Privacy Policy
This Privacy Policy applies between you, the User of this Website, and Limitless Travel, the owner and provider of this Website. Limitless Travel takes the privacy of your information very seriously. This Privacy Policy applies to our use of any and all Data collected by us or provided by you in relation to your use of the Website.
This Privacy Policy should be read alongside, and in addition to, our Terms and Conditions, which can be found at: https://www.limitlesstravel.org/terms-and-conditions.
Please read this Privacy Policy carefully.
Definitions and Interpretation
- In this Privacy Policy, the following definitions are used:
| Data |
collectively all information that you submit to Limitless Travel via the Website. This definition incorporates, where applicable, the definitions provided in the Data Protection Laws. |
| Cookies |
a small text file placed on your computer by this Website when you visit certain parts of the Website and/or when you use certain features of the Website. Details of the cookies used by this Website are set out below (see Cookies). |
| Data Protection Laws |
any applicable law relating to the processing of personal Data, including but not limited to the GDPR, and any national implementing and supplementary laws, regulations and secondary legislation. |
| GDPR |
the UK General Data Protection Regulation. |
|
Limitless Travel, we or us
|
Limitless Travel, a company incorporated in England and Wales with registered number 09735991 whose registered office is at 222 Custard Factory, Gibb Street, Birmingham, England, B9 4AA. |
| UK and EU Cookie Law |
the Privacy and Electronic Communications (EC Directive) Regulations 2003 as amended by the Privacy and Electronic Communications (EC Directive) (Amendment) Regulations 2011 & 2018. |
| User or you |
any third party that accesses the Website and is not either (i) employed by Limitless Travel and acting in the course of their employment or (ii) engaged as a consultant or otherwise providing services to Limitless Travel and accessing the Website in connection with the provision of such services. |
| Website |
the website that you are currently using, https://www.limitlesstravel.org, and any sub-domains of this site unless expressly excluded by their own terms and conditions. |
- In this Privacy Policy, unless the context requires a different interpretation:
- the singular includes the plural and vice versa;
- references to sub-clauses, clauses, schedules or appendices are to sub-clauses, clauses, schedules or appendices of this Privacy Policy;
- a reference to a person includes firms, companies, government entities, trusts and partnerships;
- "including" is understood to mean "including without limitation";
- reference to any statutory provision includes any modification or amendment of it;
- the headings and sub-headings do not form part of this Privacy Policy.
Scope of this Privacy Policy
- This Privacy Policy applies only to the actions of Limitless Travel and Users with respect to this Website. It does not extend to any websites that can be accessed from this Website including, but not limited to, any links we may provide to social media websites.
- For purposes of the applicable Data Protection Laws, Limitless Travel is the "data controller". This means that Limitless Travel determines the purposes for which, and the manner in which, your Data is processed.
We are registered with the Information Commissioner’s Office under registration reference ZA261195. We have appointed a Data Protection Officer, who can be contacted at dpo@limitlesstravel.org. .
Data Collected
- We may collect the following Data, which includes personal Data, from you:
- name;
- date of birth;
- gender;
- job title;
- contact Information such as email addresses and telephone numbers;
- physical address;
- emergency contact Information;
- GPs details;
- medical and disability Information.
Where we provide care and support, records are also created during the course of that service. These include your care plan and risk assessment, the daily care records written by the Service Providers supporting you, records of any incident, accident or safeguarding concern, records of the equipment ordered and delivered for you, and notes of your care calls and pre departure conversations.
in each case, in accordance with this Privacy Policy.
How We Collect Data
- We collect Data in the following ways:
- data is given to us by you; and
- data is collected automatically.
Data That is Given to Us by You
- Limitless Travel will collect your Data in a number of ways, for example:
- when you contact us through the Website, by telephone, post, e-mail or through any other means;
- when you register with us and set up an account to receive our products/services;
- when you complete surveys that we use for research purposes (although you are not obliged to respond to them);
- when you enter a competition or promotion through a social media channel;
- when you make payments to us, through this Website or otherwise;
- when you elect to receive marketing communications from us;
- when you use our services.
in each case, in accordance with this Privacy Policy.
Data That is Collected Automatically
- To the extent that you access the Website, we will collect your Data automatically, for example:
- we automatically collect some information about your visit to the Website. This information helps us to make improvements to Website content and navigation, and includes your IP address, the date, times and frequency with which you access the Website and the way you use and interact with its content.
- we will collect your Data automatically via cookies, in line with the cookie settings on your browser. For more information about cookies, and how we use them on the Website, see the section below, headed "Cookies".
Special Category Data
Health, medical, disability and mobility information is special category personal data under the GDPR. We collect it because we cannot assess, plan or deliver your care safely without it.
Where we process special category data we rely on Article 9(2)(h) of the GDPR, the provision of health or social care, together with the condition at paragraph 2 of Part 1 of Schedule 1 to the Data Protection Act 2018. Where we process it in connection with safeguarding an adult at risk, we rely on Article 9(2)(b) and the safeguarding condition in Part 2 of Schedule 1. Where we process it to respond to a medical emergency and you are unable to give consent at the time, we rely on Article 9(2)(c), protection of vital interests.
We maintain an appropriate policy document setting out how we comply with these conditions. A copy is available on request.
We do not use your health, disability or care information for marketing.
Our Use of Data
- Any or all of the above Data may be required by us from time to time in order to provide you with the best possible service and experience when using our Website. Specifically, Data may be used by us for the following reasons:
- internal record keeping;
- improvement of our products / services;
- assessing your care and support needs and agreeing the appropriate care package;
- preparing your care plan and risk assessment;
- briefing the Service Providers who will be supporting you;
- arranging your mobility and care equipment;
- delivering your care and keeping a record of the care delivered;
- responding to incidents, accidents and medical emergencies;
- meeting our safeguarding obligations in relation to adults at risk;
- investigating and responding to complaints;
- reviewing and improving the quality and safety of the care we deliver;
- meeting our regulatory, insurance and legal obligations;
- transmission by email of marketing materials that may be of interest to you;
in each case, in accordance with this Privacy Policy.
- We may use your Data for the above purposes if we deem it necessary to do so for our legitimate interests. If you are not satisfied with this, you have the right to object in certain circumstances (see the section headed "Your rights" below).
Where we use your Data to assess, plan, deliver or review your care, our lawful basis is the performance of our contract with you, or compliance with a legal obligation. Where that Data includes health or disability information, we also rely on the conditions set out in the Special Category Data section above.
- For the delivery of direct marketing to you via e-mail, we'll need your consent, whether via an opt-in or soft-opt-in:
- soft opt-in consent is a specific type of consent which applies when you have previously engaged with us. Under "soft opt-in" consent, we will take your consent as given unless you opt out.
- for other types of e-marketing, we are required to obtain your explicit consent.
- if you are not satisfied with our approach to marketing, you have the right to withdraw consent at any time (see the section headed "Your rights" below).
- When you register with us and set up an account to receive our services, the legal basis for this processing is the performance of a contract between you and us and/or taking steps, at your request, to enter into such a contract.
How We Use Technology, Including Artificial Intelligence
We use software to help us organise and make sense of the information we already hold about you. Some of that software uses artificial intelligence.
What it does. These tools bring together information that already exists across our systems, for example your care records, your equipment order and your feedback, and produce a summary for our team to read before they speak with you or before your holiday departs. The purpose is to make sure the person supporting you already knows what matters, rather than asking you to explain it again.
What it does not do. These tools do not make decisions about your care. They do not decide your care package, and they do not assess your needs.
Your rights. You have the right under Article 22 of the GDPR not to be subject to a decision based solely on automated processing which produces a legal or similarly significant effect on you. We do not make decisions in that way. If you would prefer that these tools are not used to prepare summaries about you, please contact us and we will discuss how we can accommodate that.
Our safeguards. We assess the data protection risks before introducing technology of this kind. Our agreements with technology suppliers prevent them from using your information for their own purposes, including to train their systems.
Who We Share Data With
- We may share your Data with the following groups of people for the following reasons:
- third party service providers who provide services to us which require the processing of personal data – to help third party services, such as transport and accommodation providers where appropriate. Only required information for these services will be shared;
- third party payment providers who process payments made over the Website – to enable third party payment providers to process invoices, payments and refunds on our behalf.
- the self employed Service Providers who deliver your care, so that they have the care plan, risk assessment and support needs of the guests they are supporting and can deliver care safely;
- equipment suppliers, so that the equipment you need reaches the right place at the right time;
- cruise operators, where we are required to provide accessibility and mobility information on mandatory forms such as on board needs forms;
- health and emergency services, where this is necessary to obtain urgent medical assistance for you;
- safeguarding authorities and regulators, where we are required to share information because of a concern about the safety of an adult at risk, or where a regulator lawfully requires it;
- our technology and software suppliers, who hold information in the systems they provide to us, act on our written instructions, and may not use your information for their own purposes;
- our insurers and professional advisers, where necessary in connection with a claim, a complaint or legal advice;
in each case, in accordance with this Privacy Policy.
Keeping Data Secure
- We will use technical and organisational measures to safeguard your Data, for example:
- access to your account is controlled by a password and a user name that is unique to you.
- we store your Data on secure servers.
- Technical and organisational measures include measures to deal with any suspected data breach. If you suspect any misuse or loss or unauthorised access to your Data, please let us know immediately by contacting us via this e-mail address: admin (at) limitlesstravel.org.
- If you want detailed information on how to protect your information, computers, and devices against fraud, identity theft, viruses, and many other online problems, please visit www.getsafeonline.org.
Data Retention
- Unless a longer retention period is required or permitted by law, we will only hold your Data on our systems for the period necessary to fulfil the purposes outlined in this Privacy Policy or until you request that the Data be deleted.
- Even if we delete your Data, it may persist on backup or archival media for legal, tax or regulatory purposes.
Our current retention periods are:
Care records, care plans and risk assessments:10 years
Incident, accident and safeguarding records: 10 years
Booking and travel records: 10 years
Financial and payment records: 6 years, to meet HMRC requirements
Complaint and investigation records: 10 years
Marketing preferences: until you ask us to stop
Your Rights
- You have the following rights in relation to your Data:
- Right to access – the right to request copies of the information we hold about you, or that we modify, update or delete such information.
- Right to correct – the right to have your Data rectified if it is inaccurate or incomplete.
- Right to erase – the right to request that we delete or remove your Data from our systems.
- Right to restrict our use of your Data – the right to "block" us from using your Data or limit the way in which we can use it.
- Right to data portability – the right to request that we move, copy or transfer your Data.
- Right to object – the right to object to our use of your Data including where we use it for our legitimate interests.
- To make enquiries, exercise any of your rights set out above, or withdraw your consent (where consent is our legal basis for processing), please contact our Data Protection Officer at dpo (at) limitlesstravel.org, or admin (at) limitlesstravel.org.
- If you are not satisfied with the way a complaint in relation to your Data is handled, you may be able to refer your complaint to the ICO. See https://ico.org.uk/.
- It is important that the Data we hold about you is accurate and current. Please keep us informed if your Data changes during the period for which we hold it.
Transfers Outside the United Kingdom and European Economic Area
- Data which we collect from you may be stored and processed in and transferred to countries outside of the UK and EEA. This could occur if our servers or service providers are located in a country outside the UK or EEA.
- We will only transfer Data outside the UK or EEA where it is compliant with data protection legislation and the means of transfer provides adequate safeguards.
- To ensure that your Data receives an adequate level of protection, we have put in place appropriate safeguards and procedures with the third parties we share your Data with.
Links to Other Websites
- This Website may, from time to time, provide links to other websites. We have no control over such websites and are not responsible for the content of these websites. This Privacy Policy does not extend to your use of such websites.
Changes of Business Ownership and Control
- Limitless Travel may, from time to time, expand or reduce our business. This may involve the sale and/or the transfer of control of all or part of Limitless Travel. Data provided by Users will, where it is relevant, be transferred along with that part and the new owner or newly controlling party will be permitted to use the Data for the purposes for which it was originally supplied to us.
- We may also disclose Data to a prospective purchaser of our business or any part of it.
- In the above instances, we will take steps with the aim of ensuring your privacy is protected.
Cookies
- This Website may place and access certain Cookies on your computer. Limitless Travel uses Cookies to improve your experience of using the Website and to improve our range of products and services. We have taken steps to ensure that your privacy is protected and respected at all times.
- All Cookies used by this Website are used in accordance with current UK and EU Cookie Law.
- Before the Website places Cookies on your computer, you will be presented with a message bar requesting your consent to set those Cookies. By giving your consent, you enable Limitless Travel to provide a better experience and service to you. You may deny consent; however, certain features of the Website may not function fully.
- This Website may place the following Cookies:
| Type of Cookie |
Purpose |
| Strictly necessary cookies |
Required for the operation of our website. They enable you to log into secure areas of our website, use a shopping cart or use e-billing services. |
| Analytical/performance cookies |
They allow us to recognise and count the number of visitors and to see how visitors move around our website. This helps us improve the way our website works. |
| Functionality cookies |
Used to recognise you when you return to our website. This enables us to personalise our content for you. |
- You can find a list of Cookies that we use within your internet browser settings.
- You can choose to enable or disable Cookies in your internet browser. By default, most browsers accept Cookies. You can switch off Cookies at any time, but you may lose information that enables you to access the Website more quickly and efficiently.
- It is recommended that you ensure your browser is up-to-date and consult the help provided by the developer if you are unsure about adjusting your privacy settings.
- For more information generally on cookies, including how to disable them, please refer to aboutcookies.org.
General
- You may not transfer any of your rights under this Privacy Policy to any other person. We may transfer our rights under this Privacy Policy where we reasonably believe your rights will not be affected.
- If any court or authority finds that any provision of this Privacy Policy is invalid, illegal or unenforceable, that provision will be deemed to be deleted, and the validity and enforceability of the other provisions will not be affected.
- No delay, act or omission by a party in exercising any right or remedy will be deemed a waiver of any other right or remedy.
- This Agreement will be governed by and interpreted according to the law of England and Wales. All disputes arising under the Agreement will be subject to the exclusive jurisdiction of the English and Welsh courts.
Changes to This Privacy Policy
- Limitless Travel reserves the right to change this Privacy Policy as we may deem necessary from time to time or as may be required by law. Any changes will be posted on the Website and you are deemed to have accepted the terms of the Privacy Policy on your first use of the Website following the alterations. You may contact Limitless Travel by email at admin (at) limitlesstravel.org.
This Privacy Policy was updated on 09 January 2025.