Zoe's Cruise and Tours LLC
EU–US Data
Compliance
How we respect GDPR and CCPA standards and handle international data transfers responsibly.
1. Our Commitment
Zoe's Cruise and Tours LLC is committed to protecting the privacy and rights of all individuals who interact with zoescruises.com, regardless of their location. Although we are a small operator, we believe transparency and accountability in data handling are non-negotiable.
We align our data practices with the principles of:
GDPR
General Data Protection Regulation — applicable to individuals in the European Economic Area (EEA)
CCPA
California Consumer Privacy Act — applicable to residents of California, USA
2. Data We Collect and Why
We collect minimal personal data. Please refer to our Privacy Policy for full details. In summary:
| Data Type | Source |
|---|---|
| Name & Email | Contact Form |
| Anonymised analytics | Google Analytics |
3. GDPR Compliance (EEA Residents)
If you are located in the European Economic Area, you benefit from rights under GDPR including the right to access, correct, delete, restrict, or port your data. See our Privacy Policy for how to exercise these rights.
Legal bases for processing:
Legitimate interest
Analytics data used to improve Site performance
Consent / Legitimate interest
Contact Form data used to respond to your enquiry
We do not rely on consent as the basis for analytics — we rely on legitimate interest, with appropriate safeguards (IP anonymisation enabled).
4. CCPA Compliance (California Residents)
As a California-based LLC, we take our obligations under the California Consumer Privacy Act seriously. If you are a California resident, you have the right to:
- Know what personal information we collect and how it is used
- Request deletion of your personal information
- Opt out of the sale of your personal information (we do not sell personal information)
To submit a request, contact us at info@zoescruises.com. We will respond within 45 days as required by CCPA.
5. International Data Transfers to the United States
Some of our third-party service providers — most notably Google Analytics — are based in or may transfer data to the United States. We ensure all such transfers comply with applicable data protection law through:
Standard Contractual Clauses (SCCs)
European Commission-approved contractual safeguards that obligate US-based recipients to protect data to EEA standards.
Data Processing Agreements (DPAs)
In place with all relevant third-party processors, binding them to our data protection standards.
6. Data Minimisation Principle
We follow a data minimisation approach:
- We collect only what is strictly necessary for the stated purpose
- We do not retain data longer than needed
- We anonymise or delete data when it is no longer required
7. Contact & Supervisory Authority
For any data protection enquiry, contact us at info@zoescruises.com.
If you believe we have not handled your data correctly, you have the right to lodge a complaint with your local data protection authority:
EEA Residents
Your national Data Protection Authority (e.g., ICO in the UK, CNIL in France)
California Residents
California Attorney General's Office
This statement will be reviewed and updated whenever our data practices materially change.
Data protection enquiries:
info@zoescruises.com