THE GOOD LIFE INTERNATIONAL LTD
Privacy Policy
Effective Date: 1 July 2025
Version: 1.0
The Good Life International LTD (EOOD), registered in Bulgaria under UIC 206032672, with registered office at 1A Ivan Mihaylov Str., Floor 7, Office 2, 2700 Blagoevgrad, Bulgaria (hereinafter “The Company”, “we”, “us”, or “our”) is committed to protecting your personal data and respecting your privacy.
This Privacy Policy explains what personal data we collect, why we collect it, how we use and store it, who we share it with, and what your rights are. It applies to all individuals whose data we process, including website visitors, enquiry contacts, and clients who book services through us.
This Policy is issued in compliance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the Bulgarian Personal Data Protection Act.
1. Who We Are and How to Contact Us
The Good Life International LTD (EOOD)
2. What Personal Data We Collect
2.1 Data you provide directly to us
We collect personal data you provide when you contact us, submit an enquiry, complete a questionnaire, or confirm a booking. This includes:
- Full name
- Email address
- Phone number and WhatsApp contact
- Passport details (number, nationality, date of birth, expiry date) — where required by suppliers such as yacht operators, private aviation providers, or villa owners
- Dietary requirements, food allergies, and intolerances
- Medical conditions or health information you voluntarily share relevant to your planned activities
- Travel preferences, accommodation preferences, and lifestyle interests
- Names, ages, and details of other members of your travel party
- Payment information (bank transfer details, card details processed via our payment provider)
- Any other information you choose to share with us through email, WhatsApp, questionnaires, or direct communication
2.2 Data collected through our tools and channels
Depending on how you interact with us, we may collect your data through the following channels:
- Website enquiry and contact forms (tglc.co)
- Typeform questionnaires — used to gather detailed trip preferences and client information
- WhatsApp — individual chats and group communications
- Email correspondence
- Mailchimp — email marketing and newsletters
- ActiveCampaign — our CRM and client management platform
- Trello — used internally for trip planning and task management
- Travefy — used to build and share travel itineraries with clients
- Google Drive — used to store and share documents, planning files, and client information
2.3 Data collected automatically from our website
When you visit our website, we and our service providers may automatically collect limited technical data, including:
- IP address
- Browser type and version
- Pages visited and time spent on the website
- Referring website or source
This data is collected via cookies and similar technologies. Please see Section 10 (Cookies) for further information.
3. Why We Collect Your Data and Our Legal Basis
We only process your personal data where we have a lawful basis to do so under Article 6 of the GDPR. The table below sets out the purposes for which we process your data and the corresponding legal basis.
| Purpose | Data used | Legal basis | Details |
| Responding to enquiries and providing quotes | Name, email, phone, WhatsApp, preferences | Contract (Art. 6(1)(b)) | Necessary to take steps at your request prior to entering a contract |
| Processing and managing bookings | Full name, passport, dietary/medical info, payment details, travel party details | Contract (Art. 6(1)(b)) | Necessary to perform the services you have booked |
| Sharing information with Suppliers | Name, passport, dietary/medical info, preferences | Contract (Art. 6(1)(b)) | Required to arrange and confirm your bookings with third-party suppliers |
| Sending trip itineraries and travel documents | Name, email, trip details | Contract (Art. 6(1)(b)) | Delivery of confirmed booking materials via Travefy or email |
| Sending marketing emails and newsletters | Name, email | Consent (Art. 6(1)(a)) | Only where you have opted in. You may withdraw consent at any time |
| Managing client relationships via CRM | Name, email, communication history, preferences | Legitimate interests (Art. 6(1)(f)) | To manage our business relationships and improve our service quality |
| Internal trip planning and coordination (Trello, Google Drive) | Name, booking details, preferences | Legitimate interests (Art. 6(1)(f)) | Operational necessity for our internal team to deliver your trip |
| Compliance with legal obligations | Name, payment records, booking records | Legal obligation (Art. 6(1)(c)) | Bulgarian tax law requires retention of accounting records for 10 years |
| Handling complaints and disputes | All relevant data in the matter | Legitimate interests (Art. 6(1)(f)) / Legal obligation (Art. 6(1)(c)) | To defend or pursue legal claims and comply with legal requirements |
| Website operation and security | IP address, browser data, cookies | Legitimate interests (Art. 6(1)(f)) | To maintain and secure our website and understand visitor behaviour |
4. Special Categories of Data
Some of the information you provide to us — such as dietary requirements, allergies, medical conditions, or health information — may constitute “special category” data under Article 9 of the GDPR, which requires a higher level of protection.
We collect this data only where you have voluntarily provided it and where it is necessary to arrange safe, appropriate services for you. By providing this information to us, you explicitly consent to us processing it solely for the purpose of coordinating your trip with relevant Suppliers (for example, informing a private chef of a severe allergy, or advising a wellness provider of a relevant medical condition).
We do not share special category data with any party beyond what is strictly necessary for your booking, and we do not use it for any other purpose.
5. Who We Share Your Data With
We share your personal data only where necessary and only with the following categories of recipients:
5.1 Suppliers
When you confirm a booking, we share the personal data required to arrange that service — such as names, passport details, dietary requirements, and payment information — with the relevant Supplier (for example, a villa owner, yacht operator, private chef, or transport provider). Each Supplier is an independent data controller in respect of the data they receive and processes it under their own policies and applicable law.
5.2 Our operational team and contractors
We work with a small team of back-office support contractors (individuals who provide services to us under contracts for services and issue invoices to the Company). These contractors assist with trip planning, client coordination, supplier communication, and administration. Where necessary for the performance of their role, they have access to client personal data including names, travel details, preferences, and communication records.
These contractors are bound by confidentiality obligations and are only permitted to use client data for the purposes of carrying out their contracted work for The Good Life International LTD. They are not employees of the Company but are treated as data processors or authorised recipients for the purposes of GDPR.
5.3 Referral partners and associates
Where you have been referred to us by a partner or associate, that partner may have shared your basic contact details with us for the purpose of making an introduction. We may also communicate with referral partners in the context of coordinating your trip where they are involved in your group or travel arrangements. We share only the minimum data necessary with referral partners and only where operationally relevant to your booking.
5.4 Technology and platform providers
We use the following third-party platforms that process personal data on our behalf as data processors. Each operates under its own privacy and data processing terms:
- ActiveCampaign (USA) — CRM and client communication platform
- Mailchimp / Intuit (USA) — email marketing platform
- Typeform (Spain/EU) — online questionnaire and data collection
- Travefy (USA) — travel itinerary creation and sharing
- Trello / Atlassian (USA/Australia) — internal trip planning and task management
- Google Workspace / Google Drive (USA) — document storage and team collaboration
- WhatsApp / Meta (USA) — client and team communication (see Section 13 for full details)
- Our website platform and hosting provider
- Our payment processing provider(s)
5.5 Professional advisors
We may share your data with our lawyers, accountants, or other professional advisors where necessary, subject to confidentiality obligations.
5.6 Competent authorities
We may disclose your data to law enforcement, regulatory authorities, or courts where we are legally required to do so.
5.7 No sale of data
We do not sell, rent, or trade your personal data to any third party for commercial purposes under any circumstances.
6. International Data Transfers
Several of the tools we use — including ActiveCampaign, Mailchimp, Travefy, Trello, Google Drive, and WhatsApp — are operated by companies based in the United States. When we use these tools to process your personal data, your data is transferred to the United States, which is outside the European Economic Area (EEA).
We rely on the following safeguards for such transfers, as required by Chapter V of the GDPR:
- EU Standard Contractual Clauses (SCCs) in place with processors where applicable;
- The EU-US Data Privacy Framework (where the recipient is certified under it);
- Binding Corporate Rules or other appropriate safeguards where applicable.
We also share data with Suppliers in non-EU countries (including Greece, Spain, France, Mexico, and the United States) where this is necessary to perform your booking. Such transfers are made on the basis of Article 49(1)(b) GDPR — necessity for the performance of a contract entered into at your request.
You may request further information about the specific safeguards in place for any transfer by contacting us at info@tglc.co.
7. How Long We Keep Your Data
We retain your personal data only for as long as necessary for the purposes for which it was collected, taking into account our legal obligations. Our standard retention periods are:
- Booking records, payment records, and accounting data: 10 years, in accordance with Bulgarian tax and accounting law.
- Client correspondence (email, WhatsApp): retained for the duration of the client relationship and for up to 5 years thereafter, in case of disputes.
- Trip planning data stored in Trello, Google Drive, and Travefy: retained for the duration of the trip and for up to 3 years thereafter.
- Marketing data (Mailchimp, ActiveCampaign): retained until you withdraw consent or unsubscribe, after which we will remove your data from active marketing lists within 30 days.
- Typeform questionnaire responses: retained for up to 3 years or until your relationship with us ends, whichever is earlier.
- Website technical data (IP addresses, cookies): retained in accordance with our cookie settings, typically up to 13 months.
When data is no longer required, we will securely delete or anonymise it.
8. Your Rights Under the GDPR
As a data subject under the GDPR, you have the following rights in respect of your personal data:
- Right of access (Article 15): You have the right to request a copy of the personal data we hold about you and information about how we process it.
- Right to rectification (Article 16): You have the right to ask us to correct any inaccurate or incomplete personal data we hold about you.
- Right to erasure (Article 17): You have the right to ask us to delete your personal data in certain circumstances — for example, where we no longer need it for the purpose it was collected, or where you withdraw consent.
- Right to restriction of processing (Article 18): You have the right to ask us to restrict how we use your data in certain circumstances.
- Right to data portability (Article 20): Where we process your data by automated means on the basis of your consent or a contract, you have the right to receive your data in a structured, commonly used, machine-readable format.
- Right to object (Article 21): You have the right to object to our processing of your data where we rely on legitimate interests as our legal basis. You also have the right to object at any time to processing for direct marketing purposes.
- Right to withdraw consent: Where we process your data on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
To exercise any of these rights, please contact us at info@tglc.co. We will respond within 30 days. We may need to verify your identity before processing your request.
You also have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (Комисия за защита на личните данни) at www.cpdp.bg, or with the data protection authority in your country of residence within the EU.
9. Data Security
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, loss, alteration, or disclosure, in accordance with Article 32 of the GDPR.
- Password-protected and access-controlled systems for all platforms holding personal data (ActiveCampaign, Google Drive, Trello, Travefy);
- Restricted internal access — only team members who need your data to arrange your trip have access to it;
- Use of encrypted communication channels where possible;
- Regular review of third-party processors to ensure they maintain adequate security standards.
Despite these measures, no system is completely immune from risk. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Bulgarian Commission for Personal Data Protection within 72 hours and will notify you directly without undue delay where required under Articles 33 and 34 of the GDPR.
10. Cookies
Our website uses cookies and similar technologies. A cookie is a small text file placed on your device when you visit a website.
10.1 Types of cookies we use
- Strictly necessary cookies: Required for the website to function. These cannot be disabled.
- Analytics cookies: Help us understand how visitors interact with our website (e.g. which pages are visited most). These are only set with your consent.
- Marketing cookies: Used to track enquiries and marketing campaign performance. These are only set with your consent.
10.2 Your cookie choices
When you first visit our website, a cookie consent banner will ask for your preferences. You may accept, reject, or customise which types of cookies are set. You can change your preferences at any time through the cookie settings link in our website footer.
You may also control cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of our website.
10.3 Third-party cookies
Some cookies on our website may be set by third-party services such as analytics providers or social media platforms. These third parties have their own privacy policies and we recommend reviewing them.
11. Children’s Data
Our services are not directed at children under the age of 16. We do not knowingly collect personal data from children under 16 without verifiable parental consent.
When you book services for a travel party that includes minors, you confirm that you are the parent or legal guardian of those minors and that you consent to us processing their data (name, age, dietary and medical information where relevant) solely for the purposes of arranging their travel. We will not use minors’ data for any other purpose.
12. Marketing Communications
We will only send you marketing emails or newsletters where you have explicitly opted in to receive them — for example, by ticking a marketing consent checkbox on our website or in our Typeform questionnaire.
You may unsubscribe from marketing communications at any time by:
- Clicking the “unsubscribe” link in any marketing email;
- Contacting us directly at info@tglc.co.
Unsubscribing from marketing does not affect your ability to receive essential service communications related to a confirmed booking (such as itineraries, payment confirmations, or important trip updates).
13. WhatsApp — How We Use It and What You Should Know
WhatsApp is one of our primary communication channels — with clients, within our internal team, and with suppliers and partners. We want to be transparent about exactly how it is used and what that means for your personal data.
13.1 Types of WhatsApp communication we use
- Individual client chats — for enquiries, bookings, updates, and trip coordination;
- Client group chats — where multiple members of a travelling group are added together for coordination purposes;
- Internal team chats — between Company team members and contracted back-office support staff;
- Supplier and partner chats — with venues, villa owners, yacht operators, transport providers, and referral partners for the purpose of arranging your booking.
13.2 Transmission of sensitive documents via WhatsApp
We always advise clients to send sensitive documents — such as passport scans, identity documents, and payment details — by email where possible, as email provides a more controlled and auditable record.
However, we recognise that in practice many clients and suppliers choose to send documents including passports via WhatsApp, as it is faster and more convenient. Where this occurs:
- We accept the document and process it solely for the purpose for which it was sent (for example, to register a yacht charter or book a villa);
- We ask that you delete the document from the chat on your end once you have confirmed it has been received;
- We do not forward passport or identity documents via WhatsApp group chats — sensitive documents are shared with suppliers individually and only where strictly required;
- Where we need to pass a passport or identity document to a Supplier, we will do so via the most secure available channel, which in some cases is WhatsApp where that is the Supplier’s standard method of operation.
13.3 Group chats and data visibility
Please be aware that in WhatsApp group chats, all members of the group can see messages and files shared within the chat. Our client group chats may include:
- Members of your travelling party;
- The Company’s team members and contracted back-office support staff;
- In some cases, relevant partners or associates connected to your trip.
We aim to keep group membership limited to those who genuinely need to be included for the coordination of your trip. Please be mindful of what personal information you share in group chats, and contact us individually if you need to share something confidential.
13.4 WhatsApp and Meta
WhatsApp is operated by Meta Platforms, Inc. (USA). All WhatsApp messages — including those containing personal data — are processed on Meta’s infrastructure, which is based outside the EU. Meta’s own privacy policy applies to all data processed through WhatsApp. We recommend reviewing it at whatsapp.com/legal/privacy-policy.
If you prefer not to use WhatsApp, you are always welcome to communicate with us exclusively by email at info@tglc.co.
14. Links to Third-Party Websites
Our website and communications may contain links to third-party websites, including Supplier websites, venue pages, and other external resources. We are not responsible for the privacy practices of those websites. We encourage you to read the privacy policy of any website you visit.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the tools we use, or applicable law. The current version will always be available at https://tglc.co/privacy-policy, with the version number and effective date shown at the top.
Where changes are material, we will notify active clients by email. Your continued engagement with our services after any update constitutes your acknowledgment of the revised Policy.
16. Contact and Complaints
For any questions about this Privacy Policy or your personal data, please contact us:
Email: info@tglc.co
WhatsApp: +1 786 670 5503
Post: The Good Life International LTD, 1A Ivan Mihaylov Str., Floor 7, Office 2, 2700 Blagoevgrad, Bulgaria
UIC / BULSTAT: 206032672
Website: tglc.co
For any questions, requests, or complaints regarding your personal data, please contact us at info@tglc.co. We will respond within 30 days.
If you are not satisfied with our response, you have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection:
- Website: www.cpdp.bg
- Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria
- Email: kzld@cpdp.bg
You may also contact the data protection authority in your country of residence if you are located in another EU member state.
