SafariBook
Guest-data overviewRetention & deletionData processing
SafariBook legal

Privacy Notice

Version 1.1 · Last updated 22 August 2026

SafariBook is operated by Jason Degiorgio, a UK sole trader trading as SafariBook. This notice explains how personal information is handled through the SafariBook web app at app.safari-book.com, the SafariBook website and related service communications.

1. Contact details

Jason Degiorgio, trading as SafariBook
Inn on the Lake Hotel
Watling Street
Gravesend
Kent
DA12 3HB
United Kingdom

hello@safari-book.com

Correspondence address only: Inn on the Lake Hotel does not operate or endorse SafariBook.

2. Who is responsible for your information?

For lodge guest and trip information, the lodge is normally the controller and SafariBook is its processor. The lodge decides why the information is used, which guests use SafariBook, what information is entered, who on its team may access it and the lawful basis for that processing. SafariBook processes that information to provide and support SafariBook on the lodge's documented instructions.

SafariBook is an independent controller for limited SafariBook business and operational purposes, including lodge/customer contacts, account administration, authentication and security, support and privacy correspondence, supplier administration, contracts and acceptance evidence, legal compliance and genuinely anonymised or aggregate service statistics where SafariBook determines the purpose and means.

This notice does not replace a lodge's own privacy notice and does not cover the lodge's website, booking system or other services.

3. UK and Kenya scope

SafariBook is operated from the United Kingdom. UK data protection law applies to SafariBook where relevant. The Kenyan Data Protection Act 2019 can also apply when SafariBook processes personal data about people located in Kenya, even though SafariBook is not established in Kenya.

Where Kenyan law applies, SafariBook and the relevant lodge must also follow applicable Kenyan requirements concerning transparency, data-subject rights, processor contracts, security, breach handling and transfers of personal data outside Kenya.

4. Information SafariBook handles

  • Lodge and staff information: names, work email addresses, user/account identifiers, roles, preferred language, guide biography/profile information, years guiding, languages, favourite animal and optional guide photograph.
  • Authentication and security information: sign-in/session information, password/authentication records held by the authentication provider, timestamps, IP address, user agent and audit/security events.
  • Guest and trip information: guest or party name, email address, preferred language, arrival/departure dates, lodge, assigned guide, trip status and private guest-link controls.
  • SafariBook content: game drives, dates and times, wildlife sightings and counts, highlights, guide notes, guest-facing captions and the selected Safari story.
  • Delivery information: recipient email, delivery status/mode, provider message identifier, attempts, sent/attempt timestamps and technical error details.
  • Guest engagement events: opens, shares, review-link clicks and rebooking-link clicks associated with the relevant trip. SafariBook currently uses a fresh random event/session key and does not store a persistent guest analytics identifier.
  • Browser and offline information: language choice, necessary app/session storage, cached staff context, offline trip snapshots, guide drafts and queued changes used to keep the Guide Logger working with poor connectivity.
  • Support, privacy and compliance records: correspondence, attachments, rights-request records, incident records and contract/acceptance evidence where applicable.

Information may come from the lodge or its authorised staff, from the person using SafariBook, from guest browser interactions, or automatically from the service providers used to operate and secure SafariBook.

5. Sensitive information and children

SafariBook is not designed to require health information, biometric identification data, passport information, payment-card data or other unnecessary sensitive information. Free-text fields can nevertheless contain sensitive information if a lodge or guide enters it.

Kenyan law treats some family details as sensitive personal data. For Kenyan pilots, lodges should therefore use a lead-guest name or a neutral party label where practicable and should not enter children's full names, family relationships or other sensitive details unless they are necessary, lawful and separately safeguarded.

Children may be members of a guest party, but SafariBook does not currently ask for a child's age or date of birth. The lodge is responsible for deciding whether child information is necessary and for providing any legally required transparency, authority or safeguards.

6. Why information is used and legal bases

  • Lodge guest/trip processing: SafariBook processes this information on the lodge's documented instructions. The lodge is responsible for identifying and documenting the appropriate lawful basis for its guest processing.
  • Customer and staff account administration: to provide and administer SafariBook, manage authorised access and support the service, relying as appropriate on contract and legitimate interests.
  • Security, reliability and misuse prevention: to protect accounts and private links, investigate faults and security events and maintain the service, relying as appropriate on legitimate interests and legal obligations.
  • Support, privacy and compliance: to respond to requests, maintain necessary evidence and comply with legal or regulatory duties, relying as appropriate on contract, legitimate interests and legal obligations.
  • Service statistics: SafariBook may use genuinely anonymised or aggregate information to understand service reliability and usefulness. Trip-level guest engagement remains lodge-controlled processing while it is identifiable.

SafariBook does not sell personal information, use guest information for third-party advertising, build cross-site advertising profiles, or make decisions producing legal or similarly significant effects solely by automated means.

7. Who receives information?

Personal information is made available only where needed for the service or another lawful purpose. Recipients may include:

  • authorised lodge administrators and staff, and guides assigned to relevant work;
  • the guest, and anyone with whom the lodge or guest shares the private SafariBook link;
  • Supabase for database, authentication, object storage and server/edge functions. The main SafariBook project is configured in the EU (Ireland);
  • Vercel for web hosting, static delivery and edge/network infrastructure;
  • Resend for transactional SafariBook email delivery and associated technical delivery records;
  • GoDaddy for the hello@safari-book.com business mailbox and related support/privacy correspondence; and
  • professional advisers, regulators, courts or law-enforcement bodies where reasonably necessary or legally required.

SafariBook maintains contractual and security requirements for suppliers where applicable. Supplier-specific processing countries, onward transfers, retention and transfer safeguards are reviewed and recorded as part of SafariBook's subprocessor and international-transfer governance.

8. International transfers

The main SafariBook database is configured in the EU (Ireland), so personal data entered by a Kenyan lodge is transferred from Kenya to the EU. Some suppliers may also process information in other countries.

For Kenyan personal data: a transfer outside Kenya must have a permitted transfer basis and the required safeguards under applicable Kenyan law. Before a real-data Kenyan pilot begins, SafariBook and the lodge must document the relevant transfer basis, recipients/countries and safeguards for the supplier flows they use. SafariBook does not treat this privacy notice alone as a transfer mechanism.

For restricted transfers under UK data protection law: SafariBook uses an applicable lawful mechanism where required, which may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another permitted mechanism.

SafariBook does not intentionally require Kenyan sensitive personal data for the ordinary service. If a proposed use would involve transferring Kenyan sensitive personal data outside Kenya, the processing must not begin until the lodge and SafariBook have separately confirmed the lawful basis, required consent where applicable and appropriate safeguards.

9. Cookies, browser storage and offline use

SafariBook does not use advertising cookies. Staff pages use necessary browser storage for sign-in/session support, language choice, cached context, offline drafts, queued changes and application assets. Offline data can include guest names, stay dates, guide assignments, drive notes and sighting changes on the staff device until they are synchronised or cleared.

Guest pages may store the chosen language for that SafariBook. Guest engagement events use a fresh random event/session key; SafariBook does not store a persistent guest analytics identifier.

Lodge staff should sign out on shared devices and must not leave SafariBook offline data on a device that is lost, transferred or disposed of.

10. Retention and deletion

  • Guest trips and related SafariBook records: up to 24 months after the scheduled departure date, unless the lodge instructs earlier deletion.
  • Staff access: removed when no longer required; residual profile/photo information is targeted for deletion or anonymisation within 90 days after the last active lodge relationship unless another lawful retention need applies.
  • Support correspondence: normally 24 months after closure or last substantive contact.
  • Routine identifiable security/technical logs: up to 12 months or the provider's shorter operational period, unless linked to an active incident or lawful hold.
  • Rights/compliance records: normally three years after closure.
  • Minimal contract/DPA acceptance evidence: normally six years after the lodge relationship ends.
  • Browser/offline data: only while needed for the current user/workflow and subject to sign-out, synchronisation and browser/device controls.
  • Genuinely anonymised statistics: may be retained without a fixed personal-data period where individuals cannot reasonably be re-identified.

Deleted database information may remain temporarily in restricted provider backups until the applicable recovery copy expires. If a database backup is restored, applicable deletion instructions must be reapplied before normal service resumes.

See the Data Retention and Deletion Policy for more detail.

11. Security and private links

SafariBook uses measures including authenticated staff access, role-based database controls, tenant isolation, encrypted connections, private guest links, restricted service credentials, private guide-photo storage, security headers, provider backups and controls around offline data. Security measures are reviewed as the service changes.

A private SafariBook link is not a public page, but anyone who receives a valid enabled link can view that guest book. Lodges and guests should therefore treat the link as confidential and should tell the lodge or SafariBook promptly if it may have been exposed.

12. Your data-protection rights

Your rights depend on the applicable law and circumstances. They can include rights to be informed, access personal data, correct inaccurate data, request deletion, object to or restrict certain processing, obtain portable data where applicable, and withdraw consent where consent is the legal basis.

Guest or trip information: contact the lodge first where practicable because the lodge is normally the controller. You may also contact SafariBook at hello@safari-book.com. SafariBook will respond directly where it is the controller and will route or assist the lodge where SafariBook is acting as processor. Identity or authority may need to be verified.

United Kingdom: you may complain to the Information Commissioner's Office (ICO) at ico.org.uk.

Kenya: where Kenyan data protection law applies, you may make a complaint to the Office of the Data Protection Commissioner (ODPC). Information about the ODPC and its complaint process is available at odpc.go.ke.

13. Changes to this notice

SafariBook may update this notice when the service, suppliers, processing, countries or law changes. The latest version and update date will remain available at app.safari-book.com/privacy. Material changes affecting an active lodge pilot will be communicated where reasonably practicable.

Kenyan pilot launch condition. This notice provides the transparency framework for the pilot, but the separate supplier/transfer verification and any required Kenyan registration or other regulatory steps must also be completed before real Kenyan guest data is introduced.
Guest-data overview·Retention & deletion·Data processing·© 2026 SafariBook