hero-image

Data Protection Policy

1. Introduction

Master Himalaya Treks and Expedition is committed to protecting the privacy and security of personal data. This Data Protection Policy outlines our practices for collecting, using, and protecting personal data in compliance with relevant data protection laws.

 

2. Scope

This policy applies to all employees, contractors, and partners of the Company, as well as to all personal data processed by the Company, whether in electronic or physical form.

3. Data Collection

We collect personal data only for specified, explicit, and legitimate purposes. The types of data we may collect include:

  • Contact Information: Name, address, phone number, email address.
  • Identification Information: Passport details, national ID numbers.
  • Payment Information: Credit card details, bank account information.
  • Health Information: Medical history, allergies, emergency contacts.
  • Travel Information: Itineraries, travel preferences, accommodation details.

4. Legal Basis for Processing

We process personal data based on one or more of the following legal grounds:

  • Consent of the data subject.
  • Performance of a contract with the data subject.
  • Compliance with a legal obligation.
  • Legitimate interests pursued by the Company.

5. Data Usage

Personal data will be used only for the purposes for which it was collected. These purposes include:

  • Organizing and managing treks and expeditions.
  • Communicating with clients regarding their bookings.
  • Processing payments and refunds.
  • Ensuring the safety and security of our clients.
  • Complying with legal and regulatory requirements.

6. Data Protection Principles

We adhere to the following data protection principles:

  • Lawfulness, Fairness, and Transparency: We process data lawfully, fairly, and transparently.
  • Purpose Limitation: We collect data for specified, legitimate purposes and do not process it further in ways incompatible with those purposes.
  • Data Minimization: We collect only the data necessary for the intended purposes.
  • Accuracy: We ensure that data is accurate and kept up to date.
  • Storage Limitation: We retain data only as long as necessary for the purposes for which it was collected.
  • Integrity and Confidentiality: We protect data against unauthorized or unlawful processing, accidental loss, destruction, or damage.

7. Data Security

We implement appropriate technical and organizational measures to ensure data security, including:

  • Access controls to restrict data access to authorized personnel.
  • Encryption of sensitive data.
  • Regular security audits and risk assessments.
  • Employee training on data protection best practices.

8. Data Subject Rights

Data subjects have the following rights regarding their personal data:

  • Access: The right to request access to their personal data.
  • Rectification: The right to request correction of inaccurate data.
  • Erasure: The right to request deletion of their data.
  • Restriction: The right to request restriction of data processing.
  • Portability: The right to receive their data in a structured, commonly used format.
  • Objection: The right to object to data processing based on legitimate interests or direct marketing.

9. Data Breach Response

In the event of a data breach, we will:

  • Notify the relevant supervisory authority within 72 hours.
  • Inform affected data subjects if the breach is likely to result in a high risk to their rights and freedoms.
  • Take steps to mitigate the breach and prevent future occurrences.

10. Third-Party Data Sharing

We do not share personal data with third parties except where necessary for the provision of our services or as required by law. Any third parties with whom we share data must agree to our data protection standards.

11. International Data Transfers

If personal data is transferred outside the country, we ensure that appropriate safeguards are in place to protect the data in compliance with applicable data protection laws.

12. Policy Review and Updates

 

This policy is reviewed annually and updated as necessary to ensure ongoing compliance with data protection laws and best practices.

13. Contact Information

For questions or concerns about this policy or data protection practices, please contact:

  • Data Protection Officer
  • Email: info@masterhimalaya.com
  • Address: Kathmandu, Thamel

14. Policy Acceptance

 

All employees, contractors, and partners of the Company are required to read, understand, and comply with this 

Data Protection Policy.

By implementing this Data Protection Policy, Master Himalaya Treks and Expedition commits to safeguarding personal data and upholding the privacy rights of all individuals we serve.