Curated Island Experiences
PRIVACY POLICY
Version 2.0 | Effective: July 2026
Maldives Stories Travel Pty Ltd (ABN 22 693 792 022), trading as Maldives Diaries
Australia | Republic of Maldives
YOUR PRIVACY MATTERS: Maldives Diaries is committed to protecting the personal data of our clients, website visitors, and business partners. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, and what rights you have over your information. Please read this document carefully.
"Maldives Diaries" is the trading name of Maldives Stories Travel Pty Ltd (ABN 22 693 792 022), a company incorporated under the Corporations Act 2001 (Cth) and carrying on business in Australia (hereinafter "the Company," "we," "us," or "our"). Maldives Stories Travel Pty Ltd is the primary Data Controller for personal data collected in connection with our website, Bookings, and marketing activities.
The on-ground delivery of Packages within the Republic of Maldives is carried out by Maldives Diaries Private Limited ("the Local Operator"), a duly licensed tour operator incorporated under the laws of the Republic of Maldives. The Local Operator processes personal data on our behalf, and, in respect of data it is independently required to collect and report under Maldivian law (for example, immigration and safety-related data), acts as a joint controller together with the Company.
This Policy applies to all personal data collected and processed by the Company and the Local Operator through:
This Policy is published in compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the Maldives Data Protection Act 2017 (Law No. 29/2017) and in anticipation of further obligations under the Privacy and Personal Data Protection Bill (as consulted upon in 2023 and any successor legislation enacted thereafter), as well as the General Data Protection Regulation (GDPR) of the European Union and the UK General Data Protection Regulation (UK GDPR) to the extent applicable to our processing of personal data of individuals resident in those jurisdictions.
For the purposes of applicable data protection law, Maldives Stories Travel Pty Ltd acts as the primary Data Controller (and, for Australian purposes, the relevant APP entity) with respect to personal data collected from Clients, website visitors, and business partners. Our details are:
Maldives Diaries
A trading name of Maldives Stories Travel Pty Ltd (ABN 22 693 792 022)
Email (Privacy): privacy@maldivesdiaries.com
Phone: +61 494 741 329
"Data Controller" means the entity that determines the purposes and means of processing personal data. For the purposes of the Privacy Act 1988 (Cth), this corresponds to an "APP entity" and "personal data" corresponds to "personal information."
"Data Processor" means an entity that processes personal data on behalf of the Data Controller.
"Data Subject" means a natural person whose personal data is processed by the Company.
"Personal Data" means any information relating to an identified or identifiable natural person, including but not limited to names, identification numbers, location data, online identifiers, or factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.
"Processing" means any operation performed on personal data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, combination, restriction, erasure, or destruction.
"Sensitive Personal Data" means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for identification purposes, health data, or data concerning sexual orientation. This corresponds broadly to "sensitive information" under the Privacy Act 1988 (Cth).
"Third Party" means a natural or legal person, public authority, agency, or body other than the Data Subject, Data Controller, or Data Processor.
The Company collects and processes the following categories of personal data:
Health data constitutes Sensitive Personal Data (and "sensitive information" under the Privacy Act 1988 (Cth)). We process such data only where strictly necessary for the safe delivery of our services and with the explicit consent of the Data Subject.
We collect personal data through the following channels:
We process personal data on the following legal bases:
We process personal data for the following purposes:
We share personal data with third parties only where necessary and on a lawful basis. Recipients of personal data may include:
The Local Operator (Maldives Diaries Private Limited), and guesthouses, transport operators, activity providers, dive centres, and local guides engaged to deliver elements of the Package, receive the minimum personal data necessary to deliver their specific service. All Service Providers engaged by the Company are required under our Service Provider Agreements to process personal data only for the purposes for which it is shared and in compliance with applicable law.
Where a Booking is received through a foreign tour operator or travel agent operating under an affiliation agreement with the Company, personal data may be shared with that partner to the extent necessary for the coordination of the Package. Foreign partners are required to maintain appropriate data protection standards and to process personal data only for the purposes of the Booking.
Payment transactions are processed by third-party payment processors who are PCI-DSS compliant. We do not store full credit or debit card details. Payment processors operate under their own privacy policies and data security standards.
We may disclose personal data to Australian regulators (including the Australian Taxation Office and the Office of the Australian Information Commissioner where relevant) and to Maldivian authorities, including the Ministry of Tourism, Maldives Immigration, Maldives Customs Service, the Maldives Inland Revenue Authority (MIRA), and the Maldives Police Service, where required by law, where necessary for the safe delivery of our services, or in response to a lawful order from a court or authority. Clients should be aware that Maldivian immigration authorities require advance passenger information for all arrivals.
In the event of a medical or safety emergency, the Company may share personal data, including health information, with emergency services, medical facilities, and evacuation services to protect the vital interests of the Data Subject or others.
Our legal advisers, auditors, accountants, and insurers may receive personal data where necessary in connection with their professional services, subject to professional confidentiality obligations.
In the event of a merger, acquisition, or restructuring of the Company, personal data held by the Company may be transferred to the successor entity as part of the business transfer, subject to the receiving entity being bound by equivalent data protection obligations.
As an Australian company, Maldives Stories Travel Pty Ltd takes reasonable steps to ensure that overseas recipients of personal data, including the Local Operator and Service Providers in the Republic of Maldives, handle personal data consistently with the Australian Privacy Principles, in accordance with APP 8 of the Privacy Act 1988 (Cth).
The nature of our business also requires that personal data is shared with Service Providers, partners, and authorities in the Republic of Maldives. Clients from the European Economic Area (EEA), the United Kingdom, or other jurisdictions with data transfer restrictions should be aware that neither Australia (for transfers onward to the Maldives) nor the Maldives currently holds an adequacy decision from the European Commission or equivalent body in respect of these onward transfers.
Where personal data is transferred from the EEA or UK to Australia- or Maldives-based recipients, we rely on Standard Contractual Clauses (SCCs) or other appropriate safeguards where contractually feasible. Where SCCs are not in place, we rely on the necessity of the transfer for the performance of the contract between the Data Subject and the Company (Article 49(1)(b) GDPR).
Personal data may be transferred to foreign tour operator partners in the Client's country of residence. Such transfers are made pursuant to contractual necessity and, where applicable, supported by SCCs or equivalent safeguards.
For Clients from jurisdictions outside the EEA and UK, the Company complies with applicable local data protection law regarding cross-border transfers to the extent notified in writing by the Client's jurisdiction.
We retain personal data for no longer than is necessary for the purposes for which it was collected, subject to applicable legal requirements.
The following indicative retention periods apply:
At the end of the applicable retention period, personal data will be securely deleted or irreversibly anonymised.
Maldives Diaries implements appropriate technical and organisational security measures to protect personal data against unauthorised access, accidental loss, disclosure, alteration, or destruction, commensurate with the nature and sensitivity of the data processed, consistent with our obligations under Australian Privacy Principle 11 and equivalent Maldivian requirements.
Security measures include, but are not limited to:
Notwithstanding the foregoing, no method of transmission over the internet or electronic storage is completely secure. The Company cannot guarantee absolute security and encourages Clients to use secure channels when transmitting sensitive personal information.
Payment card data is handled exclusively by PCI-DSS compliant payment processors. The Company does not store, transmit, or process full card numbers.
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of Data Subjects, the Company will:
Notifications to Data Subjects will describe the nature of the breach, the likely consequences, the measures taken or proposed to address the breach, and provide the contact details of the Company's privacy contact.
Subject to applicable law and any exemptions therein, Data Subjects have the following rights with respect to their personal data held by Maldives Diaries:
You have the right to request a copy of the personal data we hold about you and information about how it is processed. We will respond to such requests within 30 days (or such other period as required by applicable law, including a reasonable period under Australian Privacy Principle 12). We may require verification of your identity before fulfilling an access request.
You have the right to request correction of inaccurate personal data. If you believe any personal data we hold is incorrect or incomplete, please contact us and we will rectify it without undue delay, consistent with Australian Privacy Principle 13 and equivalent requirements under other applicable law.
You have the right to request deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purpose for which it was collected, where consent has been withdrawn, or where the data has been unlawfully processed. This right is subject to our legal obligations to retain data for tax, regulatory, or legal purposes, which may override a deletion request.
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as where you contest the accuracy of the data or where you have objected to processing pending verification of our legitimate interests.
Where processing is based on consent or contractual necessity and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
You have the right to object to the processing of your personal data for direct marketing purposes at any time, without giving reasons. You also have the right to object to processing based on our legitimate interests, on grounds relating to your particular situation.
You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects concerning you. Maldives Diaries does not currently engage in such automated decision-making.
Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.
You have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction. For Australian residents, this is the Office of the Australian Information Commissioner (OAIC). For EEA residents, this is the data protection authority of your EU Member State. For UK residents, this is the Information Commissioner's Office (ICO). For Maldivian residents or for complaints relating to Maldivian law, you may contact the relevant Maldivian authority responsible for data protection matters.
To exercise any of the above rights, please submit a written request to privacy@maldivesdiaries.com. We may ask you to verify your identity before processing your request. We will respond within 30 days, or within the timeframe required by applicable law.
Our website uses cookies and similar tracking technologies to enhance user experience, analyse website performance, and support our marketing activities. A cookie is a small data file stored on your device when you visit a website.
Types of Cookies We Use:
We obtain your consent before placing non-essential cookies on your device through our cookie consent tool. You may withdraw or modify your consent at any time by accessing your cookie settings on our website.
You may also control cookies through your browser settings. Disabling certain cookies may affect the functionality of our website.
Our website may include social media sharing features, embedded content, or links to third-party websites. The Company is not responsible for the privacy practices of third-party websites and encourages you to review their respective privacy policies.
When you interact with our social media channels, your personal data will also be processed by the operator of the relevant platform (e.g., Meta, Instagram, Facebook) in accordance with their privacy policies. We do not control this processing.
We may use your contact details to send you promotional communications about our Packages, special offers, new itineraries, and travel content. We rely on:
You may unsubscribe from marketing communications at any time by clicking the unsubscribe link in any marketing email, or by contacting us at privacy@maldivesdiaries.com. Unsubscribing from marketing does not affect communications necessary for the performance of an existing Booking.
We do not sell, rent, or exchange your personal data with third parties for their own marketing purposes.
Where you provide us with a review, testimonial, or photograph for publication on our website or marketing materials, we will publish this content only with your explicit written consent.
You may withdraw consent for publication of your testimonial or photograph at any time by contacting us. We will remove such content within a reasonable time, acknowledging that content already distributed in physical print materials cannot be recalled.
Our services are marketed to adults aged 18 and over. Where a Package includes minors (persons under 18 years of age), the personal data of such minors is processed only with the explicit consent of and under the authority of the minor's parent or legal guardian, who accepts full responsibility for compliance with these terms on behalf of the minor.
The personal data of minors will be used only to the extent necessary for the delivery of the booked Package and compliance with Maldivian immigration and safety requirements.
The Company does not knowingly collect personal data from children for marketing purposes. If we become aware that we have inadvertently collected such data, we will delete it promptly.
We recognise that health data is among the most sensitive categories of personal data. We process health-related information provided by Clients solely for the following purposes:
Health data is shared with Service Providers only to the extent strictly necessary for safety, and is not disclosed for any other purpose.
We process health data on the basis of explicit consent, which you provide by completing the health declaration section of our Booking Form. You may withdraw this consent at any time; however, withdrawal may mean that the Company is unable to assess the suitability of certain activities for your participation.
Passport and travel document data is collected solely for the purposes of coordinating travel logistics and fulfilling Maldivian immigration requirements. Copies of passports are held in encrypted digital storage and are not shared beyond the parties necessary for immigration, transport, and accommodation check-in purposes.
Maldivian law and immigration regulations require that certain passenger data be provided to Maldivian immigration authorities. Provision of this data is a legal requirement and is not subject to Client objection.
As Maldives Stories Travel Pty Ltd is registered and operates in Australia, we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) to the extent applicable to our business. This includes principles relating to open and transparent management of personal information, collection, use and disclosure, direct marketing, cross-border disclosure, data quality, data security, and access and correction.
Australian Clients who are not satisfied with our response to a privacy enquiry or complaint may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Where we process personal data of individuals in the EEA or UK, we do so in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the UK GDPR respectively. This includes observing all applicable data subject rights described above, maintaining records of processing activities, and implementing appropriate safeguards for international transfers.
Our lawful basis for international transfer from the EEA or UK to Australia or the Maldives is primarily the necessity of the transfer for the performance of a contract between the Data Subject and the Company (Article 49(1)(b) GDPR). Where we engage EEA or UK-based data processors, we ensure Standard Contractual Clauses are in place where required.
EEA and UK Clients have the right to complain to their local data protection authority: for EEA residents, the supervisory authority of the relevant EU Member State; for UK residents, the Information Commissioner's Office (ico.org.uk).
Clients resident in countries with applicable data protection legislation (including but not limited to Canada, Singapore, India, and other jurisdictions with privacy frameworks) retain their rights under applicable local law. The Company will endeavour to accommodate rights requests from Data Subjects in all jurisdictions within a reasonable timeframe.
Clients are encouraged to contact privacy@maldivesdiaries.com to exercise any jurisdiction-specific rights or to request information about how we comply with applicable local data protection law.
We review and update this Privacy Policy periodically to reflect changes in our data processing activities, applicable law, and best practice. The current version and its effective date are displayed at the top of this document.
Where we make material changes to this Policy, we will notify affected Data Subjects by email (where we hold an active email address) and will publish the updated Policy prominently on our website. Continued use of our services following notification of a material update constitutes acceptance of the updated Policy.
We encourage you to review this Policy periodically.
This Privacy Policy, insofar as it governs the processing of personal data by Maldives Stories Travel Pty Ltd, is governed by the laws of Australia, including the Privacy Act 1988 (Cth). Insofar as this Policy governs the processing of personal data by the Local Operator in the Republic of Maldives, it is governed by the laws of the Republic of Maldives, including the Maldives Data Protection Act 2017. To the extent required by applicable law in the jurisdiction of the Data Subject, the applicable data protection law of that jurisdiction also applies to the processing of that Data Subject's personal data.
For all data protection enquiries, rights requests, or concerns, please contact our Office:
ABN: 22 693 792 022Data Protection Commitment: Maldives Diaries is committed to handling your personal data with the highest standard of care, transparency, and respect. If you believe your data has been mishandled, please contact us directly so we may address your concern. You also have the right to escalate to your local supervisory authority — including the OAIC for Australian residents — at any time.