Legal

PrivacyPolicy

How we collect, use, share and protect personal data when you use the Design My Safari platform — including the legal bases we rely on and the rights you have.

Last updated20 May 2026
01

About this privacy notice

Design My Safari B.V. (“Design My Safari”, “we”, “us”, “our”) provides an online platform that lets travellers design safari itineraries, select routes and accommodation, communicate with tour operators, and confirm bookings. This privacy notice explains how we collect, use, share and protect personal data when you:

  • visit our websites (including designmysafari.com);
  • create an account, design or submit a safari;
  • communicate via our chat or other channels; and/or
  • confirm a booking and make a payment through our platform.

We value your trust and want you to understand what we do with your data, the legal bases we rely on, and the rights you have.

This notice applies to travellers and users of our platform. We may also publish separate privacy notices for tour operators and other business partners.

We may update this notice from time to time. Where changes are significant, we will take reasonable steps to highlight them before they take effect.

02

Key terms

To make this notice easier to read:

  • Platform — The Design My Safari website and its related booking, messaging, and payment systems.
  • Traveller / You — Anyone using or considering using our platform.
  • Tour / Safari Operator — A third-party safari operator who receives and fulfils bookings.
  • Booking — A confirmed safari booking accepted by you and fulfilled by a safari tour operator.
  • Personal data — Information that identifies you or can reasonably be linked to you.
03

Who we are (and our role under data protection law)

Controller. Design My Safari B.V. is typically the controller for personal data processed to run our platform, manage accounts, facilitate communication, take payments, and provide customer support.

Tour operators. When you confirm a booking, relevant details are shared with the tour operator so they can deliver your safari. Tour operators often act as independent controllers for their own processing (e.g. fulfilling the safari, meeting legal obligations, handling on-the-ground logistics). Their privacy practices are governed by their own policies.

Payment providers. Payments are handled through the platform using payment service providers. Those providers may process certain personal data as controllers or processors depending on the situation.

04

Personal data we collect

A) Data you give us

Depending on how you use the platform, we may collect:

  • Identity & contact details — name, email address, telephone number, country of residence, and similar identifiers.
  • Government-issued identification — passport or national ID details (such as document number, full name, nationality, and date of birth), collected only where required for booking administration, accommodation registration, or mandatory park-entry requirements.
  • Account details — login credentials (hashed), account preferences, saved itineraries, favourites.
  • Safari and booking details — travel dates, party size, accommodation selections, itinerary choices, budget range, special requirements (e.g. dietary or accessibility needs).
  • Communications — messages sent via platform chat, email, forms, or social media; call metadata (date / time / duration) if you call us.
  • Payment details — we typically do not store full card details ourselves; these are handled by payment providers. We may receive payment confirmations, payment status, limited identifiers (e.g. transaction reference), and billing details as needed for accounting and support.

B) Data you give us about others

If you book for other travellers (e.g. a partner, family, other individual or group), you may provide their identity & contact details, and special requirements (e.g. dietary or accessibility needs). You must ensure you have permission to share their data and that they understand this notice.

C) Data we collect automatically

When you use the platform, we may automatically collect:

  • Device and usage data — IP address, browser type, device identifiers, operating system, language settings, pages viewed, clicks, and referring pages.
  • Approximate location — derived from IP address. We do not collect precise GPS location.
  • Cookie and similar tracking data — described in the Cookies section below.

D) Data we receive from other sources

We may receive personal data from:

  • Tour operators (e.g. booking updates, fulfilment status, operational messages);
  • Payment service providers (e.g. payment confirmation, fraud signals, chargebacks);
  • Marketing / analytics partners (e.g. aggregated campaign performance, attribution data);
  • Public sources (limited checks for fraud prevention or dispute handling, where lawful).
05

Special categories of data (sensitive data)

Some information, such as health-related details (e.g. mobility needs) can be considered special category data under GDPR. We ask you not to share sensitive data in free-text fields unless it is necessary. Where we do process special category data, we will only do so where we have a lawful basis (for example, your explicit consent or where necessary for reasons of substantial public interest, depending on circumstances).

06

Why we use your personal data

We use personal data to:

Provide the platform and your account

Create and manage accounts, save itineraries, store preferences.

Facilitate and administer bookings

Confirm your booking, issue confirmations, share necessary details with tour operators, handle changes / cancellations, and support booking administration.

Process payments and prevent fraud

Take payment through our payment providers, manage refunds / chargebacks, detect suspicious activity, protect the platform and users.

Enable communication

Provide platform chat and messaging between travellers and tour operators; send service messages (confirmations, reminders, security alerts).

Customer support

Respond to enquiries, resolve issues, handle disputes, and provide assistance.

Park entry and conservation access

Collect and share traveller identification details (such as full name, nationality, date of birth, passport or national ID number) where required by national park authorities or conservation bodies in order to arrange park entrance permits, fees, and access for safari activities. This processing is necessary to ensure lawful entry into protected areas and to allow tour operators to comply with park regulations and on-the-ground entry controls.

Improve and secure our services

Analytics, testing, troubleshooting, measuring performance, improving usability, and maintaining security.

Marketing (where permitted)

Send newsletters and promotions (where you opt in or where lawful), measure campaign performance, and show relevant offers.

07

Legal bases we rely on

Under GDPR / UK GDPR, we rely on one or more of these legal bases:

  • Contract — to provide the platform and administer bookings you request.
  • Legitimate interests — to improve services, prevent fraud, secure systems, and communicate operationally (balanced against your rights).
  • Consent — for certain marketing communications and certain cookies / trackers (where required).
  • Legal obligation — for tax / accounting, responding to lawful requests, and regulatory compliance.
08

How we share personal data

We share personal data only when necessary for the purposes above, including with:

A) Tour operators (booking fulfilment)

When you confirm a booking, we share the details required for fulfilment, such as your name, contact details, travel dates, party size, itinerary, accommodation selections, and relevant preferences / requirements.

B) Payment service providers

We use payment providers to process card and other electronic payments. They may process your payment details and share confirmations and fraud signals with us.

C) Service providers (processors)

We may use trusted providers to support our platform, such as:

  • cloud hosting and infrastructure;
  • customer support tools;
  • email delivery and communications;
  • analytics and performance monitoring;
  • security and fraud prevention services;
  • CRM and marketing tools (where applicable).

These providers are authorised to process personal data only on our instructions, under appropriate contracts.

A current list of our key service providers is available on request from our privacy contact.

D) Professional advisers and authorities

We may share data with legal advisers, auditors, insurers, or regulators where necessary, and with competent authorities where we are legally required to do so.

E) Business transfers

If we are involved in a merger, acquisition, restructuring, or sale of assets, personal data may be transferred as part of that process (subject to safeguards).

09

International transfers

We are based in the Netherlands and generally process data within the EEA. Where personal data is transferred outside the EEA / UK (for example, if a service provider hosts data in another country), we use appropriate safeguards such as:

  • the European Commission’s Standard Contractual Clauses; and / or
  • UK international data transfer mechanisms;
  • plus additional technical and organisational measures where needed.
10

Data retention

We keep personal data only as long as necessary for the purposes described, including:

  • to provide services and maintain your account;
  • to handle bookings, disputes, refunds and chargebacks;
  • to comply with legal obligations (e.g. accounting / tax); and
  • to prevent fraud and protect the platform.

Retention periods vary depending on the data type and legal requirements. Where possible, we anonymise or delete data when it is no longer needed.

11

Security

We use a combination of technical and organisational measures to protect personal data, such as access controls, encryption in transit where appropriate, logging, monitoring, and secure development practices. No system is perfectly secure, but we work to maintain appropriate safeguards and review them regularly.

12

Cookies and similar technologies

We use cookies and similar technologies to:

  • enable essential site functions (functional cookies);
  • understand how the platform is used (analytics cookies); and
  • (where applicable and lawful) support marketing (marketing cookies).

Where required by law, we ask for your consent before placing analytics / marketing cookies. You can also control cookies through your browser settings and (where available) our cookie preferences tool.

Cookie notice. We may publish a separate Cookie Notice with a detailed list of cookies and retention periods.

13

Automated decision-making and AI

We may use automated tools to help:

  • detect and prevent fraud, abuse, or spam;
  • prioritise support requests; and
  • improve recommendations and user experience (e.g. suggesting itineraries or relevant accommodations).

We do not intend to make decisions that have legal or similarly significant effects on you solely by automated means without human involvement. If this changes, we will update this notice and explain your rights and safeguards.

14

Children and minors

Our platform is designed for use by adults. User accounts and bookings must be created by persons aged 18 or over.

However, safari bookings may include children under the age of 18 who are travelling as part of a family or group. In such cases:

  • Personal data relating to minors (such as name, age, date of birth, nationality, or identification details) is collected only from a parent or legal guardian as part of a booking made by an adult.
  • This information is processed solely for legitimate travel-related purposes, including booking administration, safety requirements, accommodation arrangements, and mandatory park entry and conservation authority requirements.
  • We do not knowingly permit minors to create their own accounts or submit personal data directly through the platform.

If we become aware that personal data relating to a minor has been provided without appropriate parental or guardian authority, we will take reasonable steps to delete or restrict that data, unless we are legally required to retain it.

If you believe that a minor’s personal data has been processed by us inappropriately, please contact us using the details in the Contact us section.

15

Your rights

Subject to applicable law, you may have the right to:

  • Access your data;
  • Correct inaccurate data;
  • Delete your data;
  • Restrict or object to processing (including where we rely on legitimate interests);
  • Withdraw consent (where processing is based on consent); and
  • Data portability (in certain situations).

You can exercise rights by contacting us (see below). For security, we may need to verify your identity before responding.

You also have the right to lodge a complaint with your local supervisory authority.

16

Contact us

Data Controller

Design My Safari B.V.

Address
Lauriergracht 30-1
1016 RL Amsterdam
The Netherlands
Privacy contact
[email protected]
17

Changes to this policy

We may update this policy to reflect changes to our services, legal requirements, or how we process data. The “Last updated” date at the top shows when changes were made.