Data Privacy Policy
North & South Travel Limited is committed to protecting your personal data. This policy explains how we collect, use, and safeguard information when you book flights, hotels, and travel services through our platform. We comply with applicable data protection laws and use your data solely for processing bookings, improving services, and communicating travel updates. Your privacy and security are our priority.
NORTH AND SOUTH TRAVEL LIMITED
GLOBAL DATA PRIVACY POLICY
Document Reference: NST-POL-PRIV-001
Version: 3.1
Effective Date: August 15, 2026
Governance Scope: Global Operations (ODPC & GDPR Compliant)
1. Executive Statement & Scope
North and South Travel Limited (“Company”, “We”, “Us”, or “Our”) is committed to maintaining the highest standards of data privacy, security, and integrity across all global operations. As an international travel management and tour operator, We collect, store, and process Personal Data from travelers, corporate clients, contractors, vendors, and employees.
This Data Privacy Policy ("Policy") sets out the principles and operational standards governing how Personal Data is collected, processed, transferred, and stored by North and South Travel Limited. This Policy applies to all operations, web platforms, booking systems, mobile applications, and personnel across all operating regions.
This Policy is formulated to ensure strict compliance with:
-
The Office of the Data Protection Commissioner (ODPC) under the Kenya Data Protection Act, 2019 (DPA) and its accompanying Regulations.
-
Annual ODPC Registration: North and South Travel Limited is fully registered with the Office of the Data Protection Commissioner (ODPC) and maintains its registration annually in accordance with applicable Kenyan data protection requirements.
-
The European Union General Data Protection Regulation (EU GDPR) 2016/679 and the UK General Data Protection Regulation (UK GDPR).
2. Roles & Governance Structure
2.1 Data Controller vs. Data Processor Roles
North and South Travel Limited operates in multiple capacities under applicable privacy law:
-
Data Controller: When determining the purpose and means of processing personal data for direct retail clients, employees, website visitors, and marketing leads.
-
Data Processor: When fulfilling corporate travel arrangements on behalf of enterprise clients under a formal Data Processing Agreement (DPA).
2.2 Data Protection Officer (DPO)
North and South Travel Limited has appointed a designated Data Protection Officer (DPO) to oversee data protection compliance, serve as the point of contact for the ODPC and EU/UK supervisory authorities, and act as the liaison for Data Subjects exercising their legal rights.
DPO Contact Details:
-
Attn: Data Protection Officer
-
Address: North and South Travel Limited HQ, Nairobi, Kenya
-
Email:
dpo@northandsouthtravel.com/privacy@northandsouthtravel.com
3. Core Data Protection Principles
North and South Travel Limited adheres strictly to the fundamental principles of data privacy outlined in both the ODPC framework and the GDPR:
┌────────────────────────────────────────────────────────────────────────┐
│ DATA PROTECTION PRINCIPLES │
├──────────────────┬───────────────────┬─────────────────────────────────┤
│ Lawfulness, │ Purpose │ Data │
│ Fairness & │ Limitation │ Minimization │
│ Transparency │ │ │
├──────────────────┼───────────────────┼─────────────────────────────────┤
│ Accuracy & │ Storage │ Integrity & │
│ Currency │ Limitation │ Confidentiality (Security) │
└──────────────────┴───────────────────┴─────────────────────────────────┘
-
Lawfulness, Fairness, and Transparency: Data is processed lawfully, fairly, and in a transparent manner in relation to the Data Subject.
-
Purpose Limitation: Data is collected for specified, explicit, and legitimate travel management purposes and not further processed in a manner incompatible with those purposes.
-
Data Minimization: Processing is limited strictly to what is adequate, relevant, and necessary for the provision of travel and logistics services.
-
Accuracy: Personal data is kept accurate and, where necessary, up-to-date. Reasonable steps are taken to erase or rectify inaccurate data immediately.
-
Storage Limitation: Data is kept in a form that permits identification of Data Subjects for no longer than is necessary for specified processing purposes.
-
Integrity and Confidentiality: Data is processed using appropriate technical and organizational measures to ensure security, including protection against unauthorized processing, accidental loss, or destruction.
4. Categories of Data & Lawful Bases for Processing
4.1 Categories of Personal Data Collected
To provide comprehensive travel, visa, accommodation, and ticketing services, We collect the following categories of Personal Data:
-
Identity Data: Full names, title, gender, date of birth, nationality, passport details, visa documentation, and national identification numbers.
-
Contact Data: Email addresses, telephone numbers, physical billing/delivery addresses, and emergency contact details.
-
Financial Data: Payment card details, bank account information, billing records, and transactional history.
-
Travel & Health Data (Sensitive/Special Category): Dietary requirements, medical condition accommodations, accessibility requests, passenger name records (PNR), flight itineraries, and hotel bookings.
-
Technical & Usage Data: IP addresses, browser types, session cookies, geolocation, and platform usage metrics collected via Our booking engines.
4.2 Legal Bases for Processing
Under Section 30 of the Kenya Data Protection Act and Article 6 of the GDPR, North and South Travel Limited processes personal data under the following legal bases:
| Processing Activity | Categories of Personal Data | Lawful Basis (ODPC DPA / EU GDPR) |
|---|---|---|
| Flight, Hotel & Visa Bookings | Identity, Contact, Financial, Passport Data | Performance of Contract |
| Processing Health/Dietary Needs | Special Category Data / Health Records | Explicit Consent |
| Fraud Prevention & System Security | Technical & Transactional Data | Legitimate Interest |
| Regulatory & Tax Reporting | Financial & Identity Data | Legal Obligation |
| Promotional & Direct Marketing | Contact Data, Marketing Preferences | Consent / Opt-In |
5. Cross-Border Data Transfers & International Operations
Due to the nature of global travel management, Personal Data collected by North and South Travel Limited is routinely transferred across international borders to airlines, global distribution systems (GDS, e.g., Amadeus, Sabre), hotel chains, foreign immigration authorities, and overseas ground handlers.
5.1 Transfer Safeguards
International data transfers outside Kenya or the European Economic Area (EEA) are conducted strictly in compliance with Sections 48–50 of the Kenya Data Protection Act and Chapter V of the GDPR. Transfers are executed under the following mechanisms:
-
Adequacy Decisions: Transfers to jurisdictions recognized by the ODPC or European Commission as offering adequate levels of data protection.
-
Standard Contractual Clauses (SCCs): Implementation of approved standard data protection clauses in agreements with international processors and third-party vendors.
-
Necessity for Performance of Contract: Transfers strictly necessary for the fulfillment of travel contracts requested by the Data Subject (e.g., issuing an international airline ticket or securing a foreign hotel reservation).
6. Data Subject Rights
In compliance with both the ODPC and GDPR regulations, Data Subjects whose Personal Data is held or processed by North and South Travel Limited enjoy the following rights:
Your Statutory Rights:
Right to be Informed: The right to receive clear, transparent information regarding how your data is collected and used.
Right of Access: The right to request copies of your Personal Data held by Us.
Right to Rectification: The right to request correction of inaccurate, outdated, or incomplete data.
Right to Erasure ("Right to be Forgotten"): The right to request the deletion of Personal Data where no overriding legal basis for retention exists.
Right to Object & Restrict Processing: The right to object to processing based on legitimate interests or direct marketing.
Right to Data Portability: The right to receive your personal data in a structured, commonly used, and machine-readable format.
Right to Withdraw Consent: Where processing is based on consent, the right to withdraw that consent at any time without affecting prior lawful processing.
Procedure for Exercising Rights
Data Subjects may submit requests to the DPO via privacy@northandsouthtravel.com. We will verify identity prior to fulfilling requests and respond within statutory timeframes (30 calendar days under ODPC guidelines and GDPR regulations).
7. Security Safeguards & Data Breach Protocols
7.1 Technical and Organizational Measures
North and South Travel Limited implements robust technical and organizational security measures to safeguard Personal Data against accidental loss, unauthorized access, destruction, or disclosure:
-
Encryption: End-to-end encryption for data in transit (TLS 1.3) and data at rest (AES-256 standards) across all booking platforms and database storage.
-
Access Control: Role-Based Access Controls (RBAC) and Multi-Factor Authentication (MFA) enforcing strict least-privilege principles for employee access.
-
Network & Systems Security: Continuous threat monitoring, web application firewalls (WAF), regular vulnerability assessments, and penetration testing.
7.2 Data Breach Notification Protocol
In the event of a confirmed or suspected Personal Data breach:
-
Regulatory Notification: North and South Travel Limited will notify the Office of the Data Protection Commissioner (ODPC) within 72 hours of becoming aware of the breach, as mandated by Section 43 of the Data Protection Act. EU/UK supervisory authorities will be notified in accordance with GDPR Article 33 timelines.
-
Data Subject Notification: Where the breach is likely to result in a high risk to the rights and freedoms of affected individuals, Data Subjects will be notified without undue delay, along with recommended remedial actions.
8. Data Retention Policy
Personal Data is retained only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, tax, or regulatory reporting requirements.
-
Travel Booking Logs & Financial Records: Retained for 7 years following contract completion to satisfy statutory tax and financial reporting requirements under Kenyan and international law.
-
Passport & Visa Processing Documents: Erased or anonymized within 90 days of travel completion, unless statutory requirements mandate longer retention.
-
Marketing Preferences Data: Retained until consent is explicitly withdrawn or after 24 months of continuous account inactivity.
9. Policy Maintenance & Regulatory Engagement
This Policy is reviewed annually or whenever significant regulatory changes are issued by the ODPC or European Data Protection Board (EDPB). North and South Travel Limited also maintains its registration with the Office of the Data Protection Commissioner (ODPC) on an annual basis and remains committed to meeting all applicable registration, compliance, and regulatory requirements.
If you have unresolved concerns regarding Our processing of your Personal Data, you have the right to lodge a formal complaint with the relevant regulatory authority:
-
Kenya: Office of the Data Protection Commissioner (ODPC) —
www.odpc.go.ke
-
EU/UK: The relevant national Data Protection Authority (DPA) or Information Commissioner's Office (ICO).