Comprehensive Privacy Policy (GDPR / Global Standard)
Last Updated: August 29, 2026
This Privacy Policy explains how FinTours ("we", "us") processes personal data when you visit our website, use our AI assistant, or book travel services. We adhere to the stringent requirements of the EU General Data Protection Regulation (GDPR), the UK GDPR, and major global privacy frameworks.
1. Data Controller
FinTours
Email: info@fintours.org
[Insert Legal Address/Registration Number Here]
Data Protection Officer: privacy@fintours.org
2. What Data We Collect and How We Collect It
We collect data directly from you, automatically through your website usage, and occasionally from co-travelers who book on your behalf:
- Master Data: First name, last name, date of birth, gender, nationality.
- Contact Data: Email address, phone/WhatsApp number, billing address.
- Travel Data: Passport number, expiration date, frequent flyer numbers, Known Traveler numbers (TSA/Global Entry).
- Special Categories of Data (Art. 9 GDPR): We only process health data (e.g., wheelchair assistance) or religious data (e.g., halal/kosher meals) if you explicitly provide it to us for the purpose of the booking.
- Payment Data: Credit card details (processed securely via PCI-DSS compliant providers; we do not store full card numbers).
- Technical & Usage Data: IP address, browser type, device ID, log files, and chat transcripts with our AI assistant (Mira).
3. Purposes and Legal Bases of Data Processing
We process your data based on the following legal grounds:
3.1 Fulfillment of Contract (Art. 6(1)(b) GDPR):
- To process your booking inquiries and reserve flights, hotels, and tours.
- To manage your customer portal and issue travel documents.
- To provide customer support and process cancellations/refunds.
3.2 Legal Obligations (Art. 6(1)(c) GDPR):
- To comply with commercial and tax retention laws (e.g., retaining invoices for up to 10 years).
- To fulfill international border and aviation security mandates (e.g., Advanced Passenger Information / Secure Flight data required by governments like the USA, Canada, or UK).
3.3 Legitimate Interests (Art. 6(1)(f) GDPR):
- To prevent fraud and ensure IT security.
- To optimize our website and train our AI assistant to better serve luxury travel queries.
3.4 Consent (Art. 6(1)(a) GDPR):
- To send marketing newsletters (you can unsubscribe at any time).
- To process special dietary or medical requests.
4. Data Sharing and Third-Party Recipients
Because travel is inherently global, we must share your data with essential third parties:
- Travel Providers: Airlines, hotels, car rental agencies, and local transfer operators.
- Global Distribution Systems (GDS): Systems like Amadeus, Sabre, or Travelport used to finalize airline reservations.
- Service Providers: Payment gateways (e.g., Stripe, PayPal), cloud hosting providers, and customer support software.
- Government Authorities: Customs, immigration, and security agencies (e.g., US Customs and Border Protection) when required by the itinerary.
5. International Data Transfers (Third Countries)
If you book a trip outside the European Economic Area (EEA), your data must be transferred to the destination country to fulfill the contract (Art. 49(1)(b) GDPR). For internal IT systems and service providers located outside the EEA (e.g., server hosts in the US), we ensure data protection through standard contractual clauses (SCCs) issued by the EU Commission or rely on adequacy decisions (e.g., EU-US Data Privacy Framework).
6. AI Assistant (Mira) and Automation
Our AI assistant, Mira, uses natural language processing to assist with inquiries. Chat transcripts are securely logged to ensure context is maintained when transferring your case to a human luxury travel consultant. No automated decision-making (profiling) is used that produces legal effects concerning you (Art. 22 GDPR).
7. Cookies and Tracking Technologies
We use cookies to enable core website functionality, remember currency preferences, and analyze site traffic.
- Essential Cookies: Required for the website to function (e.g., keeping you logged in). Cannot be disabled.
- Analytics & Marketing Cookies: Used only with your explicit consent via our Cookie Banner to analyze behavior and offer tailored travel advertisements.
8. Your Data Protection Rights
You have the following rights regarding your personal data:
- Right to Access (Art. 15 GDPR): Request a copy of the data we hold about you.
- Right to Rectification (Art. 16 GDPR): Correct inaccurate data.
- Right to Erasure (Art. 17 GDPR): Request deletion of data (subject to legal retention periods).
- Right to Restriction (Art. 18 GDPR) & Portability (Art. 20 GDPR).
- Right to Object (Art. 21 GDPR): Object to processing based on legitimate interest, particularly direct marketing.
To exercise your rights, please email us at privacy@fintours.org.
9. Right to Lodge a Complaint
If you believe your data has been processed unlawfully, you have the right to lodge a complaint with a supervisory authority. In Germany, this is the State Commissioner for Data Protection in the federal state of your residence or our company's registration (e.g., Die Landesbeauftragte für Datenschutz und Informationsfreiheit Bremen).