Camille
Travel Destination Expert
camille.

Privacy Policy

Last updated: 18 July 2026

Camille ("Camille", "we", "us"), operated by Scicolone Consulting FZ-LLC, a free zone company registered with the Ras Al Khaimah Economic Zone (RAKEZ), United Arab Emirates (registration number RAKEZ202610000, commercial licence 47034656), including our Camille Go service, provides an AI destination expert that travel brands ("operators") embed on their own websites via a JavaScript snippet. This policy explains what we collect, both from the visitors who chat with Camille on an operator's site and from the operators who use our service, and what we do with that information. Questions and data requests: privacy@camille.travel.

1. What we collect from website visitors

When a visitor interacts with the Camille expert panel on an operator's website, we collect:

2. What we collect from operators

When a travel brand signs up to use Camille, we collect the account owner's email address, company name, website URL, and usage metadata (for example, how many conversations and leads the account has generated). We do not collect or store payment card details. Paid subscriptions are billed through Paddle, our payment processor and merchant of record, which collects and processes billing and payment details (such as payment method, billing address, and tax information) directly from the account owner.

3. How we use visitor data

Visitor data is used to (a) power the live conversation and generate helpful replies; (b) produce a lead brief — name, email, and trip preferences — that is sent to the operator on whose site the conversation took place; and (c) produce anonymized, aggregated analytics that we use to improve the service and to develop and provide new products and services. The aggregates contain no personal information.

4. How we use operator data

Operator data is used to provide and operate the service, send transactional emails (such as lead notifications and account messages), and manage billing.

5. Data sharing

Lead data (name, email, and trip preferences) is shared with the specific operator on whose website the conversation occurred — that is the entire purpose of capturing it. We do not sell personal data. We rely on a small number of processors who handle data only to provide their service to us:

Some of these providers operate in the United States. Where personal data is transferred outside its country of origin, we rely on contractual safeguards — including Standard Contractual Clauses (SCCs) — in our agreements with these providers, ensuring a level of protection equivalent to that of the data's country of origin.

Optional voice call. Some operators turn on a voice option so you can speak with the destination expert instead of typing. Before a call connects you are told that the destination expert understands and answers your voice in real time, that your audio is not recorded, and that you can hang up at any time, and you choose whether to continue. During a call your microphone audio is streamed to ElevenLabs, which converts your speech to text and the destination expert's replies back to speech. We do not store the audio or the transcript, ElevenLabs is set to retain them for zero days (scheduled deletion), and they are not used to train its models. The destination expert always discloses that it is AI. The call is used to continue the conversation and to prepare the same lead brief described above. We keep only basic call metadata, such as its duration, to run and bill the service.

This website (camille.travel and go.camille.travel). Separately from the Service described above, these websites use Google Analytics (Google LLC) to understand how visitors use them, for example which pages are viewed and how visitors found us. This runs only if you consent to the "Statistics" category in the cookie banner shown on the site. For this activity, Camille acts as the data controller of your browsing data on these websites, not as a processor on behalf of any operator. Google may process this data in the United States; we rely on Standard Contractual Clauses (SCCs) for this transfer.

6. Anonymized aggregate data (Camille as controller)

Separately from the per-site service described above, Camille produces anonymized, aggregated statistics about travel demand — for example, interest in a destination, typical budget bands, and conversion rates — from visitor conversations across self-serve operator installations. For this activity Camille acts as an independent data controller, on the legal basis of our legitimate interest in understanding travel demand and improving and developing our products.

These aggregates are produced so that no individual can be singled out: figures are grouped by destination and day, cohorts that are too small are dropped, and no name, email, IP address, or session identifier is stored in the aggregated dataset. Because the result is genuinely anonymized, it is retained indefinitely and used to improve Camille and to develop new products and services. The aggregation is performed only on our servers. Because the result is genuinely anonymized and contains no personal information, it is not personal data under applicable data protection law, and we may use it, publish it, or make it available to third parties, including as part of commercial market-insight products. It is never used to identify, target, contact, or advertise to any individual, and we never sell your personal data. Enterprise and white-label deployments are excluded from this aggregation unless their contract provides otherwise.

Linking to your account (profiling). When you browse this site we collect, using pseudonymous identifiers (such as cookies or device identifiers), information about the pages you view and your preferences, for statistical and service-improvement purposes (legal basis: legitimate interest, Art. 6.1.f GDPR; data held in aggregated and pseudonymous form). If you later create an account and give specific consent, we may link this pseudonymous data, including the history collected before you signed up, to your identity (name, surname, contact details) to personalise your experience and the suggestions you receive. This linking happens only with your explicit, revocable consent (Art. 6.1.a GDPR). You can withdraw consent at any time from your account settings: the linked profile will be re-anonymised or deleted, without losing access to the service.

7. Your rights (GDPR, Australia, and other regions)

For visitor data collected on an operator's website, the operator is the data controller and Camille acts as a data processor on the operator's behalf. Operators are responsible for having an appropriate legal basis for the data collected on their site and for describing Camille in their own privacy policy. You may ask us to access, correct, or delete personal data we hold about you. Data-subject requests: privacy@camille.travel.

Australia. Where we handle the personal information of individuals in Australia, we do so in line with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). As described in section 5, some of your information is stored and processed outside Australia (in the European Union and the United States); under APP 8 we remain accountable for that information and take reasonable steps, including contractual safeguards with our providers, to ensure it is handled consistently with the APPs. If we become aware of a data breach likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme. You can ask us to access or correct your personal information at the contact above; if you are not satisfied with our response, you may complain to the OAIC (oaic.gov.au).

8. United States (California and other state privacy laws)

This section applies to residents of U.S. states with comprehensive privacy laws, including California (CCPA/CPRA), Virginia, Colorado, Connecticut, and Texas. For personal information collected from visitors on an operator's website, Camille acts as a service provider (a processor) to the operator, which is the business (the controller). For the anonymized aggregate analytics described in section 6, Camille acts as a business on its own behalf.

Categories of personal information we collect. Identifiers (such as name, email, an optional phone number, IP address, and a pseudonymous session identifier); internet and electronic activity (the conversation text and derived signals); coarse location inferred from IP address; and inferences about travel interest and budget. We do not seek sensitive personal information, government IDs, or financial-account numbers, and we do not collect payment-card details.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding twelve months. Because we do not sell or share, no "Do Not Sell or Share My Personal Information" action is required; where applicable we honor browser opt-out preference signals such as the Global Privacy Control (GPC).

Your rights. Depending on your state, you may have the right to know and access the personal information we hold about you, to delete it, to correct it, to opt out of its sale, sharing, or use for targeted advertising, to limit the use of sensitive personal information, and to not be discriminated against for exercising these rights. Some states also give you a right to appeal a decision. To exercise any of these, contact privacy@camille.travel; you may use an authorized agent. We will verify your request against the information we hold before acting on it. Because the operator is usually the business that controls visitor data, you may also direct your request to the operator on whose website you used Camille.

Children. Camille is not directed to children, and we do not knowingly collect personal information from children under 13 (or, where a higher age applies under state law, under 16) without the consent required by law.

California "Shine the Light". We do not disclose personal information to third parties for those third parties' own direct-marketing purposes.

9. United Arab Emirates

Where we handle the personal data of individuals in the UAE, we do so in line with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL"). As with other regions, for visitor data collected on an operator's website the operator is the controller and Camille acts as a processor on the operator's behalf. We process personal data on a lawful basis (such as your consent or another basis permitted by the PDPL), and you may ask us to access, correct, delete, or restrict your data, to object to processing, or to withdraw consent, at privacy@camille.travel.

As described in section 5, your data is stored in the European Union (Frankfurt), a jurisdiction offering an adequate level of protection, and any onward transfer to a provider in another country is made under appropriate contractual safeguards as permitted by the PDPL's cross-border transfer provisions. If we become aware of a data breach likely to cause harm, we will notify affected individuals and the competent authority (the UAE Data Office) as required.

10. Kingdom of Saudi Arabia

Where we handle the personal data of individuals in the Kingdom of Saudi Arabia, we do so in line with the Personal Data Protection Law (Royal Decree M/19 of 2021, as amended by Royal Decree M/148 of 2023) and its Implementing Regulations (the "PDPL"), regulated by the Saudi Data & AI Authority (SDAIA). As with other regions, for visitor data collected on an operator's website the operator is the controller and Camille acts as a processor on the operator's behalf. We process personal data on a lawful basis (such as your consent or another basis permitted by the PDPL); voice data is treated as sensitive data requiring your explicit consent before a call connects (see section 5). You may ask us to access, correct, delete, or restrict your data, to object to processing, to withdraw consent, or to receive a copy in a portable format, at privacy@camille.travel.

As described in section 5, your data is stored in the European Union (Frankfurt). Onward transfer to our processors outside the Kingdom — including those in the United States — is made under the Kingdom's Standard Contractual Clauses (published by SDAIA, September 2024) or equivalent contractual safeguards, supported by a documented transfer risk assessment. If we become aware of a data breach likely to cause harm, we will notify affected individuals and provide the operator the information it needs to notify the National Data Governance Platform within 72 hours, as required. We do not make decisions about you based solely on automated processing without human involvement.

11. Indonesia

Where we handle the personal data of individuals in Indonesia, we do so in line with Law No. 27 of 2022 on Personal Data Protection (the "PDP Law"). As with other regions, for visitor data collected on an operator's website the operator is the controller (the Personal Data Controller) and Camille acts as a processor (Personal Data Processor) on the operator's behalf. We process personal data on a lawful basis permitted by the PDP Law (such as your consent), and you may ask us to access, correct, complete, delete, or restrict your data, to object to processing, to withdraw consent, or to obtain a copy of your data, at privacy@camille.travel.

As described in section 5, your data is stored in the European Union (Frankfurt), and any onward transfer to a provider in another country is made under appropriate contractual safeguards, consistent with the PDP Law's requirement that the destination provide protection at least equivalent to the PDP Law, or that adequate binding safeguards or your consent are in place. If we become aware of a data breach affecting personal data, we will notify affected individuals and the competent authority within 72 hours of becoming aware, as required by the PDP Law, and give the operator the information it needs to meet its own notification duties.

12. Retention

Changes

We may update this policy as the product grows. The "last updated" date above always shows the current version.

Contact

privacy@camille.travel

← Back to camille.travelgo.camille.travel