This notice explains how Simien Ethio Tours, trading online as Gondar Simien Tours, handles personal information provided through this website.
Who is responsible
The data controller is Simien Ethio Tours, Fasil Castle Street, Gondar, Ethiopia. Privacy questions and requests can be sent to info@simienethiotours.com.
Journey-planning inquiries
The planner collects your name, email address, message, and any optional travel dates, group size, interests, trip duration, accommodation preferences, night counts, or budget guidance you provide. We use this information to answer your request and prepare a possible journey proposal.
Delivery is attempted in this order: first, the inquiry is sent to our backend and stored in the contact database. The backend may also send a notification through our configured email service. If the contact service fails, the website may send the inquiry to a configured secure webhook. If neither service accepts it, the site asks your browser to open a prepared message in your own email application. In that last case, your email provider—not this website—sends and stores the message.
Newsletter subscriptions
If you subscribe, we store the email address you submit and the subscription date so the operator can manage requested updates. A duplicate submission does not create another record. The address remains stored until you withdraw or ask us to delete it. Until self-service unsubscribe is available, email info@simienethiotours.com from the subscribed address.
AI travel assistant
When the assistant is enabled, we store the messages you send, its replies, a random conversation identifier, message and token counts, and a one-way HMAC hash of your IP address. The hash helps enforce usage limits without storing the raw IP address in the chat session. Your browser keeps the conversation identifier only in the current page session; it is not placed in local storage or a cookie.
To produce a reply, recent conversation messages and relevant public catalogue content are sent to the configured AI provider, currently supported through Google Gemini or OpenAI. Do not enter passport, payment, medical, or other sensitive information in the assistant. The assistant provides general travel information and does not confirm bookings or make decisions about you.
Necessary cookies and technical records
The site uses a NEXT_LOCALE session cookie to keep the selected language. The private admin area uses an admin_session cookie for authentication. It is HTTP-only, SameSite=Lax, secure in production, and cleared on logout; the signed session has a configured validity period of seven days by default. These cookies are necessary for language or security functions and are not advertising cookies.
Hosting and security systems may record IP address, browser information, timestamps, requested pages, and error or request logs to operate, protect, and diagnose the service. This application does not install advertising trackers or analytics cookies.
Service providers and transfers
Information may be processed by vendors used for website hosting, database hosting, email delivery (SMTP or Resend), a configured contact webhook, and the enabled AI provider. Their processing locations and retention may differ by the production services selected. We require the production configuration and provider terms to be reviewed before launch.
How long information is kept
- Stored planner inquiries are eligible for automatic deletion after 730 days.
- Assistant sessions, their messages, and associated hashed IP are eligible for automatic deletion 30 days after the conversation was last active.
- Newsletter addresses remain until withdrawal or deletion.
- Aggregate daily assistant usage totals contain no transcript, session identifier, or IP hash and may be retained for service monitoring.
- Hosting, email, and webhook copies follow the configured provider’s reviewed retention settings.
Information may be retained longer where reasonably required to establish, exercise, or defend legal claims or meet an applicable legal obligation.
Your choices and requests
You may ask whether we hold information about you and request access, correction, deletion, or withdrawal from the newsletter by emailing info@simienethiotours.com. We may ask for enough information to verify that the request relates to you. Applicable law may permit or require us to retain some information. You may also use the same address to raise a concern about how your information is handled.
Please do not include passport numbers, payment-card details, medical records, or other sensitive information in an initial planner inquiry, newsletter form, or assistant conversation.
Effective and last updated: 12 September 2026.