Privacy policy
Last updated: 26 September 2026
This policy explains which personal data Abysso Run processes, why, who it is shared with and what your rights are. It is based on the Swiss Federal Act on Data Protection (FADP) and, for people living in the European Union, on the General Data Protection Regulation (GDPR).
Who is responsible for your data?
Abysso Run, a sole proprietorship of Salim Ali, registered in Geneva, Switzerland.
Contact for any question about your data: abyssorun@gmail.com
What data we process
Your spot request. The website form does not store anything on our servers: it prepares a message that you send yourself via WhatsApp. This message contains the information you entered: first name, last name, email, phone, chosen package, running level and goal, dates and number of people (Private package), comments and your choice regarding photos.
Our conversations by WhatsApp and email.
Your registration and trip: the information needed to organise it, for example your identity as shown on your passport (bookings, flights in the Full Service package), an emergency contact, your dietary requirements, and any health information you choose to share with us for your safety at altitude. Health information is sensitive data: we only process it with your consent and solely for your safety.
Payments and invoicing: amounts, dates and payment references.
Photos and videos taken during the trip.
Technical data when you visit the website (see “Website” below).
Why we use it
To answer your request and check that the trip matches your level (pre-contractual steps).
To organise and deliver your trip, and to invoice it (performance of the contract).
To meet our legal obligations, in particular keeping accounting records (legal obligation).
To use photos or videos in which you appear for Abysso Run's communication (website, social media), only if you have given your consent, which you can withdraw at any time (consent).
To keep the website running and secure (legitimate interest).
We never sell your data and do not use it for advertising.
Who we share it with
Only when necessary:
Our providers in Ethiopia (accommodation, transport, local guiding), to organise your trip.
Airlines and, where applicable, the authorities responsible for visas, in the Full Service package.
Our communication and hosting tools: WhatsApp (Meta), Gmail (Google), the website host Netlify and the domain name service Cloudflare.
Authorities, when required by law.
International transfers
Some data is processed outside Switzerland. Transfers to Ethiopia are necessary to perform your travel contract. Providers based in the United States (Meta, Google, Netlify, Cloudflare) are subject to appropriate safeguards, such as the Swiss-U.S. Data Privacy Framework where they are certified, or standard contractual clauses.
Website
No advertising cookies or audience measurement tools are used on this website.
Your language choice (French or English) is stored only in your browser, so you don't have to choose again on each visit.
Like any host, Netlify records technical connection data (IP address, browser type, date and time) to keep the website running and secure.
Fonts are loaded from Google Fonts servers, which means your IP address is sent to Google.
How long we keep it
Requests that do not lead to a booking: deleted no later than 12 months after our last exchange.
Participants: for as long as needed to organise the trip and follow up on your file. Accounting records (invoices, payments) are kept for 10 years, as required by Swiss law.
Health information: deleted after the trip, unless it is needed to handle an incident.
Photos and videos used for communication: until you withdraw your consent. Content already published cannot always be removed everywhere.
Your rights
You can at any time request access to your data, its correction or deletion, a copy of your data, or withdraw a consent you gave (for example for photos). If you live in the European Union, you can also object to certain processing or ask for it to be restricted.
Write to us at abyssorun@gmail.com: we normally reply within 30 days.
You can also contact the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, in the European Union, the data protection authority of your country.
Security
We limit access to your data to the people and providers who need it, and use secure services (encrypted HTTPS connection, protected accounts).
Changes
This policy may be updated, for example when our services change. The date of the last update is shown at the top of this page.