PRIVACY & DATA POLICY
Last updated: 27 July 2026
1. Who we are
This Privacy & Data Policy explains how Global Dec Ltd (“Global Dec”, “we”, “us”, or “our”) collects, uses, stores, shares and protects personal data when you visit our website, contact us, or purchase or receive our services, including, where applicable, travel ground arrangements and cultural accompaniment.
Data Controller
Global Dec Ltd
Company No. 10385559
Registered Office:
3 Oakwood Gardens
Consett
DH8 0BX
United Kingdom
Email: office@global-dec.com
As the owner of this website, Global Dec Ltd acts as the Data Controller for the personal data collected through the website.
Our website is hosted by Wix, which provides the website infrastructure and related services. Where applicable, Wix processes visitor data on our behalf as a data processor under its own Data Processing Agreement.
2. Legal framework
We process personal data in accordance with:
* the UK General Data Protection Regulation (UK GDPR);
* the Data Protection Act 2018.
Where we provide services to individuals located within the European Union or the European Economic Area (EEA), we also take into account the principles and requirements of the EU General Data Protection Regulation (EU GDPR), where applicable.
3. What personal data we collect
We may collect and process the following categories of personal data.
3.1 Information you provide
This may include:
* name;
* email address;
* telephone or WhatsApp number;
* postal address where required;
* booking details;
* travel preferences;
* correspondence with us;
* invoices and receipts;
* traveller information required to provide travel services, including passport details where necessary, nationality, date of birth and emergency contact information;
* payment references and payment status.
We do not store complete payment card details.
3.2 Information collected automatically
When you use our website, we may automatically collect:
* IP address;
* browser type;
* device identifiers;
* operating system;
* referral pages;
* pages visited;
* date and time of access;
* cookies and similar technologies (see Section 12).
3.3 Special category data
Where necessary for travel or safety purposes, you may voluntarily provide information relating to health, dietary requirements or accessibility needs.
We process this information only where necessary to provide our services and apply additional safeguards. Such information is shared only where strictly required, for example with accommodation providers or local suppliers responsible for meeting those requirements.
4. Why we use your data
We use personal data to:
1. respond to enquiries;
2. provide our services;
3. manage bookings and customer support;
4. coordinate travel ground arrangements with hotels, transport providers, guides and other suppliers;
5. process payments and fulfil accounting, legal and fraud prevention obligations;
6. improve our website, services and user experience;
7. send operational communications, including booking confirmations, schedule updates and document requests;
8. send marketing communications where permitted by law and in accordance with your preferences.
5. Lawful bases for processing
Depending on the circumstances, we rely on one or more of the following lawful bases.
Contract
Where processing is necessary to perform a contract or to take steps requested before entering into a contract.
Legal obligation
Where processing is necessary to comply with legal, regulatory, accounting or tax obligations.
Legitimate interests
Where processing is necessary for the operation, security and improvement of our business and website, provided such interests are not overridden by your rights and freedoms.
Consent
Where consent is required, including for certain cookies, marketing communications or the processing of special category data.
You may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.
6. Who we share your data with
We share personal data only where necessary.
Website provider
Wix, which hosts and operates our website.
Payment providers
Payment providers selected by you (such as PayPal, Stripe or other available providers) and banking institutions involved in payment processing.
These providers may act as independent data controllers for their own legal and regulatory obligations.
Travel suppliers
Where necessary to deliver travel services, we may share relevant information with:
* hotels;
* accommodation providers;
* transport companies;
* local guides;
* venues;
* restaurants;
* other service providers involved in your itinerary.
Only the information necessary to provide the service is shared.
Professional advisers
Where required, we may disclose personal data to:
* accountants;
* auditors;
* legal advisers;
* insurers;
* regulators;
* law enforcement authorities.
We do not sell personal data.
​
7. International data transfers
Because some of our technology providers and travel suppliers operate internationally, your personal data may be transferred to, stored in or accessed from countries outside the United Kingdom or the European Economic Area.
Where UK personal data is transferred internationally, we rely, where appropriate, on recognised transfer mechanisms including:
* UK adequacy regulations;
* the UK International Data Transfer Agreement (IDTA);
* the UK Addendum to the EU Standard Contractual Clauses;
* or any other lawful safeguard recognised under UK data protection law.
Where EU personal data is transferred outside the EEA, we rely on:
* European Commission adequacy decisions;
* the EU Standard Contractual Clauses;
* or other lawful transfer mechanisms permitted under the EU GDPR.
Where appropriate, we also assess transfer risks and implement supplementary safeguards to protect personal data.
The United Kingdom currently benefits from a European Commission adequacy decision permitting personal data to flow from the EEA to the UK, subject to applicable legal review.
8. Data retention
We retain personal data only for as long as necessary to:
* provide our services;
* fulfil contractual obligations;
* comply with legal and accounting requirements;
* resolve disputes;
* protect our legal rights.
Retention periods vary depending on the type of information and applicable legal obligations.
When personal data is no longer required, it is securely deleted or anonymised where appropriate.
​
9. Security
We implement appropriate technical and organisational measures designed to protect personal data against:
* unauthorised access;
* loss;
* alteration;
* disclosure;
* destruction;
* misuse.
These measures include restricted access controls, secure storage and reasonable security procedures.
However, no internet transmission or electronic storage system can be guaranteed to be completely secure.
10. Your rights
Depending on applicable law, you may have the right to:
* be informed;
* access your personal data;
* request correction of inaccurate information;
* request deletion of your data;
* restrict processing;
* object to processing;
* request data portability where applicable;
* withdraw consent;
* object to automated decision-making and profiling where applicable.
Requests may be sent to:
We may request proof of identity before responding.
11. Marketing communications
We will send marketing communications only where permitted by law.
Every marketing communication includes an option to unsubscribe or opt out.
Operational communications relating to bookings or services are not marketing communications and may continue while your booking or contractual relationship remains active.
12. Cookies and analytics
We use cookies and similar technologies to:
* operate the website;
* remember user preferences;
* improve website performance;
* analyse website usage;
* support website functionality.
Where required by law, visitors are presented with a cookie banner allowing them to manage their cookie preferences.
If third-party services such as Google Analytics are enabled, they may place cookies or collect device and usage information in accordance with their own privacy policies.
Rejecting non-essential cookies may limit certain website functionality.
13. Children’s data
Our services are generally intended for adults.
Where services involve minors, personal data must be provided by a parent, legal guardian or another authorised adult, who confirms they have the authority to do so.
We do not knowingly collect children’s personal data directly through our website without appropriate authorisation.
​
14. Third-party websites
Our website may contain links to third-party websites.
We are not responsible for their privacy practices or content.
We encourage users to review the privacy policies of those websites before providing personal information.
​
15. Complaints
If you have any questions or concerns regarding this Policy or our processing of personal data, please contact:
We will make every reasonable effort to resolve your concerns.
You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO).
If you are located in the European Union or the European Economic Area, you may also contact your local supervisory authority.
​
16. Changes to this Policy
We may update this Privacy & Data Policy from time to time to reflect changes in legislation, technology, our services or our business operations.
The most recent version will always be published on this page together with its Last updated date.