Data protection and UK GDPR

Roam Pal Guide · roampalguide.com · last reviewed 2 October 2026

This page is for organisations, and for anyone who wants the data flows in one place. It covers UK GDPR and the Data Protection Act 2018. The full notice for visitors is our privacy notice. Both pages describe the same data flows.

The short version. Roam Pal has no accounts and no sign-in. Trips, notes, places, photos and access needs are saved on the visitor’s own device, not on our servers. Our Hub at adaidigital.co.uk receives internet addresses when the app checks video report counts, and reports or corrections that people choose to send. Outside services supply maps, photos and video pictures, and see internet addresses.

1. Who is responsible

Roam Pal Guide is provided by ADAI Digital Ltd (“we”, “us”), company number 17242851. Roam Pal began in the UK; the company's registered office is Suite A, 82 James Carter Road, Mildenhall, England, IP28 7DE. This is the statutory registered office, not a customer visiting address. We are the controller for the personal data described here. Our ICO registration number is ZC208103. Contact: admin@adaidigital.co.uk.

We have not appointed a data protection officer. Questions about privacy go to Allan Drummond, a director of ADAI Digital, at the email address above.

2. What stays on the device

Roam Pal saves what people make in their browser’s own storage, on their device. This covers current and past trips, wish lists, day plans, their own places (such as home or caravan storage), notes, photos, videos, voice notes, access needs, travel profiles, journey support plans, assistance requests, bookings and booking references. Saved memberships and discount cards stay on the device too, and Roam Pal never asks for card numbers, proof of eligibility or portal passwords.

We hold no copy. A person removes all of it by clearing the site’s data in their browser or uninstalling the app. A shared trip copy is encrypted on the device and carried in the link. It is not uploaded to us.

3. Every data flow off the device

Automatic, as the app is used

Only when a person uses a feature

Sent only when a person chooses

Video reports and report counts

4. Where data is held, and transfers

The Hub runs on Google Cloud Run in London, in the europe-west2 region. It stores reports in Google’s Firestore database, which is in London too. Google’s data processing terms say that when Google sends information to a country the UK does not treat as adequate, it uses an approved safeguard that it tells us about, or standard contractual clauses. We have accepted Google’s data processing terms for this project. Firebase Hosting serves pages from a worldwide network. The outside services above act for themselves. Several are outside the UK, for example in the European Union and the United States. The visitor’s device contacts them directly, and we have no separate transfer safeguard with them.

5. Lawful basis and retention

Legitimate interests covers serving the website securely, showing maps and photos, keeping videos and access information accurate and safe, and replying to messages. Trip Check relies on taking the steps a person asks for before a contract, and carrying it out. Consent covers anonymous service measurement. Retention is listed in the privacy notice, section 10. Request logs: 30 days, Google Cloud’s standard setting.

6. Access needs and other sensitive information

Access needs could be special category data under UK GDPR (information about health or disability). Roam Pal keeps the access profile on the device and never sends it to us. Report and correction forms ask people not to include personal or health details, but a note could still contain them. Trip Check emails may describe access needs. For Trip Check health and access details, our condition is Article 9(2)(a): your explicit consent, which you give by ticking the box on the Trip Check request. You can withdraw it at any time by emailing us.

If a person shares a journey support plan or their Access Passport, it goes from their device to the recipient they choose, through their own share or copy options. For a journey support plan, the app shows a plain-text preview first, and booking references, contact details and private notes are excluded unless the person adds them.

7. Security and breaches

The website and the Hub are served only over encrypted connections (HTTPS). There are no user accounts or passwords. The Hub limits video reports to 20 a day per connection. Our approach is set out in our security overview. If a reportable breach of personal data we control ever occurred, we would assess it and, where required, report it to the ICO within 72 hours and tell anyone affected.

8. For organisations considering Roam Pal

9. Rights and complaints

People have the right to access, correct and delete their data, to restrict or object to its use, to data portability where it applies, and to withdraw consent. Most app data is on their own device, so they can view, change, back up and delete it themselves. For anything we hold, email admin@adaidigital.co.uk and we will reply within one month. Anyone can complain to the Information Commissioner’s Office (ICO) at ico.org.uk/make-a-complaint or on 0303 123 1113.

All policies · Privacy · Cookies · Security · Back to Roam Pal Guide