PRIVACY POLICY



Flying Carpet Amsterdam
Last Updated: March 4, 2026

1. Data Controller

Flying Carpet Amsterdam (“Company”, “we”, “us”) acts as the Data Controller within the meaning of Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR).

Business Address: [Insert Address]
Email: [Insert Email]
KvK: [Insert Number]
VAT: [Insert Number]


2. Legal Basis for Processing

We process personal data strictly in accordance with:

  • Regulation (EU) 2016/679 (GDPR)

  • Dutch GDPR Implementation Act (UAVG)

  • Applicable Dutch tax and commercial legislation

Processing is based on:

  • Performance of a contract (tour booking)

  • Legal obligation (tax/accounting retention)

  • Legitimate interest (service improvement, fraud prevention)

  • Explicit consent (marketing communications)


3. Categories of Personal Data

We may process:

  • Full name

  • Contact details (email, phone)

  • Billing address

  • Booking details

  • IP address & device information

  • Payment transaction reference

We do not store complete credit card details. Payments are processed via certified PCI-DSS compliant providers.


4. Purpose of Processing

Data is processed exclusively to:

  • Manage bookings and contracts

  • Process secure payments

  • Provide private tour and transport services

  • Comply with tax obligations (7-year retention under Dutch law)

  • Prevent fraud and misuse


5. Data Retention

  • Invoice and financial records: 7 years (Dutch tax law)

  • Booking records: up to 5 years

  • Marketing data: until consent is withdrawn


6. International Transfers

If data is transferred outside the European Economic Area (EEA), such transfers shall occur only under:

  • Adequacy decisions, or

  • Standard Contractual Clauses approved by the European Commission


7. Data Subject Rights

Under GDPR, you have the right to:

  • Access

  • Rectification

  • Erasure

  • Restriction of processing

  • Data portability

  • Objection

  • Withdraw consent

You may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).


8. Security Measures

We implement appropriate technical and organizational safeguards including:

 

  • SSL encryption

  • Secure hosting within the EU

  • Access limitation

  • Payment provider encryption

 


Quick Support
Questions about tour durations or custom pricing? Chat with us!