Privacy Policy.
How we collect, hold and use your personal data. Plainly explained, in line with the UK GDPR and the Data Protection Act 2018.
1. Who We Are
TravelinBusiness is a trading name of Rizka Travel Limited, a company registered in England and Wales (Company No. 10763351), with our registered office at 40 Neeld Crescent, London NW4 3RR. We hold ATOL licence No. 12118, issued by the Civil Aviation Authority, and are a registered IATA TIDS member (TIDS No. 96108924).
Rizka Travel Limited also trades as HighStreet Holidays, a luxury travel brand offering bespoke flight-inclusive holiday packages. Both TravelinBusiness and HighStreet Holidays operate under the same parent company, Rizka Travel Limited, and share the same Data Controller, legal entity, ATOL licence and IATA TIDS membership.
Rizka Travel Limited is the Data Controller for all personal data collected through TravelinBusiness and its associated brands. We are registered with the Information Commissioner's Office (ICO) as a Data Controller.
If you have any questions about this Privacy Policy or how we handle your personal data, please contact us at:
- Email: info@travelinbusiness.co.uk
- Phone: 0203 322 7866
- Post: Rizka Travel Limited, 40 Neeld Crescent, London NW4 3RR
2. Our Commitment to Your Privacy
At TravelinBusiness, we understand and respect the importance of your privacy. This Privacy Policy explains how we collect, use, store and protect your personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We are committed to being transparent about how we use your data and to ensuring that your personal information is handled securely and responsibly at all times.
3. What Personal Data We Collect
In operating our website and providing our travel services, we may collect and process the following data about you:
- Full name and contact details, including postal address, telephone number and email address
- Passport details, nationality and date of birth (required for flight bookings)
- Payment information (processed securely via our payment provider; we do not store full card details)
- Travel preferences, dietary requirements and accessibility or health needs
- Details of your visits to our website, including traffic data, location data, web logs and other communication data
- Information you provide when completing forms on our website, subscribing to our newsletter, or making a booking
- Records of correspondence when you contact us by phone, email or online
Some information we collect may be considered special category (sensitive) personal data under UK GDPR, such as health or accessibility information. We will only collect and process such data where we have your explicit consent or where it is strictly necessary to fulfil your travel arrangements.
4. How We Collect Your Data
We collect personal data directly from you in the following ways:
- When you make a booking or enquiry with us
- When you subscribe to any newsletter or marketing communications we may offer
- When you register an account with us
- When you contact our customer services team by phone, email or online
- When you visit and interact with our website (via cookies and analytics tools)
We may also receive data that has been collected by third parties, such as airline and hotel booking systems, in connection with your travel arrangements. All such data is handled in accordance with this Policy.
5. Lawful Basis for Processing
Under UK GDPR, we must have a lawful basis for processing your personal data. Depending on the purpose, we rely on the following:
- Contract: To fulfil your booking and provide the travel services you have requested
- Legal obligation: To comply with legal requirements, including those relating to ATOL protection and financial regulations
- Legitimate interests: To improve our services, manage our business operations and prevent fraud
- Consent: For marketing communications and the use of non-essential cookies — you may withdraw consent at any time without affecting the lawfulness of prior processing
6. How We Use Your Personal Data
We use your personal data for the following purposes:
- To process and manage your travel bookings and arrangements
- To communicate with you about your booking, including confirmations, updates and notifications
- To respond to enquiries and customer service requests
- To comply with our legal obligations, including ATOL protection requirements
- To process payments securely via our payment provider
- To send you marketing communications about special offers, products and services — only where you have consented or where we have a legitimate interest to do so
- To improve our website, products and services through analytics and feedback
- To detect and prevent fraud or other unlawful activity
We will never sell your personal data to third parties.
7. Sharing Your Personal Data
We may share your personal data with the following categories of third parties, only where necessary and on a need-to-know basis:
- Airlines, hotels, cruise lines and other travel suppliers required to fulfil your booking
- Payment processors and financial institutions for secure payment handling
- Technology and IT service providers who support our website and booking systems
- Other trading brands within Rizka Travel Limited (including HighStreet Holidays) where relevant to your booking or enquiry
- Legal and regulatory authorities, including the Civil Aviation Authority in connection with our ATOL obligations, where required by law
We do not share your personal data with third-party marketers without your explicit consent. Where we engage third-party processors, we ensure appropriate data processing agreements are in place in line with UK GDPR requirements.
8. International Data Transfers
Some of your personal data may be transferred to, or processed in, countries outside the United Kingdom — for example, where your travel arrangements involve international suppliers. Where such transfers occur, we ensure appropriate safeguards are in place in accordance with UK GDPR, including the use of UK International Data Transfer Agreements (IDTAs) or reliance on UK adequacy regulations where applicable.
9. Data Retention
We retain your personal data only for as long as is necessary for the purposes for which it was collected, and in accordance with our legal obligations. As a general guide:
- Booking and financial records are retained for a minimum of 7 years to comply with ATOL and financial regulations
- Marketing preferences and consent records are retained until you withdraw consent or request erasure
- Enquiry records (where no booking was made) are retained for up to 12 months
- Website usage and analytics data is retained for up to 26 months
After the applicable retention period, your data is securely deleted or anonymised.
10. Your Rights Under UK GDPR
You have the following rights in relation to your personal data:
- Right of access: You may request a copy of the personal data we hold about you (a Subject Access Request)
- Right to rectification: You may ask us to correct any inaccurate or incomplete personal data
- Right to erasure: You may ask us to delete your personal data where there is no compelling reason for us to continue processing it
- Right to restrict processing: You may ask us to limit how we use your data in certain circumstances
- Right to data portability: You may request your data in a structured, commonly used and machine-readable format
- Right to object: You may object to processing carried out on the basis of legitimate interests, or to direct marketing at any time
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, please contact us at info@travelinbusiness.co.uk. We will respond within one calendar month of receiving your request. There is no charge for exercising your rights in most circumstances.
If you are dissatisfied with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at www.ico.org.uk or by calling 0303 123 1113.
11. Website Security & Cookies
We take the security of your personal data seriously and use a range of technical and administrative measures to protect it. All data transmitted via our website is encrypted using SSL/TLS technology.
Our website uses cookies to improve your browsing experience and help us understand how visitors use our site. For full details of the cookies we use and how to manage your preferences, please see our Cookie Policy, available on our website.
12. External Links
Our website may contain links to third-party websites. This Privacy Policy applies only to the TravelinBusiness website and our services. We are not responsible for the privacy practices of third-party sites and encourage you to read their privacy policies before providing any personal data.
13. Monitoring & Call Recording
To ensure quality, accuracy and security, we may monitor and/or record telephone calls and customer interactions. All recordings are stored securely and remain the sole property of Rizka Travel Limited. Recordings are used solely for training, quality assurance and dispute resolution purposes.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the law or our data practices. We encourage you to review this Policy periodically. The date of the most recent revision is shown at the top of this document. Continued use of our services following any changes constitutes your acceptance of the updated Policy.
15. Contact Us
For any questions, concerns or requests relating to this Privacy Policy or your personal data, please contact us:
- Email: info@travelinbusiness.co.uk
- Phone: 0203 322 7866
- Post: Rizka Travel Limited, 40 Neeld Crescent, London NW4 3RR
Rizka Travel Limited · Company No. 10763351 · ATOL No. 12118 · IATA TIDS No. 96108924