1. First things first, who are we?
1.1. Introduction
Hello! We are Vacaciones eDreams S.L.U., known by you as the branding name you see in this Platform. Vacaciones eDreams, SL is a company belonging to the eDreams ODIGEO Group (“eDO Group”).
When this Privacy Notice mentions “we”, “us”, or “our”, it refers to Vacaciones eDreams S.L.U. acting as Data Controller regarding our Platforms or the Data Controller of the service provided in accordance with our General terms and conditions and our Prime terms and conditions
.
Thank you for using our Platform. Your trust is the most important value to us, that is why in this Privacy Notice we are going to show you our responsibilities regarding the privacy and security of your data. The only thing you have to do is read it, and if you have any questions related to it, you can tell us about it in our Privacy form . Remember that for non-data protection related questions, you can check our Help Center and contact our customer service team, where needed. After that, you are all set to book your next adventure through us.
Vacaciones eDreams S.L. is a Spanish-based company, with tax ID number ESPB61965778.
As mentioned above, while Vacaciones eDreams S.L.U. is the primary Data Controller for most of our services in all our Platforms, the specific Data Controller may vary depending on the service and domain you are using. For example, unless otherwise stated in our General terms and conditions and our Prime terms and conditions .
- Vacaciones eDreams S.L.U. is the Data Controller for accounts management, general flights, dynamic packages, car rentals, insurance, and Prime subscriptions.
- Engrande S.L., with tax ID number B62064845, is the Data Controller for standalone hotel bookings.
- eDreams LLC, with tax ID number EIN270833859, is the Data Controller for transactions on the “.net”; domain with US credit card payments.
- eDreams Gibraltar Limited, with tax ID number 707979, is the Data Controller for transactions on the “.co.uk” domain with UK credit card payments.
- Geo Travel Pacific Pty Ltd, with tax ID number 33167794756, is the Data Controller for transactions on the “.com.au” domain.
Regardless of which entity acts as the Data Controller, we adhere to the principles and practices outlined in this Privacy Notice.
Our privacy commitments are the following:
- We value your privacy and data security.
- We use data for your best travel experience with us.
- You control your data.
- Several Platforms, one Privacy Notice.
We commit to processing your data in accordance with the applicable data protection laws, including the observation of the data processing principles (such as lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability), and to only processing your data for the purposes explained to you in this Privacy Notice or as informed in the corresponding data collection process, in line with the lawful bases as explained below (in Section 2.10: Lawful basis we rely on).
1.2. Data Protection Officer
We have a Data Protection Officer who monitors and advises the group of companies regarding the data processing carried out with respect for your privacy in accordance with the applicable privacy regulations.
When you exercise your privacy rights through our Privacy form a dedicated team of privacy rights experts will take care of your request. If you want to raise any privacy topic but not exercise any of your Privacy Rights, you can do so in the same form by selecting “Other Data Protection comments or suggestions”. We will verify your request and/or identity before taking further action on your request for security purposes.
1.3. Definitions
For a better understanding of this Privacy Notice we have prepared a definitions section that includes the following concepts based on the General Data Protection Regulation (“GDPR”): Automated Decisions, Data Controller, Data Processor, Privacy Rights, Lawful Bases, Personal Data, Platforms, Sensitive Personal Data and Third Countries.
- Automated Decisions: decision-based solely on automated processing, including profiling, which produces legal effects concerning the individual or similarly significantly affects them (Article 22.1 of the GDPR).
- Data Controller: anyone responsible for determining the purposes and means of processing your data.
Note: We are the Data Controllers of your data in the terms described in this Privacy Notice when contracting our services in accordance with our General terms and conditions and our Prime terms and conditions or any other of our terms and conditions you accepted through the contracting process. If you choose to book a trip through our Platforms, we will be sending your data to other Data Controllers – the carrier or the provider of other services (e.g. booking partners or the global distribution systems), who will again use your data for their own purposes and based on their own means, as described in their own Privacy Notices (which is published on their websites). You can see below the overview of Data Controllers categories with whom we might share the data. In any case, the disclosure of your data to any service provider will be done in accordance with the applicable laws. Each Data Controller is responsible for your data and shall process it in accordance with the applicable laws. - Data Processor: a third party that only helps to achieve the purposes determined by the Data Controller.
Note: We as a Data Controller use many third-party services to which we outsource some parts of our activities that we do not do ourselves for various reasons such as cost-efficiency. A Data Processor is only allowed to process your data according to our documented instructions, and in compliance with the applicable law. This means that we are still in charge of your data, and they will not be able to process your data for any incompatible purpose. - Privacy Rights: rights over one's data. When we use the term “Privacy Rights”, we refer in short to the applicable data protection or privacy rights. Data protection regulations allow you to exercise your rights to be informed, access, rectification, erasure, restrict processing, object, to withdraw your consent, and data portability, when applicable. You can find more information regarding your Privacy Rights in Section 6: How can you control your data and exercise your Privacy Rights?
- Lawful Bases: processing of your data shall be lawful only if at least one of these bases applies (Article 6 of the GDPR). For the six lawful bases covered in the law, we will essentially rely on Consent, Contract, Legal Obligation or Legitimate Interest. However, exceptionally, we might rely on Vital Interests or Public Tasks. You can find more information below (in Section 2: Why do we process your data?).
- Personal Data (in this Privacy Notice also referred to essentially as “your data”): any information relating to a directly or indirectly identified or identifiable to you, as a natural person.
- Platforms: all the websites, apps, call centres, etc., that facilitate interactions between you and us.
- Sensitive Personal Data: data related to racial origin, ethnic group, religion, health, sexual orientation and biometric data constitute special categories of data (Article 9 of the GDPR).
Note: As you will find explained below (in Section 3.7: Why do not we normally process Sensitive Personal Data?), we will normally not need to process Sensitive Personal Data. - Third Countries: countries in which the GDPR regime is not applicable. This means, countries outside the European Economic Area (i.e. outside the European Union, Iceland, Liechtenstein and Norway).
2. Why do we process your data?
The main purpose is to offer you travel-related mediation services in accordance with our General terms and conditions . This includes the specific purposes covered here.
We rely on different legal basis for such processing purposes. Depending on the legal basis for our processing of your data, you may have a particular Privacy Right alongside the rest of the Privacy Rights. For example, in individual cases, you have the right to object to the processing of your data (you can find further information under Section 6: How can you control your data and exercise your Privacy Rights?).
2.1. Booking
Lawful bases: #Contract #Legitimate Interest#Your Consent
During the purchase process, we ask you for the data that we need to provide you with our mediation services to contract travel products. Please, bear in mind that the identification data we use internally is the email that you introduce in your booking or account.
This includes completing and managing your booking, advising you on ancillary products or other related products for your trip, sending you contractual-based communications by email, call, or SMS in relation to your booking (e.g. confirmations, modifications, and reminders), and responding to your queries. Such communications could be managed by us or by our travel partners. In this sense, we endeavour to show to you the most relevant travel data and help you in a customised manner with your booking and post-booking. When you book a service through us (such as a flight or hotel) and accept the service provider's terms and conditions, you agree that we need to process and share certain information with them so they can fulfil their services. This sharing is essential for them to provide the service you have requested. For example, airlines are legally required to process specific passenger data (for instance, by the EU Directive 2016/681, concerning Passenger Name Records or PNR). As a result, we are also required to initially process and share this information with them. These processing activities described are necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract.
We might save your data for future bookings to make it easier for you to finish a booking with us. This processing is necessary for legitimate interest purposes, namely, we have a commercial interest to facilitate further booking reservations. However, we only store your payment details for future bookings if you have a Prime subscription as it is necessary to fulfil our contract with you. Otherwise, we will ask for your consent to store your payment details for future use. Remember that a Prime subscription requires having at least one valid credit card assigned to it in order to manage the recurrent payment. In case you want to stop paying for it, you will have to cancel your Prime subscription in your account or through our Customer Service, in accordance with the Prime terms and conditions .
We may as well ask you when needed for your consent in order to retrieve the booking information that you have already provided, so you do not have to enter your data again in the same booking process.
To maintain a consistent record of your input during multi-stage interactions with us through our Platforms, such as filling out online forms across multiple pages or tracking items added to your shopping cart, we need to process browsing and device data that link your actions throughout your session. The processing is limited to the duration of your active session on the Platform and is necessary for the performance of a contract to which you are a party.
We also may use your geolocation to provide a better search experience for you, in order to pre-populate the “origin” field of the search form. This processing of personal data is only possible if you consent to it.
2.2. Booking
Lawful bases: #Contract #Your Consent #Legitimate Interest
You can create a user account on our Platforms, enabling us to use your data to manage your account. You can also subscribe to our programs for our customers (e.g. Prime account). We will process your data with the objective to show you the most relevant travel booking and post-booking experience, allowing you to receive the services and features covered in the General terms and conditions and the Prime terms and conditions .
Processing activities related to your subscription (such as your Prime account) are necessary for the performance of our contract with you. This includes storing your payment details within your Prime account. We store the payment information you provide when you initially subscribe and create your Prime account, as well as any payment details provided for subsequent bookings. You can update your payment details in your Prime account at any time.
To authenticate your identity when you log in to the Platform, we use browsing and device data (such as session IDs). This allows you to access authorised content, including viewing your account balance and transaction history, and ensures seamless navigation during your session. This processing is limited to the duration of your active session on the Platform and is necessary for the performance of a contract to which you are a party.
To enhance the support and customer service we provide, we may consider your previous interactions with us to ensure a more efficient and tailored service experience. This processing is necessary for our legitimate interest in improving the efficiency and effectiveness of our customer service. We believe this processing is also in your interest as it benefits you by enabling us to provide more tailored and relevant assistance, ultimately leading to a smoother and more satisfying experience.
2.3. Travel-related services
Lawful bases: #Contract #Your Consent #Legitimate Interest
We may offer you other travel-related services based on our role as a travel agent as described in our General terms and conditions .
We may occasionally inform you about services that can assist you in the event of travel incidents or disruptions, such as flight cancellations or significant delays. This includes information about potential compensation or rebooking options. This processing is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract.
We may request your authorisation to process your personal data for certain purposes related to our travel-related services, such as contacting you through specific instant messaging platforms different from those stated in the “Booking” subsection (e.g. WhatsApp, Telegram, etc.), or to send information previously requested by travel services providers. For those cases, we will process your personal data once you provide us with your consent.
When performing a search in our Platform, we may use recent historical data of past bookings in the last one to twelve months (including the same information that the one filled in each search with us) when you have an existing account to customise the search. If no account is detected, this customisation of the search is only made with aggregated data to recommend the most relevant data for your search. This customisation aims to apply a similar search criteria to the one already provided when contracting past bookings. This processing is necessary for legitimate interest purposes, since we have a commercial interest in facilitating further booking reservations, and also you may have an interest in our services as travel agents to customise your search.
2.4. Communications
Lawful bases: #Contract #Your Consent #Legitimate Interest
In line with the communications already mentioned above (in Section 2.1: Booking), we can get in touch with you by the different means provided by you, and for contract-related purposes (such as emergencies, queries, reminders, alerts, or quality communications).
- To contact you whenever a travel service provider is not going to be able to provide you with the service or it might affect your booking (e.g. due to insolvency or similar). This processing is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract.
- To respond to any query or request from you or any travel service provider and to handle it by any of our contact channels (e.g. email, phone, social media, chatbot, etc.). We endeavour to maintain our best levels of customer service and we are attentive to the personal situation of each of our various customers in order to customise our services. If the processing is related to the services provided, the processing is necessary for the performance of a contract to which you are a party.
- To try to remember your search and contact you immediately after, in case you have not finalised a booking online, as we believe that this additional service benefits you, by allowing you to carry on with a booking without having to fill in your reservation details again. This processing is necessary for legitimate interest purposes, since this purpose could lead to close contractual relations that otherwise would not take place due to the fact of the amount of options available in our Platforms, and to avoid you having to invest time again to search for the trip that you already searched for and started the contracting process by entering your personal data.
- To inform you how to contact us if you need assistance while you are away or other data that we feel might be useful to you in your planning or getting the best of your trip, or data of upcoming trips or a summary of previous bookings you made with us. This processing is necessary for legitimate interest purposes, since we have a commercial interest to facilitate further booking reservations.
- We may need to send you other administrative messages, which may include security alerts. This processing is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract.
- We may process your personal data for understanding customer experiences and conducting market research:
- Collecting customer experience reviews: We have a legitimate interest in understanding how satisfied you are with our services and those of our travel partners. To do this, we may conduct brief customer satisfaction surveys (oral or written), and monitor and analyse your reviews. This processing is based on our legitimate interest, since we have an interest in knowing your satisfaction degree and quality perception regarding the services that you have received to consider those to improve our services.
- Market research to develop new products and services: With your consent, we may use your data for market research, such as conducting surveys and interviews.
Those feedbacks may be available to other customers to help them make decisions about a product or a service, and also can be used internally for administrative and reporting purposes.
2.5. Marketing activities
Lawful bases: #Legitimate Interest #Your Consent
Under certain circumstances described below, we may use your personal data for marketing purposes.
To send you discount codes, deal alerts, specific price alerts, and a birthday surprise with eDreams newsletter. For this purpose, we will process your personal data once you provide us with your consent.
When you book with us, you are subscribed to our marketing list, hence making you eligible to receive commercial offers and communications (through email, web, including through social media, telephone, including calls, SMS, and push-up notifications and postal mailing), unless you state otherwise, before confirming your booking or in any moment after that. Our marketing list allows us to send you regular news and offers on travel, transportation and accommodation-related products and services within our intermediation services that we provide you as your travel agent, and that we think you might find interesting, and to administer any promotional activity where you participate. You can easily unsubscribe from our marketing list at any time by: clicking on the unsubscribe link included in each newsletter, by objecting to the processing of your data through our Privacy form , or if we are calling you for any commercial purpose, by objecting to the processing of your data for this purpose at any moment during the call. This processing is necessary for legitimate interest purposes as long as you are our customer, since we have a commercial interest to show you travel products and services related to those you have already purchased.
We may show you customised offers in the content displayed to you on our Platforms when you access them, or in third-party platforms (including social media sites). Such offers can be booked on our site and can consist of other third-party offers or products we think you might find interesting, always related to the services we are providing you with. When using cookies for this purpose, we will rely on your consent (for more information, check out our ).
Otherwise, we will use your identification and contact data pseudonymised (e.g. hashing your data) for this purpose, and we will rely on our legitimate interests as long as you are our customer to show you our travel-related products and services to those you have already contracted. This will only be done if you have an account with the corresponding digital company that provides online advertising services, and they have the possibility to match your details securely based on their terms and conditions and your preferences in your account with them.
With regard to processing activities aimed at customising offers using your identification and contact data as the ones described above, we have a legitimate interest in avoiding sending promotional content that is irrelevant or of no interest to you. For example, we might exclude in our Prime marketing campaigns for new subscriptions those users who are already Prime subscribers.
2.6. Call and chat recordings
Lawful bases: #Legitimate Interest #Your Consent #Contract
We may process and record your calls and online communications for quality, contractual and legal purposes when you contact our Customer Service.
Not all calls or chats are recorded. However, when you contact Customer Service or when our Customer Service team contacts you due to contractual and legal purposes, we must record them, albeit they are kept for a limited amount of time and automatically deleted thereafter (unless we have a legitimate interest to keep such recordings for a longer period, including fraud investigation and legal purposes). This processing covers the calls performed between us and the agents of travel providers (such as airlines and hotels agents). These processing activities are necessary for the performance of a contract to which you are a party.
With regard to those calls and online communications recorded for quality purposes such as service and practices improvement, and agents training, those processing activities are necessary for preserving our legitimate interest in improving the quality of our services.
Where legally required,we will rely on your consent to record the call.
2.7. Legal and compliance purposes
Lawful basis: #Legitimate Interest
We use browsing and device data for functional and analytical purposes. The main goal here is to optimise our online Platforms to our customers’ needs, making our site easier and more enjoyable to use. We strive to use pseudonymised or anonymised data for these purposes.
Our teams work to enhance the user experience. For this purpose, we need to be able to use the data:
- for testing and troubleshooting to avoid or fix any technical glitches,
- for audience measuring,
- for keeping user preferences and settings across our Platforms, and
- for improving the functionality and quality of our online travel services.
The processing of your personal data will be necessary for legitimate interest purposes, since we have an interest in improving the network and information security, and since we have an interest in improving the quality of our services, respectively. For this, we need to understand how our customers interact with our Platform (including if our customers come once, twice or more times to make a booking, which is the overall conversion rates, etc.).
Finally, we will also elaborate anonymised statistics regarding the overall conversion rate of our Platforms. This processing is necessary for legitimate interests purposes, since we have a commercial interest to assess the percentage of users that have become customers.
2.8. Promotion of a safe and trustworthy service
Lawful bases: #Legal Obligation#Legitimate Interest#Contract
We may use data for the detection and prevention of fraud and other illegal or unwanted activities, as well as for security purposes (e.g. authentication of users and bookings). Our objective here is to create and maintain a trustworthy environment for all (for you, your fellow travellers, other customers, our service providers and our travel providers, etc.). For such purposes, we may have to stop or put on hold certain bookings. We also process data to ensure its accuracy and prevent mismatches, which helps us maintain the integrity of our systems and provide you with the best possible service. The processing of your data will be necessary for legitimate interest purposes, since we have an interest in ensuring network and information security.
As some of these security measures we have implemented for these purposes are compulsory by law and international standards, the corresponding data processing is also necessary for compliance with a legal obligation to which we are subject. In other cases, we have deployed security measures that require the processing of personal data for legitimate interest purposes, since we have an interest in preventing fraud, as fraud has a negative financial impact in companies, and avoiding it or reducing it as much as possible reduces costs which can benefit in better offers to our genuine customers.
To enhance the security of the services you have requested we process browsing and device data. This includes detecting repeated failed login attempts, performing software updates necessary for security purposes, identifying potential breaches of our terms of service, and implementing other security measures to protect our login systems from abuse. This processing helps maintain or restore the security of our information society services and terminal equipment, prevent fraud, and detect technical faults. The processing is limited to the duration necessary for these security purposes and is necessary for the performance of a contract to which you are a party.
We process technical load balancing and multimedia data (e.g., image quality, buffering) to ensure proper network communication for transmitting data, including routing information, ensuring data packets are reassembled in the proper order, optimising website performance to ensure an efficient service delivery, and detecting transmission errors. This processing is necessary for our legitimate interests in maintaining connectivity and communication over electronic networks.
Whenever we contact you, or you contact us through any channel, our staff is instructed to perform authentication questions, ensuring that your reservation details are kept confidential. To streamline your experience and expedite service, we use an automated system to identify your phone number and link it to your existing reservations when you call our customer service team. If you contact us through email, we also identify your email address and link it to your existing reservations. This reduces the need to manually confirm your booking details, saving you time. However, our customer service representatives may still request additional verification to ensure the security of your reservation information. These processing activities are necessary for the performance of a contract to which you are a party.
With regard to the security measures implemented, note that your data may be processed in different ways, such as:
- Through our five-attempt password policy (if you incorrectly enter your password more than five times, we will block your account, requiring you to change your password).
- Through our preventive stolen-credential control on the internet (if we might have any hint that your credentials could have been compromised, we may also block your account and ask you to reactivate it with a new password).
With these examples, among other actions, we protect your data and reduce fraud risk.
2.9. Legal and compliance purposes
Lawful bases: #Legal Obligation #Legitimate Interest
In certain cases, we may need to use your data to handle and resolve legal disputes, for regulatory investigations and compliance, to enforce our General terms and conditions or to comply with lawful requests from law enforcement. This processing is necessary for complying with a legal obligation which we are subject to, and also it is necessary for legitimate interest purposes, since we have an interest in defending our rights and interests.
When you exercise your Privacy Rights or contact us through our Privacy form , we will process the data you submit to respond to your request, comply with data protection regulations, and document the procedure for any potential claims or legal proceedings. This processing is necessary for compliance with our legal obligations.
When you provide consent or enter into a contractual agreement with us, we need to collect and retain necessary information, including browsing and device data and statements, to demonstrate that data processing is conducted in accordance with applicable regulatory provisions. This ensures we can provide evidence of our lawful processing activities. This processing is necessary for compliance with our legal obligations.
2.10. Lawful basis we rely on
The main Lawful Bases commonly used are #Your Consent #Contract #Legal Obligation #Legitimate Interest
- Contract: you have a contract or pre-contract with us. As an example, when booking an airline or hotel with us, or when accepting our General terms and conditions or any other of our terms (e.g. Prime terms and conditions ), we need relevant data to process your reservation or handle your account respectively.
- Legal Obligation: we have a legal obligation. Normally, accounting and tax regulations require the storage of necessary data for compliance purposes.
- Legitimate Interest: it is in our legitimate interest, and it is judged not to affect your rights and freedoms significantly.
- Your Consent: we rely on your consent for processing your personal data when there is no other lawful Basis, in accordance with the law. We will provide you with transparent information regarding the use of your data for the specific purpose
- Vital Interest: you or a third party have a vital interest. We will not normally process data based on this legal basis, but if we do, we will let you know.
- Public Task: we have a public task to perform. We will not normally process data based on this legal basis, but if we do, we will let you know.
2.11. Automated Decisions that could produce legal effects or similarly significantly affect you
We do not make any decisions based solely on automated processing, beyond the legitimate interest of fraud prevention and the customisation of your user experience, marketing and advertising, which will not produce legal effects or similarly significantly affect you.
We may use automated processes to analyse your account activity and other information related to your interactions with our Platforms, such as your booking history and payment patterns, to identify potential risks, such as fraudulent activity or violations of our Terms and Conditions. These automated processes may also be used to assess the risk associated with certain reservations or user behaviour. However, any decisions that could have an impact on you, such as account suspension or restrictions on services, will always be reviewed and made by a human. Automated decisions are used to assist our team in making informed decisions, not to make decisions autonomously. Bear in mind that account monitoring and risk assessment are necessary for the performance of our contract with you, and to protect our legitimate interests in maintaining a secure and safe platform for all users.
You can always contact us through our Privacy form to request us a review of any decision that you believe impacts you.
In case we shall make any Automated Decision that could produce legal effects or similarly significantly affect you, we will apply all appropriate measures and inform you.
3. What types of data do we process?
We offer you a wide range of services, which you can also use in a wide range of ways. Depending on whether you contact us online, by phone or otherwise and on which services you use, various data from different sources may come into play. Much of the data we process is provided by you when you use our services or contact us, for example when you register and provide your name or email address or address (Data you give to us). We also receive the technical device and access data which is automatically collected when you interact with our services. This may be, for example, information on which device you are using (Data we collect from you).
In any case when the data might not be obtained directly from you, we will provide you with transparent information regarding the use of your data for the specific purpose within a reasonable period after the data has been obtained.
The types of data while relating to a person are grouped into the following data categories (categories are not exclusive, and data may transcend multiple categories):
3.1. Identification and Contact data
Data you give to us Data used to identify you as a natural person and/or data we use to contact you.
For example, your name, surname, gender, nationality, billing address, date of birth, email address and telephone number.
Please, bear in mind that your email will be your identity data. We will be able to link your data based on your email.
3.2. Account and Settings data
Data you give to us Data that you give us to execute the payment.
For instance, email and password (we never store the passwords in a non-encrypted form), price alerts, search history, specific settings, preferred choices and other details saved in your account. This also applies if you have a Prime account.
3.3. Payment data
Data you give to us Data that you give us to execute the payment.
Usually, this means the payment card details. For example, credit card number, cardholder name and expiration date (we always store the credit card data in an encrypted form).
3.4. Travel-related data
Data you give to us Data that you provide to us during the booking process, all that you choose in the order form and what you later change or purchase as an addition to the original order.
For example, the number and expiration date of the ID and/or Passport, contact data, travel preferences, boarding passes or e-tickets.
Please, bear in mind that in the case you provide data from travel companions, you should have previously obtained the consent of other individuals before providing us with their data and travel preferences, as any access to view or change their data will be available only through your account or email.
3.5. Communications data
Data you give to us Data we collect from youData from all the text and voice communications exchanged between you and us in connection to your requests.
Such as customer support cases, metadata, and notes generated by our systems and agents.
3.6. Browsing and Device data
Data we collect from you Data that we may automatically collect from your device when you visit our Platforms.
For example, IP address, browser type, internet service providers, geographic location, technical data about the device, pages accessed and links clicked, the time and duration of request and visit, and the method used to submit the request to the server.
Please note that we may associate this data with your account or email.
Some of this data may be collected by using different types of Cookies or similar technologies. For more information, please find our .
3.7. Why do we not normally process Sensitive Personal Data?
We strive to limit the circumstances in which we collect and process Sensitive Personal Data. Please avoid providing us with Sensitive Personal Data unless it is strictly necessary and specifically requested.
One example for which we may collect and process such data would be if exceptional circumstances arose, such as a health emergency, where we might offer you the possibility to provide us with any relevant data in order to share it with the corresponding airline booked, for example, so as to smooth the check-in process or due to mandatory reasons.
In any case, the corresponding appropriate security measures will be implemented to protect your Sensitive Personal Data in line with this Privacy Notice.
Additionally, you may ask us to inform the airline, the hotel, etc. of a special service (such as a menu or an adapted room) which might constitute Sensitive Personal Data because they may imply or suggest data about your religion, health, or other related data. In any case, this information will not be mandatory to provide in any of our booking funnels, so you are free to either provide it or not.
3.8. What happens with the data belonging to children?
Our services are not intended for minors, as described in our General terms and conditions .
The limited cases where we might need to collect minors’ data would be as a booking passenger.
If we become aware that we have processed the data of a child without the valid consent of a parent or guardian, we will delete it.
3.9. Data we collect from third parties
We lawfully obtain data about you from business partners and other independent third-party sources (e.g. contact data such as email, purchase or demographic data). We may obtain such information from fraud prevention companies when the payment method chosen has been compromised, travel insurance companies when hired, and travel-related services providers that have previously managed your data. In any of those cases, we will process your data according to this Privacy Notice. In cases of chargebacks, we may request proof of service from accommodation providers, which may include customer signatures and ID information when required by law. For the previous cases, we will process your data according to this Privacy Notice.
4. Who might be the recipients of your data?
We work particularly closely with certain service providers (e.g. travel service providers, security service providers, etc.) that might normally act as Data controller or Data Processor depending on their circumstances (e.g. on their purposes and type of data they process, our relationship with them, our relationship with you or your relationship with them, their responsibilities under the law, etc.). We are selecting below their main categories.
4.1. Service providers
We will define and regulate the data transfer or processing contractually when required by law with the appropriate security measures.
- Travel service provider you booked with Data controller (e.g. airlines or carriers, hotels, car rental companies, touristic services providers, etc.). In our Platform, there might be services fully or partially provided by our travel business partners. Travel business partners’ terms and conditions and Privacy Notices shall apply, and when so, you will find a link to them in the booking funnel.
- Other travel service providers which are necessary or provide an added value for the performance of our services Data controllerData Processor (e.g. travel insurances, global distribution systems or computerised reservation systems, booking and ticketing agents, tour operators, travel meta searchers, travel and check-in service providers, calendar solutions, claims management service providers, etc.). They make it possible to offer you our services and help us in making all endeavours to have the best alternatives at the best price. When we share your data with other Data Controllers in this way, you will get an opportunity to review their Privacy Notices and terms and conditions first, so you can understand how that service provider will use your data.
- Customer services and support tools Data Processor(e.g. customer communication tools, call centre agents, etc.). We work with customer support providers and tools in order to respond to your requests and manage communications with you if needed.
- Payment and fraud services Data controller (e.g. payment processors, banks, fraud prevention and chargeback management services, etc.). When you pay on our Platform (as in any other) a set of long chains of technical operations need to happen before the payment request is accepted by your bank and notified to us. We also use service providers to detect fraud risks.
- Information security servicesData Processor. We work with information security services to protect your data.
- IT infrastructure providers Data Processor(e.g. hosting service providers). They help us provide you with an available and secure Platform.
- Software solutions and engineers Data Processor. Software solutions and engineers help us work on a day-to-day basis and to continue improving our services.
- Analytical service providers Data Processor. They provide us with the necessary data to understand the use within our Platform, see if there are any technical glitches or bugs or decide how we can improve our services.
- Customer Relationship Management and marketing solutions Data Processor Data Controller. They allow us to manage customised commercial communications. Some of them also help us display customised ads throughout the internet. Other purposes are enabling interest-based content or targeted advertising throughout your online experience (e.g. web, email, connected devices, in-app, etc).
- Social platforms Data Controller. When you login with your social media, clicking on a social media “like” button integrated into our Platforms by plugins, or using any social media services to interact with us, your data can be shared between us and the social media providers.
- Finance, administrative and legal services and tools Data Processor Data Controller (e.g. accounting systems, legal service providers, collection agencies, corporate insurances, etc.).
4.2. Our group companies
We share your data within the eDO Group for internal purposes relating to management centralisation.
In particular, we centralise the processing of your data through the Spanish subsidiary eDreams International Network, SLU, acting as a Data Controller for internal administrative purposes. Likewise, we share your data as customers with other companies from our group, to manage the services provided by us as Data Controller, and for accountability purposes as a group of undertakings, including financial, fiscal and legal duties. Those companies that are included in our group of companies are detailed in our General terms and conditions .
The eDO Group has a common Privacy Policy applying to all of them to ensure that any data processing carried out within our group, is made under the same level of privacy requirements and will be processed exclusively for the same purposes for which the data had been collected, according to the applicable laws. This also applies to our common group Security Policy.
4.3. Competent authorities
We might disclose your data to law enforcement insofar as it is required by law or is strictly necessary for the prevention, detection or prosecution of criminal acts and fraud or if we are otherwise legally obliged to do so, which will act as Data Controller.
We may need to further disclose your data to competent authorities to protect and defend our rights or properties, or the rights and properties of third parties. We are also required by law to share your information with administrative bodies when we are providing you our online travel agency’s services under certain circumstances.
4.4. Others
We will transparently inform you and gather your consent for disclosing your data, where necessary.
These recipients might be outside the European Economic Area (EEA), implying international data transfers. For more information on this, please see below (Section 5.3: International data transfers).
5. How do we protect your data?
5.1. Security measures
While no online service can guarantee absolute security, we design our systems and devices with your security and privacy in mind. We work to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
Some examples of security measures we implement are as follows:
- Data Encryption and Pseudonymisation: We implement pseudonymisation and encryption where applicable to ensure the security of your data. When using our online platforms, your information is transmitted via a secure connection using Hypertext Transfer Protocol Secure (HTTPS), which guarantees encryption during transit to protect it from unauthorised interception.
In addition, as part of our commitment to safeguarding your data, we are certified in accordance with leading industry standards, including ISO/IEC 27001:2013 for information security management. Furthermore, when processing payment information, we adhere to the Payment Card Industry Data Security Standards (PCI DSS). These certifications reflect our ongoing dedication to upholding the highest standards of data security and privacy. In addition, we have numerous suppliers who handle payment data and information, so we ensure that they too continue to be compliant on an annual basis. For further details regarding our IT standards, regulatory compliance, and security protocols, please refer to our dedicated resources here. - Confidentiality and Data Integrity: We uphold the confidentiality, integrity, availability, and resilience of our processing systems. We have implemented comprehensive physical, electronic, and procedural security measures for the collection, storage, and sharing of your data. As part of our security procedures, we may require identity verification before disclosing sensitive information. Furthermore, our platforms include security features to protect against unauthorised access and potential data loss.
- Business Continuity: We have established protocols to restore the availability and accessibility of personal data in a timely manner following any physical or technical incidents.
- Regular Security Audits: We routinely test, assess, and evaluate the effectiveness of our technical and organisational measures to ensure the ongoing security of data processing activities.
5.2. Retention procedures
We will keep your data for as long as we deem it necessary to enable you to use our services, to provide our services to you, comply with the applicable laws, resolve disputes with any parties, and otherwise as necessary to allow us to conduct our business (including, to detect and prevent fraud or other illegal activities). All your data we retain will be subject to this Privacy Notice.
Usually, we process your data for a maximum period of ten years, since your last trip or any further action related to it ended or since you performed your last action with our communications or Platforms for the purposes described above. With regard to unfinished bookings, we might store the information for a maximum period of one year for security and fraud prevention, unless we need to store it for longer periods to fulfil our legal obligations.
Other specific terms might apply, such as a maximum term of three years for accountability purposes regarding data protection-related interactions, or a maximum term of ten years for tax and accounting purposes or for as long as any legal claim is open.
If you provide us with your contact email address, but then you are unable to finish your booking, we will keep your email address only temporarily and, in any case, for a maximum period of seven days to help you with the booking if you are still interested.
For the purpose of customised offers, you will periodically get email offers from us, and in every email, there will be a clear and easy way to unsubscribe and therefore object to this type of processing. We will keep and use your data for this purpose until you unsubscribe or after a maximum period of two years from your last interaction with us (e.g. performing a search, performing a booking, or updating your Prime subscription), or two years after three months of your Prime account expiration. If you unsubscribe from our marketing list, bear in mind that you will still receive service emails about your bookings, as well as notifications of any updates in relation to your account, our terms, our policies and any other critical information. Changes on our marketing list typically go into effect after forty-eight hours, but can take up to seven business days.
For those processing activities based on your consent, we will store your personal data for as long as such processing activities are necessary for the purpose for which they were collected, unless you withdraw your consent or request their deletion prior to that date, and there is no legal or judicial mandate to keep the personal data. Unless otherwise specified in this Privacy Notice, the duration of consent for processing activities based on consent shall be three years from the date of consent or until you withdraw your consent, whichever occurs first.
Browsing and device analytical data collected for improving our services or developing new services will be processed for two years.
Regarding Cookies duration, please check our .
5.3. International data transfers
Our servers are located within the European Union, where your information is stored.
To facilitate our global operations (e.g. by means of service providers) your data we process may be accessed from, processed or transferred to countries other than the country in which you reside to the recipients described above (in Section 4: Who might be the recipients of your data?). Such cross-border transfer of your data is necessary for us to service your transaction with us, and for the other purposes outlined in this Privacy Notice.
It is important to note that data protection laws in some Third Countries might not be as comprehensive as those of the countries within the European Union or the European Economic Area. For this reason, for transfers to recipients in Third Countries, we have taken appropriate steps and put safeguards in place to help ensure that any access, processing and/or transfer of your data remains protected in accordance with this Privacy Notice and in compliance with the applicable data protection laws.
Some mechanisms and measures that we rely on or have put in place include:
We rely on the European Commission Adequacy Decisions, where applicable. See the updated list of Adequacy Decisions here. These are decisions from the European Commission under Article 45 of the GDPR (or equivalent decisions under other laws) where they recognise that a country offers an adequate level of data protection.
When an Adequacy Decision is not available, we rely on European Commission approved Standard Contractual Clauses (hereinafter, the “SCCs”). These contractual safeguards require third parties to process your information in accordance with the GDPR requirements. When relying on SCCs, supplementary measures are included in the SCCs where needed.
Bear in mind that any service and travel providers you choose by using our intermediary services (such as the Travel service providers mentioned in Section 4.1. Service providers) are acting as separate and independent Data Controllers, which will process your data in accordance with their own Privacy Notice or Statement and will be fully responsible for processing your data. In those cases, the transfer of your data is necessary to provide you with our services, and when they are based in Third-Countries we rely on the derogation of contract necessity (outlined in Article 49(1)(b) of the GDPR), where the aforementioned safeguards like the Adequacy Decision or SCCs are not applicable or feasible for that specific instance.
To check the list of Third Countries, click here. We make reasonable endeavours to regularly update this link. If you have any questions regarding the international transfer of your data, or you want to receive a copy of these Adequacy Decisions or SCCs, you can do so by selecting “Other Data Protection comments or suggestions” in our Privacy Form and asking for it anytime.
5.4. What further efforts can you easily do to protect your data?
We make serious efforts to care for and protect your data when you share it with us. We recommend that to keep your data safe you do not share your Booking ID, nor your data account with anyone and use a unique and strong password. Furthermore, we suggest that you beware of internet scams and phishing and only use our official Platforms.
Do not share your Booking ID
When you make a booking you will be assigned with a Booking ID. This reference will be included in your booking confirmation email.
Please, always keep your Booking ID confidential. If you share it with third persons, they might access your data. If you travel with others and you do not want them to have access to your booking data it might be advisable that you carry out your booking separately. For example, we recommend you not to share this data or any other relating to your trip on social media.
Do not share your account data with anyone and use a unique and strong password
To make sure that access to your account on our Platforms is safe please do not share your login data with anyone.
When you finish using our Platforms, please make sure to log out of your session if someone else might access your device. Avoid connecting using your account from non-trusted devices or networks like the ones in hotels, libraries or cyber coffees. If you do, please do not forget to log out once finished.
It is important that you protect yourself against unauthorised third-party access to your password and to your devices. We recommend that you use a unique strong password for your account that you do not use for other online accounts and you should renew it every reasonable period of time, such as once a year. Malicious actors may try to connect to your account using stolen credentials from other (non-related to us) services.
Of course, apply the same approach for your email account, by using unique strong credentials (as is our secure touchpoint to send you “reset link passwords”).
Be cautious and protect yourself from internet fraud and “Phishing”
Please, always double-check the sender of the emails and the links or documents attached to them. If you do not trust or have doubts, do not open the attachments or click on the links.
Be mindful of fake websites that may attempt to impersonate us to commit fraud. Our services (including bookings, account management, etc.) can only be provided directly through the official channels of our Platforms. We do not authorise any individual or third party to accept bookings on our behalf. Furthermore, we will never initiate a phone call to request your bank account information or any sensitive financial details as a method of payment. We prioritise the security and confidentiality of our customers' personal and financial information.
There is a broadly spread type of internet fraud practice known as “Phishing” aimed to illegally obtain your data by deception or by installing malware on your device and stealing your saved credentials.
“Phishing” is unsolicited emails that lead you to insert or confirm your passwords or bank details on a false or cloned website. Also, they try to make you download documents with malware, or install malicious software on your computer that will be used to steal your information, like your credentials.
These fraudsters pretend to be somebody of your trust, a bargain, somebody that needs urgent action from you, etc.If you have doubts regarding any communication that you might have received by someone saying that is us, please, contact us through our chat in our Help Center .
Use only original software
You may want to download our applications from alternative markets. Applications on those markets are not uploaded by us, so they may contain malware used to steal your credentials.
Please use only the official applications from Google Play or Apple Store.
6. How can you control your data and exercise your Privacy Rights?
We want you to be in control of how your data is used by us. You can do it in different ways:
6.1. Managing your account data and trip data
You may access and update some of your data through your account settings, our Customer Service or Help Center .
Regarding your account:
Regarding your trip:
6.2. Exercising your Privacy Rights
We are committed to ensuring fair and transparent processing. That is why it is important to us that persons concerned can exercise the following rights where the respective legal requirements are satisfied:
Rectify your data
You have the right to ask us to correct inaccurate or incomplete data about you (and which you cannot update yourself with your account settings or through our Customer Service).
Access or port your data
You may also be entitled to request copies of the data that you have provided to us in a structured, commonly used, and machine-readable format where technically feasible.
Erasure or block your data
Object or limit the use of your data
- Storing your data for future bookings to make it easier for you to finish a booking with us.
- Creating an account during the booking process when entering the payment information.
- Considering your previous interactions with us to ensure a more efficient and tailored service experience.
- Informing you about services that can assist you in the event of travel incidents or disruptions.
- Customising your searching process.
- Storing your search and contacting you in case you have not finalised a booking online.
- Informing you how to contact us if you need assistance while you are away, or other data that we feel might be useful to you in your planning.
- Collecting customer experience reviews.
- Asking you for a review of your experience with us or the travel provider.
- Subscribing you to our marketing list and sending you regular news of travel-related products and services (we remind you that you can also unsubscribe at any moment in each commercial communication, by clicking on the footer’s unsubscription link).
- Showing you customised categorised offers on our Platforms, or in third-party platforms.
- Avoiding sending promotional content that is irrelevant or of no interest to you.
- Using call or chat recordings for quality purposes and training.
- Improving our services or developing new services.
- Elaborating anonymised statistics regarding the overall conversion rate of the website.
Withdrawing your consent
- Saving your payment data for future bookings in those cases in which you are not a Prime subscriber.
- Retrieving the booking information that you have already provided so you do not have to enter your data again in the same booking process.
- Using your geolocation to pre-populate the 'origin' field of the search form.
- Creating your account.
- For certain purposes related to our travel-related services, such as contacting you through specific instant messaging platforms, or in order to send information previously requested by travel services providers.
- When you take part in a market research survey with us.
- Sending you discount codes, deal alerts, and a birthday surprise with eDreams newsletter.
Exercise your rights through our Privacy form .
We may need to verify your identity before fulfilling your request. We will answer the request directly to the email address that we have in our systems, and the one previously verified. If you require a response in a language other than those offered in the Privacy form , please indicate this by selecting "Other Data Protection comments or suggestions" in the form.
You have the right to lodge a complaint with a supervisory authority (for Spain https://www.aepd.es/).
7. Regional-specific provisions
7.1. The United Kingdom
Our UK Representative is Opodo Limited with tax ID number 766445988.
Contact us through our Privacy form to exercise a specific right or for other data protection comments or suggestions.
7.2. The United States
Depending on which state you reside in, different laws might apply (such as California, Colorado, Connecticut, Virginia, and Utah). More specifically, if you are from California, the California Consumer Privacy Act (“CCPA“) would be applicable, and you would have the following rights in relation to the personal data that we hold about you: right to know (i.e. to request information about how we process your data), right to request deletion of certain personal data that we process about you, and the right to opt-out of sale of your personal data to third parties. Contact us through our Privacy form , to exercise a specific right or for other data protection comments or suggestions.
We allow third parties to collect your data through our Platforms, and share it for the purposes described in this Privacy Notice (including without limitation for customised advertising and marketing on our Platforms and elsewhere based on users’ online activities over time and across our Platforms, services, and devices).
We do not sell your data as covered by the definition of “sale” covered in the applicable laws of Nevada and California.
Remember that you can block non-strictly necessary Cookies (including ads and analytics cookies), as described in our .
8. Updates and previous versions
We might amend this Privacy Notice from time to time to make sure it is up-to-date. Do not hesitate to visit this page regularly and you will know exactly where you stand. We will note the date that revisions were last made to this Privacy Notice at the bottom of this page, and any revisions will take effect upon posting.
Last Updated: April 2025