Privacy policy

Last updated: August 2026 · Regulation (EU) 2016/679 — GDPR

In the course of its activity and the contractual relationships it establishes, Endless Luxe Travel acts to ensure the highest standards of personal data protection.

Endless Luxe Travel complies with all legislation on the protection of personal data, in particular the General Data Protection Regulation (GDPR — EU 2016/679), guaranteeing the confidentiality, integrity and availability of such data.


Data controller

Endless Luxe Travel is the entity responsible for processing the personal data described in this policy, under the terms of the GDPR.


The processing

Endless Luxe Travel collects and processes personal data in order to plan and operate journeys, manage its contracts and meet its legal obligations.

The data collected may include: name, date of birth, tax number, address, email, telephone, and the identification and travel document details a booking requires.

  • Clients and representatives of clients
  • Users of our services
  • Suppliers and their representatives
  • Employees and collaborators

Newsletter and communications

Newsletters are sent to make the activities of Endless Luxe Travel known to clients, suppliers and partners.

Consent may be withdrawn at any time by sending an email to info@endlessluxetravel.com or by clicking “unsubscribe”.


Retention period

Data is kept for as long as the commercial relationship is in force, and may be held for longer where the law provides, for the defence of rights in legal proceedings.

Once the maximum retention period has passed, data is irreversibly anonymised or securely destroyed.


Rights of data subjects

Data subjects may exercise the following rights by written request sent to info@endlessluxetravel.com:

  • Access — to consult the personal data processed and obtain information on its purpose and retention period
  • Rectification — to correct inaccurate or incomplete data
  • Erasure — to request the deletion of data that is no longer necessary
  • Restriction of processing — to restrict processing in certain circumstances
  • Portability — to receive your data in a structured, machine-readable format
  • Objection — to object to processing on grounds relating to your particular situation
  • Complaint — to lodge a complaint with the CNPD or another competent supervisory authority

Security measures

Endless Luxe Travel maintains every technical means at its disposal to prevent unauthorised access to, loss of, or destruction of personal data:

  • Communication over HTTPS with an SSL certificate
  • Data transferred only in encrypted form
  • Permanent monitoring of access to information systems
  • Regular audits of the technical and organisational measures adopted
  • Regular data protection training for staff
  • Mechanisms for rapid recovery in the event of a physical or technical incident

Personal data breach

Endless Luxe Travel will notify data subjects when a breach occurs that entails a high risk to their rights and freedoms, within 72 hours of the incident.


Sharing data with other entities

Endless Luxe Travel may share data with the hotels, guides, transport operators and other suppliers a journey requires, as well as where necessary for administrative and financial management or in compliance with legal obligations.

Any subcontractor processes the data in the name and on behalf of Endless Luxe Travel, following its instructions strictly and offering sufficient guarantees of appropriate technical and organisational measures.


International data transfers

The provision of services may involve transferring data to third countries outside the EU/EEA. In those cases, Endless Luxe Travel will adopt the measures required under applicable law to guarantee the protection of the data transferred.


Contacts

For more information about the processing of your data, or to exercise your legal rights, contact us at:

info@endlessluxetravel.com

Data Protection Officer: info@endlessluxetravel.com

August 2026