GDPR Compliance
Last updated: June 26, 2026
Our Commitment to Data Protection
elm-ocelot is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This page outlines how we comply with GDPR requirements and your rights under this legislation.
Legal Basis for Processing
We process your personal data under the following legal bases:
- Contract: Processing is necessary for the performance of a contract to which you are party (booking our services)
- Consent: You have given clear consent for us to process your personal data for specific purposes (marketing communications)
- Legitimate interests: Processing is necessary for our legitimate interests (improving our services, website functionality)
Your Rights Under GDPR
Right to Access
You have the right to request copies of your personal data. We may charge a small fee for this service.
Right to Rectification
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
Right to Erasure
You have the right to request that we erase your personal data, under certain conditions.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data, under certain conditions.
Right to Object to Processing
You have the right to object to our processing of your personal data, under certain conditions.
Right to Data Portability
You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.
How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month.
Please provide the following information with your request:
- Your full name and contact details
- Details of your specific request
- Proof of identity (to ensure we are disclosing information to the correct person)
Data Processing Activities
What data we collect
- Contact information (name, email address)
- Booking information (service selected, preferences)
- Communication records
Why we collect it
- To provide our tourism services
- To communicate with you about your bookings
- To improve our services
- To comply with legal obligations
How long we keep it
We retain personal data for as long as necessary to fulfill the purposes for which it was collected. Booking records are typically retained for seven years to comply with accounting and tax requirements.
Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Regular security assessments
- Access controls and authentication
- Staff training on data protection
Data Breaches
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.
International Data Transfers
We do not transfer your personal data outside the United Kingdom or European Economic Area. Should this change, we will ensure appropriate safeguards are in place.
Complaints
If you believe we have not complied with GDPR requirements, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) in the United Kingdom.
ICO Contact Details:
Website: www.ico.org.uk
Telephone: 0303 123 1113
Contact Our Data Protection Officer
For any questions regarding GDPR compliance or data protection, please contact us at [email protected]