Privacy Policy
Last updated: 11 August 2026
1. Controller
The controller responsible for processing personal data in connection with our travel services and digital offerings is:
Tru Safari GmbHMühlauerstrasse 19
CH-5644 Auw
Switzerland
Phone: +41 56 664 80 80
Email: info@trusafari.ch
This Privacy Policy applies to Tru Safari GmbH in its capacity as a travel company and as the provider of the website, the travel-planning and customer-management system, the web-based customer portal, and the “Tru Safari” mobile app.
It is governed by Swiss data protection law, particularly the Federal Act on Data Protection (FADP), and, where applicable, the European Union General Data Protection Regulation (GDPR).
2. Scope of our data processing
This Privacy Policy applies in particular when you:
- visit our websites or use an online form or the Travel Planner;
- ask us to inquire about, plan, quote, or book a trip;
- are listed as a traveler or fellow traveler in an inquiry or booking;
- communicate with us by email, telephone, chat, social media, or another channel;
- access the digital customer portal using a personal link or QR code;
- voluntarily use the “Tru Safari” mobile app for your quote, booking, travel documents, or during your trip;
- use the optional “Tembo” AI travel assistant;
- contact us as a prospect, business partner, service provider, or representative of an organization.
We use our internal travel-planning system for advice, quotations, planning, booking, and operating trips. Customer and travel data is therefore processed in this system whether or not you later use the customer portal or mobile app. The mobile app is optional and is not required to make a booking.
3. Data we process
Depending on your contact with us and the services booked, we process the following categories of data in particular:
- Identity and contact data: first and last name, title/gender, language, address, place of residence, country, email address, and telephone number;
- Inquiry and planning data: requested countries and destinations, travel dates and duration, number of travelers, budget, accommodation category, interests, requested national parks and activities, flexibility, comments, and information concerning accompanying children;
- Booking and travel data: itinerary, accommodation, room and meal preferences, activities, guides, transfers, flights, tickets, booking status, prices, payments, invoices, vouchers, and correspondence with service providers;
- Identity and entry data: date of birth, nationality, passport and visa data, and copies of or information from identity and travel documents, where needed for a booking, entry requirements, or operating the trip;
- Fellow-traveler data: names, travel details, and information required for a joint booking. For children, this may include their age or date of birth;
- Sensitive data: health information, allergies, dietary or accessibility requirements, insurance information, and emergency information, but only where you provide it and it is needed for the trip;
- Documents: quotations, travel programs, flight tickets, accommodation and transfer vouchers, entry information, insurance and emergency documents, health information, and other travel-related files;
- Communication data: the content and metadata of emails, calls, forms, support requests, chat messages, and other correspondence;
- Portal and app data: personal access link or QR code/token, imported trips, last synchronization time, selected language, downloaded content, and questions and answers from the optional travel assistant;
- Technical and usage data: IP address, time and requested resource, browser and device type, operating system, app version, screen size, referrer, log and error data, and security events;
- Marketing and attribution data: campaign, advertising, and click parameters (such as UTM parameters or Google Click IDs), first landing page, referring page, and time of first visit where these details are present;
- Other data you voluntarily provide or that is necessary to deliver the agreed service.
The mobile app does not currently collect your contacts, precise device location, microphone recordings, or advertising ID. The app contains no personalized advertising and does not currently send push notifications. If this changes, we will update this Privacy Policy and any necessary consent or permission prompts before introducing the relevant feature.
4. Sources of data
We obtain personal data in particular:
- directly from you through forms, the online Travel Planner, email, telephone, personal conversations, the customer portal, or the app;
- from the lead traveler where that person provides information about fellow travelers;
- from travel agencies, partner agencies, hotels, airlines, transport providers, insurers, and other travel-service providers;
- from publicly available sources where this is necessary and permitted for contacting you or performing a contract;
- automatically when you use our websites, APIs, customer portal, or app, particularly in the form of technical, log, and security data.
If you provide data about another person, you confirm that you are authorized to do so, that the information is accurate, and that you have informed that person about this Privacy Policy.
5. Purposes of processing
We process personal data in particular:
- to respond to inquiries and provide personal travel advice;
- to create, adapt, and present travel proposals and quotations;
- to manage customer relationships in our travel-planning system;
- to take steps before entering into a travel contract and to conclude and perform that contract;
- to book and coordinate accommodation, flights, transfers, guides, activities, and other services;
- to process payments, keep accounts, issue invoices, and comply with legal obligations;
- to provide the web-based customer portal and, if you choose to use it, the mobile app with an offline itinerary and travel documents;
- to provide the optional “Tembo” travel assistant;
- to communicate with you, provide customer care, and handle changes, complaints, emergencies, and support requests;
- to maintain operations and information security, prevent misuse and fraud, and diagnose errors;
- to improve our trips, processes, websites, and digital offerings;
- to measure reach, assess campaign performance, and conduct direct marketing where permitted;
- to establish, exercise, or defend legal claims and cooperate with authorities.
We do not sell personal data or provide it to third parties for their own advertising in exchange for payment.
6. Legal bases
Under Swiss data protection law, we process personal data within the applicable legal framework. Where the GDPR applies, the legal basis depends on the purpose and may be:
- steps taken before entering into a contract and performance of a contract (Article 6(1)(b) GDPR);
- compliance with a legal obligation (Article 6(1)(c) GDPR);
- our or a third party’s legitimate interests, particularly in providing advice, managing customers, maintaining secure operations, preventing fraud, improving our services, and enforcing legal rights (Article 6(1)(f) GDPR);
- your consent where it is required (Article 6(1)(a) GDPR);
- for sensitive data or special categories of personal data, your explicit consent or another legally permitted basis (in particular Article 9(2) GDPR).
You may withdraw consent at any time with effect for the future. Processing completed before your withdrawal remains lawful.
7. Travel-planning system, customer portal, and mobile app
Travel-planning and customer-management system
We keep the customer and travel data needed for inquiries, quotations, bookings, and trip operations in our central system. This includes identity and contact data, preferences, itinerary variants, price and status information, itineraries, fellow travelers, booking and travel documents, and trip-related communications. Access is limited to authorized staff and contracted service providers on a need-to-know basis.
Personal link, QR code, and app access
The customer portal and app do not currently use a conventional user account with a username and password. For a particular quotation or trip, we give you a unique personal link or QR code. It contains an access token and acts like an access key. Keep it confidential and share it only with authorized fellow travelers. Tell us immediately if you suspect misuse.
The app can access a trip only after you scan the QR code or enter the personal link. Its use is optional. Until a trip is imported, the app does not process customer or travel data from our system.
Local processing on your device
When you import a trip into the app:
- the access link/token is kept in protected device storage, while travel information, your first name, itinerary, visible document metadata, images, and synchronization data are stored or cached locally so content is available offline;
- questions to “Tembo” and its answers are stored locally on your device as chat history;
- travel documents you intentionally download may be saved in your device’s Downloads folder;
- your selected app language is stored locally.
Your operating system or device-backup service may back up local app data according to your settings and the device provider’s privacy terms. Tru Safari does not directly control those backups.
Camera and file access
The camera is used only when you choose to scan a travel QR code. Camera frames are analyzed on the device and are neither uploaded nor stored by us; only the decoded access token is sent to our system. You can alternatively enter the personal link manually. On older Android versions, the app may request storage permission when you choose to save a document. The app does not scan your other files.
Maps
The app displays travel routes and places using Google Maps. The Google Maps SDK automatically collects technical request data (such as operating system, device model, app/SDK version, and IP address), a pseudonymous SDK identifier, and crash and diagnostic data. Depending on use, it may also collect map interactions such as panning and zooming. Google uses this data to provide, stabilize, measure, and improve its services. The app does not access the current location of your device. For details, see Google’s Privacy Policy.
8. Optional “Tembo” AI travel assistant
“Tembo” is an optional AI-based feature. When you submit a question, the following information is sent through our servers to our AI service provider and processed to generate the answer:
- your question and the previous chat history included with the current request;
- details of the active trip relevant to the answer, including destinations, dates, itinerary, accommodation, activities, flights, number of travelers, prices/budget, and, if part of the travel plan, information about accompanying children;
- relevant extracts from our internal travel documentation.
Your name, address, email address, and telephone number from the customer master record are not intentionally sent to the AI model. If you type this or any other personal or sensitive information into your question, however, it will be processed as part of your message. Do not enter passport data, payment data, health data, or other confidential information into “Tembo.”
Under our current configuration, AI processing takes place using Microsoft Azure OpenAI infrastructure in Switzerland. Microsoft processes the data as our IT service provider. Under the terms applicable to this enterprise service, prompts and outputs are not used to train the underlying models; limited processing for security, abuse detection, and technical operations may occur. We do not maintain the chat shown in the app as a permanent server-side customer profile; it is stored locally on your device. Technical logs remain reserved.
AI responses may be incorrect or incomplete. “Tembo” does not make automated decisions that have legal or similarly significant effects. Only confirmed booking and travel documents and information from our staff are binding.
9. Processing when you use our websites
Server logs
When you visit our websites, our servers or hosting providers process technically necessary data such as IP address, date and time, requested page, referrer, browser, operating system, and status code. We use this data to deliver the website, maintain security, diagnose errors, and prevent abusive access.
Local storage, cookies, and attribution data
Our websites use cookies and browser local storage. They may store your language selection, notice status, campaign and click parameters, first landing page, referrer, browser identifier, screen size, and time of first visit. When you submit an inquiry form, available attribution and campaign data may be sent to us together with your inquiry so we can attribute the request and assess advertising performance.
You may delete or block cookies and local data through your browser settings. This can affect individual features. Where required by law, we rely on your consent for non-essential measurement or marketing technologies.
Google reCAPTCHA
We use Google reCAPTCHA to protect our forms from automated misuse. This may send data such as your IP address, browser and device data, referrer, interactions with the website, and cookies set by Google to Google for risk analysis. The providers are Google Ireland Limited and affiliated companies, including Google LLC in the United States. The legal basis is our interest in securing our forms and, where required, your consent. Google’s Privacy Policy and Terms of Service apply.
Google Tag Manager, audience measurement, and advertising measurement
Some country websites may use Google Tag Manager to manage analytics and marketing tags. Depending on the active configuration, this can load Google services, particularly Google Analytics or Google Ads. Usage, device, campaign, and online-identifier data may be sent to Google. Active tags may differ between websites. We use this data for audience measurement, campaign attribution, and improving our offerings. Where required by law, the legal basis is your consent; otherwise, we rely on our legitimate interests. You can also use the privacy and advertising settings of your Google account.
External links and social media
Our websites contain links to external websites and social-media profiles. The relevant provider processes data under its own responsibility only after you open such a link. Its privacy terms then apply.
10. Recipients and processors
We disclose personal data only where this is necessary for the purposes described or legally permitted. Recipients may include:
- authorized staff and travel advisers working for us;
- local partner agencies, tour operators, hotels and lodges, airlines, transport providers, guides, activity providers, and other travel-service providers;
- insurers, banks, payment providers, and accounting providers where required for the relevant service;
- IT, hosting, cloud, database, storage, security, email, mapping, support, and AI providers, particularly Microsoft group companies and Google;
- travel agencies or business partners involved in your booking;
- legal, tax, insurance, and audit advisers;
- authorities, courts, consulates, border and immigration authorities where disclosure is legally required or needed for your trip.
Processors may use data only on our instructions and for the agreed purposes. Independent controllers—such as airlines, hotels, public authorities, and app-store operators—also process data under their own privacy terms.
11. International processing
We generally process data in Switzerland and also use service providers in Switzerland and the European Economic Area. Because travel and some IT services are international, data may be transferred to or accessed from other countries.
These countries include in particular:
- the destination and transit countries listed in your quotation, booking, or itinerary, for example Tanzania, Kenya, Uganda, Rwanda, Namibia, Botswana, South Africa, Zambia, Zimbabwe, Malawi, Madagascar, or Angola;
- EU and EEA member states for IT, communications, and business services;
- the United States and other countries where global providers such as Microsoft or Google operate affiliates, data centers, or support locations.
Where a destination country is not legally recognized as providing adequate data protection, we use appropriate safeguards where required, particularly recognized standard contractual clauses and supplementary safeguards. A transfer may also rely on a statutory exception, particularly where it is necessary to enter into or perform your travel booking, you have expressly consented, or the transfer is needed to establish, exercise, or defend legal claims.
12. Retention
We retain personal data only for as long as necessary for the relevant purpose. We then delete or anonymize it unless legal obligations or overriding interests require continued storage. The following criteria apply in particular:
- Customer, booking, and contract data: for the customer relationship and then according to statutory retention and limitation periods. Booking, business, and accounting records are generally retained for ten years;
- Inquiries without a booking: for as long as advice or later travel planning can reasonably be expected, and then only where needed for evidence, security, or legal purposes;
- Passport, health, and other sensitive travel data: only while needed for the booking, safe operation of the trip, emergencies, evidence, or legal obligations;
- Marketing data: until you withdraw consent, object, or the purpose no longer applies;
- Technical logs: for the limited period required for operations, error diagnosis, and security;
- Local app data: until you remove the trip in the app, delete the app data, or uninstall the app. You may need to delete downloaded documents separately in your device’s file system;
- Backups: until they are overwritten through our regular backup and overwrite cycles. Until then, they are used only for restoration and security.
13. Data deletion and local app data
The mobile app does not currently create a separate app user account. There is therefore no standalone app account that needs to be closed.
You can delete local data for an imported trip directly in the app: Info → Trips/Safaris → menu for the relevant trip → “Remove/forget trip.” This removes the local itinerary, access token, cached images, and local “Tembo” chat for that trip from the device. Uninstalling the app also removes app data, although separately downloaded documents may remain in the Downloads folder.
Removing a trip from the app or uninstalling the app does not automatically delete customer, booking, and travel data in our central system. We need to process this data for travel operations and legal obligations independently of the app.
You may request deletion of server-side data or revocation of digital access at any time by emailing info@trusafari.ch with the subject “Data deletion request – Tru Safari App.” Please provide the booking email address and enough information for us to verify your identity and the relevant trip. We generally process requests within 30 days or the applicable statutory period.
We will delete or anonymize the relevant data unless statutory retention duties, an ongoing booking, security interests, or legal claims require continued retention. If so, we will tell you which data must be kept and why.
14. Data security
We use appropriate technical and organizational measures to protect personal data. These include in particular:
- encrypted transmission using HTTPS/TLS;
- access restrictions and role-based authorization;
- authentication and logging of administrative access;
- protected device storage for app access tokens;
- backups, system monitoring, and security-incident procedures;
- contractual confidentiality and data-protection obligations for staff and service providers.
No system is completely secure. Protect personal links, QR codes, and downloaded travel documents against unauthorized access. Do not send passport, health, or other sensitive data through unprotected channels where we provide a more secure option.
15. Your rights
Subject to applicable data protection law, you may have the following rights:
- access to personal data we process about you;
- correction of inaccurate data and completion of incomplete data;
- deletion or anonymization unless retention duties or overriding reasons apply;
- restriction of processing where provided by law;
- objection to processing, particularly direct marketing;
- withdrawal of consent with effect for the future;
- delivery or transfer of certain data in a commonly used electronic format where provided by law;
- a complaint to the competent data-protection supervisory authority.
In Switzerland, the competent authority is the Federal Data Protection and Information Commissioner (FDPIC). In the EU or EEA, you may also contact the authority for your place of residence or work.
We may request proof of identity before handling a request. Rights may be restricted to the extent permitted by law, for example to protect another person, trade secrets, or comply with statutory retention duties.
16. Children’s data
Our app and websites are not independently directed at children. Parents, guardians, or the lead traveler provide information about minor fellow travelers only for planning and operating the trip. Minors should not submit data through forms or “Tembo” without the consent of a parent or guardian.
17. Changes to this Privacy Policy
We may update this Privacy Policy when our processing activities, digital offerings, or legal requirements change. The version published on this website is authoritative. For material changes, we will provide notice through an appropriate channel, such as the website, app, or email.