Legal

Privacy Policy

Last updated:

GDPR Compliant

CruiseRMD ('we', 'us', 'our') is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use our website or services, and sets out your rights under the General Data Protection Regulation (GDPR) and applicable data protection law.

Data Controller

The data controller responsible for your personal data is CruiseRMD, 1 River Plaza, Suite 400, New York, NY 10004. You can contact our Data Protection Officer at [email protected] or by writing to the address above.

1. Data We Collect

  • Identity & contact dataName, email address, telephone number, and postal address — collected when you submit a booking enquiry, create an account, or contact us.
  • Booking & travel dataPassport details, date of birth, nationality, travel preferences, dietary requirements, and accessibility needs — collected when you make a booking.
  • Financial dataPayment card details processed securely via our payment provider. We do not store full card numbers on our systems.
  • Technical & usage dataIP address, browser type, device identifiers, pages visited, and time spent on pages — collected automatically via cookies and server logs when you visit our website.
  • Marketing preferencesYour opt-in or opt-out choices for email newsletters and promotional communications.

2. Lawful Basis for Processing

  • Contract performanceProcessing your booking, managing your voyage, and providing customer support — necessary to fulfil our contract with you.
  • Legal obligationRetaining financial records, complying with ABTA/ATOL requirements, and responding to regulatory requests.
  • Legitimate interestsImproving our website and services, preventing fraud, and sending service-related communications to existing customers.
  • ConsentSending marketing emails and placing non-essential cookies — only where you have given explicit, freely withdrawable consent.

3. How We Use Your Data

We use your personal data to: process and manage your booking; communicate with you about your voyage; send you relevant travel information and updates; comply with legal and regulatory obligations; improve our website and services; detect and prevent fraud; and, where you have consented, send you marketing communications about river cruise offers and news.

4. Who We Share Your Data With

We share your data only where necessary: with cruise line operators and accommodation providers to fulfil your booking; with payment processors to handle transactions securely; with ABTA and the CAA (ATOL) as required by our membership obligations; with IT service providers who host and maintain our systems under strict data processing agreements; and with law enforcement or regulatory bodies where required by law. We do not sell your personal data to third parties.

5. International Transfers

Some of our cruise line partners and service providers are based outside the UK and European Economic Area (EEA). Where we transfer your data internationally, we ensure appropriate safeguards are in place — such as Standard Contractual Clauses approved by the European Commission — to protect your data to the same standard as within the EEA.

6. Data Retention

We retain your personal data only for as long as necessary for the purposes set out in this policy. Booking records are kept for 7 years to comply with financial and regulatory obligations. Marketing preferences are retained until you withdraw consent. Website analytics data is retained for 26 months. When data is no longer required, it is securely deleted or anonymised.

7. Cookies

Our website uses cookies to improve your experience and analyse site usage. Essential cookies are required for the site to function and are placed without consent. Analytics and marketing cookies are placed only with your explicit consent, which you can manage or withdraw at any time via our cookie preference centre. For full details, please see our Cookie Policy.

8. Your GDPR Rights

  • Right of accessYou may request a copy of the personal data we hold about you (a Subject Access Request).
  • Right to rectificationYou may ask us to correct inaccurate or incomplete personal data.
  • Right to erasureYou may ask us to delete your personal data where there is no compelling reason for us to continue processing it.
  • Right to restrict processingYou may ask us to suspend processing of your data in certain circumstances.
  • Right to data portabilityYou may request a machine-readable copy of the data you provided to us.
  • Right to objectYou may object to processing based on legitimate interests or for direct marketing at any time.
  • Right to withdraw consentWhere processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
  • Right to lodge a complaintYou have the right to lodge a complaint with your national supervisory authority — in the UK, the Information Commissioner's Office (ICO) at ico.org.uk.

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or destruction. These include TLS encryption for data in transit, access controls, regular security reviews, and staff training. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by law.

10. Children's Privacy

Our services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The current version will always be available on this page with the date it was last updated. We will notify you of material changes by email where we hold your contact details.

Exercise Your Rights

To submit a Subject Access Request, withdraw consent, or raise a data protection concern, contact our Data Protection Officer at [email protected] or use the form below.

Contact Our DPO