GDPR Compliance and Data Protection
This page explains what personal data may be processed through Voyasee, why it may be used, which legal bases may apply, how cookies and external services fit into the website, and how individuals can exercise privacy rights.
This page works alongside the Privacy Policy, Affiliate Disclosure, and Terms and Conditions.
1. Who Is Responsible for the Data?
For personal data processed directly through Voyasee.com, Voyasee generally acts as the data controller because it determines the purposes and means of that processing.
Third-party providers—such as analytics companies, advertising networks, affiliate partners, booking platforms, embedded-content providers, email services, hosting providers, or security services—may act as processors for Voyasee, independent controllers, or both, depending on the service and data involved.
Privacy questions and requests can be sent to:
Email: [email protected]
Contact page: Voyasee Contact Page
2. Data Protection Principles
Where GDPR applies, personal data should be handled according to principles such as lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability.
Only information reasonably connected to a defined website, communication, security, consent, or service purpose should be collected.
Readers should receive understandable information about why data is used and who may receive it.
Retention should match the reason for collection, legal obligations, security needs, and provider settings.
Technical and organizational safeguards should reflect the type of site, data, risk, and available security controls.
3. Personal Data Voyasee May Collect
The exact data depends on how the website is used and which features are enabled. Categories may include:
- Contact data: name, email address, and information included in a message, support request, comment, or subscription form.
- Technical data: IP address, browser, device, operating system, referring page, timestamps, language, approximate location, and security logs.
- Usage data: pages viewed, clicks, session information, tool usage, navigation paths, and broad interaction patterns.
- Consent and cookie data: consent choices, cookie identifiers, advertising preferences, and records needed to remember those choices.
- Newsletter data: email address, subscription status, delivery information, and engagement data where an email service is used.
- Tool inputs: information voluntarily entered into calculators, quizzes, checkers, planners, or forms. Some tools may process data only in the browser; others may send limited information to a website service or external provider.
- Referral data: affiliate link identifiers, campaign parameters, and aggregated conversion or commission information supplied by a partner network.
- Security and anti-spam data: information used to detect abuse, malicious traffic, automated submissions, fraud, or technical attacks.
Avoid sending passport numbers, payment-card details, health records, government identifiers, passwords, or other sensitive data through a general contact form or email unless a secure and necessary process has been clearly provided.
4. Sources of Personal Data
Personal data may come directly from you, automatically from your device or browser, from cookies or similar technologies, or from service providers that support website operation, analytics, security, email, advertising, and affiliate tracking.
When you follow an external link, book with a partner, watch embedded media, use a third-party map, or interact with an external widget, that provider may collect data directly from you under its own privacy notice.
5. Purposes and Possible Legal Bases
| Purpose | Examples | Possible GDPR basis |
|---|---|---|
| Operate and secure the site | Hosting, logs, security, spam prevention, troubleshooting, consent storage | Legitimate interests, legal obligation, or contractual necessity depending on the situation |
| Respond to requests | Contact forms, support questions, correction reports, privacy requests | Legitimate interests, steps requested before a service, legal obligation, or consent |
| Provide requested communications | Newsletter or email updates | Consent, and in limited cases another lawful basis where permitted |
| Measure and improve performance | Analytics, page performance, tool usage, error detection | Consent where required; otherwise legitimate interests where legally permitted |
| Advertising and affiliate measurement | Ad delivery, frequency limits, referral tracking, campaign reporting | Consent where required; legitimate interests only where lawful and appropriately balanced |
| Meet legal requirements | Compliance, fraud prevention, accounting, responding to lawful requests | Legal obligation or legitimate interests |
The correct legal basis depends on the feature, country, provider, and actual processing. Consent, where used, should be freely given, specific, informed, and unambiguous.
6. Cookies and Similar Technologies
Voyasee may use cookies, pixels, tags, local storage, referral parameters, and similar technologies. Some are needed for core website functions; others may support analytics, advertising, affiliate attribution, embedded content, preferences, or performance measurement.
Security, forms, consent preferences, load balancing, and basic website operation.
Broad traffic, page performance, errors, and how readers use content or tools.
Ad delivery, measurement, frequency management, and personalization where enabled and permitted.
Referral identifiers used to record that a reader reached a partner through a Voyasee link.
Where consent is required, a cookie or consent tool may allow you to accept, reject, or manage non-essential categories. You can also use browser controls, although blocking technologies may affect some site functions or partner tracking.
7. Analytics, Advertising, Affiliate Partners, and Embedded Content
Voyasee may use service providers for hosting, caching, security, analytics, advertising, email delivery, affiliate tracking, forms, maps, video, images, booking links, or embedded content.
These providers may receive technical, usage, cookie, or referral information. When a provider determines its own purposes and means, it may act as an independent controller. Its privacy policy and terms will apply to its service.
Following an affiliate or booking link does not normally give Voyasee your full payment-card details, passport data, booking record, or account password. A partner may provide Voyasee with aggregated reporting, referral status, transaction value, or commission information.
8. Voyasee Tools and Browser Storage
Some Voyasee tools may store preferences, progress, recent selections, or temporary results in the browser. Other tools may transmit limited input to a website endpoint or an external data provider to return a result.
Do not enter confidential, identifying, or sensitive information unless the tool clearly asks for it and explains why it is needed. Tool outputs are intended for travel planning and are not a substitute for official or professional decisions.
9. Data Sharing and Recipients
Personal data may be shared with service providers only where reasonably needed to operate, secure, measure, maintain, or support the website; comply with law; protect rights; or complete a request initiated by the user.
Possible recipient categories include hosting and infrastructure providers, security and anti-spam services, analytics providers, consent-management services, email and form services, advertising networks, affiliate networks, professional advisers, and public authorities where legally required.
Voyasee does not sell personal data to advertisers. Advertising and affiliate technologies may still involve third-party tracking or data processing as described in this page and the relevant provider notices.
10. International Data Transfers
Some providers may process data outside the European Economic Area. Where GDPR applies, transfers may rely on an adequacy decision, standard contractual clauses, another recognized safeguard, or a limited legal derogation where appropriate.
The provider's location, corporate group, infrastructure, and transfer mechanism may change. Review the provider's privacy documentation for current transfer details.
11. Data Retention
Voyasee aims to keep personal data only for as long as reasonably necessary for the purpose of collection, legal obligations, dispute handling, security, fraud prevention, or technical administration.
Kept long enough to answer, follow up, keep reasonable records, and address disputes or misuse.
Kept while the subscription remains active and as needed to record an unsubscribe or suppression request.
Kept for a limited period appropriate to detecting abuse, investigating incidents, and protecting the website.
Retained according to the relevant provider's settings, contracts, legal duties, and privacy notice.
12. Security
Voyasee aims to use reasonable technical and organizational measures appropriate to the website and data involved. Measures may include encrypted connections, controlled access, updates, backups, anti-spam protection, logging, security services, and limiting unnecessary collection.
No website, device, email system, database, or internet transmission is completely secure. Absolute security cannot be guaranteed.
13. Personal Data Breaches
A personal data breach may involve accidental or unlawful loss, destruction, alteration, unauthorized disclosure, or unauthorized access to personal data.
Where GDPR applies and a breach creates a risk to individuals, the controller may be required to notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware. A high-risk breach may also require communication to affected individuals.
14. Your Data Protection Rights
Depending on the law, legal basis, and circumstances, you may have rights to:
- receive information about processing
- access personal data held about you
- correct inaccurate or incomplete data
- request erasure where the legal conditions apply
- restrict processing in certain situations
- object to processing based on legitimate interests or direct marketing
- receive certain data in a structured, commonly used, machine-readable format
- withdraw consent at any time where consent is the legal basis
- avoid certain decisions based solely on automated processing that produce legal or similarly significant effects
- lodge a complaint with a competent supervisory authority
These rights are not absolute. Exceptions may apply where data is needed for legal obligations, legal claims, freedom of expression, security, or other lawful reasons.
15. How to Make a Privacy Request
Email [email protected] and clearly state the right or concern involved.
Explain which email, form, subscription, comment, or interaction the request relates to.
Voyasee may request reasonable information to avoid disclosing or deleting another person's data.
Where GDPR applies, Voyasee aims to respond without undue delay and generally within one month.
A request may be extended where the law permits because of complexity or volume. If a request is refused or limited, the reason and available complaint options should be explained where required.
16. Children’s Privacy
Voyasee is intended for a general travel-planning audience and is not directed to young children. Voyasee does not knowingly seek personal data from children through ordinary site use.
If you believe a child submitted personal data, contact [email protected] so the situation can be reviewed. Age thresholds and parental-consent requirements vary by country.
17. Email Communications and Direct Marketing
If you subscribe to an email update, Voyasee may use the email address to send the requested content. You can unsubscribe through a link in the message where available or contact [email protected].
Withdrawing consent does not make earlier consent-based processing unlawful. Limited records may be retained to respect an unsubscribe request or meet legal obligations.
18. Supervisory Authority and Complaints
You may complain to the data protection authority in the country where you live, work, or believe an infringement occurred.
For Croatia, the supervisory authority is the Croatian Personal Data Protection Agency (AZOP). Information about complaints is available on the AZOP complaint page.
Voyasee encourages individuals to contact [email protected] first where appropriate so the concern can be reviewed, but contacting Voyasee does not remove the right to approach a supervisory authority.
19. Official Data Protection Resources
20. Frequently Asked Questions
Who is the data controller for information submitted directly to Voyasee?
For personal data processed directly through Voyasee.com, Voyasee generally acts as the data controller because it determines why and how that information is used. External providers may act as separate controllers for data collected on their own websites.
How can I request access to or deletion of my data?
Email [email protected] with a clear description of the request. Voyasee may ask for reasonable identity verification before disclosing, changing, or deleting personal data.
How long does Voyasee have to respond to a GDPR request?
Where GDPR applies, requests should be handled without undue delay and generally within one month. The period may be extended where permitted for complex or numerous requests, with an explanation provided to the requester.
Can I reject non-essential cookies?
Where a consent tool is available and consent is legally required, you can accept, reject, or manage non-essential categories. Essential cookies may still operate because they support security, consent choices, forms, or core website functions.
Does Voyasee receive my payment or passport data from affiliate partners?
Voyasee normally does not receive full payment-card details, passport information, or booking records merely because you click an affiliate link. The external provider processes information under its own privacy notice. Voyasee may receive aggregated referral or commission information.
Can I complain to a data protection authority?
Yes. Where GDPR applies, you may lodge a complaint with the supervisory authority in your country. In Croatia, the supervisory authority is the Croatian Personal Data Protection Agency (AZOP).
21. Changes and Contact
Voyasee may update this page when website features, providers, data practices, legal requirements, or privacy controls change. Material changes may be highlighted where appropriate.
Email: [email protected]
Contact page: Voyasee Contact Page
Important: This page is provided for transparency and general information. It is not legal advice.
Last updated: