1. Introduction & Who We Are
Karibu Origins (“we”, “us”, “our”) is a tailor-made travel company specialising in Uganda and East African journeys. We are the data controller responsible for your personal information collected through our website at karibuorigins.com, our inquiry forms, email communications, and any other touchpoints through which you engage with us.
We take our obligations under the EU General Data Protection Regulation (GDPR), the UK GDPR, the Uganda Data Protection and Privacy Act 2019, and other applicable international data protection laws seriously. This Privacy Policy applies to all individuals whose personal data we process, including prospective travellers, confirmed guests, newsletter subscribers, and website visitors from any country.
Contact details: Karibu Origins · Email: info@karibuorigins.com · Website: karibuorigins.com
2. Personal Data We Collect
We collect personal data through various channels. The categories of data we may collect include:
2.1 Data You Provide Directly
- Identity data: Full name, title, date of birth, nationality, passport details (where required for permit applications)
- Contact data: Email address, telephone number, postal address, WhatsApp number
- Travel preferences: Preferred travel dates, group size, accommodation preferences, dietary requirements, accessibility needs, special occasions
- Financial data: Budget range (we do not store full payment card details — payments are processed by PCI-DSS compliant third-party processors)
- Health data: Medical conditions or mobility requirements relevant to your safari safety (processed only with your explicit consent)
- Communications: Records of correspondence via email, contact forms, WhatsApp, or telephone
- Marketing preferences: Your consent to receive newsletters and travel inspiration
2.2 Data Collected Automatically
- Technical data: IP address, browser type and version, device type, operating system, time zone
- Usage data: Pages visited, time on site, referral source, click behaviour, session duration
- Cookie data: See our Cookie Policy for full details
2.3 Data from Third Parties
- Analytics providers (e.g. Google Analytics 4) — aggregated and anonymised where possible
- Referral partners and travel agents who introduce clients to us
- Publicly available sources such as LinkedIn (for business contacts only)
3. How We Use Your Data
We use your personal data for the following purposes:
| Purpose | Data Used |
|---|---|
| Responding to travel enquiries and designing bespoke itineraries | Identity, contact, travel preferences |
| Processing bookings, permits and reservations | Identity, contact, passport details, health data |
| Communicating pre-departure information and travel updates | Identity, contact |
| Processing payments and managing accounts | Identity, contact, financial data |
| Sending newsletters and travel inspiration (with consent) | Identity, contact, marketing preferences |
| Improving our website and services through analytics | Technical, usage, cookie data |
| Complying with legal obligations (e.g. tax, anti-money laundering) | Identity, financial data |
| Protecting against fraud and ensuring website security | Technical, usage data |
We will never sell your personal data to third parties. We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.
4. Legal Basis for Processing
Under GDPR and UK GDPR, we rely on the following lawful bases:
- Contract performance (Article 6(1)(b)): Processing necessary to fulfil your booking or respond to your pre-contractual enquiry
- Legitimate interests (Article 6(1)(f)): Improving our services, fraud prevention, direct marketing to existing clients (balanced against your rights)
- Consent (Article 6(1)(a)): Newsletter subscriptions, non-essential cookies, processing of health/special category data
- Legal obligation (Article 6(1)(c)): Compliance with financial, tax and anti-money laundering regulations
- Vital interests (Article 6(1)(d)): In emergency situations where your safety requires us to share information with medical or emergency services
6. International Data Transfers
As an international travel company serving clients worldwide, your data may be transferred to and processed in countries outside the European Economic Area (EEA) and UK, including Uganda, Kenya, Rwanda, and countries where our technology providers operate.
Where we transfer data outside the EEA or UK, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- UK International Data Transfer Agreements (IDTAs)
- Adequacy decisions where applicable
- Binding Corporate Rules where relevant
7. Data Retention
We retain personal data only for as long as necessary for the purposes set out in this policy:
- Booking and guest records: 7 years from the date of travel (to comply with financial and legal obligations)
- Enquiry records (non-converted): 2 years from last contact
- Marketing consent records: Until you withdraw consent, plus 1 year for record-keeping
- Website analytics data: 26 months (Google Analytics default, anonymised)
- Correspondence: 3 years from last interaction
When data is no longer required, it is securely deleted or anonymised in accordance with our data disposal procedures.
8. Your Rights
Under GDPR, UK GDPR and applicable laws, you have the following rights:
Right of Access
Request a copy of the personal data we hold about you (Subject Access Request)
Right to Rectification
Request correction of inaccurate or incomplete personal data
Right to Erasure
Request deletion of your personal data where there is no compelling reason for continued processing
Right to Restriction
Request that we restrict processing of your data in certain circumstances
Right to Portability
Receive your data in a structured, machine-readable format and transfer it to another controller
Right to Object
Object to processing based on legitimate interests or for direct marketing purposes
Right to Withdraw Consent
Withdraw consent at any time where processing is based on consent, without affecting prior processing
Right to Lodge a Complaint
Complain to your national supervisory authority (e.g. ICO in the UK, PDPO in Uganda)
To exercise any of these rights, please contact us at info@karibuorigins.com. We will respond within 30 days. We may need to verify your identity before processing your request.
10. Security Measures
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or damage. These measures include:
- TLS/SSL encryption for all data transmitted via our website
- Access controls limiting data access to authorised personnel only
- Regular security assessments and staff training
- Secure data storage with reputable, compliant cloud providers
- Incident response procedures for data breaches
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected individuals without undue delay.
11. Children's Privacy
Our website is not directed at children under the age of 16. We do not knowingly collect personal data from children without verifiable parental or guardian consent. Where we process data relating to children as part of a family booking, we do so only with the consent of the parent or guardian and solely for the purpose of fulfilling the travel arrangements.
If you believe we have inadvertently collected data from a child without appropriate consent, please contact us immediately at info@karibuorigins.com.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, notify you by email.
We encourage you to review this policy periodically. Your continued use of our website and services after any changes constitutes your acceptance of the updated policy.
13. Contact & Complaints
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Privacy Lead:
If you are based in the UK or EU and are not satisfied with our response, you have the right to lodge a complaint with your national data protection supervisory authority:
- UK: Information Commissioner's Office (ICO) — ico.org.uk
- EU: Your local Data Protection Authority (DPA)
- Uganda: Personal Data Protection Office (PDPO) — pdpo.go.ug
Related Policies