Privacy Policy
This text has not yet been reviewed by legal counsel and still contains placeholders marked [TO BE CONFIRMED: …]. It must not be linked from an app store listing until those are filled in and the document is approved.
1. Who we are
Numero Chip (previously named Loenvi) is a participant-tracking system for tour operators. Two companies are involved in it, and it is worth being clear about which does what, because you will see both names.
Konik d.o.o. operates the Numero Chip service. It is the company your tour operator contracts with, it runs the servers your data is held on, and it is the company to contact about your data.
Kaudata d.o.o. makes the software. It develops the Numero Chip apps and platform and licenses them to Konik, and it is the publisher listed on the App Store and Google Play — so the developer name you saw when you installed the app is Kaudata, not Konik. It also holds the cloud account the service runs in and supports it technically, which means it can reach your data and is therefore a sub-processor — see section 2.1. What it cannot do is decide anything about your data; it acts on Konik’s instructions.
| Konik d.o.o. | Kaudata d.o.o. | |
|---|---|---|
| Role | Service provider — operates Numero Chip for tour operators | Software supplier and sub-processor — builds and licenses the software, holds the hosting account, supports the live service; publisher of the apps on the App Store and Google Play |
| Registered address | Troblje 1, 2380 Slovenj Gradec, Slovenija | Kidričeva cesta 2B, 3320 Velenje, Slovenija |
| Registration number (matična številka) | 5304245000 | 8948925000 |
| VAT ID (davčna številka) | SI 39895874 | SI 76817008 |
| Contact | trgovina@konik.si — a monitored mailbox operated by Konik, the company that holds the data. It is one address for everything: privacy and data-protection questions, deletion requests, and general enquiries about the service all arrive here. | |
| Data Protection Officer | None appointed. Neither company meets the GDPR Art. 37 threshold that makes one mandatory. Data-protection matters go to trgovina@konik.si — see section 15. | |
In this policy, “we”, “us” and “Konik” mean Konik d.o.o., the company that operates the service. “Kaudata” means Kaudata d.o.o., and is used only where the statement is actually about the software supplier. “The app” means the Numero Chip mobile application used by tour guides. “Tour company” means the tour operator that employs or engages a guide and that buys the Numero Chip service.
2. Who is responsible for your data
This matters more here than in a typical app, because the people whose data the app shows — tour participants — are not the people using it.
| Data | Controller — decides why and how | Konik’s role | Kaudata’s role |
|---|---|---|---|
| Tour participant records (name, phone number, tag assignment) | The tour company | Processor — stores and transmits them on the tour company’s instructions | Sub-processor — holds the hosting account the system runs in, and supports it |
| Guide accounts (email, name, sign-in and session records) | The tour company | Processor — the tour company creates, administers and closes these accounts | Sub-processor, same role |
| Tour activity and detection records | The tour company | Processor | Sub-processor, same role |
| Konik’s own service records: account-deletion requests, support correspondence, security and abuse logs, the contract with the tour company | Konik | Controller | None |
The tour company decides what participant data goes into the system, why, and for how long. Neither Konik nor Kaudata chooses those purposes, and neither uses participant data for anything of its own. Participants are the tour company’s customers; the tour company is responsible for informing them and for obtaining any consent or other lawful basis at the time of booking. If you are a participant and want to know why your details are in a tour operator’s system, ask that operator first — but you can also contact us (section 15) and we will pass the request on.
2.1 Where Kaudata sits in the chain
Kaudata is a sub-processor. We say that plainly because it is the paragraph a data-protection audit goes straight to, and because the alternative description — a licensor that writes code and never touches the running system — would not be true here.
Kaudata does two things. It writes the software, which on its own would not make it a processor of anybody’s data. It also holds the cloud account the service runs in, which does: whoever owns the hosting account can reach the production system, and therefore the personal data inside it. Add the technical support Kaudata provides on the live service and the position is unambiguous. Under GDPR Art. 28(4) it is a sub-processor engaged by Konik, not a supplier standing outside the chain.
What that does not change: Kaudata decides nothing. It does not choose why your data is held, what is collected or how long it is kept — those are the tour company’s decisions, carried out by Konik. Kaudata may use production data only to run, maintain and support the service on Konik’s documented instructions, and for nothing of its own.
The relationship is governed by written agreements at both levels: a data-processing agreement under GDPR Art. 28 between Konik and each tour company, and a back-to-back sub-processing agreement between Konik and Kaudata that binds Kaudata to the same obligations Konik owes the tour company. [TO BE CONFIRMED: both must be signed before publication — the operator DPA and the Konik–Kaudata sub-processing agreement. The Kaudata role described above is settled and is not what is open here; only the signatures are.]
Tour companies are told who the sub-processors are, and can object. Each tour company receives the current list of sub-processors as part of its Art. 28 agreement, and we give notice before adding or replacing one. A tour company that objects to a new sub-processor on reasonable data-protection grounds can raise it with us; if we cannot resolve it, it may terminate the affected part of the service rather than be bound by a change it did not accept. Kaudata is on that list today, in the role described above.
3. What the app collects, and why
3.1 Guide account data
A guide cannot sign up in the app. There is no registration screen. Accounts are created by the tour company in its own web dashboard, and the tour company supplies the details. We hold:
- Email address — the sign-in identifier, and where password-reset links are sent.
- Name and display name — so operators and colleagues can tell guides apart.
- Password — stored only as a salted hash. We never see or store the password itself.
- Role and company access — which tour company the account belongs to and what it may do.
- Session records — a session token, its expiry, and the IP address and device/browser identifier (user agent) that the session was created from. This is what keeps you signed in and what lets an administrator revoke access from a lost phone.
3.2 Tour participant data
Participant records are entered or imported by the tour company, never by the app. The app receives, for each participant on a tour a guide is assigned to:
- First name and last name — so the guide can see who is missing and call them by name.
- Phone number — so the guide can contact a missing participant directly.
- The identity of the wristband tag assigned to that person.
The tour company’s own records may hold more than this (for example an email address or a note); the phone bundle deliberately carries only the fields above.
3.3 Bluetooth detection events
The app listens for the short-range Bluetooth signal broadcast by each wristband. A detection tells the app one thing: this tag is within radio range of this phone right now. It is a yes/no presence signal. It is not a position, not a coordinate, not a direction and not a distance measurement, and it says nothing about where the phone or the wristband is in the world.
3.4 In-app activity records
The app sends a record of what happened during a tour to the tour company’s own Numero Chip backend, so the operator has an accurate account of each tour. These records include: when scanning started and stopped, when a tag was detected, when a guide marked someone as found manually, when a guide called a participant, when a tag was assigned, when a tour was opened, and when offline data was synced. Each record carries a timestamp, the tour, the guide and the tour company.
Where a record concerns a particular participant — that a guide marked someone found, or called a missing participant — it identifies that person by the internal reference the tour company’s own records use, and not by name or phone number. The app does not put them in the record; the name the guide sees on screen is read from the participant list already held for that tour and is not copied into the activity record. The server also removes any such field if an older version of the app sends one, so it cannot be stored either way. These records go only to the tour company’s own backend, operated by Konik. They are never sent to an analytics provider, an advertising network or any other third party.
No location, no GPS coordinates, no advertising identifier, no device fingerprint, no contact list, no photos, no microphone or camera access, no health data, no payment data. The app asks for none of these and holds none of them.
4. Bluetooth and the Android location permission
The app needs permission to use Bluetooth, because Bluetooth is how it finds wristbands. What it asks for differs by platform.
4.1 iOS
The app requests Bluetooth permission only. It does not request location permission on iOS, and it must not — on iOS, Bluetooth scanning and location are separate permissions and the app has no use for the second one.
4.2 Android — why a location permission appears
On Android the app requests the Bluetooth scanning permissions, and on older
Android versions (Android 11 and earlier) it must also request
ACCESS_FINE_LOCATION.
This is an Android platform requirement, not something the app wants. Until Android 12, Google’s Bluetooth API refused to return any scan results at all unless the app held a location permission — the reasoning being that a list of nearby Bluetooth devices could in principle be used to infer where you are. Android 12 introduced dedicated Bluetooth permissions and removed the coupling, which is why newer devices do not show this prompt.
Numero Chip never accesses your location. Concretely, and verifiably:
- The app contains no location, GPS or geolocation code. It never calls the Android location APIs.
- No coordinate, no address, no place name and no location estimate is ever computed, displayed, stored on the phone, or sent to any server.
- The permission is requested for one reason only: so that the operating system will let the app receive Bluetooth scan results.
- You can verify this from the outside: the app declares no location data in its App Store and Google Play data disclosures, and the server has no field to put a location in.
[TO BE CONFIRMED: whether the Android manifest ships the
neverForLocation flag on BLUETOOTH_SCAN, which formally
declares to Android that scan results are not used to derive location. This depends on
hardware testing that is still outstanding — see the compliance notes. Update this
paragraph to match what actually ships.]
4.3 What a Bluetooth detection does and does not reveal
- It does reveal: that a specific wristband was in radio range of a specific guide’s phone at a specific time, and roughly how strong the signal was.
- It does not reveal: where either of them was, which direction the wristband is in, how the person moved, or anything about the person wearing it beyond the fact of presence.
- Radio range is short — a few tens of metres at most, and less through walls, bodies and terrain. Losing the signal is a normal and frequent event and does not mean anything has happened to anyone.
- The wristband is a passive broadcast beacon. It contains no personal data, does not record anything, and does not know who is wearing it. The link between a wristband and a person exists only in the tour company’s records.
5. The offline cache on the phone
Guides work where there is no signal, so before a tour the app downloads that tour’s participant list and keeps it on the phone. The cached bundle holds the tour details plus each participant’s first name, last name, phone number and tag identity.
- It is stored in the app’s private storage area, which the operating system keeps separate from other apps on the device. The app does not add its own encryption on top; it relies on the encryption iOS and Android apply to device storage, which is why the screen lock below matters.
- It expires automatically. The tour company sets the offline window per tour — the default is 48 hours from the tour’s start time. Once the window closes, the app deletes the bundle the next time it tries to read it.
- Activity records created while offline are queued on the phone and sent to the server when connectivity returns, then cleared from the phone.
- Signing out erases it. An explicit sign-out removes every cached tour and the queued activity records from the phone, so a handset passed on, sold or sent for repair does not carry the previous guide’s participant list.
- A guide can also clear cached tours from within the app.
- The cache can be opened without signing in. The app has a “work offline” route that reaches it with no password. That is deliberate: a guide whose session has expired, in a place with no signal, has to be able to reach their group. It means the phone’s own lock is what protects the cache.
Because a phone can be lost, and because the two points above put the weight on the device itself, we ask tour companies to require a screen lock on any device running Numero Chip, and to keep offline windows as short as their operations allow. Device storage encryption on iOS and Android only takes effect where a passcode is set.
6. What we do not do
These are absolute statements about the product as built, not aspirations:
- We do not sell personal data. Not to anyone, ever, in any form.
- There is no advertising in the app, and no advertising or attribution SDK in it.
- There is no third-party analytics or crash-reporting SDK. No Google Analytics, no Firebase, no Facebook SDK, no Sentry, no attribution or A/B-testing tool.
- We do not track you across apps or websites, and we do not use the device advertising identifier. The app does not show Apple’s tracking prompt because it does not track.
- We do not build profiles of guides or participants, and there is no automated decision-making with legal or similarly significant effects.
- We do not collect location data — see section 4.
- We do not use participant data for our own purposes, including improving or training anything.
Activity and detection records exist so the tour company can see what happened on its own tours. They are not a product analytics pipeline, and they do not leave the tour company’s backend.
7. Legal bases
Under the GDPR:
- Guide accounts — processed on the tour company’s instructions so that its staff can do their job. The tour company relies on its employment or engagement relationship with the guide and on its legitimate interest in running its tours safely (Art. 6(1)(b) and 6(1)(f)).
- Participant data — the tour company determines the basis. In practice it is normally performance of the booking contract (Art. 6(1)(b)) together with the operator’s legitimate interest and duty of care in keeping its groups together (Art. 6(1)(f)); in an emergency, protection of vital interests may also apply (Art. 6(1)(d)). Ask your tour operator which basis it relies on — it is their determination, not ours.
- Our own records (deletion requests, support, security logs) — our legitimate interest in operating and securing the service and in being able to show we honoured a request, and where applicable our own legal obligations (Art. 6(1)(f) and 6(1)(c)).
The app processes no special categories of personal data under Art. 9.
8. How long data is kept
| Data | Kept for |
|---|---|
| Offline tour bundle on the phone | The tour’s offline window — 48 hours from tour start by default. Deleted automatically after that, and erased when the guide signs out. |
| Queued activity records on the phone | Until the next successful sync, then deleted from the device. Also erased when the guide signs out. |
| Sign-in sessions | Until they expire, until sign-out, or until an administrator revokes them — whichever comes first. |
| Guide account | For as long as the tour company keeps the account open. See section 9. |
| Participant identifiers — first name, last name, phone number, email address and any free-text note held about the person | 24 months after the tour ends, then redacted. All five fields are overwritten in place; the record itself is not deleted. Where a tour has no end date the clock runs from its start date, which can only bring the redaction forward. |
| The rest of the participant record — which tag was assigned, presence and detection events, head counts | Kept indefinitely, without the identifiers. See the explanation below. |
| Tour activity and detection telemetry (what the app reported during a tour) | Kept indefinitely. It carries no direct identifiers: the app does not send names or phone numbers, and the server strips any that arrive, so they are never stored in it. |
| Administrative audit log (who changed what) | Retained. It is the record of who did what to the operator’s data, and it would not do its job if it expired. Pseudonymised when an account is erased — see section 9. |
| Account-deletion requests | 24 months, as the record that a request was made and honoured. |
8.1 Why the participant record splits in two
Two different needs pull in opposite directions here, so the record is split rather than forced to satisfy both.
The identifying part goes. A participant’s name, phone number, email address and any note held about them are useful for exactly one thing — reaching that person, or telling them apart from someone else, while the tour is running. That usefulness expires. Twenty-four months after the tour ends those fields are redacted: overwritten in the record itself, not moved somewhere quieter. After that no one, including us and including the tour company, can tell from the system who the participant was.
The rest stays. What survives is the shape of what happened: that a tag was assigned to a participant, that the participant was detected at these moments and missing at those, how many people the group held. Stripped of the identifying fields it is no longer personal data about anyone — you cannot work backwards from “participant 4 of 23 was marked missing at 14:12” to a person.
That is what makes keeping it indefinitely defensible rather than hoarding. A tour operator needs to be able to reconstruct a tour years later — an insurance claim, an incident investigation, a regulator or a court asking what happened on a particular day. Deleting the anonymised record would destroy that ability, and it would do so without protecting anyone, because by then there is no one identifiable left in it. Deleting only the identifiers protects the participant and leaves the operator its audit trail. Storage limitation under GDPR Art. 5(1)(e) is a limit on keeping people identifiable, not a rule against remembering that something happened.
The same reasoning applies to the telemetry the app sends back during a tour. It is kept indefinitely, and it never contains a name or a phone number in the first place: the app does not send them, and the server removes any such field as the records arrive, before anything is written down. There is nothing there to expire. It also means that once a participant’s details are redacted at 24 months, the activity records that point at them become anonymous on their own — there is no second copy of the name anywhere to go and find.
The tour company remains the controller for participant data and may instruct us to delete it sooner. The periods above are what the service does by default.
9. Deleting an account and its data
Numero Chip is a tool bought by a tour company for its staff, like a company email account. The tour company creates guide accounts, assigns them to tours, and closes them. For that reason a guide cannot delete their own account from inside the app: the account is the tour company’s record, it is attached to that company’s tour history, and deleting it unilaterally mid-season would remove the operator’s record of who was responsible for a group.
That does not remove your right to have your personal data erased. There are two routes, and both end in erasure:
- 1Ask your tour company. An administrator can delete a guide account immediately from the web dashboard. This is the fastest route.
- 2Submit a request to us directly at the account and data deletion page. You do not need your employer’s permission to use it, and you do not need to be able to sign in.
We acknowledge requests within 72 hours and complete them within 30 days of verifying who you are, in line with GDPR Art. 12(3). You get an email confirmation when it is done. The full process, including what happens if your tour company objects, is set out on that page.
9.1 What is erased
- Your user record — email address and name.
- Your credentials, including the stored password hash.
- All your sign-in sessions, which signs you out on every device immediately.
- Your company access permissions.
- Your name on your guide profile, which is replaced with a non-identifying pseudonym.
- Your email address wherever it appears in administrative log entries — including entries written before you were identified, such as a failed sign-in attempt — which is overwritten with a pseudonym unique to your former account, at a domain that can never receive mail (
deleted.numerochip.com), so nothing can be sent to it, by us or by anyone else.
What replaces you is a pseudonym, not a blank. Your name and email are overwritten with a label that is stable for your former account and different from every other account’s. The audit history therefore still shows that one particular person made a change, and that a second change was made by someone else — it just no longer says who either of them is.
That distinction matters both ways. Replacing every erased account with the same “deleted user” would silently merge separate people into one, which would make the operator’s record of who was responsible for what wrong rather than merely anonymous. Keeping the pseudonym stable avoids that. It does not keep you identifiable: the personal data it stood for — your name, your email address, your credentials — has been erased, so there is nothing left in the system to match the label back to.
9.2 What is kept, and why
- Tour history in non-identifying form. The record that a tour ran, and that a guide was assigned to it, survives — with your name and email removed. Tour operators need to be able to reconstruct what happened on a tour, including for insurance and incident purposes, and that need does not disappear when you leave.
- Participant data. This is not yours to delete — it belongs to the tour company’s records about its own customers. Deleting your account does not delete it.
- The record of your deletion request itself, so we can demonstrate we honoured it.
- Anything we are legally required to keep. If that applies, we will tell you what and why, and delete it when the obligation ends (GDPR Art. 17(3)).
10. Children
The app is not for children. Its users are working tour guides. It has no sign-up, no social features, no user-generated content and no advertising.
Participants, however, may be children — family holidays and school trips are exactly the situations where keeping a group together matters most. Where a group includes minors, their name, phone number (usually a parent’s or teacher’s) and wristband assignment are handled the same way as any other participant’s, with no additional collection and no profiling.
The tour company is the controller for that data and is responsible for the lawful basis, including any parental consent or authorisation required under GDPR Art. 8 and national law. Consent is obtained by the tour company at booking, not by Konik and not in the app — a child never installs Numero Chip, never sees a screen and never interacts with it. Konik processes the data only on the operator’s documented instructions.
If you are a parent or guardian and want to know what a tour operator holds about your child, contact that operator; you may also write to us and we will route the request to them without delay.
11. Who else touches the data
We do not share personal data with third parties for their own purposes. We use a small number of suppliers to run the service:
| Supplier | Purpose | Location |
|---|---|---|
| Cloud infrastructure provider | Hosting the application servers and the database, and the object storage that holds the signed agreements filed against a tour company’s record. The account with it is held by Kaudata, on the row below. | Within the European Union |
| Kaudata d.o.o. — sub-processor | Building and maintaining the software; holding the hosting account the service runs in; technical support on the running service — see section 2.1 | Slovenia (EU) |
| Apple and Google | Distributing the app. They collect their own data about downloads under their own privacy policies; they receive no personal data from us. | Per their own terms |
There is no third-party email provider. Password-reset links, verification links and confirmation messages are sent from the service’s own mail infrastructure, on the same European hosting as the application servers. No mail service, marketing platform or delivery vendor sits between us and your inbox, so your email address is not handed to one.
We do not name our infrastructure supplier here. Publishing the exact provider and region of a system that holds other people’s customer data narrows an attacker’s work for no benefit to you. Tour companies get the full, named list of sub-processors as part of the Article 28 agreement, together with notice before it changes and the right to object to a change — see section 2.1. That is where the disclosure belongs and where you have a contractual right to it. Kaudata is the one sub-processor named on this page, because it is also the company whose name you see on the store listing and it would be odd to leave you to guess at the connection.
This website itself contacts no one but us. Every file these public pages need — the typefaces, the stylesheet, the animation behind the graphics on the home page — is served from our own hosting in the European Union. Earlier drafts loaded the typefaces from Google’s font service and the animation library from a public code CDN; both have been removed, because your browser fetches such files directly and that alone would have disclosed your IP address to a company you never chose to visit. No page on this site makes any third-party request, and there are no cookies, no analytics, no tracking pixels and no advertising code — including on this page. Nothing here asks you to accept anything, which is why you were not shown a cookie banner.
The tour company that employs you inevitably sees your account and your tour activity — that is the point of the product.
We may also disclose data where we are legally required to, or to establish or defend legal claims. If Konik is ever sold or merged, personal data may transfer with the business; we would tell affected tour companies first.
International transfers. The servers, the database and the mail infrastructure that hold and send your data are all located within the European Union, and both Konik and Kaudata are established in Slovenia. The service does not transfer your personal data outside the EU/EEA. Because there is no third-party email provider in the chain, there is no transfer hidden behind one either. If that ever changes we will say so here, and we will put the Article 46 safeguards in place first — tour companies are told before a sub-processor changes, under the Article 28 agreement.
12. How we protect data
- Where it lives — the application servers, the database and the mail infrastructure that sends our emails are all hosted within the European Union. We do not name the provider publicly; see section 11 for why, and for how tour companies get the named list.
- In transit — all communication between the app and the server uses HTTPS/TLS.
- Sign-in tokens on the phone — stored in the operating system’s secure store (iOS Keychain, Android Keystore), not in ordinary app storage. Your password is never stored on the device.
- Passwords on the server — stored only as salted hashes.
- Sessions — held server-side, so an administrator can revoke access immediately; locking an account destroys every session it has.
- Separation between tour companies — every request is checked against the company the account belongs to. One operator cannot see another’s tours, participants or guides.
- Cached tour data on the phone — kept in the app’s private storage area, which the operating system isolates from other apps; deleted when the offline window closes, and erased when a guide signs out. It is not encrypted by the app itself. It relies on the encryption iOS and Android apply to device storage, which takes effect only where the user has set a passcode — so the screen lock we ask tour companies to require in section 5 is the control that carries this. We are telling you this rather than leaving it unsaid: it is the one place in the service where personal data sits outside our infrastructure, and the protection depends on the handset.
- Access on our side — limited to the staff who need it to run and support the service, and recorded in an audit log.
No system is perfectly secure. If a breach affects personal data we hold, we notify the tour company that controls it without undue delay after becoming aware of it — the standard GDPR Art. 33(2) sets — with what we know at the time, and the rest as we learn it.
Who then notifies the supervisory authority is not our decision to make. For guide, participant and tour data the tour company is the controller (section 2), so the judgement under Art. 33 and 34 — whether to report the breach to the authority, and whether to tell the people affected — is theirs, and we support it rather than pre-empt it. We would notify on their behalf only if they instructed us to in writing. For the records where we are the controller — deletion requests, support correspondence, our security logs — the decision and the notification are ours, and we make them.
13. Your rights
If you are in the EU/EEA, you have the right to:
- Access the personal data held about you, and get a copy of it.
- Correct data that is wrong or incomplete.
- Erase your data — see section 9.
- Restrict processing while a dispute about accuracy or lawfulness is resolved.
- Object to processing based on legitimate interests.
- Portability — receive data you provided in a structured, machine-readable format.
- Withdraw consent, where the processing was based on consent, without affecting what was done before.
How to exercise them
- If you are a tour participant, or a parent or guardian of one: contact the tour company you booked with. It is the controller and it decides. You may also write to us and we will forward your request to them promptly and help them answer it.
- If you are a guide: contact your tour company for account and tour data, or use the deletion page for erasure. Either route works.
- For data we control ourselves — deletion requests, support correspondence, security logs — write to us directly at the privacy contact in section 15.
We answer within one month, as required by GDPR Art. 12(3). We may ask you to confirm your identity first, so that we do not hand your data to someone else. Exercising these rights is free; we may charge only for manifestly unfounded or excessive repeat requests.
Complaints. You can complain to your national data protection authority. In Slovenia this is the Information Commissioner (Informacijski pooblaščenec), www.ip-rs.si. If you live in another EU/EEA country you can complain to your own authority instead. We would rather you came to us first, but you do not have to.
14. Changes to this policy
If we change how the app handles personal data, we will update this page and change the effective date at the top. For changes that materially affect you, we will notify tour companies in advance so they can inform their staff and customers. The version in force is always the one published here.
15. Contact
Privacy questions, requests and complaints go to Konik d.o.o., the company that operates the service and holds the data:
- Konik d.o.o., Troblje 1, 2380 Slovenj Gradec, Slovenija
- Email: trgovina@konik.si — the single address for everything, privacy and otherwise. There is no separate support mailbox, and no address at numerochip.com.
- Data Protection Officer: none appointed — see below.
- Account and data deletion: delete-account.html
We have not appointed a Data Protection Officer, because we are not required to. GDPR Art. 37(1) makes one mandatory for public authorities, for organisations whose core activity is regular and systematic monitoring of people on a large scale, and for those whose core activity is large-scale processing of special categories of data or criminal-conviction data. None of those describes Konik: the service holds a small, ordinary set of contact details for a defined group of tour companies and their guides, it does not monitor anyone’s behaviour, and it processes no special categories of data at all (section 7). Not appointing one is a conclusion about the scale and nature of the processing, not a gap.
Data-protection questions, requests and complaints therefore go to the address above, trgovina@konik.si, and are answered by Konik itself. If the processing ever grows into Art. 37 territory we will appoint a DPO, publish the contact details here and notify the supervisory authority.
If you reached this page from the App Store or Google Play listing, the developer named there is Kaudata d.o.o., Kidričeva cesta 2B, 3320 Velenje, Slovenija — it wrote the app and publishes it (section 1). Write to it if your question is about the software itself. Anything about your personal data should go to Konik at the address above; Kaudata will forward such requests rather than answer them.
If your question is about a specific tour or a specific participant, contact the tour company that ran it — they hold the answer and the authority to act. Tell us too if you are not getting anywhere, and we will help.