Privacy Policy

By using our Site, you are agreeing to the terms and conditions of this Privacy Policy.

© Campbell Island Scenery By Adam Riley

Privacy Notice

Rockjumper Birding Ltd | Last updated: 7 August 2026

 

Your privacy matters to us. This notice explains what personal information we collect, why we use it, who we share it with, how long we keep it, and the choices and rights available to you.

Who we are

Rockjumper Birding Ltd (referred to as “Rockjumper”, “we”, “us” or “our”) organises and supplies guided travel experiences. For the processing described in this notice, Rockjumper Birding Ltd is generally the data controller because it decides why and how personal information is used.

 

Our contact details are: Labourdonnais Village, Mapou, Riviere du Rempart 31803, Mauritius; email: info@rockjumper.com; website: https://www.rockjumperbirding.com/.

 

Some travel suppliers that receive your information make their own decisions about how they use it and may therefore be independent data controllers. Their privacy notices may also apply.

Scope of this notice

This notice applies when you visit our website, enquire about or book a tour, travel with us, create an account, subscribe to communications, attend an event or webinar, enter a promotion, supply services to us, apply for work, or otherwise communicate or interact with us. It also applies when another person makes an enquiry or booking on your behalf.

 

If you provide information about another traveller, emergency contact or family member, you must be authorised to do so and should make this notice available to that person where reasonably possible.

Information we collect

Category

Examples

Identity and contact information

Name, title, date of birth, postal and email addresses, telephone number, nationality and account details.

Booking and travel information

Tour choices, booking reference, itinerary, accommodation and rooming preferences, travel companions, loyalty information, special requests and previous travel with us.

Passport and immigration information

Passport copy, passport number, issuing country and place, issue and expiry dates, visas, permits and information required by border or government authorities.

Transport information

Flight numbers, arrival and departure dates and times, airports, ticketing details and transfer arrangements.

Emergency and insurance information

Emergency contacts, next of kin, travel insurer, policy or reference number and information needed to assist with an incident or claim.

Health, accessibility and dietary information

Medical conditions, allergies, medication-related information, mobility or accessibility needs, dietary requirements, physical capability and other information needed to assess suitability or provide safe and appropriate services.

Payment and transaction information

Billing address, bank or payment details, currency, amount, payment status, transaction reference, refunds and related accounting records. We do not store complete payment-card numbers or card security codes when payment is handled by our payment provider.

Communications and preferences

Emails, telephone or chat records, enquiries, complaints, feedback, reviews, survey responses, marketing choices, interests and tour preferences.

Images and trip content

Photographs, video, audio, trip reports and testimonials where you provide them or where they are captured with appropriate notice or permission.

Technical and website information

IP address, device and browser information, login and security records, pages viewed, referral source, cookie identifiers and interactions with our website and messages.

Supplier, guide and applicant information

Business contact and payment information, qualifications, licences, work history, references and information relevant to providing services or applying for a role.

How we obtain information

We obtain information directly from you and from people acting for you, including travel agents, family members and lead bookers. We may also receive it from our group companies, payment and booking providers, travel suppliers, guides, publicly available sources, marketing partners, referees, insurers and authorities, where lawful. Our website and security systems collect some technical information automatically.

Why we use information and our lawful bases

We use personal information only where we have a lawful basis. The applicable basis depends on the purpose and circumstances. Consent is not our only basis and is generally reserved for activities where a genuine choice is possible, such as certain marketing, optional use of images and some uses of sensitive information.

 

Purpose

What we do

Lawful basis

Enquiries, quotations and bookings

Respond; recommend suitable options; create and administer bookings; issue documents; take payment; arrange changes, cancellations and refunds.

Steps requested before entering a contract; performance of our contract; legitimate interests in administering enquiries and our services.

Delivering the tour

Arrange accommodation, transport, guides, permits, meals and activities; manage rooming and special requests; communicate operational information.

Performance of our contract; legitimate interests in delivering and coordinating the tour; legal obligations where applicable.

Safety and emergencies

Assess practical suitability; accommodate accessibility, dietary or medical needs; respond to illness, injury, evacuation or another emergency; contact next of kin or insurers.

Explicit consent where required for sensitive information; vital interests in an emergency; contract and legitimate interests for non-sensitive operational information; applicable legal obligations.

Payments, accounting and fraud prevention

Process and reconcile payments; conduct fraud and security checks; maintain tax, audit and accounting records; recover debts.

Contract; legal obligations; legitimate interests in protecting our business and preventing fraud.

Passports, visas and authorities

Arrange permits, visas, tickets and passenger services; provide mandatory passenger or immigration information; meet border, sanctions and regulatory requirements.

Contract; legal obligations; legitimate interests in lawful and effective travel arrangements.

Service, support and quality

Answer questions; manage complaints, incidents, claims and feedback; train staff; improve itineraries, service standards and tour suitability.

Contract; legal obligations; legitimate interests in service quality, staff training and the establishment, exercise or defence of legal claims.

Personalisation and recommendations

Use travel history, stated preferences, interests and practical requirements to suggest suitable tours and tailor service.

Legitimate interests in relevant customer service; consent where required. You may object to direct marketing or ask us not to personalise recommendations.

Marketing and events

Send newsletters, offers and invitations; manage webinars, promotions and loyalty activities; measure communications.

Consent where required; otherwise legitimate interests, subject to applicable direct-marketing law and your right to object.

Website, analytics and security

Operate accounts and website functions; remember choices; understand usage; diagnose faults; secure systems; prevent misuse.

Contract where needed for requested functions; legitimate interests in operating, improving and protecting our services; consent for non-essential cookies where required.

Legal, insurance and corporate matters

Meet legal and regulatory duties; respond to authorities; maintain insurance; manage disputes, audits, restructuring, sale or acquisition.

Legal obligations; legitimate interests in governance, insurance, risk management and legal claims.

Suppliers, guides and recruitment

Engage and pay suppliers and guides; conduct due diligence; manage applications, references and possible appointments.

Contract or pre-contractual steps; legal obligations; legitimate interests in resourcing and managing our business.

 

Where we rely on legitimate interests, we consider the necessity of the processing and balance our interests against the individual’s rights and reasonable expectations. You may contact us for further information about that assessment.

Sensitive information

Health, disability and some dietary information may be treated as special-category or sensitive personal information. We ask only for information reasonably needed to evaluate practical suitability, make appropriate arrangements, protect health and safety or respond to an emergency. We normally rely on explicit consent where the law requires an additional condition for this processing. In a genuine emergency, we may process or disclose information to protect your or another person’s vital interests where consent cannot reasonably be obtained.

 

You may decline to provide optional sensitive information. However, if information is necessary to assess whether a tour is appropriate or to deliver an essential safety or accessibility arrangement, we may be unable to confirm or safely provide some services without it.

Who we share information with

We share only the information reasonably required for the relevant purpose. Recipients may include:

  • accommodation providers, lodges, camps and rooming coordinators;
  • airlines, charter operators, rail, cruise, transfer and vehicle operators;
  • destination management companies, ground handlers, local operators, tour leaders and guides;
  • activity providers, parks, reserves, permit offices and conservation authorities;
  • visa, immigration, customs, border, aviation, health and other government authorities;
  • payment gateways, banks, card networks, accountants and fraud-prevention providers;
  • IT hosting, cloud, communications, booking, customer-management, analytics and security providers;
  • insurers, assistance companies, medical providers and emergency services where necessary;
  • our related companies and operational teams supporting the Rockjumper group and its associated travel brands, where they support the booking or shared business operations;
  • professional advisers, auditors, regulators, courts, law-enforcement bodies and parties involved in a legal claim;
  • a purchaser, investor or successor in connection with a proposed or completed corporate transaction.

 

Some recipients act on our instructions as processors. Others, particularly airlines, accommodation providers, authorities, insurers and certain local operators, may process information as independent controllers under their own legal duties and privacy notices.

Payments

Online card payments are processed through a payment gateway that is expected to maintain applicable Payment Card Industry Data Security Standard (PCI DSS) controls. Complete card numbers and card security codes are submitted to and processed by the payment provider; we do not store those complete details. We may retain limited transaction information such as payer name, billing details, amount, currency, date, payment status, an abbreviated card reference or last digits, and a transaction identifier for booking, accounting, fraud-prevention, refund and legal-compliance purposes.

Automated decisions and tour recommendations

We may use preferences, previous travel, mobility or fitness information and other practical requirements to assist staff in recommending an appropriate tour. We do not intend to make decisions producing legal or similarly significant effects solely by automated means. A member of our team can review recommendations and discuss your requirements. If this changes, we will provide the information and safeguards required by applicable law.

International transfers

We operate international tours. Your destination, residence, payment route, suppliers and our service providers may be in countries outside Mauritius and, where applicable, outside the United Kingdom, European Economic Area or South Africa. Those countries may have different data-protection laws.

 

We transfer only information reasonably needed to arrange and deliver services, protect travellers, process payments or meet legal requirements. Depending on the circumstances and applicable law, we rely on an adequacy decision, approved contractual protections, another recognised safeguard, transfer necessary to perform or conclude a travel contract requested in your interests, legal claims, important public-interest grounds, vital interests, or your explicit consent after explaining relevant risks. You may contact us for information about the safeguard relevant to a particular transfer, subject to lawful confidentiality restrictions.

Retention

We keep information only for as long as reasonably necessary for the purpose for which it was collected, including legal, tax, accounting, safety, insurance and claims requirements. The periods below are our standard targets and may be extended where a complaint, claim, investigation, legal hold or statutory requirement applies, or shortened where the information is no longer needed.

 

Record type

Standard retention approach

General enquiries not resulting in a booking

Up to 2 years after the last meaningful contact.

Booking, contract, payment, invoice and accounting records

Normally 7 years after the end of the tour or relevant financial period.

Passport copies, identity documents and visa-support records

We retain these documents while required to administer your booking and tour. If you ask us to retain your passport copy for future bookings, we may keep it securely until the passport expires, you ask us to delete it, or five years have passed since your last booking or meaningful interaction with us, whichever occurs first.
Where an identity document forms part of a KYC, anti-money laundering, tax, sanctions, regulatory, audit, investigation or legal record that we are required to retain, we will keep it for the applicable statutory or legal period. During that period, its use will be restricted to the relevant compliance or legal purpose. We may also retain limited passport-related information without retaining the complete copy where reasonably necessary.

Health, accessibility, dietary, emergency-contact and insurance details

Normally deleted or securely anonymised within 90 days after the tour, unless needed for an incident, claim, legal obligation or a future booking at your request.

Complaints, incidents, insurance matters and legal claims

For the life of the matter and the applicable limitation period, plus a reasonable period for closure and audit.

Marketing records

Until you unsubscribe or object, or after a period of inactivity under our retention schedule. A minimal suppression record may be kept to honour your choice.

Website, account, security and analytics records

According to the relevant system and cookie schedule; security logs are normally retained for up to 12 months unless an investigation requires longer.

Recruitment records for unsuccessful applicants

Normally up to 12 months after the process, unless you agree to longer retention or law requires otherwise.

Supplier and guide records

For the relationship and normally 7 years thereafter where needed for contract, tax, audit or claims purposes.

 

When a period expires, we delete, securely destroy or anonymise information unless continued retention is lawful and necessary. Backup copies are isolated from ordinary use and removed in accordance with backup cycles.

Security

We use appropriate technical and organisational measures designed to protect personal information against accidental or unlawful loss, misuse, alteration, unauthorised access or disclosure. Measures may include access controls, authentication, encryption in transit or at rest where appropriate, secure payment processing, staff confidentiality and training, supplier controls, backups, monitoring and incident-response procedures. No system is completely secure, and you should use secure channels and protect your account credentials.

Cookies and similar technologies

Our website may use cookies, pixels, local storage and similar technologies. These may be:

  • strictly necessary technologies required for security, network management, login, forms, booking functions and user-requested services;
  • preference technologies that remember choices and settings;
  • analytics technologies that help us understand use, performance and errors; and
  • marketing technologies that help measure campaigns or tailor advertising, where used.

 

Where required, non-essential technologies are used only after you make a choice through our cookie controls. You can change available choices through those controls and may also manage cookies in your browser. Blocking necessary technologies may prevent parts of the website from working. Our cookie banner or cookie notice should identify current technologies, providers, purposes and durations; it forms part of this notice.

Direct marketing

We may send information about tours, events, content and offers where you have consented or where applicable law otherwise permits it. You can unsubscribe through the link in an email or contact us at any time. We may retain a minimal suppression record so that we do not contact you again through that channel. Service messages about an enquiry or booking are not marketing and may still be sent where necessary.

Photographs, video and testimonials

We may invite you to provide a testimonial, image or trip content, or ask permission to use identifiable photographs or recordings for editorial or promotional purposes. Where consent is the appropriate basis, participation is voluntary and you may withdraw consent for future use. Withdrawal does not make prior lawful use unlawful and may not allow us to recall printed material or content already shared by others. We will provide more specific information where a particular shoot, event or campaign requires it.

Children

Children may travel on some tours. A parent, guardian or authorised adult must provide information for a child and make booking and privacy choices on the child’s behalf where required. We use a child’s information only as reasonably necessary to assess suitability, make travel and safety arrangements, comply with law and deliver the tour. We do not knowingly use children’s information for direct marketing without appropriate authorisation.

Your rights

Depending on the law applicable to you and the circumstances, you may have the right to:

  • be informed about how your personal information is used;
  • request access to your personal information and a copy of it;
  • ask us to correct inaccurate or incomplete information;
  • ask us to erase information where there is no lawful reason to keep it;
  • ask us to restrict processing in specified circumstances;
  • object to processing based on legitimate interests and object at any time to direct marketing;
  • receive certain information in a structured, commonly used, machine-readable format or ask for it to be transferred, where the right to portability applies;
  • withdraw consent at any time for future consent-based processing; and
  • request human intervention and challenge a qualifying decision made solely by automated means.

 

To exercise a right, email info@rockjumper.com. Please describe your request and the information concerned. We may ask for information reasonably needed to verify your identity or authority. Rights can be subject to legal conditions and exemptions; if we cannot fulfil a request, we will explain why where the law requires. We do not ordinarily charge a fee, but applicable law may permit one for manifestly unfounded, excessive or repeated requests.

 

You may also complain to the Data Protection Office of Mauritius (dataprotection.govmu.org). If another data-protection law applies, you may have the right to complain to the supervisory authority in your country or region. We encourage you to contact us first so we can try to resolve the matter.

Providing information

Some information is required to enter into or perform a booking, comply with law or protect traveller safety. We will indicate where information is mandatory when this is not obvious. If you do not provide required information, we may be unable to issue a quotation, confirm a booking, arrange a service or safely accept participation. Optional information can be withheld without affecting unrelated services.

Third-party websites and services

Our websites and communications may link to services that we do not control. Their privacy practices are governed by their own notices. A link does not mean that we are responsible for the other service’s processing.

Changes to this notice

We may update this notice to reflect changes in our activities, systems or legal obligations. The current version will be posted on our website with its revision date. Where a change materially affects how we use existing information, we will provide additional notice where reasonably practicable or legally required.

Contact us

Questions, rights requests and privacy complaints may be sent to info@rockjumper.com or by post to Rockjumper Birding Ltd, Labourdonnais Village, Mapou, Riviere du Rempart 31803, Mauritius. Please mark correspondence “Privacy”.

 

This notice should be read together with any more specific privacy information provided at the point of collection, our cookie information and the terms applicable to your booking or use of our services.