Privacy Policy
A legal disclaimer
Privacy Policy (GDPR Compliant)
Effective Date: [Insert Date]
At [Your Business Name], we respect your privacy and are committed to protecting your personal information in accordance with the General Data Protection Regulation (GDPR). This Privacy Policy explains how we collect, use, store, and protect your personal data when you book a tour with us or interact with our website.
By using our services or visiting our website, you agree to the collection and use of your information as outlined in this policy.
1. Information We Collect
We collect the following personal data when you book a tour or communicate with us:
-
Personal Identification Information: Name, Last Name, Date of Birth
-
Contact Information: Email Address, Phone Number, Country of Residence
-
Payment Information: Payment method (e.g., credit/debit card details)
-
Booking Information: Tour-related details, special requests (e.g., dietary preferences)
We do not collect any sensitive data unless necessary for specific requests (e.g., dietary needs). We also do not use cookies or track user behavior on our website.
2. Lawful Basis for Processing Personal Data
We process your personal data based on the following legal grounds:
-
Contractual Necessity: We process your data to provide our services (e.g., booking a tour and confirming your details).
-
Consent: We may send marketing emails or updates with your explicit consent, and you can withdraw this consent at any time.
-
Legal Obligation: We may process your data to comply with legal obligations (e.g., invoicing, tax records).
By booking a tour or interacting with our website, you consent to the collection and use of your personal data for the purposes outlined in this policy.
3. How We Use Your Information
We use your personal data for the following purposes:
-
To process your booking and communicate with you: This includes confirming your tour details, sending reminders, and providing updates.
-
To fulfill legal obligations: Such as accounting, invoicing, and tax reporting.
-
For marketing communications: With your consent, we may send you updates, newsletters, or promotional offers related to our services. You can opt-out of these communications at any time by clicking the "unsubscribe" link in our emails.
We will not share your data with third parties unless required for the services mentioned (e.g., payment processing) or as required by law.
4. Payment Processing
We use the Wise Payment System for processing payments. Your payment details are securely handled by their platform and are not stored on our servers.
5. Data Protection and Security
We take your privacy seriously and implement physical, technical, and administrative security measures to protect your personal information from unauthorized access, use, alteration, or disclosure. Your data is stored on secure servers protected by encryption and access controls.
However, please note that no method of transmitting data over the internet or through wireless networks can be guaranteed as 100% secure. While we strive to protect your data, we cannot ensure its absolute security during transmission.
6. Data Retention
We will retain your personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by law (e.g., tax or legal requirements). Once the data is no longer needed, we will securely delete or anonymize it.
7. Your Rights Under GDPR
As a data subject, you have the following rights regarding your personal data under GDPR:
-
Right to Access: You can request a copy of the personal data we hold about you.
-
Right to Rectification: You can ask us to correct any inaccurate or incomplete personal data.
-
Right to Erasure: You can request that we delete your personal data, subject to certain legal limitations.
-
Right to Restriction of Processing: You can request us to restrict processing of your personal data under certain conditions.
-
Right to Data Portability: You can request your personal data in a structured, commonly used format for transfer to another service provider.
-
Right to Object: You can object to the processing of your personal data for direct marketing purposes at any time.
-
Right to Withdraw Consent: You can withdraw your consent for marketing communications at any time by unsubscribing from our emails.
To exercise any of these rights, please contact us at [your contact email].
8. Third-Party Service Providers
We may use third-party service providers (such as payment processors and email marketing services) to help us run our business. These third parties may have access to your personal data to the extent necessary to provide their services, but they are not permitted to use your data for any other purposes.
We use Wise Payment System for processing payments, and your payment information is securely handled by their platform.
9. International Data Transfers
If you are located outside the EU, please be aware that your personal data may be transferred to and processed in the EU or other countries where our service providers are located. We will ensure that appropriate safeguards are in place to protect your personal data during such transfers, in compliance with GDPR.
10. Links to Other Websites
Our website may contain links to third-party websites that are not operated by us. We are not responsible for the privacy practices or content of these external sites. We encourage you to review their privacy policies before providing them with any personal data.
11. Data Protection Officer (DPO)
If you have any concerns regarding how your personal data is processed, or wish to exercise your GDPR rights, you can contact our Data Protection Officer (DPO) at:
-
Email: [Your DPO Email]
-
Phone: [Your DPO Phone Number]
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Any updates will be posted on this page with an updated "Effective Date." We recommend reviewing this policy periodically to stay informed of any changes.
13. Contact Us
If you have any questions or concerns about this Privacy Policy or how we process your personal data, please contact us:
-
Email: [Your Contact Email]
-
Phone: [Your Contact Number]
-
Address: [Your Business Address]
Acknowledgment
By booking a tour with us or using our website, you acknowledge that you have read, understood, and agree to the terms of this Privacy Policy.
Final Notes:
-
GDPR Compliance: Ensure that you are not only collecting data based on consent but also honoring customer requests to withdraw that consent and manage their data rights.
-
Legal Review: If you're unsure about the GDPR-specific elements, consider having a legal professional review the policy for full compliance.
Let me know if you need additional customization or further explanation on any point!