top of page

Privacy Policy

Last Updated: [26 July 2026]

Effective Date: [26 July 2026]

Version: 2.0

 

  1. INTRODUCTION

Sustained Travel ("Sustained Travel", "we", "our", "us") is committed to protecting your privacy and handling personal information fairly, lawfully and transparently.

This Privacy Policy explains how we collect, use, store, share and protect personal information when you:

• visit our website;

• contact us;

• subscribe to newsletters or updates;

• register an account;

• purchase or use our services;

• complete sustainability assessments;

• upload evidence or supporting documentation;

• communicate with us;

• attend webinars or events;

• apply to become an assessor or partner; or

• otherwise interact with Sustained Travels.

We recognise that trust is fundamental to our business. Protecting your personal information forms part of our commitment to responsible business practices.

This Privacy Policy has been written to comply, as applicable, with:

• UK General Data Protection Regulation (UK GDPR)

• EU General Data Protection Regulation (EU GDPR)

• UK Data Protection Act 2018

• Privacy and Electronic Communications Regulations (PECR)

• Other applicable privacy legislation where required.

 

  1. WHO WE ARE

Sustained Travels operates an independent evidence-based sustainability assessment framework for tourism businesses.

Our services include, but are not limited to:

• sustainability assessments

• evidence verification

• public sustainability profiles

• digital assessment labels

• benchmarking

• reporting

• consultancy

• training

• destination assessments

• industry research

For the purposes of UK GDPR and EU GDPR, Sustained Travels acts as the Data Controller for personal information processed through our website and services unless otherwise stated.

Controller Details

Steve Gwenin

Sustained Travel

Email:
Steve@sustainedtravel.com

Website:
www.sustainedtravel.com

If appointed, details of our Data Protection Officer (DPO) will also be published here.

 

  1. OUR PRIVACY PRINCIPLES

We are committed to:

• processing personal information lawfully, fairly and transparently;

• collecting only information we genuinely require;

• using information only for legitimate purposes;

• keeping information accurate and up to date;

• retaining information only for as long as necessary;

• protecting information using appropriate technical and organisational security measures;

• respecting individuals' rights;

• being transparent about how decisions are made;

• never selling personal information.

 

  1. SCOPE OF THIS POLICY

This Privacy Policy applies to personal information collected through:

• our website;

• online assessment platform;

• customer portal;

• assessor portal;

• email communications;

• online forms;

• social media interactions where applicable;

• webinars;

• training sessions;

• telephone calls;

• video meetings;

• events;

• surveys;

• customer support;

• payment systems;

• publicly available business information used during assessments.

This Policy does not apply to third-party websites which may be linked from our website.

Users should review the privacy policies of those websites separately.

 

  1. DEFINITIONS

For the purposes of this Privacy Policy:

Personal Data

Any information relating to an identified or identifiable individual.

Processing

Any operation performed on personal information including collection, storage, organisation, analysis, disclosure or deletion.

Data Controller

The organisation determining why and how personal information is processed.

Data Processor

An organisation processing personal information on behalf of a controller.

Assessment

Our independent sustainability review process.

Evidence

Documentation or information submitted to support an assessment.

Operator

A tourism business participating in an assessment.

Public Profile

The publicly accessible assessment summary published following successful verification.

 

  1. INFORMATION WE COLLECT

Depending upon your relationship with Sustained Travels, we may collect the following information.

Identity Information

• name

• title

• organisation

• job title

• employer

• business registration details

Contact Information

• email address

• telephone number

• postal address

• country

• preferred language

Account Information

• username

• encrypted password

• login history

• account preferences

Assessment Information

• assessment responses

• uploaded evidence

• supporting documentation

• policies

• procedures

• photographs

• videos

• spreadsheets

• reports

• certificates

• licences

• sustainability data

• environmental performance information

• governance information

• social responsibility information

Communications

• emails

• messages

• customer support enquiries

• webinar registrations

• consultation notes

• meeting notes

Technical Information

• IP address

• browser type

• operating system

• device identifiers

• screen resolution

• referring website

• pages visited

• session duration

• clickstream information

• cookie identifiers

Marketing Information

• newsletter preferences

• event registrations

• download history

• consent records

Payment Information

Payments are processed by approved third-party payment providers.

Unless necessary for accounting or fraud prevention purposes, Sustained Travels does not store complete payment card information.

Publicly Available Information

Where relevant to an assessment we may review publicly available information including:

• company websites

• published sustainability reports

• regulatory registers

• official certification registers

• publicly available government records

• publicly available environmental disclosures

This information is used solely for legitimate assessment purposes.

 

  1. SPECIAL CATEGORY DATA

We do not intentionally request or require Special Category Personal Data unless it is genuinely necessary for delivering a requested service.

Examples include information revealing:

• racial or ethnic origin;

• political opinions;

• religious beliefs;

• trade union membership;

• genetic data;

• biometric data;

• health information;

• sexual orientation.

If such information is submitted unintentionally, we may remove or securely delete it where appropriate.

Where Special Category Data is required for a legitimate purpose, we will process it only in accordance with applicable law.

 

  1. CHILDREN

Our website and services are intended for businesses and adults.

They are not directed at children under the age of 16.

We do not knowingly collect personal information from children.

If we become aware that personal information relating to a child has been submitted without appropriate authorisation, we will take reasonable steps to delete it.

 

  1. HOW WE COLLECT INFORMATION

Information may be collected directly when you:

• visit our website;

• complete online forms;

• create an account;

• request information;

• subscribe to newsletters;

• purchase services;

• upload assessment evidence;

• contact customer support;

• participate in webinars;

• complete surveys;

• communicate with assessors.

Information may also be collected automatically through:

• cookies;

• analytics technologies;

• server logs;

• security monitoring;

• website performance tools.

In limited circumstances we may receive information from:

• your employer;

• authorised representatives;

• publicly available sources;

• payment providers;

• technology service providers;

• regulatory bodies where legally permitted.

 

  1. OUR LAWFUL BASIS FOR PROCESSING

We process personal information only where a lawful basis exists under applicable data protection legislation.

These lawful bases include:

Performance of a Contract

Processing necessary to provide requested services.

Examples include:

• operating customer accounts;

• carrying out sustainability assessments;

• issuing assessment reports;

• providing customer support;

• administering subscriptions.

Legitimate Interests

We may process information where necessary for our legitimate interests provided those interests do not override your rights.

Examples include:

• improving our services;

• preventing fraud;

• maintaining website security;

• responding to enquiries;

• business administration;

• quality assurance;

• maintaining assessment integrity;

• defending legal claims.

Consent

Where required by law we rely upon your consent.

Examples include:

• marketing communications;

• optional cookies;

• newsletters;

• promotional emails.

Consent may be withdrawn at any time.

Legal Obligation

We may process information where necessary to comply with legal obligations including:

• accounting requirements;

• taxation;

• regulatory investigations;

• court orders;

• fraud prevention;

• law enforcement requests where legally required.

Public Interest

Where permitted by law, certain processing may be undertaken in the public interest.

  1. HOW WE USE YOUR PERSONAL INFORMATION

We use personal information only where necessary to operate our business, deliver our services, comply with legal obligations and improve our platform.

We may use your information to:

• provide sustainability assessments;

• verify submitted evidence;

• communicate with you regarding your assessment;

• administer your account;

• process payments;

• provide customer support;

• respond to enquiries;

• manage subscriptions;

• produce assessment reports;

• create public assessment profiles where authorised;

• issue digital assessment labels;

• conduct quality assurance and assessor calibration;

• improve our assessment methodology;

• analyse website performance;

• maintain platform security;

• prevent fraud or misuse;

• comply with legal obligations;

• maintain accounting records;

• investigate complaints;

• exercise or defend legal claims;

• conduct anonymous statistical analysis;

• develop new products and services.

We will never use your personal information for purposes incompatible with those described in this Privacy Policy unless we have another lawful basis for doing so.

 

  1. ASSESSMENT DATA

Our assessment platform is designed primarily to assess organisations rather than individuals.

Assessment submissions may include:

• business policies;

• environmental information;

• governance documentation;

• operational procedures;

• sustainability evidence;

• photographs;

• videos;

• certificates;

• licences;

• utility information;

• supplier information;

• management information;

• improvement plans.

Operators should avoid submitting unnecessary personal information wherever possible.

Where personal information is included within uploaded documents, it will be processed only to the extent necessary to complete the assessment.

 

  1. PUBLIC PROFILES

Where an operator successfully completes a verified assessment and chooses to participate in our public programme, we may publish information including:

• organisation name;

• location;

• business description;

• assessment date;

• assessment outcome;

• assessment summary;

• sustainability indicators;

• evidence summary;

• assessment methodology version;

• digital assessment label;

• public contact details provided by the operator;

• website link;

• promotional images supplied by the operator.

We will not intentionally publish personal information about individuals unless they have provided consent or publication is otherwise lawful.

 

  1. MARKETING COMMUNICATIONS

Where permitted by law we may send information relating to:

• service updates;

• newsletters;

• webinars;

• events;

• industry insights;

• product launches;

• research publications.

Where consent is required, we will request it before sending marketing communications.

You may unsubscribe at any time by:

• clicking the unsubscribe link;

• updating your account preferences;

• contacting us directly.

Service communications relating to existing accounts, assessments or contractual obligations are not considered marketing.

 

  1. WHO WE SHARE INFORMATION WITH

We do not sell personal information.

We may share information with carefully selected service providers where necessary to operate our business.

These may include:

• cloud hosting providers;

• payment processors;

• website providers;

• email service providers;

• customer relationship management systems;

• analytics providers;

• document storage providers;

• identity verification providers;

• professional advisers;

• insurers;

• accountants;

• legal advisers;

• regulators where legally required.

All processors are required to:

• maintain appropriate security;

• process information only on our instructions;

• comply with applicable data protection legislation;

• maintain confidentiality.

 

  1. INTERNATIONAL TRANSFERS

Some of our service providers may process information outside the United Kingdom or European Economic Area.

Where international transfers occur we will ensure appropriate safeguards are implemented, including where appropriate:

• UK International Data Transfer Agreement (IDTA);

• International Data Transfer Addendum;

• European Commission Standard Contractual Clauses;

• adequacy decisions;

• other safeguards recognised under applicable law.

 

  1. DATA RETENTION

We retain information only for as long as necessary.

Typical retention periods include:

Customer enquiries

Up to 24 months

Customer accounts

Duration of relationship plus up to seven years where required for legal or accounting purposes

Assessment records

Normally seven years following the most recent assessment unless longer retention is justified

Financial records

Normally seven years

Marketing consent records

Until withdrawn plus evidence of consent where required

Website analytics

Normally between 14 and 26 months depending upon system configuration

Security logs

Normally between six and twenty-four months

Information may be retained longer where necessary for:

• legal claims;

• fraud prevention;

• regulatory investigations;

• legal obligations.

At the end of the applicable retention period information will be securely deleted or anonymised.

 

  1. INFORMATION SECURITY

We implement appropriate technical and organisational measures designed to protect personal information.

These measures may include:

• encrypted communications;

• encryption of stored information where appropriate;

• access controls;

• multi-factor authentication;

• password security;

• least privilege access;

• security monitoring;

• vulnerability management;

• regular software updates;

• secure backups;

• audit logging;

• staff confidentiality obligations;

• regular security reviews.

Although we take reasonable precautions, no internet-based system can be guaranteed to be completely secure.

 

  1. AUTOMATED DECISION MAKING

Our assessment methodology includes structured scoring, evidence mapping and rules-based analysis.

Final verified assessment outcomes include human review and are not based solely upon automated decision-making.

Where automated tools assist assessors they are used only as decision-support tools.

Individuals may request further information regarding assessment processes by contacting us.

 

  1. YOUR RIGHTS

Subject to applicable legislation you may have the right to:

• access your personal information;

• obtain a copy of your information;

• request correction of inaccurate information;

• request deletion of personal information;

• request restriction of processing;

• object to certain processing;

• withdraw consent where processing relies upon consent;

• request portability of information;

• complain to a supervisory authority.

We aim to respond to requests within one month unless an extension is permitted by law.

Identity verification may be required before fulfilling certain requests.

 

  1. DATA BREACHES

If we become aware of a personal data breach likely to result in a risk to individuals' rights and freedoms we will investigate promptly.

Where legally required we will notify the appropriate supervisory authority without undue delay.

Where required by law we will also notify affected individuals.

 

  1. THIRD-PARTY WEBSITES

Our website may contain links to third-party websites.

We are not responsible for the privacy practices of those websites.

Users should review the privacy policies of each website they visit.

 

  1. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time.

Material changes will be published on our website.

Where appropriate we will notify registered users.

The latest version will always be available on our website.

 

  1. CONTACT US

If you have any questions regarding this Privacy Policy or our handling of personal information please contact:

Privacy Officer:

Steve Gwenin

Sustained Travel

Email:
steve@sustainedtravel.com

Website:
www.sustainedtravel.com

 

  1. COMPLAINTS

If you are dissatisfied with how we have handled your personal information we encourage you to contact us first so we have the opportunity to resolve the issue.

If you are located in the United Kingdom you also have the right to lodge a complaint with the Information Commissioner's Office (ICO).

If you are located within the European Union you may also contact your local supervisory authority.

 

  1. POLICY REVIEW

This Privacy Policy will be reviewed periodically and updated whenever necessary to reflect:

• changes in legislation;

• changes to our services;

• changes in technology;

• regulatory guidance;

• organisational changes;

• improvements to our privacy practices.

Version: 2.0

Last Updated: [26 July 2026]​​​​​​

bottom of page