Privacy policy

Data Protection Privacy Statement

Introduction

Eman Channel Ltd ("we", "our" or "us") is the operator of the Light Upon Light Global - Türkiye Retreat 2027. Light Upon Light is a project of Eman Channel, and the personal data collected through this website is held and managed by Eman Channel Ltd. This privacy notice outlines why we collect and use your personal data, the circumstances under which we may share your personal data with other organizations, and your individual rights regarding your personal data.

We are committed to transparency and aim to help you understand and exercise your rights concerning your personal data. We do not share personal data with any organization for their marketing purposes, and we do not sell, rent or trade personal data.

This privacy notice is organized into the following sections:

  • Who we are
  • Your rights over your personal data
  • Privacy statement for our supporters and retreat guests
  • Privacy statement for our employees and volunteers
  • Keeping your personal data secure
  • Sending your personal data outside the UK
  • Use of cookies
  • Links to other websites
  • How long we keep personal data
  • Changes to the privacy notice
  • How to make a complaint

If you have any questions about this privacy notice, or about information we hold about you, please contact our Data Protection Lead at [email protected].

Who we are

Light Upon Light Global is a project of Eman Channel Ltd, and Eman Channel Ltd is the data controller for the personal data described in this notice.

Your rights over your personal data

You have the following rights regarding your personal data:

  • Right to withdraw consent. If we ask for your consent to use your personal data, you may withdraw it at any time. Any direct marketing materials will include clear instructions on how to withdraw your consent, such as an "unsubscribe" link in emails. To stop processing your personal data for marketing purposes, please contact our Data Protection Lead.
  • Right of access (subject access request). You have the right to know what personal data we hold about you and to request a copy of that information.
  • Right to object or restrict processing. You can request that we restrict or stop the processing of your personal data.
  • Right of data portability. You can request a copy of your personal data in a portable format, or have it transferred directly to another organization.
  • Right of erasure. You may request that we delete the personal data we hold about you (the "right to be forgotten").
  • Right of rectification. If you believe the personal data we hold is inaccurate, you can request corrections or updates.

To exercise these rights, or for more information, contact our Data Protection Lead. We are committed to providing a confidential and professional service and will respond fully to your requests.

Privacy statement for our supporters and retreat guests

When we collect your personal data

We collect your personal data in the following situations:

  • When you book a room, add guests to a booking, or make a payment on this website.
  • When you register for or attend one of our retreats or activities.
  • When you make a donation.
  • When you sign up for a campaign or event.
  • When you contact us by email, telephone, post, live chat or through our website.
  • When you interact with us on social media.
  • When you visit and use our website (see "Use of cookies" below).

What personal data we collect

  • Your details. Your name, email address, telephone number and postal address.
  • Guest details. The name, date of birth and gender of every person on a booking. Hotels in Türkiye are required to register each guest individually, so we cannot confirm a room without them. Dates of birth also determine the price of a room, because children are charged at different rates from adults.
  • Travel documents. Passport details, where they are needed for hotel registration, visas or travel arrangements.
  • Payment information. Card details are entered directly into our payment provider's secure form and are processed by them. We never see or store your full card number. We hold a record of what you paid and when, and a reference that lets our payment provider collect any instalments you have agreed to.
  • Technical data. Your IP address, browser and device type, and how you move through our website.
  • Correspondence. Emails, chat messages, support tickets, call notes and feedback you send us, together with our replies.

Why we collect and use your personal data

We collect and use your personal data for the following purposes:

  • To take and manage your booking, including allocating rooms and registering your party with the hotel.
  • To take payment, to collect instalments you have agreed to, and to issue receipts and refunds.
  • To keep you informed about your booking, the programme and practical arrangements for the retreat.
  • To process donations and handle Gift Aid declarations.
  • To manage event registrations and provide confirmation details.
  • To communicate with you about our activities, campaigns and ways to support us (only with your consent for email, phone or SMS communications).
  • To personalize services, such as predicting your interests for tailored communications.
  • To handle your queries and feedback about our services.
  • To improve our services and our website, including finding and fixing faults.

Sharing personal data with other organizations

We may share your personal data in the following circumstances:

  • With the hotel hosting the retreat, for room allocation, guest registration and health and safety.
  • With travel partners, such as transport and airport transfer providers, where you have booked those services.
  • With payment processors, for transactions involving bookings, donations or purchases.
  • With HMRC for Gift Aid purposes.
  • With law enforcement agencies when required by valid legal instruction.
  • With event organizers for health and safety purposes when you register for events.
  • With marketing service providers (for example, mailing houses) to prepare and send approved materials on our behalf.
  • For due diligence checks, we may use third-party screening services for significant donations or support.
  • With data storage providers, such as cloud storage or website hosting companies.

In all instances, we ensure contracts with these organizations include data protection clauses to secure your data and prohibit its use for their own marketing purposes.

We process your personal data on the following legal grounds:

  • Consent. For marketing communications via email, phone or SMS (withdrawable at any time).
  • Contractual necessity. To take and fulfil your booking, to collect payment, and to process donations or event registrations.
  • Legal obligations. For compliance with tax laws, such as Gift Aid records, and with the guest-registration requirements of the country the retreat is held in.
  • Legitimate interests. For communications and marketing, and for keeping our website working and secure, unless your rights override our interests.

Privacy statement for our employees and volunteers

When we collect personal data

  • During recruitment and onboarding processes.
  • Through everyday administration, such as leave requests or updates to personal details.
  • When managing performance or addressing concerns and complaints.

Why we use personal data

  • To recruit and manage staff, volunteers and contractors.
  • To process payroll, tax and pension contributions.
  • To comply with legal obligations, such as health and safety regulations.
  • For operational planning, including staffing and resource allocation.
  • To address complaints and safeguarding concerns.

Sharing data

  • With HMRC for taxation purposes.
  • With insurance companies for claims involving staff or volunteers.
  • For background checks, using services such as DBS, DVLA or employment agencies.
  • With third-party providers, such as cloud storage or software systems.

We ensure third-party contracts include data protection clauses to secure your data and limit its use.

Keeping your personal data secure

We use appropriate technical and organizational measures to protect your personal data against unauthorized access, loss or destruction. This website is served over an encrypted connection, access to booking records is restricted to the staff who need it and is logged, and card details are handled entirely by our payment provider rather than stored by us.

No method of transmission over the internet is completely secure, so we cannot guarantee absolute security. Where we are required to, we will report a personal data breach to the Information Commissioner's Office and, where the breach is likely to be a high risk to you, we will tell you as well.

Sending your personal data outside the UK

The retreat takes place in Türkiye, so some of the personal data described above is sent to the hotel and to travel partners there in order to register and arrange your stay. This includes each guest's name and date of birth, and passport details where the hotel or the authorities require them. Some of the suppliers we use to run this website and send our email also store data outside the UK.

Where personal data leaves the UK, we make sure the transfer is covered by the safeguards that UK data protection law requires, such as an adequacy decision or standard contractual clauses.

Use of cookies

Cookies are small text files stored on your device when you visit a website. You can manage or refuse cookies through your browser settings, though disabling them may stop parts of this website working. You can change your choice at any time using the "Cookie preferences" link in the footer of any page.

There are three kinds of cookie and similar technology on this site, and only the third asks your permission.

Essential, always on. These keep you signed in, keep your booking and checkout working, remember your cookie choice, and protect our forms against cross-site request forgery. The site cannot work without them, so they are not optional and there is no consent to give.

Fault reporting and usage analytics, always on. These run on every visit, before and regardless of any banner choice, because they are how we find out that something is broken for you. One records the technical detail of an error; the other records which pages were opened and which steps of a booking were reached. Neither records your name, what you type into a form, or a recording of your screen: page text and form fields are masked before anything is sent, and usage is linked to your account only when you are already signed in. We rely on our legitimate interest in running a working and secure booking service. If you would prefer that we did not do this, please contact our Data Protection Lead.

Marketing, only with your permission. These load only after you choose "Accept all" on the cookie banner. If you choose "Essential only" they are never loaded and nothing is recorded. They cover website analytics provided by Google, advertising measurement provided by Meta, and a cookie that remembers which campaign or link brought you to the site, so that we can tell which advertising is worth paying for. Video embedded from services such as YouTube may also set cookies when you play it.

Our website, our emails and our social media posts may link to websites we do not run. This privacy notice does not cover them, and we are not responsible for their content or for how they handle your personal data. Please read the privacy notice of any website you go on to visit.

How long we keep personal data

We keep booking and payment records for seven years after the retreat, to meet UK accounting and tax obligations. Marketing contact data is kept until you withdraw your consent or ask us to stop contacting you. Employee and volunteer records are kept for the periods required by employment and tax law. Personal data we no longer need for these purposes is deleted or anonymized. To ask what we hold about you, or to ask us to delete it, contact our Data Protection Lead.

Changes to the privacy notice

We review our privacy notice regularly. Updates will be posted on our website. For material changes, we will include a prominent notice.

Last updated: August 2026.

How to make a complaint

If you have concerns about our processing of your personal data, contact our Data Protection Lead at [email protected].

You can find our ICO registration details at ico.org.uk/ESDWebPages/Entry/ZB334762.

If you are unsatisfied with our response, you can escalate your complaint to the UK Information Commissioner's Office (ICO) at ico.org.uk/global/contact-us.