GuestVoyages is built on the principles of the UK GDPR, the EU GDPR and equivalent frameworks. This page sets out, in plain language, the role we play in protecting your information and the rights you have over it.
Under Article 4 of the GDPR:
This split matters for your rights: requests for access, correction or deletion are addressed to the controller (your operator), who then uses GuestVoyages tooling to action them.
Every category of data we process maps to an explicit lawful basis (see the Privacy Policy). Guests see what they are providing as they provide it — there are no hidden collections.
Data captured for one purpose (e.g. passport details for manifest compliance) is not repurposed for another (e.g. marketing) without a fresh lawful basis.
The platform asks only for the fields the operator needs to deliver a luxury hospitality service safely. Optional fields are clearly marked as optional.
Guests can amend their own profile, preferences and travel details at any time directly through the portal. Inaccuracies discovered by the operator can be corrected in admin tooling.
Retention periods are defined per data category in the Privacy Policy and are aligned with the operator's legal record-keeping obligations.
See the technical and organisational measures below.
The platform maintains audit logs of significant data events (logins, document uploads, document access, exports). These are available to the operator and to GuestVoyages security.
You may exercise the following rights under the UK GDPR and EU GDPR:
How to exercise these rights: contact the charter operator who issued your account. They are the controller and will use GuestVoyages tooling (or supported channels) to action the request. We aim to support every valid request within 30 calendar days.
If you are not satisfied with how your request was handled, you have the right to complain to a supervisory authority — in the United Kingdom this is the Information Commissioner's Office (ico.org.uk); in the European Union, your national data-protection authority.
Luxury hospitality is, by its nature, an international service — your charter may begin in one jurisdiction, sail through another and conclude in a third. Personal data may therefore be transferred between jurisdictions to deliver the service. Where data leaves the UK or the EEA, we rely on:
If we become aware of a personal data breach affecting your information, we will:
If you are evaluating GuestVoyages on behalf of a charter business, a Data Processing Addendum (DPA) is available on request and is incorporated by reference into our service agreement. The DPA covers:
To request the DPA, please contact GuestVoyages through your existing commercial channel.