top of page
Need Help?

Feel Free to Contact Us

Privacy notice

Published: 3 August 2026


1. Who we are

Timeless North Limited, company number SC860505, trading as Scottish Luxury Experience (“SLE”, “we”, “us” or “our”), is the controller of the personal information described in this notice.

Our registered office is Suite 53, Bonnington Bond, 2 Anderson Place, Edinburgh, Scotland, EH6 5NP.

For a privacy enquiry, rights request or data-protection complaint, contact our privacy contact at contact@scottishluxuryexperience.com or write to the registered office above. We do not describe this contact as a data protection officer unless a formal appointment has been made and recorded.

Our contracted platform development and support provider handles personal information in providing those services on our instructions.


2. What this notice covers

This notice covers personal information used in connection with:

  • our website, enquiries, calls and marketing;

  • proposals, bookings, contracts, payments and financial-failure protection;

  • planning, supplying and supporting trips;

  • our guest, Guide and operations applications;

  • traveller, Guide and supplier communications and documents;

  • complaints, incidents, claims and legal or regulatory matters; and

  • security, audit, backup and recovery of our systems.

A supplier, payment provider, insurer or other organisation may also act as a separate controller for its own processing. Its own privacy notice will then also apply.


3. Information we collect

Depending on your relationship with us, we may collect and use:

  • identity and contact information, including names, postal and email addresses, telephone numbers and traveller relationships;

  • passport, nationality, date-of-birth, visa and other travel-document information where it is reasonably required;

  • enquiry, proposal, booking and contract information, including itineraries, dates, preferences, budgets, party details, contractual services and change requests;

  • health, disability, mobility, accessibility, allergy, dietary and religious information where it is relevant to a request or trip;

  • emergency-contact information and information needed to respond to a safety incident;

  • payment records, payment schedules, currency and settlement information, refunds, disputes and fraud-prevention information. We do not receive the full card number held by Stripe;

  • financial-failure-protection records, policy eligibility, claims and communications;

  • messages, call notes, chats, support requests, photographs, tickets, documents and other material supplied through our services;

  • app-account, access, device, push-notification and coarse technical information;

  • Guide, driver, supplier, assignment, qualification and operational records;

  • website and cookie information, including device, browser, IP address, referral, consent and interaction data;

  • marketing preferences and records of consent or objection; and

  • audit, security, fraud-prevention, diagnostic, backup and recovery records.


4. Where information comes from

We may receive information from:

  • you, a lead booker or another person authorised to act for you;

  • another traveller, Guide or supplier involved in a booking;

  • Stripe, banks and other payment or fraud-prevention providers;

  • accommodation, transport, Guide, attraction and experience providers;

  • International Passenger Protection, DUAL Corporate Risks, the relevant insurers, Sedgwick and other parties involved in protection or claims;

  • GoHighLevel, Wix, Google Workspace and connected business systems;

  • historic Protected Trust Services records and settlement information;

  • app stores, identity, notification and technical service providers; and

  • public sources where use of the information is fair and lawful.

If a lead booker gives us information about another adult, they must have authority to do so. Health or other special-category information should normally be supplied or expressly authorised by the traveller concerned.


5. Why we use information and our lawful bases

We use only the lawful basis that fits the particular purpose.


Purposes and normal Article 6 lawful bases

Purpose

Normal UK GDPR Article 6 basis

Responding to an enquiry, preparing a requested proposal and taking steps towards a booking

Article 6(1)(b), steps requested before a contract

Forming, administering and delivering a booking, taking payment and providing support

Article 6(1)(b), performance of a contract

Keeping tax, accounting, company, consumer, package-travel, insolvency-protection and regulatory records

Article 6(1)(c), legal obligation

Protecting a person's life or physical safety in a genuine emergency

Article 6(1)(d), vital interests

Operating, securing, auditing, improving and defending our services; managing suppliers; preventing fraud; and handling ordinary business communications

Article 6(1)(f), our or another person's legitimate interests, where those interests are not overridden by your rights

Email or similar direct marketing where consent is required, and non-essential cookies or comparable technologies

Article 6(1)(a), consent

Establishing, exercising or defending legal rights and claims

Article 6(1)(f), legitimate interests, and Article 6(1)(c) where a legal duty applies

Where we rely on legitimate interests, we consider the purpose, necessity and effect on the people concerned. You may ask us for information about that assessment.

We do not use consent as the basis for performing a contract where the processing is objectively necessary to provide the requested service.


6. Health, accessibility and other special-category information

Some dietary, accessibility, mobility or allergy information may reveal health information or religious belief and is special-category data. We ask for it only where it is relevant to a requested arrangement or safe trip delivery.

For ordinary trip planning, our usual Article 9 condition is the traveller's explicit consent under Article 9(2)(a) of the UK GDPR. Where we rely on that condition, consent is requested separately from booking terms and marketing, and the traveller may withhold or withdraw it. We may be unable to assess or provide a requested adjustment after withdrawal.

In a genuine emergency where the person cannot consent, or where processing is necessary for a legal claim, another Article 9 condition may apply. We use and share only what is reasonably necessary for the applicable purpose.


7. Payments, financial protection and historic Trust records

Where Stripe is offered and used for a payment, Stripe receives the name, email address, amount, currency, our booking or customer references and the payment information needed to process that payment. Stripe stores the full card number; we do not receive it. We may receive a payment-method identifier and limited card details such as brand, last four digits and expiry date. Stripe and the relevant bank may act as separate controllers for parts of their payment, security and legal processing.

For bookings previously administered through Protected Trust Services, we retain historic booking and payment records, recorded with their true source; we do not represent a historic payment as a Stripe transaction. This is historical record-keeping and does not determine the protection applying to a new booking.

The financial-failure protection applying to a booking, if any, is identified in its booking-specific information and will be recorded in the applicable Booking Confirmation. We may share necessary information with International Passenger Protection, DUAL Corporate Risks, the applicable insurers, Sedgwick or another claims administrator, broker, professional adviser or regulator.


8. AI-assisted work

Authorised staff may use AI services, provided under contract by technology providers acting on our instructions, to help prepare trip documents and process booking correspondence. The content needed for a task may be shared with those providers and can include traveller names, preferences and booking documents; the requirements in section 6 apply where special-category information is involved.

A member of staff reviews AI-assisted output, and a human remains responsible for customer-facing publication and material booking or safety decisions. We do not use AI alone to make a decision producing legal or similarly significant effects about a traveller.


9. Who we share information with

Where necessary for the purposes above, we may share information with:

  • accommodation, passenger-transport, Guide, driver, attraction, restaurant, activity and other travel-service providers;

  • Stripe, banks and payment, refund, dispute and fraud-prevention providers;

  • International Passenger Protection, DUAL Corporate Risks, Liberty Mutual Insurance Europe SE UK Branch, Axis Specialty Europe SE (UK Branch), Sedgwick and other relevant protection, insurance or claims parties;

  • our platform development and support provider and its authorised support personnel;

  • website, customer-relationship, email and document providers acting on our instructions;

  • hosting, database, storage, identity and related infrastructure providers acting on our instructions;

  • technology providers supplying the AI-assisted document processing described in section 8, acting on our instructions;

  • Apple, Google and other app-distribution, push-notification and, where enabled, restricted diagnostics providers;

  • accountants, lawyers, insurers, auditors and other professional advisers; and

  • courts, regulators, law-enforcement bodies, emergency services and public authorities where disclosure is lawful and necessary.

Where a provider processes information only on our instructions, SLE remains responsible for selecting and overseeing that provider. Some listed organisations determine parts of their own processing and act as separate controllers.


10. International transfers

SLE is based in the United Kingdom, but travellers, travel suppliers and some technology providers may be elsewhere. Some recipients may be outside the United Kingdom.

We will not make a transfer restricted by UK data-protection law unless an applicable UK adequacy regulation, appropriate contractual safeguard or statutory exception applies. The mechanism depends on the recipient and destination. For an occasional disclosure to an overseas travel provider necessary to perform or conclude a contract in the traveller's interests, the applicable statutory exception may be used.

Contact our privacy contact for information about the mechanism used for a particular transfer, subject to protection of confidential terms.


11. How long we keep information

Retention depends on the purpose and any legal, accounting, safety, complaint or claim requirement.

Booking, contract, payment, tax, financial-failure-protection and claim records are normally kept for up to seven years after the relevant trip and final financial or claim activity. Passport, health, accessibility and dietary information is deleted or anonymised when it is no longer needed for the trip or a live incident, complaint or claim. Routine messages, tickets and uploads are kept while needed for trip delivery and any related contractual, accounting, safety or claim record.

Marketing contact data is kept until opt-out or it is no longer needed; a minimal suppression record may be retained. App access rights are revoked when entitlement ends. App identity records and push tokens are removed through the valid account-deletion process, subject to records that must be retained.

Restricted backup and recovery copies are access-controlled and normally age out within 12 months.

A legal hold, unresolved payment, safety incident, complaint, claim or regulatory investigation may require a relevant restricted record to be kept longer. When the reason ends, we return to the applicable retention approach.


12. Security and recovery

We use proportionate organisational and technical measures including access controls, logical separation of customer data, encryption in transit, restricted secrets, logging, backups, recovery testing and staff or supplier controls.

No internet or storage system is completely secure. If a personal-data breach occurs, we assess it and notify affected people and the Information Commissioner's Office where the law requires.

Deletion from a live system may not immediately remove an item from a restricted backup or recovery copy. Those copies remain access-controlled, are not used for ordinary business and age out under the retention periods above. Restored data is subject to the original deletion or restriction again.


13. Marketing and cookies

We may send marketing where you have consented or where another rule lawfully permits it. You can opt out at any time using the message link or by contacting us. Opting out of marketing does not stop service messages about an enquiry, booking, payment, safety matter or rights request.

We may use cookies or similar technology that is strictly necessary to provide, secure or remember choices on the website. We seek consent before using non-essential analytics, advertising or comparable technology where required. Withdrawing cookie consent does not make earlier use unlawful.


14. Your rights

Depending on the circumstances and applicable exemptions, you may have the right to:

  • obtain confirmation and a copy of your personal information;

  • correct inaccurate or incomplete information;

  • have information erased;

  • restrict how information is used;

  • object to processing based on legitimate interests or to direct marketing;

  • receive information you supplied in a portable format where the right applies;

  • withdraw consent at any time; and

  • obtain human intervention in relation to a qualifying solely automated decision. We do not currently make such booking decisions.

To exercise a right, contact our privacy contact. We may ask for proportionate information to verify identity or authority. A lead booker cannot exercise another adult's rights without evidence of authority.

These rights are not absolute. For example, we may retain information needed for tax, accounting, a legal obligation or a legal claim. We will explain a material refusal or restriction.


15. Data-protection complaints

Send a data-protection complaint to contact@scottishluxuryexperience.com with enough information for us to understand the concern.

We will acknowledge a data-protection complaint within 30 days. Without undue delay, we will make appropriate enquiries, keep you informed and communicate the outcome.

You may also complain to the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/ or by using the current contact details on the ICO website. We would welcome the opportunity to address the concern first, but you do not have to contact us before contacting the ICO.


16. Changes to this notice

We may issue a new version where our processing or the law changes. The version supplied for a booking remains part of that booking's evidence; a later website version does not rewrite the record of what was supplied.

Where a change materially affects an active booking or how we rely on consent, we will provide appropriate notice and obtain fresh consent where required.

bottom of page