Independent travel guide. Curated routes & verified local operators.
⚠ Draft for legal review. This document was prepared as a structured starting point for review by a UK-qualified solicitor. It has not been reviewed by a lawyer and is not legal advice. Before publishing, have a solicitor confirm it complies with UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), and Turkish KVKK to the extent it applies.

The short version

Contents

  1. Who’s the data controller
  2. Sites this covers
  3. What data we collect
  4. Why we use it (lawful bases)
  5. Who we share it with
  6. International transfers
  7. Cookies & similar tech
  8. How long we keep it
  9. How we protect it
  10. Your rights
  11. Children
  12. Changes to this policy
  13. Contact & complaints

1. Who’s the data controller

The data controller for personal data collected through this service is Pixelo Mobile Ltd, a company registered in England and Wales (company number 10585806), registered office Demsa Accounts, 565 Green Lanes, Haringey, London, England, N8 0RL.

For data-protection enquiries: privacy@explorelycia.com.

We are not currently required to appoint a Data Protection Officer (DPO) under UK GDPR Article 37. Our ICO registration number is [INSERT once registered].

2. Sites this covers

This policy applies to:

It does not cover third-party sites you reach by clicking a link from us — including operator websites, Stripe, our payment processor, or partner platforms. Each of those has its own privacy policy.

3. What data we collect

3.1 Data you give us directly

When
What we collect
Required?
Lawful basis
You submit a booking enquiry on oludenizairgames.co.uk
Name, email, phone, party size, preferred dates, free-text notes
Yes (name + email)
Legitimate interest + your consent at submit
You sign up to a newsletter
Email, optional name, language preference
Yes (email)
Consent
You apply to list your business (operators)
Business name, contact name, email, phone, website, languages, category, description
Yes (business + email + phone)
Pre-contract steps + legitimate interest
You subscribe to a paid tier (operators)
Above, plus billing details collected by Stripe
Yes
Contract performance
You log in to the operator dashboard
Email, signed magic-link token, JWT in your browser
Yes
Contract performance + security
You email us
Whatever you write
You decide
Legitimate interest

3.2 Data we collect automatically

3.3 Data we don’t collect

We do not collect:

4. Why we use it (lawful bases under UK GDPR Art. 6)

  1. To forward your booking enquiry to the named operator. Lawful basis: legitimate interest (operating a directory matching travellers with operators) plus your consent at the point of submitting.
  2. To provide the operator dashboard and process subscription payments. Lawful basis: contract performance.
  3. To send the newsletter (only if you opted in). Lawful basis: consent. You can withdraw at any time via the unsubscribe link.
  4. To respond to your emails. Lawful basis: legitimate interest.
  5. To detect and prevent abuse (spam, fraud, scraping, attacks). Lawful basis: legitimate interest in maintaining the security and integrity of the service.
  6. To comply with legal obligations (accounting records, lawful information requests). Lawful basis: legal obligation.

We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects on you.

5. Who we share it with

5.1 Operators

When you submit a booking enquiry, we forward your name, email, phone, party size, dates, and notes to the operator you selected. From that point on, that operator is a separate, independent data controller. Their handling of your data is governed by their own privacy policy and applicable law in their jurisdiction (typically Turkey for Lycian-coast operators).

We require operators (under our Operator Listing Terms) to use your data only to respond to your specific enquiry and not to add you to marketing lists or sell your data.

5.2 Service providers (data processors acting on our behalf)

5.3 Other recipients

5.4 What we never do

6. International transfers

The UK is the home base for this service. However, personal data flows internationally in two main scenarios:

You can ask us at any time which countries your specific data has been transferred to.

7. Cookies and similar technologies

We use the minimum technical storage needed for the service to function. Specifically:

We do not use:

Because no non-essential cookies are set, we do not currently display a cookie banner under PECR. If we add analytics in future, we’ll add a banner with proper consent before the first such cookie is set.

8. How long we keep your data

Data type
Retention
Then
Why
Booking enquiries
12 months
Anonymised or deleted
Customer-service follow-up window
Newsletter subscribers
Until you unsubscribe
Email removed; suppression hash kept
To honour the unsubscribe
Operator account & subscription records
Duration of subscription + 6 years
Anonymised or deleted
UK accounting law (Companies Act 2006)
Magic-link tokens
15 minutes (single-use)
Immediately invalid
Security; never persisted to DB
Server access logs
90 days
Aggregated then deleted
Security and abuse investigation
Email correspondence
3 years
Deleted
Service quality and dispute resolution
Stripe payment data
Per Stripe’s policy (typically 7 years)
Per Stripe
Stripe’s legal obligations

9. How we protect your data

No system is perfectly secure. If we discover a breach affecting your personal data, we’ll notify the ICO within 72 hours where required by UK GDPR Art. 33, and notify you directly if it’s likely to result in a high risk to your rights and freedoms.

10. Your rights under UK GDPR

You have the following rights in respect of your personal data:

  1. Access (Art. 15) — ask for a copy of what we hold about you
  2. Rectification (Art. 16) — correct inaccurate data
  3. Erasure (Art. 17) — ask us to delete your data, subject to lawful exceptions
  4. Restriction (Art. 18) — ask us to pause processing while a dispute is resolved
  5. Portability (Art. 20) — receive a machine-readable copy of data you gave us
  6. Objection (Art. 21) — object to processing based on legitimate interest, including direct marketing
  7. Withdraw consent — for processing based on consent, withdraw it at any time (won’t affect lawfulness of past processing)
  8. Complain to the ICO — the UK’s data-protection regulator at ico.org.uk/make-a-complaint or 0303 123 1113

How to use a right: email privacy@explorelycia.com from the email address on file (or include enough information to verify your identity). We respond within 30 calendar days. There’s no fee in normal cases; for manifestly unfounded or excessive requests we may charge a reasonable admin fee or refuse, in line with UK GDPR Art. 12(5).

11. Children

The directory and booking-enquiry service are aimed at adult travellers and adult business owners. We don’t knowingly collect personal data from children under 16. If you believe a child has submitted personal data through us, email privacy@explorelycia.com and we’ll delete it.

Adults may, of course, submit booking enquiries on behalf of family members including children — in which case the adult is responsible for the information they provide.

12. Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top reflects the most recent change. Material changes (e.g. a new processor, a new lawful basis, a new data category) will be flagged with a banner on the home page for at least 14 days before they take effect. We’ll also email registered operators directly about material changes that affect their account.

Old versions are archived for 12 months — available on request from privacy@explorelycia.com.

13. Contact & complaints

For any privacy-related question, request, or concern:

If you’re not satisfied with our response, you can complain to the UK Information Commissioner’s Office:

Reminder: this draft requires legal review before publication. Your solicitor should pay particular attention to: clause 6 (international transfers to Turkey, where adequacy isn’t in place — the consent + contract basis needs validation), clause 8 (retention periods, especially the 6-year accounting overlap), and clause 5.2 (each named processor needs a current data processing agreement on file).