Legal
Privacy Policy
This page explains how BluStarJourneys handles personal information submitted through this website in accordance with the General Data Protection Regulation (GDPR).
1. Data controller
BluStarJourneys is responsible for the personal information submitted through this website. Privacy enquiries and requests may be sent to info@blustarjourneys.com.
2. Information we collect
When you use the contact form, we may collect your name, company or agency, email address, telephone number, destination, group information, proposed dates and the contents of your message.
3. Purpose and legal basis
We use the information to review your request, communicate with you and prepare or discuss a potential travel proposal or business relationship. Processing is based on your consent and, where applicable, on steps requested by you before entering into a contract.
4. Recipients and service providers
We do not sell personal information. Information may be processed by the website hosting and email providers and may be shared with travel suppliers only when necessary to respond to or fulfil a request, subject to appropriate confidentiality and data-protection safeguards.
5. International transfers
Where a service provider or supplier processes information outside the European Economic Area, BluStarJourneys will seek to use an appropriate legal transfer mechanism and suitable safeguards whenever required by law.
6. Retention
Information is retained only for as long as reasonably necessary to respond to the request, manage any resulting business relationship and comply with applicable legal obligations.
7. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction or portability of your personal information, object to certain processing or withdraw consent. You may also lodge a complaint with the competent supervisory authority, including Portugal’s Comissão Nacional de Proteção de Dados (CNPD).
8. Cookies and technical data
The website uses a functional language-preference cookie and a temporary, strictly necessary session cookie to protect the contact form. It does not install advertising or analytics cookies. The hosting provider may process essential technical logs to deliver and secure the website.
9. Form security and minimisation
The contact form uses anti-spam controls, origin validation, a security token and temporary rate limiting. The website does not create a marketing profile or store submitted form content in a local database.
10. Security
Reasonable technical and organisational measures are used to protect information submitted through the website. No internet transmission can be guaranteed to be completely secure.
11. Updates
This policy may be updated to reflect legal, operational or technical changes. Last updated: 4 August 2026.