Last updated: May 2026
EME International SARL ("EME," "we," "us," or "our") operates the EME website and tour-operator services. This Privacy Policy explains how we collect, use, store, and protect your personal information, and the rights you have over that information under the EU General Data Protection Regulation (GDPR), applicable national data protection laws, and — where you access the service from the United States — applicable US state privacy laws.
Data controller: EME International SARL, a company registered in Lebanon, 4th Floor, Final Touch Spa Building, Fanar Main Road, Lebanon. Registry code: 2012754 (Mount Lebanon Commercial Register).
For privacy questions, data-subject requests, or to contact our data-protection point of contact, email [email protected]. We aim to respond within five business days and to fulfil rights requests within one month, extendable by a further two months for complex requests (GDPR Article 12).
We collect the following categories of information:
What we do not collect. We do not knowingly collect special categories of personal data under GDPR Article 9 (health, race, religion, sexual orientation, biometric or genetic data, political opinions, trade-union membership). Please do not submit such information through trip notes, prompts, or support messages. If accessibility-related information is necessary for performing a package booking, we will collect only the minimum needed and with your explicit consent.
We process personal data only where we have a lawful basis under GDPR Article 6:
| Purpose | Legal basis |
|---|---|
| Account creation and authentication | Contract (Art. 6(1)(b)) |
| Saving trips and itineraries | Contract (Art. 6(1)(b)) |
| Recommender results and prompts | Contract (Art. 6(1)(b)) |
| Package booking, payment, performance | Contract (Art. 6(1)(b)) |
| Service security, fraud prevention, abuse detection | Legitimate interests (Art. 6(1)(f)) |
| Analytics and product improvement (aggregated) | Legitimate interests (Art. 6(1)(f)) |
| Non-essential cookies, marketing emails | Consent (Art. 6(1)(a)) — withdrawable at any time |
| Accounting records, tax reporting, regulator requests | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we balance those interests against your rights and freedoms. You may object to processing based on legitimate interests at any time — see section 13.
Age policy. EME is a service for adults planning travel. The service is not directed at children. We do not knowingly create accounts for, market to, or solicit personal information from children under the age of 16. In EU member states that set a lower digital-consent age under GDPR Article 8 (some allow as low as 13), users below 16 but at or above their national consent age may use the service only with verifiable consent from a holder of parental responsibility.
United States — COPPA.For visitors from the United States, we do not knowingly collect personal information from children under 13 as defined by the Children's Online Privacy Protection Act. If you are under 13, please do not create an account or submit information through the website.
Children included in adult bookings. Adult travellers may include children as passengers in a trip or package. In that case, we collect only the data strictly needed to deliver the travel services (first name, age band, special dietary or accessibility requirements where you provide them). The adult booker is responsible for confirming that they have authority to share information about accompanying minors and for informing them in age-appropriate terms.
No profiling or behavioural advertising directed at minors. We do not profile minors, run automated decision-making against them, or display behaviour-based advertising. Minors' data is never used to train AI models, by us or by any sub-processor.
Discovery and deletion. If we learn that we have collected personal data from a child in violation of this section, we will delete that data without undue delay. Parents or guardians who believe their child has provided personal data to EME may email [email protected] with the subject line "Child data deletion request" and we will action it within 14 days.
We use a small number of cookies and equivalent client-side storage mechanisms. Cookies that are not strictly necessary are loaded only with your consent, recorded through our cookie banner. You can change your choice at any time by clearing theeme_cookie_consentvalue in your browser's site-data settings, which will cause the banner to reappear.
| Category | Purpose | Duration | Consent |
|---|---|---|---|
| Strictly necessary | Authentication session, CSRF protection, load balancing | Session — 30 days | Not required (essential) |
| Preferences | Remembering selected interests, recent trip, cookie choice | Up to 12 months | Not required (essential to feature you used) |
| Analytics | Aggregated usage statistics to improve the product | Up to 13 months | Consent required |
| Marketing / advertising | We do not currently use marketing or cross-site tracking cookies. | — | Would require consent if introduced |
We honour the Global Privacy Control (GPC) signal sent by your browser as a request to opt out of non-essential tracking and the sale or sharing of personal information.
We rely on carefully selected sub-processors to operate the service. Each is bound by a written data-processing agreement meeting GDPR Article 28 requirements:
| Provider | Purpose | Location | Transfer basis |
|---|---|---|---|
| Neon (Postgres database) | Storage of account, trip, and recommendation data | EU (Frankfurt) | EEA — no transfer |
| Vercel | Hosting, edge delivery, server-side rendering | EU primary; US fallback | EU-US Data Privacy Framework + SCCs |
| Anthropic | LLM router for the Europe Recommender | United States | Standard Contractual Clauses; zero-retention configuration; no model training on inputs |
| Stripe | Payment processing | Ireland + United States | EU-US Data Privacy Framework + SCCs |
| OAuth sign-in, Places autocomplete | United States | EU-US Data Privacy Framework | |
| Travelpayouts / Aviasales | Flight search and affiliate links | Cyprus / outside EEA | Standard Contractual Clauses |
| OpenStreetMap | Map tiles | EU / UK | EEA / UK adequacy |
| Wikimedia / Unsplash | Open-licence destination imagery | United States | Public domain / open-licence content; no personal data shared |
We never sell your personal information. We do not share personal data with data brokers, ad networks, or any party other than the sub-processors listed above. An up-to-date list of sub-processors is available on request from [email protected].
Personal data is stored in encrypted databases in the European Economic Area, with access restricted to authorised systems and personnel under written confidentiality obligations. Passwords are hashed using industry-standard algorithms and are never stored in plain text. We use TLS for data in transit, role-based access controls, audit logging, and least-privilege principles. We regularly review our technical and organisational measures against ENISA guidance and update them as the threat landscape evolves.
We retain personal data only for as long as needed for the purpose it was collected, or as required by law:
| Data | Retention |
|---|---|
| Active account, trips, preferences | Until you delete your account |
| Deleted-account residue (backups) | Up to 30 days after deletion, then permanently removed |
| Recommender prompts and outputs | 90 days for quality monitoring, then anonymised or deleted |
| Server and security logs | Up to 90 days |
| Support correspondence | Up to 24 months after the ticket closes |
| Marketing consent records | 3 years from last interaction or until withdrawn |
| Accounting, tax, invoice records | 7 years (statutory accounting-record retention) — overrides earlier deletion |
| Package travel contract documentation | 3 years after the trip ends (limitation periods) |
Where a legal obligation requires us to retain data after you have asked us to delete it, we will restrict its processing to that obligation only and erase it once the period expires.
Where personal data is transferred outside the European Economic Area — for example to sub-processors listed in section 7 — EME relies on a lawful transfer mechanism: an adequacy decision (e.g. the EU-US Data Privacy Framework for participating US recipients, or the Commission adequacy decision for Canada), Standard Contractual Clauses combined with a documented Transfer Impact Assessment, or another mechanism permitted under GDPR Chapter V. A copy of the relevant safeguards is available on request from [email protected].
The Europe Recommender uses AI. When you submit a prompt to the Recommender, EME forwards it together with selected preferences (interests, budget tier, traveller type) to a large language model operated by Anthropic, which returns scored destination matches. The router uses your prompt to extract travel concepts and to rank options in our destination catalogue.
How decisions are made. The output is a recommendation, not a binding decision. You remain in control of every choice — whether to view a destination, save a trip, or proceed to checkout. We do not use the Recommender to deny services, set prices on an individual basis, or take other consequential automated decisions about you. Accordingly, GDPR Article 22 (automated individual decisions with legal or similarly significant effects) does not apply, but we still afford you the right to obtain an explanation, contest a result, and request a human review at [email protected].
EU AI Act transparency. The Recommender is a general-purpose AI system used for limited-risk personalisation within the meaning of the EU AI Act. You are interacting with an AI system whenever you see Recommender output. AI is not used in our package-travel decision-making, complaints handling, or customer-support conversations.
No training on your data.Anthropic operates under a zero-retention configuration for our traffic, and your prompts and outputs are not used to train Anthropic's models, EME's models, or any third party's models. We do not sell prompts or outputs to data brokers.
We send marketing emails — such as new-destination announcements, seasonal offers, or product news — only where you have given separate, explicit opt-in consent (for example by ticking a newsletter checkbox at sign-up or in your profile). Every marketing message contains a one-click unsubscribe link. You can also withdraw consent at any time from your profile settings or by emailing [email protected]. Withdrawing consent does not stop transactional or service-critical messages (booking confirmations, password resets, security alerts), which are sent on the contractual basis in section 3.
You have the right to:
To exercise any of these rights, contact us at [email protected]. You also have the right to lodge a complaint with the data protection supervisory authority in your EU member state of residence.
If you are a resident of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, or another US state with a comprehensive consumer-privacy law, you may have additional rights including:
To exercise a US-state right, email [email protected] with the subject line "US state privacy request" and your state of residence. We will verify your identity through your registered email before fulfilling the request. We do not charge a fee for exercising these rights and we do not discriminate against consumers who exercise them.
In the event of a personal-data breach likely to result in a risk to your rights and freedoms, EME will notify the competent data protection supervisory authority without undue delay and where feasible within 72 hours of becoming aware of the breach, in line with GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, in line with Article 34, describing the nature of the breach, the likely consequences, and the measures we are taking.
We may update this Privacy Policy from time to time. Material changes will be communicated through a prominent notice on the platform and, where you have an account, by email at least 14 days before they take effect. We will keep prior versions available on request. Continued use of EME after changes take effect constitutes acceptance of the updated policy. We encourage you to review this page periodically.
Questions about your privacy? Contact us at [email protected]. We aim to respond within five business days.