Privacy Policy
This policy explains which personal data MSL Holidays processes, why it is needed, how long it is retained and which privacy rights you have.
Last updated:
This legal page is being finalised and is currently excluded from search-engine indexing.
MSL Holidays only processes personal data when this is needed to operate and secure the website, answer messages, manage accounts, fulfil shop orders, comply with legal obligations or load optional external services you have accepted.
1. Who is responsible for your personal data?
MSL Holidays is the controller responsible for the personal-data processing described in this Privacy Policy.
- Business status
- Business registration pending
- Privacy email
- info@mslholidays.com
- Website
- https://mslholidays.com
2. Personal data we may process
The information processed depends on how you use the website. MSL Holidays may process the following categories of personal data.
Contact information
- your name and email address;
- the contents of messages submitted through the contact form;
- subsequent correspondence and customer-service notes.
Account information
- your name and email address;
- your securely generated password hash;
- account activation, login and account-status information;
- saved addresses and account preferences.
MSL Holidays does not store your original account password in readable form.
Order and delivery information
- billing and delivery names and addresses;
- email address and, where required, telephone number;
- ordered products, quantities, prices and order status;
- shipping, tracking, cancellation and return information;
- communications about an order or complaint.
Payment information
- payment status and transaction identifiers;
- the payment method and limited payment metadata made available by Stripe;
- refund, dispute and fraud-prevention information where applicable.
MSL Holidays does not receive or store complete payment-card numbers. Payment details are entered and processed through Stripe.
Technical and security information
- IP address and approximate connection information;
- browser, operating-system and device information;
- requested pages, timestamps and referral information;
- login attempts, form submissions and technical errors;
- security, fraud-prevention and abuse-detection events.
Website preferences
- shopping-cart and session information;
- selected currency and website preferences;
- cookie and privacy-category choices;
- temporary guest-cart identifiers.
Optional external services
When you accept or activate optional services, providers such as Google, YouTube, GetYourGuide or Expedia Group may receive technical connection data and information about your interaction with their content.
More information about these technologies is available in our Cookie Policy.
3. Why we process personal data
| Purpose | Typical data | Legal basis |
|---|---|---|
| Responding to questions and requests | Name, email address, message contents and correspondence | Steps requested before entering into a contract, or our legitimate interest in responding to enquiries |
| Creating and managing customer accounts | Account details, password hash, addresses and login information | Performance of a contract and steps requested before entering into a contract |
| Processing and delivering shop orders | Customer, order, delivery and payment-status information | Performance of a contract |
| Processing payments and refunds | Transaction identifiers, payment status, refund and fraud-prevention information | Performance of a contract, legal obligations and legitimate interests in preventing payment fraud |
| Accounting, tax and statutory administration | Orders, invoices, payments, refunds and related customer information | Compliance with legal obligations |
| Website and account security | IP address, logs, login attempts, security events and technical information | Our legitimate interests in protecting the website, customers and business against abuse, fraud and attacks |
| Handling complaints and legal claims | Orders, correspondence, account information and other relevant records | Legal obligations and legitimate interests in establishing, exercising or defending legal claims |
| Loading optional external media and affiliate widgets | IP address, device information and interaction data | Your consent |
Where processing is based on legitimate interests, MSL Holidays considers whether those interests are necessary and proportionate and whether your rights and interests override them.
4. How we obtain personal data
Most personal data is provided directly by you when you:
- submit a contact form;
- create or manage an account;
- place, cancel or return an order;
- communicate with customer service;
- select privacy or website preferences.
Technical information is generated automatically when you use the website. MSL Holidays may also receive limited order, payment, delivery or refund information from service providers involved in fulfilling your request.
5. Service providers and other recipients
Personal data is only disclosed where this is reasonably necessary for the purposes described in this policy. Recipient categories may include:
- website-hosting and technical service providers;
- email and communication providers;
- Stripe for payment processing and fraud prevention;
- delivery and fulfilment providers used for shop orders;
- accounting, legal or other professional advisers where required;
- government authorities where disclosure is legally required.
These parties may act as processors on behalf of MSL Holidays or as independent controllers for their own services and legal obligations. Their role depends on the service concerned.
When optional content is enabled, Google, YouTube, GetYourGuide or Expedia Group may also receive personal data such as your IP address, browser information and interaction data.
Clicking an external or affiliate link takes you to the relevant provider. That provider’s own privacy policy and terms then apply to your use of its website and services.
6. International transfers
Some service providers may process personal data outside the European Economic Area. Where the GDPR requires additional safeguards, a transfer may be based on:
- a European Commission adequacy decision;
- approved Standard Contractual Clauses;
- another lawful transfer mechanism permitted by the GDPR.
Supplementary technical or organisational measures may be used where appropriate. You may contact MSL Holidays for more information about the safeguards relevant to a particular transfer.
Choosing Necessary only prevents optional external media and marketing widgets from loading. It does not necessarily prevent data transfers by providers required to host the website, secure accounts, process payments or fulfil an order.
7. How long we retain personal data
Personal data is not retained longer than reasonably necessary for the purpose for which it was collected, unless a longer period is required by law or needed for a dispute, security investigation or legal claim.
- Contact messages are normally retained for no longer than 12 months after the conversation has ended.
- Security and form-abuse logs are normally retained for no longer than 12 months, unless an incident requires longer investigation.
- Temporary guest shopping-cart identifiers expire after approximately 30 days.
- Cookie and privacy preferences are stored for up to 180 days, after which the website may ask for your choices again.
- Account information is retained while the account is active and is removed or anonymised when no longer needed, subject to outstanding orders, legal obligations and disputes.
- Order, invoice and financial administration that forms part of the legally required business records is generally retained for seven years.
- Information required for a complaint, chargeback or legal claim may be retained until the relevant limitation or dispute period has ended.
8. Your privacy rights
Subject to the conditions and exceptions in the GDPR, you may have the right to:
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request deletion of personal data;
- request restriction of processing;
- receive certain data in a portable format;
- object to processing based on legitimate interests;
- withdraw consent at any time;
- lodge a complaint with a data-protection authority.
Withdrawing consent does not affect the lawfulness of processing that occurred before consent was withdrawn.
Optional privacy choices can be changed through .
Send privacy requests to: info@mslholidays.com .
MSL Holidays will normally respond without undue delay and within one month. This period may be extended where a request is particularly complex or where several requests have been submitted. You will be informed when an extension is necessary.
We may request information that is reasonably necessary to confirm your identity. Privacy rights are not absolute, and a request may be restricted where data must be retained because of a legal obligation, an existing contract or a legal claim.
You may also submit a complaint to the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens:
Submit a privacy complaint to the Autoriteit Persoonsgegevens
9. Security
MSL Holidays uses technical and organisational measures intended to protect personal data against loss, misuse, unauthorised access, alteration and disclosure.
Measures may include:
- HTTPS encryption during transmission;
- access restrictions and authentication controls;
- secure password hashing;
- CSRF and form-abuse protection;
- security logging and software maintenance;
- payment processing through Stripe;
- limiting access to people and providers who need the information.
No website, storage system or internet transmission can guarantee absolute security.
10. Automated processing and fraud prevention
MSL Holidays does not itself use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects.
Stripe and other payment providers may use automated systems to identify suspected fraud, assess transactions or protect their services. Their own privacy information explains how those systems operate and which rights may apply.
11. Children
The website and shop are not intentionally directed at children under 16, and MSL Holidays does not knowingly request that children under 16 create an account or place an order independently.
If you believe that a child has provided personal data without appropriate permission or involvement from a parent or guardian, contact us so that the situation can be reviewed and the data removed where required.
12. Cookies and optional services
Necessary storage is used to operate and secure the website, forms, sessions, accounts, shopping cart and checkout. Optional functionality, external media and affiliate widgets are only activated according to your privacy choices.
Detailed information about the categories, providers and storage periods is available in the Cookie Policy.
You can reopen the privacy controls at any time: .
13. Changes to this Privacy Policy
This policy may be updated when the website, online shop, service providers, processing activities or legal requirements change.
The latest version and its update date will be published on this page. Material changes may also be communicated through the website or by another appropriate method.