Privacy policy

Privacy Policy – ticketsnotredamedeparis.com
Effective Date: April 12, 2025
1. Introduction
• 1.1. This Privacy Policy describes how Tourmaster (“we”, “us”, “our”), located at Dubai Silicon Oasis, collects, uses, processes, and protects your personal data when you visit our website ticketsnotredamedeparis.com (the “Website”) and book our guided tours of Notre Dame de Paris (“Tours”).
• 1.2. We are committed to protecting your privacy and processing your personal data in accordance with the applicable laws of the United Arab Emirates, including Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “PDPL”).
• 1.3. By using our Website and booking our Tours, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller
• 2.1. Tourmaster is the data controller responsible for the personal data collected through this Website.
• 2.2. Our contact details for privacy-related matters are provided in Section 14.
3. Information We Collect
• 3.1. We may collect and process the following categories of personal data:
◦ a) Identity Data: Full name, title.
◦ b) Contact Data: Email address, phone number, billing address (if required for payment verification).
◦ c) Booking Data: Details of the Tour(s) you book (date, time, number of participants, language preference), booking reference number.
◦ d) Financial Data: Payment card details (processed directly by our secure third-party payment gateway; we typically only receive confirmation of payment, transaction IDs, and possibly the last four digits of your card number, but do not store full card details).
◦ e) Technical Data: Internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this Website.  
◦ f) Usage Data: Information about how you use our Website (pages visited, time spent, links clicked).  
◦ g) Communication Data: Your preferences in receiving marketing from us (if applicable) and your communication preferences, records of correspondence if you contact us.
4. How We Use Your Information
• 4.1. We use your personal data for the following purposes:
◦ a) To Provide Services: To process your Tour bookings, manage your reservations, process payments, and provide you with Booking Confirmations and relevant Tour information.
◦ b) To Communicate: To send you service-related communications regarding your booking (confirmations, reminders, updates, changes), respond to your inquiries, and provide customer support.
◦ c) To Improve Our Services: To analyze Website usage (using aggregated or anonymized data where possible) to improve the Website functionality, user experience, and Tour offerings.
◦ d) For Marketing (with Consent): To send you newsletters, special offers, or information about other tours or services that may interest you, but only if you have explicitly consented to receive such communications. You can opt-out at any time.
◦ e) For Legal and Security Purposes: To comply with legal or regulatory obligations, prevent fraud, enforce our Terms and Conditions, and protect our rights and the safety of our users.
5. Legal Basis for Processing (Under PDPL)
• 5.1. We process your personal data based on the following legal grounds under the PDPL:
◦ a) Contractual Necessity: Processing is necessary for the performance of a contract with you (i.e., to fulfill your Tour booking). This applies to Identity, Contact, Booking, and Financial Data used for providing the service.
◦ b) Consent: Where you have given us clear, specific, and unambiguous consent to process your personal data for a particular purpose (e.g., receiving marketing communications).
◦ c) Legal Obligation: Processing is necessary for compliance with a legal obligation to which we are subject (e.g., financial record-keeping, responding to legal authorities).
◦ d) Legitimate Interests: Processing is necessary for our legitimate interests (e.g., website security, improving services), provided that your fundamental rights and freedoms do not override those interests.
6. Data Sharing and Disclosure
• 6.1. We do not sell your personal data. We may share your personal data with the following categories of third parties only when necessary:
◦ a) Payment Processors: Secure third-party payment gateways to process your payments.
◦ b) Tour Guides/Operators: Licensed guides or partner tour operators (especially if located in France) who conduct the Tours, solely for the purpose of managing your participation in the specific Tour you booked.
◦ c) IT Service Providers: Companies that provide website hosting, maintenance, analytics, and other technical services.
◦ d) Marketing Tools: Email marketing service providers (if you consent to marketing).
◦ e) Legal and Regulatory Authorities: If required by law, court order, or other legal process, or to protect our rights or safety.
• 6.2. We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We only permit them to process your personal data for specified purposes and in accordance with our instructions.  
7. International Data Transfers  
• 7.1. Since the Tours take place in Paris, France, it may be necessary to transfer certain personal data (e.g., participant names for the guide) outside the UAE.
• 7.2. France is part of the European Union, which has data protection laws (GDPR) generally considered to provide an adequate level of protection.
• 7.3. Any transfer of personal data outside the UAE will be done in compliance with the requirements of the PDPL, ensuring appropriate safeguards are in place, such as transferring to countries deemed adequate by the UAE Data Office, using approved standard contractual clauses, or obtaining your explicit consent for the transfer after informing you of the risks.
8. Data Security
• 8.1. We have implemented appropriate technical and organizational security measures to prevent your personal data from being accidentally lost, used, accessed in an unauthorized way, altered, or disclosed.  
• 8.2. These measures include encryption (where appropriate), access controls, secure servers, and staff training. We limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know.  
• 8.3. While we strive to protect your personal data, no internet transmission or electronic storage is 100% secure.
9. Data Retention
• 9.1. We will only retain your personal data for as long as reasonably necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements.  
• 9.2. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process it, and applicable legal requirements.  
• 9.3. Booking information may be kept for a period after the Tour date to handle any post-tour inquiries or comply with financial regulations. Data collected solely based on consent (like marketing subscriptions) will be kept until you withdraw your consent.
10. Your Data Protection Rights (Under UAE PDPL)
• 10.1. Under the PDPL, you have the following rights regarding your personal data:
◦ a) Right to Access: Request access to the personal data we hold about you and information about how it’s processed.
◦ b) Right to Rectification: Request correction of inaccurate or incomplete personal data.
◦ c) Right to Erasure (‘Right to be Forgotten’): Request deletion of your personal data where there is no compelling reason for us to keep processing it (subject to legal/contractual restrictions).
◦ d) Right to Restrict Processing: Request the suspension of processing your personal data in certain circumstances.
◦ e) Right to Data Portability: Request the transfer of your personal data to you or a third party in a structured, commonly used, machine-readable format (where processing is based on consent or contract and is automated).  
◦ f) Right to Object: Object to the processing of your personal data where we are relying on legitimate interests (or those of a third party), or where we are processing it for direct marketing purposes.  
◦ g) Right related to Automated Processing/Profiling: Right not to be subject to decisions based solely on automated processing, including profiling, which produces legal or similarly significant effects (we currently do not engage in such activities impacting users significantly).  
◦ h) Right to Withdraw Consent: Where processing is based on consent, you have the right to withdraw that consent at any time (this will not affect the lawfulness of processing before withdrawal).
◦ i) Right to Lodge a Complaint: You have the right to lodge a complaint with the UAE Data Office (the UAE’s data protection regulator) if you believe your data protection rights have been infringed.
11. How to Exercise Your Rights
• 11.1. To exercise any of the rights listed above, please contact us using the contact details provided in Section 14.
• 11.2. We may need to request specific information from you to help us confirm your identity before processing your request. This is a security measure to ensure that personal data is not disclosed to unauthorized persons.  
• 11.3. We will respond to legitimate requests within the timeframe stipulated by the PDPL (generally one month, extendable in complex cases).
12. Cookies and Similar Technologies
• 12.1. Our Website uses cookies (small text files placed on your device) and similar technologies to distinguish you from other users, provide essential functionality, analyze website traffic, and potentially personalize content or advertising (if applicable).  
• 12.2. For detailed information on the cookies we use, the purposes for which we use them, and how you can manage your cookie preferences, please see our Cookie Policy [Insert Link to your Cookie Policy or describe management via banner/settings here].  
13. Children’s Privacy
• 13.1. Our Website and Tours are not primarily directed at children under the age of 18. We do not knowingly collect personal data from children without parental consent where required by law. If you believe we have inadvertently collected data from a child without proper consent, please contact us immediately so we can take appropriate action.  
14. Links to Other Websites
• 14.1. Our Website may contain links to other websites not operated by us. If you click on a third-party link, you will be directed to that third party’s site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.  
15. Changes to This Privacy Policy
• 15.1. We may update this Privacy Policy from time to time to reflect changes in our practices or for legal or regulatory reasons. We will notify you of any significant changes by posting the new Privacy Policy on this page and updating the “Effective Date” at the top.  
• 15.2. We encourage you to review this Privacy Policy periodically for any updates.
16. Contact Us
• 16.1. If you have any questions about this Privacy Policy, our data practices, or wish to exercise your data protection rights, please contact us at:
◦ Tourmaster
◦ Dubai Silicon Oasis
◦ Email for Privacy Matters: [email protected]