World Camps

Cerca

Cerca campi, articoli di assistenza e il tuo account

Privacy Policy

Version 1.9 · Effective date: 8 September 2026

Platform: World Camps
Operator: World Schools Sàrl, Route de la Bernadaz 5A, 1094 Paudex, Switzerland
Version: 1.9 | September 2026
Effective Date: 8 September 2026
Data Protection Contact: privacy@world-camps.org


Material changes are notified to data subjects in accordance with applicable data protection law.


1. Introduction and Scope

1.1 This Privacy Policy ("Policy") explains how World Schools Sàrl ("World Camps", "we", "us", "our") collects, uses, stores, shares, and protects personal data when you access or use the World Camps platform ("Platform").

1.2 The Platform is an international online marketplace that enables parents, guardians, and users ("Users", "you") to discover, compare, and book camps, schools, and educational programmes offered by independent third-party providers ("Providers"). Our data practices reflect the nature of this intermediary role.

1.3 Who this Policy covers. This Policy applies to:

  • parents and guardians who create accounts or make bookings;
  • children and minors on whose behalf parents or guardians use the Platform;
  • visitors who browse the Platform without registering;
  • Provider representatives who interact with the Platform on behalf of Provider organisations.

1.4 Children's data. A significant portion of the personal data processed through the Platform relates to children and minors. We apply heightened standards to the collection and processing of children's personal data, as described throughout this Policy and in particular in Section 10.

1.5 Jurisdiction. World Schools Sàrl is incorporated in Switzerland. This Policy is designed to comply with the Swiss Federal Act on Data Protection ("FADP"), the EU General Data Protection Regulation ("GDPR"), the UK General Data Protection Regulation ("UK GDPR"), the US Children's Online Privacy Protection Act ("COPPA"), applicable US state privacy laws (including the California Consumer Privacy Act / California Privacy Rights Act and analogous regimes in other states), the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) ("EU AI Act"), and applicable international data protection standards. Jurisdiction-specific supplements are set out in Section 17.

1.6 Related documents. This Policy should be read alongside the World Camps Customer Terms and Conditions, Provider Terms and Conditions, Cookie Policy, and any booking-specific terms displayed at checkout.


2. Definitions

"Booking" means a confirmed reservation of a Provider Programme made through the Platform.

"Child" or "Minor" means any individual under the age of 18, or such higher age as constitutes minority under applicable law.

"Controller" means the entity that determines the purposes and means of processing personal data. World Camps is a Controller in respect of data processed to operate the Platform.

"Personal Data" means any information relating to an identified or identifiable natural person.

"Platform" means the World Camps website, mobile applications, APIs, and associated technology infrastructure.

"Processing" means any operation performed on personal data, including collection, storage, use, disclosure, and deletion.

"Provider" means any independent camp, school, or educational organisation listing programmes on the Platform.

"Sensitive Personal Data" means personal data revealing racial or ethnic origin, health, medical conditions, religious beliefs, or other special categories of data as defined under applicable law.

"Sub-processor" means a third party engaged by World Camps to process Personal Data on our behalf, as listed in Section 5.7.

"User Account" means the registered account created on the Platform.


3. Data We Collect

3.1 Account and Identity Data

When you create a User Account, we collect:

  • full name;
  • email address;
  • password (stored in hashed form);
  • country of residence;
  • preferred language;
  • account creation date and activity history.

3.2 Child and Minor Profile Data

When you create a profile for a Child or Minor, we collect:

  • full name and date of birth;
  • gender (where provided);
  • nationality and language(s);
  • educational level or grade;
  • interests and preferences relevant to programme matching.

3.3 Health, Medical, and Dietary Data

To facilitate programme bookings and ensure appropriate Provider preparation, we may collect:

  • medical conditions, allergies, and intolerances;
  • dietary requirements and restrictions;
  • physical or mobility considerations;
  • medications or treatment requirements relevant to programme participation;
  • information about disabilities or special educational needs.

This constitutes Sensitive Personal Data and is handled under heightened safeguards as described in Section 8.

3.4 Booking and Transaction Data

In connection with Bookings, we collect:

  • programme selections, dates, and booking references;
  • deposit and payment schedules;
  • payment method details (processed and stored by our payment provider, Stripe — we do not store full card numbers);
  • transaction history, refund requests, and cancellation records;
  • communications exchanged during the booking process.

3.5 Communication Data

When you contact us or interact with the Platform, we collect:

  • the content of support queries, complaints, and correspondence;
  • email and in-platform message records;
  • feedback and review content submitted by you.

3.6 Emergency Contact Data

  • name and relationship of emergency contacts;
  • phone number and email address of emergency contacts.

3.7 Travel and Documentation Data

Where relevant to the Provider Programme:

  • passport or national identity document details (where required by Providers);
  • nationality and visa status (where disclosed);
  • travel itinerary information.

This data is shared with the relevant Provider only and is not used for any other purpose.

3.8 Technical and Usage Data

Automatically collected when you access the Platform:

  • IP address and approximate geolocation;
  • device type, operating system, and browser;
  • pages visited, search queries, and interaction data;
  • referral source and session duration;
  • cookies and similar tracking technologies (see Cookie Policy).

3.9 AI and Personalisation Data

Where AI features are active:

  • preferences inferred from browsing and booking behaviour;
  • programme interaction signals used to generate recommendations;
  • search and filter history;
  • the content of queries you submit to AI-assisted Platform features (including the AI knowledge base assistant).

AI features are powered by the Sub-processors listed in Section 5.7. AI personalisation is governed by two distinct controls: an account-level "AI personalisation" toggle that governs personalisation drawn from the data you have explicitly saved to your account (a withdrawal control that defaults on), and the device-level AI / Personalisation category of the Cookie Preference Centre, which governs guest and browser-stored personalisation signals and defaults off like every other consent category (see Section 9.6).

3.10 Waitlist and Interest Data

Where a Programme is not currently bookable, you may ask to be notified when it becomes available. In that case we collect:

  • the email address you provide for the notification;
  • the Programme or category of interest to which the notification relates;
  • the date of the request.

This data is collected on the basis of your consent, is used only for the single purpose of sending the requested availability notification, and you may unsubscribe at any time (see Section 4.8).

What a Provider sees of this waitlist and interest data is limited to aggregate demand: Providers see how many families are waiting for a camp or session and, where the group is large enough, an aggregated country breakdown — never the identity, contact details or position of an individual family until a Booking is confirmed.


4. How We Use Personal Data

4.1 To provide and operate the Platform

PurposeLegal Basis
Creating and managing User AccountsPerformance of contract
Processing and managing BookingsPerformance of contract
Facilitating payments and refundsPerformance of contract
Communicating booking confirmations and updatesPerformance of contract
Providing customer supportPerformance of contract / Legitimate interests

4.2 To share data with Providers

When a Booking is confirmed, we share relevant personal data — including Child profile data and health/medical information — with the relevant Provider to enable them to deliver the programme. This sharing is necessary for the performance of the Booking and, where it involves Sensitive Personal Data, is additionally based on your explicit consent obtained at the time of providing that data.

Providers receive data as independent data controllers and are bound by applicable data protection law and the obligations set out in the Provider Agreement.

4.3 To manage payments

Payment processing for marketplace Bookings is carried out by Stripe. We share booking and identity data with Stripe as necessary to process transactions, manage refunds, and handle disputes. Stripe's processing is governed by Stripe's own Privacy Policy.

Provider subscription and licence fees (the fees Providers pay to list and operate on the Platform) are processed separately by our third-party subscription-billing provider and its payment gateway, and not through the Stripe / Stripe Connect flow used for marketplace Bookings. See Section 5.2 and Section 5.7.

4.4 To ensure platform safety and integrity

PurposeLegal Basis
Fraud detection and preventionLegitimate interests
Chargeback management and dispute resolutionLegitimate interests / Legal obligation
Platform abuse preventionLegitimate interests
Security monitoring and incident responseLegitimate interests / Legal obligation

4.5 To comply with legal obligations

PurposeLegal Basis
Compliance with applicable law and regulationLegal obligation
Responding to court orders, regulatory requestsLegal obligation
Tax and financial record-keepingLegal obligation
Enforcement of Terms and ConditionsLegitimate interests

4.6 To improve the Platform and personalise your experience

PurposeLegal Basis
Platform analytics and performance monitoringLegitimate interests
AI-powered programme recommendationsConsent (where required) / Legitimate interests
AI-assisted knowledge base and support toolingPerformance of contract / Legitimate interests / Consent (where required)
A/B testing and product developmentLegitimate interests
Aggregate and anonymised market researchLegitimate interests

AI-driven features are subject to the transparency, labelling, and human-review safeguards set out in Section 9.

4.7 Marketing and communications

PurposeLegal Basis
Sending service-related notificationsPerformance of contract / Legitimate interests
Sending marketing communications (with opt-in)Consent
Personalised marketing based on booking historyConsent

You may withdraw consent to marketing communications at any time by using the unsubscribe link in any communication or by updating your account preferences.

4.8 Waitlist and availability notifications

PurposeLegal Basis
Notifying you when a Programme becomes bookable, using an email address you provide for that purposeConsent

Where you ask to be notified that a Programme has become bookable, we use the email address you provide solely to send that notification. This is a single-purpose use: we do not use a waitlist email address for marketing or any other purpose. You may unsubscribe from the notification at any time using the unsubscribe link, after which the address is retained only as a suppression (no-recontact) record and then deleted in accordance with Section 7.2.


5. Data Sharing and Disclosure

5.1 Providers

We share personal data with Providers when a Booking is confirmed. The data shared is limited to what is operationally necessary for programme delivery. We do not share data with Providers for their own marketing purposes without your separate consent.

5.2 Payment processors

We share transaction data with Stripe, Inc. to process payments, manage refunds, and handle disputes. Stripe processes data as an independent data controller in accordance with its own privacy documentation.

Separately from the marketplace payment flow, Provider subscription and licence fees are processed by our third-party subscription-billing provider and its payment gateway. This flow concerns the billing relationship between World Camps and Providers and is distinct from the Stripe / Stripe Connect flow used for Customer Bookings. That provider's processing is described in Section 5.7.

5.3 Technology service providers

We engage third-party service providers to support Platform operations, including cloud hosting, email delivery, analytics, customer support tooling, fraud prevention, and AI services. These providers process data on our behalf as data processors (or, where the nature of the service requires it, as independent or joint controllers) under binding contractual arrangements. The current list is set out in Section 5.7.

5.4 Legal and regulatory disclosure

We may disclose personal data to law enforcement authorities, regulators, courts, or other public bodies where required to do so by applicable law, or where disclosure is necessary to protect the rights, safety, or property of World Camps, its users, or third parties.

5.5 Business transfers

In the event of a merger, acquisition, restructuring, or sale of assets, personal data may be transferred to the successor entity, subject to equivalent privacy protections. Affected users will be notified in advance where required by law.

5.6 No sale or sharing of personal data

We do not sell, rent, or trade personal data to third parties for their own commercial purposes. For the purposes of US state privacy laws — including the California Consumer Privacy Act / California Privacy Rights Act, the Colorado Privacy Act, the Virginia Consumer Data Protection Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, and the Texas Data Privacy and Security Act — we do not "sell" Personal Data and we do not "share" Personal Data for cross-context behavioural advertising. We honour validated Global Privacy Control ("GPC") browser signals as an opt-out of sale and sharing for the relevant session, as further described in Sections 13 and 17.5.

5.7 Sub-processors and third-party recipients

The following Sub-processors and independent recipients are engaged in the operation of the Platform as at the effective date of this Policy. The current list, including any additions or replacements, is also published in the Cookie Preference Centre and is available on request.

ProviderRoleCategory of dataLocation / transfer mechanism
Stripe, Inc.Independent controller — payment processing, fraud preventionIdentity, transaction, payment method, IP, deviceUS — Stripe DPA / SCCs
Cloudflare, Inc.Processor — security, bot mitigation, content deliveryConnection metadata, IPUS / global — SCCs / UK IDTA
Google LLC (Google Fonts, Google Maps and Places, Google sign-in)Independent controller / processor depending on serviceIP, request metadata, authentication data (sign-in)US — SCCs / UK IDTA
Apple Inc. (Sign in with Apple)Independent controller — authenticationAuthentication dataUS — SCCs / Privacy Framework
Supabase (database, authentication, backend hosting)Processor — database, authentication, backend infrastructureAll Platform data / authentication dataUS / global — SCCs / UK IDTA
Vercel (application hosting, edge network / CDN)Processor — application hosting, edge network / content deliveryConnection metadata, IP, request metadataUS / global — SCCs / UK IDTA
Vercel Speed InsightsProcessor — cookieless website-performance measurement (loaded under legitimate interests, without cookies)Aggregated performance metrics, connection metadataUS / global — SCCs / UK IDTA
Resend (transactional and notification email)Processor — transactional and notification emailIdentity, email address, message metadataSCCs / UK IDTA where the provider is established outside the adequacy circle
Sentry (error detection and diagnostics)Processor — error detection and diagnosticsConnection metadata, technical logs (no Platform Sensitive Personal Data)SCCs / UK IDTA where the provider is established outside the adequacy circle
Google Analytics 4 (Google LLC)Processor — usage analytics (consent-gated, Analytics category)Pseudonymous usage dataUS — SCCs / UK IDTA
Google Ads / conversion tag (Google LLC)Independent controller / processor — advertising and conversion measurement (consent-gated, Marketing category)Pseudonymous usage and conversion dataUS — SCCs / UK IDTA
CARTO / OpenStreetMapProcessor / independent recipient — map tiles for wishlist and map displayVisitor IP address, map request metadataEU / global — SCCs where applicable
Cloudflare (asset CDN)Processor — front-end asset deliveryIP, request metadataUS / global — SCCs
HubSpot, Inc.Processor — CRM ticketing for the Provider licence-cancellation flow (Provider / B2B data only, never family data)Provider identity, email, and contract dataUS / global — DPA with SCCs
Anthropic (Claude)Processor — AI translation of Provider listing content and Customer reviews into the Platform's supported languages; AI-assisted platform features as described in §9Provider listing content, Customer review text, AI feature query contentUS / EU — DPA with SCCs; no training on submitted content per Anthropic's commercial terms
Third-party subscription-billing providerProcessor / independent controller as appropriate — subscription and licence billing for ProvidersProvider identity and billing data, transaction dataUS / global — DPA with SCCs
Trigger.dev (background job processing, including processing of Provider-supplied public website content for listing enrichment)Processor — background job processingProvider-supplied website content and associated metadata (which may incidentally include personal data such as staff names published on the Provider's website)US / global — DPA with SCCs

The subscription-billing entry above relates to the Provider subscription-billing flow (the fees Providers pay to World Camps), which is separate from the marketplace Stripe / Stripe Connect flow used to process Customer Bookings (see Sections 4.3 and 5.2).

Where the Platform deploys AI Features (as described in Section 9), Sub-processors are engaged for language-model inference and translation, as reflected in the table above (Anthropic (Claude)). Where additional AI Sub-processors are engaged in future for embedding generation or vector-database storage, this Section 5.7 will be updated and registered Users will be notified in accordance with the change-notification process below.

We update this list when Sub-processors are added or replaced. Material changes are notified to registered Users with reasonable advance notice and, where required, will trigger a re-prompt for cookie consent.


6. International Data Transfers

6.1 World Camps operates internationally. Personal data may be transferred to, stored in, and processed in countries outside your home jurisdiction, including Switzerland, the European Economic Area, the United Kingdom, and the United States.

6.2 Where data is transferred from the EEA or UK to countries not recognised as providing an adequate level of data protection, we implement appropriate safeguards, which may include:

  • Standard Contractual Clauses ("SCCs") approved by the European Commission;
  • the UK International Data Transfer Agreement ("IDTA") or addendum;
  • Binding Corporate Rules where applicable;
  • other lawful transfer mechanisms recognised under applicable law.

6.3 Switzerland benefits from EU adequacy recognition for GDPR purposes. Transfers from Switzerland are governed by the FADP and applicable transfer mechanisms, including the Swiss addendum to the EU SCCs.

6.4 You may request details of the transfer mechanisms applicable to your data, including in respect of any Sub-processor listed in Section 5.7, by contacting us at the address in Section 16.


7. Retention of Personal Data

7.1 We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by applicable law.

7.2 The following standard retention periods apply:

Data CategoryRetention Period
Account dataDuration of account + 3 years after closure
Booking and transaction records10 years (financial / legal compliance; Swiss Code of Obligations Art. 958f)
Checkout consent snapshot (cancellation-policy text shown, payment schedule, timestamp, IP address)10 years (payment-dispute and Strong Customer Authentication mandate evidence)
Payment / transaction audit log (append-only payment-event record)10 years (financial / legal compliance; Swiss Code of Obligations Art. 958f)
Health and medical data (Child) — medical profileRetained while the Child profile remains active, under the explicit consent given at collection; deleted immediately on withdrawal of consent, deletion of the Child profile, or account closure; deleted automatically after twenty-four (24) months without any Booking activity for that Child; subject to the incident-record carve-out in §7.2A(d)
Health and medical data (Child) — incident record6 years from incident date (subject to local personal-injury limitation), per §7.2A(d) — unchanged
Travel and passport dataDeleted within 90 days of programme end
Customer support communications3 years from last interaction
Waitlist / availability-notification emailKept while the request is live; after unsubscribe or fulfilment, retained as a suppression (no-recontact) record for up to 3 years, then deleted
Marketing consent recordsDuration of consent + 3 years
Cookie consent recordsDuration of consent + 3 years (per Cookie Policy §8)
AI conversations retained in your account (visible chat history)Until deleted by you, or on account closure
Backend AI query and prompt logs (technical/diagnostic)90 days from interaction (subject to abuse-prevention exceptions) — unchanged
Technical logs and usage data13 months on a rolling basis

7.2A Children's health and medical data — Article 9 carve-out and incident records. Where information falling within the Child health and medical data categories in Section 7.2 is collected for the purpose of facilitating a Booking and the consequential delivery of a Programme:

(a) the medical-profile information of the Child (including allergies, medications, medical conditions, dietary requirements, and other Sensitive Personal Data necessary for safe Programme participation) is held as a durable profile under the explicit consent obtained at the point of collection, so that it can be reused for subsequent Bookings without re-entry. It is deleted immediately upon withdrawal of that consent, deletion of the Child profile, or closure of the account, and automatically after twenty-four (24) months without any Booking activity for the Child concerned;

(b) this Section 7.2A and the on-screen retention pledge on the child medical-safety screen operate as the storage-limitation position for Sensitive Personal Data of Children under Article 5(1)(e) and Article 9 of the GDPR (and equivalent provisions in other jurisdictions), and displace any longer retention period otherwise applicable to Booking-related data;

(c) at each new Booking, the Customer is required to review and expressly confirm that the Child's medical-profile information is current before the Booking Request can be submitted; this requirement is enforced server-side, and the confirmation (including its timestamp) is recorded on the Booking and cannot be recorded without the confirmation being given. Before a Booking is accepted, a Provider can see the Child's first name and age only; medical-profile information is disclosed to the Provider only for Bookings that have been accepted, only for the period the Booking is active, and every such Provider access is written to an append-only access log;

(d) where an incident affecting the Child is logged during a Programme, the information necessary to record and respond to that incident is copied at the time of the incident to a separate, access-restricted incident-record register held by World Camps, which has a retention period of six (6) years from the date of the incident (or such longer period as may be required by applicable personal-injury limitation, insurance retention obligation, or regulatory record-keeping requirement in the relevant jurisdiction). The incident-record register operates independently of the medical-profile deletion in paragraph (a), which proceeds as scheduled regardless of whether an incident record has been opened; and

(e) access to medical-profile information occurs only through logged mechanisms; every provider access is recorded with the identity of the accessor, the time of access, and the purpose of the access.

7.3 Where data is subject to a legal hold, regulatory investigation, or active dispute, retention will be extended as necessary.

7.4 Following the expiry of the applicable retention period, data will be securely deleted or irreversibly anonymised.

7.5 Alignment with on-screen disclosures. A retention pledge is displayed on the child medical-safety screen, stating that the Child's medical information is visible only while a Booking is active, that every access to it is logged, that it is auto-deleted after twenty-four (24) months without Booking activity, and that it can be removed at any time. Where a retention period is disclosed on a specific Platform screen (for example, the child medical-safety screen) the on-screen disclosure prevails for the data collected through that screen, provided that the on-screen period is not longer than the corresponding period in this Policy. Where the on-screen period is shorter, World Camps will honour the shorter period.


8. Sensitive Personal Data

8.1 Health, medical, dietary, and disability-related information relating to Children constitutes Sensitive Personal Data under GDPR and equivalent frameworks. We process such data only:

  • with your explicit consent, obtained at the time of data collection;
  • to the extent necessary to facilitate the relevant Booking and communicate relevant information to the Provider;
  • in compliance with applicable obligations relating to the health and safety of programme participants.

8.2 We do not use health or medical data for profiling, marketing, or any purpose other than those set out in Section 4.2.

8.3 Sensitive Personal Data is encrypted at rest and in transit and is subject to access controls restricting processing to authorised personnel only. Consistent with Section 7.2A, a Child's medical-profile information is not exposed through any general administrative interface; it is disclosed only to a Provider for an accepted Booking and only while that Booking is active, and every such access is recorded in an append-only access log with the identity of the accessor, the time of access, and the purpose of the access.

8.4 You may withdraw consent to the processing of Sensitive Personal Data at any time, subject to the understanding that withdrawal may affect the Platform's ability to facilitate the Booking.

8.5 Retention. The retention period applicable to Sensitive Personal Data relating to Children is set out in Section 7.2 and Section 7.2A. In summary: the Child's medical profile is retained under explicit consent for reuse across Bookings, must be re-confirmed as current at each Booking, and is deleted on consent withdrawal, profile or account deletion, or after twenty-four (24) months of Booking inactivity — with a separate access-restricted incident-record register operating on a six-year limitation-aligned retention only where an incident is logged during a Programme.


9. Automated Decision-Making and AI Features

9.1 The Platform uses automated tools and AI-powered features to generate programme recommendations, search rankings, content moderation signals, and an AI-assisted knowledge base ("AI Features"). AI Features involve automated analysis of your usage behaviour, preferences, booking history, and the content of the queries you submit to them.

9.2 No Booking decisions, account restrictions, or material outcomes affecting you or your Child are determined solely by automated processing without human review. AI Feature outputs on the Platform are informational and do not constitute advice within the meaning of any applicable law.

9.3 Where automated processing produces outputs that have a significant effect on you or your Child (for example, targeted pricing, content moderation removals, or eligibility filtering), you have the right to request human review of that decision. Contact us at the address in Section 16.

9.4 We do not subject Children's personal data to automated profiling for marketing, advertising, or commercial purposes.

9.5 AI transparency and labelling. Consistent with Article 50 of the EU AI Act and equivalent transparency principles in other jurisdictions, we apply the following safeguards to AI Features:

  • Each AI-generated response surfaced by the Platform is identified as AI-generated through a visible on-screen label or persistent indicator.
  • The AI-assisted knowledge base assistant identifies itself as an AI in its first response in any conversation and remains identifiable as an AI throughout the interaction.
  • AI-assisted content moderation signals (for example, AI-flagged reviews) are subject to human review before any user-facing action is taken, in line with the Digital Services Act transparency obligations applicable to the Platform.
  • We do not present AI-generated responses as legal, medical, financial, or other professional advice.
  • The AI Sub-processors used to power AI Features are listed in Section 5.7. The Sub-processors are contractually prohibited from using Platform data to train their models.

9.6 AI personalisation controls. AI personalisation is governed by two distinct controls rather than a single mirror. (a) An account-level "AI personalisation" toggle governs personalisation derived from the data you have explicitly saved to your account. Because it operates as a withdrawal control over data you have deliberately provided, it defaults on; disabling it stops AI-driven personalisation drawn from your saved account data. (b) The device-level AI / Personalisation category in the Cookie Preference Centre governs personalisation signals held in guest or browser storage. Like every other non-essential consent category, it defaults off and takes effect only if you opt in. Disabling either control removes the corresponding personalisation.

9.7 Provider-side AI use. Providers may use AI tools independently in connection with their own operations. World Camps is not responsible for AI processing carried out independently by a Provider following the lawful transfer of data to that Provider in connection with a Booking.

9.8 Provider-website enrichment at onboarding. At Provider onboarding or acceptance, World Camps may generate camp suggestions and listing enrichment from the Provider's own publicly available website in order to build accurate and complete Listings. Where such content includes personal data (for example, the names of Provider staff published on that website), the lawful basis for this processing is our legitimate interests in building accurate Listings. The Provider-supplied website content is processed through the background-processing Sub-processor listed in Section 5.7 (Trigger.dev). A path to correct or request removal of any personal data surfaced through this enrichment is available by contacting us at the address in Section 16.


10. Children's Privacy

10.1 Heightened protection. The Platform is designed to be used by parents and guardians on behalf of Children. We apply heightened data minimisation, security, and processing standards to all personal data relating to Minors.

10.2 Parental authority. We collect Children's personal data only from parents or legal guardians who represent, by creating a Child profile, that they have the legal authority to provide and consent to the processing of that data.

10.3 Age gate. The Platform is not directed at Children for direct use. Children under 18 are not intended to create their own accounts or directly interact with the booking functionality. Where we become aware that a Minor has created an account without appropriate parental authority, we will delete that account and associated data. Submission of a public review requires the reviewer to self-attest that they are aged 18 or over; this is an 18+ self-attestation enforced server-side, and is a self-declaration rather than formal age verification.

10.4 Data minimisation for Children. We collect only the minimum personal data necessary to facilitate programme matching and Bookings. We do not collect behavioural tracking data on Children for commercial profiling purposes.

10.5 No marketing or AI personalisation to Children. We do not use Children's personal data for targeted marketing, advertising profiling, or any commercial purpose beyond the facilitation of the Booking. We do not seek to identify whether a session belongs to a Minor. A Child's personal data is never used for marketing, advertising, or commercial profiling; where AI-driven programme recommendations draw on the family profile an adult account holder has saved (governed by the account-level "AI personalisation" setting described in Section 9.6), the Child's identity is not disclosed to the AI model — children are represented without names.

10.6 Provider data handling. When we share Children's data with Providers, we do so under contractual obligations requiring Providers to: process the data only for the purpose of delivering the booked programme; comply with applicable data protection law; implement appropriate security measures; and not use Children's data for their own marketing or commercial purposes.

10.7 COPPA (United States). Where the Platform is accessed by users in the United States, we do not knowingly collect personal information from children under the age of 13 without verifiable parental consent. If you believe we have inadvertently collected data from a child under 13 without appropriate consent, please contact us immediately at privacy@world-camps.org and we will promptly delete that data. See Section 17.3 for full COPPA disclosures.

10.8 UK Children's Code. Where the Platform is accessible to users in the United Kingdom, we apply the standards of the UK Age Appropriate Design Code, including: treating all users as potential children unless age can be verified; defaulting to high privacy settings for child-facing features; and applying data minimisation as a default.


11. Security

11.1 We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or alteration. These measures include:

  • encryption of data at rest and in transit (TLS/HTTPS);
  • access controls and role-based permissions;
  • regular internal security assessments and code review;
  • incident detection and response procedures;
  • vendor security due diligence for third-party processors and Sub-processors;
  • platform audit logging covering payment, refund, licence, and subscription-plan events and other security-sensitive system actions (access to a Child's medical-profile data is separately recorded in the append-only access log described in Sections 7.2A and 8.3).

11.2 No transmission of data over the internet is completely secure. While we take all reasonable precautions, we cannot guarantee absolute security against all threats.

11.3 In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware and, where required, will notify affected individuals without undue delay.

11.4 Checkout consent snapshot and payment audit log. When you submit a Booking Request, we store a record of the exact cancellation-policy text and payment schedule shown to you at checkout, together with the date and time and your IP address (the "consent snapshot"). We also maintain an append-only audit log of payment events relating to your Bookings. We process these records on the basis of our legitimate interests in preventing and defending payment fraud and disputes, and to meet our and the Provider's legal obligations relating to Strong Customer Authentication and financial record-keeping. These records are retained for the periods set out in Section 7.2.


12. Cookies and Tracking Technologies

12.1 The Platform uses cookies and similar tracking technologies to support functionality, analytics, and (with your consent) personalisation and marketing. A full description of the cookies we use, their purposes, and how to manage your preferences is set out in our separate Cookie Policy.

12.2 Where cookies involve the processing of personal data, the applicable legal basis is either your consent (for non-essential cookies) or our legitimate interests (for strictly necessary functionality cookies).

12.3 We do not serve third-party advertising cookies or enable behavioural advertising in respect of Child user sessions.

12.4 Validated Global Privacy Control browser signals are honoured as an opt-out of sale and sharing for the relevant session, as further described in Section 11.3 of the Cookie Policy and Section 17.5 of this Policy.

12.5 Consent records. Each cookie-consent decision is recorded on our servers as a discrete record, together with the policy version in force at the time. These server-side consent records make the retention period for cookie-consent records set out in Section 7.2 (duration of consent + 3 years) operative and auditable.


13. Your Rights

13.1 Subject to applicable law and the terms set out in Section 17, you have the following rights in respect of your personal data:

RightDescription
AccessRequest a copy of the personal data we hold about you
RectificationRequest correction of inaccurate or incomplete data
ErasureRequest deletion of your data, subject to legal retention obligations
RestrictionRequest that we limit processing in certain circumstances
PortabilityReceive your data in a structured, machine-readable format
ObjectionObject to processing based on legitimate interests or for direct marketing
Withdraw consentWithdraw consent at any time where processing is consent-based
Automated decisionsRequest human review of automated decisions affecting you
Opt out of sale or sharingDirect us not to "sell" or "share" your Personal Data for cross-context behavioural advertising (US state privacy law concepts) — see Section 17.5
Non-discriminationNot to be discriminated against for exercising any of these rights

13.2 To exercise any of these rights, please contact us at privacy@world-camps.org. We will respond within 30 days. Where requests are complex or numerous, we may extend this by a further 60 days with notice.

13.3 We may ask you to verify your identity before processing your request. We will not charge a fee for standard requests, but may charge a reasonable fee for manifestly unfounded or excessive requests.

13.4 Rights in respect of Children's data. Parents and guardians may exercise the rights above on behalf of a Child for whom they have parental authority. Requests to access, correct, or delete a Child's data should identify the relevant Child and the requesting party's relationship to that Child. A parent or guardian exercising the right of access or portability in respect of a Child receives, as part of the data export, the Child's medical-profile access log, showing which Providers accessed the Child's medical information and when.

13.5 Complaints. If you are dissatisfied with our response, you have the right to lodge a complaint with:

  • the Swiss Federal Data Protection and Information Commissioner (FDPIC) — for Swiss residents;
  • your national data protection supervisory authority — for EU residents;
  • the UK Information Commissioner's Office (ICO) — for UK residents;
  • the relevant state attorney general or the Federal Trade Commission — for US residents.

13.6 Authorised agents. Where US state privacy law permits, you may use an authorised agent to submit a rights request on your behalf. We may require written authorisation from you and verification of the agent's identity before responding.


14.1 The Platform may contain links to third-party websites or integrate with third-party services. These third parties operate under their own privacy policies. We are not responsible for their data practices and encourage you to review their policies independently.

14.2 Our payment processing is carried out by Stripe, Inc. Stripe's privacy practices are governed by the Stripe Privacy Policy. We do not control how Stripe processes data beyond our contractual arrangements with them.


15. Changes to this Policy

15.1 We may update this Policy from time to time to reflect changes in our practices, applicable law, or Platform functionality. Material changes will be notified to registered Users by email or in-platform notification with reasonable advance notice.

15.2 The current version of this Policy is always available on the World Camps website and is identified by the version number and effective date at the top of this document.

15.3 Continued use of the Platform following the effective date of any updated Policy constitutes your acknowledgement of the changes. Where the updated Policy materially changes how Sensitive Personal Data, AI Features, or cookies are used, your continued use does not constitute consent to those uses; affirmative re-consent is collected through the relevant Platform mechanism.


16. Contact and Data Protection Enquiries

World Schools Sàrl
Route de la Bernadaz 5A
1094 Paudex
Switzerland
Email: privacy@world-camps.org

We aim to acknowledge all privacy enquiries within 5 business days and provide a substantive response within 30 days.


17. Jurisdiction-Specific Supplements

The following supplements apply in addition to the main body of this Policy for users in the specified jurisdictions. In the event of conflict between a supplement and the main Policy, the supplement prevails for users in the relevant jurisdiction.


17.1 European Union — GDPR Supplement

Lawful bases. All processing of personal data by World Camps is carried out on one or more of the following lawful bases under Article 6 GDPR: performance of a contract; compliance with a legal obligation; legitimate interests (where not overridden by your interests or fundamental rights); or consent. Processing of Sensitive Personal Data is carried out under Article 9(2)(a) (explicit consent) or Article 9(2)(b) (employment, social protection — where applicable).

Children's data and Article 8 GDPR. The Platform is contracted with parents and legal guardians, not with children, and is not a service offered directly to children within the meaning of Article 8 GDPR and Recital 38. Where personal data of a Minor is processed, the lawful basis is primarily performance of the contract entered into by the parent or guardian (Article 6(1)(b)) and, in the case of Sensitive Personal Data, the explicit consent provided by the parent or guardian (Article 9(2)(a)). World Camps does not collect consent-based marketing preferences from any user identified as a Minor. The parent or guardian's authority to provide and consent to the processing of a Child's personal data is confirmed by attestation at the point of profile creation, as described in Section 10.

EU AI Act. AI Features fall within scope of the EU AI Act transparency obligations (Article 50). World Camps applies the labelling and disclosure measures set out in Section 9.5. World Camps does not currently deploy any high-risk AI system as defined in Annex III of the EU AI Act.

Data Protection Officer. World Camps does not currently have a formally designated DPO. Privacy enquiries should be directed to privacy@world-camps.org. We will keep this position under review as the Platform scales.

Supervisory authority. EU Users have the right to lodge complaints with their national supervisory authority. World Schools Sàrl is established in Switzerland and does not have a main establishment in the EU; the GDPR "one-stop-shop" lead-supervisory-authority mechanism therefore does not apply, and each national supervisory authority within the EU may exercise its competence directly in respect of data subjects resident in its territory. The Swiss Federal Data Protection and Information Commissioner ("FDPIC") is the competent authority in respect of FADP processing.

International transfers. Transfers of personal data outside the EEA are conducted under Standard Contractual Clauses (SCCs) as approved by the European Commission, or other lawful transfer mechanisms.

Legitimate interests assessment. Where we rely on legitimate interests as a lawful basis, we have carried out a balancing assessment. Details are available on request.


17.2 United Kingdom — UK GDPR and AADC Supplement

UK GDPR. World Camps processes the personal data of UK Users in accordance with the UK GDPR and Data Protection Act 2018. The information in the EU GDPR Supplement applies equally to UK Users, subject to the UK-specific instruments referenced below.

International transfers. Transfers of personal data from the UK are conducted under the UK International Data Transfer Agreement (IDTA) or an addendum to EU SCCs, as appropriate.

Age Appropriate Design Code. Where the Platform is accessible to users in the United Kingdom, we apply the standards of the ICO's Age Appropriate Design Code (Children's Code), including best interests of the child as a design principle, high privacy defaults for child-facing features, data minimisation, no geolocation tracking of children, and no nudge techniques directed at children.

Supervisory authority. UK Users may lodge complaints with the Information Commissioner's Office (ICO): www.ico.org.uk.


17.3 United States — COPPA Supplement

Applicability. This supplement applies to users in the United States where the Platform is accessed by or in connection with children under the age of 13.

No knowing collection from under-13s. World Camps does not knowingly collect personal information directly from children under 13 in the United States. The Platform is designed for use by parents and guardians; children do not directly register or interact with booking functionality.

Parental consent. Where a parent or guardian provides information relating to a child under 13, we rely on that parent or guardian's authority and consent as the legal basis for processing. By providing a child's information on the Platform, you represent that you are the parent or legal guardian of that child.

COPPA rights. Parents have the right to: review the personal information we have collected about their child; request correction or deletion of that information; and refuse further collection or use of their child's information. To exercise these rights, contact privacy@world-camps.org.

No behavioural advertising for under-13s. We do not use personal information of children under 13 for targeted advertising or behavioural profiling.

Inadvertent collection. If we discover that we have inadvertently collected personal information from a child under 13 without appropriate parental consent, we will delete that information as promptly as possible. To report a potential COPPA concern, contact privacy@world-camps.org.


17.4 Switzerland — FADP Supplement

Applicable law. World Camps is incorporated in Switzerland and processes personal data in accordance with the revised Swiss Federal Act on Data Protection (FADP, in force 1 September 2023).

Data subjects' rights. Swiss residents have the right to access, rectify, and request the deletion of their personal data, and to object to certain forms of processing, in accordance with the FADP. Requests should be directed to privacy@world-camps.org.

Supervisory authority. Swiss residents may lodge complaints with the Federal Data Protection and Information Commissioner (FDPIC): www.edoeb.admin.ch.

Sensitive data. Processing of sensitive personal data (including health data and data relating to minors) is carried out with explicit consent or under another lawful basis recognised by the FADP.

Cross-border transfers. Transfers of personal data from Switzerland to third countries are conducted in accordance with the FADP's transfer requirements, including contractual safeguards where the recipient country does not offer an adequate level of protection.


17.5 United States — State Privacy Laws Supplement

Applicability. This supplement applies to users who are residents of US states whose comprehensive privacy laws apply to World Camps' processing of their Personal Data, including:

  • California — California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA");
  • Colorado — Colorado Privacy Act;
  • Virginia — Virginia Consumer Data Protection Act;
  • Connecticut — Connecticut Data Privacy Act;
  • Utah — Utah Consumer Privacy Act;
  • Texas — Texas Data Privacy and Security Act;

and other US state comprehensive privacy laws as they come into effect.

Consumer rights. Subject to the requirements of each applicable state law, you have the right to:

  • know and access the categories and specific pieces of Personal Data we collect about you;
  • request correction of inaccurate Personal Data;
  • request deletion of your Personal Data, subject to legal retention obligations;
  • opt out of the "sale" of Personal Data and the "sharing" of Personal Data for cross-context behavioural advertising;
  • opt out of certain forms of profiling that produce legal or similarly significant effects;
  • limit the use and disclosure of sensitive Personal Data to purposes reasonably necessary to provide the requested service;
  • appeal a denial of any rights request;
  • be free from discrimination or retaliation for exercising any of these rights.

No sale or sharing. As stated in Section 5.6, we do not sell Personal Data and we do not share Personal Data for cross-context behavioural advertising under the meaning given by these laws. We honour validated Global Privacy Control signals as an opt-out of sale and sharing for the relevant session. You may also exercise the opt-out at any time through the Cookie Preference Centre or by contacting privacy@world-camps.org.

Sensitive Personal Information / Sensitive Data. Health and medical information relating to a Child is processed only for the purposes set out in Section 4.2 and Section 8, with the explicit consent of the parent or guardian. We do not use sensitive Personal Information to infer characteristics about an individual.

Notice at collection (California). The categories of Personal Information we collect and the purposes for which we collect them are set out in Sections 3 and 4. The categories of recipients with whom we share Personal Information are set out in Section 5.

Verification. We may require verification of your identity (and, where applicable, your authority to act on behalf of a Child) before responding to a request. We will not discriminate against you for exercising any rights under this supplement.

Submitting a request. Requests may be submitted by emailing privacy@world-camps.org or through the rights request form available in your account settings.

Appeals. Where a state law provides a right of appeal against the denial of a rights request, you may submit an appeal to privacy@world-camps.org. We will respond within the period prescribed by the applicable law (typically within 60 days). If your appeal is denied, you may contact your state attorney general.

Children under 16 (California). We do not "sell" or "share" the Personal Information of California residents under the age of 16 without opt-in consent.


This Privacy Policy was last updated on 8 September 2026 and supersedes all prior versions.