Last Updated: August 19, 2026
violet-nebula is committed to complying with the General Data Protection Regulation and protecting the privacy rights of individuals within the European Economic Area and the United Kingdom.
violet-nebula acts as the data controller for personal information collected through our website and services. We determine the purposes and means of processing your personal data.
Data Controller:We process personal data under the following lawful bases:
When you submit a booking request or contact form, you provide explicit consent for us to process your information for the stated purposes.
Processing is necessary to perform our travel services contract with you, including booking coordination and trip management.
We may process data based on legitimate business interests, such as improving our services, analyzing website usage, and maintaining security.
We process certain data to comply with legal requirements, including financial record-keeping and regulatory obligations.
Under GDPR, you have the following rights regarding your personal data:
You have the right to request copies of your personal data that we hold. We will provide this information in a commonly used electronic format.
You can request correction of inaccurate or incomplete personal data.
You may request deletion of your personal data under certain circumstances, subject to legal retention requirements.
You can request that we limit how we use your personal data in specific situations.
You have the right to receive your personal data in a structured, machine-readable format and transmit it to another controller.
You may object to processing based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing that produces legal or similarly significant effects.
To exercise any of your GDPR rights, please contact us at [email protected] with your request. We will respond within one month of receiving your request.
You will need to provide sufficient information to verify your identity before we can process your request.
For questions specifically about data protection and GDPR compliance, you may contact our data protection representative at [email protected].
We retain personal data for different periods depending on the type of information and purpose:
We work with third-party service providers who process data on our behalf. All processors are contractually obligated to protect your data in accordance with GDPR requirements.
When transferring data outside the UK or EEA, we ensure appropriate safeguards are in place through:
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected individuals without undue delay.
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority.
UK Supervisory Authority:
Information Commissioner's Office (ICO)
Website: ico.org.uk
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. The last updated date will be revised accordingly.