Last Updated: August 2026
We are committed to complying with the General Data Protection Regulation (GDPR) and protecting the rights of individuals regarding their personal data. This page outlines how we meet our obligations under GDPR.
For the purposes of GDPR, we are the data controller for personal information collected through our website and services.
Contact Details:
Email: [email protected]
Address: 47 Kensington Court, London W8 5DA, United Kingdom
We process personal data only when we have a lawful basis to do so. Our lawful bases include:
We obtain your explicit consent before processing certain types of personal data, such as sending marketing communications. You can withdraw consent at any time.
We process data necessary to fulfill our contractual obligations to you, including arranging travel services you have requested.
We process data when required by law, such as for tax reporting or compliance with regulatory requirements.
We may process data based on legitimate business interests, provided these do not override your fundamental rights and freedoms.
You have the right to request confirmation of whether we process your personal data and to receive a copy of that data.
You can request correction of inaccurate or incomplete personal data we hold about you.
Under certain circumstances, you can request deletion of your personal data. This right is not absolute and depends on our legal obligations and legitimate interests.
You can request that we limit how we use your personal data in specific situations.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
You can object to processing based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing that produces legal effects or similarly significant effects. We do not currently employ such automated decision-making.
To exercise any of your GDPR rights, please contact us at [email protected] with:
We will respond to your request within one month. If your request is complex or we receive multiple requests, we may extend this period by two additional months and will inform you accordingly.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.
When we engage third-party processors to handle personal data on our behalf, we ensure they:
When transferring personal data outside the European Economic Area, we ensure appropriate safeguards are in place, such as:
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements. Our standard retention period is seven years following the completion of services.
We do not knowingly process personal data of children under 16 without parental consent. If we become aware that we have collected such data without consent, we will delete it promptly.
You have the right to lodge a complaint with a supervisory authority if you believe we have not complied with GDPR. In the United Kingdom, the supervisory authority is the Information Commissioner's Office (ICO).
ICO Contact:
Website: ico.org.uk
Helpline: 0303 123 1113
We may update our GDPR compliance information periodically. Significant changes will be communicated through our website.
If you have questions about our GDPR compliance or data protection practices, please contact us at [email protected].