Our commitment to protecting your personal data under UK data protection legislation.
Last updated: January 2024
maroon-cedar is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take our responsibilities as a data controller seriously and have implemented appropriate measures to ensure the security and lawful processing of personal data.
For the purposes of data protection legislation, the data controller is:
maroon-cedar
47 Briggate Street
Leeds, LS1 6HD
United Kingdom
Email: [email protected]
We process personal data under the following lawful bases as defined by Article 6 of the UK GDPR:
Processing is necessary to perform our contract with you when booking travel services, including communicating with travel suppliers, arranging transportation and accommodation, and providing travel documentation.
Processing is necessary for our legitimate business interests, including improving our services, preventing fraud, and maintaining security. We conduct a balancing test to ensure that our interests do not override your fundamental rights.
Processing is necessary to comply with legal requirements, including financial reporting obligations, immigration requirements, and responding to lawful requests from authorities.
Where we process data based on your consent (such as for marketing communications), you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
As a data subject, you have the following rights:
You have the right to obtain confirmation of whether we process your personal data and, if so, access to that data along with information about how it is processed.
You have the right to request correction of inaccurate personal data and completion of incomplete personal data.
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for its original purpose or when you withdraw consent.
You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of data or object to processing.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.
You have the right to object to processing based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not currently use automated decision-making in our services.
To exercise any of your rights, please contact us using the details provided above. We will respond to your request within one month, although this period may be extended by a further two months for complex requests. We may request verification of your identity before processing your request.
There is no fee for exercising your rights, although we may charge a reasonable fee for manifestly unfounded or excessive requests.
When arranging international travel, we may need to transfer your personal data to travel suppliers outside the United Kingdom. Such transfers are made in accordance with UK GDPR requirements, using appropriate safeguards such as:
In the event of a personal data breach that poses a high risk to your rights and freedoms, we will notify you without undue delay, providing information about the nature of the breach and steps you can take to mitigate potential adverse effects.
If you are not satisfied with our response to your concerns, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Website: ico.org.uk
We may update this GDPR compliance notice periodically to reflect changes in our practices or legal requirements. We will post any updates on this page with a revised effective date.