Privacy Policy

Effective Date: [August 12th, 2025]
Last Reviewed: June 2025

1. Introduction

Irish Rugby Tours (“we,” “our,” or “us”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, share, and safeguard your data in compliance with the GDPR and other applicable laws.

2. What Data We Collect

  • Personal details: name, date of birth, gender
  • Contact information: email, phone, postal address
  • Passport details, nationality, emergency contact information
  • Health or dietary details when required for travel and safety
  • Payment and transaction data (processed by secure third-party providers)
  • Enquiries and correspondence history

3. Legal Basis for Processing

We process your data based on:

  • Performance of a contract – to manage your booking and deliver tour services
  • Legitimate interests – to provide support and essential updates related to your enquiry or booking
  • Legal obligations – to meet tax, accounting, and regulatory requirements

4. How We Use Your Personal Data

  • Manage enquiries, bookings, itineraries, and on-tour operations
  • Process payments securely and handle refunds where applicable
  • Provide customer support and essential travel updates
  • Meet legal and regulatory requirements
  • Improve our services and website

5. Communications

We use your contact details for operational purposes only (e.g., booking confirmations, tour updates, support). We do not send marketing emails, so unsubscribe links are not applicable. If this changes in future, we will request your consent first.

6. Data Storage & Retention

Your data is stored securely on encrypted platforms, including WeTravel (bookings/payments), HubSpot (CRM), and Google Workspace (email/document storage). We retain data for:

  • Booking and payment records: 7 years
  • Passport and emergency contact information: deleted 12 months post-tour
  • General correspondence: up to 2 years post-tour

7. Third-Party Processors

We work with GDPR-compliant providers under Data Processing Agreements, including:

  • WeTravel – bookings and payments
  • HubSpot – customer relationship management
  • Google Workspace – email and file storage

8. International Data Transfers

When data is transferred outside the EEA, we rely on an EU adequacy decision or the EU Standard Contractual Clauses (SCCs) to protect your data.

9. Cookies & Tracking

We use necessary cookies for site functionality. Analytics and marketing cookies (if any) will only run with your consent via our cookie banner. You can change preferences at any time using the cookie settings link on our site. For details, see our Cookie Policy (coming soon).

10. Children’s Data

We do not knowingly collect personal data from children under 16 without verified parental or guardian consent. Group leaders are responsible for ensuring appropriate permissions are obtained for youth tours.

11. Your Rights

Under GDPR, you can:

  • Access, correct, or erase your personal data
  • Restrict or object to processing
  • Request data portability
  • Withdraw consent where processing relies on consent

To exercise your rights, contact info@irishrugbytours.com. We will respond within one month.

12. Data Breach Procedure

If a data breach occurs, we will assess the impact, notify the Irish Data Protection Commission within 72 hours when required, and inform affected individuals where there is a high risk to their rights and freedoms.

13. Contact

Data Protection Officer
Irish Rugby Tours
1 Main Street, 1st Floor, Carrigaline, Cork, Ireland
Email: info@irishrugbytours.com

You have the right to lodge a complaint with the Irish Data Protection Commission.

This policy is reviewed annually and updated as necessary.