Privacy Policy

Last updated: 29 July 2026

This Privacy Policy explains how Excelsior Escapes & Events - FZCO, trading as Excelsior Escapes and Events ("Excelsior", "we", "us", or "our"), handles personal data when you use excelsiorescapes.com (the "Site"), contact us, or ask us to plan or deliver a service. It applies to visitors and clients worldwide, including people in the United Arab Emirates, the European Economic Area (EEA), and the United Kingdom where applicable.

This notice describes our own handling of personal data. A travel supplier, venue, insurer, airline, accommodation provider, payment provider, or social platform may process data under its own privacy notice.

Controller and contact details

Excelsior Escapes & Events - FZCO is the controller for the personal data described in this notice. We are registered in the United Arab Emirates under Trade License No. 68842, issued by Dubai Integrated Economic Zones Authority (DIEZ). Our business address is Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, United Arab Emirates.

For privacy questions or requests, email suzette.vanwyk@excelsiorescapes.com or call +971563833034. Please use the subject line “Privacy request” so that we can identify and handle your request promptly.

Personal data we collect

  • Inquiry and contact data: name, email address, phone number when provided, service interest, and the content of your message or brief.
  • Service and booking data: information you or your authorised contact provide that is necessary to scope, arrange, or support a requested travel, event, relocation, or Travel With Purpose service.
  • Correspondence: information you share through email, telephone, WhatsApp, or another communication channel you choose to use.
  • Technical and usage data: IP address, device and browser information, pages viewed, referring URLs, and cookie or similar-technology data where you have allowed optional technologies. See our Cookie Policy.

Please do not send passport numbers, payment-card details, health information, or other sensitive data through the Site's first inquiry form. If such information is genuinely needed for a confirmed service, we will tell you the appropriate and secure way to provide it.

Why we use personal data

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

  • To respond to your request and take steps toward an agreement: to reply to an inquiry, prepare a proposal, arrange requested services, and communicate about an existing engagement.
  • Legitimate interests: to run and protect our business and Site, prevent misuse, keep appropriate records, and improve our services, provided those interests are not overridden by your rights and freedoms.
  • Legal obligations: to meet applicable accounting, tax, regulatory, or legal requirements.
  • Your consent: for optional analytics and advertising technologies, and for any other processing where consent is required. You may withdraw consent at any time; withdrawal does not affect processing already carried out lawfully before it.

We do not sell personal data. We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you.

Who may receive personal data

We share data only when necessary for the purposes above, including with:

  • email and form-delivery provider Brevo, which routes Site inquiries to our team;
  • Google and Meta, only when you enable the relevant optional analytics or marketing technologies;
  • suppliers involved in a service you ask us to arrange, such as travel, accommodation, transport, event, or destination providers, where needed to deliver that service; and
  • professional advisers, authorities, or other recipients where disclosure is required by law, necessary to establish or defend legal claims, or needed to protect people or property.

We require service providers to handle data only for authorised purposes and with appropriate safeguards. They may be independent controllers where they decide how to use data for their own services.

International transfers

We are based in the UAE and serve an international client base. Personal data may therefore be accessed or processed in the UAE and in other countries where we, our providers, or relevant suppliers operate. These locations may not provide the same level of data protection as your home country.

Where an EEA or UK transfer is subject to transfer restrictions, we will use an applicable transfer mechanism and safeguards required by law, such as an adequacy decision or contractual protections. You may ask us for information about the relevant safeguards by contacting us.

How long we keep data

We retain personal data only for as long as necessary for the purpose for which it was collected. Inquiries that do not lead to a service are normally retained for up to 24 months after our last meaningful contact. Where a service is arranged, we retain relevant records for the engagement and for any additional period needed for accounting, tax, dispute-resolution, or legal obligations. We may keep limited information for longer where needed to protect or exercise legal rights.

Your privacy rights

Depending on your location and applicable law, you may have rights to request access to, correction of, deletion of, or a copy of your personal data; to ask us to restrict processing; to object to certain processing, including direct marketing; and to receive data you provided in a portable format. You may also withdraw consent where processing relies on it.

To make a request, use the contact details above. We may need to verify your identity and will respond within the time required by applicable law. If you are in the EEA or UK, you may also complain to the data-protection authority in your country of habitual residence, workplace, or the place of the alleged infringement. UAE data subjects may use the rights and remedies available under applicable UAE data-protection law.

Security

We use reasonable technical and organisational measures designed to protect personal data from unauthorised access, loss, misuse, alteration, or disclosure. No internet transmission or storage system can be guaranteed completely secure.

Children

The Site is not directed to children. A parent, guardian, school, or other authorised adult should make an inquiry for a child or group involving minors. If you believe a child has submitted personal data without appropriate authority, contact us and we will review the request promptly.

Changes to this policy

We may update this policy when our data practices or applicable requirements change. The current version will be posted here with its revision date.

WhatsAppStart a conversation