Privacy Policy

Last updated: August 2026

Velvet Hippo Ltd respects your privacy and is committed to protecting your personal information.

This Privacy Policy explains how we collect, use, store, disclose and protect personal information when you:

  • visit our website;

  • contact us with an enquiry;

  • request a quotation or travel proposal;

  • make or participate in a booking;

  • use our travel planning, concierge or lifestyle services;

  • communicate with us by email, telephone, messaging service or social media;

  • subscribe to our marketing communications;

  • act as a Supplier, professional contact or corporate client; or

  • otherwise interact with Velvet Hippo.

Please read this Privacy Policy carefully. It should be read alongside our Booking Terms and Conditions, Cookie Policy and any privacy information supplied by the relevant Booking Provider, tour operator, airline, hotel or other Supplier.

In this Privacy Policy, Booking Provider means Colletts Travel Limited or another organisation, platform or intermediary through which a booking is arranged. Supplier means an airline, hotel, tour operator, venue, transport provider or other third party providing a travel or lifestyle service.

1. WHO WE ARE

Velvet Hippo Ltd is a company registered in England and Wales under company number 17223465.

Our registered office is:

167–169 Great Portland Street
London
W1W 5PF

We trade as:

Velvet Hippo

For the purposes of UK data-protection law, Velvet Hippo Ltd is the controller of the personal information we collect and use for our own business, advisory, planning, booking-support, concierge, administration and marketing activities.

This means that we determine why and how that information is used.

Privacy contact

Questions, requests and complaints relating to this Privacy Policy or our use of personal information should be directed to:

Email: hello@velvethippo.co.uk
Telephone: +44 (0)20 3051 2325
Post: Velvet Hippo Ltd, 167–169 Great Portland Street, London W1W 5PF.

Please mark written correspondence for the attention of the Privacy Contact.

2. HOW BOOKING INFORMATION IS SHARED

Velvet Hippo Ltd is independently owned and operated.

Travel bookings are generally made through Colletts Travel Limited and arranged under its licence, with the company acting as licence holder. Selected lifestyle and ancillary services may be arranged separately through specialist third-party suppliers.

Where necessary to research, arrange, administer or support a booking, we may share personal information with the licence holder, another Booking Provider or the relevant Supplier.

Depending on its role, the recipient may process that information as:

  • a separate controller responsible for its own use of the information;

  • a processor acting on our instructions; or

  • another party involved in providing the booking or service.

Where another organisation acts as a separate controller, its own privacy policy will apply. You should also read the privacy information provided by the relevant Booking Provider, tour operator, airline, hotel, venue or Supplier.

Velvet Hippo remains responsible for the personal information it controls. We are not responsible for the independent privacy practices of another controller.

Colletts Travel Limited’s Privacy Policy is available on its website.

3. THE PERSONAL INFORMATION WE COLLECT

The information we collect depends on the nature of your enquiry, booking or relationship with us.

3.1 Identity information

This may include:

  • full name;

  • title;

  • previous or alternative names;

  • date of birth;

  • age;

  • gender, where relevant to a booking;

  • nationality;

  • passport information;

  • passport expiry date;

  • visa or entry-authorisation information;

  • driving-licence details;

  • government-issued identification;

  • photographs or copies of identification documents; and

  • signatures.

3.2 Contact information

This may include:

  • home, business or billing address;

  • email address;

  • telephone and mobile numbers;

  • emergency contact details;

  • social-media account or messaging details; and

  • preferred method of communication.

3.3 Travel and booking information

This may include:

  • destinations and travel dates;

  • flight, accommodation and transport details;

  • arrival and departure information;

  • traveller names and passenger details;

  • rooming and occupancy information;

  • seat, cabin and room preferences;

  • baggage requirements;

  • loyalty, frequent-flyer and hotel-membership numbers;

  • known-traveller or trusted-traveller details;

  • car-hire and driver information;

  • visa, transit and entry requirements;

  • dietary preferences;

  • accessibility and assistance requirements;

  • special requests;

  • activity, dining and entertainment preferences;

  • celebration and special-occasion information;

  • previous and planned travel;

  • travel companions and family relationships;

  • corporate travel-policy information; and

  • itinerary, ticket, voucher and booking-reference information.

3.4 Financial and transaction information

This may include:

  • billing information;

  • amounts paid or payable;

  • deposits, balances and refunds;

  • bank-transfer references;

  • partial payment-card details;

  • payment-provider references;

  • invoices and receipts;

  • chargeback or payment-dispute information;

  • currency and transaction information; and

  • records relating to commissions, fees and Supplier payments.

Where you pay through a third-party payment provider, that provider may collect your full payment-card information directly.

Velvet Hippo does not normally need to retain the full card number or card security code. We may receive a payment token, transaction reference, last four digits or other limited confirmation from the payment provider.

You should not send full payment-card details or card security codes to us by ordinary email, WhatsApp or social-media message.

3.5 Communication and service information

This may include:

  • enquiries and quotation requests;

  • emails, messages and correspondence;

  • notes of telephone conversations;

  • preferences and instructions;

  • feedback and survey responses;

  • complaints and claims;

  • records of assistance provided;

  • marketing preferences;

  • consent records; and

  • records of our relationship with you.

3.6 Website and technical information

When you use our website, we may collect:

  • internet protocol address;

  • browser type and version;

  • device type;

  • operating system;

  • approximate location derived from technical information;

  • website pages viewed;

  • dates and times of visits;

  • referring website or link;

  • website interactions;

  • cookie identifiers;

  • consent preferences;

  • form submissions;

  • website security information; and

  • diagnostic and performance information.

Further information is provided in our Cookie Policy.

3.7 Corporate and professional information

For corporate clients, Suppliers and professional contacts, we may collect:

  • organisation name;

  • job title and department;

  • business contact details;

  • employee or traveller identifiers;

  • billing and account information;

  • internal travel-policy information;

  • authorised-booker information;

  • authority and approval records;

  • Supplier contracts and commercial correspondence; and

  • professional or regulatory information.

3.8 Identity, fraud and compliance information

Where reasonably necessary, we may collect:

  • proof of identity and address;

  • company-registration information;

  • information confirming authority to make a booking;

  • payment-verification information;

  • fraud-risk indicators;

  • sanctions-screening results;

  • information about suspected unauthorised transactions; and

  • information needed to comply with legal, regulatory or Booking Provider requirements.

4. SPECIAL-CATEGORY PERSONAL INFORMATION

Some information requires additional protection under data-protection law.

In the course of arranging travel, we may need to process information relating to:

  • physical or mental health;

  • disabilities or mobility requirements;

  • allergies;

  • medication;

  • medical equipment;

  • pregnancy;

  • dietary requirements that reveal health information or religious beliefs;

  • religious requirements;

  • other sensitive personal circumstances.

We will collect only the information reasonably necessary to understand and communicate your requirements.

Our lawful basis under Article 6 will usually be taking steps before entering into a contract, performing our contract with you, or our legitimate interests in arranging travel for another person included in the booking. We will normally rely on explicit consent as the additional Article 9 condition for processing special-category information.

In addition, we will normally rely on your explicit consent as the special-category condition permitting us to use and disclose the information.

In limited circumstances, we may instead process sensitive information where:

  • it is necessary to protect someone’s vital interests and they are physically or legally unable to consent;

  • it is necessary to establish, exercise or defend legal claims; or

  • another condition permitted by law applies.

Where required, we will ask you to provide explicit consent for us to share relevant health, accessibility or dietary information with the Booking Providers and Suppliers responsible for delivering the service.

You may withdraw consent at any time. However, if the information is necessary to arrange or safely provide a service, withdrawing consent may mean that we or the Supplier cannot continue with that element of the booking.

5. INFORMATION ABOUT CHILDREN

Our website and services are not directed specifically at children acting independently.

We may nevertheless process information about children where they are travelling with, or under the authority of, a parent, guardian, school, corporate client or other responsible adult.

This may include:

  • name;

  • date of birth and age;

  • passport and travel-document details;

  • relationship to accompanying adults;

  • parental-consent information;

  • dietary or medical requirements;

  • accessibility requirements; and

  • information needed by airlines, hotels, border authorities or other Suppliers.

The Lead Booker must have appropriate authority to provide a child’s information and to make decisions relating to the child’s booking.

Where explicit consent is required for sensitive information about a child, we may seek consent from the parent, guardian or other person authorised to provide it.

We do not knowingly use children’s personal information for direct marketing.

6. INFORMATION ABOUT OTHER TRAVELLERS

A Lead Booker, family member, personal assistant, employer or corporate travel manager may provide information about other travellers.

When you provide information about another person, you confirm that:

  • the information is accurate;

  • you have authority or another lawful basis to provide it;

  • the person understands that their information will be used to arrange the booking;

  • you will bring this Privacy Policy and relevant Supplier privacy information to their attention; and

  • where sensitive information is provided, the person has agreed to its disclosure unless another lawful condition applies.

Where appropriate and reasonably practicable, we may also provide privacy information directly to the other traveller.

7. HOW WE OBTAIN PERSONAL INFORMATION

We may obtain information:

  • directly from you;

  • from the Lead Booker;

  • from another traveller;

  • from a family member, personal assistant, representative or guardian;

  • from your employer or corporate travel manager;

  • from the licence holder, another Booking Provider or a Supplier;

  • from airlines, hotels, tour operators and other Suppliers;

  • from payment providers and financial institutions;

  • from loyalty and membership programmes;

  • from our website, cookies and technical systems;

  • from social-media and messaging platforms;

  • from public registers, sanctions lists and company-information services;

  • from insurers, claims handlers and professional advisers; and

  • from authorities where permitted by law.

If we obtain your information from someone other than you, we will provide the necessary privacy information within the period required by law, unless an exemption applies or you already have the information.

8. HOW AND WHY WE USE PERSONAL INFORMATION

We use personal information only where we have a lawful basis for doing so. The lawful basis may vary depending on the information, the person concerned and the purpose of the processing.

8.1 Responding to enquiries and preparing proposals

We use information to:

  • understand your requirements;

  • communicate with you;

  • research destinations and Suppliers;

  • prepare quotations and Travel Options documents;

  • check prices and availability; and

  • recommend suitable arrangements.

We normally rely on taking steps at your request before entering into a contract, performance of a contract, or our legitimate interests in responding to prospective clients and providing professional travel-planning services.

8.2 Arranging and administering bookings

We use information to:

  • make reservations;

  • issue confirmations;

  • arrange flights, accommodation, transfers and experiences;

  • communicate traveller details to Booking Providers and Suppliers;

  • process amendments and cancellations;

  • manage payments and refunds;

  • provide tickets, vouchers and itineraries;

  • communicate time-sensitive updates; and

  • support you before, during and after travel.

We normally rely on performance of a contract, taking pre-contractual steps at your request, or our legitimate interests in arranging travel for persons included within a booking.

8.3 Providing concierge and lifestyle services

We may use information to:

  • arrange dining;

  • secure theatre or event tickets;

  • organise transfers, guides or chauffeurs;

  • arrange celebrations and special occasions;

  • make experience and activity reservations;

  • provide destination support; and

  • respond to in-trip requests.

We normally rely on performance of a contract or taking steps at your request before entering into a contract.

8.4 Managing payments and financial records

We use information to:

  • issue invoices and payment requests;

  • receive and allocate payments;

  • make onward payments to Booking Providers and Suppliers;

  • reconcile accounts;

  • process commissions and refunds;

  • prevent duplicate or fraudulent transactions;

  • deal with payment disputes; and

  • maintain tax and accounting records.

We rely on performance of a contract, compliance with legal obligations and our legitimate interests in managing payments, preventing fraud and maintaining accurate business records.

8.5 Identity, fraud, security and sanctions checks

We may use information to:

  • verify identity;

  • establish authority to make a booking;

  • confirm payment legitimacy;

  • prevent fraud and chargebacks;

  • protect clients, Velvet Hippo and Suppliers;

  • comply with sanctions or legal restrictions; and

  • investigate suspicious activity.

We rely on legal obligations where applicable and our legitimate interests in protecting our business, clients, Booking Providers and Suppliers.

8.6 Customer service, complaints and legal claims

We use information to:

  • provide customer support;

  • investigate service issues;

  • respond to complaints;

  • communicate with Suppliers;

  • assist with insurance or recovery claims;

  • establish what occurred;

  • protect legal rights; and

  • defend or pursue legal claims.

We rely on performance of a contract, compliance with legal obligations and our legitimate interests in resolving disputes and protecting our legal position.

8.7 Service improvement and business administration

We may use information to:

  • understand client preferences;

  • maintain client profiles;

  • improve our services;

  • train and support authorised personnel;

  • manage Suppliers and professional service providers;

  • monitor business performance;

  • maintain security;

  • prevent misuse of our systems; and

  • plan and administer our business.

We rely on our legitimate interests in operating and improving a professional travel and concierge business.

Where possible, we use anonymised or aggregated information for reporting and analysis.

8.8 Legal and regulatory compliance

We may use information to:

  • comply with tax and accounting requirements;

  • respond to lawful requests from authorities;

  • comply with court orders;

  • meet data-protection obligations;

  • comply with package-travel, consumer-protection, data-protection and other applicable travel-industry requirements;

  • maintain legally required records; and

  • report or investigate suspected unlawful conduct.

We rely on compliance with legal obligations and, where appropriate, our legitimate interests in protecting our rights and complying with professional standards.

8.9 Emergencies and vital interests

In an emergency, we may use or disclose information where reasonably necessary to:

  • protect the life or physical safety of a traveller or another person;

  • contact an emergency contact;

  • communicate with medical professionals;

  • contact insurers, local authorities or consular services; or

  • assist an incapacitated traveller.

We may rely on vital interests, performance of a contract or another lawful basis appropriate to the circumstances.

9. LEGITIMATE INTERESTS

Where we rely on legitimate interests, those interests may include:

  • providing responsive and personalised client service;

  • administering enquiries and bookings;

  • arranging travel for members of a travelling party;

  • maintaining accurate client and Supplier records;

  • understanding client preferences;

  • preventing fraud and unauthorised payments;

  • protecting our systems and communications;

  • improving our website and services;

  • managing our commercial relationships;

  • recovering money owed;

  • dealing with disputes and legal claims; and

  • marketing relevant services where permitted.

Before relying on legitimate interests, we consider whether the processing is necessary and whether your interests, rights or freedoms override our interests.

You may object to processing based on legitimate interests. Further information appears in section 20.

10. WHEN YOU MUST PROVIDE INFORMATION

Some personal information is required to:

  • prepare an accurate quotation;

  • identify travellers;

  • comply with airline, hotel or border requirements;

  • make or administer a booking;

  • process payment;

  • arrange appropriate assistance;

  • issue tickets or travel documents; or

  • comply with legal or Supplier requirements.

You are not always legally required to provide information. However, if you do not provide information needed for the requested service, we may be unable to:

  • provide an accurate proposal;

  • make or confirm a booking;

  • process payment;

  • arrange accessibility or medical assistance;

  • issue travel documents; or

  • continue providing the service.

We will explain where particular information is mandatory.

11. WHO WE SHARE PERSONAL INFORMATION WITH

We disclose personal information only where reasonably necessary for the purposes described in this Privacy Policy.

Recipients may include:

11.1 Booking Providers and travel Suppliers

This may include:

  • Colletts Travel Limited, acting as licence holder;

  • other Booking Providers;

  • tour operators;

  • airlines and aviation providers;

  • hotels, resorts, villas and property managers;

  • cruise and yacht operators;

  • rail and coach companies;

  • car-hire providers;

  • chauffeurs and transfer companies;

  • destination management companies;

  • ground handlers;

  • guides and excursion providers;

  • restaurants;

  • theatres, venues and event organisers;

  • ticketing and hospitality providers;

  • airport-assistance providers; and

  • other travel and lifestyle Suppliers.

We share only the information reasonably required to check availability, obtain a quotation, make the booking, provide the service, manage changes or respond to an issue.

11.2 Payment and financial-service providers

This may include:

  • payment processors;

  • merchant-service providers;

  • banks;

  • card issuers;

  • fraud-prevention providers; and

  • accounting and invoicing providers.

11.3 Technology and professional service providers

This may include providers of:

  • website hosting;

  • customer-relationship management systems;

  • email and communications;

  • cloud storage;

  • document management;

  • electronic signatures;

  • itinerary and booking systems;

  • analytics;

  • security and fraud prevention;

  • IT support;

  • accountancy;

  • legal advice;

  • insurance;

  • auditing; and

  • business administration.

These providers may act as processors under contracts requiring appropriate confidentiality and security.

11.4 Corporate clients and authorised representatives

Where travel is booked by an employer or organisation, we may share relevant booking, expense and traveller information with:

  • the employer;

  • an authorised travel manager;

  • a personal assistant;

  • an account administrator;

  • the person paying for the travel; or

  • another authorised representative.

We will not ordinarily disclose private information unrelated to the corporate booking.

11.5 Authorities and legal recipients

We may disclose information to:

  • border and immigration authorities;

  • customs authorities;

  • police and law-enforcement bodies;

  • courts and tribunals;

  • tax authorities;

  • regulatory bodies;

  • the Information Commissioner’s Office;

  • the Civil Aviation Authority;

  • fraud-prevention bodies;

  • insurers and claims handlers; and

  • professional advisers.

We do so only where required or permitted by law or reasonably necessary to establish, exercise or defend legal rights.

11.6 Business transfers

If Velvet Hippo is sold, merged, reorganised or transfers part of its business, relevant information may be disclosed to professional advisers, prospective purchasers or the acquiring organisation, subject to appropriate confidentiality and data-protection safeguards.

12. WE DO NOT SELL PERSONAL INFORMATION

Velvet Hippo does not sell personal information to data brokers or unrelated third parties.

We do not provide personal information to another organisation so that it can market unrelated products or services to you without an appropriate lawful basis.

Sharing information with Booking Providers and Suppliers to research, arrange, administer or support your travel is not a sale of personal information.

13. INTERNATIONAL TRANSFERS

International travel necessarily involves sending personal information to organisations in other countries.

For example, we may need to send traveller information to:

  • an overseas hotel;

  • an airline;

  • a destination management company;

  • a transfer provider;

  • a cruise operator;

  • a local guide;

  • an event venue;

  • immigration or border authorities; or

  • an overseas technology or support provider.

Some countries may not provide the same level of legal protection for personal information as the United Kingdom.

Where UK international-transfer rules apply to a transfer initiated by Velvet Hippo, we will use an appropriate lawful mechanism where required. Depending on the circumstances, this may include:

  • UK adequacy regulations;

  • the UK International Data Transfer Agreement;

  • the UK Addendum to approved standard contractual clauses;

  • another legally recognised safeguard; or

  • a permitted exception, including where the transfer is necessary to perform a contract with you or to take steps at your request.

Where the overseas recipient is an independent controller, it may process information under its own privacy policy and the laws applying in its country.

You may contact us for further information about the safeguards applying to a particular transfer.

14. MARKETING COMMUNICATIONS

We may send information about:

  • destinations;

  • travel offers;

  • new services;

  • events;

  • inspiration and editorial content;

  • relevant travel or lifestyle benefits; and

  • other Velvet Hippo travel or lifestyle services.

We will send electronic marketing only where:

  • you have consented;

  • the existing-customer exception applies and we are promoting similar services; or

  • another lawful basis is available under applicable marketing law.

Where we rely on the existing-customer exception, you will have been given an opportunity to opt out when your details were collected and in every subsequent marketing message.

Business contact details may be used for relevant business-to-business marketing where permitted by law.

You may stop receiving marketing at any time by:

  • selecting the unsubscribe option in a marketing email;

  • replying and asking to unsubscribe; or

  • contacting hello@velvethippo.co.uk.

Withdrawing from marketing will not affect booking confirmations, payment notices, itinerary updates, disruption messages or other communications necessary to provide your service.

When you opt out, we may retain minimal information on a suppression list so that we can respect your preference and avoid contacting you again for marketing.

15. COOKIES AND SIMILAR TECHNOLOGIES

Our website may use cookies and similar technologies, including:

  • essential cookies;

  • security cookies;

  • preference cookies;

  • analytics technologies;

  • embedded-content technologies; and

  • marketing technologies.

Essential technologies may be used where necessary to operate the website, maintain security, remember privacy choices or provide a service requested by you.

Where consent is required, non-essential technologies will not be activated until you have made a choice through our cookie banner or consent tool.

You can accept, reject or manage non-essential cookies through the website’s cookie settings.

Further information about the technologies used, their purposes, providers and duration is contained in our Cookie Policy.

Your cookie choices do not prevent us from collecting limited technical information necessary for website security, fraud prevention or basic operation where permitted by law.

16. SOCIAL MEDIA AND THIRD-PARTY PLATFORMS

If you contact or interact with Velvet Hippo through a social-media or messaging platform, the platform provider will also process information under its own privacy policy.

This may include platforms used for:

  • social-media messaging;

  • WhatsApp communications;

  • comments and reactions;

  • advertising;

  • content sharing; and

  • website integrations.

We recommend that you review the platform’s privacy settings and privacy policy.

Sensitive travel documents, full payment-card details and confidential medical information should not be sent through public comments or insecure social-media channels.

17. HOW LONG WE KEEP PERSONAL INFORMATION

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including satisfying legal, accounting, regulatory, tax, contractual and dispute-resolution requirements.

The appropriate period depends on:

  • the type of information;

  • the nature and duration of the client relationship;

  • the booking and Supplier requirements;

  • whether travel has been completed;

  • potential legal claims;

  • regulatory and accounting obligations;

  • consent and marketing preferences; and

  • the sensitivity and security risk of retaining the information.

Our usual retention periods are as follows.

17.1 Enquiries that do not result in a booking

Enquiry, proposal and correspondence information will normally be retained for up to 24 months after the last substantive contact.

We may retain it longer where you remain actively engaged with us, have asked us to continue planning, or a dispute or legal reason requires continued retention.

17.2 Confirmed bookings and client records

Booking confirmations, invoices, financial records, contractual communications and core client records will normally be retained for up to six years after completion of the booking or the end of the client relationship.

This allows us to maintain accounting records, respond to complaints, deal with claims and establish or defend legal rights.

17.3 Client preference profiles

Travel preferences, loyalty information and relevant client-profile information may be retained while you remain an active client so that we can provide a personalised service.

You may ask us to update or delete non-essential profile information.

17.4 Passport and identity information

Copies of passports, visas and identity documents retained within systems controlled by Velvet Hippo will normally be deleted or securely redacted within 90 days after completion of the relevant trip, once they are no longer required for booking administration, complaints, claims or legal obligations.

Where a client asks us to maintain an ongoing travel profile, we may retain limited passport information, such as the traveller’s name, nationality, passport number and expiry date, to assist with future bookings.

Information retained within an ongoing travel profile will be reviewed periodically and at least annually. It will normally be deleted after 24 months without a booking or substantive client contact, unless continued retention remains reasonably necessary or is required by law.

Full passport or identity-document copies will not ordinarily be retained solely for the convenience of possible future bookings.

17.5 Health, accessibility and other sensitive information

Sensitive information retained within systems controlled by Velvet Hippo will normally be deleted within 90 days after completion of the relevant trip.

With the traveller’s explicit consent, relevant health, accessibility, dietary or other sensitive information may be retained within an ongoing travel profile to assist with future bookings.

Information retained for this purpose will be reviewed at each new booking and at least annually. It will normally be deleted after 24 months without a booking or substantive client contact, or sooner where consent is withdrawn or the information is no longer necessary, unless continued retention is required or permitted by law.

17.6 Complaints, incidents and claims

Information relating to complaints, incidents, refunds, chargebacks and legal claims may be retained for up to six years after the matter is concluded, or longer where legal proceedings or another lawful requirement makes this necessary.

17.7 Marketing information

Marketing information will be retained until you withdraw consent, object or unsubscribe, or until we determine that it is no longer accurate or useful.

Minimal suppression information may be retained after opt-out to ensure that your preference continues to be respected.

17.8 Website and cookie information

Website and cookie information is retained for the periods described in our Cookie Policy and consent-management system.

When a retention period expires, information will be deleted, anonymised or securely archived where continued storage is legally required.

You may ask us at any time to update or delete information held within your ongoing travel profile. Any request will be considered in accordance with your data-protection rights and any legal or contractual reason requiring continued retention.

18. HOW WE PROTECT PERSONAL INFORMATION

We use proportionate technical and organisational measures designed to protect personal information against:

  • unauthorised access;

  • loss;

  • alteration;

  • disclosure;

  • misuse;

  • accidental destruction; and

  • unlawful processing.

These measures may include:

  • access controls;

  • password protection;

  • multi-factor authentication where available;

  • secure payment systems;

  • encryption in transit;

  • secure cloud and document-storage systems;

  • restricted access to sensitive information;

  • Supplier and processor due diligence;

  • confidentiality obligations;

  • backup and recovery measures;

  • staff awareness and training; and

  • incident-response procedures.

Access is limited to people and providers who reasonably need the information to perform their role or provide the relevant service.

No internet, email or storage system can be guaranteed completely secure. You should therefore:

  • use secure passwords;

  • protect your devices;

  • verify unexpected payment instructions;

  • avoid sending confidential documents through insecure channels; and

  • notify us promptly if you suspect unauthorised access or fraudulent communication.

If a personal-data breach occurs, we will investigate and notify the Information Commissioner’s Office and affected individuals where required by law.

19. YOUR DATA-PROTECTION RIGHTS

Depending on the circumstances and lawful basis, you may have the right to:

19.1 Access

You may ask whether we hold personal information about you and request a copy of that information.

19.2 Rectification

You may ask us to correct inaccurate information or complete incomplete information.

19.3 Erasure

You may ask us to delete personal information where there is no continuing lawful reason for us to retain it. The right to deletion is not absolute. We may need to retain information for legal, accounting, contractual or claims purposes.

19.4 Restriction

You may ask us to restrict the use of information in certain circumstances, including while accuracy or lawfulness is being considered.

19.5 Data portability

Where processing is based on consent or contract and carried out by automated means, you may be entitled to receive information you provided in a structured, commonly used and machine-readable format or ask us to transfer it to another controller where technically feasible.

19.6 Withdrawal of consent

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that took place lawfully before consent was withdrawn.

19.7 Objection

You may object to processing based on legitimate interests and you have an absolute right to object to the use of your personal information for direct marketing.

19.8 Automated decisions

You may have rights relating to decisions made solely by automated processing that produce legal or similarly significant effects.

19.9 Complaints

You may complain to us about our use of personal information and may also raise a concern with the Information Commissioner’s Office.

These rights are not all absolute and may not apply in every circumstance.

We may need to request information to verify your identity and ensure that information is not disclosed to an unauthorised person.

We will normally respond to a valid rights request without undue delay and within one calendar month. Where a request is particularly complex or multiple requests are made, the period may be extended as permitted by law. We will explain any extension.

We do not normally charge for exercising data-protection rights. A reasonable fee may be charged, or a request may be refused, where permitted by law because it is manifestly unfounded or excessive.

To exercise a right, contact: hello@velvethippo.co.uk

20. YOUR RIGHT TO OBJECT

You have the right to object at any time to the use of your personal information for direct marketing. If you object, we will stop using your information for that purpose.

You may also object where we rely on legitimate interests.

When you object to legitimate-interest processing, we will stop unless:

  • we demonstrate compelling legitimate grounds that override your interests, rights and freedoms; or

  • the processing is necessary to establish, exercise or defend legal claims.

To object, email hello@velvethippo.co.uk and explain the processing to which you object.

21. AUTOMATED DECISION-MAKING

Velvet Hippo does not ordinarily make decisions about clients based solely on automated processing where the decision would have a legal or similarly significant effect.

Payment, booking, security and fraud-prevention providers may use automated systems to assess transactions or identify unusual activity.

Where this results in a payment or booking being delayed or declined, we may request further information or arrange for the matter to be reviewed.

If we introduce solely automated significant decision-making, we will provide the additional information and protections required by law.

22. DATA-PROTECTION COMPLAINTS

You have the right to complain if you are dissatisfied with how Velvet Hippo has collected, used, shared, retained or protected your personal information.

A data-protection complaint may relate to:

  • failure to provide access to information;

  • inaccurate information;

  • unwanted marketing;

  • inappropriate disclosure;

  • failure to delete information;

  • excessive collection or retention;

  • security concerns;

  • failure to respect a data-protection right; or

  • any other concern about our handling of personal information.

How to complain

Please send your complaint to:

Email: hello@velvethippo.co.uk
Subject: Data Protection Complaint

Alternatively, write to:

Privacy Contact
Velvet Hippo Ltd
167–169 Great Portland Street
London
W1W 5PF

Please include:

  • your name and contact details;

  • a description of the issue;

  • relevant dates;

  • booking or correspondence references;

  • any supporting documents; and

  • the outcome you are seeking.

We will:

  • provide a clear way for you to raise the complaint;

  • acknowledge the complaint within 30 days;

  • take appropriate steps to investigate it;

  • keep you informed where further time or information is needed; and

  • communicate the outcome without undue delay.

We may need to verify your identity or ask for clarification before completing the investigation.

Where the matter primarily concerns the licence holder, another Booking Provider or a Supplier acting as a separate controller, we may refer the complaint or help direct you to that organisation.

23. COMPLAINTS TO THE INFORMATION COMMISSIONER

You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection.

We would appreciate the opportunity to address the issue first, but you are not prevented from contacting the Information Commissioner.

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Telephone: 0303 123 1113

Complaints can also be submitted through the Information Commissioner’s Office website.

24. THIRD-PARTY WEBSITES

Our website, proposals or communications may contain links to websites operated by:

  • Colletts Travel Limited;

  • hotels;

  • airlines;

  • tour operators;

  • venues;

  • payment providers;

  • insurers;

  • government authorities; and

  • other third parties.

We do not control those websites and are not responsible for their privacy policies, cookies, security or content.

You should review the relevant third-party privacy policy before providing personal information through an external website.

25. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy to reflect:

  • changes in law or regulatory guidance;

  • changes to our services;

  • new Booking Providers, Suppliers or systems;

  • changes to our information-handling practices; or

  • security and operational developments.

The latest version will be published on our website and will show the date it was last updated.

Where a change materially affects how we use information already collected, we will provide additional notice where required.

26. CONTACT US

For privacy enquiries, rights requests, consent withdrawals or complaints, contact:

Velvet Hippo Ltd

Privacy email: hello@velvethippo.co.uk
Office: +44 (0)20 3051 2325

Registered office:
167–169 Great Portland Street
London
W1W 5PF

Registered in England and Wales under company number 17223465.

Your Journey Starts Here

Ready to begin planning your next escape? Get in touch and let us create a travel experience tailored around you.

Call 020 3051 2325, message on WhatsApp, or Request a Quote.

Stay Inspired

Discover new destinations, exceptional experiences and carefully selected travel ideas, along with the latest offers and inspiration from Velvet Hippo.