Your security notice lists what applied to you. It is not the same for everyone — we checked records individually rather than sending one generic warning.
This page covers Quarterdeck records. Quarterdeck Life Ltd is a separate company from Yacht Week and Ski Week and holds its own records, so if you also travelled as a guest with either of those, that is a separate notice and a separate answer.
What was copied
Depending on your record, this may have included:
Identity details given for work, travel and border requirements — passport number, date of birth, place and country of birth, nationality and sex
Contact details — name, email address, phone number, postal address, and next-of-kin where you gave one
Your account password — see Do I need to change my Quarterdeck password?, because this one needs action from you
Payment records — the amounts, dates and status of payments
A stored card reference — a token held on our side, with the card type, expiry and last four digits
For a smaller group, bank account details — account holder name, address, phone, account number, IBAN, SWIFT and routing number. If this applied to you, your notice says so, and there is separate guidance in My bank details were included — what should I do?
Password-recovery codes. All of the codes copied had already expired before the intrusion ended, so none could be used
What was not taken
Your uploaded documents. Passport copies, licences, certificates and CVs were not reachable in this incident. The reasoning is set out in Were my passport or licence documents taken?
No card security codes. We never store CVV or PIN numbers, and none were taken.
No usable card numbers. The card references held are gateway tokens and cannot be used to take a payment.
What was not compromised
The intrusion was confined to an internal reporting tool that had access to our databases. The Quarterdeck platform itself was not compromised — no unauthorised administrative access, no account takeover, and no service disruption. Nothing in your record was altered or deleted; the access was read-only throughout.
This is what was taken, not everything we hold
The categories above are what left our systems in August. They are not the same as what sits in your account today — a record can hold details that were not in the tables copied.
If you want to see what we currently hold on you, you can download it yourself in a few clicks. See How do I get a copy of my data? — and if you want us to confirm what your individual record contained at the time, the same page covers asking us in writing.
