Introduction
The purpose of this policy is to outline how Once in a Lifetime Holidays has established measures to protect your privacy and information rights. We only ask for personal information when we truly need it to provide a service to you. We collect it by fair and lawful means, with your knowledge and consent. We also let you know why we’re collecting it and how it will be used.
Your Rights
We recognise that you have rights as a ‘data subject’, and that we have an obligation to uphold these. This privacy notice aims to outline how we maintain these rights. In particular, it outlines:
When we collect personal information about you;
What types of personal information we collect;
Why we collect it;
How we keep it safe;
Who we share personal information with; and
Your rights and choices about the personal information that we hold.
Right to be informed
This encompasses the obligation for us to be transparent in how we collect and use your personal data.
Right of access
You have the right to access your personal data and supplementary information.
Right to rectification
If the information we hold on you is inaccurate or incomplete, you can request we correct this.
Right to erasure
You can request we delete or remove personal data where there is no compelling reason us to continue processing.
Right to restrict processing
You have the right to request we cease processing your data, if:
– You consider it inaccurate or incomplete;
– Where you object to processing and we are considering whether we still have a legitimate interest to process it.
– Where we don’t need the data for the original reason we collected it, but may need it to support a legal claim.
Right to data portability
Where you have consented to our processing your data, or where the processing is necessary for us to deliver a contract, you can request a copy of that data be provided to a third party in electronic form.
Right to object
You have the right to object to our processing under certain circumstances. For example, you can object to:
– direct marketing (including profiling); and
– processing for purposes of scientific/historical research and statistics.
Rights relating to automated decision making including profiling
Where we apply automated decision making, we must
– give you information about the processing;
– introduce simple ways for you to request human intervention or challenge a decision;
– carry out regular checks to make sure that our systems are working as intended.
Information related to automated decision making is contained later in this notice.
When we collect personal information about you
We collect personal information about you whenever you make a booking or otherwise interact with us in person or via telephone, our websites, email or other contact methods (whether directly with us or through agents acting on our behalf).
The types of personal data we collect and why we collect it
Personal and contact details
Why we collect it
– To be able to make and fulfil your booking.
– To communicate with you about your booking.
– For keeping in touch with marketing initiatives.
How we process this
– All information stored digitally is stored on machines that are password protected and servers that encrypt data and are protected by the latest SSL security technology.
– All information stored in paper format is kept in secure file storage which only authorised personnel are able to access.
Passport information
Why we collect it
– To complete required Advance Passenger Information or Electronic Travel Authorisations.
– To arrange visas.
– To obtain boarding cards.
How we process this
When sharing information with suppliers, it is always transmitted through secure communication channels and websites protected by the latest SSL security technology.
Information about medical conditions
Why we collect it
– So that suppliers can provide assistance / provide special arrangements.
– To be able to arrange assistance in a medical or other emergency.
– So that travel insurers can provide cover.
How we process this
When sharing information with suppliers, it is always transmitted through secure communication channels and websites protected by the latest SSL security technology.
Ad-hoc information about, for example, interests, special occasions, special requests
Why we collect it
To arrange or provide services tailored to your requirements.
How we process this
When sharing information with suppliers, it is always transmitted through secure communication channels and websites protected by the latest SSL security technology.
Payment information
Why we collect it
To be able to process your payment.
How we process this
All payments are made securely through a payment processing portal that adheres to the latest PCI DSS compliance policies.
Information about past and current bookings
Why we collect it
– To arrange or provide services tailored to your requirements.
– To communicate in a relevant way.
– For purposes of accounting, reporting, analysis and regulatory disclosures.
How we process this
– All information stored digitally is stored on machines that are password protected and servers that encrypt data and are protected by the latest SSL security technology.
– All information stored in paper format is kept in secure file storage which only authorised personnel are able to access.
Correspondence, including complaints
Why we collect it
To assist customers in relation to their travel arrangements and to handle complaints.
How we process this
– All information stored digitally is stored on machines that are password protected and servers that encrypt data and are protected by the latest SSL security technology.
– All information stored in paper format is kept in secure file storage which only authorised personnel are able to access.
Call Recordings
Why we collect it
– Staff Development / Identifying errors and issues.
– Evidence of what was said.
How we process this
– All information stored digitally is stored on machines that are password protected and servers that encrypt data and are protected by the latest SSL security technology.
– All information stored in paper format is kept in secure file storage which only authorised personnel are able to access.
Who do we share your personal information with?
Your personal information is shared with our Suppliers – in order to provide products or services requested by you we share personal data with suppliers of your travel arrangements, including but not exclusively airlines, hotels, transfer companies and insurance providers. In many cases such supplier will themselves separately be controllers of your personal data.
Your personal information is shared within The Travel Network Group where it is necessary for them to be involved with the services you have requested.
Your personal information is shared with payment processing companies to process your payment.
Your personal information is shared with regulatory authorities – it may be necessary to disclose personal data for immigration, border control, security and anti -terrorism purposes or any other purposes required by regulatory authorities.
It is often necessary for us to send your personal information outside the European Economic Area to fulfil your travel arrangements. This is because the suppliers providing your travel services are located around the world, also your personal information may need to be transferred to border control and immigration outside of the EEA. This may involve sending your data to countries where under their local laws you may have fewer legal rights.
Our legal basis for using your personal information
We will only process your personal information where we have a legal basis to do so. Depending on the circumstances, the legal basis will almost always be one or more of the following:
- So that we can make and fulfil your booking or otherwise perform our contract with you;
- Because it is in our legitimate interests to use your personal information to operate and improve our business as a travel agency;
- To comply with a legal obligation;
- To protect the vital interests of you or another person; or
- Because you have consented to our using your information for a particular purpose.
How do we keep your personal information safe?
Protecting the confidentiality and integrity of your personal data is a responsibility that we take seriously at all times. Once in a Lifetime Holidays applies technical and organisational security measures in line with industry good practices such as ISO 27001 to help to keep personal data secure against unauthorised or unlawful processing, and against accidental loss, destruction or damage. All of our team have undertaken specific GDPR training.
Once in a Lifetime Holidays has achieved the Cyber Essentials accreditation.
Marketing Communications
When you book or register with us we will ask if you would like to receive marketing communications. If you have previously agreed to receive marketing communications we may send you relevant offers and news about our products.
You can change your marketing preferences by contacting us in any way or by using the ‘unsubscribe’ link in our marketing emails.
We will respect your choice as to what communications you wish to receive and the methods by which you are sent them.
Website Cookies
When using our website you may opt in to saving your name, email address and other personal information in cookies. These are for your convenience so that you do not have to fill in your details again when you use our website. These cookies will last for one year.
We may also set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
Embedded content from other websites
Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.
Our website may link to external sites that are not operated by us. Please be aware that we have no control over the content and practices of these sites, and cannot accept responsibility or liability for their respective privacy policies.
Data Retention
Once in a Lifetime Holidays retains information for seven (7) years from our point of last contact. We hold this information to support our legal and regulatory requirements. If you object to this retention, please contact us – details are provided in the ‘Contact’ section.
We will keep your personal data for only as long as it is necessary for the purposes set out in this privacy notice. For example, after travel we will keep the information related to your booking so that we can respond to any complaints and fulfil our record keeping obligations. After this time, we will securely erase or anonymise personal data.
Your rights and choices about the personal information that we hold
You can ask us for a copy of the information that we hold about you.
You can also ask us to correct any information which you don’t think is correct or to delete the information we hold about you.
To comply with these requests we may need you to confirm your identity by providing documents or additional information.
You have the right to lodge a complaint about how we have handled your personal information with the Information Commissioner’s Office (ICO).
Contact Details
We recognise that you may have questions on how we process and/or store your data, or may want to change either the data we hold on you or how we communicate with you in the future.
If you have given consent for processing, you are free to withdraw that consent. To let us know email
admin@onceinalifetimeholidays.co.ukIf you have any questions in respect of this notice, or would like to exercise your rights as a data subject (for example, to correct data or to exercise your right to access):
Email us:
admin@onceinalifetimeholidays.co.ukWrite to us: Data Protection Manager, Once in a Lifetime Holidays, 2 Taborsfield, Stebbing Road, Bardfield Saling, Essex, CM7 5DY.
If you are unhappy that we have responded to your query adequately, of if you have a further complaint, The Information Commissioner’s Office can be contacted by visiting
https://ico.org.uk/global/contact-us/