togo-framework domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/digineib/bushescapessafaris.com/wp-includes/functions.php on line 6260Bush Escapes Safaris (“Bush Escapes Safaris”, “we”, “us” or “our”) respects your privacy and is committed to handling personal data lawfully, fairly, securely and transparently.
This Privacy Policy explains how we collect, use, store, share and protect personal data when you:
request a safari quotation or customised itinerary;
create an account, make a booking or pay for a service;
travel on a safari or use a service arranged by us;
contact us by email, telephone, WhatsApp, social media or another channel;
subscribe to our communications; or
otherwise interact with Bush Escapes Safaris.
This Policy is intended to reflect the Kenya Data Protection Act, 2019, the Data Protection (General) Regulations, 2021 and other applicable privacy laws. Where another law gives you additional rights, we will respect those rights to the extent that law applies.
Bush Escapes Safaris is the data controller for personal data that we determine how and why to process. Certain hotels, airlines, transport operators, activity providers, payment providers and other travel suppliers may act as separate data controllers for information they receive in order to provide their services.
Questions or requests concerning personal data may be submitted using the contact details at the end of this Policy.
The personal data we collect depends on how you interact with us and the services you request. It may include:
full name, title, nationality, gender and date of birth;
postal address, country of residence, email address and telephone number;
passport details, national identification information, visa information and travel documents; and
details of a parent, guardian, emergency contact or travelling companion.
travel dates, destinations, itinerary, accommodation and room preferences;
flight, transfer, vehicle and activity information;
loyalty programme details where relevant;
group, family and companion information;
special occasions and experience preferences; and
communications relating to a quotation, booking, amendment, complaint or request.
Where necessary to arrange a safe and suitable trip, we may collect information concerning:
allergies and dietary requirements;
disability, mobility and accessibility needs;
medical conditions, medication, pregnancy or fitness to participate;
vaccination or health-documentation requirements; and
emergency medical assistance.
We will collect and share this information only where there is a lawful basis, including your explicit consent where required, the protection of vital interests, or the establishment, exercise or defence of a legal claim.
We may collect billing details, payment status, transaction references, currency, amount paid and refund information. Card or banking information may be processed directly by authorised banks or payment-service providers. We do not intentionally retain complete payment-card details where the transaction is handled by a third-party payment provider.
When you use our website, we may collect:
internet protocol address;
browser and device type;
operating system and language settings;
pages visited, links selected and approximate visit times;
referring website and general location derived from an IP address;
account and login activity; and
cookie, analytics and similar technology identifiers.
We may receive photographs, videos, testimonials, reviews or other content that you choose to provide. We will seek separate permission before using an identifiable traveller’s image or testimonial for public marketing where consent is required.
We may collect personal data:
directly from you through the website, a booking form, email, telephone, WhatsApp, social media or in-person communication;
from the lead traveller or another person arranging travel on your behalf;
from travel agents, corporate travel coordinators or group organisers;
from hotels, airlines, guides, transport providers, payment providers and other suppliers involved in your trip;
automatically through cookies, server logs and similar technology; or
from lawful public or regulatory sources where necessary.
If you provide another person’s information, you should have authority to do so and should make this Policy available to that person.
We may process personal data to:
respond to an enquiry and prepare a quotation or personalised itinerary;
create, confirm, manage, amend or cancel a booking;
arrange accommodation, transport, flights, guides, park access, activities and other services;
process payments, deposits, refunds and financial records;
provide customer service and communicate important travel information;
accommodate dietary, medical, accessibility or other special requirements;
provide emergency support and protect the health and safety of travellers;
comply with immigration, park, aviation, tax, accounting, insurance, public-health and other legal requirements;
prevent fraud, misuse, cyber incidents and other security threats;
maintain and improve our website, services and customer experience;
manage complaints, legal claims and supplier disputes;
send marketing communications where you have consented or where otherwise permitted by law; and
create aggregated or anonymised business insights that do not identify an individual.
Depending on the circumstances, we rely on one or more of the following lawful bases:
Contract: processing is necessary to provide a quotation, make a booking or perform our agreement with you.
Consent: you have freely agreed to a specific use, such as certain marketing, sensitive travel information, or public use of an image or testimonial.
Legal obligation: processing is required to meet a legal, regulatory, tax, accounting, immigration or safety obligation.
Legitimate interests: processing is reasonably necessary to operate and improve our business, protect our systems, communicate with customers, prevent fraud or resolve disputes, provided those interests are not overridden by your rights.
Vital interests: processing is necessary to protect the life or safety of a traveller or another person, particularly in an emergency.
Legal claims: processing is necessary for the establishment, exercise or defence of a legal claim.
Where we rely on consent, you may withdraw it at any time. Withdrawal will not make earlier lawful processing invalid and may affect our ability to provide a service that requires the relevant information.
We may share only the information reasonably necessary with:
hotels, lodges, camps and other accommodation providers;
airlines, charter operators, transfer companies and vehicle operators;
professional guides, tour leaders and activity providers;
park, reserve, conservation and government authorities;
immigration, visa, border-control and public-health authorities where required;
banks, card processors and other payment providers;
insurers, medical providers and emergency-assistance companies;
travel agents, corporate travel coordinators and group organisers involved in your booking;
website hosting, email, customer-management, cloud-storage, analytics, communications and cybersecurity providers;
accountants, auditors, lawyers and professional advisers;
law-enforcement, courts, regulators or other authorities where disclosure is required or legally permitted; and
a successor or prospective purchaser in connection with a legitimate business reorganisation, subject to appropriate confidentiality and legal safeguards.
We do not sell personal data. We require service providers acting on our instructions to use personal data only for authorised purposes and to apply appropriate confidentiality and security measures.
Safari arrangements often require personal data to be shared with suppliers and authorities in the countries included in an itinerary. These countries may have privacy laws that differ from those in Kenya or your country of residence.
Where personal data is transferred outside Kenya, we will use a lawful transfer mechanism and reasonable safeguards required by applicable law. Depending on the transfer, this may include your informed consent, contractual safeguards, a transfer necessary to perform your travel contract, or another legally recognised basis.
We may process a child’s personal data when a parent, legal guardian or authorised adult makes or manages a family booking. This may include age, passport information, dietary needs, health requirements and travel-consent documents.
The responsible adult must have authority to provide the information and consent to processing where consent is required. We will use a child’s information only as reasonably necessary to plan and deliver the trip, protect the child’s interests, comply with law or handle an emergency. We do not knowingly use children’s personal data for behavioural advertising.
Our website may use cookies and similar technology to:
enable essential website, security, account and booking functions;
remember language, currency and other preferences;
understand website traffic and performance;
improve content and navigation; and
measure or personalise marketing where permitted.
Where required, non-essential cookies will be used only after you have made a choice through the cookie banner or settings tool. You can also restrict cookies through your browser, although disabling essential or functional cookies may affect parts of the website.
Third-party services embedded in the website may set their own cookies and process information under their respective privacy policies.
We may send safari news, offers, destination inspiration or other marketing where you have consented or where applicable law otherwise permits it. You can unsubscribe using the link in a marketing email or by contacting us.
Opting out of marketing will not prevent us from sending operational messages about an enquiry, quotation, booking, payment, itinerary, safety matter or legal obligation.
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected and to meet legal, accounting, tax, regulatory, safety and dispute-resolution requirements.
Retention periods may depend on:
whether an enquiry resulted in a booking;
the length of our relationship with you;
supplier and payment-record requirements;
applicable limitation periods and legal obligations;
the sensitivity of the information; and
whether a complaint, dispute, investigation or legal claim is ongoing.
Sensitive travel information that is no longer required will be securely deleted, restricted or anonymised, subject to any continuing legal or safety requirement. Marketing information may be retained until you unsubscribe, withdraw consent or the information is no longer needed for the stated purpose.
We use reasonable administrative, technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss, misuse or destruction. Measures may include controlled access, staff confidentiality, secure systems, authentication, backups, supplier due diligence and incident-response procedures.
No website, email service or electronic transmission is completely secure. Travellers should use secure devices and networks, keep account credentials confidential and verify unexpected payment or information requests using our published contact details.
If a personal data breach occurs, we will investigate it, take reasonable steps to contain and remedy it, and notify affected individuals and the Office of the Data Protection Commissioner where notification is required by law.
Subject to applicable law and any lawful exception, you may have the right to:
be informed about how your personal data is processed;
request access to personal data we hold about you;
request correction of inaccurate or incomplete personal data;
request deletion of personal data that we no longer have a lawful reason to retain;
object to certain processing, including direct marketing;
request restriction of processing;
receive eligible personal data in a portable format;
withdraw consent where processing is based on consent; and
complain to a competent data-protection authority.
To protect your information, we may ask for reasonable proof of identity before responding to a request. We will respond within the period required by applicable law. Some rights may be limited where information must be retained to perform a contract, protect another person, meet a legal obligation or handle a legal claim.
Please contact us first if you have a concern about how we handle personal data so that we can investigate and respond.
You may also complain to Kenya’s Office of the Data Protection Commissioner (ODPC) through its official website at https://www.odpc.go.ke/ or to another competent authority where applicable.
Our website may link to airlines, hotels, payment providers, social-media platforms or other third-party websites. Their privacy practices are controlled by them, not by Bush Escapes Safaris. You should review the privacy notice of a third party before providing personal data directly to it.
We may update this Policy to reflect changes in our services, technology, suppliers or legal obligations. The current version will be published on our website with its effective date. Where a change materially affects how we use personal data, we will provide additional notice where reasonably practicable or legally required.
For questions, requests or complaints concerning this Privacy Policy or your personal data, contact:
Bush Escapes Safaris
Website: https://bushescapessafaris.com/
Email: bookings@bushescapessafaris.com
Telephone: +254 701 770 000