Privacy Policy
Liminal Journeys Limited (Hong Kong) · Trading as "Liminal" · Effective [date] · Version v4 DRAFT
1. About this Privacy Policy
1.1 This privacy policy (“Privacy Policy”) explains how Liminal Journeys Limited ("Liminal", "we", "us") handles personal data. It applies whenever you visit our website, enquire about our services, become a client, travel with us, or otherwise interact with us, and should be read alongside our Terms and Conditions and the booking conditions of each Supplier. Unless otherwise defined in this Privacy Policy, capitalised terms have the meanings given to them in our Terms and Conditions.
1.2 We are the data user/controller of personal data we hold about you. Our contact details are at the end of this Notice. We have appointed:
- an EU representative under Article 27 of the EU GDPR — [appointed representative], to be confirmed
- a UK representative under Article 27 of the UK GDPR — [appointed representative], to be confirmed
1.3 We comply with the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO") and, where applicable to processing of personal data of individuals in the EU and the UK, with the EU GDPR and the UK GDPR.
1.4 Liminal’s travel services are not offered to persons ordinarily resident in the Hong Kong Special Administrative Region. As part of our intake we will ask you to confirm your country of ordinary residence, and we process that confirmation to verify eligibility for our services and to comply with Hong Kong regulatory boundaries.
2. The personal data we collect
We collect and process the following categories of personal data, in different combinations depending on your relationship with us:
- Identity data: full legal name as on travel documents, preferred name, date of birth, gender, nationality, photograph for identification.
- Contact data: email address, phone numbers, postal address, social-handle on platforms used for client communication.
- Residency-confirmation data: country of ordinary residence (collected to evidence eligibility under clause 1.4 above), supporting information where you indicate dual or recent residence in Hong Kong.
- Travel-document data: passport number and expiry, visa status, residency status, frequent-flyer numbers, traveller-rewards numbers.
- Sensitive data (collected with your express consent only, where consent is the lawful basis): health information relevant to your trip (including but not limited to allergies, mobility, medical conditions, dietary needs, prescriptions, mental-health needs that affect travel), religious or philosophical preferences (where they affect food, accommodation or itinerary), accessibility needs, and emergency-contact information for next-of-kin.
- Financial data: payment-card data is not stored by us — it is processed directly by our payment processor; bank-account details only as needed for refunds. Where you settle a Liminal invoice for a Transactional-model component, we additionally process the payment-confirmation data and any AML/KYC documents required under our Terms (clause 13.2).
- Travel-preference data: prior trip history, named partner relationships, profile preferences (room type, pillow preference, etc.).
- Companion data: data about people travelling with you, including children, only insofar as you provide it to us. You must ensure that you have informed the relevant individual and obtained any consent required by applicable law before providing their personal data to us.
- Website and analytics data: IP address, device and browser information, pages visited, click-stream, cookie identifiers — subject to our Cookie Notice.
3. Why we collect it and the lawful basis
We process your personal data for the following purposes and on the following lawful bases:
- To respond to enquiries and provide quotes: legitimate interests (operating our business; pre-contractual steps).
- To verify that you fall within the eligible client base under clause 1.4 (i.e. that you are not ordinarily resident in Hong Kong and that your itinerary does not include Hong Kong): legal obligation; legitimate interests (regulatory compliance with the Travel Industry Ordinance).
- To enter into and perform an engagement letter (SOW) and the Terms: performance of contract.
- To make bookings with Suppliers on your behalf, including under the Transactional model where Liminal contracts with the Supplier on your behalf and issues you an invoice: performance of contract; legitimate interests.
- To process payments and refunds: performance of contract; legal obligation (tax, accounting, AML).
- To process sensitive data (health, dietary, accessibility, religious/philosophical preferences) for itinerary design and Supplier instructions with your express consent where required under applicable law, including Article 9 GDPR, and otherwise in accordance with the PDPO..
- To send you administrative communications during a trip: performance of contract.
- To send you marketing material: explicit opt-in consent. You can withdraw consent at any time.
- To meet our legal obligations (tax, regulatory, anti-money-laundering, sanctions screening, fraud prevention): legal obligation.
- To protect our rights, property and the safety of our travellers and team: legitimate interests.
4. Who we share it with
We share personal data with the following categories of recipient, only to the extent strictly necessary for the purpose of the engagement:
- Suppliers — including but not limited to destination management companies, hotels and lodges, airlines, charter operators, transfer providers, restaurants, guides, photographers, videographers, equipment hire, expert co-hosts, wellness practitioners, host travel agencies or any other suppliers that may be engaged to provide services to you.
- Our chosen host travel agency for ticketing.
- Insurers and emergency-medical providers.
- Payment processors (Stripe Hong Kong) and banks.
- IT processors — CRM, email, file storage, hosting, marketing automation, analytics — under data-processing agreements.
- Professional advisors — legal, accounting, audit — bound by professional confidentiality.
- Regulators or courts where we are required by law to share data.
5. International transfers
5.1 Liminal is based in Hong Kong; many of our Suppliers and processors are based elsewhere. The processing of your personal data therefore involves transfers across borders.
5.2 Where personal data of EU- or UK-based individuals is transferred to Hong Kong or onward to third countries, we rely on the appropriate safeguards permitted under the relevant law: the European Commission Standard Contractual Clauses (2021 set), the UK International Data Transfer Addendum, and where required transfer-impact assessments. For Hong Kong PDPO purposes, we adopt the Office of the Privacy Commissioner for Personal Data’s 2022 Recommended Model Contractual Clauses and other appropriate contractual safeguards where considered appropriate.
5.3 We take reasonable steps to ensure that the destination Supplier’s data-handling is consistent with the level of protection that applies in the country of origin, including via contractual safeguards and Supplier due-diligence.
6. How long we keep it
- Enquiry and prospect data: 24 months from last contact unless you ask us to delete sooner.
- Residency-confirmation data: for the duration of the engagement and 7 years thereafter (audit-trail of eligibility decision).
- Client engagement records (SOW, itineraries, correspondence, invoices issued by Liminal): 7 years from end of engagement (Hong Kong tax, AML and dispute-limitation requirements).
- Sensitive data (health, dietary, accessibility): only for the duration of the relevant trip; deleted within 12 months of trip completion unless you ask us to retain it for future trips.
- Marketing-consent records: for as long as required to demonstrate compliance with applicable marketing laws and maintain our marketing preferences records..
- Financial records: 7 years.
We may retain personal data for longer where required or permitted by law, regulatory requirements, insurance requirements, professional obligations, or for the establishment, exercise or defence of legal claims.
7. Your rights
Subject to local law you have the following rights in respect of your personal data — to:
- Access the data we hold about you and obtain a copy.
- Have inaccurate or incomplete data corrected.
- Have your data deleted in certain circumstances.
- Restrict our processing in certain circumstances.
- Object to our processing on grounds of legitimate interests, including profiling.
- Withdraw consent (where consent is the lawful basis), without affecting the lawfulness of past processing.
- Receive your data in a structured, commonly used, machine-readable format and transmit it to another data user/controller, where the lawful basis is consent or contract and processing is automated (data portability).
- Make a complaint to the Hong Kong Office of the Privacy Commissioner for Personal Data (PCPD), the UK Information Commissioner’s Office (ICO), or the data-protection authority of your country of habitual residence in the EU.
To exercise any of these rights, data access requests and data correction requests under the PDPO contact us at privacy@liminal-journeys.co. We may need to verify your identity before responding.
8. Marketing
We will only send you marketing communications if you have given us express opt-in consent. You can withdraw consent at any time by clicking the unsubscribe link in any marketing email or by writing to us. We do not sell your personal data to third parties for their own marketing.
9. Children
Our services are directed at adults. We do not knowingly collect data about children under the age of 18 without verifiable parental consent. Where children travel with adult clients, we collect only the data necessary for the trip (names, ages, travel-document details, allergies, dietary needs) and we process it under the parent or guardian’s consent.
10. Security
We use technical and organisational measures appropriate to the data we hold: TLS in transit, encryption at rest where applicable, access controls based on role, mandatory two-factor authentication for staff, vendor due-diligence on processors, periodic backup verification, and a written incident-response procedure. Where a personal-data breach is likely to result in a risk to you, we will notify you and the relevant supervisory authority in accordance with applicable law.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will publish the updated version on our website with a revised effective date. For material changes, we will notify clients with whom we have an active engagement.
12. Contact us
For privacy enquiries, complaints or to exercise any of your rights, please contact us at privacy@liminal-journeys.co or in writing to: Liminal Journeys Limited, Unit 1603, 16/F, The L. Plaza, 367-375 Queen’s Road Central, Sheung Wan, Hong Kong.
EU representative under GDPR Article 27: [to be appointed]. UK representative under UK GDPR Article 27: [to be appointed].