GDPR Compliance
Your data protection rights under UK GDPR
Last updated: January 2024
1. Our Commitment to Data Protection
Comet Oryx Travel Agency is committed to protecting your personal data and respecting your privacy rights in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This page provides information about your rights under data protection law and how we comply with these regulations.
2. Data Controller
Comet Oryx Travel Agency is the data controller responsible for your personal data. Our contact details are:
Comet Oryx Travel Agency
47 Grey Street
Newcastle upon Tyne, NE1 6EE
Email: [email protected]
3. Your Rights Under UK GDPR
Under UK data protection law, you have the following rights:
Right to Be Informed
You have the right to be informed about how we collect and use your personal data. We provide this information through our Privacy Policy and this GDPR page.
Right of Access
You have the right to request a copy of the personal data we hold about you. This is commonly known as a Subject Access Request (SAR). We will respond to your request within one month.
Right to Rectification
You have the right to request that we correct any personal data that is inaccurate or incomplete. We will respond to your request within one month.
Right to Erasure
You have the right to request that we delete your personal data in certain circumstances, including:
- When the data is no longer necessary for the purpose it was collected
- When you withdraw consent (where consent was the legal basis)
- When you object to processing and there is no overriding legitimate interest
- When the data has been unlawfully processed
Please note that we may need to retain certain data for legal or contractual obligations.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to its processing.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.
Right to Object
You have the right to object to the processing of your personal data where we are relying on legitimate interests as the legal basis. We will stop processing unless we can demonstrate compelling legitimate grounds.
Rights Related to Automated Decision Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. We do not currently use automated decision-making in our services.
4. Exercising Your Rights
To exercise any of your rights, please contact us using the details provided above. We may need to verify your identity before processing your request. We will respond to your request within one month, although this period may be extended by two months for complex requests.
There is no fee for exercising your rights in most cases. However, we may charge a reasonable fee for manifestly unfounded or excessive requests.
5. Legal Bases for Processing
We process your personal data on the following legal bases:
- Contract: Processing necessary to fulfil travel bookings and provide our services
- Legal Obligation: Processing required to comply with laws and regulations
- Legitimate Interests: Processing necessary for our legitimate business interests, such as improving services and fraud prevention
- Consent: Processing based on your explicit consent, such as for marketing communications
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. Our retention periods are based on:
- Contractual requirements
- Legal and regulatory obligations
- Legitimate business needs
Typically, booking records are retained for seven years for accounting and legal purposes.
7. International Data Transfers
When your travel arrangements involve destinations outside the UK, we may need to transfer your personal data to travel providers in those countries. We ensure appropriate safeguards are in place, such as:
- Adequacy decisions by the UK Government
- Standard contractual clauses approved by the UK Information Commissioner
- Other appropriate legal mechanisms
8. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Secure storage systems
- Staff training on data protection
- Access controls and authentication
- Regular security reviews
9. Data Breaches
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours and, where required, inform affected individuals without undue delay.
10. Complaints
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk
We would appreciate the opportunity to address your concerns before you approach the ICO. Please contact us first so we can try to resolve the issue.
11. Updates to This Page
We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated revision date.