Legal

Privacy Policy

This page explains how BluStarJourneys handles personal information submitted through this website in accordance with the General Data Protection Regulation (GDPR).

1. Data controller

BluStarJourneys is responsible for the personal information submitted through this website. Privacy enquiries and requests may be sent to info@blustarjourneys.com.

2. Information we collect

When you use the contact form, we may collect your name, company or agency, email address, telephone number, destination, group information, proposed dates and the contents of your message.

3. Purpose and legal basis

We use the information to review your request, communicate with you and prepare or discuss a potential travel proposal or business relationship. Processing is based on your consent and, where applicable, on steps requested by you before entering into a contract.

4. Recipients and service providers

We do not sell personal information. Information may be processed by the website hosting and email providers and may be shared with travel suppliers only when necessary to respond to or fulfil a request, subject to appropriate confidentiality and data-protection safeguards.

5. International transfers

Where a service provider or supplier processes information outside the European Economic Area, BluStarJourneys will seek to use an appropriate legal transfer mechanism and suitable safeguards whenever required by law.

6. Retention

Information is retained only for as long as reasonably necessary to respond to the request, manage any resulting business relationship and comply with applicable legal obligations.

7. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction or portability of your personal information, object to certain processing or withdraw consent. You may also lodge a complaint with the competent supervisory authority, including Portugal’s Comissão Nacional de Proteção de Dados (CNPD).

8. Cookies and technical data

The website uses a functional language-preference cookie and a temporary, strictly necessary session cookie to protect the contact form. It does not install advertising or analytics cookies. The hosting provider may process essential technical logs to deliver and secure the website.

9. Form security and minimisation

The contact form uses anti-spam controls, origin validation, a security token and temporary rate limiting. The website does not create a marketing profile or store submitted form content in a local database.

10. Security

Reasonable technical and organisational measures are used to protect information submitted through the website. No internet transmission can be guaranteed to be completely secure.

11. Updates

This policy may be updated to reflect legal, operational or technical changes. Last updated: 4 August 2026.