top of page

Privacy Policy

Last updated: 30 July 2026
 

WABI-SABI TRAVELS B.V. respects your privacy and handles your personal data carefully and transparently.
 

This Privacy Policy explains how we collect, use, share and protect personal data when you visit www.wabisabi-travels.com, contact us, request a proposal, book a journey or otherwise use our services.
 

1. Who is responsible for your data?
 

The controller responsible for processing your personal data is:

WABI-SABI TRAVELS B.V.
Herengracht 449 A
1017 BR Amsterdam
The Netherlands
Chamber of Commerce (KvK): 98196588

Website: www.wabisabi-travels.com
 

For privacy questions or requests, please contact us through our website contact form:

www.wabisabi-travels.com/contact
 

Please mention “Privacy Request” in your message.
 

2. What personal data do we collect?
 

Depending on your interaction with us, we may process:
 

  • Your name, address, email address and telephone number;

  • Information submitted through our contact or enquiry forms;

  • Travel dates, destinations, preferences, budget and itinerary information;

  • Names, dates of birth, nationalities and gender of travellers;

  • Passport details and, only where necessary, copies of travel documents;

  • Flight, accommodation, transport and activity information;

  • Billing details, invoices and payment information;

  • Emergency contact details;

  • Dietary, accessibility, allergy and health-related requirements;

  • Information about children travelling as part of your party;

  • Communications with us by email, telephone, video call, WhatsApp or other channels;

  • Complaints, feedback and customer-service records;

  • Marketing and communication preferences;

  • Technical website information, such as IP address, device type, browser information and pages visited;

  • Information provided by a lead booker, travel agent, corporate organiser or another person booking on your behalf.
     

We do not normally receive or store complete credit-card details. Payments may be processed directly by specialised payment providers.
 

Why do we process your data?
 

We process your personal data for the following purposes:
 

Enquiries and travel proposals
We use your data to answer enquiries and prepare travel proposals. The legal basis is taking steps at your request before entering into an agreement.
 

Designing and operating your journey
We use your data to design, book and operate your journey. This is necessary to perform our agreement with you.
 

Communication and customer support
We use your data to communicate with you before, during and after your trip. This is necessary to perform our agreement and supports our legitimate interest in providing effective customer service.
 

Reservations
We share the necessary information with hotels, guides, transport providers, airlines, restaurants and activity providers to make and manage your reservations. This is necessary to perform our agreement.
 

Payments and administration
We use relevant information to process invoices, payments and refunds and to maintain our financial records. This is necessary to perform our agreement and comply with legal obligations.
 

Disruptions and emergencies
We use personal data to provide assistance during disruptions or emergencies. This may be necessary to perform our agreement, protect our legitimate interests or protect someone’s vital interests.
 

Complaints and legal matters
We retain and use relevant information to handle complaints, resolve disputes and manage legal claims. This is based on our legitimate interests and legal obligations.
 

Security and fraud prevention
We process information where necessary to prevent fraud and protect our website, systems, travellers and business. This is based on our legitimate interests and legal obligations.
 

Improving our website and services
We may analyse how our website and services are used. Depending on the technology involved, this is based on our legitimate interests or your consent.
 

Marketing communications
We may send newsletters and marketing communications with your consent or, where legally permitted, based on an existing customer relationship. You can unsubscribe at any time.
 

Health, allergy and accessibility information
We only process health-related or other sensitive information when necessary to arrange your journey. Where required, we rely on your explicit consent or another applicable legal exception.
 

4. Sensitive personal data
 

Dietary requirements, allergies, disabilities or medical needs may reveal health, religious or other sensitive information.
 

We only process such information when it is necessary to arrange or operate your journey. Where required, we will ask for your explicit consent before processing or sharing it.
 

You may withdraw your consent at any time. However, this may affect our ability to provide services that depend on that information.
 

Please only provide sensitive information that is genuinely necessary for your trip.
 

5. Information about other travellers
 

A lead booker may provide personal data about family members, children or other travellers.
 

The lead booker must ensure that these travellers have been informed about this Privacy Policy and that they are authorised to provide their information. For children, information must be provided or approved by a parent or legal guardian.
 

We only use children’s personal data where necessary to plan, book and operate their journey.
 

6. Who receives your data?
 

We only share personal data when reasonably necessary. Recipients may include:

  • Our employees and authorised contractors;

  • Our affiliated local operations company in Japan, where involved in planning or operating your trip;

  • Hotels, ryokans and other accommodation providers;

  • Guides, drivers, transport companies and rental-car providers;

  • Airlines, railway operators and other carriers;

  • Restaurants, attractions, activity providers and other travel suppliers;

  • Technology, website hosting, cloud storage, communication and itinerary providers;

  • Payment providers, banks and accounting providers;

  • Professional advisers, auditors, insurers and legal representatives;

  • Emergency-assistance providers;

  • Public authorities, regulators or law-enforcement bodies where legally required.


Travel suppliers receive only the information reasonably necessary to provide their part of the journey.
 

Our service providers must process personal data securely and in accordance with applicable data-protection requirements.
 

7. International transfers
 

Because we specialise in travel to Japan, personal data may be transferred to and processed in Japan.
 

The European Commission has recognised Japan as providing an adequate level of protection for personal data. European Commission.
 

Some technology providers or travel suppliers may process information in other countries outside the European Economic Area. Where required, we use an adequacy decision, Standard Contractual Clauses or another legally recognised safeguard.
 

When a transfer is necessary to arrange a service in a destination requested by you, the transfer may also be necessary for the performance of the travel agreement.
 

You may contact us for more information about the safeguards applicable to a particular transfer.
 

8. How long do we retain data?
 

We do not retain personal data longer than reasonably necessary.
 

Our usual retention periods are:

  • Enquiries that do not result in a booking: up to 24 months after our last meaningful contact;

  • Proposals and general pre-booking communications: up to 24 months after our last contact;

  • Operational travel information: normally up to 2 years after completion of the trip;

  • Passport copies and sensitive health or dietary information: deleted or securely redacted as soon as reasonably possible after the trip, normally within 30 days, unless continued retention is legally required or necessary for an unresolved matter;

  • Invoices, payment records and legally required accounting information: at least 7 years;

  • Complaints and legal claims: for as long as required to resolve the matter and during the applicable limitation period;

  • Marketing information: until you withdraw your consent, unsubscribe or have been inactive for 24 months;

  • Cookie information: for the duration specified in our cookie settings or cookie notice.
     

Data may be retained longer if required by law, a regulatory authority, legal proceedings or an unresolved dispute. Where possible, information retained for statistical or historical purposes will be anonymised.
 

9. Marketing communications
 

We may send marketing communications when:

  • You have given us permission;

  • You requested information about our services; or

  • The law allows us to contact an existing customer about similar services.
     

Every electronic marketing message will provide a clear way to unsubscribe. You can also withdraw your consent by contacting us.
 

Withdrawing consent does not affect processing that took place before the withdrawal.
 

10. Cookies and website technology
 

Our website uses cookies and similar technologies to:

  • Operate the website securely;

  • Remember website and privacy preferences;

  • Measure website performance;

  • Understand how visitors use our website; and

  • Support marketing, where you have consented.
     

Necessary cookies may be used without consent where legally permitted. We only use non-essential analytics or marketing cookies after obtaining the required consent.
 

You can accept, reject or change your cookie preferences through the cookie settings on our website. You can also delete cookies through your browser settings.
 

11. Security
 

We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration and disclosure.
 

These measures include access restrictions, password protection, secure systems, staff confidentiality obligations and limiting access to people who need the information for their work.
 

No internet-based system is completely secure. If we become aware of a personal-data breach, we will take appropriate action and notify the Dutch Data Protection Authority and affected individuals where legally required.
 

12. Your privacy rights
 

Subject to the conditions of the GDPR, you may have the right to:

  • Access the personal data we hold about you;

  • Correct inaccurate or incomplete information;

  • Request deletion of your personal data;

  • Restrict how we process your information;

  • Receive certain information in a portable format;

  • Object to processing based on legitimate interests;

  • Object to direct marketing at any time;

  • Withdraw consent at any time;

  • Ask for information about international-transfer safeguards; and

  • Lodge a complaint with a data-protection authority.
     

To exercise your rights, contact us through www.wabisabi-travels.com/contact and mention “Privacy Request”.
 

We may request additional information to verify your identity. We will normally respond within one month. In complex cases, the GDPR allows this period to be extended, but we will inform you if this applies.
 

You may lodge a complaint with the Dutch Data Protection Authority:

Autoriteit Persoonsgegevens
www.autoriteitpersoonsgegevens.nl/en
 

We would appreciate the opportunity to address your concerns directly first.
 

13. Automated decision-making
 

We do not use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects.
 

14. External websites
 

Our website may contain links to external websites, social-media platforms or third-party services. Their own privacy policies apply when you use those websites or services.

We are not responsible for the privacy practices of independent third parties.
 

15. Changes to this Privacy Policy
 

We may update this Privacy Policy when our services, systems or legal obligations change.

The current version will always be published on our website. Important changes will be communicated where appropriate.
 

One important implementation point: the Wix cookie banner should offer “Accept”, “Reject” and preference controls, and analytics or marketing cookies must remain disabled until consent. The Dutch Data Protection Authority states that only functional and limited low-impact analytical cookies may generally be placed without consent. Autoriteit Persoonsgegevens

bottom of page