EU regulations that apply to this service

ExploreWorldAI is an EU regulatory intelligence platform for companies, not a travel service.

Eight rulebooks decide what we may build, what we must show and what you can demand from us. This page states each one in plain business language, what it means for us in practice, and where the official text sits.

This is a description of how we read the rules that apply to us. It is not legal advice, and it does not say that an authority has reviewed or approved ExploreWorldAI.

Reviewed: 2026-08-08

GDPR

Instrument
Regulation (EU) 2016/679
Applies from
25 May 2018
What it covers
All handling of personal data in the EU and the EEA: legal basis, purpose, retention, transfers outside the union and the rights of the person the data is about.
What it means for us
We read public company pages, not private profiles, and we keep the amount of personal data to a minimum. Where a name or a role appears in a report, it comes from a public source and the source is shown next to it.
Duties it puts on us
  • A stated legal basis for every activity that touches personal data
  • Data minimisation, retention limits and deletion on request
  • A processing agreement with every customer who sends us data
  • Breach reporting to the supervisory authority within 72 hours
  • Records of processing and an assessment where the risk is high
Supervised by
IMY in Sweden, Datatilsynet in Norway, coordinated by the EDPB
Official text
eur-lex.europa.eu, Regulation 2016/679

AI Act

Instrument
Regulation (EU) 2024/1689
Applies from
1 August 2024, with duties phased in through 2026 and 2027
What it covers
AI systems placed on the union market: prohibited practices, high-risk duties, transparency towards the user and rules for general purpose models.
What it means for us
Our answers and scores are produced by fixed, written rules. Where a language model writes text, it is a drafting step and never the final word. We tell the reader when an answer is machine generated.
Duties it puts on us
  • Classify each function and state the class in public
  • Tell the reader when text or an answer is produced by a machine
  • Keep a human in the loop before anything binding leaves the service
  • Log the calls that produced an answer, so a decision can be traced
  • Review models and rules on a fixed schedule, and record the review
Supervised by
The European AI Office, with national market surveillance authorities
Official text
eur-lex.europa.eu, Regulation 2024/1689

NIS2

Instrument
Directive (EU) 2022/2555
Applies from
National law from 18 October 2024
What it covers
Security of network and information systems for essential and important entities: risk measures, incident reporting, supply chain security and management accountability.
What it means for us
We are not designated as an essential entity, but our customers in transport, finance and public service are, and they pass the requirement on to us as a supplier. We answer as if the duties applied directly.
Duties it puts on us
  • Documented risk handling and access control
  • An incident process with a named owner and a fixed clock
  • Early warning to the customer within 24 hours of a significant incident
  • Supplier review, including the providers we call ourselves
  • Management sign-off on the security measures
Supervised by
MSB and PTS in Sweden, NSM and Nkom in Norway
Official text
eur-lex.europa.eu, Directive 2022/2555

DSA

Instrument
Regulation (EU) 2022/2065
Applies from
17 February 2024
What it covers
Digital services that carry content from others: notice and action, transparency about recommendations and advertising, and a yearly report for larger platforms.
What it means for us
We are not a marketplace and we do not host user content for the public. We do read public pages and show extracts, so we keep a notice route open for anyone who wants an extract removed.
Duties it puts on us
  • A contact point and a route to report content in an extract
  • A stated reason when we decline a request
  • Clear labelling of anything sponsored, which today is nothing
  • No dark patterns in the checkout or in consent
Supervised by
The European Commission, with national digital services coordinators
Official text
eur-lex.europa.eu, Regulation 2022/2065

DMA

Instrument
Regulation (EU) 2022/1925
Applies from
2 May 2023
What it covers
Duties on the largest platforms, named gatekeepers: self preferencing, data combination, access for business users and interoperability.
What it means for us
We are not a gatekeeper, we are a business user of several. The rule matters to our customers because it opens access to search and store data that used to be closed, which is exactly the material a visibility report is built on.
Duties it puts on us
  • Use gatekeeper interfaces on the published terms, never by scraping around them
  • Pass on the data access a customer is entitled to under the rule
  • State which surfaces a measurement covers, and which it does not
Supervised by
The European Commission
Official text
eur-lex.europa.eu, Regulation 2022/1925

ePrivacy

Instrument
Directive 2002/58/EC, as amended by 2009/136/EC
Applies from
31 July 2002, with the cookie rule from 2011
What it covers
Cookies and similar storage on a device, electronic direct marketing and the confidentiality of communication.
What it means for us
The site runs without marketing cookies. What we store is needed to make the service work, and the preference page lets you see and change it.
Duties it puts on us
  • Consent before any storage that is not strictly necessary
  • A withdrawal that is as easy as the consent
  • Named purpose and retention for each stored item
  • No email marketing without a prior relationship or a consent
Supervised by
PTS in Sweden, Nkom in Norway
Official text
eur-lex.europa.eu, Directive 2002/58/EC

PSD2

Instrument
Directive (EU) 2015/2366
Applies from
13 January 2018, strong authentication from 14 September 2019
What it covers
Payment services in the union: strong customer authentication, the split between payer, provider and merchant, and refund rights.
What it means for us
We never hold card data. Payment runs at our payment provider, and strong authentication happens there. We store the receipt and the amount, not the card.
Duties it puts on us
  • Strong customer authentication on card payment, handled by the provider
  • Price, currency and tax shown before the payment is confirmed
  • A receipt for every charge, with buyer type and tax stated
  • A stated route for refunds and for disputed charges
Supervised by
Finansinspektionen in Sweden, Finanstilsynet in Norway
Official text
eur-lex.europa.eu, Directive 2015/2366

Package Travel Directive

Instrument
Directive (EU) 2015/2302
Applies from
1 July 2018
What it covers
Package travel and linked travel arrangements: pre-contract information, liability for the package and insolvency protection for the traveller.
What it means for us
ExploreWorldAI is not a travel service. We do not sell trips, we do not take bookings and we hold no traveller money. The rule reaches our customers in the travel trade, and it shapes what a booking page must say before a traveller pays.
Duties it puts on us
  • Never present ourselves as an organiser or a retailer of travel
  • Keep the disambiguation line visible: we sell visibility work, not trips
  • Point travel customers to the information duties their own booking page carries
Supervised by
Kammarkollegiet in Sweden, Reisegarantifondet in Norway
Official text
eur-lex.europa.eu, Directive 2015/2302

Which rule answers which question

One line per question, so you do not have to read all eight blocks to find the right rulebook.

Which rule answers which question
Your questionThe rule that answers it
What happens to my personal dataGDPR, and our GDPR statement
Who decides what the service answersThe AI Act, human oversight
What happens when there is an incidentNIS2, and our incident process
How do I get an extract removedThe DSA notice route
Why can you read data from a large platformThe DMA, business user access
What is stored on my deviceePrivacy, and the cookie preferences page
How is my card handledPSD2, at our payment provider
Do you sell tripsThe Package Travel Directive, and no, we do not

Nearby texts

ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.

Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.