Introduction
At THOMAS ASHLEY, we are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share your information when you engage with our services, in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Who We Are
Thomas Ashley is a luxury travel design service acting as an agent, providing bespoke travel arrangements, including accommodation, flights, rental cars, and experiences. In order to facilitate these services, we collect and process certain personal data.
What Information We Collect
We may collect and process the following personal data:
Personal details: Name, contact details (email, phone number, address), and payment details.
Travel preferences: Destination preferences, accommodation choices, dietary requirements, mobility needs, and other relevant information.
Passport and visa details: Where necessary for travel bookings.
Communication data: Any correspondence between you and THOMAS ASHLEY.
How We Use Your Information
We collect and use your data for the following purposes:
To arrange and manage your travel bookings and itineraries.
To share necessary details with third-party suppliers, such as hotels, airlines, private transport providers, and experience operators, to facilitate your bookings.
To personalise and improve our services based on your preferences.
To send you service-related communications, including confirmations, itinerary updates, and relevant offers.
To comply with legal and regulatory obligations.
Sharing Your Information
We share your personal data with third-party travel suppliers solely for the purpose of booking and managing your travel arrangements. These suppliers include hotels, airlines, concierge services, and transportation providers. We ensure that all third parties adhere to appropriate data protection standards.
We do not sell, rent, or trade your personal information with any third parties for marketing purposes. However, we may disclose your information if required by law or to protect our legal rights.
Data Security
We implement appropriate technical and organisational measures to safeguard your personal data from unauthorised access, disclosure, or misuse. However, while we strive to protect your information, no data transmission over the internet can be guaranteed as 100% secure.
Retention of Your Data
We will retain your personal data only for as long as necessary to fulfil the purposes outlined in this policy, including satisfying legal, accounting, or reporting requirements.
Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
Access: Request a copy of the personal data we hold about you.
Correction: Request correction of inaccurate or incomplete data.
Erasure: Request deletion of your data where there is no legal reason for us to continue processing it.
Objection: Object to processing based on legitimate interests or direct marketing.
Data Portability: Request to receive your data in a structured, commonly used format.
To exercise any of these rights, please contact us at [email protected]
Marketing Preferences
We may send you promotional emails regarding our services. You can opt out of these communications at any time by clicking the “unsubscribe” link in our emails or contacting us directly.
Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on our website, and where appropriate, we will notify you via email.
Contact Us
If you have any questions or concerns about this Privacy Policy or how we handle your personal data, please contact us at:
Email: [email protected]
Last Updated: 01/01/2025