Our commitment to data protection under the General Data Protection Regulation
We process your personal data based on the following legal grounds:
You have the right to obtain confirmation about whether we process your personal data and to receive a copy of that data. We will provide this information in a commonly used electronic format.
You may request correction of inaccurate personal data and completion of incomplete data. We will make corrections promptly upon verification.
You may request deletion of your personal data when it is no longer necessary for the purposes it was collected, when you withdraw consent, or when there is no overriding legitimate ground for processing.
You may request restriction of processing in specific circumstances, such as when contesting data accuracy or objecting to processing based on legitimate interests.
You have the right to receive your personal data in a structured, machine-readable format and to transmit it to another controller where technically feasible.
You may object to processing based on legitimate interests or for direct marketing purposes. We will cease such processing unless we demonstrate compelling legitimate grounds that override your interests.
While our AI systems generate travel recommendations, final decisions involve human review. You have the right to request human intervention, express your point of view, and contest automated decisions.
To exercise any of these rights, send a request to [email protected] with the subject line "GDPR Request." Include your full name, email address, and specific right you wish to exercise.
We will respond to your request within one month. This period may be extended by two months for complex requests, and we will inform you of such extension.
We may request additional information to verify your identity before processing requests involving personal data access or deletion.
For questions about our data protection practices or to contact our Data Protection Officer, email [email protected] with "DPO" in the subject line.
If you believe we have violated your data protection rights, you have the right to lodge a complaint with the Irish Data Protection Commission or the supervisory authority in your country of residence.
Data Protection Commission
21 Fitzwilliam Square South
Dublin 2, D02 RD28
Ireland
We implement appropriate technical and organizational measures to ensure data security levels appropriate to the risk, including:
In the event of a personal data breach likely to result in high risk to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach.
We engage third-party service providers who may process your data on our behalf. All processors are selected based on their ability to guarantee GDPR compliance and are bound by data processing agreements.
When transferring data outside the European Economic Area, we ensure appropriate safeguards are in place through standard contractual clauses approved by the European Commission or other legally recognized mechanisms.
We regularly review and update our data protection practices to ensure ongoing GDPR compliance. Changes will be reflected on this page with updated effective dates.