Privacy And Data Protection Policy

Version: 2.1 (January 2026)

Company: Savvy Holiday Maker

Compliance: UK Data Use and Access Act (DUAA) 2025/26 & UK GDPR

1. INTRODUCTION AND SCOPE

This Privacy Policy sets out the framework under which Savvy Holiday Maker ('we', 'us', or 'our') collects, manages, and protects the personal data of visitors to www.savvyholidaymaker.com. As a travel directory, we facilitate the connection between users and holiday providers. This policy explains our commitment to transparency, particularly regarding our "Where Am I Going For My Next Holiday?" search features and directory ranking systems.

2. THE DATA WE COLLECT

We categorise the data we collect into three distinct groups:

  • Identity & Contact Data: Includes first name, last name, and email address.

  • Preference Data: Includes budget ranges, destination interests, and "My Next Holiday Is..." alert settings.

  • Technical & Usage Data: IP addresses, browser characteristics, and details of which "Holiday Cards" you clicked on.

3. HOW YOUR DATA IS USED

We process your information based on the following legal frameworks:

  • User Registration: We process Identity and Contact data to fulfill our contract with you.

  • Holiday Matching: We process Usage data to rank and display relevant Holiday Cards (Legitimate Interest).

  • Marketing Alerts: We use your Contact data for "My Next Holiday Is..." updates only where you have given explicit Consent.

  • Fraud Prevention: We process Technical data under the Recognised Legitimate Interest (Crime) provision of the 2026 Act to prevent bot activity and protect the directory.

4. AUTOMATED MATCHING AND RANKING TRANSPARENCY

In compliance with the DUAA 2026 transparency requirements, we disclose that our directory uses automated algorithms to determine search results.

  • Ranking Logic: Cards are ranked based on real-time availability, price relevancy, and the provider's compliance with our quality standards.

  • Intervention: You have the right to challenge an automated ranking. If you believe our system is unfairly filtering results, contact our support team for a manual review.

5. COOKIES AND TRACKING TECHNOLOGIES

Our website uses a layered cookie approach.

  • Necessary Cookies: Essential for site security.

  • Analytics & Performance: We use these to understand how users interact with our directory. Under 2026 UK standards, these are active by default to improve site "Access," but you have an absolute right to opt-out via our footer link.

6. DISCLOSURE AND SECURITY

We do not sell your data. We share it only with trusted technical providers (like AWS for hosting) or with travel providers when you choose to click on a holiday card. We use industry-standard encryption to ensure your data remains "Safe by Design."

7. DATA RETENTION

We retain your personal data for no longer than 2 years following your last login or interaction, unless legal obligations require a longer period. Marketing consent remains valid until you choose to unsubscribe.

8. YOUR LEGAL RIGHTS

Under the UK’s 2026 regime, you have the right to request access, correction, or erasure of your data. Note: We may "Stop the Clock" on the 30-day response period if we require further information to verify your identity.

9. MANDATORY COMPLAINTS PROCEDURE (Direct-First)

In accordance with the Data Use and Access Act 2026, if you have a complaint, the law requires you to attempt to resolve it with us first before contacting the regulator.

  1. Lodge a Complaint: Email us or use our website support form.

  2. Timeline: We will acknowledge your complaint within 30 days.

  3. Escalation: If you remain unsatisfied after our final response, you may escalate to the Information Commission at www.ico.org.uk.

10. CONTACT US

Savvy Holiday Maker Data Protection Officer - Contact