Privacy Policy

 

Effective date: 21 August 2026

This Privacy Policy explains what personal information Latitude 40 Enterprises Limited collects and uses when you enquire about or book travel, communicate with us, use the Portugal Holidays website, subscribe to marketing or otherwise deal with us. It also explains who receives the information, how long we keep it and your rights.

1. Who we are

1.1 Latitude 40 Enterprises Limited, trading as Portugal Holidays, is the controller of the personal information covered by this policy. We are registered in England and Wales under company number 01209645. Our registered office is 21A Pembridge Road, London W11 3HG; this address is not open to the public.

1.2 For questions about this policy or to exercise a data-protection right, email info@portugalholidays.co.uk or telephone 0207 871 7036.

2. Information we collect

2.1 The information we collect depends on your enquiry, booking and relationship with us. It may include:

·   identity information, including title, name, date of birth, gender where relevant to a supplier requirement, nationality and passenger type;

·   contact information, including postal address, email address, telephone number and WhatsApp contact details;

·   passport, identity-document, visa, immigration and entry information, including document number, issuing country and expiry date;

·   booking and travel information, including destinations, dates, flights, accommodation, transfers, car hire, activities, seating preferences, loyalty numbers and other itinerary details;

·   payment and transaction information, including amounts paid, payment method, masked or transaction references, invoices, refunds and outstanding balances;

·   special requirements, including medical, disability, reduced-mobility, allergy, dietary and other accessibility information where necessary for your arrangements;

·   emergency-contact information and, where relevant, insurance or claim information;

·   communications with us, including emails, WhatsApp Business messages, enquiry forms, complaint records and recorded telephone calls;

·   technical and website information, including IP address, device/browser information, cookie identifiers and website activity where permitted; and

·   marketing preferences and records of consent, withdrawal or objection.

2.2 We do not normally need a complete copy of a passport when the required details can be provided securely in another form. If a copy is supplied, we use and retain it in accordance with this policy.

3. Information about other travellers

3.1 A lead booker may provide information about other passengers, including children. The lead booker must have authority to provide that information and must make this policy available to the other travellers. Where appropriate, the lead booker should obtain their agreement before providing medical or other sensitive information.

3.2 Bookings must be made by an adult. We process children’s information only as necessary to arrange and administer their travel, comply with legal requirements and protect their interests. We do not knowingly direct marketing to children.

4. Where information comes from

4.1 We may receive personal information directly from you or from a lead booker, parent or guardian, corporate client or employer, another travel agent, or an airline, hotel, tour operator or other travel supplier. We may also receive technical information through the website and our consented analytics tools.

4.2 If we receive information from another source, we use it only for the purposes described in this policy and as permitted by law.

5. How and why we use information

Purpose

Information typically used

Lawful basis

Enquiries, quotations and requested pre-booking work

Identity, contact, preferences and proposed itinerary

Steps requested before entering a contract; legitimate interests where appropriate

Making and administering bookings

Identity, contact, passport, booking, payment and communications

Contract; legal obligation where applicable

Supplying special assistance or dietary arrangements

Special requirements and relevant booking information

Contract or legitimate interests, plus explicit consent or another applicable Article 9 condition for special-category information

Payments, refunds, accounting and debt recovery

Payment, transaction, contact and booking records

Contract; legal obligation; legitimate interests

APIS, immigration, ATOL, IATA and regulatory compliance

Identity, passport, booking and transaction records

Legal obligation; contract where appropriate

Customer service, complaints and legal claims

Booking, communication, call recordings and relevant evidence

Contract; legal obligation; legitimate interests

Security, fraud prevention and protecting our systems

Contact, transaction, device and technical information

Legitimate interests; legal obligation where applicable

Email newsletters

Name, email address, consent and preferences

Consent

Website analytics and Meta measurement/interest targeting

Cookie, device and website-activity information

Consent for non-essential cookies; legitimate interests for related administration

5.1 Our legitimate interests include operating and improving our travel business, communicating with customers, keeping appropriate records, preventing fraud, securing systems, recovering debts and defending legal claims. We balance those interests against your rights and expectations.

5.2 We do not use personal information to make solely automated decisions that produce legal or similarly significant effects about customers.

6. Special-category information

6.1 Medical, disability, reduced-mobility and allergy information may be special-category personal information. We request only information reasonably necessary to assess suitability, arrange assistance or communicate a requirement to a supplier.

6.2 Where we rely on explicit consent, you may withdraw it at any time by contacting us. Withdrawal does not affect earlier lawful processing. If we cannot use or share information needed for a requested service, we may be unable to arrange that service. In a genuine emergency, we may use information where necessary to protect vital interests or as otherwise permitted by law.

7. Who we share information with

7.1 We share only the information reasonably necessary for the relevant purpose. Recipients may include:

·   airlines, other transport providers and global distribution/reservation systems, including Travelport/Galileo;

·   hotels, tour operators, destination-management companies and overseas ground handlers;

·   transfer, car-hire, excursion and activity providers;

·   border, immigration, customs, security, police and other public authorities where required;

·   our customer and booking-management provider, Penguin Commercial Ltd;

·   Microsoft 365 and other secure communications, hosting, storage and IT-support providers;

·   WhatsApp Business/Meta where you communicate with us through that service;

·   Barclaycard and Cardstream for payment acquiring and processing;

·   Mailchimp for consented newsletters;

·   Google Analytics and Meta advertising tools where you consent to the relevant cookies;

·   accountants, auditors, insurers, lawyers, banks and professional advisers;

·   the Civil Aviation Authority, Air Travel Trust, IATA and other regulators or protection bodies where applicable; and

·   a prospective buyer, investor or successor if our business is sold or reorganised, subject to appropriate confidentiality and data-protection measures.

7.2 Some travel suppliers act as separate controllers and use information under their own privacy notices. Other providers process information on our instructions under contractual safeguards.

8. International transfers

8.1 Travel is international by nature. To provide your arrangements, we may need to send information to airlines, accommodation providers, authorities and other suppliers in the destination or transit country, including countries outside the United Kingdom.

8.2 Where UK data-protection transfer rules apply, we use an available lawful mechanism. Depending on the recipient and circumstances, this may be UK adequacy regulations, an approved contractual safeguard such as the UK International Data Transfer Agreement or UK Addendum, or a limited legal exception, including where the transfer is necessary to perform your travel contract or take steps you request before it is made.

8.3 Some technology providers may process information internationally. We assess the relevant mechanism and contractual safeguards. You may contact us for further information about the safeguard used for a particular transfer.

9. Payments and recorded calls

9.1 Card payments and online payment links are processed through Barclaycard and Cardstream. We do not store complete payment-card numbers or card security codes. When card details are given during a telephone call, call recording is paused while the details are provided.

9.2 Most customer telephone calls are recorded. Callers are informed by a recorded announcement. We use recordings for customer service, staff training, accuracy, dispute resolution, fraud prevention and protection of our business and customers. Our lawful basis is legitimate interests. Recordings are normally retained for one year, unless a particular recording is needed longer for a complaint, investigation or legal claim.

10. WhatsApp Business

10.1 If you choose to communicate through our company WhatsApp Business account, messages may contain general booking information, itineraries, travel documents and passport details or copies. WhatsApp/Meta processes information under its own terms and privacy information.

10.2 Do not send payment-card details through WhatsApp. Where a passport copy or other sensitive document is received, we apply the retention periods below. You may ask to use email or another available communication method instead.

11. How long we retain information

Information

Normal retention period

Enquiries and quotations that do not become bookings

Two years after the last meaningful contact

Completed booking, invoice, payment and ordinary correspondence records

Six years after completion of the trip, or longer where required for an active claim or legal obligation

Passport copies and medical, dietary or accessibility details

Deleted within 90 days after return, unless required for an unresolved complaint, claim, legal duty or future booking at your explicit request

Recorded telephone calls

One year, unless required longer for a complaint, investigation or legal claim

Newsletter consent and preferences

While subscribed; a minimal suppression record may be retained after opt-out to ensure we respect it

Cookie and analytics information

For the period stated in the Cookie Policy and the applicable tool settings

11.1 Retention periods may be extended where information is required to establish, exercise or defend legal claims, respond to a regulator, meet a legal hold or investigate suspected fraud. When information is no longer required, we securely delete or anonymise it.

12. Marketing

12.1 We send Portugal Holidays newsletters through Mailchimp only to people who have actively opted in. You can withdraw consent at any time by using the unsubscribe link or contacting us. Withdrawal does not affect service messages about an existing enquiry or booking.

12.2 Our social-media advertising may target broad interests or audience characteristics selected within an advertising platform, such as people interested in Portugal or Portuguese- or Brazilian-related communities in the UK. We do not currently upload Latitude 40 customer email lists to Meta for advertising audiences.

13. Cookies, analytics and embedded content

13.1 Our website uses essential cookies needed for security and core operation. With your consent, it also uses Google Analytics and Meta/Facebook Pixel to understand website use, measure advertising and improve our services. Non-essential analytics or advertising technologies must not be activated before consent.

13.2 The website may include Google Maps and may include embedded media in future. These providers can receive technical information when content loads. Where their technologies are non-essential or store/access information on your device, they should remain blocked until you consent.

13.3 Our separate Cookie Policy identifies the cookies and similar technologies in use, their providers, purposes and durations, and explains how to change or withdraw consent. Withdrawing consent does not affect processing that took place before withdrawal.

14. Information security

14.1 We use proportionate organisational and technical measures to protect information against unauthorised access, alteration, disclosure, loss or destruction. These include access controls, secure service providers, staff procedures and payment processes designed not to retain complete card data. Electronic records may be held in our CRM, Microsoft 365, company systems and secured local office computers.

14.2 No system is completely secure. If a personal-data breach occurs, we assess it, take appropriate action and notify the Information Commissioner’s Office and affected individuals where the law requires.

15. Your data-protection rights

15.1 Depending on the circumstances and lawful basis, you may have the right to:

·   ask for access to your personal information and a copy of it;

·   ask us to correct inaccurate or incomplete information;

·   ask us to erase information in certain circumstances;

·   ask us to restrict processing in certain circumstances;

·   receive information you provided in a portable format where the right applies;

·   object to processing based on legitimate interests;

·   object to direct marketing at any time; and

·   withdraw consent at any time where processing is based on consent.

15.2 These rights are not absolute. For example, we may need to retain information to meet a legal obligation or defend a legal claim. We may request information reasonably necessary to confirm your identity. There is normally no charge, and we normally respond within one month, subject to permitted extensions for complex or numerous requests.

15.3 To exercise a right, email info@portugalholidays.co.uk.

16. Complaints

16.1 Please contact us first if you have a concern so that we can try to resolve it. You also have the right to complain to the Information Commissioner’s Office: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; telephone 0303 123 1113; website www.ico.org.uk. You do not have to contact us before approaching the ICO.

17. External websites and supplier notices

17.1 Our website and booking communications may link to external websites. Their operators are responsible for their own privacy practices. Airlines, hotels, tour operators, payment providers, WhatsApp/Meta, Mailchimp and other separate controllers may provide their own privacy notices, which you should read where relevant.

18. Changes to this policy

18.1 We may update this policy to reflect changes in our services, systems or legal obligations. The current version will be published on our website with its effective date. If a change materially affects how we use information already collected, we will provide an appropriate additional notice where required.

Get in touch

Please fill out our enquiry form if you have any questions relating to our Privacy Policy.

By clicking send you agree to us using the information provided to manage your enquiry. If enquiring on behalf of someone else, you must obtain their consent to provide us with their information.