Privacy Policy

Consenting to collection of personal information when using our website

In accessing and using our website, you acknowledge that we (Heritage Expeditions (2018) Limited) may collect personal information and personal data (personal information) from you, and that such personal information is freely given, including information about your:

  1. Name (if supplied by you)
  2. Contact information including your email address and phone number (if supplied by you)
  3. IP address and location data
  4. Your activity on our website, including use of cookies
  5. Any other information you freely provide to us via our website enquiry form

We collect your personal information in order to:

  • add you to our e-newsletter subscription and market our services to you
  • communicate with you where you have made a website enquiry
  • to conduct research and statistical analysis
  • to improve your experience using our website

Consenting to collection of personal information when booking

In making a booking for a voyage with us, you further acknowledge that we may collect further personal information, and that such personal information is freely given to us on this basis, including:

  • Your passport information
  • Credit card and other payment information
  • Your medical history and information, including that which is collected onboard or during the voyage
  • Date of birth
  • Postal and email addresses
  • Contact numbers
  • Emergency contact details
  • Dietary requirements

We collect your personal information in order to:

  • ensure we are aware of your specific health and safety and medical requirements prior to a voyage departing
  • ensure our health and safety and first aid officers are aware of any medical requirements in the event of needing to administer or advise in a medical situation during a voyage
  • help create the best possible travel experience on your voyage

We may also share your personal information with third party companies and service providers we engage during voyages, as part of their operational requirements. For international voyages we may also be required to provide your details to the relevant governmental and customs authorities. In making a booking with us for a voyage, you consent to the disclosure of your personal information where required by third party companies and service providers.

Providing some personal information is optional. When making an enquiry online, if you choose not to provide your email address then we will be unable to respond to your enquiry. We do not require you to subscribe to our newsletter when you make an enquiry; however, if you do not consent to being added to our e-newsletter list you will not find out about our upcoming voyages and promotions.

If you request that we not provide your personal information to a third-party company and service provider, they may not be able to provide their services to you during a voyage. Please note that preventing us from providing certain personal information to us and/or third parties may prevent you from being able to participate in a voyage. If we identify that you have requested such essential information not be provided to us or third parties, we will contact you to explain the situation.

We may disclose your personal information to a third party where we are required to by law.

We are required to hold your personal information only as long as necessary. Because different types of personal data have different uses these periods may vary. At any time however you have the right to request that we remove your personal information from our system.

Principles of consent

  1. You can withdraw this consent at any time.
  2. Passengers under 18 may only give consent with permission from a parent
  3. We will keep documentary evidence of consent in the form of retaining booking confirmations and/or newsletter subscriptions as applicable

Principles of data retention and processing

We adhere to the following principles relating to processing of personal data:

  1. Personal data shall be:
    a) Processed lawfully, fairly, and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’)
    b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, not be considered incompatible with the initial purpose (‘purpose limitation’)
    c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’)
    d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data which are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’)
    e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organisational measures implemented in order to safeguard the rights and freedoms of the data subject (‘storage limitation’);
    f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).
  2. We shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (‘accountability’).

Protecting your personal information

We will take reasonable steps to protect your personal information from unauthorised use, including ensuring that computers and devices are protected or locked by appropriate passwords and/or two-factor authentication. Transport Layer Security (TLS) and at-rest encryption cloud-based storage systems may also be employed for the storage of your personal information.  Staff with access to your personal information are trained in technical and organisational security measures.

Third party service providers we use for reservations and other processes employ reasonable steps for protection of personal information from unauthorised use.

Breaches of personal information protection

The protection and security of your personal information is important to us, and physical administrative, and technological safeguards have been employed to preserve the integrity and security of all personal information collected. Notwithstanding this, no system is 100% impenetrable and we cannot guarantee the complete protection of your personal data in our system from data breaches. If we experience a serious privacy breach, including with respect to your information, we will notify you and the Office of the Privacy Commissioner within 72 hours of becoming aware of the breach. We will take steps to investigate the situation, including but not limited to engaging an external data security expert.

Your rights

You have the right to:

  • request that we provide you copies of your personal information, and to make corrections to any personal information you believe is inaccurate
  • request that we complete personal information you believe is incomplete
  • request that we erase your personal information
  • object to us processing your personal information
  • request that we transfer the personal information we have collected to another organisation, or directly to you

To exercise any of these rights please contact us at [email protected]

Other websites

Our website may contain links to other websites. Our privacy policy only applies to our website. If you visit any other such website, you should review their privacy policies.

This privacy policy has been developed to communicate to you the obligations that we have to you in relation to collecting, using, disclosing and protecting your personal information in accordance with the Privacy Act 2020 and its principles, and the European Union’s General Data Protection Rules.

This Privacy Policy was last updated on 1st July 2024.

Contact Us

Send Message
Call Us
Receive e-News
Request Brochure