Skip to main content
Beyond Routes logoBeyond Routes
NLEN

Privacy policy

Beyond Routes Privacy Notice
Last updated: 3 July 2026

A special journey often begins often with sharing plans, preferences and personal details. That calls for trust. Beyond Routes therefore handles the information you provide to us with care.

In this privacy notice, we explain in clear language which personal data we collect, why we do so, who we share data with and what choices and rights you have. This privacy notice applies to our website, our communications and the trips and other services we offer.

1. Who is responsible for your data?
Beyond Routes is responsible for processing your personal data.
Our details are:
Company name: Beyond Routes
Trading name: Beyond Routes
Address: Curacaostraat 86-3, 1058 CA Amsterdam
Chamber of Commerce number: 96144599
Email address: info@beyondroutes.nl
Telephone number:
Do you have a question about your personal data or would you like to exercise a privacy right? Please contact us at info@beyondroutes.nl

2. Which personal data do we process?
The data we process depends on your contact with us and the service you purchase from us.
We may process, among other things, the following data:

  • your name, address, town or city and contact details
  • your date of birth, gender and nationality
  • details of your fellow travellers
  • information about your travel wishes, travel period, budget and preferences
  • passport, identity and visa details
  • driving licence details
  • flight and transport details
  • details of an emergency contact
  • invoice, payment and transaction details
  • correspondence via email, telephone, WhatsApp, social media or other channels
  • information about dietary requirements, allergies, mobility or health, insofar as this is necessary to organise the trip properly and safely
  • data you enter via forms on our website
  • technical information about your use of our website, such as your browser type, device and cookie preferences
  • other information that you provide to us and that is relevant to your enquiry or trip.

We only ask for data that we genuinely need. Therefore, do not provide us with medical, financial or other sensitive information when it is not necessary for your trip or enquiry.

a privacy right? Please contact us at info@beyondroutes.nl

3. What do we use your personal data for?
Handling an enquiry or initial consultation
When you contact us or schedule a travel consultation, we process your name, contact details and the information in your enquiry. This enables us to answer your question, hold an introductory conversation and prepare a suitable travel proposal. We process this data because it is necessary to take steps at your request before potentially entering into an agreement. In some cases, we process data on the basis of our legitimate interest in responding to enquiries carefully and managing our communications.

Providing a trip or other service
When you book a trip or advisory service with us, we process the data needed to perform the agreement. This may include putting the trip together, making reservations, arranging transport, providing travel information and assisting with changes or problems.
Without certain information, we cannot reserve or provide the trip or service. For example, when an airline, accommodation provider, rental company or other supplier requires your official name or passport details, we must receive this information to make the reservation.

Making reservations with suppliers
To provide your trip, we may share data with parties involved in the trip. These include:

  • destination management companies, or DMCs
  • accommodation providers and campsites
  • car hire companies and transfer companies
  • airlines and other carriers;
  • guides, activity providers and national parks
  • local agents
  • visa and other support service providers.

We only share the information the relevant party needs to carry out its part of the trip.

Processing special requests and health information
Sometimes we need information about allergies, dietary requirements, reduced mobility or a medical condition, for example. This may be necessary to arrange suitable accommodation, meals, activities or other facilities. As this may be sensitive information, we only process it when necessary and when there is a valid legal basis for doing so. Where necessary, we will ask for your explicit consent. You can withdraw consent you have given at any time. Please note, however, that without certain information we may be unable to arrange suitable facilities.

Processing payments and administration
We process invoicing and payment details to send and process invoices, check payments, maintain our records and comply with tax and other legal obligations.

Staying in touch during and after the trip
We use your contact details to provide practical information about your trip, answer questions and offer assistance with changes, emergencies or complaints. Afterwards, we may contact you to ask how you experienced the trip. You are, of course, not obliged to take part.

Sending newsletters and offers
When you subscribe to our newsletter, we use your name and email address to send you news, travel inspiration and offers from Beyond Routes. We do this on the basis of your consent, unless we are legally permitted to inform existing customers about similar services of our own. You can unsubscribe at any time using the unsubscribe link at the bottom of every mailing or by contacting us. Withdrawing your consent does not affect messages that were lawfully sent before you unsubscribed.

Improving our website and services
We may use data about how our website is used to understand which pages are visited, whether the website is working properly and how we can improve our services. Depending on the type of cookies and analytical tools, we do this on the basis of your consent or our legitimate interest. More information can be found under the heading ‘Cookies’.

Protecting our interests and complying with the law
We may process personal data when necessary to:

  • prevent fraud or misuse
  • handle complaints and disputes
  • establish, exercise or defend our rights
  • comply with obligations imposed by regulators, tax authorities or other competent authorities
  • protect the safety of our customers, systems and organisation.

4. What are the legal bases for processing data?
Under the GDPR, we may only process personal data where there is a valid reason to do so. Beyond Routes may process personal data on the basis of:

  • performance of a contract, for example to organise your trip
  • steps prior to entering into an agreement, for example to prepare a travel proposal
  • a legal obligation, for example for our financial administration
  • your consent, for example for a newsletter or certain sensitive data
  • a legitimate interest, for example for sound business operations, security, customer service and handling complaints.

When we rely on a legitimate interest, we weigh our interest against your privacy interest.

5. Who do we share personal data with?
We do not sell your personal data.
We may share data with parties needed to provide our services or enable our organisation to operate. These may include:

  • DMCs and local travel partners
  • accommodation providers, carriers, rental companies, guides and activity providers
  • payment service providers
  • our bookkeeper, accountant or administrative service providers
  • providers of CRM, booking and travel planning software
  • providers of email, cloud storage, hosting and website management
  • providers of newsletter, analytics and marketing software, insurers, guarantee funds or assistance organisations
  • legal advisers and debt collection service providers
  • government authorities and regulators, when we are legally required to provide data.

When a service provider processes personal data solely on our behalf, we make the necessary arrangements in a data processing agreement where required. We also expect other recipients to handle personal data carefully and in accordance with applicable privacy legislation.

6. Data outside the European Economic Area
Beyond Routes organises trips to countries outside the European Economic Area (EEA), including countries in Africa. To carry out your trip, it may be necessary to provide personal data to a DMC, accommodation provider, carrier or other local supplier in the destination country.

The privacy legislation in these countries may not always provide the same level of protection as within the EEA. We therefore limit the data shared to what is necessary and, where required and possible, take appropriate measures to protect personal data.
Some software providers may also process data outside the EEA. In that case, we check that a valid transfer mechanism and appropriate safeguards are used, such as an adequacy decision or approved standard contractual clauses.
You can request more information about a specific international transfer via info@beyondroutes.nl.

7. How long do we retain personal data?
We do not retain personal data for longer than necessary for the purpose for which it was collected. Sometimes we must retain data for longer due to a legal obligation, an ongoing dispute or the possibility that a legal claim may still arise.
In principle, we apply the following retention periods:

  1. Individual enquiries that do not result in a booking: up to 12 months after the last contact
  2. Quotes and travel proposals without a booking: [term]
  3. Booking and customer records: [term] after the end of the trip
  4. Passport and identity details: for as short a time as possible and, in principle, deleted as soon as they are no longer needed for the reservation or trip, unless longer retention is necessary
  5. Medical data, dietary requirements and other sensitive travel information: in principle, deleted [term] after the end of the trip, unless there is a valid reason to retain it for longer
  6. Financial administration and invoices: for the applicable statutory tax retention period
  7. Correspondence about complaints or disputes: for as long as necessary to handle them and for the applicable limitation period
  8. Newsletter data: until you unsubscribe, supplemented by a limited record of your unsubscription to prevent you from receiving unwanted messages again
  9. Cookie and analytics data: in accordance with the periods stated in our cookie settings or cookie policy.

When a retention period has expired, we delete or anonymise the data.

8. How do we protect personal data?
We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access and unwanted disclosure.
Depending on the nature of the data, we use, for example:

  • secure devices and accounts
  • strong passwords and two-step verification where possible
  • restricted access to customer data
  • secure internet and website connections
  • up-to-date software and security updates
  • reliable hosting, email and software providers
  • back-ups and access management
  • agreements with suppliers that process personal data on our behalf
  • procedures for security incidents and data breaches.

No digital environment is entirely without risk. We therefore regularly review our working methods and security.
9. Email, WhatsApp and social media

You can communicate with us by email, telephone, WhatsApp and social media. Messages you send through these channels may contain personal data and are processed to handle your enquiry or trip.
This communication also takes place via the systems of the relevant provider. The provider’s privacy terms also apply to your use of these platforms.
Where possible, do not share passport copies, medical documents or other highly sensitive information via WhatsApp, social media or standard email, unless we have agreed an appropriate and secure method for doing so.
10. Cookies
Our website uses cookies and similar technologies. Cookies are small text files that may be stored on your device during your visit.
Necessary cookies
We use necessary cookies to ensure that the website works properly and securely and, for example, to remember your cookie preferences. No consent is required for these cookies.
Google Analytics
We use Google Analytics 4 (GA4) from Google to gain insight into the use of our website. This allows us to see, for example, how many people visit our website, which pages are viewed, what type of device visitors use to access the website and how visitors navigate through it.
We use this information to improve the website and our services. We do not use GA4 to identify visitors directly.
We have entered into a data processing agreement with Google.
We do not share names, email addresses or other directly identifying customer data with GA4.
Google Signals is disabled.
Ad personalisation and advertising features are disabled.
GA4 is not linked to Google Ads.
The retention period for user and event data is set to 14 months.
The data collected is not used for personalised advertising.
Google may process data on servers outside the European Economic Area. Further information about the processing and protection of data can be found in Google’s privacy policy.
We have configured GA4 to limit the impact on your privacy as much as possible. We therefore do not ask for consent for these limited analytics cookies.

11. Links and websites of other parties
Our website may contain links to websites of, for example, accommodation providers, carriers, tourism organisations and other travel partners. Beyond Routes is not responsible for the way these parties process personal data.
We recommend that you read the privacy statement of the relevant website before leaving personal data there

12. Data relating to other travellers

Are you providing us with the details of a fellow traveller or an emergency contact? If so, make sure that this person knows that you are sharing their details with Beyond Routes and that this privacy statement applies.
Do not share more data than necessary.

13. Children’s data
A trip may also include underage travellers. We process their personal data only insofar as necessary to organise and carry out the trip.
Bookings and communication generally take place via a parent, guardian or another authorised adult. We do not knowingly seek marketing consent directly from young children.

14. Automated decision-making
Beyond Routes does not make decisions that have significant consequences for you and are based solely on the automated processing of personal data.
If this changes in the future, we will inform you clearly in advance.

15. Your privacy rights
Depending on the situation, you have the right to:
know which personal data we process about you;
access your personal data;
have incorrect or incomplete data corrected;
have data deleted;
have the processing of your data restricted;
object to processing;
receive your data in a portable format;
withdraw consent you have given;
object to direct marketing;
not be subject to certain decisions based solely on automated processing.
You can send a request to info@beyondroutes.nl. Please state as clearly as possible what you are asking us to do.
To prevent someone else from requesting your data, we may ask you to confirm your identity in an appropriate manner. We will not ask for more information than necessary.
Some rights are not absolute. For example, we may be unable to delete certain data when we are legally required to retain it or when it is still needed for a legal dispute.
As a rule, we will respond to your request within one month. If a request is complex or if there are many requests, this period may be extended in accordance with the GDPR. In that case, we will inform you.

16. Submitting a complaint
Do you have a question or complaint about the use of your personal data? If so, please contact us first, preferably via [privacy e-mailadres]. We are happy to work with you to find a solution.
You also have the right to submit a complaint to the Dutch Data Protection Authority. More information about this can be found on the website of the Dutch Data Protection Authority.

17. Changes to this privacy statement
Our services, website and systems we use may change. We may therefore amend this privacy statement from time to time.
The most recent version is always available on our website. At the top of the statement, we state when it was last amended. We will inform you separately of significant changes where necessary.