Henri Leroux
Legal

Privacy Policy

v1.1 · Last updated:

1. Who we are and who controls your data

HENRI LEROUX LTD, a private limited company incorporated in England and Wales under company number 17319863, with its registered office at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom, operates the Henri Leroux brand and https://henrileroux.com.

HENRI LEROUX LTD is the controller responsible for the personal data described in this Privacy Policy. In this policy, “Henri Leroux”, “we”, “us” and “our” refer to HENRI LEROUX LTD.

Privacy enquiries may be sent to [email protected].

2. Scope

This notice applies when you visit our website, submit a form or enquiry, communicate with us, ask us to plan or coordinate travel, act as a business contact, or are a traveller whose information is provided for an arrangement. It covers our own planning and coordination activity and our necessary communications with suppliers. A third party’s own privacy notice applies when that party independently controls personal data.

3. Personal data we may collect

Depending on the request, we may process:

  • identity and contact data, including name, email address, telephone number and employer or organisation;
  • enquiry and communication records;
  • destinations, dates, itinerary, traveller numbers and service preferences;
  • information about companions or passengers;
  • supplier and business-contact information;
  • technical and security data generated when the website is used;
  • cookie consent and preference records;
  • invoice or transaction records where payment or invoicing becomes applicable; and
  • limited special category personal data where relevant to a requested arrangement;
  • anonymised, non-identifying technical and security data generated when the website is used.

We ask you not to provide information that is not needed for the request.

4. Data about other travellers

If you provide information about a companion, passenger or colleague, you should have an appropriate basis and authority to do so and, where appropriate, tell that person that their information will be shared with us. We use it only as needed to consider, plan or coordinate the relevant request and do not treat this expectation as removing our own data-protection responsibilities.

5. How we obtain data

We receive data directly from you; from an authorised representative, employer, host, family member or travel organiser; from a supplier involved in an arrangement; and automatically through website and security technologies. We do not purchase consumer data lists.

6. Purposes and lawful bases

PurposeData typically involvedLawful basis
Respond to enquiries and take steps requested before a contractIdentity, contact and request dataSteps at your request before entering a contract; legitimate interests where the enquirer is not the prospective contracting party
Provide agreed planning and coordination servicesIdentity, contact, itinerary, traveller and communication dataPerformance of a contract
Communicate with suppliers and share information necessary for an arrangementTraveller, itinerary and relevant request dataPerformance of a contract and, depending on the relationship, our legitimate interests in coordinating the requested service
Administer the business, maintain proportionate records, monitor service quality and establish or defend claimsContact, request, communication and service recordsLegitimate interests; legal obligation where applicable
Accounting, tax and other legal complianceContract, invoice and transaction records where applicableLegal obligation
Protect the website, prevent misuse and operate strictly necessary technologiesTechnical, security and consent recordsLegitimate interests and applicable storage-access rules
Use optional analytics technologiesTechnical and usage dataConsent where required
Send direct marketingContact details and marketing preferencesConsent or legitimate interests only where permitted by law
Understand aggregated website traffic and improve the siteAnonymised, non-identifying technical and usage dataLegitimate interest

Where we rely on legitimate interests, those interests include responding efficiently, operating and improving the business, maintaining security, keeping proportionate business records, preventing misuse and fraud, and establishing or defending legal claims. We consider the impact on individuals before relying on this basis.

7. Special category personal data

Health, accessibility, mobility, allergy or dietary information may constitute special category personal data. Please provide it only when relevant to a specific request. We minimise this information, use it only for the relevant arrangement, and seek explicit consent where that is the appropriate legal condition. Other conditions may apply where the law permits; we do not request such data without a practical need.

8. Recipients

We share personal data only where reasonably necessary with categories such as accommodation providers; transport and chauffeur providers; airlines, restaurants, venues and guides; technology, communications, hosting and support providers; professional advisers; and public authorities where required by law.

Some suppliers determine independently how they use data for their own service and act as independent controllers. Other service providers process data on our instructions. The role depends on the service and applicable arrangements; we do not describe every recipient as having the same legal role.

We do not sell personal data.

9. International transfers

International travel may require data to be sent outside the United Kingdom or European Economic Area so that a requested service can be considered or fulfilled. For processors and technology providers, applicable mechanisms may include UK adequacy regulations, EU adequacy decisions, contractual safeguards or a permitted derogation, as relevant. A transfer necessary for a requested international arrangement may also rely on the applicable legal provisions.

Specific safeguards depend on the recipient and destination. You may request further information at [email protected].

10. Retention

We retain data only for a period justified by its purpose and the applicable legal, accounting, operational and dispute requirements. In particular:

  • enquiries that do not lead to an engagement are reviewed when they are no longer active;
  • active request and client records are kept while the service is being considered or provided and for a proportionate period afterwards;
  • contractual, invoice and accounting records are kept for applicable statutory periods;
  • supplier communications are retained with the related request record where needed;
  • consent records are retained as evidence of the choice, while marketing suppression records may be kept to respect an opt-out;
  • technical and security records are retained according to the security need; and
  • material relevant to a claim may be retained until the dispute and relevant limitation periods have ended.

We periodically review whether records remain necessary. A formal retention schedule will be refined as the operating model develops.

11. Security

We use proportionate organisational and technical safeguards and restrict access according to operational need. No internet transmission or storage system can be guaranteed completely secure. Please do not send unnecessary sensitive information by ordinary email.

12. Marketing

We send marketing only where permitted by law and provide a way to unsubscribe or object. Service messages needed to answer or manage a request are not marketing. After an opt-out, we may retain a minimal suppression record so that the preference continues to be respected.

13. Cookies and similar technologies

The current production environment does not deploy an analytics or marketing provider. Optional cookie-based analytics or marketing technologies must not be enabled before the required choice is made.

14. Children

A request is normally initiated by an adult. We may process limited information about children travelling with a parent, guardian or authorised organiser when needed for an arrangement. We minimise that data and use it for the relevant request. Children should not submit requests independently without appropriate adult involvement.

15. Your rights

Depending on the circumstances and lawful basis, you may have rights to access your data; correct inaccurate data; request erasure; restrict processing; receive portable data; object to processing; and withdraw consent. Withdrawal does not affect processing already carried out lawfully.

Right to object: you may object to processing based on legitimate interests. You may object to direct marketing at any time.

Rights are not absolute, and we may need to verify identity or retain information where the law permits or requires it. Contact [email protected] to exercise a right.

16. Complaints

Please contact us first if you have a privacy concern. You may also complain to the UK Information Commissioner’s Office at https://ico.org.uk. If you are in the EEA, you may contact the competent supervisory authority in your country. We do not claim to have appointed an EU representative in this notice.

17. Automated decisions

We do not currently use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects.

18. External websites

Links to third-party websites are provided for convenience. Those organisations are responsible for their own privacy practices.

19. Changes to this notice

We may revise this notice when our services, technologies or legal obligations change. A new revision date will be shown. This policy is a transparency notice and does not rely on fictional acceptance through continued website use.

20. Contact details

HENRI LEROUX LTD, 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.

Company number: 17319863. Privacy: [email protected]. Website: https://henrileroux.com.