Privacy Policy
Learn more about our data protection standards and your privacy rights.
Privacy Policy & Data Protection Charter
1. Introduction and Scope
Welcome to the Privacy Policy of Ilqusen. We are committed to protecting your privacy and ensuring the security of your personal data. This document outlines how we collect, process, share, and protect your personal information when you interact with our cruise travel agency services, website, and related digital solutions. This policy complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Data Controller Details
For the purposes of applicable data protection legislation, the data controller is Ilqusen. If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact our Data Protection Officer using the details provided in Section 11 of this document.
3. Personal Data We Collect
We may collect, use, store, and transfer different kinds of personal data about you, which we have grouped as follows:
- Identity Data: First name, maiden name, last name, username, passport details (for international cruise bookings), and date of birth.
- Contact Data: Billing address, delivery address, email address, and telephone numbers.
- Financial Data: Bank account and payment card details (processed securely via PCI-DSS compliant third-party payment gateways).
- Transaction Data: Details about payments to and from you, and other details of products and services you have purchased from us.
- Technical Data: Internet protocol (IP) address, login data, browser type and version, time zone setting, operating system, and platform.
- Marketing and Communications Data: Your preferences in receiving marketing from us and our third parties, and your communication preferences.
4. Legal Bases for Processing
Under the UK GDPR, we must always have a lawful basis for processing your personal data. We rely on the following bases:
- Performance of a Contract: Necessary for the performance of a contract to which you are a party (e.g., booking your cruise, flights, or accommodations).
- Legitimate Interests: Necessary for our legitimate interests (or those of a third party) in running our business, provided your interests and fundamental rights do not override those interests.
- Legal Obligation: Necessary to comply with a legal or regulatory obligation (e.g., security clearances, tax reporting, or maritime safety regulations).
- Consent: Where you have given clear, explicit consent for us to process your data for a specific purpose (e.g., sending promotional newsletters or processing special category health data for accessibility requirements).
5. How We Process and Use Your Data
We utilize your personal data for clear, predefined objectives designed to guarantee a high-quality, seamless booking experience. These purposes include, but are not limited to:
- Booking Administration: Securing cabins, processing payments, arranging transfers, and issuing travel documentation.
- Customer Support: Managing inquiries, resolving booking modifications, and handling emergency situations during travel.
- Marketing Communications: Informing you about exclusive cruise deals, loyalty program upgrades, and destination guides (subject to your opt-in consent).
- Service Enhancement: Conducting feedback analysis, website optimization, and staff training to elevate our customer journey.
6. Data Sharing & Third-Party Disclosures
To deliver our cruise travel services, we must share your personal data with trusted third parties, including:
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes, only permitting them to process your data for specified purposes and in accordance with our strict instructions.
- Cruise Lines and Maritime Operators: To secure your vessel reservations, passenger manifests, and onboard credits.
- Airlines and Ground Transport Providers: To facilitate flight connections, airport transfers, and baggage services.
- Payment Gateways: To execute secure transactions using encrypted channels.
- Regulatory and Security Authorities: To comply with border control, port authority regulations, and custom requirements.
7. International Data Transfers
Because cruises cross international borders, processing your travel arrangements may require transferring your data outside the United Kingdom. Whenever we transfer your personal data out of the UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
- We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the UK Government.
- Where we use certain service providers, we may use specific contracts approved for use in the UK (the International Data Transfer Agreement or Addendum) which give personal data the same protection it has in the UK.
8. Data Retention Policy
We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process it, and the applicable legal requirements. Financial records are retained for a minimum of 7 years, while inactive customer accounts are securely archived or deleted after 5 years.
9. Security Measures
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way, altered, or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
10. Your Rights Under the UK GDPR
You have rights under data protection laws in relation to your personal data. These rights include:
- Request Access: Commonly known as a "data subject access request". This enables you to receive a copy of the personal data we hold about you.
- Request Correction: This enables you to have any incomplete or inaccurate data we hold about you corrected.
- Request Erasure: This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it.
- Object to Processing: You can object where we are relying on a legitimate interest and there is something about your situation which makes you want to object to processing.
- Request Restriction: This enables you to ask us to suspend the processing of your personal data in certain scenarios.
- Request Transfer: We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format.
- Withdraw Consent: You can withdraw consent at any time where we are relying on consent to process your personal data.
11. Contact and Complaints
If you wish to exercise any of the rights set out above, or have queries regarding this policy, please contact us using the details below:
Address: 39, Hayes Crescent, Frodsham, WA6 7PF, United Kingdom
Phone: 441364476445
Email: [email protected]
You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact us in the first instance.