Last updated: 2026-05-10 · v1
Privacy Policy
Effective Date: 2026-05-11 Last Updated: 2026-05-11 Version: 1.0
This Privacy Policy explains how GRANDROUTES GLOBAL PTE. LTD. ("Gvoya", "we", "us") collects, uses, discloses, and protects your personal data when you use the Gvoya AI voyage concierge services (the "Service"). It is designed to comply with the EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018 and UK GDPR, the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), the Singapore Personal Data Protection Act 2012 (PDPA), the People's Republic of China Personal Information Protection Law (PIPL), Brazil's Lei Geral de Proteção de Dados (LGPD), Canada's PIPEDA and Quebec Law 25, Japan's APPI, Australia's Privacy Act 1988, and other applicable privacy frameworks.
1. Identity of the Controller
GRANDROUTES GLOBAL PTE. LTD. (UEN: [TBD]), a company incorporated in the Republic of Singapore, is the controller of personal data processed through the Service.
- Data Protection Officer (DPO): dpo@gvoya.com
- EU/EEA Representative (Art. 27 GDPR): [appointed; contact via dpo@gvoya.com]
- UK Representative: [appointed; contact via dpo@gvoya.com]
- General privacy contact: privacy@gvoya.com
2. Categories of Personal Data We Collect
| Category | Examples | Source |
|---|---|---|
| Identification & Account | Name, email, phone, password hash, optional date of birth | You |
| Booking & Travel | Passenger names, passport numbers (AES-256-GCM encrypted at rest), itinerary, dietary/medical needs you submit | You |
| Payment | Last-4 digits of card, transaction reference (full card never stored on our systems) | Payment processor |
| AI Conversation | Your messages with the AI Concierge, derived intent, recommended voyages, click-through outcomes | You + automated processing |
| Geolocation | Approximate country derived from IP, optional precise location if you grant browser permission | Inferred / you |
| Device & Usage | IP address (truncated to /24 for IPv4 / /48 for IPv6 in retention), browser/user-agent, page views, referer | Automated |
| Cookies & Identifiers | First-party cookies (gvoya_anon_id, gvoya_geo, language, session token), analytics cookies if accepted | Automated / your consent |
| Compliance | Consent records (document slug, version, hash, scope, IP truncated, UA, timestamp), DSAR submissions | Automated / you |
We do not intentionally collect special categories of personal data under Art. 9 GDPR (e.g., health, race, religion, sexual orientation) unless you voluntarily provide such information in connection with a booking (e.g., dietary or accessibility needs you choose to disclose to the operator). Where you do, we process it on the basis of your explicit consent and only to fulfill the booking.
3. Lawful Basis for Processing (GDPR / UK GDPR)
| Purpose | Lawful basis |
|---|---|
| Account creation, authentication, account management | Contract performance — Art. 6(1)(b) |
| Processing bookings, AI Concierge recommendations, customer support | Contract performance — Art. 6(1)(b) |
| Marketing communications (newsletter, promotions) | Consent — Art. 6(1)(a); withdrawable at any time |
| Fraud prevention, account security, defense logging, sanction screening | Legitimate interests — Art. 6(1)(f); we balance against your rights |
| Tax records, accounting, legal claims | Legal obligation — Art. 6(1)(c) |
| Service improvement (de-identified analytics, AI quality measurement) | Legitimate interests — Art. 6(1)(f) |
For PIPL (China), our legal bases include separate consent for each cross-border transfer scenario, contract performance, and legal obligation under Art. 13 PIPL. For PDPA (Singapore), our processing relies on consent, contractual necessity, and the legitimate-interests exceptions in the First Schedule. For CCPA/CPRA (California), we rely on the "business purpose" disclosures in §1798.140(e).
4. How We Use Your Data
a. To deliver the Service: process bookings, route AI Concierge requests to inference providers, return personalized recommendations. b. To communicate: confirm bookings, send pre-departure information, deliver service notices, respond to support inquiries. c. To personalize: remember preferences (destination, cabin type, budget) so the AI Concierge can return better matches in future conversations. You may clear this memory at any time via /account/settings. d. To comply: maintain Consent records (GDPR Art. 7, PIPL Art. 14 separate consent), respond to Data Subject Access Requests, satisfy tax and accounting law. e. To protect: detect and prevent fraud, abuse, scraping, brute-force attacks (DefenseEvent log with hash chain), screen counterparties against OFAC/UN/EU/UK/CN sanction lists. f. To improve: analyze de-identified usage patterns to improve the AI Concierge and Service. We do not use your raw conversation logs to train AI models without separate explicit consent.
5. Disclosures to Third Parties
We share personal data with the following categories of recipients on a need-to-know, contractually-restricted basis:
| Recipient | Role | Location |
|---|---|---|
| Suppliers (cruise lines, yacht operators) | Independent controllers for the booking | Various |
| Anthropic, PBC | Processor — AI inference | United States |
| Cloudflare, Inc. | Processor — CDN, R2 storage, DDoS | United States / Global |
| Neon Inc. | Processor — managed PostgreSQL | United States / EU |
| Resend, Inc. | Processor — transactional email | United States |
| Stripe / Alipay / WeChat Pay | Independent controllers — payment | Various |
| Sentry / PostHog | Processor — error & analytics (de-identified where possible) | United States / EU |
| Google / WeChat | Processor (where applicable) — OAuth identity | Various |
| Government, regulators, courts | When required by law or valid legal process | Various |
We have entered into Data Processing Agreements (DPAs) and Standard Contractual Clauses (EU SCC 2021/914 Module Two and Module Three; UK International Data Transfer Addendum) where applicable. See our DPA and Sub-processor List.
We do not sell your personal information for monetary consideration, as defined under CCPA §1798.140(t). We do not "share" personal information for cross-context behavioral advertising under §1798.140(ah).
6. International Transfers
Your data may be transferred to and processed in jurisdictions outside your country of residence, including Singapore, the European Union, the United States, mainland China, and other markets where Gvoya operates. We rely on the following transfer mechanisms:
- EU/EEA → third countries: Standard Contractual Clauses (Commission Decision 2021/914), supplementary measures (encryption in transit, encryption at rest with AES-256-GCM, contractual override of US executive-branch access where applicable), Transfer Impact Assessments per Schrems II.
- UK → third countries: UK International Data Transfer Addendum 2022.
- China → outside China: Separate consent under PIPL Art. 39, Standard Contract for Cross-Border Transfer of Personal Information (CAC) where applicable, and Cybersecurity Review for sensitive volumes.
- All transfers: Encrypted in transit (TLS 1.2+) and at rest (AES-256-GCM for sensitive fields).
7. Retention
We retain personal data only as long as necessary for the purposes described:
| Data | Retention |
|---|---|
| Account data | Until you delete your account (subject to legal-hold exceptions) |
| Booking & financial records | Seven (7) years from completion (tax / audit requirement) |
| AI conversation logs | Two (2) years from creation, then anonymized |
| Consent records | Seven (7) years from acceptance, then anonymized (ipAddressTrunc, userAgent, anonId cleared) |
| Marketing consents | Until you withdraw, then immediately deleted from active marketing systems |
| Server logs | Ninety (90) days |
| DefenseEvent (security incidents) | Two (2) years for evidence preservation |
Anonymization is enforced automatically by the legal-retention worker cron each day at 03:00 UTC.
8. Your Rights
Depending on your jurisdiction, you have some or all of the following rights:
| Right | Description |
|---|---|
| Access | Request a copy of personal data we hold about you (GDPR Art. 15, CCPA §1798.110, PIPL Art. 45) |
| Rectification | Correct inaccurate or incomplete data (GDPR Art. 16, PIPL Art. 46) |
| Erasure / "right to be forgotten" | Delete your data, subject to legal-retention exceptions (GDPR Art. 17, CCPA §1798.105, PIPL Art. 47) |
| Restriction | Restrict processing in specific circumstances (GDPR Art. 18, PIPL Art. 44) |
| Portability | Receive your data in a structured, machine-readable format (GDPR Art. 20, CCPA §1798.130(a)(2)) |
| Object | Object to processing based on legitimate interests, including direct marketing (GDPR Art. 21) |
| Withdraw consent | Withdraw consent at any time, including for cookies and AI training data (GDPR Art. 7(3), PDPA s.16, PIPL Art. 15) |
| Not be subject to solely automated decisions | Object to automated decision-making with legal/significant effects (GDPR Art. 22, PIPL Art. 24, LGPD Art. 20) |
| Non-discrimination | Equal price and service if you exercise rights (CCPA §1798.125) |
To exercise any right, submit a request via /account/legal-requests/new or email privacy@gvoya.com. We respond within thirty (30) days under GDPR / PIPL / PDPA / PIPEDA, forty-five (45) days under CCPA, fifteen (15) days under LGPD. We may extend by an additional thirty (30) days for complex requests with notice. You also have the right to lodge a complaint with your local supervisory authority (e.g., your EU Data Protection Authority, the UK ICO, the Singapore PDPC, the Cyberspace Administration of China).
9. Children
The Service is intended for individuals aged 18 or older. We do not knowingly collect personal data from children under 13 (or 16 in the EU/EEA). If you believe a child has provided us with personal data, contact privacy@gvoya.com and we will delete the data promptly.
10. Cookies and Similar Technologies
Our use of cookies, web beacons, and similar technologies is described in detail in the Cookie Policy. You can manage your cookie preferences via the cookie banner or your account settings.
11. Security
We implement technical and organizational measures appropriate to the risk, including:
- TLS 1.2+ for all data in transit
- AES-256-GCM encryption for passport numbers and other high-sensitivity fields at rest
- Bcrypt password hashing (cost factor 12)
- JWT session tokens with 8-hour expiry
- Truncated IP storage (/24 IPv4, /48 IPv6) for compliance evidence
- Two-tier rate limiting and honeypot routes (DefenseEvent system) to deter automated attacks
- Hash-chained audit logs that detect tampering
- Annual penetration testing and quarterly internal reviews
- Sub-processors bound by DPAs and SCCs
In the event of a personal-data breach posing a high risk to your rights, we will notify you within seventy-two (72) hours of awareness, in compliance with GDPR Art. 33-34 and analogous obligations.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes (those affecting your rights or how we use data) will be announced at least thirty (30) days before they take effect via email and the in-app reaccept banner. Continued use after the effective date constitutes acceptance. Each version is hash-stamped and your acceptance recorded for compliance.
13. Contact
For any privacy-related inquiry, please contact:
Data Protection Officer: dpo@gvoya.com Privacy team: privacy@gvoya.com EU/EEA Representative (Art. 27): dpo@gvoya.com UK Representative: dpo@gvoya.com
GRANDROUTES GLOBAL PTE. LTD. 25 SEAH STREET, #02-01, SINGAPORE 188381