Last updated: August 2026
topaz-ember operates in full compliance with the General Data Protection Regulation (GDPR) and related UK data protection legislation. We take your privacy seriously and have implemented appropriate measures to ensure your personal data is processed lawfully, fairly, and transparently.
We process your personal data based on several legal grounds depending on the nature of our interaction. When you request travel services, we process your information to fulfill our contractual obligations. In some cases, we rely on legitimate interests to improve our services or comply with legal obligations that apply to travel service providers.
Where required, we obtain your explicit consent before processing certain types of data. You may withdraw consent at any time without affecting the lawfulness of processing conducted before withdrawal.
Under GDPR, you have comprehensive rights regarding your personal data. You may request access to the information we hold about you and receive a copy in a structured, commonly used format. If you believe any data is inaccurate, you have the right to request corrections.
You may also request erasure of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes it was collected, or when you withdraw consent. The right to be forgotten is subject to exceptions, particularly where we have legal obligations to retain information.
Additional rights include the ability to restrict processing, object to processing based on legitimate interests, and request data portability to transfer your information to another service provider.
We maintain records of our data processing activities as required by GDPR. Personal data collected through our website and inquiry forms is processed to provide travel planning services, respond to questions, and maintain records for legal compliance.
Data is stored securely within the European Economic Area or in jurisdictions with adequate data protection standards. When transfers occur to third countries, we ensure appropriate safeguards are in place through mechanisms such as standard contractual clauses.
For matters specifically related to data protection and GDPR compliance, you may contact our designated data protection representative at [email protected]. We will respond to all requests within the timeframes mandated by applicable law.
We do not engage in automated decision making or profiling that produces legal effects or similarly significant impacts on individuals. All travel recommendations and service decisions involve human assessment and input from our team.
In the unlikely event of a data breach that poses risks to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Affected individuals will be informed without undue delay when the breach is likely to result in high risk to their rights.
Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without appropriate parental consent, we will take steps to delete that information promptly.
You have the right to lodge a complaint with a data protection supervisory authority if you believe our processing of your personal data violates applicable law. In the United Kingdom, the relevant authority is the Information Commissioner's Office.
We regularly review our data protection practices to ensure ongoing compliance with GDPR and evolving regulations. Material changes to how we process personal data will be communicated through updates to our privacy documentation.