Data Protection, GDPR and Information Retention Policy
Last updated: 27th August 2026
This internal policy explains how Cotswolds Expeditions Ltd ("we", "our", "us") manages personal information and sets out its approach to UK data protection law, information security, individual rights, data breaches and record retention.
It should be read alongside the customer-facing Privacy Policy and Cookie Policy.
1. Scope
This policy applies to personal information handled by Cotswolds Expeditions Ltd in connection with customers, prospective customers, corporate contacts, partners, employees, contractors, suppliers and other individuals whose personal information is processed by the business.
2. Responsibility
All employees and contractors who have access to personal information are responsible for handling it in accordance with this policy and for reporting suspected data-security incidents promptly.
A company Director of Cotswolds Expeditions Ltd is responsible for data protection compliance.
3. Data Protection Principles
Cotswolds Expeditions Ltd will process personal information in accordance with the applicable UK data-protection principles. Personal information must be:
Processed lawfully, fairly and transparently
Collected for specified and legitimate purposes and not reused incompatibly
Adequate, relevant and limited to what is necessary
Accurate and kept up to date where necessary
Kept in identifiable form for no longer than necessary
Protected by appropriate technical and organisational measures
Handled in a way that allows the company to demonstrate accountability
4. Lawful Bases and Special Category Data
Before personal information is processed, Cotswolds Expeditions Ltd must identify an appropriate lawful basis under UK data-protection law.
Where special category information is processed, including health information voluntarily supplied in connection with accessibility, allergies or safe participation, the company must also identify a separate valid condition for processing special category data.
Where explicit consent is relied upon for special category information, it must be specific, informed, affirmative and recorded. Customers should not be asked to provide more medical information than is necessary for the relevant purpose.
5. Systems and Data Locations
Personal information is handled through the systems actually used by Cotswolds Expeditions Ltd. The current confirmed systems are:
Bókun
Booking and customer-management data required to administer bookings and customer records.
Stripe
Payment processing and transaction/refund information. Cotswolds Expeditions Ltd does not store full card details itself.
Microsoft
Business email and communications containing enquiries, booking correspondence and other customer communications.
Squarespace
Website platform and website-form functionality. Personal information collected through the website is handled in accordance with the live Squarespace configuration and the company Privacy Policy.
Squarespace Analytics
Website analytics information.
Google Analytics
Website analytics information, subject to cookie-consent requirements.
STQRY
Digital/audio-tour delivery. Cotswolds Expeditions Ltd does not store customer personal data in STQRY.
If Cotswolds Expeditions Ltd chooses to run paid advertising, marketing technologies may be used through Meta and Google in accordance with the Cookie Policy and applicable consent requirements.
6. Access Controls and Security
Access to personal information must be limited to people who need it for their role. Accounts should use individual credentials where available and must be protected by appropriate passwords and other security controls made available by the relevant service.
Personal information must not be copied into unnecessary systems, shared through inappropriate channels or retained in personal accounts or devices without an authorised business reason and suitable safeguards.
Where multi-factor authentication is available for administrator accounts, it should be enabled wherever reasonably practicable.
7. Data Sharing and Processors
Personal information may only be shared where there is a valid business and legal reason to do so and only to the extent necessary for that purpose.
Relevant recipients may include authorised booking platforms, drivers or contractors involved in delivering the service, partner venues where information is needed for a booking, accountants, insurers, professional advisers, regulators and law-enforcement bodies where required.
Before introducing a new supplier that will process personal information on the company's behalf, Cotswolds Expeditions Ltd should consider the supplier's role, data-protection terms, security arrangements and any international transfers involved.
8. International Transfers
Where a service provider processes personal information outside the United Kingdom and the transfer is restricted under UK data-protection law, Cotswolds Expeditions Ltd will ensure that an appropriate transfer mechanism or safeguard applies.
9. Data Minimisation and Accuracy
Only information that is adequate, relevant and necessary for a defined purpose should be collected. Information should not be collected merely because it might be useful later.
Reasonable steps should be taken to keep personal information accurate. Material inaccuracies should be corrected when identified.
10. Information Retention
Personal information must not be kept indefinitely. The ICO requires organisations to be able to justify their retention periods and recommends documenting standard periods wherever possible.
Cotswolds Expeditions Ltd will apply the following retention rules to the extent they are relevant to the records held:
Accounting, tax and supporting financial records
6 years from the end of the last company financial year they relate to, or longer where HMRC rules require it. Statutory/tax requirement
Booking records forming part of accounting/tax evidence
Retained with the relevant accounting/tax records where needed to evidence the transaction. Linked to statutory/tax retention
General enquiries that do not become bookings
3 months from the last substantive contact. Business retention decision
Marketing subscriber/contact records
Until consent is withdrawn or the individual unsubscribes/objects, with a minimal suppression record retained where necessary to honour the opt-out. Purpose-based
RIDDOR-reportable accident/incident records
At least 3 years in accordance with HSE record-keeping requirements. Health & safety requirement
Other accident, incident and insurance-claim records
Retained for the period required by the company insurer, claims process or applicable legal limitation period. Insurer / legal-risk requirement
Complaints and dispute records
3 years after closure, unless a longer period is required because of an active or reasonably anticipated legal claim. Business / legal-risk decision
Accessibility/health information for an individual booking
Delete or anonymise when it is no longer required for the booking, incident, complaint or other lawful purpose. Data minimisation / storage limitation
Cookie consent records
Retained for the period configured or required by the Squarespace consent system and applicable compliance needs. System/compliance based
At the end of a retention period, records should be securely deleted or anonymised unless there is a documented reason to keep them longer, for example an active complaint, claim, investigation or legal requirement.
11. Individual Rights
Cotswolds Expeditions Ltd will maintain a process for dealing with applicable data-protection rights, including access, rectification, erasure, restriction, objection, portability and withdrawal of consent where relevant.
Requests must be handled within the legal timescales that apply to the particular right. Identity should only be verified to the extent reasonably necessary.
Data-subject requests should be sent to privacy@cotswoldsexpeditions.co.uk.
12. Data Breaches and Security Incidents
Any suspected loss, unauthorised disclosure, hacking, misdirected email, inappropriate access or other incident involving personal information must be reported internally without unnecessary delay.
The responsible person must assess what happened, what information and individuals are affected, the likely risk, containment steps, whether affected individuals need to be informed and whether notification to the Information Commissioner's Office is legally required.
Any suspected data breach must be reported immediately to Cotswolds Expeditions Ltd. They are responsible for assessing the breach and the risks posed, deciding what containment or remedial action is required, and determining whether notification to the Information Commissioner’s Office or affected individuals is necessary.
13. Marketing and Cookies
Marketing communications and website tracking must be handled in accordance with the Privacy Policy, Cookie Policy and applicable electronic-communications requirements.
Squarespace Analytics and Google Analytics are used for website analytics. Cookie choices are managed through the Squarespace cookie banner. If paid advertising is run through Meta or Google, any associated non-essential marketing technologies must follow the consent choices applicable to the visitor.
14. Photography and Reviews
Identifiable guest photographs used for marketing must only be used where the company has an appropriate lawful basis and the permission described in the Privacy Policy has been obtained.
Customers may be contacted after an experience to request feedback or invite a review in accordance with the Privacy Policy and applicable marketing/communications rules.
15. Children's Information
Cotswolds Expeditions Ltd does not knowingly collect personal information directly from children. Information relating to a child participating in a booking is supplied by the parent, guardian or person making the booking and should be limited to what is needed for the booking and safe participation.
16. Disposal and Deletion
Electronic records that have reached the end of their retention period should be securely deleted from the systems under the company's control, subject to the functionality and backup arrangements of the relevant provider. Paper records containing personal information, if any, should be destroyed securely.
17. Training and Review
People with access to personal information should receive guidance appropriate to the information and systems they use. This policy should be reviewed when systems or processing activities materially change, following a significant data incident, or when relevant legal requirements change.
This policy will be reviewed at least every 12 months, and sooner where systems, processing activities, legal requirements or material risks change.