Last updated: 28 July 2026
privacy policy
This Privacy Policy explains how Africa Cycling Safaris collects, uses, discloses and protects personal information when you visit our website, enquire about or book a cycling safari, or otherwise interact with us. It is operated by Kapen Africa (Pty) Ltd (South Africa) and Kapen Africa Limited (United Kingdom).
1. Introduction
Kapen Africa (Pty) Ltd, a company registered in South Africa (registration number [XXXX/XXXXXX/07]), with its registered address at [registered address, South Africa] (“Kapen Africa SAâ€); and Kapen Africa Limited, a company registered in England and Wales (company number [XXXXXXX]), with its registered address at [registered address, UK] (“Kapen Africa UKâ€), together referred to as “Kapen Africaâ€, “weâ€, “us†or “ourâ€. Kapen Africa SA and Kapen Africa UK act as joint controllers (or, under POPIA, joint responsible parties) of personal information collected in connection with Africa Cycling Safaris. Kapen Africa SA is generally responsible for tour operations, guiding and logistics in South Africa and neighbouring countries; Kapen Africa UK is generally responsible for marketing and customer relationships with guests based in the United Kingdom and European Economic Area (“EEAâ€).
This policy is designed to meet our obligations under the UK General Data Protection Regulation and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025 (together, “UK GDPR”); the EU General Data Protection Regulation, Regulation (EU) 2016/679 (“EU GDPR”); and the Protection of Personal Information Act 4 of 2013 of South Africa (“POPIA”). Where these laws use different terms for the same concept, this policy uses them interchangeably and intends them to carry the equivalent meaning under each applicable law.
2. Scope of This Policy
This policy covers personal information collected through:
• our website [www.africacyclingsafaris.com] (the “Siteâ€)
• booking enquiry and reservation forms
• email, telephone, WhatsApp and social media correspondence
• pre-trip questionnaires, including medical, dietary and emergency-contact information
• your tour itself (e.g. photographs, route/GPS data, incident reports)
• newsletter and marketing sign-ups
It does not cover third-party websites or services we link to or work with, such as individual accommodation providers, airlines, tour partners or insurers, who maintain their own privacy policies.
3. Personal Information We Collect
• Identity and contact data: full name, date of birth, nationality, passport/ID number and expiry date, gender, phone number, postal and email address.
• Booking and payment data: tour selection, dates and group composition, billing address, payment details (processed by our payment provider — see section 8), invoicing history.
• Travel and logistics data: flight details, visa status, accommodation preferences, next-of-kin and emergency contact details.
• Health and fitness data: cycling ability and experience, relevant medical conditions, allergies, medication and fitness-to-participate declarations. This is “special category data” under GDPR and “special personal information” under POPIA — see section 7.
• Marketing preferences: newsletter subscriptions, communication preferences, survey responses, reviews and testimonials.
• Website and technical data: IP address, browser and device type, pages visited, referring site, cookies and similar identifiers (see section 9).
• Images and video: photographs and video taken during tours for safety records and, with your consent, for marketing.
We collect most of this directly from you. We may also receive information from travel agents or partners booking on your behalf, from publicly available sources, and from service providers such as payment processors or fraud-prevention services.
4. How and Why We Use Your Information
The list below sets out our main purposes and the corresponding legal basis under UK/EU GDPR and the applicable condition under POPIA.
• Process bookings, arrange logistics and deliver the tour you purchased — Performance of a contract (Art. 6(1)(b)) / Necessary for a contract to which you are a party
• Assess fitness to participate and arrange safety measures for cycling in remote / wildlife areas — Explicit consent for special category data (Art. 9(2)(a)); vital interests where relevant / Consent; protecting a legitimate interest of the data subject
• Communicate about your booking (confirmations, itinerary changes, safety alerts) — Performance of a contract; legitimate interests / Necessary for the contract; legitimate interest
• Comply with immigration, customs, park authority or conservation requirements — Legal obligation (Art. 6(1)(c)) / Compliance with a legal obligation
• Send marketing about new tours and offers — Consent, or legitimate interests (existing customers, soft opt-in) / Consent (direct marketing under s.69 requires opt-in, subject to a narrow existing-customer exception)
• Improve our website and services; analytics — Legitimate interests / Legitimate interest, provided it does not override your rights
• Prevent fraud and maintain security — Legitimate interests; legal obligation / Legitimate interest / legal obligation
• Establish, exercise or defend legal claims — Legitimate interests; legal obligation / Legitimate interest / legal obligation
5. Marketing Communications
We will only send you marketing by email or other electronic means with your consent, or — for South African data subjects — where you are an existing customer, we are marketing similar products or services, and you were given a clear opportunity to opt out at the point of collection (POPIA s.69(3)). You can withdraw consent or opt out at any time using the unsubscribe link in any marketing communication, or by contacting us (section 15).
6. Cookies and Similar Technologies
Our Site uses cookies and similar technologies to operate correctly, remember your preferences, and understand how visitors use the Site. We use the following categories:
• Strictly necessary cookies — required for the Site to function (e.g. maintaining your session during a booking enquiry). These do not require consent.
• Functional cookies — remember your preferences (e.g. currency or language).
• Analytics cookies — e.g. [Google Analytics], helping us understand Site usage in aggregate.
• Marketing/advertising cookies — e.g. [Meta/Facebook Pixel], used to measure and target advertising, set only with your consent.
Under the UK’s Privacy and Electronic Communications Regulations (“PECR”) and the EU’s ePrivacy rules, we ask for your consent via a cookie banner before setting non-essential cookies, and you can change your preferences at any time via [cookie settings link]. You can also control cookies through your browser settings, though blocking cookies may affect how the Site functions.
7. Special Category / Health Data
Because our tours involve physically demanding cycling in remote areas, and in some cases Big Five wildlife reserves, we ask you to disclose relevant medical conditions, allergies, medication and fitness information before your trip. We collect this data:
• with your explicit, freely given consent;
• strictly to assess suitability for the tour, brief our guides, and respond appropriately in a medical emergency; and
• with access limited to guides, safety personnel and management directly involved in running your trip.
You may decline to provide this information, but this may affect our ability to accept your booking or to accommodate your needs safely.
8. Who We Share Your Information With
We share personal information only where necessary, with:
• ground operators, guides and accommodation providers, to deliver your itinerary;
• payment processors (e.g. [Payfast / Stripe / PayGate]), to process payments securely — we do not store full card details ourselves;
• travel insurers, where you purchase or are required to hold travel insurance;
• park authorities, conservancies and immigration/border control, where required for permits, conservation fees or entry requirements;
• IT, hosting, email and CRM service providers, who process data on our behalf under written data processing agreements;
• professional advisers and regulators, where necessary for legal, accounting or compliance purposes; and
• emergency services and next of kin, in a genuine emergency.
We do not sell your personal information. Any third party processing data on our behalf is contractually bound to protect it and use it only for the purposes we specify, consistent with Article 28 GDPR and the “operator” obligations under POPIA section 21.
9. International Data Transfers
Kapen Africa operates across South Africa, the United Kingdom and, through guests and partners, the EEA and other African countries (e.g. Botswana, Namibia, Zambia). Personal information may be transferred between these regions.
Transfers from the UK or EEA to South Africa: South Africa does not currently hold a formal UK or EU adequacy decision. We therefore rely on appropriate safeguards, such as the UK International Data Transfer Agreement/Addendum or the EU Standard Contractual Clauses, alongside POPIA’s own cross-border transfer conditions (section 72).
Transfers from South Africa: where we transfer personal information out of South Africa (for example, to UK-based marketing or IT systems), we ensure the recipient is subject to a law, binding corporate agreement, or code of conduct that provides an adequate level of protection substantially similar to POPIA’s conditions, as required by POPIA section 72.
You can request more information about the safeguards we use by contacting us (section 15).
10. Data Retention
We keep personal information only as long as necessary for the purposes described in this policy, including to meet legal, accounting, tax or reporting requirements. As a general guide:
- Booking and financial records: typically 5-7 years after your trip, to meet South African and UK/EU tax and accounting requirements.
- Health/medical information: deleted or securely destroyed no later than 12 months after your trip, unless a longer period is required for an insurance or legal claim.
- Marketing preferences: retained until you unsubscribe, or for a maximum of 24 months of inactivity.
- Website analytics data: typically held in identifiable form for up to 14-26 months, and in anonymised/aggregated form thereafter.
11. Security
We implement appropriate technical and organisational measures to protect personal information against unauthorised access, loss, misuse or alteration, including access controls, encryption of payment data in transit, and confidentiality obligations for staff and guides. No system is completely secure, and we encourage you to also protect any account credentials you use with us.
If a data breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority (the ICO, an EU supervisory authority and/or South Africa’s Information Regulator, as applicable) and affected individuals in accordance with applicable law and timeframes.
12. Your Rights
If you are in the UK or EEA (UK GDPR / EU GDPR): subject to certain exemptions, you have the right to access your personal data; rectify inaccurate data; erase your data (right to be forgotten); restrict processing; receive your data in a portable format; object to processing (including direct marketing and profiling); withdraw consent at any time; and lodge a complaint with a supervisory authority. Following the UK’s Data (Use and Access) Act 2025, subject access requests may be limited to reasonable and proportionate searches, and we may pause (stop the clock) the one-month response period while we clarify your request or verify your identity.
If you are in South Africa (POPIA): you have the right to be notified that your information is being collected; access your personal information; request correction or deletion of information that is inaccurate, irrelevant, excessive, out of date, incomplete, or was unlawfully obtained; object to processing; not be subject to a decision based solely on automated processing that affects you significantly; and lodge a complaint with the Information Regulator.
To exercise any of these rights, contact us using the details in section 15. We may need to verify your identity before responding, and we will respond within the timeframes required by applicable law, generally one month under UK/EU GDPR, and within a reasonable period under POPIA, subject to any lawful extension.
13. Automated Decision-Making
We do not currently use automated decision-making or profiling that produces legal or similarly significant effects on you without human involvement. If this changes, we will update this policy and, where required, seek your consent.
14. Children’s Privacy
Our tours and Site are intended for adults. We do not knowingly collect personal information from children without the consent of a parent or guardian. Where a minor joins a tour, we collect the necessary information (e.g. passport details, medical information) directly from, or with the consent of, their parent or guardian, and apply additional safeguards consistent with the children’s data protections introduced into the UK GDPR by the Data (Use and Access) Act 2025.
15. How to Contact Us / Complaints
For any questions about this policy, or to exercise your rights, contact: Kapen Africa, Privacy / Information Officer. Email: [privacy@africacyclingsafaris.com]. Postal address: [registered address].
If you are not satisfied with our response, you have the right to lodge a complaint with:
- South Africa: the Information Regulator - enquiries@inforegulator.org.za / complaints.IR@inforegulator.org.za, https://inforegulator.org.za
- United Kingdom: the Information Commissioner’s Office (ICO) - https://ico.org.uk, tel. 0303 123 1113
- European Union: the data protection supervisory authority in your country of residence, or the applicable lead authority.
16. Changes to This Policy
We may update this policy from time to time to reflect changes in our practices or legal requirements. The updated version will be posted on our Site with a revised Last updated date, and where changes are material, we will take reasonable steps to notify you directly.
