QualiMundi  /  Privacy

Privacy statement

You tell us personal things about how you want to travel. Here is exactly what we do with that, in plain language.

Last updated on 6 October 2026.

Who we are

QualiMundi is a brand of A'Top Travel & Incentives, established in Belgium.
Ronkenburgstraat 5
9340 Lede
Company number: BE 0472.490.760
Tour operator licence: A5941
E-mail: hello@qualimundi.com

What we collect

When you fill in the enquiry form, we receive:

  • Contact details: first name, surname, e-mail address, and optionally a phone number, town and country.
  • Travel details: destination or destinations, preferred period and how flexible it is, length of the journey, number of travellers, who is coming along and, if you tell us, the ages of any children.
  • What you tell us: what draws you, what you want to experience, what would make the journey a success, what you would rather avoid, earlier travel experiences, your answer to the open question, your budget indication and anything else you add.
  • Technical: the moment you sent the form, the page you came from, and which site or campaign brought you to us and on which page you arrived. If you opened the form on an earlier day, your own browser remembers how you arrived then, and that goes along with your enquiry.

Everything apart from your name, e-mail address, preferred period and the number of travellers is optional. You decide how much you tell us.

Why we use them

To understand your travel question, to discuss it with you and to build a journey around it together with a local partner. That is the only reason. We do not use your details to profile you for advertising, and we do not sell them.

The legal basis is your consent when you send the enquiry, and after that the performance of the agreement once you travel with us.

Who we share them with

With the local partner we select for your journey, and only what they need in order to think along. That may be a party outside the European Union, which is part of travelling abroad. We share no more than necessary, and we ask our partners for the same care.

Beyond that, with the parties needed to carry out your journey, such as accommodations, airlines and insurers, and with the hosting company that runs the website.

How long we keep them

  • Enquiries that do not lead to a journey: two years at most, so that we do not have to ask you everything again next time. After that we delete them.
  • Enquiries that do lead to a journey: as long as the law requires us to keep our records, usually seven years for the financial documents.
  • Would you like to be erased sooner? Let us know and we will do it.

Your rights

You may ask which details we hold about you, have them corrected, have them deleted, have the processing restricted, object, and receive your details in a readable file. One e-mail to hello@qualimundi.com is enough; we reply within a month.

If you are unhappy with how we handle your details, you can lodge a complaint with the Belgian Data Protection Authority in Brussels.

Cookies

This website places no advertising or tracking cookies and uses no external services that follow what you do. The typefaces are on our own server too, so nothing goes to third parties while you read this site.

We use one technically necessary cookie for your session, which disappears as soon as you close your browser. If you fill in the enquiry form, your own browser keeps your answers locally so you can continue later. Those answers stay on your own device and are only sent to us when you press send.

If you leave your email address halfway through the enquiry form to continue later, we keep your answers on our server until then, for 30 days at most, and send you one email with a link. If you then do not continue for a few days, one of us may contact you once to ask whether we can help. When you send the enquiry or the period runs out, your address and those answers are deleted. If you want that sooner, reply to the email with the link.

If you ask for a reminder on a destination page, we keep your email address and that destination. You first confirm with a click in an email. If you do not, we erase both after 7 days. You receive one email a year per destination, and one click unsubscribes you and removes your address.

When you send a request, we keep with it the pages you read on our site that day. The list comes from that one day's visitor figures and is only made at the moment you send. If you send nothing, no list is kept.

If you sign in to your own portal, you make yourself known at that moment. From then on we link the pages you read on our site that day to your file, so your advisor knows what you were looking at. It only concerns the days you sign in, and the visitor figures themselves stay nameless. If you do not sign in, nothing is linked.

If you tick the box with an alert, we send your email address to Meta in scrambled form, as a SHA-256 fingerprint. That lets Facebook and Instagram show our adverts to you and to people like you. Meta can only match such a fingerprint to an account that uses the same address. You can withdraw on your preferences page.

If you give your Instagram name after your trip, we keep it to mention your name with photos of your trip that we share. You can withdraw in your traveller portal, and then we erase the name at once.

Visitor figures

We keep track of which pages are read, so that we can improve the site. That happens on our own server, without cookies and without anything going to another party. It is why you see no consent banner here.

Per visit we note the page, the type of device (phone, tablet or computer), the site or campaign you came from, how far down you scroll, how long you actually read a page, how fast it loads for you, which buttons and links you click, what you type into the search box of the site and, if you start the enquiry form, how far you get. That last figure is the most useful one we have: it shows which question makes people give up.

Where you click on a page is stored apart from everything else: as a dot on a map of that page, without a fingerprint and with only the date. That way we see what stands out, not who clicked.

On a page that is built from blocks we also note which blocks came into view for you and for how long. Only the kind of block and its place on the page, nothing about you.

Your IP address is not stored. Instead we make an irreversible fingerprint of it, encrypted with a key that changes every day. That means we cannot link the same visitor tomorrow to today, so no profile is built, not even by us. We keep these figures for fourteen months at most and delete them automatically afterwards.

If you have switched on "Do Not Track" or a privacy control in your browser, we do not measure your visit at all.

Sometimes we show two versions of a sentence or a button, to see which works better. Which version you see follows from the same day fingerprint as the visitor figures above: no cookie is involved, and tomorrow you are someone new to us. If your browser asks not to be tracked, you always see the usual version.

Security

Enquiries are sent over a secure connection and stored in a shielded location that cannot be reached through the website. Access is limited to the people working on your journey.