TOURS FOR ANY AND EVERYONE
Skip to content
Call Us:   0808 169 8807

Trafalgar Privacy Policy

Last updated: August 2020

1. About this policy

This document (our “privacy policy”) sets out information into how we use personal information relating to people we interact with including, for example, customers and website users It serves as an expression of our commitment to protecting their private personal information, but is not a contract.  Please see Section 17 below for the rights which the law provides you with in relation to your personal data.

2. Your consent

3. Copyright notice

4. About us

5. Contacting us

If you have any questions about our privacy policy or about how we process your personal data, including any complaints, please contact us either by e-mail to enquiries@trafalgartours.co.uk, telephone on 0800 533 5616, or by post to Picquet House, St Peter Port, Guernsey, UK, GY1 1AF.

6. Our commitment

7. Who our privacy policy covers

7.1 Our customers
Our privacy policy sets out how we process personal data (including information) relating to individuals who are:
- booking or enquiring about booking travel services with or through us; or 
- the recipients of any travel services booked with or through us (e.g. you are the passenger for a booking or booking enquiry made by someone else for you); or 
- customers or potential customers or recipients of travel services that can be booked with or through us.
 
7.2 Examples of who this policy covers
We include in this privacy policy personal data we process relating to:
 (1) individuals who are making any enquiry or booking with us or through us, and individuals in respect of whom any enquiry or booking is made (such as friends, family members, and tour group members, and officers and employees of businesses and organisations booking with or through us); (2) individuals in respect of whom any enquiry or booking is made with us by an agent; (3) where our customer is a business or organisation, employees or individuals who are acting as representatives of that business or other organisation, and individuals connected to that business or other organisation, such as owners, partners, shareholders, and directors; (4) individuals whose personal data from other companies in our group (such as where you have consented to your personal data being disclosed to other group companies for marketing purposes).  
7.3 When we are data processor only
Please however note that this privacy policy does not apply where we are processing personal data strictly as a sub-contractor or data processor on behalf of a third party, and not on our own account.  In this case, you should look to that third party and its privacy policy, who will be answerable for how we process that personal data.
7.4 Terms used in this policy
When we refer to "you" and "your" in this privacy policy, we refer to you, any such individual whose personal data we process from time to time. 
When we refer to "processing" of your personal data, this includes obtaining, recording, storing or holding your personal data, and anything we do with it, such as organizing, adapting or altering it, retrieving, consulting or using it, disclosing it or otherwise making it available to others, combining it with other data, and blocking, erasing or destroying it.
When we refer to "travel services" this covers all products and services which may be booked with or through us, such as bespoke holidays, package holidays, accommodation, tours, transport and transfers (whether by air, coach, bus, train, ferry, taxi or other means), car hire, cruises, and charters, and it includes both (1) all such products and services which we supply or operate ourselves (including where we sub-contract); and (2) any such products and services provide by a third party which we book for you (acting as agent for you or that third party). Travel services also includes any services we or a third party provide in association with travel, such as obtaining visas, foreign exchange, and providing local representatives and support.
 
8. What types of personal data we may process

This section summarizes the types of personal data about you that we process: -

8.1 Data concerning you as an individual

We may collect the following:

- name,
- age, 
- photograph,
- gender, 
- address, 
- telephone, 
- mobile, 
- fax, 
- e-mail, 
- social networking contact details, 
- proofs of identity and address, copies of passports, driving licences, and utility bills, 
- card and other payment details, and financial information, 
- health information relevant to your planned travel and travel insurances held, 
- results of searches carried out against you (such as to verify you identity, address, and credit status), 
- your preferences, 
- frequent flyer or travel partner programme affiliation and member number; and
- any other information provided to us by or in relation to you which concern you as an individual.


8.2 Business Related Information

If you are an individual associated with a business or other organisation that is our customer, then your personal data may include the following information that we link to you: 


- business or organisation details (such as name, address, telephone numbers, payment arrangements, financial information, etc.), 
- your relationship with that business or organisation (such as owner, partner, director, shareholder, employee, or agent), and
- your contact details within that business (such as work address, work telephone and mobile numbers, work fax number, and work e-mail address).


8.3 Enquiry and Booking information

Information concerning enquiries and bookings made with or through us for travel services, including where you are making the enquiry or booking or are the recipient of the travel services to which the enquiry or booking relates. This information may include:

- records of enquiries and searches for holiday and travel products made by or on your behalf, 
- details of your personal interests, 
- needs and other data relevant to your enquiry; 
- details of results, quotes, proposals, estimates and other information given in response to enquiries; 
- details of the holiday, accommodation, travel, car hire, and other travel services booked or enquired about;
- details of the passengers / holidaymakers travelling; 
- details of the provider of the travel services (e.g. tour operator); 
- dates and times of travel; 
- price; 
- payment details (including card details); 
- passport information and visa information; 
- foreign exchange requirements and arrangements; and 
- sensitive information such as health, medical, dietary, mobility, disability, or other requirements relevant to the service you are enquiring about or your contract with us.

8.4 Performance information
Information generated concerning the performance of any booking or other contract made with or through us, including information relating to anything arising during any holiday or other travel services, and information relating to payments to be made. 


8.5 Survey Information

Information collected or generated out of any surveys we conduct.


8.6 Competition Information

Information collected or generated out of any competitions or promotions we run.


8.7 Account, Registration and Loyalty Information

Information concerning any accounts, registrations, or memberships with us, or participation in any loyalty program.


8.8 Correspondence

Correspondence, communications and messages, including between you and us, and between us and third parties, including relating to any booking or booking enquiry, or performance of any contract.


8.9 Website Usage Information

We may collect information about your visits to, browsing of, and use of our website, unless your web browser blocks this. The range of data we collect will depend on how you interact with our website. 
This information may include:  

- your IP address (a unique identifier allocated to your computer for your connection to the internet);
- your computer device details (PC, tablet, smartphone, watch etc.); 
- the make and version of web browser (e.g. Internet Explorer, Firefox, Safari, Opera, Chrome) you are using; 
- your operating system (e.g. Windows, Windows Phone, OSX, iOS, Android, Linux etc); 
- your time-zone; 
- your browser plug-ins; 
- any web-page you came from, identified as the referrer web page address by your web browser; 
- cookies; 
- page response times; 
- download error; 
- pages and parts of pages you visit; 
- usage you make of our website, including enquiries and searches undertaken, and registrations for accounts, forums etc.; 
- services and products you viewed; 
- length of visit to website and pages;
- page interaction information (such as scrolling, keys pressed, mouse clicks, touches, and mouse-overs). 

This will normally be collected and used anonymously, and aggregated for analysis, with your name and any characteristics identifying you remaining anonymous, but our privacy policy will apply, and it will be treated as your personal data, if this information is in any way linked to you personally

This information may also include: 
- data inputted into forms and fields; 
- registrations for any accounts, 
- forum, 
- feedback mechanism, 
- social functionality, 
- newsletters or other features of our site; 
- usernames and passwords, 
- log-in / out history, and settings; 
- actions taken within any account or other registration, including view and update and changes to settings; and posts to any forum, feedback, review or other social functionality on our website.

9. How we collect or generate your personal data

This section sets out the ways in which we may collect or generate personal data concerning you.
9.1 Visiting our website
By visiting and using our website you or your computer may provide personal data. This includes:  information which is automatically provided by your browser to our servers; information record on our web servers about your interaction with our website and pages viewed; information we capture or place on your computer or generate using cookies or other technologies on our website; and information you input into forms and fields on our website.  
9.2 Data you provide
Your personal data will include data you provide (or later amend), whether: 
- from correspondence with you;
- verbally to us over the phone or in person; 
- by filing in any field or form on a website; 
- by filling in any printed form we provide you with; 
- by e-mail; 
- from documents you provide use with; and 
- from updates to any information you provide to us from time to time.  
This includes when you: 
- register or subscribe for any service, account, members, or loyalty program, 
- make an enquiry or booking for a holiday or other travel services whether in person, by phone, through our website or otherwise; 
- send us your comments or suggestions; 
- subscribe to any newsletter or other publication; 
- and request sales and advertising information, including brochures. 

9.3 Data obtained from third parties
We may obtain personal data concerning you from third parties, including from: 
- providers of any holidays, accommodation, other travel services which are enquired about or booked, and their intermediaries; 
- credit, fraud, identity and other searches we may undertake, including searches with public records and regulatory and private organisations; 
- any business or organisation you are associated with; from telephone numbers identified by the telephone system when you telephone us.
9.4 Data generated by us
We and any suppliers or sub-contractors working for us may generate personal data relating to you, including:
- in connection with responding to and dealing with any enquiry, booking or complaint; or 
- in performing any booking or other contract with you; or
- through the analysis of your personal data; or 
- data gained from your use of our website. 
We may record telephone calls with you.

10. What do we use your personal data for?

This section sets out the uses which we make of your personal data and the legal basis on which we rely to do this.
10.1 Operate our website
To operate and provide the search, booking, accounts, review, forums and other services, facilities and functions of our websites.  This includes managing any accounts or registrations you have with our websites and making changes to your settings and profile at your request.
10.2 Provide information and respond to enquiries
To provide information to you about our website, systems and services, including to respond to booking enquiries and searches for holidays and travel, and to keep you updated generally.  This is done on the basis of our legitimate interests in ensuring our business is run efficiently.
10.3 Bookings and other contracts
To enable you to make bookings, and to fulfill, provide, perform, administer, manage, and enforce all bookings, orders, and other contracts which relate to you (including if you are a passenger in a booking made by someone else), and to process any transactions authorised or made with us which relate to you. This is done on the basis of our legitimate interests in ensuring our business is run efficiently.
10.4 Payments
To collect and make payments due and administer our accounts.  This is necessary for the preparation of any contract between us.
10.5 Communication with customers
To communicate with you concerning any enquiries, bookings, travel services provided, problems and complaints, and to respond to any submissions, enquiries or requests from you.  This is done on the basis of our legitimate interests in ensuring our business is run efficiently.
10.6 Record Keeping
To keep internal records and maintain reasonable archives, including concerning as to enquiries, bookings, contracts, travel services, and complaints.  This is done on the basis of our legitimate interests in ensuring our business to run efficiently.
10.7 Manage and Improve our business
To analyse, audit, provide, operate, administer, maintain and improve our business, website, systems, and services; 
- to carry out surveys and analyse the results; 
- to run promotions and competitions; 
- undertake product or customer research/development; 
- to assist us in and help us to improve our sales, 
- editorial, advertising and marketing processes; 
- to carry out other business development and improvement activities; and 
- to provide training to our staff, sub-contractors and suppliers. 
For example, we may use your personal data to help us profile how our customers generally are using our websites and booking travel services with (or through) us. We may also use this information to ascertain interests so that we can better tailor our business offerings.  This is done on the basis of our legitimate interests in ensuring our business to run efficiently.
10.8 Direct marketing
To carry out direct marketing to you, see section 12.1 for further information.
10.9 Advertising
To report aggregate information concerning usage of our websites to our advertisers. We normally create anonymous statistical data about browsing actions and patterns, and do not identify any individual.
10.10 Anything you have specifically consented to
For any purpose which we have obtained your consent to. We will do this only where you have a choice whether to consent or not, you have control over that data and you have had to take an affirmative step to give consent on an informed basis.
10.11 Consequences of Not Providing your Data
You are not obligated to provide your personal information, however, where the information is required for us to provide you with our services/deliver your products, we may not be able to offer some/all our services without it.

11. Period for retaining your data

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

12. Use of your personal data for direct marketing

We do not use or disclose your personal data for direct marketing purposes unless:
- we have obtained your consent to this, such as through an opt-in  box on any form or website of ours; and/or
- you have made a booking with us and there is a legitimate interest to do is. 

In addition to data protection law if we use your personal information for direct marketing purposes we may also be subject to additional rules that regulate direct marketing.  The term “direct marketing” essentially means direct marketing material or advertising at a particular individual.
12.1 Direct marketing by us
We will use your personal data to send you marketing information (including adverts and details of promotions) about travel services:

(a) offered by us; 
(b) which can be booked with third parties through us;
(c) which can be booked with other companies within our group (i.e. the Travel Corporation Group); and
(d) offered by third parties selected by us. 

Where applicable we will only send you marketing information about the categories of travel services you have selected. Also, we will only contact you in the manner you agreed to (e.g. by email).  

12.2 Direct Marketing by Third Parties
From time to time we may disclose your contact details (i.e. your name, email address, postal address, telephone number, mobile number, fax number and preferences) to:
(a) other companies within our The Travel Corporation; and
(b) other companies which offer services that may enhance your travel experience or be able to help you to finalise your travel arrangements (“third parties”). Such third parties may then contact you directly with marketing information about services and products offered by them, third parties will only contact you in the manner you agreed to (e.g. email, text) when providing your consent.  

12.3 Withdrawing from Direct Marketing 
You are free to stop receiving marketing information from us at any time by contacting us as detailed in this privacy notice or by following the instructions set out in our marketing communications. If you email us to withdraw your consent, it would be helpful if you could insert the word “Unsubscribe” as the subject heading.” 
When you elect to stop receiving marketing information we will, from that point onwards, not share you information further with any other third parties. 
You are also free, at any time, to notify any third party to whom we have previously passed your contact details to, that you no longer wish to receive marketing communications from them.

13. Disclosure of your personal data 

We transfer your personal data to third parties in the following circumstances:
13.1 Credit Checks etc.
We may disclose your personal data to third parties (including intermediaries) as necessary to carry out any checks regarding your financial standing. The identities of these parties may change from time to time. They may include credit reference agencies and other companies for use in credit decisions, for fraud prevention and to pursue debtors.
13.2 Bookings and performance of contracts 
We disclose your personal data to third parties (including intermediaries) as necessary to deal with any booking enquiry being made by or for you, to make any booking requested by or for you, to perform and administer any booking for you or other contract with or in respect of you.  This may include; 
- to apply for visas on your behalf, 
- to collect payments to be made by you, 
- to investigate and respond to complaints, and 
- to enforce any booking or other contract with you.
Such third parties may include any suppliers or sub-contractors and their agents (e.g. airlines, coach, ferry or train companies, hoteliers, hire companies, cruise companies, tour operators etc.). The identities of these parties may change from time to time and are engaged so we can provide our services to you.
13.3 Suppliers of travel and other services
We may disclose your personal data to any third party (e.g. supplier, contractor sub-contractor) we make any enquiries with concerning or engage or sub-contract to perform any booking or other contract, including to provide any travel, tour or other products or services we have agreed to provide to you in order to perform our contract with you. 
We may disclose your personal data to any supplier with whom we make any enquiry concerning or book any travel or other products and services for you as agent (whether as agent for you, someone representing you, or the supplier), such as a tour operator.  Details of any third party tour operators or other third parties who will be responsible for or supply you with the travel services booked or enquired about, may be obtained from us on request, and may be stated in any tour or other brochure provided by us. 
13.4 Insurance
If any application is made through us for any travel or other insurance to cover you, we will pass your personal data on to the insurer.  Information provided by you may be put on to a register of claims and shared with other insurers to prevent fraudulent claims. 
13.5 Business Function Outsourcing
Where we use third parties to host, provide, operate or supply any part of our websites, databases, systems, business, or services, or carry out on our behalf any of our business functions or actions (including sending mail, processing payments, providing marketing assistance, providing customer and advertising analysis, and providing customer services), then then we may provide your personal data to them as required for use for or processing as part of those purposes. 
13.6 Public forums etc.
Where any facility on our website is clearly designed to make certain of your personal data public (e.g. posts you make to any public forum or reviews facility) then any personal data you provide in relation to that forum or other facility, which is provided in circumstance where it is clear that it is intended to be published, will be disclosed to the public accordingly, subject to moderation by us and to the terms of this privacy policy.
13.7 Legal requirements
We may supply personal data to a government authority or regulator where required to:
- comply with a legal requirement, 
- for the administration of justice, 
- for the purposes of customs, visas and immigration, or 
- where reasonably required to protect your vital interests or 
- enforce any booking or other contract.  
We may disclose your personal data where otherwise required by or permitted by law. 
  
13.8 Direct Marketing by third parties
We may disclose your personal data to third parties to carry out direct marketing to you, where you have given your prior consent, to third parties to carry out direct marketing.  See the direct marketing section above.
13.9 Business Customers who are businesses (not individuals)
If you are a business or organisation (“Business Customer”), and we are holding personal data of any authorised representative (such as an employee agent, employee, officer, owner, partner, or director), then we may disclose to them that personal data.   
If a Business Customer is making a booking or booking enquiry on behalf of an individual, with that person’s authority, then we may disclose to our Business Customer that individual’s personal data as reasonably required in connection with such booking or enquiry, or the subsequent performance of or payment for any booking made.
13.10 Business acquirers
If our business is ever transferred to a third party, then your personal data will be transferred to the acquirer to enable them to continue our business.

14. How third parties will handle your personal data

Where we provide your personal data to a third party one of the following two circumstances will apply:
14.1 Processing on our behalf
In some cases, your personal data may be held and otherwise processed by others on our behalf.  We have not included the names of our service partners as these will change over time. We will remain responsible for what they do with your personal data, and your personal data will only be held and processed by them in accordance with our instructions and this privacy policy.  The sharing of your data is necessary for the performance of any contract with you and for the efficient provision of our services.
14.2 Processing on their own account
In other cases, your personal data may need to be provided to them to be held and processed by them in their own right and on their own account.  In such case, they will have their own responsibility for your personal data, subject to their own privacy policy, and we will not be responsible for what they do with it following disclosure. This will only be done to perform the contract

15. Location of your personal data

We (and any affiliate, subcontractor or other person processing your personal data on our behalf) may transfer, store and otherwise process your personal data anywhere within the European Economic Area (“EEA”).  

We will only send your personal data outside the EEA to companies either within our group or to parties with whom we have a contract.  We ensure your personal data is protected by requiring all our group companies to follow the same rules when processing your personal data. This means within our group and for those other organisations with whom we have contracts we ensure that we have in place adequate safeguards in respect of such transfers outside the EEA. You can find out about what adequate safeguards these are by contacting us using the details provided in section 2 of this privacy notice.

16. Keeping your data secure

16.1 Our security measures

We take appropriate technical and organizational measures to secure your information and to protect it against unauthorized or unlawful use and accidental loss or destruction, including:

• only sharing and providing access to your information to the minimum extent necessary, subject to confidentiality restrictions where appropriate, and on an anonymized basis wherever possible;
• using secure servers to store your information;
• verifying the identity of any individual who requests access to information prior to granting them access to information
• using Secure Sockets Layer (SSL) and Transport Layer Security (TLS) software or other similar encryption technologies to encrypt your personal and payment transactions

Transmission of information over email is not secure, and if you submit any information to us over the internet by email you do so entirely at your own risk. We cannot be responsible for any costs, expenses, loss of profits, harm to reputation, damages, liabilities or any other form of loss or damage suffered by you as a result of your decision to transmit information to us by email.

16.2 Your security measures

For your own privacy protection, we encourage you to maintain anti-virus and other malware protection software on your computers and other devices, and to maintain your own measures to protect your personal data. Please do not include sensitive personal data in any e-mails you may send to us, including payment card information. 

We also encourage you to be careful about who you give personal data to. We never contact you to ask you for sensitive personal data, such as payment card information, or sensitive personal data such as passport numbers or log-in details, and we will only ask you for such information in person or through our website, or by telephone in connection with a booking you are making or have made.  Please let us know if you someone purports to contact you in our name.

17. Your Rights

Our privacy policy is not intended to create a contract or form part of any contract. You have certain non-contractual rights under the laws noted above, which we summarize below. If you contact us about these rights, we may ask for proof of your identity before we act, and may refuse to act if you do not provide this or your identity is not established by you. This is to ensure that your data is protected and kept secure.  More information about your rights and our obligations can be found on www.ico.gov.uk
17.1 Access to your personal data
You may request us to tell you whether we are processing personal data about you, to tell you what personal data we are processing and for what purposes, and to provide you with a copy of your personal data that we hold. 
The law does allow us, in certain cases to refuse your request, and we will advise you at the time if this is the case. 
17.2 Rectification
You have the right to have your personal data amended if it is inaccurate or incomplete.
17.3 A right to object
You have the right to object to the use of your personal information for direct marketing or where we use it on the basis that we say we have a legitimate interest in using it.
17.4 Deletion of Data inaccuracies
You have the right to have your personal information deleted or removed in certain circumstances and we may have the right in some cases to refuse to do so.
17.5 Portability
 You have the right to obtain and re-use your personal information for your own use in certain circumstances.
17.6 Restrict Processing
You may prevent or suppress the processing of your personal information in certain circumstances.
17.7 Complaints to applicable authority

The laws we comply with are regulated by the Information Commissioner (www.ico.gov.uk) in the United Kingdom.  In addition to your rights above, it is open to you, if you have a complaint or concern, to seek assistance from this supervisory authority who has powers to compel us to comply with applicable laws and fine us for non-compliance.  However, before you do so, we would hope that you will contact us first to discuss any complaint or concerns you have.  You can contact us using the details provided in section 2 of this our privacy notice. 

17.8 Right to withdraw your consent

You are free to withdraw your consent at any time. Please contact using the details outlined in Section 5 of this policy. See also section 12.3 for details as to how to unsubscribe from our mailing lists. 

18. EU-US and Swiss-US Privacy Shield

The Travel Corporation Inc. (TTC) including all its entities and Subsidiaries in the US complies with the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union and Switzerland to the United States.
The Travel Corporation (TTC), has certified to the Department of Commerce that it adheres to the Privacy Shield Principles, namely Notice, Data Integrity and Purpose Limitation, Choice, Security, Access, Recourse, Enforcement and Liability and Accountability for Onward Transfer Principles. If there is any conflict between the terms in this Privacy Policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern.
To learn more about the Privacy Shield program, and to view our certification, please visit https://www.privacyshield.gov/ and https://ttc.com/privacy-shield-statement/. Under Privacy Shield Frameworks, we are subject to the authority of the U.S. Federal Trade Commission.
If you have any questions or concerns relating to our use and disclosure of your personal information in accordance to the Privacy Shield Principles, contact compliance@ttc.com. We will respond to a complaint or inquiry within 45 days of receipt.
We commit to cooperate with the EU data protection authorities or the Swiss Federal Data Protection and Information Commissioner (‘DPAs’), as applicable, and comply with their advice with regards to personal information transfers from the EU or Switzerland. If you believe that your questions or concerns were not addressed by us to your satisfaction, you may also contact the DPA of your place of residence. The dispute resolution by DPAs will be provided at no cost to you.
In certain circumstances, you may also have the right to pursue binding arbitration through the Privacy Shield Framework, as described in Annex I to the Privacy Shield Principles.
If we have received your personal information under the Privacy Shield and subsequently transfer it to a third-party service provider for processing as described in this Privacy Policy, we will remain responsible if they process your personal information inconsistently with the Privacy Shield Principles, except where we can establish that we are not responsible for the violation.
Visit our USA Privacy Policy here.

19. Changes to this privacy policy

20. Applicable Law And Disputes

Our privacy policy is subject to the law of England and Wales and disputes can be determined by the courts of England and Wales.

Contiki Privacy Policy

LEGAL STUFF
CONTIKI HOLIDAYS LIMITED
Privacy and Cookie Policy
Last updated: August 2020


1. About this policy
This document (our “privacy policy”) sets out information into how we use personal information relating to people we interact with including, for example, customers and website users It serves as an expression of our commitment to protecting their private personal information, but is not a contract. Please see Section 17 below for the rights which the law provides you with in relation to your personal data.

2. Your consent
We will only use and retain your personal data with your consent or other lawful basis. We ask for your consent on those occasions and in those places where we specify what we will use your personal data for.

3. Copyright notice
This document, and all content of our websites is Copyright© 2018 Contiki Holidays Limited. ALL RIGHTS RESERVED.

4. About us
This is the privacy policy of Contiki Holidays Limited (referred to as "we", "us" or "our"). We are incorporated under the laws of England and Wales. Our incorporation number is 50681 and our incorporation address or registered office is Travel House, St. Peter Port, Guernsey, GY1 2JH, Channel Islands. We are a member of ABTA (Y1792) and licensed by the Civil Aviation Authority (10144).

5. Contacting us
If you have any questions about our privacy policy or about how we process your personal data, including any complaints, please contact us either by e-mail to webmaster@contiki.com, telephone on 0845 075 0990, or by post to Travel House, St. Peter Port, Guernsey, GY1 2JH, Channel Islands.

6. Our commitment
We respect your right to privacy and we aim to ensure you have a trustworthy experience with us, including when using our websites or shops and booking with or through us. We understand that you care about how your personal data is used by us, and we want to share with you the policies and practices we’ve adopted. This way you can feel confident about how we handle your personal data.

7. Who our privacy policy covers

7.1 Our customers
Our privacy policy sets out how we process personal data (including information) relating to individuals who are:
- booking or enquiring about booking travel services with or through us; or
- the recipients of any travel services booked with or through us (e.g. you are the passenger for a booking or booking enquiry made by someone else for you); or
- customers or potential customers or recipients of travel services that can be booked with or through us.

7.2 Examples of who this policy covers
We include in this privacy policy personal data we process relating to:

(1) individuals who are making any enquiry or booking with us or through us, and individuals in respect of whom any enquiry or booking is made (such as friends, family members, and tour group members, and officers and employees of businesses and organisations booking with or through us);
(2) individuals in respect of whom any enquiry or booking is made with us by an agent;
(3) where our customer is a business or organisation, employees or individuals who are acting as representatives of that business or other organisation, and individuals connected to that business or other organisation, such as owners, partners, shareholders, and directors;
(4) individuals whose personal data from other companies in our group (such as where you have consented to your personal data being disclosed to other group companies for marketing purposes).

7.3 When we are data processor only
Please however note that this privacy policy does not apply where we are processing personal data strictly as a sub-contractor or data processor on behalf of a third party, and not on our own account. In this case, you should look to that third party and its privacy policy, who will be answerable for how we process that personal data.

7.4 Terms used in this policy
When we refer to "you" and "your" in this privacy policy, we refer to you, any such individual whose personal data we process from time to time.
When we refer to "processing" of your personal data, this includes obtaining, recording, storing or holding your personal data, and anything we do with it, such as organizing, adapting or altering it, retrieving, consulting or using it, disclosing it or otherwise making it available to others, combining it with other data, and blocking, erasing or destroying it.
When we refer to "travel services" this covers all products and services which may be booked with or through us, such as bespoke holidays, package holidays, accommodation, tours, transport and transfers (whether by air, coach, bus, train, ferry, taxi or other means), car hire, cruises, and charters, and it includes both

(1) all such products and services which we supply or operate ourselves (including where we sub-contract); and
(2) any such products and services provide by a third party which we book for you (acting as agent for you or that third party). Travel services also includes any services we or a third party provide in association with travel, such as obtaining visas, foreign exchange, and providing local representatives and support.

8. What types of personal data we may process
This section summarizes the types of personal data about you that we process: -

8.1 Data concerning you as an individual
We may collect the following:
- name,
- age,
- photograph,
- gender,
- address,
- telephone,
- mobile,
- fax,
- e-mail,
- social networking contact details,
- proofs of identity and address, copies of passports, driving licences, and utility bills,
- card and other payment details, and financial information,
- health information relevant to your planned travel and travel insurances held,
- results of searches carried out against you (such as to verify you identity, address, and credit status),
- your preferences,
- frequent flyer or travel partner programme affiliation and member number; and
- any other information provided to us by or in relation to you which concern you as an individual.

8.2 Business Related Information
If you are an individual associated with a business or other organisation that is our customer, then your personal data may include the following information that we link to you:

- business or organisation details (such as name, address, telephone numbers, payment arrangements, financial information, etc.),
- your relationship with that business or organisation (such as owner, partner, director, shareholder, employee, or agent), and
- your contact details within that business (such as work address, work telephone and mobile numbers, work fax number, and work e-mail address).

8.3 Enquiry and Booking information
Information concerning enquiries and bookings made with or through us for travel services, including where you are making the enquiry or booking or are the recipient of the travel services to which the enquiry or booking relates. This information may include:

- records of enquiries and searches for holiday and travel products made by or on your behalf,
- details of your personal interests,
- needs and other data relevant to your enquiry;
- details of results, quotes, proposals, estimates and other information given in response to enquiries;
- details of the holiday, accommodation, travel, car hire, and other travel services booked or enquired about;
- details of the passengers / holidaymakers travelling;
- details of the provider of the travel services (e.g. tour operator);
- dates and times of travel;
- price;
- payment details (including card details);
- passport information and visa information;
- foreign exchange requirements and arrangements; and
- sensitive information such as health, medical, dietary, mobility, disability, or other requirements relevant to the service you are enquiring about or your contract with us.

8.4 Performance information
Information generated concerning the performance of any booking or other contract made with or through us, including information relating to anything arising during any holiday or other travel services, and information relating to payments to be made.

8.5 Survey Information
Information collected or generated out of any surveys we conduct.

8.6 Competition Information
Information collected or generated out of any competitions or promotions we run.

8.7 Account, Registration and Loyalty Information
Information concerning any accounts, registrations, or memberships with us, or participation in any loyalty program.

8.8 Correspondence
Correspondence, communications and messages, including between you and us, and between us and third parties, including relating to any booking or booking enquiry, or performance of any contract.


8.9 Website Usage Information
We may collect information about your visits to, browsing of, and use of our website, unless your web browser blocks this. The range of data we collect will depend on how you interact with our website.
This information may include:
- your IP address (a unique identifier allocated to your computer for your connection to the internet);
- your computer device details (PC, tablet, smartphone, watch etc.);
- the make and version of web browser (e.g. Internet Explorer, Firefox, Safari, Opera, Chrome) you are using;
- your operating system (e.g. Windows, Windows Phone, OSX, iOS, Android, Linux etc);
- your time-zone;
- your browser plug-ins;
- any web-page you came from, identified as the referrer web page address by your web browser;
- cookies;
- page response times;
- download error;
- pages and parts of pages you visit;
- usage you make of our website, including enquiries and searches undertaken, and registrations for accounts, forums etc.;
- services and products you viewed;
- length of visit to website and pages;
- page interaction information (such as scrolling, keys pressed, mouse clicks, touches, and mouse-overs).

This will normally be collected and used anonymously, and aggregated for analysis, with your name and any characteristics identifying you remaining anonymous, but our privacy policy will apply, and it will be treated as your personal data, if this information is in any way linked to you personally
This information may also include:

- data inputted into forms and fields;
- registrations for any accounts,
- forum,
- feedback mechanism,
- social functionality,
- newsletters or other features of our site;
- usernames and passwords,
- log-in / out history, and settings;
- actions taken within any account or other registration, including view and update and changes to settings; and posts to any forum, feedback, review or other social functionality on our website.

8.10 Cookie Notice

What are Cookies?
A ‘cookie’ is a small piece of data sent from a website and stored on the user’s computer by the user’s web browser while the user is browsing. When you visit a site that uses cookies for the first time, a cookie is downloaded onto your computer/mobile device so that the next time you visit that site, your device will remember useful information such as items added in the shopping cart, visited pages or logging in options. Cookies are widely used in order to make websites work, or to work more efficiently, and our site relies on cookies to optimize user experience and for features and services to function properly.

What Cookies do we use?
There are different types of cookies. They all work in the same way, but have minor differences and we may use the following:

Session cookies
Session cookies last only for the duration of your visit and are deleted when you close your browser. These facilitate various tasks such as allowing a website to identify that a user of a particular device is navigating from page to page, supporting website security or basic functionality.

Persistent cookies
Persistent cookies last after you have closed your browser, and allow a website to remember your actions and preferences. Sometimes persistent cookies are used by websites to provide targeted advertising based upon the browsing history of the device.
We use persistent cookies to allow us to analyse customer visits to our site. These cookies help us to understand how customers arrive at and use our site so we can improve the overall service.

Strictly necessary cookies
These cookies are essential in order to enable you to move around the website and use its features, and ensuring the security of your experience. Without these cookies services you have asked for, such as applying for products and managing your accounts, cannot be provided. These cookies don’t gather information about you for the purposes of marketing.

Performance cookies
These cookies collect information about how visitors use a web site, for instance which pages visitors go to most often, and if they get error messages from web pages. All information these cookies collect is only used to improve how a website works, the user experience and to optimise our advertising. By using our websites you agree that we can place these types of cookies on your device, however you can block these cookies using your browser settings.

Functionality cookies
These cookies allow the website to remember choices you make (such as your username). The information these cookies collect is anonymized (i.e. it does not contain your name, address etc.) and they do not track your browsing activity across other websites. By using our websites you agree that we can place these types of cookies on your device, however you can block these cookies using your browser settings.

Targeting cookies
These cookies collect several pieces of information about your browsing habits. [They are usually placed by third party advertising networks]. They remember that you have visited a website and this information is shared with other organisations such as media publishers. These organisations do this in order to provide you with targeted adverts
more relevant to you and your interests.

Third party cookies
Please note that third parties (including, for example, advertising networks and providers of external services like web traffic analysis services) may also use cookies, over which we have no control. These cookies are likely to be analytical/performance cookies or targeting cookies.

8.11 How can I exercise choice regarding cookies and other types of online tracking?
Most web browsers allow some control to restrict or block cookies through the browser settings, however if you disable cookies you may find this affects your ability to use certain parts of our website or services.

For more information about cookies visit https://www.aboutcookies.org.

9. How we collect or generate your personal data
This section sets out the ways in which we may collect or generate personal data concerning you.

9.1 Visiting our website
By visiting and using our website you or your computer may provide personal data. This includes: information which is automatically provided by your browser to our servers; information record on our web servers about your interaction with our website and pages viewed; information we capture or place on your computer or generate using cookies or other technologies on our website; and information you input into forms and fields on our website.

9.2 Data you provide
Your personal data will include data you provide (or later amend), whether:
- from correspondence with you;
- verbally to us over the phone or in person;
- by filing in any field or form on a website;
- by filling in any printed form we provide you with;
- by e-mail;
- from documents you provide use with; and
- from updates to any information you provide to us from time to time.
This includes when you:
- register or subscribe for any service, account, members, or loyalty program,
- make an enquiry or booking for a holiday or other travel services whether in person, by phone, through our website or otherwise;
- send us your comments or suggestions;
- subscribe to any newsletter or other publication;
- and request sales and advertising information, including brochures.

9.3 Data obtained from third parties
We may obtain personal data concerning you from third parties, including from:
- providers of any holidays, accommodation, other travel services which are enquired about or booked, and their intermediaries;
- credit, fraud, identity and other searches we may undertake, including searches with public records and regulatory and private organisations;
- any business or organisation you are associated with; from telephone numbers identified by the telephone system when you telephone us.

9.4 Data generated by us
We and any suppliers or sub-contractors working for us may generate personal data relating to you, including:
- in connection with responding to and dealing with any enquiry, booking or complaint; or
- in performing any booking or other contract with you; or
- through the analysis of your personal data; or
- data gained from your use of our website.
We may record telephone calls with you.

10. What do we use your personal data for?
This section sets out the uses which we make of your personal data and the legal basis on which we rely to do this.

10.1 Operate our website
To operate and provide the search, booking, accounts, review, forums and other services, facilities and functions of our websites. This includes managing any accounts or registrations you have with our websites and making changes to your settings and profile at your request.

10.2 Provide information and respond to enquiries
To provide information to you about our website, systems and services, including to respond to booking enquiries and searches for holidays and travel, and to keep you updated generally. This is done on the basis of our legitimate interests in ensuring our business is run efficiently.

10.3 Bookings and other contracts
To enable you to make bookings, and to fulfill, provide, perform, administer, manage, and enforce all bookings, orders, and other contracts which relate to you (including if you are a passenger in a booking made by someone else), and to process any transactions authorised or made with us which relate to you. This is done on the basis of our legitimate interests in ensuring our business is run efficiently.

10.4 Payments
To collect and make payments due and administer our accounts. This is necessary for the preparation of any contract between us.

10.5 Communication with customers
To communicate with you concerning any enquiries, bookings, travel services provided, problems and complaints, and to respond to any submissions, enquiries or requests from you. This is done on the basis of our legitimate interests in ensuring our business is run efficiently.

10.6 Record Keeping
To keep internal records and maintain reasonable archives, including concerning as to enquiries, bookings, contracts, travel services, and complaints. This is done on the basis of our legitimate interests in ensuring our business to run efficiently.

10.7 Manage and Improve our business
To analyse, audit, provide, operate, administer, maintain and improve our business, website, systems, and services;

- to carry out surveys and analyse the results;
- to run promotions and competitions;
- undertake product or customer research/development;
- to assist us in and help us to improve our sales,
- editorial, advertising and marketing processes;
- to carry out other business development and improvement activities; and
- to provide training to our staff, sub-contractors and suppliers.
For example, we may use your personal data to help us profile how our customers generally are using our websites and booking travel services with (or through) us. We may also use this information to ascertain interests so that we can better tailor our business offerings. This is done on the basis of our legitimate interests in ensuring our business to run efficiently.

10.8 Direct marketing
To carry out direct marketing to you, see section 12.1 for further information.

10.9 Advertising
To report aggregate information concerning usage of our websites to our advertisers. We normally create anonymous statistical data about browsing actions and patterns, and do not identify any individual.

10.10 Anything you have specifically consented to
For any purpose which we have obtained your consent to. We will do this only where you have a choice whether to consent or not, you have control over that data and you have had to take an affirmative step to give consent on an informed basis.

10.11 Consequences of Not Providing your Data
You are not obligated to provide your personal information, however, where the information is required for us to provide you with our services/deliver your products, we may not be able to offer some/all our services without it.

11.Period for retaining your data
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

12. Use of your personal data for direct marketing
We do not use or disclose your personal data for direct marketing purposes unless:
- we have obtained your consent to this, such as through an opt-in box on any form or website of ours; and/or
- you have made a booking with us and there is a legitimate interest to do is.

In addition to data protection law if we use your personal information for direct marketing purposes we may also be subject to additional rules that regulate direct marketing. The term “direct marketing” essentially means direct marketing material or advertising at a particular individual.

12.1 Direct marketing by us
We will use your personal data to send you marketing information (including adverts and details of promotions) about travel services:

(a) offered by us;
(b) which can be booked with third parties through us;
(c) which can be booked with other companies within our group (i.e. the Travel Corporation Group); and
(d) offered by third parties selected by us.

Where applicable we will only send you marketing information about the categories of travel services you have selected. Also, we will only contact you in the manner you agreed to (e.g. by email).

12.2 Direct Marketing by Third Parties
From time to time we may disclose your contact details (i.e. your name, email address, postal address, telephone number, mobile number, fax number and preferences) to:
(a) other companies within our The Travel Corporation; and
(b) other companies which offer services that may enhance your travel experience or be able to help you to finalise your travel arrangements (“third parties”). Such third parties may then contact you directly with marketing information about services and products offered by them, third parties will only contact you in the manner you agreed to (e.g. email, text) when providing your consent.

12.3 Withdrawing from Direct Marketing
You are free to stop receiving marketing information from us at any time by contacting us as detailed in this privacy notice or by following the instructions set out in our marketing communications. If you email us to withdraw your consent, it would be helpful if you could insert the word “Unsubscribe” as the subject heading.”
When you elect to stop receiving marketing information we will, from that point onwards, not share you information further with any other third parties.
You are also free, at any time, to notify any third party to whom we have previously passed your contact details to, that you no longer wish to receive marketing communications from them.

13. Disclosure of your personal data
We transfer your personal data to third parties in the following circumstances: -

13.1 Credit Checks etc.
We may disclose your personal data to third parties (including intermediaries) as necessary to carry out any checks regarding your financial standing. The identities of these parties may change from time to time. They may include credit reference agencies and other companies for use in credit decisions, for fraud prevention and to pursue debtors.

13.2 Bookings and performance of contracts
We disclose your personal data to third parties (including intermediaries) as necessary to deal with any booking enquiry being made by or for you, to make any booking requested by or for you, to perform and administer any booking for you or other contract with or in respect of you. This may include;
- to apply for visas on your behalf,
- to collect payments to be made by you,
- to investigate and respond to complaints, and
- to enforce any booking or other contract with you.
Such third parties may include any suppliers or sub-contractors and their agents (e.g. airlines, coach, ferry or train companies, hoteliers, hire companies, cruise companies, tour operators etc.). The identities of these parties may change from time to time and are engaged so we can provide our services to you.

13.3 Suppliers of travel and other services
We may disclose your personal data to any third party (e.g. supplier, contractor sub-contractor) we make any enquiries with concerning or engage or sub-contract to perform any booking or other contract, including to provide any travel, tour or other products or services we have agreed to provide to you in order to perform our contract with you.
We may disclose your personal data to any supplier with whom we make any enquiry concerning or book any travel or other products and services for you as agent (whether as agent for you, someone representing you, or the supplier), such as a tour operator. Details of any third party tour operators or other third parties who will be responsible for or supply you with the travel services booked or enquired about, may be obtained from us on request, and may be stated in any tour or other brochure provided by us.

13.4 Insurance
If any application is made through us for any travel or other insurance to cover you, we will pass your personal data on to the insurer. Information provided by you may be put on to a register of claims and shared with other insurers to prevent fraudulent claims.

13.5 Business Function Outsourcing
Where we use third parties to host, provide, operate or supply any part of our websites, databases, systems, business, or services, or carry out on our behalf any of our business functions or actions (including sending mail, processing payments, providing marketing assistance, providing customer and advertising analysis, and providing customer services), then then we may provide your personal data to them as required for use for or processing as part of those purposes.

13.6 Public forums etc.
Where any facility on our website is clearly designed to make certain of your personal data public (e.g. posts you make to any public forum or reviews facility) then any personal data you provide in relation to that forum or other facility, which is provided in circumstance where it is clear that it is intended to be published, will be disclosed to the public accordingly, subject to moderation by us and to the terms of this privacy policy.

13.7 Legal requirements
We may supply personal data to a government authority or regulator where required to:
- comply with a legal requirement,
- for the administration of justice,
- for the purposes of customs, visas and immigration, or
- where reasonably required to protect your vital interests or
- enforce any booking or other contract.
We may disclose your personal data where otherwise required by or permitted by law.

13.8 Direct Marketing by third parties
We may disclose your personal data to third parties to carry out direct marketing to you, where you have given your prior consent, to third parties to carry out direct marketing. See the direct marketing section above.

13.9 Business Customers who are businesses (not individuals)
If you are a business or organisation (“Business Customer”), and we are holding personal data of any authorised representative (such as an employee agent, employee, officer, owner, partner, or director), then we may disclose to them that personal data.
If a Business Customer is making a booking or booking enquiry on behalf of an individual, with that person’s authority, then we may disclose to our Business Customer that individual’s personal data as reasonably required in connection with such booking or enquiry, or the subsequent performance of or payment for any booking made.

13.10 Business acquirers
If our business is ever transferred to a third party, then your personal data will be transferred to the acquirer to enable them to continue our business.


14. How third parties will handle your personal data
Where we provide your personal data to a third party one of the following two circumstances will apply: -

14.1 Processing on our behalf
In some cases, your personal data may be held and otherwise processed by others on our behalf. We have not included the names of our service partners as these will change over time. We will remain responsible for what they do with your personal data, and your personal data will only be held and processed by them in accordance with our instructions and this privacy policy. The sharing of your data is necessary for the performance of any contract with you and for the efficient provision of our services.

14.2 Processing on their own account
In other cases, your personal data may need to be provided to them to be held and processed by them in their own right and on their own account. In such case, they will have their own responsibility for your personal data, subject to their own privacy policy, and we will not be responsible for what they do with it following disclosure. This will only be done to perform the contract

15. Location of your personal data
We (and any affiliate, subcontractor or other person processing your personal data on our behalf) may transfer, store and otherwise process your personal data anywhere within the European Economic Area (“EEA”).


We will only send your personal data outside the EEA to companies either within our group or to parties with whom we have a contract. We ensure your personal data is protected by requiring all our group companies to follow the same rules when processing your personal data. This means within our group and for those other organisations with whom we have contracts we ensure that we have in place adequate safeguards in respect of such transfers outside the EEA. You can find out about what adequate safeguards these are by contacting us using the details provided in section 2 of this privacy notice.

16. Keeping your data secure


16.1 Our security measures
We take appropriate technical and organizational measures to secure your information and to protect it against unauthorized or unlawful use and accidental loss or destruction, including:

• only sharing and providing access to your information to the minimum extent necessary, subject to confidentiality restrictions where appropriate, and on an anonymized basis wherever possible;
• using secure servers to store your information;
• verifying the identity of any individual who requests access to information prior to granting them access to information
• using Secure Sockets Layer (SSL) and Transport Layer Security (TLS) software or other similar encryption technologies to encrypt your personal and payment transactions

Transmission of information over email is not secure, and if you submit any information to us over the internet by email you do so entirely at your own risk. We cannot be responsible for any costs, expenses, loss of profits, harm to reputation, damages, liabilities or any other form of loss or damage suffered by you as a result of your decision to transmit information to us by email.

16.2 Your security measures
For your own privacy protection, we encourage you to maintain anti-virus and other malware protection software on your computers and other devices, and to maintain your own measures to protect your personal data. Please do not include sensitive personal data in any e-mails you may send to us, including payment card information.
We also encourage you to be careful about who you give personal data to. We never contact you to ask you for sensitive personal data, such as payment card information, or sensitive personal data such as passport numbers or log-in details, and we will only ask you for such information in person or through our website, or by telephone in connection with a booking you are making or have made. Please let us know if you someone purports to contact you in our name.

17. Your Rights
Our privacy policy is not intended to create a contract or form part of any contract. You have certain non-contractual rights under the laws noted above, which we summarize below. If you contact us about these rights, we may ask for proof of your identity before we act, and may refuse to act if you do not provide this or your identity is not established by you. This is to ensure that your data is protected and kept secure. More information about your rights and our obligations can be found on https://ico.org.uk.

17.1 Access to your personal data
You may request us to tell you whether we are processing personal data about you, to tell you what personal data we are processing and for what purposes, and to provide you with a copy of your personal data that we hold.
The law does allow us, in certain cases to refuse your request, and we will advise you at the time if this is the case.

17.2 Rectification
You have the right to have your personal data amended if it is inaccurate or incomplete.

17.3 A right to object
You have the right to object to the use of your personal information for direct marketing or where we use it on the basis that we say we have a legitimate interest in using it.

17.4 Deletion of Data inaccuracies
You have the right to have your personal information deleted or removed in certain circumstances and we may have the right in some cases to refuse to do so.

17.5 Portability
You have the right to obtain and re-use your personal information for your own use in certain circumstances.

17.6 Restrict Processing
You may prevent or suppress the processing of your personal information in certain circumstances.

17.7 Complaints to applicable authority
The laws we comply with are regulated by the Information Commissioner (www.ico.org.uk) in the United Kingdom. In addition to your rights above, it is open to you, if you have a complaint or concern, to seek assistance from this supervisory authority who has powers to compel us to comply with applicable laws and fine us for non-compliance. However, before you do so, we would hope that you will contact us first to discuss any complaint or concerns you have. You can contact us using the details provided in section 2 of this our privacy notice.

17.8 Right to withdraw your consent
You are free to withdraw your consent at any time. Please contact using the details outlined in Section 5 of this policy.
See also section 12.3 for details as to how to unsubscribe from our mailing lists.

18. EU-US and Swiss-US Privacy Shield

The Travel Corporation Inc. (TTC) including all its entities and Subsidiaries in the US complies with the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union and Switzerland to the United States.
The Travel Corporation (TTC), has certified to the Department of Commerce that it adheres to the Privacy Shield Principles, namely Notice, Data Integrity and Purpose Limitation, Choice, Security, Access, Recourse, Enforcement and Liability and Accountability for Onward Transfer Principles. If there is any conflict between the terms in this Privacy Policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern.
To learn more about the Privacy Shield program, and to view our certification, please visit https://www.privacyshield.gov/ and https://ttc.com/privacy-shield-statement/. Under Privacy Shield Frameworks, we are subject to the authority of the U.S. Federal Trade Commission.
If you have any questions or concerns relating to our use and disclosure of your personal information in accordance to the Privacy Shield Principles, contact compliance@ttc.com. We will respond to a complaint or inquiry within 45 days of receipt.
We commit to cooperate with the EU data protection authorities or the Swiss Federal Data Protection and Information Commissioner (‘DPAs’), as applicable, and comply with their advice with regards to personal information transfers from the EU or Switzerland. If you believe that your questions or concerns were not addressed by us to your satisfaction, you may also contact the DPA of your place of residence. The dispute resolution by DPAs will be provided at no cost to you.
In certain circumstances, you may also have the right to pursue binding arbitration through the Privacy Shield Framework, as described in Annex I to the Privacy Shield Principles.
If we have received your personal information under the Privacy Shield and subsequently transfer it to a third-party service provider for processing as described in this Privacy Policy, we will remain responsible if they process your personal information inconsistently with the Privacy Shield Principles, except where we can establish that we are not responsible for the violation.
Visit our USA Privacy Policy here.

19. Changes to this privacy policy
We may change this privacy policy at any time and from time to time without notice to you, including by publishing a new version on our website. You should check this privacy policy for updates each time you visit our website to be sure that you are aware of any changes. You should check the top of the document to see the latest version in force. Any change will be prospective only, and we will not make any changes that have retroactive effect unless legally required to do so.

20. Applicable Law And Disputes
Our privacy policy is subject to the law of England and Wales and disputes can be determined by the courts of England and Wales.

Insight Vacations Privacy Policy

Last updated: August 2020

1. ABOUT THIS POLICY

This document (our “privacy policy”) sets out information into how we use personal information relating to people we interact with including, for example, customers and website users. It serves as an expression of our commitment to protecting your personal data. It is important that you read this privacy policy together with any other privacy notices we may provide you on all occasions of personal data collection and processing, so you are fully aware of how and why we are using your data.

This privacy notice supplements other notices and is not intended to override them.

2. OUR COMMITMENT

We respect your right to privacy and we aim to ensure you have a trustworthy experience with us, including when using our websites or shops and booking with or through us. We understand that you care about how your personal data is used by us, and we want to share with you the policies and practices we’ve adopted. This way you can feel confident about how we handle your personal data.

3. OUR LEGAL BASES FOR PROCESSING

We will process your personal data in accordance with all applicable laws and applicable contractual obligations. More specifically, we will not process personal data unless at least one of the following requirements are met:

  1. You have given consent to the processing of your personal data for one or more specific purposes (for instance, for tailored offers to your interests, for sharing of your photos/videos of experiences of our trips on social media and sharing emails of co passengers, that have agreed to stay in touch);
  2. The processing is necessary for the performance of a contract to which you are party (for instance, for booking you have made) or in order to take steps at your request prior to entering into a contract (for instance, when you request a quote from us);
  3. Processing is necessary for compliance with a legal obligation to which we are subject (for instance, for visa applications);
  4. Processing is necessary in order to protect your vital interests or of any other individual (for instance, if you have any issue during a trip);
  5. Processing is necessary for the purposes of the legitimate interests pursued by us or by a third party (for instance, protecting our customers, our employees and other individuals and maintaining their safety, health and welfare; promoting, marketing and advertising our products and services; understanding our customers’ behaviour, activities, preferences, and needs; improving existing products and services and developing new products and services; preventing, investigating and detecting crime, fraud or anti-social behaviour and prosecuting offenders, including working with law enforcement agencies; handling customer contacts, queries, complaints or disputes; managing insurance claims by customers; protecting us, our employees and customers, by taking appropriate legal action against parties who have committed criminal acts or are in breach of legal obligations to us; effectively handling any legal claims or regulatory enforcement actions taken against us; fulfilling our duties to our customers, colleagues, shareholders and other stakeholders).

4. CHANGE OF PURPOSE

We will only use your personal information for the purpose for which we obtained it. If we reasonably need to re-purpose your personal data, we will ensure it is for a reason that is compatible with the original purpose. If you require an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us. We may process your personal data for unrelated purposes, based on our legitimate Interest.

  1. There are some circumstances in which personal data may be processed for purposes that go beyond the original purpose for which the personal data was collected. When this is susceptible to be the case, we will make our best efforts to tell you in advance and request your consent when appropriate.
  2. For circumstances where we may have other secondary purposes, for processing already existing data which you have provided as part of a contract for example, booking information. The objective of further processing may include conducting marketing insights and data analysis to have a better understanding of our customers.
  3. We will adopt an aggregate data model that allows us derive aggregated data from your personal information. Aggregated data is not considered personal data by law, as you will not be directly or indirectly identified. For example we may make use of aggregated data to see performance statistics of our travel consortia/consultants and to gain insights into customer demographics for improving marketing and customer service.
  4. However, if we combine or connect aggregated data with your personal data so that it directly or indirectly identifies you, we shall treat the combined data as personal data which will be processed with strict guidelines of the GDPR.
  5. We will not repurpose sensitive data without explicit consent and where we rely on Legitimate Interest; will ensure we conduct legitimate Interest assessments and data protection impact assessments DPIA, prior to carrying out the proposed processing activity.

 

5. WHO OUR PRIVACY POLICY COVERS

5.1 Our customers

Our privacy policy sets out how we process personal data relating to individuals who are:

  1. booking or enquiring about booking travel services with or through us; or
  2. the recipients of any travel services booked with or through us (e.g. you are the passenger for a booking or booking enquiry made by someone else for you); or
  3. customers or potential customers or recipients of travel services that can be booked with or through us.

We understand personal data as any information relating to an identified or identifiable individual, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, services obtained or considered, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that individual.

5.2 Examples of who this policy covers

We include in this privacy policy personal data we process relating to:
(1) individuals who are making any enquiry or booking with us or through us, and individuals in respect of whom any enquiry or booking is made (such as friends, family members, tour group members, officers and employees of businesses and organisations booking with or through us); 
(2) individuals in respect of whom any enquiry or booking is made with us by an agent;
(3) where our customer is a business or organisation, employees or individuals who are acting as representatives of that business or other organisation, and individuals connected to that business or other organisation, such as owners, partners, shareholders, and directors; 
(4) individuals whose personal data is obtained from other companies in our group (such as where you have consented to your personal data being disclosed to other group companies for marketing purposes).

5.3 When we are data processor only

Please however note that this privacy policy does not apply where we are processing personal data strictly as a sub-contractor or data processor on behalf of a third party, and not on our own account. In this case, you should look to that third party and its privacy policy, who will be answerable for how we process that personal data on their instructions.

5.4 Terms used in this policy

When we refer to "you" and "your" in this privacy policy, we refer to you, and any such individual whose personal data we process from time to time.

When we refer to "processing" of your personal data, this includes obtaining, recording, storing or holding your personal data, and anything we do with it, such as organising, adapting or altering it, retrieving, consulting or using it, disclosing it or otherwise making it available to others, combining it with other data, and blocking, erasing or destroying it.

When we refer to "travel services" this covers all products and services which may be booked with or through us, such as bespoke holidays, package holidays, accommodation, tours, transport and transfers (whether by air, coach, bus, train, ferry, taxi or other means), car hire, cruises, and charters, and it includes both:

(1) all such products and services which we supply or operate ourselves (including where we sub-contract); and 
(2) any such products and services provide by a third party which we book for you (acting as agent for you or that third party). Travel services also includes any services we or a third party provide in association with travel, such as obtaining visas, foreign exchange, and providing local representatives and support.

6. WHAT TYPES OF PERSONAL DATA WE MAY PROCESS

This section summarises the types of personal data about you that we process:

6.1 Data concerning you as an individual

  1. name,
  2. age,
  3. photograph,
  4. gender,
  5. address,
  6. telephone,
  7. mobile,
  8. fax,
  9. e-mail,
  10. Social networking contact details, your social posts about any of our trips and travel experiences.
  11. proofs of identity and address, copies of passports, driving licences, and utility bills,
  12. card and other payment details, and financial information,
  13. health information relevant to your planned travel and travel insurances held,
  14. results of searches carried out against you (such as to verify your identity, address, and credit status), your preferences,
  15. Frequent flyer or travel partner programme affiliation and member number.

You will be free to withdraw your consent to this at any time, by contacting us as detailed in this privacy policy or as detailed in any direct marketing that you receive. In any e-mail you send we would ask you to insert "unsubscribe" as the subject heading.

6.2 Business Related Information

If you are an individual associated with a business or other organisation that is our customer, then your personal data may include the following information that we link to you:

  1. business or organisation details (such as name, address, telephone numbers, payment arrangements, financial information, etc.),
  2. your relationship with that business or organisation (such as owner, partner, director, shareholder, employee, or agent), and
  3. your contact details within that business (such as work address, work telephone and mobile numbers, work fax number, and work e-mail address).

6.3 Enquiry and Booking information

Information concerning enquiries and bookings made with or through us for travel services, including where you are making the enquiry or booking or are the recipient of the travel services to which the enquiry or booking relates. This information may include:

  1. records of enquiries and searches for holiday and travel products made by or on your behalf,
  2. details of your personal interests,
  3. needs and other data relevant to your enquiry;
  4. details of results, quotes, proposals, estimates and other information given in response to enquiries;
  5. details of the holiday, accommodation, travel, car hire, and other travel services booked or enquired about;
  6. details of the passengers / holidaymakers travelling;
  7. details of the provider of the travel services (e.g. tour operator);
  8. dates and times of travel;
  9. price;
  10. payment details (including card details);
  11. passport information and visa information;
  12. foreign exchange requirements and arrangements; and
  13. Sensitive information such as health, medical, dietary, mobility, disability, or other requirements relevant to the service you are enquiring about or your contract with us.

6.4 Survey Information

Information collected or generated out of any surveys we conduct.

6.5 Competition Information

Information collected or generated out of any competitions or promotions we run.

6.6 Account, Registration and Loyalty Information

Information concerning any accounts, registrations, or memberships with us, or participation in any loyalty program.

6.7 Correspondence

Correspondence, communications and messages, including between you and us, and between us and third parties, relating to any booking or booking enquiry, or performance of any contract.

6.8 Website Usage Information

We may collect information about your visits to, browsing of, and use of our website, unless your web browser blocks this. The range of data we collect will depend on how you interact with our website.

This information may include:

  1. your IP address (a unique identifier allocated to your computer for your connection to the internet);
  2. your computer device details (PC, tablet, smartphone, watch etc.);
  3. the make and version of web browser (e.g. Internet Explorer, Firefox, Safari, Opera, Chrome) you are using;
  4. your operating system (e.g. Windows, Windows Phone, OSX, iOS, Android, Linux etc);
  5. your time-zone;
  6. your browser plug-ins;
  7. any web-page you came from, identified as the referrer web page address by your web browser;
  8. cookies (as per our cookie policy )
  9. page response times;
  10. download error;
  11. pages and parts of pages you visit;
  12. usage you make of our website, including enquiries and searches undertaken, and registrations for accounts, forums etc.;
  13. services and products you viewed;
  14. length of visit to website and pages;
  15. page interaction information (such as scrolling, keys pressed, mouse clicks, touches, and mouse-overs).

This will normally be collected and used anonymously, and aggregated for analysis, with your name and any characteristics identifying you remaining anonymous, but our privacy policy will apply, and it will be treated as your personal data, if this information is in any way linked to you personally.

This information may include:

  1. data inputted into forms and fields;
  2. registrations for any accounts,
  3. forum,
  4. feedback mechanism,
  5. social functionality,
  6. newsletters or other features of our site;
  7. usernames and passwords,
  8. log-in / out history, and settings;
  9. actions taken within any account or other registration, including view and update and changes to settings; and posts to any forum, feedback, review or other social functionality on our website.

Such information will be treated as personal data and processed according to this privacy policy.

7. HOW WE COLLECT OR GENERATE YOUR PERSONAL DATA

This section sets out the ways in which we may collect or generate personal data concerning you.

7.1 Visiting our website

By visiting and using our website you or your computer may provide personal data. This includes: information which is automatically provided by your browser to our servers; information recorded on our web servers about your interaction with our website and pages viewed; information we capture or place on your computer or generate using cookies or other technologies on our website; and information you input into forms and fields on our website. This is more detailed in our cookie policy

7.2 Data you provide

Your personal data will include data you provide (or later amend), whether:

    1. from correspondence with you;
    2. verbally to us over the phone or in person;
    3. by filing in any field or form on a website;
    4. by filling in any printed form we provide you with;
    5. by e-mail;
    6. from documents you provide us with; and
    7. from updates to any information you provide to us from time to time.

This includes when you:

  1. register or subscribe for any service, account, members, or loyalty program,
  2. make an enquiry or booking for a holiday or other travel services whether in person, by phone, through our website or otherwise;
  3. send us your comments or suggestions;
  4. subscribe to any newsletter or other publication;
  5. and request sales and advertising information, including brochures.

7.3 User Generated Content (UGC)

We may process, Information or content provided by you in relation to your feedback or experience on a past, current or future trip with us. We will only use such content and images you have submitted to our social media channels or websites, if you have given consent to let Insight Vacations LTD. and TTC subsidiary companies to process this information in various initiatives. These could include any marketing activities such as:

  1. Print materials
  2. on our website
  3. email activities
  4. social posts
  5. images on our trips
  6. provide images to our trade partners to use on their websites, email marketing and other marketing initiatives
  7. make available in our content feeds
  8. We would share imagery in our content feeds, image repositories, via email and share with our trade partners via these methods
  9. Any other information provided to us by or in relation to you which concerns you as an individual.

7.4 Data obtained from third parties

We may obtain personal data concerning you from third parties, including from:

  1. providers of any holidays, accommodation, other travel services which are enquired about or booked, and their intermediaries;
  2. credit, fraud, identity and other searches we may undertake, including searches with public records and regulatory and private organisations;
  3. Any business or organisation you are associated with; from telephone numbers identified by the telephone system when you telephone us.

7.5 Data generated by us

We and any suppliers or sub-contractors working for us may generate personal data relating to you, including:

  1. in connection with responding to and dealing with any enquiry, booking or complaint; or
  2. in performing any booking or other contract with you; or
  3. through the analysis of your personal data; or
  4. data gained from your use of our website according to our cookie policy.

We may record telephone calls with you for training and quality purposes.

8. WHAT DO WE USE YOUR PERSONAL DATA FOR?

This section sets out the uses which we make of your personal data and the legal basis on which we rely to do this.

8.1 Operate our website

To operate and provide the search, booking, accounts, review, forums and other services, facilities and functions of our websites. This includes managing any accounts or registrations you have with our websites and making changes to your settings and profile at your request.

8.2 Provide information and respond to enquiries

To provide information to you about our website, systems and services, including to respond to booking enquiries and searches for holidays and travel, and to keep you updated generally. We process your data because you ask us to take the relevant steps in order to enter into a contract, or because we perform a service that you asked us to provide.

8.3 Bookings and other contracts

To enable you to make bookings, and to fulfil, provide, perform, administer, manage, and enforce all bookings, orders, and other contracts which relate to you (including if you are a passenger in a booking made by someone else), and to process any transactions authorised or made with us which relate to you. We process your data because you ask us to take the relevant steps in order to enter into a contract, or because we perform a service that you asked us to provide.

8.4 Payments

To collect and make payments due and administer our accounts. This is necessary for the preparation of any contract between us.

8.5 Communication with customers

To communicate with you concerning any enquiries, bookings, travel services provided, problems and complaints, and to respond to any submissions, enquiries or requests from you. We process your data because you ask us to take the relevant steps in order to enter into a contract, or because we perform a service that you asked us to provide.

8.6 Record Keeping

To keep internal records and maintain reasonable archives, including concerning as to enquiries, bookings, contracts, travel services, and complaints. This is done on the basis of our legitimate interests in ensuring our business is protected or run efficiently, or because we have the legal obligation to do so.

8.7 Manage and Improve our business

To analyse, audit, provide, operate, administer, maintain and improve our business, website, systems, and services;

  1. to carry out surveys and analyse the results;
  2. to run promotions and competitions;
  3. undertake product or customer research/development;
  4. to assist us in and help us to improve our sales,
  5. editorial, advertising and marketing processes;
  6. to carry out other business development and improvement activities; and
  7. to provide training to our staff, sub-contractors and suppliers.

For example, we may use your personal data to help us profile how our customers generally are using our websites and booking travel services with (or through) us. We may also use this information to ascertain interests so that we can better tailor our business offerings. This is done on the basis of our legitimate interests in ensuring our business to run efficiently.

8.8 Direct marketing

To carry out direct marketing to you, see section 10.1 for further information.

8.9 Advertising

To report aggregate information concerning usage of our websites to our advertisers. We normally create anonymous statistical data about browsing actions and patterns, and do not identify any individual.

8.10 Anything you have specifically consented to

For any purpose which we have obtained your consent to. We will do this only where you have a choice whether to consent or not, you have control over that data and you have had to take an affirmative step to give consent on an informed basis. We will ensure that you can withdraw your consent at any time by providing simple mechanisms if you would like to do so.

8.11 Consequences of Not Providing your Data

You are not obligated to provide your personal information, however, where the information is required for us to provide you with our services/deliver your products, we may not be able to offer some/all our services without it. Sometimes, providing your data to authorities when you travel is a legal obligation for us.

9. PERIOD FOR RETAINING YOUR DATA

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

If you would like to know more about our data retention policy, please ask us.

10. USE OF YOUR PERSONAL DATA FOR DIRECT MARKETING

We do not use or disclose your personal data for direct marketing purposes unless:

  1. we have obtained your consent to do so, such as through an opt-in box on any form or website of ours; and/or
  2. you have made a booking with us and there is our legitimate business interest to do so for similar products or services.

If you do not want to receive direct marketing activities anymore, you can manage your communications preferences on your online account or unsubscribe by following the link at the end of every of our electronic communications.

In addition to data protection law if we use your personal information for direct marketing purposes we may also be subject to additional rules that regulate direct marketing, such as the EU Privacy and Electronic Communications Directive 2009/136/EC. The term “direct marketing” essentially means direct marketing material or advertising at a particular individual.

10.1 Direct marketing by us

We will use your personal data to send you marketing information (including adverts and details of promotions) about travel services:

(1) offered by us;

(2) which can be booked with third parties through us;

(3) which can be booked with other companies within our group (i.e. the Travel Corporation Group); and

(4) offered by third parties selected by us. However, we will not pass any of your details to third parties without your prior and specific consent.

Where applicable we will only send you marketing information about the categories of travel services you have selected. Also, we will only contact you in the manner you agreed to (e.g. by email or sms).

10.2 Direct Marketing by Third Parties

From time to time we may disclose your contact details (i.e. your name, email address, postal address, telephone number, mobile number, fax number and preferences) to:

other companies within our The Travel Corporation, which are bound by the same requirements set in this privacy policy; and other companies which offer services that may enhance your travel experience or be able to help you to finalise your travel arrangements (“third parties”). Such third parties may then contact you directly with marketing information about services and products offered by them. Such third parties are not part of The Travel Corporation and are not bound by this privacy policy. However, we ensure that our partners will only contact you in the manner you agreed to (e.g. email, text) when providing your consent.

10.3 Withdrawing from Direct Marketing

You are free to stop receiving marketing information from us at any time by contacting us as detailed in this privacy notice or by following the instructions set out in our marketing communications. If you email us to withdraw your consent, it would be helpful if you could insert the word “Unsubscribe” as the subject heading.” When you elect to stop receiving marketing information we will, from that point onwards, not share your information further with any other third parties. You are also free, at any time, to notify any third party to whom we have previously passed your contact details to, that you no longer wish to receive marketing communications from them.

11. DISCLOSURE OF YOUR PERSONAL DATA TO THIRD PARTIES

We transfer your personal data to third parties in the following circumstances:

11.1 Credit Checks etc.

We may disclose your personal data to third parties (including intermediaries) as necessary to carry out any checks regarding your financial standing. The identities of these parties may change from time to time. They may include credit reference agencies and other companies for use in credit decisions, for fraud prevention and to pursue debtors.

11.2 Bookings and performance of contracts

We disclose your personal data to third parties (including intermediaries) as necessary to deal with any booking enquiry being made by or for you, to make any booking requested by or for you, to perform and administer any booking for you or other contract with or in respect of you. This may include;

  1. to apply for visas on your behalf,
  2. to collect payments to be made by you,
  3. to investigate and respond to complaints, and
  4. to enforce any booking or other contract with you.

Such third parties may include any suppliers or sub-contractors and their agents (e.g. airlines, coach, ferry or train companies, hoteliers, hire companies, cruise companies, tour operators etc.). The identities of these parties may change from time to time and are engaged so we can provide our services to you. We ensure that these third parties carry their tasks with the same level of protection on your personal data that you will expect from us.

11.3 Suppliers of travel and other services

We may disclose your personal data to any third party (e.g. supplier, contractor sub-contractor) we make any enquiries with concerning or engage or sub-contract to perform any booking or other contract, including to provide any travel, tour or other products or services we have agreed to provide to you in order to perform our contract with you.

We may disclose your personal data to any supplier with whom we make any enquiry concerning or book any travel or other products and services for you as agent (whether as agent for you, someone representing you, or the supplier), such as a tour operator. Details of any third party tour operators or other third parties who will be responsible for or supply you with the travel services booked or enquired about, may be obtained from us on request, and may be stated in any tour or other brochure provided by us.

11.4 Insurance

If any application is made through us for any travel or other insurance to cover you, we will pass your personal data on to the insurer. Information provided by you may be put on to a register of claims and shared with other insurers to prevent fraudulent claims.

11.5 Business Function Outsourcing

Where we use third parties to host, provide, operate or supply any part of our websites, databases, systems, business, or services, or carry out on our behalf any of our business functions or actions (including sending mail, processing payments, providing marketing assistance, providing customer and advertising analysis, and providing customer services), then we may provide your personal data to them as required for use for or processing as part of those purposes. We ensure that these third parties treat your personal data with the same level of care and duty as us.

11.6 Public forums etc.

Where any facility on our website is clearly designed to make certain of your personal data public (e.g. posts you make to any public forum or reviews facility), then any personal data you provide in relation to that forum or other facility, which is provided in circumstance where it is clear that it is intended to be published, will be disclosed to the public accordingly, subject to moderation by us and to the terms of this privacy policy.

11.7 Legal requirements

We may supply personal data to a government authority or regulator where required to:

  1. comply with a legal requirement,
  2. for the administration of justice or when required by a public enforcement body, or
  3. for the purposes of customs, visas and immigration.

We may disclose your personal data where otherwise required by or permitted by law.

11.8 Direct Marketing by third parties

We may disclose your personal data to third parties to carry out direct marketing to you, where you have given your prior consent. Please refer to the direct marketing section above for more information.

11.9 Business Customers who are businesses (not individuals)

If you are a business or organisation (“Business Customer”), and we are holding personal data of any authorised representative (such as an employee agent, employee, officer, owner, partner, or director), then we may disclose to them that personal data.

If a Business Customer is making a booking or booking enquiry on behalf of an individual, with that person’s authority, then we may disclose to our Business Customer that individual’s personal data as reasonably required in connection with such booking or enquiry, or the subsequent performance of or payment for any booking made.

11.10 Business acquirers

If our business is ever transferred to a third party, then your personal data will be transferred to the acquirer to enable them to continue our business. We will ensure that the acquirer is bound by terms similar to this privacy policy to protect your personal data.


12. HOW THIRD PARTIES WILL HANDLE YOUR PERSONAL DATA

Where we provide your personal data to a third party one of the following two circumstances will apply:

12.1 Processing on our behalf

In some cases, your personal data may be held and otherwise processed by others on our behalf. We have not included the names of our service partners as these will change over time. We will remain responsible for what they do with your personal data, and your personal data will only be held and processed by them in accordance with our instructions and this privacy policy. The sharing of your data is necessary for the performance of any contract with you and for the efficient provision of our services.

12.2 Processing on their own account

In other cases, your personal data may need to be provided to them to be held and processed by them in their own right and on their own account. In such case, they will have their own responsibility for your personal data, subject to their own privacy policy, and we will not be responsible for what they do with it following disclosure. This will only be done to perform the contract. When this happens, you will be informed by the third party and they will provide their privacy policy to you.

13. LOCATION OF YOUR PERSONAL DATA

We (and any affiliate, subcontractor or other person processing your personal data on our behalf) may transfer, store and otherwise process your personal data anywhere within the European Economic Area (“EEA”).

We will only send your personal data outside the EEA to companies either within our group or to parties with whom we have a contract based on the Standard Contractual Clauses as published by the European Commission. We ensure your personal data is protected by requiring all our group companies to follow the same rules when processing your personal data. This means within our group and for those other organisations with whom we have contracts we ensure that we have in place adequate safeguards in respect of such transfers outside the EEA. You can find out about what adequate safeguards these are by contacting us using the details provided in Section 4 of this privacy notice.

14. KEEPING YOUR DATA SECURE

14.1 Our security measures

We take appropriate technical and organisational measures to secure your information and to protect it against unauthorised or unlawful use and accidental loss or destruction, including:

  1. only sharing and providing access to your information to the minimum extent necessary, subject to confidentiality restrictions where appropriate, and on an anonymised basis wherever possible;
  2. using secured servers to store your information;
  3. verifying the identity of any individual who requests access to information prior to granting them access to the information
  4. using Secure Sockets Layer (SSL) and Transport Layer Security (TLS) software or other similar encryption technologies to encrypt your personal and payment transactions.

Unfortunately transmission of information over email is not secure, and if you submit any information to us over the internet by email we will do our best to protect your personal data and have contractual processes in place with our service providers to do this. Once we have received your information, we will use relevant procedures and adequate security measures to prevent unauthorised access.

For your own privacy protection, we encourage you to maintain anti-virus and other malware protection software on your computers and other devices, and to maintain your own measures to protect your personal data. Please do not include sensitive personal data in any e-mails you may send to us, including payment card information.

We also encourage you to be careful about who you give personal data to. We never contact you to ask you for your payment card information, or sensitive personal data such as passport numbers or log-in details, and we will only ask you for such information in person or through our website, or by telephone in connection with a booking you are making or have made. Please let us know if you someone purports to contact you in our name.

15. YOUR RIGHTS

You have certain rights under data protection laws, which we summarise below. If you contact us about these rights, we may ask for proof of your identity before we act on any request, and we may refuse to act if you do not provide this or your identity is not established by you. This is to ensure that your data is protected and kept secure. More information about your rights and our obligations can be found on the Commission for Communications Regulation website https://www.comreg.ie

To exercise any of your rights below, please contact us as per the contact details provided in Section 4. You can also exercise some of these rights directly through our online form https://ttc.com/personal-data-request/

You may request, we tell you whether we are processing personal data about you, to tell you what personal data we are processing, for what purposes, from which sources we have collected it, who we disclose it to and to provide you with a copy of your personal data that we hold. We will act within one month after receiving a valid request (i.e. when we will have been able to identify you as the data subject).

If your request is complex, or if we have a high volume of requests, we may extend this period for two additional months. We will advise you if this is the case.

The law does allow us, in certain cases, to refuse to act upon your request or to charge a reasonable administration fee, if we estimate that the request is manifestly unfounded or excessive We will advise you at the time if this is the case along with your possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.

15.1 Rectification

You have the right to have your personal data amended if it is inaccurate or incomplete.

15.2 Right to object

You have the right to object to the use of your personal information for direct marketing or where we use it on the basis that we say we have a legitimate interest in using it.

15.3 Erasure

You have the right to have your personal information deleted or removed in the following circumstances:

  1. The data is no longer necessary for the purpose for which it was originally collected or otherwise processed;
  2. Where you withdraw your consent, where consent was used as the legal basis for processing;
  3. Personal data has been unlawfully processed;
  4. When you object to the processing and we have no overriding legitimate interest for continuing the processing;
  5. Erasure is required for compliance with a legal requirement; or
  6. Data has been collected in relation to the offering of online services to a child.

When a request for erasure is valid, we will take reasonable steps to inform third parties which are processing the personal data that you have requested us to delete.

We have the right to refuse to act on a request of erasure if the data is necessary for:

  1. Exercising the right of freedom of expression and information;
  2. Compliance with a legal obligation;
  3. The establishment, exercise or defence of legal claims;

15.4 Portability

You have the right to receive your personal data which you have provided to us, in a structured, commonly used and machine-readable format and to transmit those data to another controller, when:

  1. the processing is based on consent or on a contract; and
  2. the processing is carried out by automated means.

15.5 Restrict Processing

You have the right to obtain from us the restriction of processing of your personal data where one of the following applies:

  1. You contest the accuracy of the personal data, for a period enabling us to verify the accuracy of the personal data;
  2. The processing is unlawful, and you oppose the erasure of the personal data and request the restriction of their use instead;
  3. We no longer need the personal data for the purposes of the processing, but the data is necessary for you for the establishment, exercise or defence of legal claims;
  4. You have objected to processing pending the verification whether our legitimate grounds override yours.

Where the processing of your personal data is restricted, at the exception of storage, we will only process your personal data with your consent, for the establishment, exercise or defence of legal claims, for the protection of the rights of another individual or organisation, or because we are legally required to do so.

We will inform you before the restriction of processing is lifted.

15.6 Right to withdraw your consent

You are free to withdraw your consent at any time, where we rely on your consent as a legal basis for processing. Please contact us using the details outlined in Section 4 of this policy. See also section 12 for details as to how to object to our direct marketing communications.

15.7 Complaints to the Data Protection Authority

The laws we comply with are regulated by the Commission for Communications Regulation (https://www.comreg.ie). In addition to your rights above, it is open to you, if you have a complaint or a concern, to seek assistance from this supervisory authority who has powers to compel us to comply with applicable laws and fine us for non-compliance. However, before you do so, we would hope that you will contact us first to discuss any complaint or concerns you have. You can contact us using the details provided in Section 4 of this our privacy notice.

Changes to this privacy policy

  1. We keep our privacy notice under regular review to make sure it is up to date and accurate. When we make any change, we will notify you by email of such change. You can check the top of the document to see the latest version in force.
  2. Applicable Law and Disputes
  3. Our privacy policy is subject to the law of Ireland and disputes can be determined by the courts of Ireland.

16. CONTACTING US

If you have any questions about our privacy policy or about how we process your personal data, including any requests or complaints, please contact us either by e-mail to compliance@ttc.com, telephone on 01 775 3803, or by post to 27, Merrion Square North, Dublin 2, Ireland.

17. ABOUT US

This is the privacy policy of INSIGHT VACATIONS LTD. (referred to as "we", "us" or "our"). We are incorporated under the laws of IRELAND. Our incorporation number is 2TA001564 and our incorporation address or registered office is Travel House,Rue De Manoir, St Peter Port, Guernsey, GY12JH. We are a member of the Irish Travel Agent Association (ITAA) and licensed and bonded by the Civil Aviation Authority Licence Number TA0713.

18. EU-US and Swiss-US Privacy Shield

The Travel Corporation Inc. (TTC) including all its entities and Subsidiaries in the US complies with the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union and Switzerland to the United States.
The Travel Corporation (TTC), has certified to the Department of Commerce that it adheres to the Privacy Shield Principles, namely Notice, Data Integrity and Purpose Limitation, Choice, Security, Access, Recourse, Enforcement and Liability and Accountability for Onward Transfer Principles. If there is any conflict between the terms in this Privacy Policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern.
To learn more about the Privacy Shield program, and to view our certification, please visit https://www.privacyshield.gov/ and https://ttc.com/privacy-shield-statement/. Under Privacy Shield Frameworks, we are subject to the authority of the U.S. Federal Trade Commission.
If you have any questions or concerns relating to our use and disclosure of your personal information in accordance to the Privacy Shield Principles, contact compliance@ttc.com. We will respond to a complaint or inquiry within 45 days of receipt.
We commit to cooperate with the EU data protection authorities or the Swiss Federal Data Protection and Information Commissioner (‘DPAs’), as applicable, and comply with their advice with regards to personal information transfers from the EU or Switzerland. If you believe that your questions or concerns were not addressed by us to your satisfaction, you may also contact the DPA of your place of residence. The dispute resolution by DPAs will be provided at no cost to you.
In certain circumstances, you may also have the right to pursue binding arbitration through the Privacy Shield Framework, as described in Annex I to the Privacy Shield Principles.
If we have received your personal information under the Privacy Shield and subsequently transfer it to a third-party service provider for processing as described in this Privacy Policy, we will remain responsible if they process your personal information inconsistently with the Privacy Shield Principles, except where we can establish that we are not responsible for the violation.
Visit our USA Privacy Policy here.

19. COPYRIGHT NOTICE

This document, and all content of our websites is Copyright © 2019 INSIGHT VACATIONS LTD. ALL RIGHTS RESERVED.

Costsaver Privacy Policy

Last updated: August 2020

1. About this policy

This document (our “privacy policy”) sets out information into how we use personal information relating to people we interact with including, for example, customers and website users It serves as an expression of our commitment to protecting their private personal information, but is not a contract.  Please see Section 17 below for the rights which the law provides you with in relation to your personal data.

2. Your consent

3. Copyright notice

4. About us

5. Contacting us

If you have any questions about our privacy policy or about how we process your personal data, including any complaints, please contact us either by e-mail to enquiries@trafalgartours.co.uk, telephone on 0800 533 5616, or by post to Picquet House, St Peter Port, Guernsey, UK, GY1 1AF.

6. Our commitment

7. Who our privacy policy covers

7.1 Our customers
Our privacy policy sets out how we process personal data (including information) relating to individuals who are:
- booking or enquiring about booking travel services with or through us; or 
- the recipients of any travel services booked with or through us (e.g. you are the passenger for a booking or booking enquiry made by someone else for you); or 
- customers or potential customers or recipients of travel services that can be booked with or through us.
 
7.2 Examples of who this policy covers
We include in this privacy policy personal data we process relating to:
 (1) individuals who are making any enquiry or booking with us or through us, and individuals in respect of whom any enquiry or booking is made (such as friends, family members, and tour group members, and officers and employees of businesses and organisations booking with or through us); (2) individuals in respect of whom any enquiry or booking is made with us by an agent; (3) where our customer is a business or organisation, employees or individuals who are acting as representatives of that business or other organisation, and individuals connected to that business or other organisation, such as owners, partners, shareholders, and directors; (4) individuals whose personal data from other companies in our group (such as where you have consented to your personal data being disclosed to other group companies for marketing purposes).  
7.3 When we are data processor only
Please however note that this privacy policy does not apply where we are processing personal data strictly as a sub-contractor or data processor on behalf of a third party, and not on our own account.  In this case, you should look to that third party and its privacy policy, who will be answerable for how we process that personal data.
7.4 Terms used in this policy
When we refer to "you" and "your" in this privacy policy, we refer to you, any such individual whose personal data we process from time to time. 
When we refer to "processing" of your personal data, this includes obtaining, recording, storing or holding your personal data, and anything we do with it, such as organizing, adapting or altering it, retrieving, consulting or using it, disclosing it or otherwise making it available to others, combining it with other data, and blocking, erasing or destroying it.
When we refer to "travel services" this covers all products and services which may be booked with or through us, such as bespoke holidays, package holidays, accommodation, tours, transport and transfers (whether by air, coach, bus, train, ferry, taxi or other means), car hire, cruises, and charters, and it includes both (1) all such products and services which we supply or operate ourselves (including where we sub-contract); and (2) any such products and services provide by a third party which we book for you (acting as agent for you or that third party). Travel services also includes any services we or a third party provide in association with travel, such as obtaining visas, foreign exchange, and providing local representatives and support.
 
8. What types of personal data we may process

This section summarizes the types of personal data about you that we process: -

8.1 Data concerning you as an individual

We may collect the following:

- name,
- age, 
- photograph,
- gender, 
- address, 
- telephone, 
- mobile, 
- fax, 
- e-mail, 
- social networking contact details, 
- proofs of identity and address, copies of passports, driving licences, and utility bills, 
- card and other payment details, and financial information, 
- health information relevant to your planned travel and travel insurances held, 
- results of searches carried out against you (such as to verify you identity, address, and credit status), 
- your preferences, 
- frequent flyer or travel partner programme affiliation and member number; and
- any other information provided to us by or in relation to you which concern you as an individual.


8.2 Business Related Information

If you are an individual associated with a business or other organisation that is our customer, then your personal data may include the following information that we link to you: 


- business or organisation details (such as name, address, telephone numbers, payment arrangements, financial information, etc.), 
- your relationship with that business or organisation (such as owner, partner, director, shareholder, employee, or agent), and
- your contact details within that business (such as work address, work telephone and mobile numbers, work fax number, and work e-mail address).


8.3 Enquiry and Booking information

Information concerning enquiries and bookings made with or through us for travel services, including where you are making the enquiry or booking or are the recipient of the travel services to which the enquiry or booking relates. This information may include:

- records of enquiries and searches for holiday and travel products made by or on your behalf, 
- details of your personal interests, 
- needs and other data relevant to your enquiry; 
- details of results, quotes, proposals, estimates and other information given in response to enquiries; 
- details of the holiday, accommodation, travel, car hire, and other travel services booked or enquired about;
- details of the passengers / holidaymakers travelling; 
- details of the provider of the travel services (e.g. tour operator); 
- dates and times of travel; 
- price; 
- payment details (including card details); 
- passport information and visa information; 
- foreign exchange requirements and arrangements; and 
- sensitive information such as health, medical, dietary, mobility, disability, or other requirements relevant to the service you are enquiring about or your contract with us.

8.4 Performance information
Information generated concerning the performance of any booking or other contract made with or through us, including information relating to anything arising during any holiday or other travel services, and information relating to payments to be made. 


8.5 Survey Information

Information collected or generated out of any surveys we conduct.


8.6 Competition Information

Information collected or generated out of any competitions or promotions we run.


8.7 Account, Registration and Loyalty Information

Information concerning any accounts, registrations, or memberships with us, or participation in any loyalty program.


8.8 Correspondence

Correspondence, communications and messages, including between you and us, and between us and third parties, including relating to any booking or booking enquiry, or performance of any contract.


8.9 Website Usage Information

We may collect information about your visits to, browsing of, and use of our website, unless your web browser blocks this. The range of data we collect will depend on how you interact with our website. 
This information may include:  

- your IP address (a unique identifier allocated to your computer for your connection to the internet);
- your computer device details (PC, tablet, smartphone, watch etc.); 
- the make and version of web browser (e.g. Internet Explorer, Firefox, Safari, Opera, Chrome) you are using; 
- your operating system (e.g. Windows, Windows Phone, OSX, iOS, Android, Linux etc); 
- your time-zone; 
- your browser plug-ins; 
- any web-page you came from, identified as the referrer web page address by your web browser; 
- cookies; 
- page response times; 
- download error; 
- pages and parts of pages you visit; 
- usage you make of our website, including enquiries and searches undertaken, and registrations for accounts, forums etc.; 
- services and products you viewed; 
- length of visit to website and pages;
- page interaction information (such as scrolling, keys pressed, mouse clicks, touches, and mouse-overs). 

This will normally be collected and used anonymously, and aggregated for analysis, with your name and any characteristics identifying you remaining anonymous, but our privacy policy will apply, and it will be treated as your personal data, if this information is in any way linked to you personally

This information may also include: 
- data inputted into forms and fields; 
- registrations for any accounts, 
- forum, 
- feedback mechanism, 
- social functionality, 
- newsletters or other features of our site; 
- usernames and passwords, 
- log-in / out history, and settings; 
- actions taken within any account or other registration, including view and update and changes to settings; and posts to any forum, feedback, review or other social functionality on our website.

9. How we collect or generate your personal data

This section sets out the ways in which we may collect or generate personal data concerning you.
9.1 Visiting our website
By visiting and using our website you or your computer may provide personal data. This includes:  information which is automatically provided by your browser to our servers; information record on our web servers about your interaction with our website and pages viewed; information we capture or place on your computer or generate using cookies or other technologies on our website; and information you input into forms and fields on our website.  
9.2 Data you provide
Your personal data will include data you provide (or later amend), whether: 
- from correspondence with you;
- verbally to us over the phone or in person; 
- by filing in any field or form on a website; 
- by filling in any printed form we provide you with; 
- by e-mail; 
- from documents you provide use with; and 
- from updates to any information you provide to us from time to time.  
This includes when you: 
- register or subscribe for any service, account, members, or loyalty program, 
- make an enquiry or booking for a holiday or other travel services whether in person, by phone, through our website or otherwise; 
- send us your comments or suggestions; 
- subscribe to any newsletter or other publication; 
- and request sales and advertising information, including brochures. 

9.3 Data obtained from third parties
We may obtain personal data concerning you from third parties, including from: 
- providers of any holidays, accommodation, other travel services which are enquired about or booked, and their intermediaries; 
- credit, fraud, identity and other searches we may undertake, including searches with public records and regulatory and private organisations; 
- any business or organisation you are associated with; from telephone numbers identified by the telephone system when you telephone us.
9.4 Data generated by us
We and any suppliers or sub-contractors working for us may generate personal data relating to you, including:
- in connection with responding to and dealing with any enquiry, booking or complaint; or 
- in performing any booking or other contract with you; or
- through the analysis of your personal data; or 
- data gained from your use of our website. 
We may record telephone calls with you.

10. What do we use your personal data for?

This section sets out the uses which we make of your personal data and the legal basis on which we rely to do this.
10.1 Operate our website
To operate and provide the search, booking, accounts, review, forums and other services, facilities and functions of our websites.  This includes managing any accounts or registrations you have with our websites and making changes to your settings and profile at your request.
10.2 Provide information and respond to enquiries
To provide information to you about our website, systems and services, including to respond to booking enquiries and searches for holidays and travel, and to keep you updated generally.  This is done on the basis of our legitimate interests in ensuring our business is run efficiently.
10.3 Bookings and other contracts
To enable you to make bookings, and to fulfill, provide, perform, administer, manage, and enforce all bookings, orders, and other contracts which relate to you (including if you are a passenger in a booking made by someone else), and to process any transactions authorised or made with us which relate to you. This is done on the basis of our legitimate interests in ensuring our business is run efficiently.
10.4 Payments
To collect and make payments due and administer our accounts.  This is necessary for the preparation of any contract between us.
10.5 Communication with customers
To communicate with you concerning any enquiries, bookings, travel services provided, problems and complaints, and to respond to any submissions, enquiries or requests from you.  This is done on the basis of our legitimate interests in ensuring our business is run efficiently.
10.6 Record Keeping
To keep internal records and maintain reasonable archives, including concerning as to enquiries, bookings, contracts, travel services, and complaints.  This is done on the basis of our legitimate interests in ensuring our business to run efficiently.
10.7 Manage and Improve our business
To analyse, audit, provide, operate, administer, maintain and improve our business, website, systems, and services; 
- to carry out surveys and analyse the results; 
- to run promotions and competitions; 
- undertake product or customer research/development; 
- to assist us in and help us to improve our sales, 
- editorial, advertising and marketing processes; 
- to carry out other business development and improvement activities; and 
- to provide training to our staff, sub-contractors and suppliers. 
For example, we may use your personal data to help us profile how our customers generally are using our websites and booking travel services with (or through) us. We may also use this information to ascertain interests so that we can better tailor our business offerings.  This is done on the basis of our legitimate interests in ensuring our business to run efficiently.
10.8 Direct marketing
To carry out direct marketing to you, see section 12.1 for further information.
10.9 Advertising
To report aggregate information concerning usage of our websites to our advertisers. We normally create anonymous statistical data about browsing actions and patterns, and do not identify any individual.
10.10 Anything you have specifically consented to
For any purpose which we have obtained your consent to. We will do this only where you have a choice whether to consent or not, you have control over that data and you have had to take an affirmative step to give consent on an informed basis.
10.11 Consequences of Not Providing your Data
You are not obligated to provide your personal information, however, where the information is required for us to provide you with our services/deliver your products, we may not be able to offer some/all our services without it.

11. Period for retaining your data

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

12. Use of your personal data for direct marketing

We do not use or disclose your personal data for direct marketing purposes unless:
- we have obtained your consent to this, such as through an opt-in  box on any form or website of ours; and/or
- you have made a booking with us and there is a legitimate interest to do is. 

In addition to data protection law if we use your personal information for direct marketing purposes we may also be subject to additional rules that regulate direct marketing.  The term “direct marketing” essentially means direct marketing material or advertising at a particular individual.
12.1 Direct marketing by us
We will use your personal data to send you marketing information (including adverts and details of promotions) about travel services:

(a) offered by us; 
(b) which can be booked with third parties through us;
(c) which can be booked with other companies within our group (i.e. the Travel Corporation Group); and
(d) offered by third parties selected by us. 

Where applicable we will only send you marketing information about the categories of travel services you have selected. Also, we will only contact you in the manner you agreed to (e.g. by email).  

12.2 Direct Marketing by Third Parties
From time to time we may disclose your contact details (i.e. your name, email address, postal address, telephone number, mobile number, fax number and preferences) to:
(a) other companies within our The Travel Corporation; and
(b) other companies which offer services that may enhance your travel experience or be able to help you to finalise your travel arrangements (“third parties”). Such third parties may then contact you directly with marketing information about services and products offered by them, third parties will only contact you in the manner you agreed to (e.g. email, text) when providing your consent.  

12.3 Withdrawing from Direct Marketing 
You are free to stop receiving marketing information from us at any time by contacting us as detailed in this privacy notice or by following the instructions set out in our marketing communications. If you email us to withdraw your consent, it would be helpful if you could insert the word “Unsubscribe” as the subject heading.” 
When you elect to stop receiving marketing information we will, from that point onwards, not share you information further with any other third parties. 
You are also free, at any time, to notify any third party to whom we have previously passed your contact details to, that you no longer wish to receive marketing communications from them.

13. Disclosure of your personal data 

We transfer your personal data to third parties in the following circumstances:
13.1 Credit Checks etc.
We may disclose your personal data to third parties (including intermediaries) as necessary to carry out any checks regarding your financial standing. The identities of these parties may change from time to time. They may include credit reference agencies and other companies for use in credit decisions, for fraud prevention and to pursue debtors.
13.2 Bookings and performance of contracts 
We disclose your personal data to third parties (including intermediaries) as necessary to deal with any booking enquiry being made by or for you, to make any booking requested by or for you, to perform and administer any booking for you or other contract with or in respect of you.  This may include; 
- to apply for visas on your behalf, 
- to collect payments to be made by you, 
- to investigate and respond to complaints, and 
- to enforce any booking or other contract with you.
Such third parties may include any suppliers or sub-contractors and their agents (e.g. airlines, coach, ferry or train companies, hoteliers, hire companies, cruise companies, tour operators etc.). The identities of these parties may change from time to time and are engaged so we can provide our services to you.
13.3 Suppliers of travel and other services
We may disclose your personal data to any third party (e.g. supplier, contractor sub-contractor) we make any enquiries with concerning or engage or sub-contract to perform any booking or other contract, including to provide any travel, tour or other products or services we have agreed to provide to you in order to perform our contract with you. 
We may disclose your personal data to any supplier with whom we make any enquiry concerning or book any travel or other products and services for you as agent (whether as agent for you, someone representing you, or the supplier), such as a tour operator.  Details of any third party tour operators or other third parties who will be responsible for or supply you with the travel services booked or enquired about, may be obtained from us on request, and may be stated in any tour or other brochure provided by us. 
13.4 Insurance
If any application is made through us for any travel or other insurance to cover you, we will pass your personal data on to the insurer.  Information provided by you may be put on to a register of claims and shared with other insurers to prevent fraudulent claims. 
13.5 Business Function Outsourcing
Where we use third parties to host, provide, operate or supply any part of our websites, databases, systems, business, or services, or carry out on our behalf any of our business functions or actions (including sending mail, processing payments, providing marketing assistance, providing customer and advertising analysis, and providing customer services), then then we may provide your personal data to them as required for use for or processing as part of those purposes. 
13.6 Public forums etc.
Where any facility on our website is clearly designed to make certain of your personal data public (e.g. posts you make to any public forum or reviews facility) then any personal data you provide in relation to that forum or other facility, which is provided in circumstance where it is clear that it is intended to be published, will be disclosed to the public accordingly, subject to moderation by us and to the terms of this privacy policy.
13.7 Legal requirements
We may supply personal data to a government authority or regulator where required to:
- comply with a legal requirement, 
- for the administration of justice, 
- for the purposes of customs, visas and immigration, or 
- where reasonably required to protect your vital interests or 
- enforce any booking or other contract.  
We may disclose your personal data where otherwise required by or permitted by law. 
  
13.8 Direct Marketing by third parties
We may disclose your personal data to third parties to carry out direct marketing to you, where you have given your prior consent, to third parties to carry out direct marketing.  See the direct marketing section above.
13.9 Business Customers who are businesses (not individuals)
If you are a business or organisation (“Business Customer”), and we are holding personal data of any authorised representative (such as an employee agent, employee, officer, owner, partner, or director), then we may disclose to them that personal data.   
If a Business Customer is making a booking or booking enquiry on behalf of an individual, with that person’s authority, then we may disclose to our Business Customer that individual’s personal data as reasonably required in connection with such booking or enquiry, or the subsequent performance of or payment for any booking made.
13.10 Business acquirers
If our business is ever transferred to a third party, then your personal data will be transferred to the acquirer to enable them to continue our business.

14. How third parties will handle your personal data

Where we provide your personal data to a third party one of the following two circumstances will apply:
14.1 Processing on our behalf
In some cases, your personal data may be held and otherwise processed by others on our behalf.  We have not included the names of our service partners as these will change over time. We will remain responsible for what they do with your personal data, and your personal data will only be held and processed by them in accordance with our instructions and this privacy policy.  The sharing of your data is necessary for the performance of any contract with you and for the efficient provision of our services.
14.2 Processing on their own account
In other cases, your personal data may need to be provided to them to be held and processed by them in their own right and on their own account.  In such case, they will have their own responsibility for your personal data, subject to their own privacy policy, and we will not be responsible for what they do with it following disclosure. This will only be done to perform the contract

15. Location of your personal data

We (and any affiliate, subcontractor or other person processing your personal data on our behalf) may transfer, store and otherwise process your personal data anywhere within the European Economic Area (“EEA”).  

We will only send your personal data outside the EEA to companies either within our group or to parties with whom we have a contract.  We ensure your personal data is protected by requiring all our group companies to follow the same rules when processing your personal data. This means within our group and for those other organisations with whom we have contracts we ensure that we have in place adequate safeguards in respect of such transfers outside the EEA. You can find out about what adequate safeguards these are by contacting us using the details provided in section 2 of this privacy notice.

16. Keeping your data secure

16.1 Our security measures

We take appropriate technical and organizational measures to secure your information and to protect it against unauthorized or unlawful use and accidental loss or destruction, including:

• only sharing and providing access to your information to the minimum extent necessary, subject to confidentiality restrictions where appropriate, and on an anonymized basis wherever possible;
• using secure servers to store your information;
• verifying the identity of any individual who requests access to information prior to granting them access to information
• using Secure Sockets Layer (SSL) and Transport Layer Security (TLS) software or other similar encryption technologies to encrypt your personal and payment transactions

Transmission of information over email is not secure, and if you submit any information to us over the internet by email you do so entirely at your own risk. We cannot be responsible for any costs, expenses, loss of profits, harm to reputation, damages, liabilities or any other form of loss or damage suffered by you as a result of your decision to transmit information to us by email.

16.2 Your security measures

For your own privacy protection, we encourage you to maintain anti-virus and other malware protection software on your computers and other devices, and to maintain your own measures to protect your personal data. Please do not include sensitive personal data in any e-mails you may send to us, including payment card information. 

We also encourage you to be careful about who you give personal data to. We never contact you to ask you for sensitive personal data, such as payment card information, or sensitive personal data such as passport numbers or log-in details, and we will only ask you for such information in person or through our website, or by telephone in connection with a booking you are making or have made.  Please let us know if you someone purports to contact you in our name.

17. Your Rights

Our privacy policy is not intended to create a contract or form part of any contract. You have certain non-contractual rights under the laws noted above, which we summarize below. If you contact us about these rights, we may ask for proof of your identity before we act, and may refuse to act if you do not provide this or your identity is not established by you. This is to ensure that your data is protected and kept secure.  More information about your rights and our obligations can be found on www.ico.gov.uk
17.1 Access to your personal data
You may request us to tell you whether we are processing personal data about you, to tell you what personal data we are processing and for what purposes, and to provide you with a copy of your personal data that we hold. 
The law does allow us, in certain cases to refuse your request, and we will advise you at the time if this is the case. 
17.2 Rectification
You have the right to have your personal data amended if it is inaccurate or incomplete.
17.3 A right to object
You have the right to object to the use of your personal information for direct marketing or where we use it on the basis that we say we have a legitimate interest in using it.
17.4 Deletion of Data inaccuracies
You have the right to have your personal information deleted or removed in certain circumstances and we may have the right in some cases to refuse to do so.
17.5 Portability
 You have the right to obtain and re-use your personal information for your own use in certain circumstances.
17.6 Restrict Processing
You may prevent or suppress the processing of your personal information in certain circumstances.
17.7 Complaints to applicable authority

The laws we comply with are regulated by the Information Commissioner (www.ico.gov.uk) in the United Kingdom.  In addition to your rights above, it is open to you, if you have a complaint or concern, to seek assistance from this supervisory authority who has powers to compel us to comply with applicable laws and fine us for non-compliance.  However, before you do so, we would hope that you will contact us first to discuss any complaint or concerns you have.  You can contact us using the details provided in section 2 of this our privacy notice. 

17.8 Right to withdraw your consent

You are free to withdraw your consent at any time. Please contact using the details outlined in Section 5 of this policy. See also section 12.3 for details as to how to unsubscribe from our mailing lists. 

18. EU-US and Swiss-US Privacy Shield

The Travel Corporation Inc. (TTC) including all its entities and Subsidiaries in the US complies with the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union and Switzerland to the United States.
The Travel Corporation (TTC), has certified to the Department of Commerce that it adheres to the Privacy Shield Principles, namely Notice, Data Integrity and Purpose Limitation, Choice, Security, Access, Recourse, Enforcement and Liability and Accountability for Onward Transfer Principles. If there is any conflict between the terms in this Privacy Policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern.
To learn more about the Privacy Shield program, and to view our certification, please visit https://www.privacyshield.gov/ and https://ttc.com/privacy-shield-statement/. Under Privacy Shield Frameworks, we are subject to the authority of the U.S. Federal Trade Commission.
If you have any questions or concerns relating to our use and disclosure of your personal information in accordance to the Privacy Shield Principles, contact compliance@ttc.com. We will respond to a complaint or inquiry within 45 days of receipt.
We commit to cooperate with the EU data protection authorities or the Swiss Federal Data Protection and Information Commissioner (‘DPAs’), as applicable, and comply with their advice with regards to personal information transfers from the EU or Switzerland. If you believe that your questions or concerns were not addressed by us to your satisfaction, you may also contact the DPA of your place of residence. The dispute resolution by DPAs will be provided at no cost to you.
In certain circumstances, you may also have the right to pursue binding arbitration through the Privacy Shield Framework, as described in Annex I to the Privacy Shield Principles.
If we have received your personal information under the Privacy Shield and subsequently transfer it to a third-party service provider for processing as described in this Privacy Policy, we will remain responsible if they process your personal information inconsistently with the Privacy Shield Principles, except where we can establish that we are not responsible for the violation.
Visit our USA Privacy Policy here.

19. Changes to this privacy policy

20. Applicable Law And Disputes

Our privacy policy is subject to the law of England and Wales and disputes can be determined by the courts of England and Wales.

Luxury Gold Privacy Policy

Last updated: June 2023

1. ABOUT THIS DOCUMENT

This is the privacy policy of Luxury Gold, Inc. (referred to as "we", "us" or "our"). We are incorporated under the laws of California. Our incorporation address is 5551 Katella Ave. Cypress, CA, 90630. This document sets out our privacy policy in respect of consumer personal information, which will govern the way in which we process any personal information that you provide us with. It serves as an expression of our commitment to protecting your private personal information. We adopt this policy to comply with the California Consumer Privacy Act of 2018 ("CCPA") as amended by the California Privacy Rights Act of 2020 (“CPRA”). Any terms defined in the CCPA/CPRA have the same meaning when used in this notice. Please see Section 9 below for the rights which the law provides you with in relation to your personal information.

We will provide a link to this privacy notice when you are using our website, providing any personal information to us, or booking any travel services with us and we will ask you to read and confirm you have read this document where we collect your personal information.

2. OUR COMMITMENT

We respect your right to privacy and we aim to ensure that you have a trustworthy experience with us, including when using our websites or shops and booking with or through us. We understand that you care about how your personal information is used by us, and we want to share with you the policies and practices we’ve adopted. This way you can feel confident about how we handle your personal information that you entrust to us.

3. WHO OUR PRIVACY POLICY COVERS

3.1 Our Customers

Our Privacy Policy sets out how we process personal information relating to individuals who are booking or enquiring about booking travel services with or through us or who are the recipients of any travel services booked with or through us (e.g. you are the passenger for a booking or booking enquiry made by someone else for you), or who are customers or potential customers or recipients of travel services that can be booked with or through us.

3.2 Examples of Who This Policy Covers

We include in this Privacy Policy personal information we process relating to: (1) individuals who are making any enquiry or booking with us or through us, and individuals in respect of whom any enquiry or booking is made (such as friends, family members, and tour group members, and officers and employees of businesses and organizations booking with or through us); (2) individuals in respect of whom any enquiry or booking is made with us by an agent; (3) where our customer is a business or organization, employees or individuals who are acting as representatives of that business or other organization, and individuals connected to that business or other organization, such as owners, partners, shareholders, and directors; (4) individuals who visit our website or other online sites operated by us or our contractors or affiliates; (5) individuals who create an online account (if applicable); (6) individuals whose personal information from other companies in our group; and (7) individuals or businesses from any other arrangement with us.

3.3 When we are in Information Processor Only

This Privacy Policy does not apply where we are processing personal information strictly as a sub-contractor or information processor on behalf of a third party, and not on our own account. In this case, you should look to that third party, who will be answerable for how we process that personal information and its Privacy Policy.

3.4 Terms Used in This Policy

When we refer to "you" and "your" in this Privacy Policy, we refer to you, any such individual whose personal information we process from time to time.

When we refer to "process" or "processing" of your personal information, this includes collecting, recording, storing or holding your personal information, and anything we do with it, such as organizing, adapting or altering it, retrieving, consulting or using it, disclosing it or otherwise making it available to others, combining it with other information, and blocking, erasing or destroying it.

When we refer to "travel services" this covers all products and services which may be booked with or through us, such as bespoke vacations, package vacations, accommodation, tours, transport and transfers (whether by air, coach, bus, train, ferry, taxi or other means), car hire, cruises, and charters, and it includes both (1) all such products and services which we supply or operate ourselves (including where we sub-contract); and (2) any such products and services provide by a third party which we book for you (acting as agent for you or that third party). Travel services also include any services that we or a third party provide in association with travel, such as obtaining visas, foreign exchange, and providing local representatives and support.

4. INFORMATION WE COLLECT

We collect information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or device ("personal information"). In particular, we have collected the following categories of personal information from consumers within the last twelve (12) months:

Category Examples Collected

A. Identifiers.

A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, account name, Social Security number, driver license number, passport number, age, photographs, gender, address, telephone, mobile, fax, email, social networking contact details, proofs of identity and address, copies of passports, driving licenses, utility bills, card and other payment details, financial information, health information relevant to your planned travel, travel insurances held, results of searches carried out against you (such as to verify your identity, address, and credit status), your preferences, frequent flyer or travel partner program affiliation and member number, and any other information provided to us by or in relation to you which concerns you as an individual or other similar identifiers.

YES

B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).

A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal information included in this category may overlap with other categories.

YES

C. Sensitive personal information (CPRA 2020)

Government-issued identifiers (such as social security, driver’s license, state identification card, or passports), account log-in and financial information (such as payment card details), precise geolocation, Racial or ethnic origin, religious or philosophical beliefs , or union membership, genetic data, biometric information that may identify consumer’s health or sexual orientation.

YES

D. Protected classification characteristics under California or federal law.

Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).

YES

E. Commercial information.

Information concerning enquiries and bookings made with or through us for travel services, including where you are making the enquiry or booking or are the recipient of the travel services to which the enquiry or booking relates; records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies; records of enquiries and searches for vacation and travel products made by or on your behalf; details of your personal interests, needs and other data relevant to your enquiry; details of results, quotes, proposals, estimates and other information given in response to enquiries; details of the vacation, accommodation, travel, car hire, and other travel services booked or enquired about; details of the passengers / vacationers traveling; details of the provider of the travel services (e.g. tour operator); dates and times of travel; price; payment details (including card details); passport information and visa information; foreign exchange requirements and arrangements; and sensitive information such as health, medical, dietary, mobility, disability, religious or other special conditions or requirements.

YES

F. Biometric information.

Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data.

NO

G. Internet or other similar network activity.

Browsing history, search history, information on a consumer’s interaction with a website, application, or advertisement.

Information generated concerning the performance of any booking or other contract made with or through us, including information relating to anything arising during any vacation or other travel services, and information relating to payments to be made.

Information collected or generated out of any surveys we conduct.

Information collected or generated out of any competitions or promotions we run.

Information concerning any accounts, registrations, or memberships with us, or participation in any loyalty program.

Correspondence, communications and messages, including between you and us, and between us and third parties, including relating to any booking or booking enquiry, or performance of any contract.

We may collect information about your visits to, browsing of, and use of our website, unless your web browser blocks this. The range of information we collect will depend on how you interact with our website.

This information may include: your IP address (a unique identifier allocated to your computer for your connection to the internet); your computer device details (PC, tablet, smartphone, watch etc.); the make and version of web browser (e.g. Internet Explorer, Firefox, Safari, Opera, Chrome) you are using; your operating system (e.g. Windows, Windows Phone, OSX, iOS, Android, Linux etc.); your time-zone; your browser plug-ins; any web-page you came from, identified as the referrer web page address by your web browser; cookies; page response times; download error; pages and parts of pages you visit; usage you make of our website, including enquiries and searches undertaken, and registrations for accounts, forums etc.; services and products you viewed; length of visit to website and pages; page interaction information (such as scrolling, keys pressed, mouse clicks, touches, and mouse-overs). This will normally be collected and used anonymously, and aggregated for analysis, with your name and any characteristics identifying you remaining anonymous, but our Privacy Policy will apply, and it will be treated as your personal information, if this information is in any way linked to you personally. This information may also include: information inputted into forms and fields; registrations for any accounts, forum, feedback mechanism, social functionality, newsletters or other features of our site; usernames and passwords, log-in / out history, and settings; actions taken within any account or other registration, including view and update and changes to settings; and posts to any forum, feedback, review or other social functionality on our website.

YES

H. Geolocation data.

Physical location or movements.
NO

I. Sensory data.

Audio, electronic, visual, thermal, olfactory, or similar information.

NO

J. Professional or employment-related information.

Current or past job history or performance evaluations, business or organization details (such as name, address, telephone numbers, payment arrangements, financial information, etc.), your relationship with that business or organization (such as owner, partner, director, shareholder, employee, or agent), and your contact details within that business (such as work address, work telephone and mobile numbers, work fax number, and work email address).

YES

K. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. § 1232g; 34 CFR Part 99)).

Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records.

NO

L. Inferences drawn from other personal information.

Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.

NO

Personal information does not include:

  • Publicly available information from government records.
  • De-identified or aggregated consumer information.
  • Information excluded from the CCPA/CPRA's scope, like:
    • health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data;
    • personal information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FCRA), the Gramm-Leach-Bliley Act (GLBA) or the California Financial Information Privacy Act (CalFIPA), and the Driver's Privacy Protection Act of 1994 (DPPA).

5. HOW WE COLLECT OR GENERATE YOUR PERSONAL INFORMATION

This section sets out the ways in which we may collect or generate personal information concerning you. We obtain categories of personal information listed above from the following categories of sources:

5.1 Visiting Our Website

By visiting and using our website you or your computer may provide personal information. This includes: information which is automatically provided by your browser to our servers; information record on our web servers about your interaction with our website and pages viewed; information we capture or place on your computer or generate using cookies or other technologies on our website; and information you input into forms and fields on our website.

5.2 Data You Provide

Your personal information will include information you provide (or later amend), whether: from correspondence with you; verbally to us over the phone or in person; by filling in any field or form on a website; by posting on our social media channel; by posting on any forum referencing us; by filling in any printed form we provide you; by email; from documents you provide us; and from updates to any information you provide from time to time. This includes when you: register for or subscribe to any service, account, members or loyalty program, or make an enquiry or booking for a vacation or other travel services whether in person, by phone, through our website or otherwise; send us your comments or suggestions; subscribe to any newsletter or other publication; and request sales and advertising information, including brochures.

If you do not provide us with your personal information, we will be unable to provide you with information or book travel services for or on your behalf.

5.3 User Generated Content (UGC)

We may process information or content provided by you in relation to your feedback or experience on a past, current or future trip with us. We will only use such content and images you have submitted to our social media channels or websites if you have given consent to let Luxury Gold and The Travel Corporation (TTC) subsidiary companies to process this information in various initiatives. These could include any marketing activities such as:

Print materials; on our website; email activities; social posts; images of our trips; images provided to our trade partners to use on their websites, email marketing and other marketing initiatives; UGC made available in our content feeds—we would share imagery in our content feeds, image repositories, via email and share with our trade partners via these methods; any other information provided to us by or in relation to you which concerns you as an individual.

5.4 Data Obtained From Third Parties

We may obtain personal information concerning you from third parties, including from: people making enquiries or bookings on your behalf; providers of any vacations, vacations, accommodation, or other travel services which are enquired about or booked, and their intermediaries; credit, fraud, identity and other searches we may undertake, including searches with public records and regulatory and private organizations; from any business or organization you are associated with; from telephone numbers identified by the telephone system when you telephone us.

Under the CCPA/CPRA, Luxury Gold, Inc ensures it will take any reasonable and appropriate steps to ensure that the third-party service provider, or contractor provides the level of privacy protection required by the CCPA/CPRA. The service provider will only use the personal information transferred in a manner consistent with the CCPA/CPRA. If the service provider is unable to meet these requirements, Luxury Gold, Inc will be notified by such service provider and take appropriate actions to protect your data in accordance with the CCPA/CPRA.

5.5 Data Generated By Us

We and any suppliers or sub-contractors working for us may generate personal information relating to you, including in connection with responding to and dealing with any enquiry, booking or complaint; or in performing any booking or other contract with you; or through the analysis of your personal information or information gained from your use of our website. We may record telephone calls with you.

6. WHAT DO WE USE YOUR PERSONAL INFORMATION FOR

We commit to use your personal information only for the purposes listed below and for as long as it is necessary to achieve these purposes.

6.1 Operate Our Website

To operate and provide the search, booking, accounts, review, forums and other services, facilities, and functions of our websites. This includes customizing your online experience by providing you with more relevant online offers and updates, managing any accounts or registrations you have with our websites, and making changes to your settings and profile at your request.

6.2 Provide Information and Respond to Enquiries

To provide information to you about our website, systems, and services, including to respond to booking enquiries and searches for vacations and travel, and to keep you updated generally.

6.3 Bookings and Other Contracts

To enable you to make bookings, and to fulfill, provide, perform, administer, manage, and enforce all bookings, orders, and other contracts which relate to you (including if you are a passenger in a booking made by someone else), and to process any transactions authorized or made with us which relate to you.

6.4 Payments

To collect and make payments due and administer our accounts.

6.5 Communication with Customers

To communicate with you concerning any enquiries, bookings, travel services provided, problems and complaints, and to respond to any submissions, enquiries or requests from you.

6.6 Record Keeping

To keep internal records and maintain reasonable archives, including concerning as to enquiries, bookings, contracts, travel services, and complaints.

6.7 Manage and Improve Our Business

To analyze, audit, provide, operate, administer, maintain and improve our business, website, systems, and services; to carry out surveys and analyze the results; to run promotions and competitions;

To undertake product or customer research/development; to assist us in and help us to improve our sales, editorial, advertising and marketing purposes, including sharing of photographs and videos which you have voluntarily participated in during our Trips. Such photos and videos, captured by our Travel Directors or Marketing Team, may be shared across our social media channels such as Facebook, Instagram, YouTube, LinkedIn or TikTok. These images will not be shared for any use other than to promote our Travel experiences. Please excuse yourself from group photos or scenes being captured by Travel Directors if you do not wish to be photographed; for example, we may use your personal data to help us profile how our customers generally are using our websites and booking travel services with (or through) us. We may also use this information to ascertain interests so that we can better tailor our business offerings.

To carry out other business development and improvement activities; and to provide training to our staff, sub-contractors and suppliers. For example, we may use your personal information to help us profile how our customers generally are using our websites and booking travel services with (or through) us. We may also use this information to ascertain interests so that we can better tailor our business offerings.

6.8 Direct Marketing

To carry out direct marketing to you, in particular to identify you as a customer and to identify your product and service preferences and to provide personalized content and ads informing you of new or additional products, services, and/or promotions that may be of interest to you. We may engage in direct marketing via the following means depending on the details you have provided to us: text messages, phone calls, targeting you on social media platforms on your personal computer and mobile device, direct mail, post, web advertising, in third-party apps, in our apps. See Section 7 for the types of products we may market to you this way.

6.8 Advertising

To report aggregate information concerning usage of our websites to our advertisers. We normally create anonymous statistical data about browsing actions and patterns, and do not identify any individual.

6.8 Advertising

For any purpose for which we have obtained your consent.

7. USE OF YOUR PERSONAL INFORMATION FOR DIRECT MARKETING

We do not use or disclose your personal information for direct marketing purposes unless we have obtained your express consent to this, such as through an opt-in or opt-out tick box on any form or website of ours.

7.1 Direct Marketing By Us

We may use your personal information to carry out direct marketing and send you marketing messages, materials, advertisements, and promotions relating to travel services that we provide or which can be booked with third parties through us.

We may also use your personal information to carry out direct marketing and send you marketing messages, materials, advertisements, and promotions relating to travel services which are offered by or which can be booked through any other company in the same group of companies as Luxury Gold and The Travel Corporation (TTC), or third parties selected by us.

You will be free to withdraw your consent to this at any time, by contacting us as detailed in this Privacy Policy or as detailed in any direct marketing that you receive or by clicking the ‘unsubscribe’ button or text link at the bottom of any of our emails. In any unsubscribe request you send us via email, we ask that you insert ‘unsubscribe’ as the subject heading.

7.2 Direct Marketing by Third Parties

We may disclose your personal information that is contact information (such as name, email, postal address, telephone, mobile or fax number) to any other company in the same group of companies as Luxury Gold and The Travel Corporation (TTC), or to third parties selected by us. They will use this to carry out direct marketing in their own right and will use it to send you marketing materials, advertisements, and promotions relating to products and services they offer or which can be booked through them. You will be free to withdraw your consent to our disclosure of your personal information for this purpose at any time, by contacting us as detailed above. If you withdraw your consent, this will not affect any disclosures we have already made (i.e. we will not be able to remove your personal information from anyone we have disclosed it to), but we will tell you who they are upon request, and you should contact them directly concerning this.

8. INFORMATION RETENTION

We will only retain your personal information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. We dispose of the information we collect in accordance with retention policies and procedures. However, if we need to retain your data analytics purposes or trend analysis, we will anonymize and de-identify your personal information. If you would like to know more about our data retention policy, please ask us.

9. DISCLOSURE OF YOUR PERSONAL INFORMATION

We may disclose your personal information to a third party for a business purpose. When we disclose personal information for a business purpose, we enter a contract that describes the purpose and requires the recipient to both keep that personal information confidential and to not use it for any purpose except performing the contract.

In the preceding twelve (12) months, we have disclosed the following categories of personal information for a business purpose:

  1. Identifiers.
  2. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).
  3. Protected classification characteristics under California or federal law.
  4. Commercial information.
  5. Internet or other similar network activity.
  6. Professional or employment-related information.

We disclose your personal information for a business purpose to the following categories of third parties:

  • Our affiliates.
  • Service providers.
  • Third parties to whom you or your agents authorize us to disclose your personal information in connection with products or services we provide to you.

In the preceding twelve (12) months, we have sold personal information for direct marketing purposes.

We transfer your personal information to third parties in the following circumstances:

9.1 Credit Checks

We may disclose your personal information to third parties (including intermediaries) as necessary to carry out any checks concerning you or enforce any booking or contract with you (including credit, security, fraud, and identity checks). This may include credit reference agencies and other companies for use in credit decisions, for fraud prevention, and to pursue debtors.

9.2 Bookings and Performance of Contracts

We disclose your personal information to third parties (including intermediaries) as necessary to deal with any booking enquiry being made by or for you, to make any booking requested by or for you, to perform and administer any booking for you or other contract with or in respect of you. This may include: to apply for visas on your behalf, to collect payments to be made by you, to investigate and respond to complaints, and to enforce any booking or other contract with you. Such third parties may include any suppliers or sub-contractors and their agents (e.g. airlines, coach, ferry or train companies, hoteliers, hire companies, cruise companies, tour operators etc.).

9.3 Suppliers of Travel and Other Services

We may disclose your personal information to any third party (e.g. supplier, contractor sub-contractor) to whom we make any enquiries with concerning or engage or sub-contract to perform any booking or other contract, including to provide any travel, tour or other products or services we have agreed to provide to you. We may disclose your personal information to any supplier with whom we make any enquiry concerning or book any travel or other products and services for you as agent (whether as agent for you, someone representing you, or the supplier), such as a tour operator. Details of any third-party tour operators or other third parties who will be responsible for or supply you with the travel services booked or enquired about, may be obtained from us on request, and may be stated in any tour or other brochure provided by us.

9.4 Insurance

If any application is made through us for any travel or other insurance coverage for you, we will pass your personal information on to the insurer. Information provided by you may be put on to a register of claims and shared with other insurers to prevent fraudulent claims.

9.5 Business Function Outsourcing

Where we use third parties to host, provide, operate or supply any part of our websites, databases, systems, business, or services, or to carry out on our behalf any of our business functions or actions (including sending mail, processing payments, providing marketing assistance, providing customer and advertising analysis through third-party ad-tech vendors, and providing customer services), then we may provide your personal information to them as required for use for or processing as part of those purposes.

9.6 Public Forums, Etc.

Where any facility on our website is clearly designed to make certain of your personal information public (e.g. posts you make to any public forum or reviews facility), then any personal information you provide in relation to that forum or other facility, which is provided in circumstance where it is clear that it is intended to be published, will be disclosed to the public accordingly, subject to moderation by us.

9.7 Legal Requirements

We may supply personal information to a government authority or regulator where required to comply with a legal requirement, for the administration of justice, for the purposes of customs, visas, and immigration, or where reasonably required to protect your vital interests or enforce any booking or other contract. We may disclose your personal information where otherwise required by or permitted by law.

9.8 Direct Marketing by Third Parties

We may disclose your personal information to third parties to carry out direct marketing to you. See the direct marketing section above.

9.9 Customer Representatives

If our customer is a business or organization, and we are holding your personal information in your capacity as an associate of that business or organization (including as agent, representative, contact, employee, officer, owner, partner, or director), then we may disclose to them that personal information. If our customer is making a booking or booking enquiry on your behalf, with your authority, then we may disclose to our customer your personal information as reasonably required in connection with such booking or enquiry, or the subsequent performance of or payment for any booking made.

9.10 Business Acquirers

If our business is ever transferred to a third party, then your personal information will be transferred to the acquirer to enable them to continue our business.

10. YOUR RIGHTS AND CHOICES

The CCPA/CPRA provides California residents with specific rights regarding their personal information. This section describes your CCPA/CPRA rights and explains how to exercise those rights.

10.1 Request information about the processing of your personal data and access it

This enables you to receive information on the processing of your personal data and a copy of personal information we hold about you in a commonly used format. This applies to information we have processed over the last 12 months.

10.2 Request rectification of your personal information

This enables you to correct and rectify inaccurate data that may be held about you. You can also request Luxury Gold, Inc to complete any incomplete data, or to record a supplementary statement.

10.3 Request deletion of your personal information

This enables you to ask us to delete personal data where there is no good reason for us to keep it, unless the law allows us to. This applies to information we have processed over the last 12 months.

10.4 Request information about the processing of your personal data in relation to our data selling and disclosure practices

This enables you to receive information on the personal data we have collected about you and shared with our service providers. You are also entitled to know which of your personal information has been sold and to whom. If you are 16 years of age or older, you have the right to direct us to not sell your personal information at any time (the " right to opt-out"). We do not sell the personal information of consumers we actually know are less than 16 years of age, unless we receive affirmative authorization (the "right to opt-in") from either the consumer who is between 13 and 16 years of age, or the parent or guardian of a consumer less than 13 years of age. Consumers who opt-in to personal information sales may opt-out of future sales at any time. You can manage your communication preferences at any time from your account. You (or your authorized representative) may also exercise the right to opt-out by submitting a request to us by visiting the following page: https://ttc.com/personal-data-request/ , or sending us an email to compliance@ttc.com

10.5 Request information on the disclosure of personal data for direct marketing purposes

This enables you to receive information on the third parties to whom we have disclosed your information and the categories of disclosed personal data, which has been shared for direct marketing purposes.

10.6 Request to opt-out of sharing your sharing personal information whether or not money or service is exchanged as a result of you sharing this information.

Opt-out requests specifically to email direct marketing must be fulfilled within ten business days of receiving the request as, per the CAN-SPAM Act. No further direct marketing emails should be sent after this time.

10.7 Request to opt-out from the sale of personal data to other companies

This enables you to cease any selling of your personal information. Please note that we are not engaged in selling any of your personal information to other companies. You can opt-out to any sale of your personal data through the following link: Do Not Sell My Personal Information. You can also use the Cookie Preferences Center to opt-out of any sale of your personal data through cookies without detriment or preventing you from accessing Luxury Gold, Inc website content.

10.8 Request not to be subject to decisions based solely on automated processing (including profiling)

This enables you to cease being subject to processing based on automated processing. If the decision produces legal effects concerning you or similarly significantly affects you. Luxury Gold, Inc shall make all attempts not to conduct automated decision-making. However, if such automated decision making occurs, you will be allowed to opt out in accordance with the CCPA/CPRA.
10.9 Not to be discriminated as our consumer when you exercise any of the aforementioned rights.
This means that, in an event of any of your request to us, we will not engage in or suggest any discrimination against you, in particular, we will not deny our services to you, we will not charge you differently, and we will not provide different level or quality of services to you, unless such difference is reasonably related to the value provided to you or you have agreed to enter into a financial incentives programme with us.

10.10 Consumers’ Right to Limit Use and Disclosure of Sensitive Personal Information

This enables you to direct Luxury Gold, Inc to limit its use of any Sensitive Personal Information that you may have provided. We will not discriminate against you for exercising your rights. We will not deny you services, charge different prices or rates, or provide a different level of service or some services require the usage of personal information to function, so compliance with your request may impact those experiences.

10.11 Exercising Your Rights

To exercise any of the privacy rights described above, please submit a verifiable request to us by either:
• E-mail to compliance@ttc.com
• Phone to 1 888 680 1241
• Mail to 5551 Katella Ave. Cypress, CA, 90630
Only you or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a verifiable consumer request related to your personal information. You may also make a verifiable consumer request on behalf of your minor child.
You may only make a verifiable consumer request for access or data portability twice within a 12-month period. The verifiable consumer request must:
• Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative.
• Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you. Making a verifiable consumer request does not require you to create an account with us. We will only use personal information provided in a verifiable consumer request to verify the requestor's identity or authority to make the request.

10.12 Response Timing and Format

We endeavor to respond to a verifiable consumer request within 45 days of its receipt. If we require more time (up to 90 days), we will inform you of the reason and extension period in writing. We will deliver our written response by mail or electronically, at your option. Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request's receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.
We do not charge a fee to process or respond to your verifiable request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
10.14 Non-Discrimination
We will not discriminate against you for exercising any of your CCPA/CPRA rights. Unless permitted by the CCPA/CPRA, we will not:
• Deny you goods or services.
• Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.
• Provide you a different level or quality of goods or services.
• Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.

11. LOCATION OF YOUR PERSONAL INFORMATION

11.1 Transfer of Personal Information Overseas

We (and any affiliate, subcontractor or other person processing your personal information on our behalf) may transfer, store and otherwise process your personal information anywhere in the world to fulfill the purposes set out in this policy, for example to: (1) our overseas offices; (2) information processors (including operators of global travel distribution systems); (3) airlines, hotels and other travel service products; and (4) information technology and business service providers.

In many cases the transfer is necessary to initiate or complete a booking or other transaction on your behalf in response to a request by you or for the purpose of entering a contract with a third party on your behalf.

Where we disclose your personal information to third parties, that disclosure may also involve a transfer of your personal information anywhere in the world, and those third parties may themselves transfer, store or otherwise process that information anywhere in the world.

In each case, we will comply with any legal requirements concerning the transfer of your personal information by us to any third party outside the country where we are established, and where your personal information is still controlled by us or is being stored or otherwise processed on our behalf, our security measures (as detailed below) will also apply.

11.2 Countries to Which Your Personal Information is Transferred

The countries to which we transfer your personal information depends on your booking. Generally, such countries include those in Asia Pacific, Africa, North and South America and Europe.

12. KEEPING YOUR DATA SECURE

12.1 Our Security Measures:

12.1.1 Our General Commitment

We are committed to doing what we reasonably can to keep your personal information secure, and we are obliged by law to put in place appropriate technical and organizational measures against unauthorized or unlawful processing of your personal information and against accidental loss or destruction of, or damage to, your personal information. We have accordingly implemented security policies, rules, and technical measures with a view to achieving this.

12.1.2 Transmissions Between Your Web Browser and Our Servers

We use Secure Sockets Layer ("SSL") software in order to encrypt the personal information that you provide to us while it is in transit over the internet. This will work if your browser is SSL enabled (which most are). You can verify that this is working by looking for the symbol of a closed lock or solid key in the browser address bar or on the bottom bar of your browser window and by checking that the prefix for the web address in the browser address bar has changed from "http" to "https."

12.1.3 Storage of Your Personal Information

The personal information we collect from you online is stored by us and/or our service providers on databases protected through a combination of physical and electronic access controls, firewall technology, and other reasonable security measures.

12.2 Your Security Measures

For your own privacy protection, we encourage you to maintain anti-virus and other malware protection software on your computers and other devices, and to maintain your own measures to protect your personal information. Please do not include sensitive personal information in any emails you may send to us, including payment card information.

We also encourage you to be careful about who you give personal information to. We never contact you to ask you for sensitive personal information, such as payment card information, or sensitive personal information such as passport numbers or log-in details, and we will only ask you for such information in person or through our website, or by telephone in connection with a booking you are making or have made. Please let us know if you someone purports to contact you in our name.

13. HOW LONG DO WE KEEP YOUR PERSONAL INFORMATION?

We keep your personal information for as long as is reasonably necessary for the purposes for which we use it, and if longer, for any duration required by law, and for statutory claims limitation periods where your personal information may be relevant to any possible liability we may have to you.

14. "DO NOT TRACK"

We are required to let you know how we respond to web browser Do Not Track (DNT) signals.

We do not respond to such signals at this time.

15. CHANGES TO THIS PRIVACY POLICY

We reserve the right to amend this Privacy Policy at our discretion and at any time without notice to you, including by publishing a new version on our website. You can check the top of the document to see the date of the latest version in force. Any change will be prospective only, and we will not make any changes that have retroactive effect unless legally required to do so.

16. CONTACTING US

If you have any questions about our privacy policy or about how we process your personal information, including any requests, queries of complaints, please contact us either by:

  • Email to compliance@ttc.com.
  • Telephone on 1 888 680 1241.
  • Post to 5551 Katella Ave. Cypress, CA, 90630

17. COPYRIGHT NOTICE

This document, and all content of our websites is Copyright© 2021 Luxury Gold. All Rights Reserved.

18. ENFORCEMENT

Our privacy policy is subject to the law of the state of California, County of Orange and disputes can be determined by the courts of state of California, County of Orange. The CCPA/CPRA is enforced by the California Privacy Protection Agency for enforcement and guidance. As the data subject you have a private right of action for breach of information.

Uniworld Privacy Policy

Last Updated: 14 August 2020

CONTENTS

Please click on a link below to jump to a specific paragraph:

1. About This Policy
2. Our Commitment
3. Our Legal Bases for Processing
4. Change of Purpose
5. Who Our Privacy Policy Covers
6. What Types Of Personal Data We May Process
7. How We Collect Or Generate Your Personal Data
8. What Do We Use Your Personal Data For?
9. Period For Retaining Your Data
10. Use Of Your Personal Data For Direct Marketing
11. Disclosure Of Your Personal Data to Third Parties
12. How Third Parties Will Handle Your Personal Data
13. Location Of Your Personal Data
14. Keeping Your Data Secure
15. Your Rights
16. Contacting Us
17. About Us
18. Copyright Notice

1. ABOUT THIS POLICY

This document (our “privacy policy”) sets out information into how we use personal information relating to people we interact with including, for example, customers and website users. It serves as an expression of our commitment to protecting your personal data. It is important that you read this privacy policy together with any other privacy notices we may provide you on all occasions of personal data collection and processing, so you are fully aware of how and why we are using your data.

This privacy notice supplements other notices and is not intended to override them.

2. OUR COMMITMENT

We respect your right to privacy and we aim to ensure you have a trustworthy experience with us, including when using our websites or shops and booking with or through us. We understand that you care about how your personal data is used by us, and we want to share with you the policies and practices we’ve adopted. This way you can feel confident about how we handle your personal data.

3. OUR LEGAL BASES FOR PROCESSING

We will process your personal data in accordance with all applicable laws and applicable contractual obligations. More specifically, we will not process personal data unless at least one of the following requirements are met:

  • You have given consent to the processing of your personal data for one or more specific purposes (for instance, for tailored offers to your interests, for sharing of your photos/videos of experiences of our trips on social media and sharing emails of co passengers, that have agreed to stay in touch);
  • The processing is necessary for the performance of a contract to which you are party (for instance, for booking you have made) or in order to take steps at your request prior to entering into a contract (for instance, when you request a quote from us);
  • Processing is necessary for compliance with a legal obligation to which we are subject (for instance, for visa applications);
  • Processing is necessary in order to protect your vital interests or of any other individual (for instance, if you have any issue during a trip);
  • Processing is necessary for the purposes of the legitimate interests pursued by us or by a third party (for instance, protecting our customers, our employees and other individuals and maintaining their safety, health and welfare; promoting, marketing and advertising our products and services; understanding our customers’ behaviour, activities, preferences, and needs; improving existing products and services and developing new products and services; preventing, investigating and detecting crime, fraud or anti-social behaviour and prosecuting offenders, including working with law enforcement agencies; handling customer contacts, queries, complaints or disputes; managing insurance claims by customers; protecting us, our employees and customers, by taking appropriate legal action against parties who have committed criminal acts or are in breach of legal obligations to us; effectively handling any legal claims or regulatory enforcement actions taken against us; fulfilling our duties to our customers, colleagues, shareholders and other stakeholders).

 

4. CHANGE OF PURPOSE

We will only use your personal information for the purpose for which we obtained it. If we reasonably need to re-purpose your personal data, we will ensure it is for a reason that is compatible with the original purpose. If you require an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us. We may process your personal data for unrelated purposes, based on our legitimate interest.

  • There are some circumstances in which personal data may be processed for purposes that go beyond the original purpose for which the personal data was collected. When this is susceptible to be the case, we will make our best efforts to tell you in advance and request your consent when appropriate.
  • For circumstances where we may have other secondary purposes, for processing already existing data which you have provided as part of a contract for example, booking information. The objective of further processing may include conducting marketing insights and data analysis to have a better understanding of our customers.
  • We will adopt an aggregate data model that allows us to derive aggregated data from your personal information. Aggregated data is not considered personal data by law, as you will not be directly or indirectly identified. For example, we may make use of aggregated data to see performance statistics of our travel consortia/consultants and to gain insights into customer demographics for improving marketing and customer service.
  • However, if we combine or connect aggregated data with your personal data so that it directly or indirectly identifies you, we shall treat the combined data as personal data which will be processed within the strict guidelines of the GDPR.
  • We will not repurpose sensitive data without explicit consent and where we rely on Legitimate Interest; will ensure we conduct Legitimate Interest assessments and data protection impact assessments (DPIA), prior to carrying out the proposed processing activity.

 

5. WHO OUR PRIVACY POLICY COVERS

5.1 OUR CUSTOMERS

Our privacy policy sets out how we process personal data relating to individuals who are:

  • booking or enquiring about booking travel services with or through us; or
  • the recipients of any travel services booked with or through us (e.g. you are the passenger for a booking or booking enquiry made by someone else for you); or
  • customers or potential customers or recipients of travel services that can be booked with or through us.

 

We understand personal data as any information relating to an identified or identifiable individual, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, services obtained or considered, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that individual.

5.2 EXAMPLES OF WHO THIS POLICY COVERS

We include in this privacy policy personal data we process relating to:

  1. individuals who are making any enquiry or booking with us or through us, and individuals in respect of whom any enquiry or booking is made (such as friends, family members, tour group members, officers and employees of businesses and organisations booking with or through us);
  2. individuals in respect of whom any enquiry or booking is made with us by an agent;
  3. where our customer is a business or organisation, employees or individuals who are acting as representatives of that business or other organisation, and individuals connected to that business or other organisation, such as owners, partners, shareholders, and directors;
  4. individuals whose personal data is obtained from other companies in our group (such as where you have consented to your personal data being disclosed to other group companies for marketing purposes).

 

5.3 WHEN WE ARE DATA PROCESSOR ONLY

Please however note that this privacy policy does not apply where we are processing personal data strictly as a sub-contractor or data processor on behalf of a third party, and not on our own account. In this case, you should look to that third party and its privacy policy, who will be answerable for how we process that personal data on their instructions.

5.4 TERMS USED IN THIS POLICY

When we refer to "you" and "your" in this privacy policy, we refer to you, and any such individual whose personal data we process from time to time.

When we refer to "processing" of your personal data, this includes obtaining, recording, storing or holding your personal data, and anything we do with it, such as organising, adapting or altering it, retrieving, consulting or using it, disclosing it or otherwise making it available to others, combining it with other data, and blocking, erasing or destroying it.

When we refer to "travel services" this covers all products and services which may be booked with or through us, such as bespoke holidays, package holidays, accommodation, tours, transport and transfers (whether by air, coach, bus, train, ferry, taxi or other means), car hire, cruises, and charters, and it includes both:

(1) all such products and services which we supply or operate ourselves (including where we sub-contract); and

(2) any such products and services provide by a third party which we book for you (acting as agent for you or that third party). Travel services also includes any services we or a third party provide in association with travel, such as obtaining visas, foreign exchange, and providing local representatives and support.

6. WHAT TYPES OF PERSONAL DATA WE MAY PROCESS

This section summarises the types of personal data about you that we process:

6.1 DATA CONCERNING YOU AS AN INDIVIDUAL

We may collect the following:

  • name,
  • age,
  • photograph,
  • gender,
  • address,
  • telephone,
  • mobile,
  • fax,
  • email,
  • Social networking contact details, your social posts about any of our trips and travel experiences,
  • proofs of identity and address, copies of passports, driving licences, and utility bills,
  • card and other payment details, and financial information,
  • health information relevant to your planned travel and travel insurances held,
  • results of searches carried out against you (such as to verify your identity, address, and credit status),
  • your preferences,
  • Frequent Flyer or travel partner programme affiliation and member number.

 

You will be free to withdraw your consent to this at any time, by contacting us as detailed in this privacy policy or as detailed in any direct marketing that you receive. In any email you send we would ask you to insert "unsubscribe" as the subject heading.

6.2 BUSINESS RELATED INFORMATION

If you are an individual associated with a business or other organisation that is our customer, then your personal data may include the following information that we link to you:

  • business or organisation details (such as name, address, telephone numbers, payment arrangements, financial information, etc.),
  • your relationship with that business or organisation (such as owner, partner, director, shareholder, employee, or agent), and
  • your contact details within that business (such as work address, work telephone and mobile numbers, work fax number, and work email address).

 

6.3 ENQUIRY AND BOOKING INFORMATION

Information concerning enquiries and bookings made with or through us for travel services, including where you are making the enquiry or booking or are the recipient of the travel services to which the enquiry or booking relates. This information may include:

  • records of enquiries and searches for holiday and travel products made by or on your behalf,
  • details of your personal interests,
  • needs and other data relevant to your enquiry;
  • details of results, quotes, proposals, estimates and other information given in response to enquiries;
  • details of the holiday, accommodation, travel, car hire, and other travel services booked or enquired about;
  • details of the passengers / holidaymakers travelling;
  • details of the provider of the travel services (e.g. tour operator);
  • dates and times of travel;
  • price;
  • payment details (including card details);
  • passport information and visa information;
  • foreign exchange requirements and arrangements; and
  • sensitive information such as health, medical, dietary, mobility, disability, or other requirements relevant to the service you are enquiring about or your contract with us.

 

6.4 SURVEY INFORMATION

Information collected or generated out of any surveys we conduct.

6.5 COMPETITION INFORMATION

Information collected or generated out of any competitions or promotions we run.

6.6 ACCOUNT, REGISTRATION AND LOYALTY INFORMATION

Information concerning any accounts, registrations, or memberships with us, or participation in any loyalty programme.

6.7 CORRESPONDENCE

Correspondence, communications and messages, including between you and us, and between us and third parties, relating to any booking or booking enquiry, or performance of any contract.

6.8 WEBSITE USAGE INFORMATION

We may collect information about your visits to, browsing of, and use of our website, unless your web browser blocks this. The range of data we collect will depend on how you interact with our website. This information may include:

  • your IP address (a unique identifier allocated to your computer for your connection to the internet);
  • your computer device details (PC, tablet, smartphone, watch etc.);
  • the make and version of web browser (e.g. Internet Explorer, Firefox, Safari, Opera, Chrome) you are using;
  • your operating system (e.g. Windows, Windows Phone, OSX, iOS, Android, Linux, etc.);
  • your time-zone;
  • your browser plug-ins;
  • any web-page you came from, identified as the referrer web page address by your web browser;
  • cookies (as per our cookie policy);
  • page response times;
  • download error;
  • pages and parts of pages you visit;
  • usage you make of our website, including enquiries and searches undertaken, and registrations for accounts, forums etc.;
  • services and products you viewed;
  • length of visit to website and pages;
  • page interaction information (such as scrolling, keys pressed, mouse clicks, touches, and mouse-overs).

 

This will normally be collected and used anonymously, and aggregated for analysis, with your name and any characteristics identifying you remaining anonymous, but our privacy policy will apply, and it will be treated as your personal data, if this information is in any way linked to you personally. This information may also include:

  • data inputted into forms and fields;
  • registrations for any accounts,
  • forum,
  • feedback mechanism,
  • social functionality,
  • newsletters or other features of our site;
  • usernames and passwords,
  • log-in / out history, and settings;
  • actions taken within any account or other registration, including view and update and changes to settings; and posts to any forum, feedback, review or other social functionality on our website.

 

Such information will be treated as personal data and processed according to this privacy policy.

7. HOW WE COLLECT OR GENERATE YOUR PERSONAL DATA

This section sets out the ways in which we may collect or generate personal data concerning you.

7.1 VISITING OUR WEBSITE

By visiting and using our website, you or your computer may provide personal data. This includes: information which is automatically provided by your browser to our servers; information recorded on our web servers about your interaction with our website and pages viewed; information we capture or place on your computer or generate using cookies or other technologies on our website; and information you input into forms and fields on our website. This is more detailed in our cookie policy.

7.2 DATA YOU PROVIDE

Your personal data will include data you provide (or later amend), whether:

  • from correspondence with you;
  • verbally to us over the phone or in person;
  • by filing in any field or form on a website;
  • by filling in any printed form we provide you with;
  • by email;
  • from documents you provide us with; and
  • from updates to any information you provide to us from time to time

 

This includes when you:

  • register or subscribe for any service, account, members, or loyalty programme,
  • make an enquiry or booking for a holiday or other travel services whether in person, by phone, through our website or otherwise;
  • send us your comments or suggestions;
  • subscribe to any newsletter or other publication;
  • and request sales and advertising information, including brochures.

 

7.3 USER GENERATED CONTENT (UGC)

We may process, information or content provided by you in relation to your feedback or experience on a past, current or future trip with us. We will only use such content and images you have submitted to our social media channels or websites if you have given consent to let Uniworld River Cruises Limited and TTC subsidiary companies process this information in various initiatives. These could include any marketing activities such as:

  • Print materials;
  • on our website;
  • email activities;
  • social posts;
  • images on our trips;
  • provide images to our trade partners to use on their websites, email marketing and other marketing initiatives;
  • make available in our content feeds;
  • we would share imagery in our content feeds, image repositories, via email and share with our trade partners via these methods;
  • any other information provided to us by or in relation to you which concerns you as an individual.

 

7.4 DATA OBTAINED FROM THIRD PARTIES

We may obtain personal data concerning you from third parties, including from:

  • providers of any holidays, accommodation, other travel services which are enquired about or booked, and their intermediaries;
  • credit, fraud, identity and other searches we may undertake, including searches with public records and regulatory and private organisations;
  • any business or organisation you are associated with; from telephone numbers identified by the telephone system when you telephone us.

 

7.5 DATA GENERATED BY US

We and any suppliers or sub-contractors working for us may generate personal data relating to you, including:

  • in connection with responding to and dealing with any enquiry, booking or complaint; or
  • in performing any booking or other contract with you; or
  • through the analysis of your personal data; or
  • data gained from your use of our website according to our cookie policy.

 

We may record telephone calls with you for training and quality purposes.

8. WHAT DO WE USE YOUR PERSONAL DATA FOR?

This section sets out the uses which we make of your personal data and the legal basis on which we rely to do this.

8.1 OPERATE OUR WEBSITE

To operate and provide the search, booking, accounts, review, forums and other services, facilities and functions of our websites. This includes managing any accounts or registrations you have with our websites and making changes to your settings and profile at your request.

8.2 PROVIDE INFORMATION AND RESPOND TO ENQUIRIES

To provide information to you about our website, systems and services, including to respond to booking enquiries and searches for holidays and travel, and to keep you updated generally. We process your data because you ask us to take the relevant steps in order to enter into a contract, or because we perform a service that you asked us to provide.

8.3 BOOKINGS AND OTHER CONTRACTS

To enable you to make bookings, and to fulfil, provide, perform, administer, manage, and enforce all bookings, orders, and other contracts which relate to you (including if you are a passenger in a booking made by someone else), and to process any transactions authorised or made with us which relate to you. We process your data because you ask us to take the relevant steps in order to enter into a contract, or because we perform a service that you asked us to provide.

8.4 PAYMENTS

To collect and make payments due and administer our accounts. This is necessary for the preparation of any contract between us.

8.5 COMMUNICATION WITH CUSTOMERS

To communicate with you concerning any enquiries, bookings, travel services provided, problems and complaints, and to respond to any submissions, enquiries or requests from you. We process your data because you ask us to take the relevant steps in order to enter into a contract, or because we perform a service that you asked us to provide.

8.6 RECORD KEEPING

To keep internal records and maintain reasonable archives, including concerning as to enquiries, bookings, contracts, travel services, and complaints. This is done on the basis of our legitimate interests in ensuring our business is protected or run efficiently, or because we have the legal obligation to do so.

8.7 MANAGE AND IMPROVE OUR BUSINESS

 

  • To analyse, audit, provide, operate, administer, maintain and improve our business, website, systems, and services;
  • to carry out surveys and analyse the results;
  • to run promotions and competitions;
  • to undertake product or customer research/development;
  • to assist us in and help us to improve our sales,
  • editorial, advertising and marketing processes;
  • to carry out other business development and improvement activities; and
  • to provide training to our staff, sub-contractors and suppliers.

 

For example, we may use your personal data to help us profile how our customers generally are using our websites and booking travel services with (or through) us. We may also use this information to ascertain interests so that we can better tailor our business offerings. This is done on the basis of our legitimate interests in ensuring our business to run efficiently.

8.8 DIRECT MARKETING

To carry out direct marketing to you; see section 10.1 for further information.

8.9 ADVERTISING

To report aggregate information concerning usage of our websites to our advertisers. We normally create anonymous statistical data about browsing actions and patterns, and do not identify any individual.

8.10 ANYTHING YOU HAVE SPECIFICALLY CONSENTED TO

For any purpose which we have obtained your consent to. We will do this only where you have a choice whether to consent or not, you have control over that data and you have had to take an affirmative step to give consent on an informed basis. We will ensure that you can withdraw your consent at any time by providing simple mechanisms if you would like to do so.

8.11 CONSEQUENCES OF NOT PROVIDING YOUR DATA

You are not obligated to provide your personal information, however, where the information is required for us to provide you with our services/deliver your products, we may not be able to offer some/all our services without it. Sometimes, providing your data to authorities when you travel is a legal obligation for us.

9. PERIOD FOR RETAINING YOUR DATA

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

If you would like to know more about our data retention policy, please ask us.

10. USE OF YOUR PERSONAL DATA FOR DIRECT MARKETING

We do not use or disclose your personal data for direct marketing purposes unless:

  • we have obtained your consent to do so, such as through an opt-in box on any form or website of ours; and/or
  • you have made a booking with us and there is our legitimate business interest to do so for similar products or services.

 

If you do not want to receive direct marketing activities anymore, you can manage your communications preferences on your online account or unsubscribe by following the link at the end of every of our electronic communications.

In addition to data protection law if we use your personal information for direct marketing purposes we may also be subject to additional rules that regulate direct marketing, such as the EU Privacy and Electronic Communications Directive 2009/136/EC. The term “direct marketing” essentially means direct marketing material or advertising at a particular individual.

10.1 DIRECT MARKETING BY US

We will use your personal data to send you marketing information (including adverts and details of promotions) about travel services:

  1. offered by us;
  2. which can be booked with third parties through us;
  3. which can be booked with other companies within our group (i.e. the Travel Corporation Group); and
  4. offered by third parties selected by us. However, we will not pass any of your details to third parties without your prior and specific consent.

 

Where applicable we will only send you marketing information about the categories of travel services you have selected. Also, we will only contact you in the manner you agreed to (e.g. by email or SMS).

10.2 DIRECT MARKETING BY THIRD PARTIES

From time to time we may disclose your contact details (i.e. your name, email address, postal address, telephone number, mobile number, fax number and preferences) to:

  • other companies within our The Travel Corporation, which are bound by the same requirements set in this privacy policy; and
  • other companies which offer services that may enhance your travel experience or be able to help you to finalise your travel arrangements (“third parties”). Such third parties may then contact you directly with marketing information about services and products offered by them. Such third parties are not part of The Travel Corporation and are not bound by this privacy policy. However, we ensure that our partners will only contact you in the manner you agreed to (e.g. email, text) when providing your consent.

 

10.3 WITHDRAWING FROM DIRECT MARKETING

You are free to stop receiving marketing information from us at any time by contacting us as detailed in this privacy notice or by following the instructions set out in our marketing communications. If you email us to withdraw your consent, it would be helpful if you could insert the word “Unsubscribe” as the subject heading.

When you elect to stop receiving marketing information we will, from that point onwards, not share your information further with any other third parties.

You are also free, at any time, to notify any third party to whom we have previously passed your contact details to, that you no longer wish to receive marketing communications from them.

11. DISCLOSURE OF YOUR PERSONAL DATA TO THIRD PARTIES

We transfer your personal data to third parties in the following circumstances:

11.1 CREDIT CHECKS ETC.

We may disclose your personal data to third parties (including intermediaries) as necessary to carry out any checks regarding your financial standing. The identities of these parties may change from time to time. They may include credit reference agencies and other companies for use in credit decisions, for fraud prevention and to pursue debtors.

11.2 BOOKINGS AND PERFORMANCE OF CONTRACTS

We disclose your personal data to third parties (including intermediaries) as necessary to deal with any booking enquiry being made by or for you, to make any booking requested by or for you, to perform and administer any booking for you or other contract with or in respect of you. This may include:

  • to apply for visas on your behalf;
  • to collect payments to be made by you;
  • to investigate and respond to complaints; and
  • to enforce any booking or other contract with you.

 

Such third parties may include any suppliers or sub-contractors and their agents (e.g. airlines, coach, ferry or train companies, hoteliers, hire companies, cruise companies, tour operators etc.). The identities of these parties may change from time to time and are engaged so we can provide our services to you. We ensure that these third parties carry their tasks with the same level of protection on your personal data that you will expect from us.

11.3 SUPPLIERS OF TRAVEL AND OTHER SERVICES

We may disclose your personal data to any third party (e.g. supplier, contractor sub-contractor) we make any enquiries with concerning or engage or sub-contract to perform any booking or other contract, including to provide any travel, tour or other products or services we have agreed to provide to you in order to perform our contract with you.

We may disclose your personal data to any supplier with whom we make any enquiry concerning or book any travel or other products and services for you as agent (whether as agent for you, someone representing you, or the supplier), such as a tour operator. Details of any third-party tour operators or other third parties who will be responsible for or supply you with the travel services booked or enquired about, may be obtained from us on request, and may be stated in any tour or other brochure provided by us.

11.4 INSURANCE

If any application is made through us for any travel or other insurance to cover you, we will pass your personal data on to the insurer. Information provided by you may be put on to a register of claims and shared with other insurers to prevent fraudulent claims.

11.5 BUSINESS FUNCTION OUTSOURCING

Where we use third parties to host, provide, operate or supply any part of our websites, databases, systems, business, or services, or carry out on our behalf any of our business functions or actions (including sending mail, processing payments, providing marketing assistance, providing customer and advertising analysis, and providing customer services), then we may provide your personal data to them as required for use for or processing as part of those purposes. We ensure that these third parties treat your personal data with the same level of care and duty as us.

11.6 PUBLIC FORUMS ETC.

Where any facility on our website is clearly designed to make certain of your personal data public (e.g. posts you make to any public forum or reviews facility), then any personal data you provide in relation to that forum or other facility, which is provided in circumstance where it is clear that it is intended to be published, will be disclosed to the public accordingly, subject to moderation by us and to the terms of this privacy policy.

11.7 LEGAL REQUIREMENTS

We may supply personal data to a government authority or regulator where required to:

  • comply with a legal requirement;
  • for the administration of justice or when required by a public enforcement body; or
  • for the purposes of customs, visas and immigration.

 

We may disclose your personal data where otherwise required by or permitted by law.

11.8 DIRECT MARKETING BY THIRD PARTIES

We may disclose your personal data to third parties to carry out direct marketing to you, where you have given your prior consent. Please refer to the direct marketing section above for more information.

11.9 BUSINESS CUSTOMERS WHO ARE BUSINESSES (NOT INDIVIDUALS)

If you are a business or organisation (“Business Customer”), and we are holding personal data of any authorised representative (such as an employee agent, employee, officer, owner, partner, or director), then we may disclose to them that personal data.

If a Business Customer is making a booking or booking enquiry on behalf of an individual, with that person’s authority, then we may disclose to our Business Customer that individual’s personal data as reasonably required in connection with such booking or enquiry, or the subsequent performance of or payment for any booking made.

11.10 BUSINESS ACQUIRERS

If our business is ever transferred to a third party, then your personal data will be transferred to the acquirer to enable them to continue our business. We will ensure that the acquirer is bound by terms similar to this privacy policy to protect your personal data.

12. HOW THIRD PARTIES WILL HANDLE YOUR PERSONAL DATA

Where we provide your personal data to a third party one of the following two circumstances will apply:

12.1 PROCESSING ON OUR BEHALF

In some cases, your personal data may be held and otherwise processed by others on our behalf. We have not included the names of our service partners as these will change over time. We will remain responsible for what they do with your personal data, and your personal data will only be held and processed by them in accordance with our instructions and this privacy policy. The sharing of your data is necessary for the performance of any contract with you and for the efficient provision of our services.

12.2 PROCESSING ON THEIR OWN ACCOUNT

In other cases, your personal data may need to be provided to them to be held and processed by them in their own right and on their own account. In such case, they will have their own responsibility for your personal data, subject to their own privacy policy, and we will not be responsible for what they do with it following disclosure. This will only be done to perform the contract. When this happens, you will be informed by the third party and they will provide their privacy policy to you.

13. LOCATION OF YOUR PERSONAL DATA

We (and any affiliate, subcontractor or other person processing your personal data on our behalf) may transfer, store and otherwise process your personal data anywhere within the European Economic Area (“EEA”).

We will only send your personal data outside the EEA to companies either within our group or to parties with whom we have a contract based on the Standard Contractual Clauses as published by the European Commission. We ensure your personal data is protected by requiring all our group companies to follow the same rules when processing your personal data. This means within our group and for those other organisations with whom we have contracts we ensure that we have in place adequate safeguards in respect of such transfers outside the EEA. You can find out about what adequate safeguards these are by contacting us using the details provided in Section 16 of this privacy notice.

14. KEEPING YOUR DATA SECURE

14.1 OUR SECURITY MEASURES

We take appropriate technical and organisational measures to secure your information and to protect it against unauthorised or unlawful use and accidental loss or destruction, including:

  • only sharing and providing access to your information to the minimum extent necessary, subject to confidentiality restrictions where appropriate, and on an anonymised basis wherever possible;
  • using secured servers to store your information;
  • verifying the identity of any individual who requests access to information prior to granting them access to the information; and
  • using Secure Sockets Layer (SSL) and Transport Layer Security (TLS) software or other similar encryption technologies to encrypt your personal and payment transactions.

 

Unfortunately, transmission of information over email is not secure, and if you submit any information to us over the internet by email we will do our best to protect your personal data and have contractual processes in place with our service providers to do this. Once we have received your information, we will use relevant procedures and adequate security measures to prevent unauthorised access.

For your own privacy protection, we encourage you to maintain anti-virus and other malware protection software on your computers and other devices, and to maintain your own measures to protect your personal data. Please do not include sensitive personal data in any emails you may send to us, including payment card information.

We also encourage you to be careful about who you give personal data to. We never contact you to ask you for your payment card information, or sensitive personal data such as passport numbers or log-in details, and we will only ask you for such information in person or through our website, or by telephone in connection with a booking you are making or have made. Please let us know if you someone purports to contact you in our name.

15. YOUR RIGHTS

You have certain rights under data protection laws, which we summarise below. If you contact us about these rights, we may ask for proof of your identity before we act on any request, and we may refuse to act if you do not provide this or your identity is not established by you. This is to ensure that your data is protected and kept secure. More information about your rights and our obligations can be found on the website of the UK Information Commissioner's Office: www.ico.org.uk.

To exercise any of your rights below, please contact us as per the contact details provided in Section 16. You can also exercise some of these rights directly through our online form at ttc.com/personal-data-request.

You may request we tell you whether we are processing personal data about you, to tell you what personal data we are processing, for what purposes, from which sources we have collected it, who we disclose it to and to provide you with a copy of your personal data that we hold. We will act within one month after receiving a valid request (i.e. when we will have been able to identify you as the data subject). If your request is complex, or if we have a high volume of requests, we may extend this period for two additional months. We will advise you if this is the case.

The law does allow us, in certain cases, to refuse to act upon your request or to charge a reasonable administration fee, if we estimate that the request is manifestly unfounded or excessive. We will advise you at the time if this is the case along with your possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.

15.1 RECTIFICATION

You have the right to have your personal data amended if it is inaccurate or incomplete.

15.2 RIGHT TO OBJECT

You have the right to object to the use of your personal information for direct marketing or where we use it on the basis that we say we have a legitimate interest in using it.

15.3 ERASURE

You have the right to have your personal information deleted or removed in the following circumstances:

  • The data is no longer necessary for the purpose for which it was originally collected or otherwise processed;
  • Where you withdraw your consent, where consent was used as the legal basis for processing;
  • Personal data has been unlawfully processed;
  • When you object to the processing and we have no overriding legitimate interest for continuing the processing;
  • Erasure is required for compliance with a legal requirement; or
  • Data has been collected in relation to the offering of online services to a child.

 

When a request for erasure is valid, we will take reasonable steps to inform third parties which are processing the personal data that you have requested us to delete.

We have the right to refuse to act on a request of erasure if the data is necessary for:

  • Exercising the right of freedom of expression and information;
  • Compliance with a legal obligation; or
  • The establishment, exercise or defence of legal claims.

 

15.4 PORTABILITY

You have the right to receive your personal data which you have provided to us, in a structured, commonly used and machine-readable format and to transmit those data to another controller, when:

  • the processing is based on consent or on a contract; and
  • the processing is carried out by automated means.

 

15.5 RESTRICT PROCESSING

You have the right to obtain from us the restriction of processing of your personal data where one of the following applies:

  • You contest the accuracy of the personal data, for a period enabling us to verify the accuracy of the personal data;
  • The processing is unlawful, and you oppose the erasure of the personal data and request the restriction of their use instead;
  • We no longer need the personal data for the purposes of the processing, but the data is necessary for you for the establishment, exercise or defence of legal claims; or
  • You have objected to processing pending the verification whether our legitimate grounds override yours.

 

Where the processing of your personal data is restricted, at the exception of storage, we will only process your personal data with your consent, for the establishment, exercise or defence of legal claims, for the protection of the rights of another individual or organisation, or because we are legally required to do so.

We will inform you before the restriction of processing is lifted.

15.6 RIGHT TO WITHDRAW YOUR CONSENT

You are free to withdraw your consent at any time, where we rely on your consent as a legal basis for processing. Please contact us using the details outlined in Section 16 of this policy. See also Section 10.3 for details as to how to object to our direct marketing communications.

15.7 COMPLAINTS TO THE DATA PROTECTION AUTHORITY

The laws we comply with are regulated by the Information Commissioner's Office: www.ico.org.uk. In addition to your rights above, it is open to you, if you have a complaint or concern, to seek assistance from this supervisory authority who has powers to compel us to comply with applicable laws and fine us for non-compliance. However, before you do so, we would hope that you will contact us first to discuss any complaint or concerns you have. You can contact us using the details provided in Section 16 of this privacy notice.

15.8 CHANGES TO THIS PRIVACY POLICY

We may change this privacy policy at any time and from time to time without notice to you, including by publishing a new version on our website. You should check this privacy policy for updates each time you visit our website to be sure that you are aware of any changes. You should check the top of the document to see the latest version in force. Any change will be prospective only, and we will not make any changes that have retroactive effect unless legally required to do so.

Our privacy policy is subject to the law of England and Wales and disputes can be determined by the courts of England and Wales.

16. CONTACTING US

If you have any questions about our privacy policy or about how we process your personal data, including any requests or complaints, please contact us either by email to webmaster@uniworld.com, telephone on 0808 168 9231 or by post to Uniworld River Cruises Limited, Attention: Webmaster, Travel House, Rue du Manoir, St Peter Port, Guernsey, Channel Islands GY1 2JH.

17. ABOUT US

This is the privacy policy of Uniworld River Cruises Limited (referred to as "we", "us" or "our"). We are incorporated under the laws of England and Wales. Our incorporation number is 58915 and our registered office address is Travel House, Rue du Manoir, St Peter Port, Guernsey, Channel Islands GY1 2JH. We are a member of ABTA (Y6200) and are licensed by the Civil Aviation Authority (10975).

18. COPYRIGHT NOTICE

This document, and all content of our websites, is Copyright © 2019 Uniworld River Cruises Limited. ALL RIGHTS RESERVED.

END OF DOCUMENT

The Red Carnation Hotels Privacy Policy

Evan Evans Tours Privacy Policy