Privacy policy
Last updated: August 2026 · Regulation (EU) 2016/679 — GDPR
In the course of its activity and the contractual relationships it establishes, Endless Luxe Travel acts to ensure the highest standards of personal data protection.
Endless Luxe Travel complies with all legislation on the protection of personal data, in particular the General Data Protection Regulation (GDPR — EU 2016/679), guaranteeing the confidentiality, integrity and availability of such data.
Data controller
Endless Luxe Travel is the entity responsible for processing the personal data described in this policy, under the terms of the GDPR.
The processing
Endless Luxe Travel collects and processes personal data in order to plan and operate journeys, manage its contracts and meet its legal obligations.
The data collected may include: name, date of birth, tax number, address, email, telephone, and the identification and travel document details a booking requires.
- Clients and representatives of clients
- Users of our services
- Suppliers and their representatives
- Employees and collaborators
Retention period
Data is kept for as long as the commercial relationship is in force, and may be held for longer where the law provides, for the defence of rights in legal proceedings.
Once the maximum retention period has passed, data is irreversibly anonymised or securely destroyed.
Rights of data subjects
Data subjects may exercise the following rights by written request sent to info@endlessluxetravel.com:
- Access — to consult the personal data processed and obtain information on its purpose and retention period
- Rectification — to correct inaccurate or incomplete data
- Erasure — to request the deletion of data that is no longer necessary
- Restriction of processing — to restrict processing in certain circumstances
- Portability — to receive your data in a structured, machine-readable format
- Objection — to object to processing on grounds relating to your particular situation
- Complaint — to lodge a complaint with the CNPD or another competent supervisory authority
Security measures
Endless Luxe Travel maintains every technical means at its disposal to prevent unauthorised access to, loss of, or destruction of personal data:
- Communication over HTTPS with an SSL certificate
- Data transferred only in encrypted form
- Permanent monitoring of access to information systems
- Regular audits of the technical and organisational measures adopted
- Regular data protection training for staff
- Mechanisms for rapid recovery in the event of a physical or technical incident
Personal data breach
Endless Luxe Travel will notify data subjects when a breach occurs that entails a high risk to their rights and freedoms, within 72 hours of the incident.
International data transfers
The provision of services may involve transferring data to third countries outside the EU/EEA. In those cases, Endless Luxe Travel will adopt the measures required under applicable law to guarantee the protection of the data transferred.
Contacts
For more information about the processing of your data, or to exercise your legal rights, contact us at:
info@endlessluxetravel.com
Data Protection Officer: info@endlessluxetravel.com
August 2026