Last updated: January 2024
clever-maple is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. This statement outlines how we comply with these regulations and respect your data protection rights.
For the purposes of data protection law, clever-maple acts as the data controller for personal information collected through our website and services.
Business Name: clever-maple
Address: 42 Stevenson Square, Northern Quarter, Manchester M1 1FB, United Kingdom
Email: [email protected]
We process personal data only when we have a lawful basis to do so under GDPR Article 6. Our lawful bases include:
Processing is necessary to perform our contract with you when you book travel services or request custom itineraries. This includes managing bookings, coordinating travel arrangements, and providing customer support.
When you provide explicit consent for specific processing activities, such as receiving marketing communications or using certain website features. You have the right to withdraw consent at any time.
Processing is necessary for our legitimate business interests, such as improving our services, preventing fraud, and maintaining website security. We balance these interests against your rights and freedoms.
Processing is necessary to comply with legal obligations, including tax regulations, accounting requirements, and responding to lawful requests from authorities.
Under the GDPR, you have the following rights regarding your personal data:
You have the right to obtain confirmation that we are processing your data and to receive a copy of your personal data along with information about how it is being processed.
You can request correction of inaccurate personal data and completion of incomplete data.
Also known as the 'right to be forgotten,' you can request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
You can request that we limit how we use your personal data in specific situations, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
You can object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we have compelling legitimate grounds that override your interests.
You have the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significantly affect you. We do not engage in automated decision-making or profiling.
To exercise any of your GDPR rights, please contact us at [email protected] with your request. We will respond within one month, though this may be extended by two additional months for complex requests. We will always inform you of any extension and the reasons for it.
When submitting a request, please provide sufficient information to allow us to verify your identity and locate your data. We may request additional information if necessary to confirm your identity.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where required by law.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements. Our retention periods are based on:
When personal data is no longer needed, we securely delete or anonymize it.
When we transfer personal data outside the United Kingdom or European Economic Area, we ensure appropriate safeguards are in place, such as:
Our services are not directed at children under 16 years of age. We do not knowingly collect personal data from children without verifiable parental consent. If we become aware that we have inadvertently collected such data, we will take steps to delete it promptly.
We work with third-party service providers who process personal data on our behalf as data processors. We ensure that:
You have the right to lodge a complaint with a supervisory authority if you believe we have not complied with data protection law. In the United Kingdom, the relevant authority is:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
United Kingdom
Website: ico.org.uk
We may update this GDPR compliance statement periodically to reflect changes in our practices or legal requirements. Material changes will be communicated through our website or directly to you where appropriate.
If you have questions or concerns about how we handle your personal data or our GDPR compliance, please contact us at [email protected].