Privacy Policy
Tebura — How we handle your personal data
Version: 1.4 | Date: 3 September 2026 | Language: English (binding original).
1. Who we are
Tebura BV ("Tebura", "we", "us", "our") operates a hotel-to-hotel luggage transfer service in Belgium. We are the controller of your personal data within the meaning of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Belgian act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data.
Tebura BV
Registered seat: Tiensevest 26 bus b0200, 3000 Leuven
CBE/KBO: 1039.726.370 | VAT: BE 1039.726.370
Email: info@tebura.eu | Website: www.tebura.eu
Tebura has not appointed a Data Protection Officer as Tebura is not a public authority and as large-scale/special-category processing is not core to the business (art. 37.1 GDPR). Privacy questions can be addressed to privacy@tebura.eu.
2. Scope
This Privacy Policy describes how we collect, use, share and protect personal data of (i) customers and prospective customers placing a booking via www.tebura.eu, (ii) recipients designated by such customers, (iii) visitors to our website, (iv) contacts at partner hotels, suppliers and business partners, and (v) candidates applying for a position at Tebura.
3. Personal data we collect
Depending on your interaction with us, we may collect the following categories of personal data.
| Category | Examples |
|---|---|
| Identification data | first and last name, title |
| Contact data | email address, mobile phone number, postal address (where provided) |
| Booking data | origin and destination hotel, travel dates, number and type of bags, booking reference, special instructions |
| Payment data | masked card data, transaction reference, billing address; full card data is collected directly by Stripe and is not stored by Tebura |
| Communication data | emails, chat messages, support tickets, recordings or notes from calls where applicable |
| Service data | pickup and delivery timestamps, photographs of the bag and Tebura tag (these photographs do not capture identifiable images of persons), scan logs, signatures or electronic confirmations from hotel reception |
| Marketing data | opt-in status, preferences, opens and clicks in marketing emails (where opted in) |
| Technical data | IP address, device and browser information, log data, cookie identifiers, pages visited |
We do not knowingly process special categories of personal data (Article 9 GDPR). You are asked not to share such data with us, in particular not to pack medical, ID or religious documents inside your bag.
4. Where we collect your personal data from
We collect personal data primarily directly from you, when you visit our website, complete a booking, contact our customer service or interact with us by email or phone. We may also receive personal data from partner hotels, from payment providers and from service providers acting on our behalf.
5. Why we use your personal data and on which legal basis
We process personal data only where we have a valid legal basis under Article 6 GDPR. The table below sets out our processing activities, their purpose and the corresponding legal basis.
| Purpose | Categories used | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Performing the booking, transporting the bag, communicating with you about the service | Identification, contact, booking, service, communication | Performance of a contract (Art. 6(1)(b)) |
| Processing payments and refunds | Identification, payment, booking | Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Issuing invoices and keeping accounting records | Identification, contact, payment, booking | Legal obligation (Art. 6(1)(c)) — Belgian tax and accounting law |
| Handling claims, disputes and insurance files | All categories as needed for the file | Performance of a contract / legal obligation / legitimate interest (Art. 6(1)(b), (c) and (f)) |
| Securing our website, preventing fraud and abuse | Technical, communication | Legitimate interest in protecting our infrastructure and customers (Art. 6(1)(f)) |
| Improving the website and the service (analytics, A/B testing) | Technical | Legitimate interest in improving the service using cookieless, aggregate-only analytics (Art. 6(1)(f)) — see clause 8 |
| Sending you marketing emails (newsletter, promotional offers) | Identification, contact, marketing | Consent (Art. 6(1)(a)) — withdrawable at any time |
| Measuring which advertisements lead to bookings (advertising cookies from Google, Meta and OpenAI) | Technical, advertising identifiers | Consent (Art. 6(1)(a)) given through our cookie banner — withdrawable at any time, and separate from the marketing-email consent above — see clause 8 |
| Managing our supplier, partner-hotel and prospect relationships | Identification, contact, communication | Legitimate interest (Art. 6(1)(f)) |
| Recruitment of candidates / Retaining a CV in a talent pool after a rejection | CV and contact data | Pre-contractual steps (Art. 6(1)(b)) and consent (Art. 6(1)(a)) |
| Complying with court orders, lawful requests by public authorities | All categories as required | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have weighed our interests against your rights and freedoms. You can obtain more information on this balancing exercise by contacting privacy@tebura.eu.
6. Recipients of your personal data
We share personal data only on a need-to-know basis and only with the following categories of recipients:
- Partner hotels: the Origin Hotel and the Destination Hotel receive the customer name, booking reference and minimum information required to hand over and receive the bag.
- Non-partner hotels asked to hold your bags: where your Origin Hotel is not a partner hotel, we may ask its reception to hold your bags until our driver collects them. About you, that request carries only your name and the number of bags. It also carries the collection date, the collection window and the release code for that day. We share no email address and no telephone number. Where we hold a verified address for the hotel we send the request by email; otherwise we read it out by telephone, and the hotel is given your booking reference in place of your name. A hotel may receive the list before it has agreed to hold anything, and it acts on its own account rather than as our processor.
- Logistics partners: the carriers and last-mile delivery partners performing the physical transport of the bag receive the shipment details required to collect, transport and deliver it, namely customer name, booking reference, origin and destination hotel, pickup and delivery time windows, number and type of bags, and any specific handling instructions. These partners act as processors on our behalf under a data processing agreement compliant with Article 28 GDPR.
- Payment provider: Stripe Payments Europe Ltd (Ireland) processes payments and refunds as a separate controller for fraud-prevention purposes and as a processor for the payment transaction itself.
- Productivity and communication tools: Google Workspace (Google Ireland Limited) hosts our email (info@tebura.eu), calendar and shared drive.
- Transactional email: Postmark (ActiveCampaign, LLC) delivers our booking and account emails on our behalf.
- Error monitoring: Honeybadger Industries LLC processes error reports and related technical data for us on its EU infrastructure.
- Hosting and infrastructure: Render Services, Inc. hosts our application and database in Frankfurt (EU); Hetzner Online GmbH (Germany) stores files and encrypted backups.
- Hotel search: when you search for a hotel that is not yet listed, your search text is sent to Google's Places service (Google Ireland Limited) to find the hotel.
- Website analytics: Simple Analytics, a privacy-first, cookieless analytics service that does not collect personal data.
- Advertising measurement: if, and only if, you accept advertising cookies, Google Ireland Limited (Google Ads), Meta Platforms Ireland Limited and OpenAI Ireland Ltd. receive data about your visit through the cookies listed in our Cookie Policy. Each acts as an independent controller of that data under its own privacy policy, not as our processor. This is a different purpose from the marketing emails above, rests on a separate consent, and is withdrawn separately.
- Professional advisors: lawyers, accountants, auditors and insurers, bound by professional secrecy or contractual confidentiality.
- Public authorities: where we are required to do so by law, court order or a lawful request.
- Acquirers or investors: in case of a contemplated or actual reorganisation, merger, acquisition or financing transaction, subject to appropriate confidentiality safeguards.
We do not sell your personal data.
7. International data transfers
Some of our processors, in particular Google and certain last-mile delivery partners, may process personal data outside the European Economic Area (EEA), including in the United States. Where you have accepted advertising cookies, Google, Meta and OpenAI may likewise process the resulting data outside the EEA as independent controllers. Where this is the case, we rely on the safeguards required by Chapter V GDPR, namely:
- an adequacy decision adopted by the European Commission (for example the EU-US Data Privacy Framework for certified US recipients); or
- the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914) supplemented, where required, by additional technical and organisational measures.
A copy of these safeguards is available on request at privacy@tebura.eu.
Through our systems, partner hotels can view only the booking information we make available to them, and that access takes place within the EEA. Where we send a hotel its daily list, or ask a non-partner hotel to hold your bags, we do so by email and the hotel keeps a copy, because the email stays in the hotel's own mailbox. Those hotels are in Belgium, and the email itself is delivered by the transactional-email provider listed above.
8. Cookies and similar technologies
We use cookies and similar technologies on www.tebura.eu. We distinguish between:
- Strictly necessary cookies: placed without consent on the basis of Article 129 of the Belgian Electronic Communications Act, because they are required to operate the website and the booking flow (signing in, remembering your language, paying securely).
- Advertising cookies (Google, Meta and OpenAI): placed only after you accept them, and used to measure which advertisements lead to bookings. One of them, OpenAI’s
__obref, is a randomly generated identifier for your browser that OpenAI uses to recognise it across visits.
We use no analytics cookies. To understand how the site is used we use Simple Analytics, a privacy-first analytics service that does not use cookies and does not collect personal data.
A separate Cookie Policy, accessible from the cookie banner and from the footer of www.tebura.eu, lists each cookie, its purpose, its provider and its retention period. You can change or withdraw your consent at any time via the "Cookie settings" link in the footer. We keep a record of each choice so we can demonstrate the consent we rely on.
9. How long we keep your personal data
We keep personal data no longer than necessary for the purposes for which it is processed, subject to legal retention obligations. Indicative retention periods are:
| Data | Retention |
|---|---|
| Booking and service data | 36 months after the booking reaches a final state (delivered, cancelled, refunded or expired); the personal data is then anonymised, while the financial record is kept (see below) |
| Prospect data (inquiries and abandoned / non-converting bookings) | 36 months from the last interaction, after which the record is anonymised |
| Customer account data | Anonymised after 60 months of account inactivity; accounts with an upcoming or in-progress booking are never anonymised |
| Partner-hotel leads | 36 months after submission, after which the record is anonymised |
| Invoicing and accounting records | 7 years from the end of the financial year (Belgian VAT and accounting law) |
| Claims and dispute files | Duration of the file + 5 years after final resolution |
| Customer support communications | 3 years after last interaction |
| Marketing data (opt-in customers) | Until you withdraw consent or after 24 months of inactivity |
| CCTV, fraud-prevention and security logs | Maximum 12 months unless required for an ongoing investigation |
| Job applications | 12 months after the end of the recruitment process |
| Cookies | As set out in the Cookie Policy |
| Record of your cookie-consent choices | 60 months from the choice. It contains no name, email or IP address, and is kept so we can demonstrate the consent we relied on |
10. Your rights
Under the GDPR you have the following rights regarding your personal data:
- Right of access (Art. 15): to obtain confirmation as to whether we process your data, and a copy of it.
- Right to rectification (Art. 16): to have inaccurate data corrected or incomplete data completed.
- Right to erasure (Art. 17): to have your data deleted in the cases listed by the GDPR.
- Right to restriction (Art. 18): to have processing restricted in certain cases.
- Right to data portability (Art. 20): to receive data you provided in a structured, commonly used, machine-readable format.
- Right to object (Art. 21): to object at any time to processing based on legitimate interests, and in any case to direct marketing.
- Right to withdraw consent (Art. 7(3)): where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.
- Right not to be subject to automated individual decision-making (Art. 22): we do not take decisions producing legal effects on you solely on the basis of automated processing, including profiling.
You can exercise your rights at any time by sending an email to privacy@tebura.eu. We may ask for additional information to verify your identity. We respond within one month of receipt of your request, extendable by two months for complex requests.
11. Lodging a complaint
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The competent authority in Belgium is:
Gegevensbeschermingsautoriteit / Autorité de protection des données
Drukpersstraat 35, 1000 Brussels
+32 2 274 48 00 | contact@apd-gba.be | www.dataprotectionauthority.be
We would, however, appreciate the opportunity to address your concerns first by contacting us at privacy@tebura.eu.
12. Security
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These include access controls based on least privilege, encryption in transit (TLS), encryption at rest where supported by our providers, regular backups, vendor due diligence and employee training.
Despite these measures, no system can guarantee absolute security. We will notify the competent supervisory authority and, where required, affected individuals in case of a personal data breach in accordance with Articles 33 and 34 GDPR.
13. Children
Our service is not directed at children under the age of 16 and we do not knowingly collect personal data from them without parental consent. If you believe that a child has provided us with personal data, please contact privacy@tebura.eu and we will delete it.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The latest version is always available at www.tebura.eu/privacy with the date of last update. We will inform you of material changes by email or via a notice on the website before they take effect.
15. Contact
Questions, comments or requests regarding this Privacy Policy can be sent to:
Tebura BV — Privacy — privacy@tebura.eu