Privacy Policy
Privacy Policy
Demapal Ltd – Relocation.London
Version 2.0
Effective and last updated: 7 September 2026
This Privacy Policy explains how Demapal Ltd collects, uses, stores and shares personal data through Relocation.London and our related communications and services.
It also explains the systems and service providers we use, how long we retain personal data, and the rights available to individuals under UK data protection law.
1. Introduction
Relocation.London is a trading name of Demapal Ltd.
We respect your privacy and are committed to handling personal data lawfully, fairly, transparently and securely.
This Privacy Policy applies when you:
- visit relocation.london;
- contact us or submit an enquiry;
- request a quotation;
- make, arrange or participate in a booking;
- receive relocation, travel, transport or related services;
- make a payment;
- communicate with us;
- act for a customer, supplier, contractor or business partner; or
- otherwise provide personal data to us.
This Privacy Policy supplements any service-specific privacy information provided when personal data is collected. It does not form part of a contract and may be updated when our services, systems or legal obligations change.
2. Who We Are
Demapal Ltd is the controller responsible for deciding how and why personal data is processed, unless we expressly state otherwise.
Legal entity: Demapal Ltd
Company number: 11059790
Trading name: Relocation.London
Business and privacy contact address: 16 Upper Woburn Place, London, WC1H 0AF, United Kingdom
Privacy contact: Ivan Zharikov
Email: info@relocation.london
Website: https://www.relocation.london
We have not appointed a statutory Data Protection Officer because we do not currently consider that the legal criteria requiring one are met. Ivan Zharikov co-ordinates privacy and data protection matters for Demapal Ltd.
3. Applicable Law
We process personal data in accordance with applicable UK data protection and privacy legislation, including:
- the UK General Data Protection Regulation;
- the Data Protection Act 2018;
- the Data (Use and Access) Act 2025;
- the Privacy and Electronic Communications Regulations 2003; and
- other applicable UK laws and regulations.
Additional laws may apply where a service provider, customer or individual is located outside the United Kingdom.
4. Personal Data We Collect
The information we collect depends on the services requested. We aim to collect only the personal data reasonably necessary for the relevant purpose.
4.1 Identity and Contact Information
This may include:
- name and title;
- date of birth or age, where required;
- nationality or country of residence, where relevant;
- employer, company, position or professional role;
- authority to act on behalf of another person or organisation;
- email address;
- telephone number;
- messaging service details;
- postal, billing, collection and destination addresses; and
- passport or identity document information where required by a carrier, hotel, venue, ticket provider, immigration or education professional, or by law.
4.2 Service, Travel and Booking Information
This may include:
- dates and times;
- routes and destinations;
- flight or train details;
- accommodation information;
- venues, itineraries and tickets;
- seating and participant information;
- group arrangements;
- relocation and housing requirements;
- education requirements;
- transport and accessibility requirements;
- language and dietary preferences;
- family or practical requirements;
- booking history;
- amendments and cancellations;
- complaints and feedback; and
- records of services provided.
4.3 Financial and Transaction Information
This may include:
- payer name;
- billing address;
- amount and currency;
- payment method;
- payment date and status;
- invoices and credit notes;
- refunds;
- bank account details where required; and
- limited card information returned by our payment provider, such as the card type and final digits.
Where card payment is used, full card numbers, expiry dates and security codes are normally entered directly into the secure environment of our payment provider and are not stored by Demapal Ltd.
4.4 Communications Information
This may include:
- emails and messages;
- attachments;
- contact form submissions;
- meeting and telephone call notes;
- instructions;
- complaints;
- correspondence with you; and
- correspondence with a person or organisation arranging services for you.
4.5 Technical and Website Information
This may include:
- IP address;
- browser type;
- device type;
- operating system;
- approximate location;
- pages visited;
- referral source;
- cookie identifiers;
- website security logs;
- form submission records; and
- technical or error information.
4.6 Marketing Information
This may include:
- marketing preferences;
- consent records;
- unsubscribe and objection records; and
- where lawfully enabled, message delivery or engagement information.
4.7 Special Category Data
You may choose to provide information concerning:
- health;
- disability or mobility requirements;
- allergies;
- dietary requirements;
- religious requirements; or
- other sensitive circumstances relevant to the requested service.
We request and use this information only where it is necessary to provide safe and appropriate services.
Where required, we will rely on your explicit consent in addition to an appropriate lawful basis under Article 6 of the UK GDPR. In an emergency, vital interests or another lawful condition may apply.
4.8 Children’s Personal Data
We may receive limited personal data relating to children where this is necessary for:
- family travel;
- accommodation;
- transport;
- tickets;
- education;
- relocation services; or
- another service requested by a parent, guardian or authorised organisation.
Children should not independently submit personal data through our website. Their information should be provided by a parent, guardian or appropriately authorised adult or organisation.
5. How We Collect Personal Data
We may collect personal data:
- directly from you through our website, contact forms, email, telephone, messaging services, payments, meetings and documents;
- from a family member or another person arranging services for you;
- from group leaders, employers, corporate customers, travel agents or relocation agents;
- from guides, drivers, transport providers, hotels, restaurants, venues, clubs and ticketing providers;
- from education, property, immigration and other professional service providers;
- from banks, payment providers, accountants, insurers and professional advisers;
- from appropriate public sources and official websites; and
- automatically through website logs, cookies and similar technologies.
If you provide another person’s personal data to us, you must have appropriate authority and a lawful reason to do so. You should also make this Privacy Policy available to that person.
We may contact that person directly where required.
6. Why We Use Personal Data and Our Lawful Bases
We may use personal data for the following purposes.
6.1 Enquiries and Quotations
We use identity, contact, service requirement and communications information to respond to enquiries and prepare quotations.
Our lawful bases are:
- taking steps at your request before entering into a contract; and
- our legitimate interests in responding to genuine enquiries.
6.2 Bookings and Service Delivery
We use identity, contact, booking, travel, participant and communications information to create bookings and provide requested services.
Our lawful bases are:
- performance of a contract; and
- our legitimate interests where a participant is not the person or organisation entering into the contract.
6.3 Sharing Information With Service Providers
We share only the information reasonably required by a guide, driver, hotel, venue, carrier, ticketing provider or other supplier.
Our lawful bases may include:
- performance of a contract;
- legitimate interests in arranging and providing the requested service; and
- explicit consent where special category data is involved.
6.4 Payments, Refunds and Accounting
We use identity, contact, financial and transaction information to:
- take and reconcile payments;
- issue invoices and credit notes;
- process refunds;
- maintain accounting records;
- prevent fraud;
- correct errors; and
- recover unpaid amounts.
Our lawful bases may include:
- performance of a contract;
- compliance with a legal obligation; and
- our legitimate interests in financial administration, fraud prevention and debt recovery.
6.5 Customer Support, Changes and Safety
We use contact, booking, communications and incident information to provide customer support, manage operational changes and protect the safety of customers, participants, staff and suppliers.
Our lawful bases may include:
- performance of a contract;
- compliance with a legal obligation;
- legitimate interests; and
- vital interests where appropriate.
6.6 Complaints, Insurance and Legal Matters
We may process booking, payment, communications and incident information to manage complaints, insurance matters, investigations and legal claims.
Our lawful bases may include:
- compliance with a legal obligation; and
- our legitimate interests in establishing, exercising or defending legal rights.
6.7 Suppliers, Contractors and Business Partners
We process business contact, contractual, payment and communications information to manage relationships with suppliers, contractors and business partners.
Our lawful bases may include:
- performance of a contract; and
- our legitimate interests in managing our business relationships.
6.8 Website Operation and Security
We process technical information, logs and necessary cookie information to operate, protect and improve our website and systems.
Our lawful bases may include:
- our legitimate interests in maintaining secure and effective systems; and
- compliance with legal obligations.
6.9 Analytics and Non-Essential Cookies
Where required by law, analytics and non-essential cookies or similar technologies are used only with consent.
6.10 Marketing
We may use contact details and marketing preferences to provide information about relevant services.
Depending on the circumstances, we may rely on:
- consent;
- the soft opt-in permitted by the Privacy and Electronic Communications Regulations, where all relevant conditions are met; and
- legitimate interests for related administrative processing.
6.11 AI-Assisted Administration
We may use appropriately minimised or pseudonymised content from relevant communications and documents for AI-assisted drafting, translation, summarisation, research, itinerary preparation and administration.
Our lawful bases may include:
- performance of a contract;
- our legitimate interests in efficient and accurate administration and service delivery; and
- explicit consent or another applicable legal condition where special category data is exceptionally required.
6.12 Rights Requests and Regulatory Enquiries
We use identity, contact, verification and case information to respond to data protection requests, complaints and regulatory enquiries.
Our lawful bases may include:
- compliance with a legal obligation; and
- our legitimate interests in demonstrating compliance.
Where we rely on legitimate interests, we consider whether the processing is necessary and balance our interests against the individual’s rights, freedoms and reasonable expectations.
Where we rely on consent, consent may be withdrawn at any time. Withdrawal does not affect processing already carried out lawfully.
7. Service Providers, Systems and Recipients
We do not sell or rent personal data.
We share personal data only where reasonably necessary and subject to appropriate contractual, confidentiality and security arrangements.
Depending on the activity, a recipient may act as our processor, a separate controller or both for different processing operations.
7.1 Xero
We use Xero for:
- accounting;
- invoicing;
- payment reconciliation; and
- financial record-keeping.
Information processed through Xero may include customer and supplier names, business contact details, invoices, payment information, bank information and transaction records.
7.2 Stripe
We use Stripe for:
- payment processing;
- payment links;
- refunds;
- fraud prevention; and
- transaction records.
Stripe may receive payer and billing information, payment method information, transaction information and relevant device or technical information.
When card payment is used, Stripe normally receives the full card information directly through its secure payment environment.
7.3 OpenAI and ChatGPT
We may use OpenAI services, including ChatGPT, to assist with:
- drafting correspondence;
- summarising information;
- translating information;
- preparing itineraries and service documents;
- organising information;
- conducting research; and
- supporting internal administration.
We aim to provide only the information reasonably required for the relevant task and, where practicable, remove or reduce names and other direct identifiers.
AI-generated output is subject to human review before being used in customer communications or material business decisions.
7.4 pCloud
We use pCloud for cloud file storage, synchronisation, secure access and backup.
Information stored may include:
- business correspondence;
- booking files;
- supplier information;
- invoices; and
- other operational records.
Access is managed according to the user’s role and business need.
7.5 Synology
We use Synology systems for:
- locally managed network-attached storage;
- access control; and
- data backup.
Operational files and backups stored on our locally managed Synology equipment remain under Demapal Ltd’s control.
Where related Synology online, cloud, remote-access, support or diagnostic services are enabled, limited account, device or technical information may also be processed by Synology.
7.6 Website and Communications Providers
We use website, hosting and communications services that may include:
- WordPress;
- website hosting;
- online forms;
- email;
- telephone;
- messaging services; and
- website security tools.
These services may process contact form information, communications, identifiers, device information, cookies and technical logs.
7.7 Travel and Relocation Suppliers
We may share necessary information with:
- guides;
- drivers;
- vehicle operators;
- airlines and other carriers;
- hotels;
- restaurants;
- venues;
- ticketing providers;
- hospitality providers;
- schools and education providers;
- property professionals;
- immigration professionals; and
- other suppliers involved in providing the requested service.
We provide only the identity, contact, booking, preference or other information reasonably required by the relevant supplier.
7.8 Professional Advisers and Public Authorities
We may share information with:
- banks;
- accountants;
- auditors;
- legal advisers;
- insurers;
- tax authorities;
- regulators;
- courts;
- law-enforcement authorities; and
- other public bodies.
We do so only where necessary for the relevant professional service, legal obligation, dispute, investigation or properly authorised request.
Where a provider offers data-processing terms, regional settings, security controls or international transfer safeguards, we select and configure them as appropriate to our use and the relevant risk.
Providers may change their infrastructure and subprocessors. Their current privacy notices and contractual terms also apply to processing they carry out in their own capacity.
8. Our Use of ChatGPT and Other AI-Assisted Tools
AI tools assist our personnel but do not replace human judgement.
When we use ChatGPT or another AI-assisted service:
- material outputs are reviewed by a person before use;
- we do not use AI to make solely automated decisions producing legal or similarly significant effects on individuals;
- we apply data minimisation;
- we remove names and other direct identifiers where reasonably practicable;
- we do not intentionally submit full payment card credentials;
- passport copies, children’s data and special category data should be submitted only where strictly necessary, lawfully authorised and subject to appropriate safeguards;
- prompts and outputs are not retained as separate records longer than reasonably necessary; and
- important information is checked because AI-generated content can contain errors.
Where an AI-generated output becomes part of a booking, contract, complaint, accounting record or legal file, it will follow the retention period applicable to that record.
Demapal Ltd remains responsible for its communications, decisions and services.
9. International Transfers
Our customers, suppliers and technology providers operate internationally. Personal data may therefore be stored in or accessed from countries outside the United Kingdom.
For example:
- Xero operates through an international group and uses global infrastructure and subprocessors;
- Stripe and OpenAI may process UK personal data in the United States and other countries in accordance with their applicable terms and transfer mechanisms;
- pCloud stores uploaded files in the data region selected for the account, which may be within the European Union or the United States;
- pCloud may process limited account, technical or customer support information in other locations;
- information stored exclusively on our locally managed Synology equipment remains under our local control, although a transfer may take place if cloud, online, remote-support or related services are enabled; and
- an international transfer may take place where a customer asks us to arrange a booking or service with an overseas provider.
Where UK data protection law treats a transfer as restricted, we use an available lawful mechanism. This may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to approved Standard Contractual Clauses;
- the UK Extension to the EU–US Data Privacy Framework, where applicable;
- another permitted safeguard; or
- a limited statutory exception, including where a transfer is necessary to perform a contract in the individual’s interests.
We assess transfer risks where required.
You may contact us for further information about the safeguard used for a particular transfer.
10. Marketing Communications
Messages concerning an enquiry, quotation, booking, ticket, payment, service change or safety matter are service communications and are not marketing.
We send electronic marketing communications to individuals only:
- with valid consent; or
- under the soft opt-in permitted by the Privacy and Electronic Communications Regulations, where all relevant conditions are met.
We provide an opportunity to opt out when contact details are collected and in each marketing message.
Corporate contacts may be contacted where permitted by law. Named business contacts continue to have data protection rights.
You may object to direct marketing at any time by:
- using the unsubscribe option provided in the message; or
- emailing info@relocation.london.
We may retain a minimal suppression record to ensure that your objection continues to be respected.
11. Cookies, Analytics and External Services
Our website uses WordPress and may use:
- online forms;
- security tools;
- server logs;
- session technologies; and
- strictly necessary cookies.
These technologies help us operate the website, process enquiries, maintain sessions and prevent misuse.
The website may also use:
- analytics;
- embedded maps;
- social media links;
- messaging links;
- payment pages; and
- similar external services.
Where consent is required under the Privacy and Electronic Communications Regulations, non-essential cookies or similar technologies will not be set until the visitor has made a choice.
Visitors must be able to reject non-essential technologies and subsequently change their choices.
Third-party websites, payment pages and messaging services have their own privacy policies. When you leave our website or choose to use WhatsApp, Telegram, a payment page, an online map or another external service, that provider may collect and use personal data as a separate controller.
12. Data Security
We use technical and organisational measures appropriate to the nature of the information and the risk associated with its processing.
These measures may include:
- access controls;
- strong passwords;
- multi-factor authentication where available;
- device and account management;
- encryption in transit and at rest where supported;
- backups;
- software and security updates;
- confidentiality obligations;
- least-privilege access; and
- incident identification and response procedures.
Access to personal data is limited to staff, contractors and suppliers who require it for an authorised task. They must follow applicable instructions and confidentiality requirements.
No transmission or storage system can be guaranteed to be completely secure. You should avoid sending passport information, health information or payment information through an insecure channel unless it is necessary and has been agreed with us.
13. Data Retention
We retain personal data only for as long as reasonably necessary for:
- the purpose for which it was collected;
- legal, regulatory and accounting obligations;
- dispute resolution;
- insurance requirements; and
- the establishment, exercise or defence of legal claims.
We review whether continued retention is necessary and securely delete or anonymise information where appropriate.
Our usual retention periods are set out below.
Enquiries That Do Not Become Bookings
Usually up to two years after the last substantive contact.
Contracts, Booking Confirmations and Service Records
Usually up to six years after completion of the service or the end of the business relationship.
Invoices, Payments and Accounting Records
Usually six years, or any longer period required by tax or company law.
This includes relevant records held in Xero.
Passport and Identity Documents
Copies and information required only for a particular service are deleted or minimised when no longer needed.
They are normally retained for no longer than 90 days following completion of the service unless a law, supplier requirement, insurance matter or dispute requires longer retention.
Special Requirements and Sensitive Information
Health, accessibility, dietary and similar information required only for a particular service is normally deleted or minimised within 90 days after completion of the service unless a longer period is necessary for a legal, insurance or dispute-related reason.
Children’s Data
Children’s personal data is retained only for the minimum period necessary for the relevant booking or service, subject to any applicable legal, insurance or dispute-related requirement.
Complaints, Incidents, Insurance and Legal Files
Usually up to six years after closure, or longer where a claim, investigation or applicable limitation period remains active.
Rights Requests
Records relating to a data protection request may normally be retained for up to six years after the matter is closed where necessary to demonstrate compliance or manage a legal claim.
Marketing Preferences
Marketing consent and preference information is retained until consent is withdrawn or the relevant marketing programme ends.
A minimal suppression record may be retained for as long as reasonably necessary to ensure that an objection is respected.
Technical and Security Logs
These are retained according to security requirements and system configuration, normally for no longer than 12 months unless a security incident requires longer retention.
AI Prompts and Outputs
AI prompts and outputs are not retained separately for longer than necessary.
If content becomes part of a booking, contract, complaint, accounting record or legal file, the retention period for that record will apply.
14. Your Data Protection Rights
Depending on the circumstances and the applicable lawful basis, you may have the right to:
- receive information about how your personal data is processed;
- request access to your personal data;
- request correction of inaccurate or incomplete information;
- request erasure where the relevant legal conditions are met;
- request restriction of processing;
- receive certain information in a structured, commonly used and machine-readable format;
- request data portability where applicable;
- object to processing based on legitimate interests;
- object at any time to direct marketing;
- withdraw consent without affecting processing already carried out lawfully;
- receive appropriate safeguards in relation to qualifying automated decisions; and
- complain to us or to the Information Commissioner’s Office.
The right to object to direct marketing is absolute.
To exercise any of these rights, contact:
Email: info@relocation.london
We may ask for proportionate information to verify your identity and locate the relevant records.
We normally respond within one month. Data protection rights are not absolute, and exemptions may apply. If we cannot fulfil a request, we will explain the reason where legally permitted.
15. Complaints
Please contact us first so that we have an opportunity to investigate and respond:
Email: info@relocation.london
You also have the right to complain to the Information Commissioner’s Office.
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom
Telephone: 0303 123 1113
Website: https://ico.org.uk/make-a-complaint/
Contacting us first does not affect your right to complain to the Information Commissioner’s Office.
16. Information Required to Provide a Service
Certain information may be required to:
- prepare or enter into a contract;
- confirm a booking;
- issue a ticket;
- process a payment;
- comply with a legal obligation;
- protect an individual’s safety; or
- meet a supplier’s requirements.
If required information is not provided, we may be unable to prepare a quotation, confirm a booking or provide the relevant service.
Where appropriate, we will explain which information is required and the likely consequences of not providing it.
17. Third-Party Privacy Information
Further information about the privacy practices of our principal technology providers is available through the following links:
- Xero Privacy Notice: https://www.xero.com/uk/legal/privacy/
- Stripe Privacy Policy: https://stripe.com/gb/privacy
- OpenAI UK and European Privacy Policy: https://openai.com/en-GB/policies/eu-privacy-policy/
- pCloud Privacy Policy: https://www.pcloud.com/privacy_policy.html
- Synology Privacy Information: https://www.synology.com/privacy
- Information Commissioner’s Office: https://ico.org.uk/
These providers may update their notices, infrastructure, subprocessors and contractual terms independently.
18. Changes to This Privacy Policy
We review this Privacy Policy when our services, suppliers, systems, technologies or legal obligations change.
The current version will be published at: https://www.relocation.london/privacy-policy
The effective date shown at the top of the page indicates when the Privacy Policy was last updated.
Where a change materially affects personal data already held by us or the rights of individuals, we will provide additional notice where required.
