Privacy Policy
Effective date and last updated: 6 April 2026.
1. Who We Are (Data Controller)
The data controller of your personal data is the sole trader Powerella from Bosnia and Herzegovina. We manage the website powerellapilgrim.com and are responsible for the security of the data you entrust to us.
Contact for all privacy inquiries: info@powerellapilgrim.com
2. What Data We Collect, Why, and on What Basis
A. Newsletter Subscription
- We collect: Your email address and your selected language preference (hr/en/es).
- Purpose: Sending notifications about new texts, pilgrimages, and products.
- Legal basis: Your explicit consent.
- Details: You may unsubscribe at any time by clicking the link at the bottom of any email.
B. Pilgrimage Registration
- We collect: First name, last name, email, phone, date of birth, city, and country. Optionally we collect the name of a roommate and your notes. For gift registrations, we collect the recipient's contact details, a personal message, and a surprise date.
- Purpose: Organizing the pilgrimage, communicating with participants, and sending instructions and payment details.
- Legal basis: Performance of a contract (fulfillment of the service for which you are registering).
C. Website Analytics (Google Analytics)
- We collect: Anonymized data about your visit (pages you read, duration of visit, device type, country).
- Purpose: Understanding how visitors use the site so we can improve its content.
- Legal basis: Your explicit consent (via the Cookie banner).
3. Data Recipients and International Transfers
We do not sell or share your data with unauthorized third parties. We process data on our private server, and for specific functionalities we use trusted partners:
- Amazon Web Services (AWS SES, USA): We use them exclusively for reliable delivery of transactional and newsletter emails. AWS applies Standard Contractual Clauses (SCC) as the legal mechanism for data transfers to the USA, ensuring compliance with GDPR.
- Google LLC (USA): If you consent to analytics cookies, anonymous data is sent to Google Analytics 4. The transfer is also based on Standard Contractual Clauses.
4. How Long We Retain Data
- Newsletter addresses: We retain them only until you withdraw your consent or unsubscribe from the list. After unsubscribing, your address is deleted.
- Pilgrimage data: Operational data (such as notes and roommate information) is deleted no later than 30 days after the pilgrimage ends. Data related to payments and invoices must be retained for up to 11 years in accordance with accounting regulations.
- Analytics: Data in Google Analytics is automatically deleted after 14 months.
- Cookie consent: The record of your decision (Cookie consent) is stored for 365 days on your device.
5. Cookies
We use Google Consent Mode v2. By default, all non-essential cookies are blocked until you give your consent.
- Necessary cookies: The site sets a cookie
cookie_consentthat remembers your privacy decision. Without it, the site cannot technically remember your settings. - Analytics cookies: Google Analytics cookies (e.g.
_ga) are activated only if you click "Accept" in the cookie notice. - Marketing cookies: Currently not in use, but our platform supports managing them if we introduce them in the future.
You can change your cookie settings at any time by clicking the "Cookie Settings" link in the footer of this website.
6. Your Rights
Under the General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:
- Right of access: You may request a copy of all data we hold about you.
- Right to rectification: You may request the correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): You may request the deletion of your data if it is no longer necessary for us to fulfill the contract or a legal obligation.
- Right to restriction of processing and data portability: You may request a temporary suspension of processing or the transfer of data to another controller.
- Right to withdraw consent: You may withdraw your consent for the newsletter or analytics at any time without any negative consequences.
You may exercise all rights by sending a request to info@powerellapilgrim.com. We will respond to you as soon as possible, and no later than within 30 days.
7. Right to Lodge a Complaint with a Supervisory Authority
If you believe that your data is being processed in violation of regulations, you have the right to lodge a complaint with the competent data protection authority in your country of residence or the country in which the business is established (Personal Data Protection Agency).
8. Changes to This Policy
We reserve the right to amend this Privacy Policy. In the event of significant changes that affect your rights (e.g., the introduction of new processing tools), we will notify you via email or a prominent notice on the website before the changes take effect.