Our website https://itawayecotours.com is committed to protecting and respecting your privacy.
This policy (together with our Terms and Conditions and any other documents referred to on it) sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.
We may collect and process the following data about you:
The data we collect and process is strictly limited to that which is necessary for us to provide our service to you under the lawful bases of consent and/or necessity.
Where we have given you (or where you have chosen) a password or access credentials which enable you to access certain parts of our site, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
We may collect information about your computer, including where available your IP address, operating system and browser type, for system administration and to report aggregate information to our partners, providers or advertisers. This is statistical data about our users’ browsing actions and patterns, and does not identify any individual.
If you register for an account with us, we may use your IP address at the time of registration for “geolocation” (meaning that we will infer your likely country of location, based on your IP address). Such geolocation is limited to the country level, and is not guaranteed to be accurate.
We do not request or otherwise collect or store any sensitive personal data (for example: data consisting of racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, gender or sexual orientation), whether in aggregate or linked to any person or account. If we become aware of any such data being stored or processed in our systems, we will take reasonable steps to erase it.
Our website uses specific cookies to distinguish you from other users of our website. This helps us to provide you with a good experience when you browse our website and also allows us to improve our site.
If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
Our entire site is available over secure SSL (HTTPS) connection. Information that you provide to us by filling in forms on our site is therefore transferred from your web browser or server using SSL encryption.
When you enter payment information, such as your credit card number, these are processed by our payment processor (Stripe). The checkout page and/or specific form fields where you enter such information are served directly from their secure servers, and we do not process, receive or store your payment details.
Although we will do our best to protect your personal data, including the use of SSL technology, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
We use information held about you in the following ways, under the lawful bases of consent, necessity and/or legal obligation:
Where we permit selected third parties to use your data, such use is strictly limited to that which is necessary to enable us to provide our service to you, and for purposes for which you have provided your consent. We ensure that these third parties are compliant with relevant data protection law, and that your data is not used or stored by any third party for purposes for which you have not consented.
If you are an existing customer, we will only contact you with information about goods and services similar to those which were the subject of a previous sale to you, and only where these are provided by us.
If you are a new customer, we will contact you by electronic means only if you have consented to this. If you email us before registering for or using our site, we will respond to you by email, only insofar as required to provide you with the information you have asked for. If you then decide that you do not wish to use our site or services based on our response to you, please inform us of this and we will no longer contact you.
We will retain information held about you for the duration of your having an account with us (or longer, if required by law). When you no longer need your account, you may delete it by emailing us at email@example.com and requesting account deletion. We will then no longer retain information about you. If your account is inactive for a long period of time, we may also erase information held about you as part of routine maintenance and data purging practices.
We may disclose your personal information to any member of our group, which means our subsidiaries, our ultimate holding company and its subsidiaries.
We may disclose your personal information to third parties:
In the event of any such disclosure, we will use our best efforts contact you to notify you of such disclosure, and give you the opportunity to exercise your right to erasure.
While we take great precaution to protect our systems and servers from unauthorised access, and carry out regular internal data security audits, there is a risk of malicious activity occurring. If we become aware of any potential or actual breach of our systems which may have caused exposure of your personal information, we will contact you via the email address you have provided to us within 72 hours of such discovery to inform you of the situation.
If you have an account on this site, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You may exercise this right at any time by emailing firstname.lastname@example.org from the email address associated with your request. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.
You have the right to ask us not to process your personal data for marketing purposes. We will usually inform you (before collecting your data) if we intend to use your data for such purposes or if we intend to disclose your information to any third party for such purposes. You can exercise your right to prevent such processing by checking certain boxes on the forms we use to collect your data. You can also exercise the right at any time by contacting us at email@example.com.
Version 1, last updated: 04/04/2022