Last updated: July 8, 2026
rovinbossb is committed to compliance with the General Data Protection Regulation (GDPR) and protecting the privacy rights of individuals in the European Economic Area and the United Kingdom.
We process personal data under the following legal bases:
Processing necessary to fulfill our contractual obligations when you book travel services through us.
Processing for our legitimate business interests, including:
Processing based on your explicit consent, such as receiving marketing communications. You may withdraw consent at any time.
Processing required to comply with legal obligations, including financial record-keeping and regulatory requirements.
Under GDPR, you have the following rights regarding your personal data:
You can request confirmation of whether we process your personal data and obtain a copy of that data.
You can request correction of inaccurate or incomplete personal information.
You can request deletion of your personal data in certain circumstances, such as when data is no longer necessary for the original purpose or when you withdraw consent.
You can request that we limit how we use your personal data in specific situations.
You can receive your personal data in a structured, commonly used format and transmit it to another controller.
You can object to processing based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month, though this period may be extended by two months for complex requests.
To protect your privacy, we may need to verify your identity before processing rights requests. This may involve requesting additional information to confirm you are the data subject.
For questions specifically related to data protection and GDPR compliance, you may contact our designated data protection contact at [email protected].
When we transfer personal data outside the European Economic Area or United Kingdom, we ensure appropriate safeguards are in place, such as:
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and relevant supervisory authorities within 72 hours of becoming aware of the breach, as required by GDPR.
We do not knowingly collect or process personal data from individuals under 16 years of age without parental consent. If you believe we have collected such data, please contact us immediately.
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority. In the United Kingdom, this is the Information Commissioner's Office (ICO).
ICO Contact:
Website: ico.org.uk
Telephone: 0303 123 1113
We regularly review our data protection practices to ensure ongoing GDPR compliance. Any significant changes will be reflected in this document and our Privacy Policy.
For GDPR-related enquiries, please contact:
Email: [email protected]
Address: Deansgate District, Manchester M3 2BQ, United Kingdom