Privacy Policy

Privacy Policy

How Melrose Travel handles visitor data, travel enquiries, cookies and your privacy rights.

Last updated: 20 September 2026

Melrose Travel respects your privacy. This policy explains what personal data we may process when you visit melrosetravel.eu, contact us, submit a travel enquiry or use our services, why we use those data, how long we keep them and what rights you have.

1. Who is responsible for your data?

Melrose Travel, based in The Hague, the Netherlands, is the controller for the processing described in this policy. Privacy questions and requests can be sent to contact@melrosetravel.eu.

2. What personal data may we collect?

The data we process depends on how you use the website and our services. They may include your name, email address, telephone number, preferred method of contact, intended travel period, duration, group composition, budget indication, accommodation and transport preferences, interests, travel pace and the information you choose to include in the story or message accompanying your enquiry.

When relevant to a journey, you may voluntarily provide information about accessibility, mobility, dietary requirements or allergies. Some of this information may qualify as sensitive or special-category personal data. We only ask for and use such information when it is relevant to arranging the service you request and, where required, on the basis of your explicit consent.

We may also process technical data needed to operate and secure the website, such as browser and device information, security logs, necessary cookie data and limited network information used for security and spam prevention.

3. Why do we use personal data?

We use personal data to respond to enquiries, understand your travel wishes, prepare and manage tailored travel proposals, communicate with you, arrange requested services, administer bookings and payments where applicable, provide customer service, maintain and secure the website, prevent misuse and spam, keep appropriate business records and comply with legal obligations.

Where non-essential cookies, analytics or marketing communications require consent, we use them only when the required consent has been obtained.

4. Legal bases for processing

Depending on the situation, processing is based on one or more of the following grounds: taking steps at your request before entering into a contract; performing a contract; complying with a legal obligation; our legitimate interests, for example website security, fraud and spam prevention and normal business administration; or your consent where consent is required.

5. Travel enquiries and contact forms

Information submitted through our travel enquiry and contact forms is used to assess and respond to your request. A genuine enquiry may be stored privately in the Melrose Travel management environment and may result in an email notification to Melrose Travel and, where configured, a confirmation to you.

Please do not include information in a free-text field that is not relevant to your journey or enquiry.

6. Spam and website security

To protect our forms against automated or abusive submissions, Melrose Travel uses layered anti-spam checks. These can include a hidden honeypot field, the time taken to complete a form, submission frequency, the number and pattern of links, characteristics of the submitted text and other technical signals.

For short-term rate limiting, a visitor’s network address may be converted into a salted cryptographic hash. The raw network address is not stored as part of the travel enquiry for this purpose. The temporary hash is used only to recognise excessive submission activity over a limited period.

Submissions classified as likely spam may be placed in a private quarantine without sending an email notification or customer confirmation. Quarantined spam is normally deleted automatically after 30 days. A human administrator can review or reclassify an item. The spam filter is not used to decide whether a person is eligible to purchase or receive a travel service.

7. Who may receive your data?

We share personal data only when this is necessary for the relevant purpose. Depending on the journey or service, recipients may include accommodation providers, transport companies, local guides, activity providers, Scottish travel partners and other suppliers involved in delivering your itinerary. We may also use hosting, IT, email, administration or payment service providers where needed.

We aim to share only the data that a recipient needs for the relevant task. Service providers that process data on our behalf are expected to handle personal data appropriately and in accordance with applicable data-protection requirements.

8. External platforms, social media and links

The website may link to or, on some pages, integrate services provided by third parties such as maps, podcast platforms, social networks, travel-search or affiliate partners. If you open or use such a service, that third party may process information under its own privacy policy. A social-media icon in our footer is a link; data are not intentionally sent to that social network by Melrose Travel merely because the icon is displayed.

9. International transfers

Some suppliers or technology providers may process data outside the European Economic Area. Where data are transferred internationally and data-protection law requires additional safeguards, we aim to use an appropriate legal transfer mechanism and applicable safeguards.

10. How long do we keep personal data?

We do not intend to keep personal data longer than necessary for the purpose for which they were collected. General enquiries are normally retained for no longer than 24 months after the last meaningful contact, unless an active booking, a legal claim or another justified purpose requires a longer period. Spam quarantined by the website is normally removed after 30 days.

Booking, invoicing and other records that form part of our statutory business administration may need to be retained for the period required by law. In the Netherlands, core tax and accounting records generally have a seven-year retention period.

11. Cookies and analytics

The website may use cookies or similar technologies that are necessary for security, session management and core website functionality. Analytics, advertising, marketing or other non-essential technologies are only used when they are actually configured and, where required by law, after consent. The technologies used on the website can change as functionality is developed, in which case this policy and any cookie information should be updated accordingly.

12. How do we protect your data?

Melrose Travel uses reasonable technical and organisational measures designed to protect personal data against loss, unauthorised access, alteration and misuse. Access to management functions is restricted. No website or internet transmission can, however, be guaranteed to be completely secure.

13. Your privacy rights

Under the General Data Protection Regulation (GDPR), you may have rights including the right to information, access, rectification, erasure, restriction of processing, data portability and objection. Where processing is based on your consent, you may withdraw that consent at any time without affecting processing that was lawful before withdrawal.

To exercise a privacy right, contact contact@melrosetravel.eu. We may need to verify your identity before acting on a request.

14. Complaints

If you have concerns about how we handle personal data, please contact us first so that we can look into the matter. You also have the right to lodge a complaint with the competent data-protection supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens.

15. Changes to this privacy policy

We may update this policy when our website, forms, services, suppliers, security measures or legal obligations change. The version published on this page is the current version. Where a change materially affects how we use personal data, we will update the relevant information before or when the new processing is introduced.