WR Travel · Privacy Policy

Privacy Policy

Last updated: June 2026

WR Travel ("we", "WR") respects and protects the personal data of every visitor and client. This policy is written to align with Hong Kong's Personal Data (Privacy) Ordinance (PDPO), the People's Republic of China's Personal Information Protection Law (PIPL), and the EU General Data Protection Regulation (GDPR). It explains, across wr-travel.com and our related services: what we collect, why we collect it, how we use and protect it, with whom we share it, how cross-border transfers are handled, and the rights and remedies available to you.

1. Data Controller

This policy is issued by WR Travel — a Hong Kong licensed travel agent (Licence No. 354519, the "Controller"). Unless stated otherwise, inquiries, rights requests, and complaints should be sent to info@wildroadgroup.com, or by post to Flat/Rm V43, 2/F, Hung Hom Commercial Centre, 37-39 Ma Tau Wai Rd, Kowloon, Hong Kong. If you are located in the EEA or the UK, you may contact our nominated local representative via the same email.

2. Information We Collect

We collect only what is necessary to deliver luxury travel concierge, corporate travel management, and B2B partnership services. Two categories: (i) basic information you provide via inquiry / partnership forms — name, email, phone, company, inquiry purpose, destination, travel dates, budget band, preferences; (ii) server logs automatically captured for security auditing — IP address, browser fingerprint, access timestamp. We do not actively collect identity numbers, full payment-card numbers, or biometric data. If a specific trip (e.g. visa support) requires such sensitive data, we will request consent separately and provide a dedicated submission channel.

3. Purposes and Legal Bases

We process your personal data on the following purposes and legal bases: (a) performance of an inquiry or contract — responding, advisor follow-up, booking execution, post-trip care; (b) legitimate interests — service-quality improvement, security audit, fraud prevention; (c) your explicit consent — sending industry updates, fam-trip invitations; (d) legal obligations — anti-money laundering, tax, and regulatory reporting. Where processing is based on consent, you may withdraw at any time without affecting the lawfulness of processing before withdrawal.

4. Sharing and Disclosure

To execute the travel or corporate travel services you commission, we may share necessary details with the following categories of recipients, strictly within the scope of your trip: partner hotels and hotel-group Preferred Partner programs, airlines, ground partners / DMCs, airport lounges and transit services, visa agents, insurance providers, and the corporate travel managers of business clients. We do not sell, rent, or trade your personal data with unrelated third parties. We may disclose data when required by lawful enforcement or judicial requests, to protect our or others' legitimate rights, or to prevent serious safety risks.

5. Cross-Border Transfers

Because WR Travel operates across Hong Kong, mainland China, and a global hotel network, your information may be transferred between the following jurisdictions: Hong Kong ↔ mainland China offices (Nanjing / Ningbo); Hong Kong / mainland ↔ countries where overseas hotels and service partners are located (including the EU, North America, Southeast Asia, Japan, etc.). We secure such transfers by: signing GDPR Standard Contractual Clauses (SCCs) or PIPL Standard Contractual Clauses with overseas recipients; passing the CAC outbound security assessment or personal information protection certification when required; encrypting all transfers in transit via TLS. To request the recipient list or a copy of the transfer agreement, email info@wildroadgroup.com.

6. Cookies and Third-Party Technical Services

We rely on the following third-party technical services to operate core functions: Cloudflare (global CDN, security, Turnstile bot defense) — your IP and device fingerprint are briefly processed, with data potentially transiting Cloudflare's global edge; Google Fonts (font delivery) — Google may briefly receive your IP at load time. We do not embed Google Analytics or advertising trackers on the site. The site itself sets no marketing cookies; only essential session storage required for form state and language switching (no cross-site tracking). If we later introduce analytics or marketing cookies, we will request your consent via a separate cookie banner.

7. Your Rights

You hold the following rights over your personal data and may exercise them anytime via info@wildroadgroup.com: (a) access; (b) correction of inaccurate information; (c) erasure (within statutory limits); (d) restriction of specific processing; (e) data portability (a copy in a structured, machine-readable format); (f) objection to specific processing; (g) withdrawal of consent. We will respond within 30 days; complex cases may be extended once with reasons provided to you.

8. Security Measures

We implement technical and organizational measures proportional to the sensitivity of the data: site-wide HTTPS encryption, Cloudflare edge security, Turnstile bot defense, STARTTLS/SSL for mail transport, least-privilege access to form submissions, and annual security awareness training. If a personal-data breach occurs that may harm your rights, we will notify the relevant regulator and affected individuals within the timeframes required by law (72 hours under GDPR; immediately under PIPL).

9. Data Retention

Inquiry data that does not result in a business relationship is cleared after 24 months. Client data for active business relationships is retained for the contract term plus statutory retention periods (including up to 7 years for tax and AML purposes). Server logs are retained for 90 days. Data beyond these periods is anonymized or destroyed. You may request earlier deletion (see Section 7).

10. Minors

We do not knowingly offer services to minors under 14, nor intentionally collect their personal data. If an adult guardian submits trip information on behalf of a minor (e.g. accompanying children), such data is used solely for that booking and is protected under this same policy. If you become aware we have inadvertently collected a minor's data, please contact info@wildroadgroup.com and we will verify and delete it.

11. Complaints and Remedies

If you believe our processing may violate the law or this policy, please first contact info@wildroadgroup.com — we commit to responding within 5 business days. If you are not satisfied, you may complain to the appropriate authority: (a) Hong Kong — the Office of the Privacy Commissioner for Personal Data (PCPD), pcpd.org.hk; (b) mainland China — your local public security bureau, the Cyberspace Administration of China, or the relevant industry regulator; (c) EU / UK — the data protection authority (DPA) in your member state, or the UK Information Commissioner's Office (ICO, ico.org.uk).

12. Updates to This Policy

This policy may be updated to reflect business or legal changes. Material changes (such as new data categories, sharing scope, or cross-border routes) will be highlighted on the homepage or notified by email, with the "Last updated" date on this page revised. Continued use of the site after an update constitutes acceptance; if you do not agree, you may stop using the site and request deletion of data already collected.

This policy may be updated from time to time. We will announce material changes on-site.