GDPR transparency, marketing, retention and operational data sharing.
Version 3.0 · Effective 31 July 2026
SIA “BCOM TRAVEL”, registration number 40203370984, VAT number as stated on the applicable invoice, where registered, registered address Mālpils iela 2B-1, Rīga, LV-1013, Latvia, operating under the BusCom brand (“BusCom”, “we”, “us” or “our”), is the controller for the personal data described in this Privacy Policy, and is the sole entity operating the BusCom website and contracting through the BusCom brand, unless mandatory law provides otherwise.
Privacy enquiries and data-subject requests may be sent to privacy@buscom.info or to the registered address above. We do not currently appoint a Data Protection Officer unless legally required; privacy enquiries are handled by the person designated internally for data protection.
This Policy applies when a person visits our website, submits a form, contacts us by email, telephone, messaging service or social media, requests or receives a quotation, makes or manages a booking, travels as part of a group, supplies services to us, applies to work with us, or otherwise interacts with BusCom.
It also applies when a group organiser, employer, school, travel agency, choir, event organiser, family member or other person provides information about passengers or group leaders.
Identity and contact data: names, job titles, organisation, postal address, email address, telephone number, preferred language and communication preferences.
Quotation and booking data: dates, itinerary, pickup and drop-off points, intermediate stops, group size, vehicle requirements, luggage, flights, trains, ferries, accommodation, accessibility requirements, child-seat requests and other operational instructions.
Passenger and group-leader data: group-leader name and contact details, emergency contacts and limited passenger information where genuinely necessary. We do not ordinarily need a complete passenger list for private charter services.
Billing and payment data: billing identity, address, registration and VAT numbers, invoice records, payment status, transaction references, payment method and fraud-prevention information. Full card details are processed by authorised payment providers and are not intended to be stored by BusCom.
Communication and service data: emails, messages, call notes, changes, complaints, feedback, reviews, photographs supplied to us and records of service performance.
Marketing data: the source of a contact, consent record where consent is used, campaign delivery data, preferences, objections, unsubscribe requests and suppression-list records.
Technical data: IP address, browser, device, approximate location, referral source, pages viewed, cookie identifiers, security logs and interaction data, subject to cookie-consent requirements.
Supplier data: contact, company, licence, insurance, vehicle, bank, tax, contract, dispatch and performance information relating to transport operators, drivers and other service providers.
Special-category data: only where strictly necessary, for example limited accessibility or health information needed to arrange safe transport. We ask users not to provide such information unless required.
We obtain data directly from the individual, from the person or organisation arranging transport, from passengers or group leaders, from transport operators and drivers, from payment and technology providers, from public registers and public business sources where lawful, and from prior correspondence.
Anyone providing another person’s data must be authorised to do so and should make this Policy available to that person.
Quotation and pre-contract steps: to assess an itinerary, obtain supplier availability, calculate a price and answer an enquiry. Basis: steps requested before entering a contract and legitimate interests in responding to business enquiries.
Booking and service delivery: to confirm, coordinate, modify and perform transport, communicate operational information and manage disruptions. Basis: performance of a contract, legitimate interests and legal obligations.
Payments, accounting and tax: to invoice, reconcile, prevent fraud, maintain records and comply with tax and accounting obligations. Basis: contract, legal obligation and legitimate interests.
Customer support and complaints: to investigate, preserve evidence, resolve disputes and improve services. Basis: contract, legal obligations and legitimate interests.
Safety and legal compliance: to meet transport, sanctions, anti-fraud, insurance, court, regulator and law-enforcement requirements. Basis: legal obligation, substantial public interest where applicable, and legitimate interests.
Supplier management: to evaluate, contract, dispatch, pay and monitor transport operators and drivers. Basis: contract, legal obligation and legitimate interests.
Website security and essential functionality: to protect systems, prevent abuse and provide requested features. Basis: legitimate interests and, where relevant, contract.
Analytics and advertising: only when required consent has been obtained for non-essential cookies or similar technologies.
Direct marketing: consent where required; the statutory existing-customer exception only where every condition is satisfied; and carefully assessed legitimate interests for permitted business-to-business communications. A quotation request alone does not automatically constitute consent.
Operational messages about a quotation, booking, payment, itinerary, service issue or complaint are not marketing.
For promotional communications to natural persons, we obtain consent where the law requires it. We may use an existing-customer exception only where the address was obtained in connection with an actual sale or provision of services, the communication concerns our own similar services, a clear free opt-out was offered when the address was collected and in every message, and the recipient has not objected.
For relevant contacts acting in a professional capacity, we may send narrowly targeted business communications where lawful, proportionate and expected in context. We do not use this wording to override stricter national rules applicable in the recipient’s country.
A person may object or unsubscribe at any time. We stop marketing without undue delay and retain a minimal suppression record so the address is not accidentally re-imported. Suppression data is not used for any other purpose.
Before a booking is confirmed, we may need to disclose limited itinerary information to potential transport operators to obtain availability and pricing. We should not disclose a passenger or group leader’s identity or direct contact details at that stage unless operationally necessary and lawful.
After confirmation, we may share the minimum information necessary with the assigned licensed transport operator, dispatcher and driver. This will normally include the itinerary, group size, group leader’s name and telephone number, and relevant operational or accessibility information.
We may also share data with payment processors, banks, fraud-prevention services, website and cloud hosts, email and CRM providers, customer-support and communications providers, accountants, auditors, insurers, lawyers, debt-recovery providers, regulators, courts, police and public authorities where necessary.
We do not sell or rent personal data for third parties’ own marketing. Service providers may process data only for contracted purposes and under appropriate protections.
Some technology providers or transport partners may process data outside the European Economic Area. Where a destination is not recognised as adequate, we use a lawful transfer mechanism such as European Commission Standard Contractual Clauses and assess supplementary safeguards where required.
Information about a specific transfer mechanism may be requested from us.
| Record | Normal retention |
|---|---|
| Unsuccessful quotation files | 24 months after the last meaningful contact, unless a shorter period is appropriate or a longer period is needed for a dispute, legal claim, fraud prevention or documented business-to-business relationship |
| Confirmed booking and contract records | 10 years after completion or termination, where needed for accounting, tax, insurance, contractual and legal-claim purposes |
| Invoices and accounting source documents | The period required by Latvian accounting and tax law, normally at least 5 years and longer where a specific rule or audit requires it |
| Complaints and incident records | 5 years after closure, or longer where a claim, insurance matter or legal proceeding remains open |
| Call recordings, if used | A short published period appropriate to purpose, typically 90 days, unless preserved for a complaint or legal matter |
| Marketing consent and campaign records | While marketing continues and for up to 3 years afterwards as evidence of compliance, subject to periodic review |
| Suppression records | As long as reasonably necessary to ensure that the objection is respected, typically indefinitely unless a reliable alternative prevents future contact |
| Website security logs | Usually 6 to 12 months unless an incident requires longer retention |
| Supplier due-diligence and contract records | For the relationship and normally 10 years afterwards where needed for legal, tax, insurance and contract purposes |
Marketing use is governed separately and does not automatically continue for the whole retention period. We periodically review retained data and delete or anonymise it when no longer necessary.
We use access controls, role-based permissions, strong authentication, backups, encryption where appropriate, logging, staff confidentiality, supplier due diligence and incident-response procedures proportionate to the risks.
No system is completely secure. Anyone who suspects misuse of information or an account compromise should contact us promptly.
Subject to applicable conditions, individuals may request access, correction, erasure, restriction, portability, objection, and information about automated decision-making. Consent may be withdrawn at any time without affecting prior lawful processing.
The right to object to direct marketing is absolute. Other objections depend on the circumstances and legal basis.
We may verify identity before acting. We normally respond within one month, subject to lawful extensions for complex or numerous requests.
We may use software, analytics or artificial-intelligence-assisted tools to organise enquiries, compare historical data, detect duplicates, route requests and support pricing decisions. These tools assist staff and do not ordinarily make a decision producing legal or similarly significant effects without meaningful human involvement.
Where we introduce qualifying solely automated decision-making, we will provide the information and safeguards required by law.
Our website is directed to adults arranging transport. Passenger groups may include children, but organisers should provide only the minimum information needed. The organiser is responsible for permissions, supervision and safeguarding obligations that apply to the group.
Strictly necessary cookies may operate without consent where permitted. Analytics, advertising and other non-essential technologies are activated only after valid consent where required. Details appear in our Cookie Policy and consent-management tool.
Please contact us first so we can address a concern. Individuals also have the right to complain to the Latvian Data State Inspectorate or, where applicable, the supervisory authority in their country of residence, work or alleged infringement.
We may update this Policy to reflect legal, operational or technical changes. The effective date will be shown at the top. Material changes will be brought to attention through an appropriate channel. A new policy does not retrospectively create consent.