Resilience Expedition is a Tanzania-registered tour operator and travel agency based in Moshi, Kilimanjaro Region, Tanzania. We arrange Kilimanjaro climbs, Northern Circuit safaris, Ngorongoro crater packages, Zanzibar beach holidays, and combined expedition itineraries throughout Tanzania.
For the purposes of data protection law โ including the Tanzania Personal Data Protection Act (PDPA) and, where applicable, the European Union General Data Protection Regulation (GDPR) โ Resilience Expedition is the data controller responsible for your personal information.
Resilience Expedition ยท Moshi, Kilimanjaro Region, Tanzania ยท Email: tours@resilienceexpedition.com ยท Phone: +255 742 119 753 ยท Website: www.resilienceexpedition.com
By using our website, submitting an enquiry form, booking a trip, or communicating with us by any means, you acknowledge that you have read this Privacy Policy and agree to the collection and use of your information as described herein.
Personal identification data
- Full name (first name and last name)
- Email address
- Phone number and/or WhatsApp number
- Nationality and country of residence
- Passport number and expiry date (required for park permit applications)
- Date of birth (required for Kilimanjaro KINAPA permits)
Trip and booking data
- Safari or climb package selected, dates, and duration
- Group size and composition (adults, children, ages)
- Accommodation tier preference (budget, mid-range, luxury)
- Flight arrival/departure details and airline information
- Emergency contact name and phone number
- Travel insurance provider and policy number
Health and special requirements
- Dietary requirements and food allergies (to inform lodge and camp kitchens)
- Medical conditions relevant to high-altitude trekking (voluntarily disclosed for safety)
- Accessibility requirements or mobility considerations
- Medication declarations relevant to altitude (voluntary, for guide awareness)
Payment data
- We do not store payment card numbers, CVV codes, or banking credentials on our servers
- Payments are processed through secure third-party payment gateways (Stripe, bank transfer)
- We retain records of amounts paid, payment dates, and transaction references for accounting purposes
Technical and usage data
- IP address, browser type and version, operating system
- Pages visited, time spent on pages, referral source
- Device type (desktop, mobile, tablet)
- Cookie data (see Section 9 for full details)
Health information you voluntarily provide (such as medical conditions for altitude safety) is classified as "special category" data under GDPR. We collect this only with your explicit consent and use it solely to keep you safe during your trip. It is deleted after your trip concludes unless you request otherwise.
We collect your personal data through the following channels:
| Channel | Data collected | Purpose |
|---|---|---|
| Website enquiry forms | Name, email, phone, trip details, dates | Respond to your safari or climb enquiry |
| Booking confirmation forms | Full booking data, passport details, emergency contacts | Arrange all trip components |
| Email correspondence | Any information you share in emails | Trip planning and support |
| WhatsApp / phone calls | Contact and trip details discussed | Customer service and booking management |
| Google Analytics / cookies | Anonymous usage data, IP, device | Website improvement and analytics |
| Payment processors | Transaction confirmation (not card data) | Financial record-keeping |
| Review platforms | Reviews you post publicly (TripAdvisor, Google) | Service improvement (we do not store these) |
We do not purchase, rent, or obtain personal data lists from third parties. All data we hold has been provided directly by you or generated by your use of our website.
Primary purposes
- To respond to your safari, Kilimanjaro, or Zanzibar enquiry and provide a customised quote
- To arrange and confirm your booking โ including lodges, park permits, vehicle, guide, and transfers
- To apply for national park permits with TANAPA, NCAA, and KINAPA on your behalf (requires passport data)
- To communicate trip logistics, itinerary changes, safety briefings, and pre-departure information
- To provide emergency contact and medical information to guides for safety during your trip
- To process payments and maintain accurate financial records
- To issue invoices, receipts, and booking confirmations
Secondary purposes
- To send post-trip review requests (one email only, opt-out available)
- To send seasonal safari newsletters and offers โ only if you have subscribed or opted in
- To analyse website usage and improve content, navigation, and booking conversion (anonymised data)
- To comply with Tanzania tourism, tax, and record-keeping regulations
- To defend against legal claims or disputes where necessary
What we will never do
- Sell, rent, or trade your personal data to any third party for commercial gain
- Send you unsolicited marketing emails without your explicit consent
- Use your data for automated decision-making or profiling that produces legal effects
- Share your health or medical data with any party other than your assigned guide and lodge (for safety)
- Retain your data beyond the periods specified in Section 8
Under the GDPR (for customers in the EU/EEA/UK) and Tanzania's Personal Data Protection Act, every processing activity must have a lawful basis. Here is how our processing activities are lawfully justified:
| Processing activity | Legal basis |
|---|---|
| Responding to your enquiry | Pre-contractual steps โ Article 6(1)(b) GDPR |
| Processing your booking and arranging your trip | Contract performance โ Article 6(1)(b) GDPR |
| Submitting park permits to TANAPA/NCAA/KINAPA | Contract performance โ Article 6(1)(b) GDPR |
| Processing payment transactions | Contract performance โ Article 6(1)(b) GDPR |
| Retaining financial records for tax compliance | Legal obligation โ Article 6(1)(c) GDPR |
| Processing health/medical information (voluntary) | Explicit consent โ Article 9(2)(a) GDPR |
| Sending marketing newsletters (opted-in) | Consent โ Article 6(1)(a) GDPR |
| Website analytics (Google Analytics) | Legitimate interests โ Article 6(1)(f) GDPR |
| Defending legal claims | Legitimate interests โ Article 6(1)(f) GDPR |
Where we process your data on the basis of consent (marketing emails, health data), you may withdraw that consent at any time by emailing tours@resilienceexpedition.com. Withdrawal does not affect the lawfulness of any processing carried out before withdrawal. It will not affect your ability to book or travel with us.
Resilience Expedition is based in Tanzania. If you are located in the European Economic Area (EEA), United Kingdom, or another jurisdiction with data transfer restrictions, please be aware that your personal data will be transferred to and processed in Tanzania, which may not have data protection laws equivalent to your home country.
We transfer your data internationally only where:
- The transfer is necessary to perform your safari or climb booking contract โ for example, submitting your passport details to TANAPA, NCAA, or KINAPA for permit registration
- The transfer is to tools that provide adequate safeguards โ Google Workspace (Google LLC), which maintains Standard Contractual Clauses (SCCs) approved by the European Commission
- You have provided explicit consent to the transfer after being informed of the risks
For EEA/UK customers, we rely on the necessity of contract performance (Article 46(2)(c) GDPR) and SCCs as the primary safeguards for international transfers. A copy of the applicable transfer mechanism is available on request by emailing tours@resilienceexpedition.com.
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by law. Our retention periods are:
| Data type | Retention period | Reason |
|---|---|---|
| Enquiry data (no booking made) | 12 months from last contact | Follow-up and business planning |
| Booking and trip records | 7 years from trip completion date | Tanzania tax and accounting law (TRA requirements) |
| Passport and permit data | Deleted 6 months after trip completion | No longer required once permits used |
| Emergency contact and health data | Deleted immediately after trip completion | Special category data โ minimal retention |
| Payment transaction records | 7 years from transaction date | Tanzania Revenue Authority (TRA) legal requirements |
| Marketing list (subscribed) | Until you unsubscribe + 30 days suppression | Consent withdrawal compliance |
| Website analytics data | 26 months (Google Analytics default) | Statistical anonymised data โ no personal identifiers |
After retention periods expire, data is permanently deleted from our systems and from all cloud services we use. If you wish to request earlier deletion, please contact us at tours@resilienceexpedition.com (see Section 10 โ Your Rights).
Our website uses cookies โ small text files placed on your device โ to improve your browsing experience, understand how visitors use our site, and occasionally to show relevant content. Here is a breakdown of the types of cookies we use:
Managing your cookie preferences
You can control and/or delete cookies as you wish. You can delete all cookies that are already on your computer, and you can set most browsers to prevent them from being placed. However, if you do this, you may have to manually adjust some preferences every time you visit our site.
- Browser settings: All major browsers allow you to control cookies through their settings/preferences. Search your browser's help documentation for "cookies"
- Google Analytics opt-out: Install the Google Analytics Opt-out Browser Add-on at tools.google.com/dlpage/gaoptout
- Cookie banner: When you first visit our site, our cookie consent banner allows you to accept or decline optional cookies
Under applicable data protection law, you have the following rights regarding your personal data. To exercise any of these rights, email tours@resilienceexpedition.com. We will respond within 30 calendar days (or within the statutory timeframe required by applicable law).
Request a copy of all personal data we hold about you (a Subject Access Request / SAR).
Request correction of inaccurate or incomplete personal data we hold about you.
Request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements.
Request that we pause processing your data in certain circumstances โ for example, while accuracy is disputed.
Receive your personal data in a structured, machine-readable format, and transfer it to another service.
Object to processing based on legitimate interests (e.g. analytics) or to direct marketing at any time.
Withdraw consent at any time where processing is consent-based โ including unsubscribing from marketing.
Complain to a supervisory authority โ in Tanzania, the TCRA; in the EU, your local Data Protection Authority.
Email tours@resilienceexpedition.com with the subject line "DATA REQUEST โ [Your Full Name]". Include your name and the email address you used when enquiring or booking. We may request proof of identity before processing your request. There is no fee for standard requests.
Our website is not directed at children under the age of 16, and we do not knowingly collect personal data from children under 16 without verifiable parental or guardian consent.
When a child under 16 travels with us as part of a family group, their personal data (name, nationality, passport details, age) is collected for the sole purpose of national park permit applications (all visitors must be registered, regardless of age). This data is:
- Provided by the parent or legal guardian โ not collected directly from the child
- Used only for permit applications to TANAPA, NCAA, or KINAPA
- Deleted 6 months after trip completion in line with our retention schedule
- Never used for marketing or any purpose other than the booking and trip delivery
If you believe we have inadvertently collected data relating to a child under 16 without appropriate consent, please contact us immediately at tours@resilienceexpedition.com and we will delete it promptly.
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, accidental loss, destruction, or alteration.
Technical safeguards
- Our website is served over HTTPS with TLS encryption on all pages
- Enquiry and booking forms transmit data over encrypted connections
- Email communications are handled through Google Workspace, which provides encryption at rest and in transit
- Payment processing is handled exclusively by PCI-DSS compliant payment processors (Stripe). We never see or store your card details
- Access to customer data within our team is restricted on a need-to-know basis
- Team accounts use two-factor authentication (2FA) where available
Organisational safeguards
- Staff are trained on data protection principles and confidentiality obligations
- Third-party service partners are contractually required to maintain equivalent security standards
- We conduct periodic reviews of our data handling practices
- Physical documents containing personal data (printed booking forms) are stored securely and shredded after use
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by applicable law.
While we implement these measures, no internet transmission is 100% secure. We cannot guarantee absolute security of data transmitted to our site, but we will notify you promptly in the event of a breach affecting your data.
Our website may contain links to external websites operated by third parties โ such as national park authority websites, hotel booking platforms, review sites (TripAdvisor, Google), social media platforms (Facebook, Instagram), and payment processors.
This Privacy Policy applies only to the Resilience Expedition website and the data we process. When you click a link to an external site, you leave our jurisdiction and the third party's own privacy policy applies. We:
- Are not responsible for the privacy practices or content of any third-party websites
- Do not endorse, monitor, or control third-party privacy policies
- Recommend you read the privacy policy of any external website before submitting personal data to it
Third-party services embedded in or used alongside our website include:
- Google Analytics โ usage analytics. Privacy policy: policies.google.com/privacy
- Google Maps โ embedded maps. Privacy policy: policies.google.com/privacy
- Stripe โ payment processing. Privacy policy: stripe.com/privacy
- WhatsApp (Meta) โ customer messaging. Privacy policy: whatsapp.com/legal/privacy-policy
- Unsplash โ photography sourcing. Privacy policy: unsplash.com/privacy
We reserve the right to update this Privacy Policy at any time to reflect changes in our data practices, legal requirements, or business operations. When we make material changes, we will:
- Update the "Last updated" date at the top of this page and in the hero section
- Where the change materially affects how we process your data, notify active customers by email
- Maintain the previous version of this policy, available on request from tours@resilienceexpedition.com
We encourage you to review this Privacy Policy periodically. Your continued use of our website or services after any changes constitutes acceptance of the updated policy.
Version history
| Version | Date | Key changes |
|---|---|---|
| v1.0 โ Initial | 1 January 2024 | First published policy |
| v1.1 | 15 March 2025 | Added children's data section; updated retention periods |
| v1.2 | 1 January 2026 | Added Tanzania PDPA references; updated cookie types |
| v1.3 โ Current | 24 April 2026 | Added international transfer safeguards; expanded rights grid; updated third-party list |
If you have any questions, concerns, or complaints about this Privacy Policy or the way we handle your personal data, please contact us using the details below. We are committed to resolving any data protection concerns fairly and promptly.
Resilience Expedition
Moshi, Kilimanjaro Region, Tanzania
Email: tours@resilienceexpedition.com
Phone: +255 742 119 753
WhatsApp: +255 742 119 753
Website: www.resilienceexpedition.com
If you are not satisfied with our response
If you have raised a concern with us and are not satisfied with our response, you have the right to lodge a complaint with the relevant data protection supervisory authority:
- Tanzania: Tanzania Communications Regulatory Authority (TCRA) โ tcra.go.tz โ which oversees the Tanzania Personal Data Protection Act
- EU/EEA residents: Your local national Data Protection Authority (DPA). A full list is available at edpb.europa.eu
- UK residents: Information Commissioner's Office (ICO) โ ico.org.uk โ helpline: 0303 123 1113
We always prefer the opportunity to address your concern directly before you escalate to a supervisory authority. Please contact us first โ we aim to resolve all data protection concerns within 30 calendar days.