Working document

Privacy policy

A brief explanation of what data are needed to book an active departure and how are visible to the client, organizer and moderator.

What data is processed

The system processes the data needed for the booking: buyer data, participant data, email contact, information about the selected date, stay options, add-ons, payments, contract, organiser payments and operational communication.

Why are they needed?

The data is used to create and operate reservations, generate documents, provide information to the organizer, send access links, support payments, complaints, reviews on departure and account security.

Access of the organiser

The organiser sees the data needed to implement a specific event: participants, allocated resources, allowances, payment status, documents and operational notes related to his offer.

Moderator Access

The platform moderator has access to the data needed to accept organizers, moderate offers, support payments, cancellations, complaints, reviews and withdrawals. Technical access should be limited to those actually administering the system.

Tokens and access links

Links to login and booking are one-time or limited time. The access secret is transmitted in the address fragment after the # character, so that it does not enter the server logs as the query parameter.

Marketing consents

Marketing consent is not a reservation condition. If implemented, it must be separate, voluntary and possible to withdraw without affecting the maintenance of the existing reservation.

Shelf-life

Booking, contract, payment and settlement data may be stored for as long as required by customer service, settlement, legal obligations, disputes or operational audit.

Working version

It's a working product description. The final privacy policy must be verified legally, supplemented by data from the controller, legal bases, processors and procedures for the exercise of the rights of persons.