Last Updated: July 8, 2026
We are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and related UK data protection legislation. This document outlines how we comply with these regulations and explains your rights under GDPR.
As a data controller, we take our obligations seriously and have implemented appropriate technical and organizational measures to ensure data protection by design and by default.
We process personal data only when we have a lawful basis to do so:
Under GDPR, you have comprehensive rights regarding your personal data:
You may request confirmation of whether we process your personal data and obtain a copy of that data. We will provide this information in a commonly used electronic format.
You may request correction of inaccurate personal data or completion of incomplete information. We will update our records promptly upon verification.
You may request deletion of your personal data when it is no longer necessary for the purposes collected, when you withdraw consent, or when you object to processing. This right is subject to legal retention obligations.
You may request temporary restriction of processing while we verify accuracy, assess objections, or when you need data preserved for legal claims.
You may receive personal data you provided to us in a structured, machine-readable format and transmit it to another controller.
You may object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds.
You have the right not to be subject to decisions based solely on automated processing that produces legal effects. We do not currently employ such automated decision-making processes.
We collect only data necessary for legitimate business purposes:
We do not collect special category data (sensitive personal information) unless absolutely necessary and with explicit consent.
We retain personal data only as long as necessary for the purposes collected or to comply with legal obligations. Booking information is typically retained for seven years to meet financial and legal requirements. Technical data is retained for shorter periods based on legitimate business needs.
Once retention periods expire, data is securely deleted or anonymized beyond recovery.
We implement appropriate technical and organizational security measures:
Personal data is processed primarily within the United Kingdom. If data must be transferred outside the UK or European Economic Area, we ensure appropriate safeguards are in place, such as standard contractual clauses or adequacy decisions.
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware. If the breach poses a high risk, we will also notify affected individuals without undue delay.
To exercise any of your GDPR rights, contact us at [email protected] with:
We will respond to verified requests within one month. Complex requests may require additional time, in which case we will notify you of the extension and reasons.
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection.
ICO Contact: [email protected] or visit www.ico.org.uk
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Material changes will be communicated through prominent notice on our website.