (Art. 6(1)(b)) |
| To send you our newsletter | Email address, consent record | Consent (Art. 6(1)(a)), which you may withdraw at any time |
| To answer your questions and correspond with you | Communications data | Legitimate interests in responding to enquiries (Art. 6(1)(f)); performance of a contract where you are already a guest (Art. 6(1)(b)) |
| To keep our Site secure, prevent fraud and abuse, and keep it running | Technical data | Legitimate interests in securing our systems (Art. 6(1)(f)) |
| To keep accounting records and comply with tax and regulatory obligations | Booking and payment records | Compliance with a legal obligation (Art. 6(1)(c)) |
| To establish, exercise or defend legal claims | Any data relevant to the claim | Legitimate interests (Art. 6(1)(f)); establishment or defence of legal claims (Art. 9(2)(f)) |
8. Cookies and similar technologies
We use exactly one cookie, and it is strictly necessary.
When you sign in to your member account, our authentication system (NextAuth) sets a session cookie in your browser. Its sole function is to remember that you are signed in as you move from page to page. Without it, the member portal cannot work: you would be signed out on every click. It contains no advertising identifier, it does not follow you to other websites, and it cannot be used to build a profile of you.
Under Article 5(3) of the ePrivacy Directive and its national implementations, cookies that are strictly necessary for the provision of a service explicitly requested by the user do not require consent. That is why you do not see a cookie banner on this Site. It is not an oversight. It is because there is nothing to consent to.
To be completely explicit about what we do not do:
- We do not use Google Analytics, or any other analytics product.
- We do not use the Meta (Facebook) pixel, or any other advertising pixel.
- We do not use advertising cookies, retargeting cookies, or conversion-tracking cookies.
- We do not use social-media tracking widgets or "like" buttons that phone home.
- We do not fingerprint your device.
- We do not use session-replay tools that record what you do on the page.
- We do not participate in any advertising network, data co-operative, or audience-sharing scheme.
- We do not respond to "Do Not Track" browser signals for the simple reason that we do not track you in the first place, whether or not you send such a signal.
9. Advertising, profiling and automated decisions
We do not engage in behavioural advertising, and we do not build marketing profiles of our guests or visitors.
We do not carry out automated decision-making that produces legal effects concerning you, or that similarly significantly affects you, within the meaning of Article 22 of the GDPR. Every decision about your booking, your group assignment and the terrain you ski is made by a human being - specifically, by a professional guide who has met you.
Our booking page includes an optional membership finder tool. It asks you three questions and suggests a membership. It runs entirely in your browser, it makes no decision that binds you or us, and it stores nothing about your answers.
10. We do not sell or share your personal data
We do not sell your personal data, and we have never sold it. We do not "share" it for cross-context behavioural advertising, as that term is defined in the California Consumer Privacy Act as amended by the CPRA. We do not disclose it for monetary or other valuable consideration to anybody.
This is true of all categories of personal data described in Section 3, and it is true of the sensitive personal information described in Section 4. We do not use or disclose sensitive personal information for any purpose other than those permitted by Section 7027(m) of the CCPA regulations - namely, to provide you with the services you have requested and to keep you safe.
Because we do not sell or share personal data, there is no "Do Not Sell or Share My Personal Information" link on this Site. There is nothing to opt out of. If that ever changes, we will update this Policy, provide the required link, and give you the opportunity to opt out before any such use begins.
11. Who we disclose your data to
We disclose personal data only in the following circumstances.
- To our own staff and guides, on a strict need-to-know basis. Your guide sees the health and ability information relevant to keeping you safe. Our reservations team sees your booking. Nobody sees more than they need.
- To the service providers listed in Section 12, who process personal data on our behalf, under written contract, on our documented instructions, and for no purpose of their own.
- To medical, rescue and emergency personnel, where you are injured or incapacitated, in accordance with Section 4 and with the instruction you gave us in your profile.
- To your travel agent or trip organiser, where you booked through one, so that they can administer your trip.
- To our insurers, auditors, accountants and legal advisers, where necessary and under a duty of confidentiality.
- To public authorities, courts, or regulators, where we are legally required to do so, or where disclosure is necessary to establish, exercise or defend legal claims.
- To a purchaser or successor, if VHSG is ever sold, merged, or reorganised - in which case your data would transfer subject to this Policy, and we would tell you before it happened.
- We do not disclose your personal data to anyone else. We do not disclose it to advertisers, data brokers, or social media platforms, because we have no relationship with any of them.
12. Our service providers (processors)
We use a small number of carefully chosen providers to run the Site and our operation. Each of them acts as a "processor" (GDPR) or "service provider" (CCPA) - meaning they may only process your data on our instructions, for the purposes we specify, and may not use it for their own purposes. Each is bound by a written data processing agreement.
This is the complete list. There are no others.
| Provider | What it does for us | Data it processes | Location |
|---|---|---|---|
| Hostinger | Hosts the Site and its server infrastructure. | All data transiting the Site; server logs including IP addresses. | European Union (Lithuania) |
| Airtable | Our database of record. Stores guest accounts, profiles, bookings and the health information described in Section 4. | Account, contact, booking, travel, health, emergency contact, and ability data. | United States |
| Brevo | Sends our transactional emails (account activation, booking confirmations) and our newsletter. | Name and email address; newsletter consent record. | European Union (France) |
| Cloudinary | Stores and serves the optional profile photograph you upload. | Your profile photograph and its associated identifier. | United States |
| PandaDoc | Provides electronic signature of liability releases and trip documents. | Name, email, the contents of the documents you sign, and the signature audit trail. | United States |
| Zapier | Automates internal workflows between the systems above (for example, notifying our team of a new booking). | Booking and account data passing between systems. No health data is routed through Zapier. | United States |
13. International transfers of your data
We are based in Alaska, in the United States. If you are located in the European Economic Area, the United Kingdom, Switzerland, Brazil, or another jurisdiction with data-transfer restrictions, your personal data will necessarily be transferred to the United States, and to the providers listed in Section 12, in order for us to provide the Services you have asked for.
The laws of the United States may not offer the same level of protection as the laws of your own country, and in particular may permit access to data by public authorities in circumstances that differ from those in your jurisdiction. We want you to be aware of that.
Where such transfers take place, we rely on the following safeguards, as applicable:
- The European Commission’s Standard Contractual Clauses (and, for the United Kingdom, the UK International Data Transfer Addendum), incorporated into our contracts with providers located outside the EEA and the UK.
- The EU-US Data Privacy Framework, the UK Extension to it, and the Swiss-US Data Privacy Framework, where the provider concerned is certified under them.
- Article 49(1)(b) of the GDPR, where a transfer is necessary for the performance of the contract between you and us - which is the case, for example, when we transfer your booking to our own systems in order to give you the trip you have purchased.
- Your explicit consent, where you have given it, in relation to the health data described in Section 4.
- You may request a copy of the relevant safeguards by writing to jeff@tsaina.com.
14. How long we keep your data
We keep personal data only for as long as we need it, and then we delete it. Because heli-skiing carries an inherent risk of injury, and because claims can be brought long after a trip, some records must be kept for longer than you might expect. Our retention periods are set out below.
| Data | How long we keep it | Why |
|---|---|---|
| Member account and profile | For as long as your account is open, and for 12 months after you close it or after your last trip, whichever is later - unless a longer period below applies. | So that you do not have to re-enter everything if you come back, and so we can answer post-trip questions. |
| Health data | Deleted or anonymised within 12 months after your last trip, unless it is relevant to an actual or reasonably anticipated legal claim, in which case it is retained until that claim is resolved and the limitation period has expired. | It has no use to us once your trip is over - except where it is evidence in a claim concerning your safety. |
| Emergency contact data | Deleted at the same time as your profile, or sooner if you or your nominated contact ask us to remove it. | It has no purpose once you are no longer travelling with us. |
| Signed liability releases and trip contracts | Retained for the duration of the applicable statute of limitations for personal-injury and contract claims in the State of Alaska, and for a reasonable period thereafter (generally up to 7 years, and longer where a claim is pending or a guest was a minor at the time of the trip). | These documents exist precisely to be produced if there is a dispute. Deleting them early would defeat their purpose. |
| Booking and financial records | Retained for at least 7 years. | Tax, accounting and audit obligations. |
| Newsletter subscription | Until you unsubscribe, plus a record of your consent and of your unsubscription, retained as proof of compliance. | To demonstrate that we had your consent, and that we honoured your withdrawal of it. |
| Correspondence | Up to 3 years from our last exchange, unless it relates to a claim. | To maintain context if you write to us again. |
| Server logs | Short-term, as configured by our hosting provider (typically days to weeks). | Security and reliability. |
15. How we protect your data
We take the security of your data seriously, and in particular the security of your health data. The measures we apply include:
- Encryption in transit. The whole Site is served over HTTPS/TLS. Data travelling between your browser and our servers, and between our servers and our providers, is encrypted.
- Encryption at rest, as provided by our infrastructure and database providers.
- Passwords are never stored in readable form. They are hashed using a modern, deliberately slow one-way algorithm. We cannot read your password, we cannot recover it, and if you lose it we can only help you set a new one. That is by design.
- Access control. Only staff who need your data in order to do their job can reach it. Guides see what they need to keep you safe. Our team sees what it needs to run your trip.
- Data minimisation. We ask for the minimum we can while still running a safe operation, and we do not collect data "just in case".
- Vetted providers. We use a deliberately small number of established providers, each under a written data processing agreement, rather than a sprawl of tools.
- No unnecessary third parties. Because we run no analytics, no advertising and no tracking, your data is exposed to dramatically fewer parties than on a typical commercial website. The safest data is the data that was never collected or shared in the first place.
- No system is perfectly secure, and we cannot guarantee absolute security. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours where required, and we will notify you without undue delay where the breach is likely to result in a high risk to you. We will also comply with the breach-notification requirements of the Alaska Personal Information Protection Act and of any other applicable law.
16. Your rights - everyone
Wherever in the world you live, and regardless of whether your local law obliges us to, we will honour the following rights on request:
- The right to know what personal data we hold about you, and to receive a copy of it.
- The right to have inaccurate or incomplete data corrected.
- The right to have your data deleted, subject to the retention obligations in Section 14 - in particular, we cannot delete a signed liability release while it remains legally relevant, and we will tell you if that is the case.
- The right to withdraw consent, at any time, where our processing is based on consent - including your consent to our use of your health data, and your consent to our newsletter.
- The right to unsubscribe from our newsletter, instantly, using the link in every email we send, or by writing to us.
- The right to object to processing based on our legitimate interests, and to have us stop unless we have compelling grounds to continue.
- The right to have your data provided to you, or transferred to another controller, in a structured, commonly used, machine-readable format.
- The right to complain, to us and to a regulator.
- The right not to be discriminated against for exercising any of these rights. We will not deny you service, charge you a different price, or give you a lesser experience because you asked us to respect your privacy.
17. Your rights - European Economic Area, United Kingdom and Switzerland
If you are in the EEA, the UK or Switzerland, the GDPR, the UK GDPR or the Swiss Federal Act on Data Protection gives you the following rights, which we honour in full:
- Right of access (Article 15): to obtain confirmation of whether we process your data, and a copy of it, together with the information set out in this Policy.
- Right to rectification (Article 16): to have inaccurate data corrected and incomplete data completed.
- Right to erasure, the "right to be forgotten" (Article 17): to have your data deleted where it is no longer necessary, where you withdraw consent and there is no other basis, where you object and there are no overriding grounds, or where it has been processed unlawfully.
- Right to restriction of processing (Article 18): to have us pause processing while a dispute about accuracy or legitimacy is resolved.
- Right to data portability (Article 20): to receive the data you gave us in a machine-readable format, and to have it transmitted to another controller where technically feasible.
- Right to object (Article 21): to object at any time to processing based on legitimate interests, and absolutely to object to direct marketing.
- Right to withdraw consent (Article 7(3)): at any time, without affecting the lawfulness of processing before withdrawal.
- Right not to be subject to automated decision-making (Article 22): we do not carry out such decision-making, as explained in Section 9.
- Right to lodge a complaint with a supervisory authority (Article 77): with the data protection authority of the country where you live, where you work, or where the alleged infringement took place. In the UK, this is the Information Commissioner’s Office (ico.org.uk). In Switzerland, it is the Federal Data Protection and Information Commissioner. In the EEA, a list of national authorities is maintained by the European Data Protection Board (edpb.europa.eu). We would ask you to raise the matter with us first, so that we can try to resolve it - but it is your right to go straight to the regulator, and we will not hold it against you.
18. Your rights - California
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you the rights set out below. We honour them in full.
- Right to know: to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collecting it, and the categories of third parties to whom we disclose it. All of that is set out in Sections 3, 6, 7, 11 and 12 of this Policy, and we will confirm it individually on request.
- Right to delete: to request that we delete personal information we have collected from you, subject to the exceptions permitted by law - notably where we must retain it to complete a transaction, to comply with a legal obligation, or to establish or defend a legal claim (see Section 14).
- Right to correct: to request that we correct inaccurate personal information.
- Right to opt out of sale or sharing: we do not sell your personal information, and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. See Section 10.
- Right to limit the use of sensitive personal information: your health data is "sensitive personal information" under the CPRA. We use it only for the purposes described in Section 4 - purposes which are permitted without a right to limit, because they are necessary to perform the services you requested and to ensure your physical safety. We do not use it to infer characteristics about you, and we do not use it for any secondary purpose.
- Right to non-discrimination: we will not deny you goods or services, charge you a different price, or provide you a different level of quality because you exercised a privacy right.
- Shine the Light (California Civil Code section 1798.83): California residents may request information about disclosures of personal information to third parties for their direct marketing purposes. We make no such disclosures.
- You may exercise these rights by writing to jeff@tsaina.com, or by calling us on +1 (913) 530-5688. We will verify your identity before responding, using the information already in your account. You may use an authorised agent, provided they give us written proof of your authorisation.
- We will respond within 45 days, extendable by a further 45 days where reasonably necessary, and we will tell you if we need the extension.
19. Your rights - other United States states
Residents of Utah, Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and other states with comprehensive privacy legislation in force have rights broadly equivalent to those described above: the right to confirm whether we process their data and to access it, the right to correct it, the right to delete it, the right to obtain a portable copy, and the right to opt out of targeted advertising, of the sale of personal data, and of profiling with legal or similarly significant effects.
We do not conduct targeted advertising. We do not sell personal data. We do not carry out profiling with legal or similarly significant effects. Accordingly, those opt-out rights have no application to us - but the access, correction, deletion and portability rights do, and we honour them in full for residents of every state, whether or not the state in question has yet enacted such a law.
Where your state gives you a right to appeal our refusal of a request, you may appeal by writing to jeff@tsaina.com with the words "Privacy Appeal" in the subject line. We will respond within the period your state law requires, and if we again decline, we will tell you how to contact your state Attorney General.
20. Your rights - Brazil, Canada, Australia and elsewhere
If you are in Brazil, the Lei Geral de Proteção de Dados (LGPD) gives you the right to confirmation of processing, access, correction, anonymisation or deletion of unnecessary or excessive data, portability, information about with whom your data has been shared, information about the consequences of refusing consent, revocation of consent, and the right to petition the Autoridade Nacional de Proteção de Dados (ANPD). We honour all of these. Our legal bases under the LGPD mirror those set out in Section 7, and our processing of health data relies on your specific and highlighted consent (LGPD Article 11(I)) or, in an emergency, on the protection of life or physical safety (Article 11(II)(e)).
If you are in Canada, PIPEDA gives you the right to access your personal information, to challenge its accuracy, and to complain to the Office of the Privacy Commissioner of Canada. We honour these rights.
If you are in Australia, the Privacy Act and the Australian Privacy Principles give you the right to access and correct your personal information and to complain to the Office of the Australian Information Commissioner. We honour these rights.
If you are somewhere not named in this Policy, write to us anyway. Our practice is to extend the same rights to every guest, regardless of where they live, because we think that is how it should work.
21. How to exercise your rights
Write to jeff@tsaina.com. Tell us what you want, and give us enough information to find you - the email address on your account is usually sufficient.
We will verify your identity before we act, because the greatest privacy risk in any rights process is disclosing someone’s data to the wrong person. Verification is normally straightforward: we will ask you to write from the email address on your account, and we may ask you to confirm details we already hold. For requests concerning health data, we may ask for a higher standard of verification, because the consequences of getting it wrong are more serious.
We will respond within one month (GDPR), or within 45 days (CCPA and most US state laws), and we will tell you if we need to extend that period - which we may do by up to two further months (GDPR) or 45 days (CCPA) where a request is complex.
Exercising your rights is free. If a request is manifestly unfounded or excessive - in particular because it is repetitive - we may charge a reasonable fee or refuse to act, but we will explain why, and we will tell you how to challenge that decision.
You may also manage a great deal yourself, without writing to anyone: you can view and edit your profile, including your health information, from your member account at any time; and you can unsubscribe from our newsletter using the link at the bottom of every email.
22. Children
The Site is not directed to children, and we do not knowingly collect personal data from anyone under the age of 13, in accordance with the Children’s Online Privacy Protection Act (COPPA). We do not knowingly collect personal data from anyone under 16 in the EEA and the UK without the consent of a parent or guardian, in accordance with Article 8 of the GDPR.
Minors do ski with us, but they do so as part of a family or group booking made by an adult. Where a minor is to take part in a trip, their information - including their health information - is provided to us by their parent or legal guardian, who signs their liability release and consents to our processing of their data on their behalf. We do not permit minors to create their own member accounts.
If you believe that we hold personal data concerning a child that was provided without the necessary parental consent, write to jeff@tsaina.com and we will delete it promptly.
23. Third-party links and changes to this Policy
The Site contains links to third-party websites - the sites of equipment manufacturers we recommend, of the partners we work with, of media that have written about us, and of social media platforms where our guests post. Following such a link takes you outside our Site, and this Policy no longer applies. We do not control those sites, and we are not responsible for their privacy practices. Read their policies.
We may update this Policy from time to time - for example, if we change a service provider, or if the law changes. When we do, we will change the "effective date" at the top of the page. If the change is material - if it affects your rights, or if it changes what we do with your data in a way you would not expect - we will tell you before it takes effect, by email if we have your address, and we will obtain your consent afresh where the law requires it.
We keep previous versions of this Policy and will provide one on request.
24. Contact us, and how to complain
If you have any question about this Policy, about what we hold, or about how we behave - ask us. We would much rather have the conversation.
Privacy matters: jeff@tsaina.com
General enquiries: sonya@vhsg.com
Telephone: +1 (913) 530-5688
Post: Valdez Heli-Ski Guides, HC-1 Box 85, Valdez, Alaska 99686, United States of America
If you are not satisfied with our response, you have the right to complain to your data protection regulator - the supervisory authority in your EEA member state, the Information Commissioner’s Office in the United Kingdom, the ANPD in Brazil, the Office of the Privacy Commissioner in Canada, your state Attorney General in the United States, or the equivalent authority where you live. We will not retaliate, and it will not affect your trip.
Related documents