← Back
Trust & Compliance

GDPR & Data Protection

Last updated · 1 June 2026

GuestVoyages is built on the principles of the UK GDPR, the EU GDPR and equivalent frameworks. This page sets out, in plain language, the role we play in protecting your information and the rights you have over it.

GDPR at a glance

  • GuestVoyages provides software to charter operators. Your charter operator owns and controls your personal data.
  • GuestVoyages does not sell, rent, lease or trade personal data — ever.
  • All data is stored in secure, encrypted, industry-standard cloud infrastructure.
  • Access is limited to authorised users on a strict need-to-know basis.
  • Guests may request correction or deletion of their information through their operator at any time.
  • The platform follows UK GDPR, EU GDPR and equivalent international data-protection principles.
  • Appropriate technical and organisational measures are in place to protect personal information end-to-end.

Who is the controller and who is the processor

Under Article 4 of the GDPR:

  • The data controller is your charter operator (the yacht charter company, broker, villa operator or hospitality business that invited you to the platform). They determine why your data is collected and how it is used.
  • GuestVoyages is the data processor. We process personal data only on the documented instructions of the controller — typically through the operator dashboard — and only for the purpose of delivering the charter experience.

This split matters for your rights: requests for access, correction or deletion are addressed to the controller (your operator), who then uses GuestVoyages tooling to action them.

Our commitments

  • We will not sell your personal information. Period.
  • We will not use your data to train AI models, build advertising profiles, or enrich third-party datasets.
  • We will not share your data with any party your operator has not authorised, except where strictly required by law.
  • We will support your operator in responding to lawful data-subject requests within the GDPR's one-month statutory window.
  • We will encrypt your data both in transit (TLS) and at rest (object-storage encryption).
  • We will limit and audit who can access production systems containing personal data.
  • We will keep a record of processing activities as required by Article 30 of the GDPR, available to our operators.

How we apply the GDPR principles

Lawfulness, fairness, transparency

Every category of data we process maps to an explicit lawful basis (see the Privacy Policy). Guests see what they are providing as they provide it — there are no hidden collections.

Purpose limitation

Data captured for one purpose (e.g. passport details for manifest compliance) is not repurposed for another (e.g. marketing) without a fresh lawful basis.

Data minimisation

The platform asks only for the fields the operator needs to deliver a luxury hospitality service safely. Optional fields are clearly marked as optional.

Accuracy

Guests can amend their own profile, preferences and travel details at any time directly through the portal. Inaccuracies discovered by the operator can be corrected in admin tooling.

Storage limitation

Retention periods are defined per data category in the Privacy Policy and are aligned with the operator's legal record-keeping obligations.

Integrity & confidentiality

See the technical and organisational measures below.

Accountability

The platform maintains audit logs of significant data events (logins, document uploads, document access, exports). These are available to the operator and to GuestVoyages security.

Technical & organisational measures

  • TLS 1.2+ for all traffic between your device and the platform.
  • Object-storage encryption at rest for passport copies and uploaded documents.
  • Bcrypt password hashing with a per-account salt — passwords are never recoverable, only resettable.
  • Per-account rate limiting and automatic temporary lockout on repeated failed sign-in attempts.
  • Strict role-based access controls: admin, lead-guest and crew roles see different data surfaces.
  • Production database and storage are isolated from the preview environment; preview data never contains live charter information.
  • Multi-factor authentication for engineer access to production systems.
  • Encrypted backups stored separately from the live database; restoration is exercised periodically.
  • Vendor and sub-processor list maintained and made available to operators on request.
  • Documented secure software development lifecycle including dependency review and security testing.

Your rights and how to exercise them

You may exercise the following rights under the UK GDPR and EU GDPR:

  • Right of access — to be given a copy of the personal data we hold about you.
  • Right to rectification — to have inaccurate or incomplete data corrected.
  • Right to erasure (the "right to be forgotten") — to have your data deleted once it is no longer required for the charter or by law.
  • Right to restriction — to limit how we process your data while a dispute is investigated.
  • Right to data portability — to receive your data in a structured, machine-readable format.
  • Right to object — to processing based on legitimate interests, including any future direct marketing.
  • Rights related to automated decision-making — GuestVoyages does not make automated decisions that produce legal or similarly significant effects on you.

How to exercise these rights: contact the charter operator who issued your account. They are the controller and will use GuestVoyages tooling (or supported channels) to action the request. We aim to support every valid request within 30 calendar days.

If you are not satisfied with how your request was handled, you have the right to complain to a supervisory authority — in the United Kingdom this is the Information Commissioner's Office (ico.org.uk); in the European Union, your national data-protection authority.

International transfers

Luxury hospitality is, by its nature, an international service — your charter may begin in one jurisdiction, sail through another and conclude in a third. Personal data may therefore be transferred between jurisdictions to deliver the service. Where data leaves the UK or the EEA, we rely on:

  • Adequacy decisions by the European Commission or the UK government where they apply.
  • Standard Contractual Clauses (SCCs) with our cloud vendors and sub-processors in countries that have not received an adequacy decision.
  • Additional safeguards (encryption, pseudonymisation, restricted access) where supplementary measures are appropriate.

If something goes wrong

If we become aware of a personal data breach affecting your information, we will:

  • Notify the affected operators without undue delay and, where feasible, within 72 hours of becoming aware.
  • Help operators meet their notification obligations to supervisory authorities.
  • Help operators communicate with affected guests in plain language, explaining what happened and what steps are being taken.
  • Investigate the cause, contain the impact and implement remediations to prevent recurrence.

Information for operators

If you are evaluating GuestVoyages on behalf of a charter business, a Data Processing Addendum (DPA) is available on request and is incorporated by reference into our service agreement. The DPA covers:

  • Roles, duties and instructions as controller and processor.
  • Categories of data subjects and personal data processed.
  • Approved sub-processors and prior-notice obligations for new ones.
  • Security measures, audit rights and assistance with data-subject requests.
  • Breach notification timelines and channels.
  • International transfer mechanisms (Standard Contractual Clauses).
  • Return or deletion of data at the end of the engagement.

To request the DPA, please contact GuestVoyages through your existing commercial channel.