Exodus Travels Ltd (t/a Headwater Holidays) is part of the Travelopia group of companies (www.travelopia.com). Here at Headwater Holidays, we take your privacy very seriously.
We understand the concerns about how data may be stored, sent and used by companies. We are committed to complying with all data protection laws and want you to feel confident in the measures we are taking to uphold your data privacy rights.
This privacy notice explains how we collect and use your personal data. We explain the types of information we collect, how we collect it, what we use it for, and who we may disclose your personal data to. Depending on where you live, we also let you know what rights you have over your information.
Please note this North America Privacy Notice is applicable to United States residents and individuals in Canada only. Please see our Global Privacy Notice if you are not a United States resident or are not in Canada.
Exodus Travels Ltd is the "data controller" or "business", as those and similar terms are defined under applicable data privacy laws, of all personal data collected and used for the purposes of providing our products or services and for any other purposes set out in this privacy notice. This means that Exodus Travels Ltd is responsible for keeping your personal data safe; deciding how and why your data is used; and ensuring that your personal data is handled legally.
We do our best to keep the personal data we collect about you to the minimum necessary needed to fulfil the purpose of collection or processing.
The personal data we collect depends upon how you are interacting with us. For example, if you are making a booking with us we are likely to ask for more information than if you're only requesting a brochure or browsing our website. We may collect, use, store and transfer different kinds of personal data depending on the nature of the product or service you buy from us; the below contains some of the personal data we may ask you to provide:
Details about you: Your first and last name, marital status, title, gender, e-mail address, telephone number, postal address, date of birth, loyalty membership details, your reasons for travel, emergency contact details, clothing size (for merchandise) and qualifications (e.g. if you book a cruising/sailing holiday).
Payment details: Your bank details and payment card details when making a booking with us. Details about payments to and from you and other details of products and services you have purchased from us.
Identification documents: If you are travelling on a route requiring advance passenger information, your passport or identity card details including your passport number, the country in which your passport was issued and the expiry date.
Details about your booking with us: Details such as where you are flying from and to, your booking information (including anyone else on the booking), any onward travel details if relevant, details of experiences or excursions booked through us, baggage requirements, upgrade information, lounge visits, seat preferences, meal or dietary preferences or requirements, details of any special assistance required and any other relevant information so that we can provide you with the entirety of the services you have arranged with us.
Details from your interactions with us: Information about interactions or conversations with us and our staff, including when you make enquiries, comments, complaints or submit feedback to us. This could also include username and password and your interests, marketing preferences, reviews and survey responses.
Your use of our systems and services: This includes how you use our site, app, physical locations (such as bases, vessels or retail stores), call centres, social media pages, IP addresses, information from cookies and other electronic tracking technologies and information you may post on social media.
Job applications: If you apply for a job with us, your CV, work history, educational details and the role you are applying for.
Special types of data: In some circumstances, we may need to collect information from you that is deemed sensitive. For example, we might collect:
We try to limit any sensitive personal data we collect to the minimum possible. Unless we have another specific lawful reason to use this information, we will ask for your explicit consent to collect it.
We do not knowingly collect or solicit any personal data directly from children under the age of 16. In the event that we learn that we have collected personal data from a child, we will promptly take steps to delete that information. If you are a parent or legal guardian and think your child has given us their personal data, you can contact us via the methods in the How can you contact us? section below.
Depending upon your interactions with us, we might collect personal data in the following ways:
You may give us your identity, contact and financial data by filling in forms or by corresponding with us by post, phone, email or otherwise, This includes personal data you provided when you:
As you interact with our website, we may automatically collect technical data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, server logs, pixels, web beacons and other similar technologies. We process the personal data collected through such technologies to help operate certain features of our website, to enhance your experience through personalisation, and to help us better understand the features of the website that you and other users are most interested in.
We use analytics services, including Google Analytics, to assist us with analyzing our website traffic through cookies and similar technologies. To learn more about how Google uses data, visit Google's page on "How Google uses data when you use our partners' sites or apps." You may download the Google Analytics Opt-out Browser Add-on for each web browser you use, but this does not prevent the use of other analytics tools. To learn more about Google Analytics cookies, visit Google Analytics Cookie Usage on Websites.
You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly. For more information about the cookies we use, please see our Cookie Policy for further details.
We may receive personal data about you from various third parties, including (but not limited to) those set out below:
We have set out below a description of the ways we may process your personal data:
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose.
If we need to use your personal data for an unrelated purpose, we will notify you and if required we will obtain your consent to such use.
Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
One of the other reasons we sometimes collect your personal data is so that we can form a view on what may be of interest to you. With this information, we decide which products, services and offers may be relevant for you and what marketing you may be interested in.
We keep you up to date with our latest offers, partnerships, sales, promotions, and competitions (or those of our partners such as other members of the Travelopia group) that we think might be of interest/relevance to you.
When required by applicable law, we will obtain your consent prior to contacting you for these purposes.
We never want to send our marketing to someone who isn't interested in receiving this content. If you have decided that you no longer wish to hear from us, you can unsubscribe from marketing by clicking on the 'unsubscribe' link included in all of our e-mails or by contacting us.
In order to provide you with the services described above, we may disclose your personal data to third parties such as:
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or disclose your personal data. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit.
If you are visiting this website or using our products or services from outside of the United States or Canada, please note that by providing your personal data, it may be transferred to, stored, collected, or processed in the United States or Canada.
Depending on where you live in the United States or Canada, and subject to certain exceptions, you may have the following rights with respect to your personal data:
If you wish to exercise any of the privacy rights afforded to you in this section, please see the How can I exercise my privacy rights? section below.
We take the security of your personal data very seriously. While no organisation can guarantee absolute security, we have reasonable technical and organisational security measures in place to address risk and prevent your personal data from being accidentally or unlawfully lost, used, accessed, altered, or disclosed in an unauthorised way. In addition to these measures, we limit access to your personal data to those employees, agents, contractors, and other third parties on a 'need-to-know' basis.
We will retain personal data only for as long as necessary to fulfil the purposes described in this privacy notice, unless otherwise required by applicable laws. We consider the following criteria to determine how long we will retain your personal data, including whether: we need your personal data to provide you with the products and services you requested; we continue to have a business relationship with you; you have requested information on our products and services; we have a legal right or obligation to continue to retain your personal data; we have an obligation to a third party that involves your personal data; our retention or recordkeeping policies and obligations dictate that we retain your personal data; we have an interest in providing you with information about other products and services; and we have another business purpose for retaining your personal data.
In some circumstances, we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.
This section applies to our collection and use of Personal Information if you are a resident of California, as required by the California Consumer Privacy Act of 2018 and its implementing regulations, as amended by the California Privacy Rights Act (collectively, "CCPA"), where "Personal Information" has the definition set forth in the CCPA.
We have collected the following categories of Personal Information from our customers within the last 12 months. The sources from which we obtain this information and the ways in which we use this information are set forth in above. We will not collect additional categories of Personal Information or use the Personal Information we collected for materially different, unrelated, or incompatible purposes without providing you notice.
Categories of CA Personal Information We Collect | Categories of Third Parties to Which We Disclose Personal Information for a Business or Commercial Purpose | Categories of Third Parties to Which We May Sell or Share Personal Information |
---|---|---|
Identifiers | Affiliates, third party suppliers, and service providers | Companies that operate cookies and other online tracking technologies |
Personal information, as defined in the California customer records law | Affiliates, third party suppliers, and service providers | Companies that operate cookies and other online tracking technologies |
Commercial Information | Affiliates, third party suppliers, and service providers | Not sold or shared |
Biometric Information | N/A | N/A |
Characteristics of protected classifications under California or Federal Law | Affiliates and service Providers | Not sold or shared |
Internet or other similar network activity | Affiliates, third party suppliers, and service providers | Companies that operate cookies and other online tracking technologies |
Geolocation data | Affiliates, third party suppliers, and service providers | Companies that operate cookies and other online tracking technologies |
Audio, electronic, visual, thermal, olfactory, or similar information | Affiliates, third party suppliers, and service providers | Not sold or shared |
Inferences drawn from other personal information | Affiliates, third party suppliers, and service providers | Companies that operate cookies and other online tracking technologies |
Professional or employment-related information | Affiliates, third party suppliers, and service providers | Not sold or shared |
Non-public education information (per the Family Education Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99) | N/A | N/A |
Sensitive personal information | Affiliates, third party suppliers, and service providers | Not sold or shared |
Please see the 'How long do we keep your personal data for?' section for information related to our data retention practices. |
Subject to certain exceptions, you may have the following rights:
Only you, or an authorized agent that you authorize to act on your behalf, may make a request related to your Personal Information. You may also make a request on behalf of your minor child.
You may only make a request for access or data portability twice within a 12-month period. The request must:
Pursuant to California's Shine the Light statute (Cal. Civ. Code Sec. 1798.83), individual customers who reside in California and who have an existing business relationship with us may request information about our disclosure of certain categories of personal information to third parties for the third parties' direct marketing purposes, if any. To opt-out of us sharing your information with third parties for such promotional purposes, email us at the email address provided in the "How can you contact us?" section of this privacy notice and include "Marketing Opt-Out" in your request. This request may be made no more than once per calendar year. Please note that, as of the date of this privacy notice, we do not disclose your information with third parties for their marketing purposes.
We comply with applicable Canadian data protection laws, including the Personal Information Protection and Electronic Documents Act (PIPEDA).
Your provision of personal data to us means that you agree and consent that we may collect, use and disclose your personal data for the purposes described in this privacy notice. Should you choose not to provide us with required personal data, we may not be able to provide certain services. You acknowledge and consent that we may retain service providers to perform certain services. In the event that a service provider is located in the United States or another jurisdiction, personal data may be processed and stored in that jurisdiction, and that foreign courts or law enforcement or regulatory agencies may be able to obtain disclosure of personal data through the laws of those jurisdictions.
Residents of Canada may access, review, and request correction of their personal data held by us. We will take reasonable steps to verify your identity prior to responding to your requests. The verification steps will vary depending on the sensitivity of the personal data and whether you have an account with us.
We reserve the right not to change personal data if we disagree that it is incorrect, but we will maintain a record of your request. We may not provide access to personal data if an exemption applies, for example, where the information requested would disclose the personal data of another individual or if the information would reveal confidential commercial information.
You have the right to refuse to provide or to withdraw your consent to processing of your personal data at any time. This would not affect processing where the applicable law allows us to process personal data without consent.
We will not collect, use or disclose your personal data for any other purpose than those outlined above, except with your consent. We will respond to your request regarding your personal data as promptly as possible.
You will not be discriminated against in any way by virtue of your exercise of the rights listed in this privacy notice which means we will not deny goods or services to you, provide different prices or rates for goods or services to you, or provide a different level or quality of goods or services to you.
To exercise any of the privacy rights afforded to you under applicable data protection law, please submit a request to us by one of the following methods:
We must verify your identity before fulfilling your requests. If we cannot initially verify your identity, we may request additional information to complete the verification process. We will only use personal data provided in a request to verify the requestor's identity. If you are an authorized agent making a request on behalf of an individual, we will also need to verify your identity, which may require proof of your written authorization or evidence of a power of attorney.
We endeavor to respond to requests within the time period required by applicable law. If we require more time, we will inform you of the reason and extension period in writing.
Whether you have an account with us or not, we will deliver our written response by mail or electronically, at your option.
We do not charge a fee to process or respond to your request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
We cannot respond to your request or provide you with personal data if we cannot verify your identity and confirm the personal data relates to you. Making a verifiable consumer request does not require you to create an account with us.
We may deny certain requests, or only fulfill some in part, as permitted or required by law. For example, if you request to delete personal data, we may retain personal data that we need to retain for legal purposes.
This privacy notice is available to consumers with disabilities. To access this privacy notice in an alternative downloadable format, please click here.
If you are not satisfied with the resolution of your request and you are afforded a right to appeal such decision, you can contact us using the information provided below.
If you have any questions about this privacy notice, including any requests to exercise your legal rights, please contact us using the details set out below.
Data Protection
Exodus Travels Ltd
Platinum House,
St. Mark's Hill,
Surbiton,
London,
United Kingdom
datateam@exodus.co.uk
CC: dataprotection@travelopia.com
Please contact us in the first instance if you have any concerns. If we are unable to resolve your concern, you have the right to make a complaint to the relevant data protection authority where you live.
We keep our privacy notice under regular review. This version was last updated September 2023.
Please note that we may modify or update this privacy notice from time to time, so please review it periodically. We may provide you with an updated privacy notice if material changes are made. Unless otherwise indicated, any changes to this privacy notice will apply immediately upon posting to our website.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
Exodus Travels Limited, trading as Headwater Holidays, is a member of the Travelopia Group of Companies. Registered UK Office: Platinum House, St Mark's Hill, Surbiton, Surrey, KT6 4BH. Registered in England and Wales No. 1150160. Vat no. 108216835.