opal-travel
About Programs Contact

GDPR Compliance

Last updated: May 25, 2026

opal-travel is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. This page explains how we comply with GDPR requirements and your rights under this regulation.

Data Controller

opal-travel is the data controller responsible for your personal information. Our contact details:

opal-travel
142 Princes Street
Edinburgh EH2 4BJ
United Kingdom
Email: [email protected]

Lawful Basis for Processing

We only process your personal data when we have a lawful basis to do so. The lawful bases we rely on include:

Consent

For marketing communications and certain optional data processing activities, we obtain your explicit consent. You can withdraw consent at any time by contacting us or using the unsubscribe link in our communications.

Contractual Necessity

We process your data to fulfill our contract with you when providing educational services. This includes enrollment processing, program delivery, and communication about your child's participation.

Legitimate Interests

We may process data based on our legitimate interests in operating and improving our services, provided these interests do not override your fundamental rights and freedoms.

Legal Obligation

We process certain data to comply with legal requirements, including financial record-keeping and safeguarding obligations.

Your Rights Under GDPR

You have the following rights regarding your personal data:

Right to Access

You can request confirmation of whether we process your personal data and obtain a copy of that data. We will provide this within one month of your request.

Right to Rectification

If your personal data is inaccurate or incomplete, you have the right to request correction or completion.

Right to Erasure (Right to be Forgotten)

In certain circumstances, you can request deletion of your personal data. This right applies when:

  • The data is no longer necessary for the purposes it was collected
  • You withdraw consent and there is no other legal basis for processing
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed
  • Erasure is required to comply with a legal obligation

Note: This right does not apply when we are legally required to retain data, such as financial records.

Right to Restriction of Processing

You can request that we limit how we use your data in certain situations, such as when you contest the accuracy of the data or object to processing.

Right to Data Portability

You can receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller. This applies to data you provided to us based on consent or contract.

Right to Object

You can object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we have compelling legitimate grounds that override your interests.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not currently engage in such automated decision-making.

Exercising Your Rights

To exercise any of your GDPR rights, please contact us:

  • Email: [email protected]
  • Post: 142 Princes Street, Edinburgh EH2 4BJ, United Kingdom

We will respond to your request within one month. If your request is complex or we receive multiple requests, we may extend this period by two months, and we will inform you of any extension.

Data Protection Measures

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encryption of sensitive data
  • Regular security assessments and penetration testing
  • Access controls limiting who can view personal data
  • Staff training on data protection and GDPR compliance
  • Secure data storage and backup procedures
  • Data minimization principles
  • Privacy by design and by default

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.

Data Protection Impact Assessments

We conduct Data Protection Impact Assessments (DPIAs) for processing activities that may pose high risks to your rights and freedoms. This ensures we identify and mitigate privacy risks before implementing new systems or processes.

Third-Party Processing

When we engage third parties to process personal data on our behalf, we ensure they:

  • Process data only according to our documented instructions
  • Maintain appropriate security measures
  • Assist us in responding to data subject requests
  • Delete or return data when the processing service ends
  • Make available information necessary to demonstrate compliance

International Data Transfers

We primarily store and process data within the United Kingdom and European Economic Area. If we transfer data internationally, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions by the European Commission
  • Binding Corporate Rules

Children's Data

Given the nature of our services, we process data relating to children. We:

  • Obtain parental consent before collecting data from children under 13
  • Collect only the minimum necessary information
  • Implement enhanced security measures for children's data
  • Provide parents with full transparency and control
  • Conduct regular reviews of data retention for children's information

Record Keeping

We maintain comprehensive records of our processing activities, including:

  • Purposes of processing
  • Categories of data subjects and personal data
  • Recipients of personal data
  • International data transfers
  • Retention periods
  • Security measures

Complaints and Supervisory Authority

If you believe we have not complied with GDPR requirements, you have the right to lodge a complaint with the supervisory authority:

Information Commissioner's Office (ICO)
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
United Kingdom
Telephone: 0303 123 1113
Website: opal-travel.com

We encourage you to contact us first so we can address your concerns directly.

Updates to This Information

We may update this GDPR information to reflect changes in our practices or legal requirements. We will notify you of significant changes through email or a prominent notice on our website.

Contact Our Data Protection Officer

For specific questions about data protection or to exercise your rights, contact our Data Protection Officer:

Email: [email protected]

opal-travel

Building financial confidence in the next generation

Quick Links

About Us Programs Contact

Legal

Privacy Policy GDPR Cookies Policy Terms of Use

© 2026 opal-travel. All rights reserved.