GDPR regulations, Privacy Policy

By the Bush-Spa & Retreats Ltd.

This Bush-Spa and Retreats Ltd. Privacy Policy has been compiled to better serve those who are concerned with how their ‘Personally Identifiable Information’ (PII) is being used online. PII, as described in EU and US privacy law and information security, is information that can be used on its own or with other information to identify, contact, or locate a single person, or to identify an individual in context. Please read our privacy policy carefully to get a clear understanding of how we collect, use, protect or otherwise handle your Personally Identifiable Information in accordance with our website.

What personal information do we collect from the people that visit our blog, website or app?  
When asking for information or registering on our site, as appropriate, you may be asked to enter your name, email address, country of residence or other details to help you with your experience.  

When do we collect information?  
We collect information from you when you subscribe to a newsletter, fill out a form or enter information on our site. We also gather information when you provide us with feedback on our products or services  

How do we use your information?  
We may use the information we collect from you when you make an enquiry, register, make a booking, sign up for our newsletter, respond to a survey or marketing communication, surf the website, or use certain other site features in the following ways:  

• To improve our website in order to better serve you.  
• To allow us to better service you in responding to your customer service requests.  
• To send periodic emails regarding your booking or other products and services.  

How do we protect your information? We do not use vulnerability scanning and/or scanning to PCI standards.  We only provide articles and information. We never ask for credit card numbers. 

Do we use ‘cookies’?  
We do not use cookies for tracking purposes. You can choose to have your computer warn you each time a cookie is being sent, or you can choose to turn off all cookies. You do this through your browser settings. Look at your browser’s Help Menu to learn the correct way to modify your cookie settings.  If you turn cookies off, some of the features that make your site experience more efficient may not function properly, sorry for that and we shall aim to improve there. However, you will still be able to ask for further information. 

We use regular Malware Scanning.
Your personal information is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems, and are required to keep the information confidential. In addition, all sensitive/credit information you supply is encrypted via Secure Socket Layer (SSL) technology.  We implement a variety of security measures when a user enters, submits, or accesses their information to maintain the safety of your personal information.

All transactions are processed through a gateway provider and are not stored or processed on our servers. 

Third-party disclosure 
We do not sell, trade, or otherwise transfer to outside parties your Personally Identifiable Information. 

Third-party links 
We work not only in close cooperation with our Zambian Bank, but also selected two separate Payment Service Providers to be able to offer you a range of payment solutions. We have put a lot of effort into making our services available to a wide range of customers to access and pay for them in a myriad of ways. 

Safety with Online payments
Following any link will open a new secure window. Before you enter any personal or payment information online, always check that the website is secure. This is indicated by a yellow padlock icon at the top of the screen and a website address that starts with ‘https://’ (the ‘s’ stands for ‘secure’). Always take the utmost care to be safe online. 

Payment Card Industry Security Standards 
As an ease of mind know that The Bush-Spa will never store or see any of your card details. So you are secure with us. It is for this very same reason we outsourced our online payment processing and we use a DPO hosted payment page as our payment processors.
Within our facility we use standard Point of Sales machines from our Zambian bank where PIN entry is required. The Bush-Spa does not come into any contact with your credit card information. 

Google 
W
e have or will be implementing the following:  
• Google Display Network Impression Reporting  
• Demographics and Interests Reporting  

We, along with third-party vendors such as Google use first-party cookies (such as the Google Analytics cookies) and third-party cookies (such as the DoubleClick cookie) or other third-party identifiers together to compile data regarding user interactions with ad impressions and other ad service functions as they relate to our website.  
O
pting out: 
Users can set preferences for how Google advertises to you using the Google Ad Settings page. Alternatively, you can opt out by visiting the Network Advertising Initiative Opt Out page or by using the Google Analytics Opt Out Browser add on. 

California Online Privacy Protection Act 
CalOPPA is the first state law in the nation to require commercial websites and online services to post a privacy policy. The law’s reach stretches well beyond California to require any person or company in the United States (and conceivably the world) that operates websites collecting Personally Identifiable Information from California consumers to post a conspicuous privacy policy on its website stating exactly the information being collected and those individuals or companies with whom it is being shared. – See more at: http://consumercal.org/california-online-privacy-protection-act-caloppa/#sthash.0FdRbT51.dpuf  
According to CalOPPA, we agree to the following: 
* Users can visit our site anonymously.
* This privacy policy is clearly linked to on our home page and on each and every page of our website.  
* Our Privacy Policy link includes the word ‘Privacy’ and can easily be found on the page specified above.  
* You will be notified of any Privacy Policy changes via our Privacy Policy Page  
* You can change your personal information by emailing us  


How does our site handle Do Not Track signals? 
We honor Do Not Track signals and Do Not Track, plant cookies, or use advertising when a Do Not Track (DNT) browser mechanism is in place. It’s also important to note that we do not allow third-party behavioural tracking 

COPPA (Children Online Privacy Protection Act)  
When it comes to the collection of personal information from children under the age of 13 years old, the Children’s Online Privacy Protection Act (COPPA) puts parents in control. The Federal Trade Commission, United States’ consumer protection agency, enforces the COPPA Rule, which spells out what operators of websites and online services must do to protect children’s privacy and safety online. The Bush-Spa does not specifically market to children under the age of 13 years old.  

Fair Information Practices  
The Fair Information Practices Principles form the backbone of privacy law and the concepts they include have played a significant role in the development of data protection laws around the globe. Understanding the Fair Information Practice Principles and how they should be implemented is critical to comply with the various privacy laws that protect personal information. In order to be in line with Fair Information Practices we will notify the users via on-site notifications within 1 business day. 
We also agree to the Individual Redress Principle which requires that individuals have the right to legally pursue enforceable rights against data collectors and processors who fail to adhere to the law. This principle requires not only, that individuals have enforceable rights against data users, but also that individuals have recourse to courts or government agencies to investigate and/or prosecute non-compliance by data processors.  

CAN SPAM Act 
The CAN-SPAM Act is a law that sets the rules for commercial email, establishes requirements for commercial messages, gives recipients the right to have emails stopped from being sent to them, and spells out tough penalties for violations. We collect your email address in order to:
• Send information, respond to enquiries, and/or other requests or questions
• Market to our mailing list or continue to send emails to our clients after the original transaction has occurred.

To be in accordance with CANSPAM, we agree to the following:  
• Not use false or misleading subjects or email addresses.  
• Identify the message as an advertisement in some reasonable way.  
• Include the physical address of our business or site headquarters.  
• Monitor third-party email marketing services for compliance, if one is used.  
• Honour opt-out/unsubscribe requests quickly.
• Allow users to unsubscribe by using the link at the bottom of each email.  
If at any time you would like to unsubscribe from receiving future emails, you can email us or follow the link at the bottom of each marketing e-mail and we will promptly remove you from ALL correspondence.  

Contacting Us 
Should there be any questions regarding this privacy policy, you may contact us using the information below.  

the Bush-Spa and Retreats
Address

The Bush-Spa & Retreats Ltd.
South Luangwa National Park
PO Box 58, Mfuwe
Eastern Province, ZAMBIA

Contacts

Email: info@bush-spa.com      Phone: +260 979 306 826
WhatsApp: +260979306826
Phone: +260 974 514 030