Bregora

Privacy Policy

Last updated: 11 August 2026

Bregora is the customer-communication platform used by Hima Travel. It brings the messages you send us — on Facebook Messenger, Instagram, WhatsApp, email and our website chat — into a single inbox, so that a real person answers you instead of your message being lost across five apps. This policy explains what we hold about you, why, and how you can have it removed.

Who is responsible for your data

Hima Travel decides why and how your personal data is processed and is the controller of that data. Bregora is the software it uses to do so.

If you have any question about this policy, or you want a copy of your data or its deletion, write to privacy@bregora.com. A person reads that address.

Where your data comes from

We do not buy contact lists and we do not collect data about you in the background. Everything we hold arrives because you contacted us on one of these channels, or because you gave it to us directly:

  • Facebook Messenger — messages you send to our Page, and your public profile name and picture as Meta provides them.
  • Instagram — direct messages, and comments or mentions you leave on our posts.
  • WhatsApp Business — messages you send to our business number, and the phone number you send them from.
  • Email — messages you send to the mailboxes we connect to the platform.
  • Our website chat — what you type in the chat widget, and basic technical information about that visit.

What we hold

  • Identity and contact details: your name or profile name, phone number, email address, and the account identifier the channel gives us.
  • The content of your messages, and ours — the conversation history, kept so that the next colleague who answers you knows what was already said.
  • Files you send: photos, voice notes, and documents. If you send travel documents such as a passport scan for a booking, we hold that document too — send such files only when a booking genuinely requires it.
  • Enquiry and booking details you tell us: destination, travel dates, number of travellers, budget, and similar.
  • Notes, tags and tasks our staff add internally while working on your enquiry.
  • Marketing preferences, including a record of when you asked us to stop messaging you.
  • Technical records needed to run the service: delivery and error logs, and login sessions of our own staff.

Why we use it

  • To answer you and to prepare, discuss and manage the trip or service you asked about. Without this we cannot reply at all.
  • To keep a history of our dealings, so you are not asked to repeat yourself and so we can resolve later questions or complaints.
  • To send you service messages about a booking you have with us.
  • To send offers or news, only where you have agreed to receive them, or where you contacted us and the law allows it. You can stop these at any time — reply STOP on WhatsApp, or simply tell us.
  • To meet legal obligations, such as accounting and consumer-protection record-keeping.
  • To keep the service secure and working: preventing abuse, diagnosing faults, and taking backups.

The legal grounds we rely on are: performance of a contract or steps taken at your request before one; your consent, for marketing; our legitimate interest in running and securing the business; and compliance with legal obligations.

Data received through Meta (Facebook, Instagram, WhatsApp)

When you message us through Messenger, Instagram or WhatsApp, Meta passes that message and a limited profile to us so we can reply. We use that Platform Data for one purpose only: to hold the conversation with you and serve the request you made.

We do not sell it, we do not use it to build advertising profiles of you, and we do not transfer it to data brokers. Where our own systems no longer need it, or you ask us to erase it, it is deleted.

Meta remains the operator of Messenger, Instagram and WhatsApp themselves, and its own privacy policy governs what happens inside those apps.

Who else can see it

  • Our own staff, limited to the colleagues who handle customer enquiries.
  • Meta Platforms — as the operator of the messaging channel your message travels through.
  • Our hosting provider, Hetzner Online GmbH, whose servers in Nuremberg, Germany hold the platform and its database. Your data stays within the European Union.
  • The email provider of any mailbox connected to the platform.
  • Authorities, where the law requires us to disclose something.

We never sell your personal data.

How long we keep it

We keep conversations and enquiry records for as long as we have an active relationship with you, and afterwards for the period our accounting and consumer-protection obligations require. Records we no longer have a reason to hold are deleted.

If you ask us to erase your data sooner, we do so unless a law requires us to keep a specific record — in which case we tell you which record and why.

Your rights

You can ask us to:

  • tell you what data we hold about you, and give you a copy;
  • correct anything that is wrong;
  • erase your data;
  • restrict or object to how we use it, including stopping marketing entirely;
  • receive your data in a portable form.

Write to privacy@bregora.com. We answer within 30 days. You also have the right to complain to your national data-protection authority if you believe we have handled your data wrongly.

How to have your data deleted

The deletion steps, and the details you need to include so we can find your records, are on a separate page: /data-deletion

Security

The platform is served only over an encrypted connection. Access requires an account, and the database and its supporting services are not reachable from the public internet. Access tokens for the messaging channels are held on the server, never in your browser. Backups are taken daily.

No system is perfect. If a breach ever affects your data, we will notify you and the competent authority as the law requires.

Children

The service is meant for adults arranging travel. We do not knowingly seek data from children. Where a booking includes a minor, we hold only what the booking itself requires, provided by the adult making it.

Changes to this policy

If we change how we handle your data, we update this page and the date at the top. Material changes will be communicated to the people affected.

Contact

Hima Travel — privacy@bregora.com