GDPR Compliance
Last updated: September 2, 2026
Scope of Application
While we operate primarily in Australia, we recognize that visitors from the European Union may use our services. This document outlines how we comply with the General Data Protection Regulation for EU residents whose personal data we process.
Legal Basis for Processing
We process personal data based on the following legal grounds:
Contract Performance: When you book a tour, we process your information to fulfill that contractual obligation. This includes coordinating meeting details, providing tour services, and handling related communication.
Legitimate Interests: We may process certain data for legitimate business interests, such as improving our services, maintaining website security, and preventing fraud. These interests are balanced against your privacy rights.
Consent: For any processing not covered by the above bases, we obtain explicit consent, which you may withdraw at any time.
Data Subject Rights
Under GDPR, you have the following rights regarding your personal data:
Right to Access: You may request confirmation of whether we process your personal data and obtain a copy of that data.
Right to Rectification: You can request correction of inaccurate personal information we hold about you.
Right to Erasure: You may request deletion of your personal data, subject to legal retention requirements and legitimate processing grounds.
Right to Restriction: You can request that we limit how we use your data in certain circumstances.
Right to Data Portability: You may receive your personal data in a structured, commonly used format and transmit it to another controller.
Right to Object: You can object to processing based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making: We do not use automated decision-making or profiling that produces legal or similarly significant effects.
How to Exercise Your Rights
To exercise any of these rights, contact us at [email protected] with a clear description of your request. We will respond within one month, though complex requests may require up to three months with explanation for the delay.
We may request additional information to verify your identity before processing requests that involve access to or deletion of personal data.
Data Transfers
Your personal information is stored on servers located in Australia. As Australia is not covered by an EU adequacy decision, we ensure appropriate safeguards are in place for any data transfers, including standard contractual clauses where applicable.
We do not routinely transfer personal data outside Australia except as necessary to fulfill tour bookings or respond to your inquiries.
Data Retention Periods
We retain personal data only as long as necessary for the purposes for which it was collected:
Booking information: Retained for the duration of the tour and up to three years afterward for accounting and legal compliance purposes.
Website usage data: Retained for up to 12 months for analytical purposes.
Communication records: Retained as long as necessary to address inquiries or resolve issues.
Security Measures
We implement technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These include encryption of data in transit and at rest, access controls, and regular security assessments.
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and relevant supervisory authorities within 72 hours of becoming aware of the breach, as required by GDPR.
Supervisory Authority
If you are an EU resident and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection authority.
Data Protection Officer
While we are not required to appoint a Data Protection Officer under GDPR, privacy inquiries should be directed to [email protected] where they will be handled by our designated privacy contact.
Children's Data
We do not knowingly process personal data of children under 16 without parental consent. Bookings that include minors assume appropriate parental or guardian authority has been obtained.
Updates to This Policy
We may update this GDPR compliance statement to reflect changes in regulations or our practices. Significant updates will be communicated through our website with a revised date indicated at the top of this document.