Legal document
DRAFT VERSION — FOR LEGAL REVIEW. This is a professional working draft, not the approved final version. Delete this single paragraph once legal counsel has approved the document.
Effective date: 11 July 2026
LeBo Travel B.V. ("LeBo Travel", "we", "us" or "our") is a company established in the Netherlands. For the purposes of the General Data Protection Regulation ("GDPR") and other applicable data-protection laws, LeBo Travel B.V. is the controller of the personal data described in this Policy.
Controller details: LeBo Travel B.V., [registered office address], the Netherlands.
Privacy contact: [privacy@lebotravel.com]. You may also contact us through our contact page.
This Policy explains how we handle personal data when you visit our website, submit an enquiry or intake, purchase a service, communicate with us, book a call, or otherwise interact with LeBo Travel. It does not govern third-party websites or services that have their own notices.
Depending on your interaction, we may process:
Please do not send passport numbers, payment-card details, visa documents, health information, or other sensitive personal data unless we specifically request it through an appropriate channel and explain why it is needed.
We may use personal data to respond to requests; assess, deliver, and support our services; process payments; arrange calls; maintain records; secure our website and systems; prevent fraud or misuse; comply with legal obligations; and establish, exercise, or defend legal claims.
Where the GDPR applies, we rely on one or more of the following legal bases: performance of a contract or steps taken at your request before entering into a contract; compliance with a legal obligation; our legitimate interests in operating, securing, and improving our business and services; and consent, where required. We obtain consent for optional cookies and for other processing where consent is the appropriate legal basis.
We collect information directly from you through forms, email, calls, payments, and other communications. We may also receive limited information from service providers involved in your request, such as payment, scheduling, form-security, hosting, or communications providers.
We use carefully selected providers to operate our website and business. Depending on the service, these may include payment processors (such as Stripe), scheduling tools, form providers, cloud hosting and security providers, email/communications providers, and professional advisers. They may process personal data on our instructions or under their own privacy notices where they act independently.
We may also disclose information where required by law, to protect rights, safety, or security, in connection with a corporate transaction, or with your direction or consent. We do not sell personal data.
Our providers and partners may process information outside your country, including outside the European Economic Area or United Kingdom. When we transfer personal data internationally, we use a lawful transfer mechanism, such as an adequacy decision or the European Commission's Standard Contractual Clauses, together with supplementary measures where appropriate.
We retain enquiry and intake records for up to 24 months after our last meaningful interaction; service and support records for up to 24 months after completion; and invoices, payment records, and other records required for accounting or tax purposes for the period required by applicable law, generally seven years in the Netherlands. We may retain information longer where necessary to resolve disputes, enforce agreements, or comply with legal obligations.
We use reasonable administrative, technical, and organisational measures designed to protect personal data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Subject to applicable law, you may request access, correction, deletion, restriction, objection, or data portability, and you may withdraw consent at any time where processing is based on consent. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the supervisory authority in your habitual residence, place of work, or place of the alleged infringement. To exercise a right, contact us at the privacy contact above. We may request information necessary to verify your identity.
Our use of cookies and similar technologies is described in our Cookie Notice. Where consent is required for non-essential technologies, we will provide an appropriate choice mechanism before setting them.
Our services are not directed to children, and we do not knowingly collect personal data from children without appropriate authority. If you believe a child has provided personal data to us without appropriate permission, contact us so we can review the request.
We may update this Policy when our practices, services, or legal requirements change. The effective date shown on this page identifies the latest version.