Private journeys across Morocco

Visit Morocco Tours

Skip to content
Visit Morocco ToursVisit Morocco Tours — Private, guided journeys across Morocco

Legal

Privacy, Cookies, Data Retention and Data Rights Policy

Visit Morocco Tours Ltd · Company number 16610456 · Effective 12 August 2026

82a James Carter Road, Mildenhall, Bury St. Edmunds, England, IP28 7DE

1. Purpose And Scope

1.1 This Policy explains how VISIT MOROCCO TOURS LTD, referred to as “VMT”, collects, uses, stores, protects and shares personal data.

1.2 This Policy also explains VMT's use of cookies and similar technologies, data retention practices, direct marketing practices and individual data-protection rights.

1.3 This Policy applies to personal data collected through:

a. the VMT website;

b. booking enquiries;

c. booking forms;

d. email;

e. WhatsApp;

f. telephone communications;

g. customer accounts where applicable;

h. travel bookings;

i. supplier communications;

j. customer service;

k. complaints;

l. reviews and feedback;

m. marketing activities;

n. in-person interactions;

o. other legitimate business activities.

1.4 This Policy applies to travellers, prospective travellers, website users, agents, suppliers, business contacts and other individuals whose personal data VMT processes.

1.5 This Policy operates alongside VMT's Customer Terms and Conditions and other VMT policies.

1.6 Where mandatory data-protection law gives an individual greater protection than this Policy, the mandatory law prevails.

2. Data Controller

2.1 VMT is the data controller for personal data processed for VMT's own business purposes.

2.2 Company:

VISIT MOROCCO TOURS LTD

Company number: 16610456

Registered office:

82a James Carter Road Mildenhall Bury St. Edmunds England IP28 7DE

2.3 General privacy contact:

hello@visitmorocco.tours

2.4 VMT determines why and how personal data is processed for its own business activities.

2.5 Where another organisation independently determines the purposes and means of processing, that organisation might act as a separate controller.

2.6 Where VMT processes personal data solely on another organisation's documented instructions, VMT might act as a processor.

3. Applicable Data-Protection Law

3.1 VMT operates from the United Kingdom and therefore principally processes personal data under:

a. UK GDPR;

b. Data Protection Act 2018;

c. Data (Use and Access) Act 2025;

d. Privacy and Electronic Communications Regulations 2003;

e. other applicable UK data-protection and electronic-communications legislation.

3.2 The relevant data-protection provisions introduced by the Data (Use and Access) Act 2025 are now in force as of 19 June 2026.

3.3 Where EU GDPR applies to VMT's processing, VMT will comply with applicable EU GDPR requirements.

3.4 EU GDPR might apply where VMT offers services to individuals located in the European Union or otherwise falls within Article 3 GDPR.

3.5 VMT will assess EU GDPR applicability according to the actual processing activity rather than the traveller's nationality alone.

3.6 Where applicable law in another jurisdiction provides mandatory privacy rights, VMT will respect those rights to the extent legally applicable.

4. Personal Data Collected

4.1 VMT might collect:

a. name;

b. title;

c. date of birth;

d. nationality;

e. country of residence;

f. postal address;

g. email address;

h. telephone number;

i. WhatsApp number;

j. booking reference;

k. travel dates;

l. destination information;

m. accommodation requirements;

n. transportation requirements;

o. tour preferences;

p. emergency contact information;

q. passport or identity-document information where required;

r. visa-related information where relevant;

s. payment and transaction information;

t. dietary requirements;

u. accessibility requirements;

v. medical or fitness information where necessary;

w. complaint information;

x. correspondence;

y. photographs or other media provided by the traveller;

z. website and technical information;

aa. marketing preferences;

ab. cookie and online identifier information;

ac. supplier or agent information;

ad. information necessary to investigate fraud or security issues.

5. Booking Information

5.1 VMT processes information necessary to administer enquiries and bookings.

5.2 This might include:

a. traveller names;

b. contact information;

c. travel dates;

d. accommodation information;

e. transportation requirements;

f. activity selections;

g. special requirements;

h. emergency contact details;

i. booking history;

j. payment status.

5.3 VMT collects only information reasonably necessary for the relevant purpose.

6. Passport And Travel Document Information

6.1 VMT might request passport or other travel-document information where reasonably necessary for a booking or travel service.

6.2 Such information might be required by:

a. accommodation providers;

b. transport providers;

c. local authorities;

d. border or immigration requirements;

e. activity providers;

f. other suppliers;

g. applicable law.

6.3 VMT will not request passport information merely because it is convenient.

6.4 Travellers should provide accurate information.

6.5 VMT is not responsible for consequences caused by inaccurate information supplied by a traveller, subject to applicable law.

7. Payment Information

7.1 VMT processes payment information to receive and reconcile booking payments.

7.2 Where a third-party payment processor handles card details, VMT aims not to retain full payment-card information unless necessary and lawfully permitted.

7.3 Payment providers might independently process personal data under their own privacy policies.

7.4 VMT might retain:

a. transaction references;

b. payment dates;

c. amounts;

d. payment status;

e. partial payment information;

f. accounting records.

7.5 VMT does not intentionally collect unnecessary full card-security information.

8. Special-Category Data

8.1 Special-category personal data receives additional protection under applicable law.

8.2 Such information might include:

a. health information;

b. disability information;

c. dietary information where it reveals health or religious information;

d. biometric information in relevant circumstances;

e. other legally protected special-category information.

8.3 VMT will only process special-category data where a lawful condition applies.

8.4 VMT might process health or accessibility information where necessary to:

a. provide a requested service;

b. assess reasonable safety requirements;

c. communicate necessary information to a supplier;

d. arrange appropriate assistance;

e. respond to an emergency;

f. comply with a legal obligation;

g. establish, exercise or defend legal claims;

h. otherwise comply with applicable law.

8.5 VMT will seek explicit consent where required and where another appropriate legal condition does not apply.

8.6 VMT will not request sensitive information without a legitimate reason.

9. Children'S Data

9.1 VMT might process information concerning children where a child participates in a booking.

9.2 VMT will collect only information reasonably necessary for the relevant service.

9.3 Where consent is relied upon for an online service directed to a child, VMT will comply with applicable age and parental-consent requirements.

9.4 Parents, guardians or persons with parental responsibility should provide accurate information concerning minors.

9.5 VMT will apply additional safeguards where reasonably necessary.

10. Sources Of Personal Data

10.1 VMT might collect information directly from an individual.

10.2 VMT might also receive information from:

a. a parent or guardian;

b. another traveller in the same booking;

c. a travel agent;

d. a corporate customer;

e. a supplier;

f. an accommodation provider;

g. a transport provider;

h. an activity operator;

i. a payment provider;

j. a website service;

k. a publicly available source;

l. another person acting lawfully on the traveller's behalf.

11. Purposes Of Processing

11.1 VMT processes personal data for purposes including:

a. responding to enquiries;

b. creating quotations;

c. creating bookings;

d. administering contracts;

e. providing travel services;

f. communicating with travellers;

g. coordinating suppliers;

h. processing payments;

i. administering refunds;

j. handling cancellations;

k. managing complaints;

l. managing emergencies;

m. safeguarding travellers;

n. preventing fraud;

o. maintaining business records;

p. complying with legal obligations;

q. defending legal claims;

r. enforcing contractual rights;

s. improving services;

t. website security;

u. website analytics;

v. marketing where legally permitted;

w. maintaining customer relationships;

x. business administration.

12. Lawful Bases

12.1 VMT will identify an appropriate lawful basis for each processing activity.

12.2 Depending on the circumstances, VMT might rely on:

a. performance of a contract;

b. steps taken at the individual's request before entering into a contract;

c. compliance with a legal obligation;

d. legitimate interests;

e. consent;

f. vital interests;

g. another lawful basis recognised by applicable law.

12.3 VMT will not rely on consent where another lawful basis provides the appropriate legal foundation.

12.4 Where VMT relies on legitimate interests, VMT will consider whether the interests are lawful, necessary and balanced against the individual's rights.

12.5 The Data (Use and Access) Act 2025 introduced changes to the UK framework concerning recognised legitimate interests and compatible further processing. VMT will apply the amended UK framework where relevant.

13. Contract Performance

13.1 VMT will process personal data where necessary to:

a. provide a quotation;

b. enter into a booking;

c. administer a booking;

d. provide contracted services;

e. communicate necessary travel information;

f. coordinate suppliers;

g. administer amendments;

h. administer cancellations;

i. process refunds;

j. provide assistance.

13.2 Where processing is necessary to perform a contract, refusing to provide required information might prevent VMT from providing the relevant service.

15. Legitimate Interests

15.1 VMT might rely on legitimate interests for purposes such as:

a. fraud prevention;

b. information security;

c. network security;

d. business administration;

e. service improvement;

f. direct marketing where legally permitted;

g. debt recovery;

h. defending legal claims;

i. enforcing contractual rights;

j. maintaining business records;

k. managing supplier relationships.

15.2 VMT will assess whether the processing is necessary and proportionate.

15.3 VMT will consider an individual's rights and reasonable expectations.

17. Direct Marketing

17.1 VMT might send marketing communications concerning:

a. Morocco tours;

b. travel services;

c. special offers;

d. destinations;

e. travel information;

f. new services;

g. relevant company updates.

17.2 VMT will comply with applicable direct-marketing requirements.

17.3 Electronic direct marketing will comply with PECR where PECR applies.

17.4 Marketing consent will be obtained where legally required.

17.5 VMT will provide a straightforward method to unsubscribe.

17.6 Each marketing communication will provide an appropriate opt-out mechanism where required.

18. Existing Customer Marketing

18.1 Where permitted by law, VMT might use an existing customer relationship to send marketing concerning similar services.

18.2 VMT will comply with applicable soft-opt-in requirements.

18.3 VMT will provide an appropriate opportunity to opt out.

18.4 VMT will not assume that being a previous customer gives unlimited permission for marketing.

19. Service Communications

19.1 VMT might send essential service communications without relying on marketing consent.

19.2 Service communications might include:

a. booking confirmations;

b. payment reminders;

c. itinerary information;

d. schedule changes;

e. safety information;

f. emergency information;

g. cancellation notices;

h. operational messages;

i. legal notices.

19.3 Service communications are distinct from direct marketing.

20. Cookies And Similar Technologies

20.1 VMT uses cookies and similar technologies where necessary and appropriate.

20.2 Cookies might collect information concerning:

a. device type;

b. browser;

c. IP address;

d. website activity;

e. preferences;

f. session information;

g. analytics information;

h. marketing interactions.

20.3 VMT will provide appropriate information about cookies.

20.4 Non-essential cookies and similar technologies will require consent where applicable law requires consent.

20.5 Strictly necessary technologies might operate without consent where the applicable legal exemption applies.

20.6 PECR requires clear information and consent for non-exempt cookies and similar technologies.

20.7 Continuing to browse the website does not itself constitute valid consent where active consent is required.

20.8 VMT will provide an appropriate mechanism for managing non-essential cookie preferences.

22. Analytics

22.1 VMT might use analytics services to understand website performance.

22.2 Analytics might provide information concerning:

a. pages viewed;

b. approximate location;

c. device;

d. browser;

e. referral source;

f. session information;

g. interactions.

22.3 Where analytics technology requires consent under applicable law, VMT will obtain consent before activating the relevant technology.

22.4 VMT will not describe non-essential analytics as “strictly necessary” merely because analytics are useful to VMT.

22.5 Third-party analytics providers might process information under their own terms and privacy documentation.

23. Third-Party Services

23.1 VMT uses third-party providers to operate its business.

23.2 Such providers might include:

a. payment processors;

b. email providers;

c. website hosting providers;

d. cloud storage providers;

e. booking systems;

f. customer relationship systems;

g. analytics providers;

h. communication platforms;

i. accounting providers;

j. cybersecurity providers;

k. travel suppliers;

l. IT support providers.

23.3 VMT will select processors and service providers according to appropriate risk and contractual requirements.

23.4 Where required by law, VMT will enter into appropriate data-processing arrangements.

24. Suppliers

24.1 VMT might share traveller information with suppliers where necessary to provide booked services.

24.2 Suppliers might include:

a. hotels;

b. riads;

c. transport providers;

d. drivers;

e. guides;

f. activity operators;

g. restaurants;

h. excursion providers;

i. emergency service providers.

24.3 VMT will share only information reasonably necessary for the relevant service, subject to applicable law.

25. International Data Transfers

25.1 VMT operates travel services in Morocco.

25.2 Personal data might therefore be transferred to or accessed from Morocco.

25.3 Personal data might also be processed by service providers located outside the UK or European Economic Area.

25.4 Where UK GDPR applies, VMT will use a lawful transfer mechanism where required.

25.5 Where EU GDPR applies, VMT will use an appropriate GDPR transfer mechanism where required.

25.6 Depending on the circumstances, safeguards might include:

a. adequacy regulations or decisions;

b. standard contractual clauses;

c. international data-transfer agreements;

d. UK Addendum mechanisms;

e. other lawful transfer mechanisms;

f. applicable derogations where legally available.

25.7 VMT will not treat a transfer as lawful merely because a supplier is reputable.

26. Morocco Processing

26.1 Traveller information might be shared with Moroccan suppliers to deliver booked services.

26.2 VMT will apply appropriate contractual and organisational safeguards.

26.3 Where Moroccan data-protection law applies to particular processing, VMT will comply with applicable requirements.

27. Us Customers

27.1 VMT welcomes customers from the United States.

27.2 US privacy laws vary significantly between states.

27.3 Whether a particular US state privacy law applies depends on factors including:

a. VMT's activities;

b. the volume of data processed;

c. revenue;

d. the number of consumers involved;

e. whether VMT sells personal data;

f. whether VMT conducts targeted advertising;

g. whether VMT meets a relevant statutory threshold;

h. whether an exemption applies.

27.4 VMT will assess applicable US state privacy requirements based on actual activities and applicable thresholds.

27.5 VMT does not represent that every US state privacy statute applies to every VMT customer.

27.6 Where a US state law gives an applicable customer specific privacy rights, VMT will provide those rights as required.

27.7 VMT does not sell personal data as part of its ordinary travel-booking business.

27.8 VMT will not use this statement to exclude any statutory definition of “sale”, “sharing” or equivalent concept where a particular state law applies.

28. Data Security

28.1 VMT takes reasonable technical and organisational measures to protect personal data.

28.2 Measures might include:

a. access controls;

b. authentication;

c. restricted permissions;

d. secure communications;

e. secure payment processing;

f. supplier controls;

g. backups;

h. device security;

i. staff confidentiality obligations;

j. incident-management procedures.

28.3 VMT limits access to personal data according to business need.

28.4 No online system provides absolute security.

28.5 VMT will respond to suspected data breaches according to applicable law.

29. Data Breaches

29.1 VMT will investigate suspected personal-data breaches.

29.2 VMT will assess whether notification to a regulator, affected individuals or another authority is legally required.

29.3 Where applicable UK GDPR requires notification to the ICO, VMT will comply with the applicable deadline.

29.4 Where another jurisdiction imposes a separate breach-notification requirement, VMT will comply where applicable.

29.5 VMT will maintain appropriate records of relevant data incidents.

30. Data Retention

30.1 VMT retains personal data only for as long as reasonably necessary for the relevant purpose, subject to legal and regulatory requirements.

30.2 Retention periods depend on:

a. the type of information;

b. the purpose;

c. contractual requirements;

d. accounting requirements;

e. tax requirements;

f. limitation periods;

g. legal claims;

h. fraud prevention;

i. safeguarding;

j. regulatory requirements.

30.3 VMT will periodically review retained information.

30.4 Information no longer required will be securely deleted, anonymised or otherwise disposed of where appropriate.

31. Booking Records

31.1 VMT will retain booking and financial information for periods required by applicable accounting, tax and legal requirements.

31.2 VMT might retain booking records beyond the end of a trip where reasonably necessary to:

a. establish or defend legal claims;

b. resolve disputes;

c. meet regulatory obligations;

d. prevent fraud;

e. comply with accounting requirements.

32. Passport Data Retention

32.1 Passport information will not be retained indefinitely.

32.2 VMT will delete or securely dispose of passport information when the relevant purpose has ended unless a lawful reason requires longer retention.

32.3 Where a supplier independently retains passport information, that supplier's own retention policy might apply.

33. Marketing Retention

33.1 Marketing information will be retained while the relevant marketing relationship or lawful basis continues.

33.2 VMT will periodically review marketing databases.

33.3 Unsubscribed individuals will not continue to receive marketing communications except where another lawful reason applies.

33.4 VMT might retain limited suppression information to ensure that an unsubscribe request is respected.

34. Data Subject Rights

34.1 Depending on the applicable law, an individual might have rights including:

a. right to be informed;

b. right of access;

c. right to rectification;

d. right to erasure;

e. right to restriction;

f. right to object;

g. right to data portability;

h. rights concerning automated decision-making;

i. right to withdraw consent where consent forms the lawful basis;

j. right to complain to a regulator.

35. Right Of Access

35.1 An individual may request access to personal data held about them where the applicable law provides such a right.

35.2 Requests should be sent to:

hello@visitmorocco.tours

35.3 VMT will verify the identity of the requester where reasonably necessary.

35.4 Identity verification protects against unauthorised disclosure.

35.5 VMT will normally respond within the applicable statutory period.

35.6 Where applicable law permits an extension because of complexity or volume, VMT will notify the requester as required.

36. Right To Rectification

36.1 Individuals may request correction of inaccurate personal data.

36.2 Individuals may request completion of incomplete information where appropriate.

36.3 VMT will update inaccurate information where the legal requirements for rectification are met.

37. Right To Erasure

37.1 Individuals might request deletion of personal data.

37.2 Erasure is not absolute.

37.3 VMT might lawfully retain information where necessary for:

a. legal obligations;

b. accounting;

c. taxation;

d. legal claims;

e. fraud prevention;

f. safeguarding;

g. other lawful purposes recognised by applicable law.

37.4 Where VMT cannot erase information because a legal exception applies, VMT will explain the applicable reason where required.

38. Right To Restriction

38.1 Individuals might request restriction of processing where the applicable legal conditions apply.

38.2 Restriction might apply while:

a. accuracy is disputed;

b. processing is unlawful but deletion is opposed;

c. VMT no longer needs the data but the individual requires it for a legal claim;

d. an objection is under consideration.

39. Right To Object

39.1 Individuals may object to processing where the applicable law provides such a right.

39.2 Individuals have an absolute right to object to direct marketing under applicable UK and EU data-protection law.

39.3 VMT will stop direct marketing following a valid objection.

39.4 Other processing might continue where VMT has a lawful basis which permits continuation under applicable law.

40. Data Portability

40.1 Where applicable law provides a right to data portability, an individual may request personal data in a structured, commonly used and machine-readable format.

40.2 The right applies only where the statutory conditions are satisfied.

40.3 Portability does not apply to every category of personal data.

41. Automated Decision-Making

41.1 VMT does not ordinarily make decisions about travellers solely through automated processing.

41.2 Where VMT introduces automated decision-making which produces legal or similarly significant effects, VMT will comply with applicable requirements.

41.3 Where applicable law provides safeguards against solely automated decisions, VMT will provide those safeguards.

41.4 The Data (Use and Access) Act 2025 changed aspects of the UK rules concerning automated decision-making. VMT will apply the amended UK requirements where relevant.

42. Profiling

42.1 VMT might use limited profiling for purposes such as:

a. website analytics;

b. service personalisation;

c. marketing segmentation;

d. fraud prevention.

42.2 VMT will comply with applicable legal requirements.

42.3 VMT will not use profiling to make decisions with significant effects on individuals without an appropriate legal basis and required safeguards.

43. Data Protection Complaints

43.1 VMT provides a dedicated route for data-protection complaints.

43.2 Complaints should be sent to:

hello@visitmorocco.tours

43.3 VMT will acknowledge a data-protection complaint within 30 days where the new UK statutory complaints requirements apply.

43.4 VMT will investigate appropriately and keep the complainant informed.

43.5 VMT will communicate the outcome of the complaint.

43.6 The new UK requirement took effect on 19 June 2026 and requires organisations to provide a clear complaint route, acknowledge complaints within 30 days, investigate appropriately and communicate the outcome.

44. Complaints To The Ico

44.1 UK individuals may complain to the Information Commissioner's Office where they believe their personal data has been handled unlawfully.

44.2 VMT encourages individuals to contact VMT first so VMT has an opportunity to investigate.

44.3 Contacting VMT first does not remove an individual's right to complain to the ICO.

44.4 ICO:

Information Commissioner's Office

44.5 VMT will provide the current ICO contact information in its website privacy information where appropriate.

45. Eu Data-Protection Complaints

45.1 Where EU GDPR applies, an individual may complain to the relevant EU supervisory authority.

45.2 An individual might complain to the supervisory authority in:

a. their habitual residence;

b. place of work;

c. place of the alleged infringement,

subject to the applicable GDPR rules.

45.3 VMT will not prevent an individual from exercising this right.

46. Eu Representative

46.1 Where Article 27 GDPR requires VMT to appoint an EU representative, VMT will make the required appointment.

46.2 Whether Article 27 applies depends on the nature and scale of VMT's EU-related processing.

46.3 VMT will publish representative details where legally required.

46.4 VMT will not claim that UK establishment alone prevents EU GDPR from applying.

47. Data Sharing With Authorities

47.1 VMT might disclose personal data where required by law or valid legal process.

47.2 Such disclosures might involve:

a. police;

b. courts;

c. regulators;

d. immigration authorities;

e. tax authorities;

f. emergency services;

g. other competent authorities.

47.3 VMT will assess requests for disclosure according to applicable law.

48. Supplier Data

48.1 VMT might process personal data concerning guides, drivers, hotels, activity providers, agents and other suppliers.

48.2 Supplier information might be processed for:

a. contracting;

b. payment;

c. booking;

d. compliance;

e. communication;

f. supplier management;

g. safety;

h. fraud prevention.

49. Business Transfers

49.1 If VMT sells, restructures or transfers part of its business, personal data might be transferred as part of the relevant transaction where legally permitted.

49.2 Any transfer will remain subject to applicable data-protection requirements.

50. Social Media

50.1 VMT might maintain social-media accounts.

50.2 Interactions with social-media platforms might involve processing by those platforms.

50.3 Those platforms have their own privacy policies.

50.4 VMT will not control processing performed independently by a social-media platform.

51. Website Security

51.1 VMT might collect technical information necessary to secure its website.

51.2 This might include:

a. IP address;

b. browser information;

c. device information;

d. security logs;

e. access times;

f. error information.

51.3 Security information might be retained longer than ordinary analytics information where reasonably necessary to detect or investigate security incidents.

53. Minimisation

53.1 VMT will seek to collect information adequate, relevant and limited to what is necessary for the relevant purpose.

53.2 VMT will avoid collecting sensitive information merely because it might become useful later.

53.3 This approach reflects the data-protection principles applying under the UK framework.

54. Accuracy

54.1 VMT seeks to keep personal data accurate.

54.2 Travellers should inform VMT of material changes to information relevant to their booking.

54.3 VMT will take reasonable steps to correct inaccurate information where required.

55. Confidentiality

55.1 VMT expects personnel and contractors with access to personal data to maintain appropriate confidentiality.

55.2 Access will be limited according to role and business need.

56. Data Processors

56.1 Where VMT appoints a processor, VMT will require appropriate contractual safeguards where legally required.

56.2 Processors will process personal data according to documented instructions and applicable law.

56.3 VMT will take reasonable steps to select processors capable of providing appropriate security.

57. International Supplier Access

57.1 A Moroccan supplier might receive traveller information necessary to deliver a service.

57.2 A US-based or other international technology provider might process information as part of providing services to VMT.

57.3 VMT will assess applicable international-transfer requirements before using relevant providers.

59. Identity Verification

59.1 VMT might request reasonable information to verify identity before responding to a rights request.

59.2 VMT will avoid requesting unnecessary identity documents.

59.3 Information provided solely for identity verification will be handled securely.

60. Rights Requests By Representatives

60.1 An authorised representative may submit a request on another person's behalf where legally permitted.

60.2 VMT might request evidence of authority.

60.3 Parents, guardians and persons with legal authority may exercise rights on behalf of children where permitted by law.

61. Requests Concerning Other People

61.1 A person must not request another individual's personal data without lawful authority.

61.2 VMT might refuse disclosure where disclosure would breach another person's privacy rights.

63. Fraud Prevention

63.1 VMT might process personal data to detect and prevent:

a. payment fraud;

b. identity fraud;

c. booking fraud;

d. refund fraud;

e. misuse of VMT services.

63.2 VMT might share relevant information with payment providers, suppliers, insurers, professional advisers or authorities where legally permitted.

64. Marketing Preferences

64.1 Travellers may manage marketing preferences through the unsubscribe mechanism provided in communications.

64.2 A marketing unsubscribe request does not necessarily stop service communications.

64.3 VMT might retain a limited record of an unsubscribe request to prevent future unwanted marketing.

66. Changes To This Policy

66.1 VMT might update this Policy to reflect:

a. legislative changes;

b. regulatory guidance;

c. changes to VMT's services;

d. changes to technology;

e. changes to suppliers;

f. changes to cookies;

g. changes to data-processing practices.

66.2 The latest version will be published on the VMT website.

66.3 Material changes will be communicated where required by law.

67. No Waiver Of Statutory Rights

67.1 Nothing in this Policy requires an individual to waive a mandatory data-protection right.

67.2 Nothing in this Policy excludes liability or obligations which cannot legally be excluded.

68. Contact Details

68.1 General privacy enquiries:

hello@visitmorocco.tours

68.2 Data-protection rights requests:

hello@visitmorocco.tours

68.3 Data-protection complaints:

hello@visitmorocco.tours

68.4 Postal correspondence:

VISIT MOROCCO TOURS LTD

82a James Carter Road

Mildenhall

Bury St. Edmunds

England

IP28 7DE

69. Policy Effective Date

69.1 This Policy takes effect on 12 August 2026.

69.2 VMT will review this Policy periodically and following material changes to applicable law.

70. Applicable Law

70.1 This Policy is principally based on UK data-protection law.

70.2 Where another mandatory data-protection regime applies to particular processing, VMT will comply with that regime to the extent required.

70.3 Nothing in this Policy removes rights granted by mandatory law.

Questions about this policy? Email hello@visitmorocco.tours.