Privacy policy
Last updated: 2026-05-01
Data controller: Wellness Trips Ltd.
Contact: info@wellnesstrips.co.uk
This policy explains what personal data Wellness Trips collects, why we collect it, how long we keep it, and how you can exercise your rights under the EU GDPR and Turkish KVKK.
What we collect
- Contact, application and partner submissions: name, email, phone, organisation, treatment area, dates, budget, message and any consent decisions.
- Hashed visitor IP and user-agent for fraud and abuse prevention. Raw IPs are never persisted.
- Consent decisions (strictly necessary / analytics / marketing) along with the policy version.
Why we use it
- To respond to your enquiry and coordinate medical and travel arrangements (legitimate interest / contract).
- To comply with regulatory, fiscal and clinical record-keeping obligations.
- To send operational updates and marketing only if you opt in (consent).
How long we keep it
- Application and contact submissions: 730 days, then anonymised in place.
- Consent log: 2555 days (evidentiary retention).
- Analytics events: 365 days.
Sharing
We do not sell your data. We share only with operational sub-processors required to deliver coordination:
- Hosting: Vercel
- Database & storage: Supabase
- Transactional email: Resend
- Bot protection: Cloudflare Turnstile
- Hospital and insurance partners as required for the case.
Your rights
You can access, rectify, erase, restrict, port, or object to processing of your personal data. Submit a request via /legal/dsar. We verify by email and respond within 30 calendar days.
Updates
Material updates are recorded alongside your saved consent so you always know which version you agreed to.
