call (0203) 983-6853
schedule Mon–Sat 9am–8pm · Sun 10am–6pm
TalvaniaGlobal

Legal

Privacy Policy

Last updated: 08 August 2026

1. Introduction

Talvania Global Ltd ("we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy explains what personal data we collect about you, how and why we use it, who we share it with, how long we keep it, and what rights you have in relation to it. This policy applies to personal data we collect through our website, over the telephone, by WhatsApp or email, and through any other channel by which you interact with us in connection with an enquiry or Booking for Travel Arrangements. Please read this policy carefully, together with our Terms & Conditions and Cookie Policy, to understand our practices regarding your personal data.

2. Who We Are (Data Controller)

For the purposes of the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018, the data controller responsible for your personal data is Talvania Global Ltd, company number 16526014, registered office at Office 8168, 321-323 High Road, Chadwell Heath, Essex, United Kingdom, RM6 6AX. You can contact us about any privacy matter using the details in Section 25 of this policy.

3. Our Approach to Accountability

We take our data protection obligations seriously and aim to embed good privacy practice into how we operate as a business. This includes maintaining records of our processing activities, carrying out due diligence on the Suppliers and service providers we share data with, providing privacy training to our staff, and reviewing this policy periodically to ensure it accurately reflects our current practices. If you have any questions about how we govern data protection within our business, please contact us using the details in Section 25.

4. Scope of This Policy

This policy applies to all personal data processed by us in connection with our travel agency services, including data relating to prospective customers who make an enquiry, confirmed customers who make a Booking, other passengers named on a Booking, and visitors to our website. It does not cover the privacy practices of third-party Suppliers (such as airlines, hotels, or tour operators), who have their own privacy policies which you should review separately when your data is shared with them in connection with a Booking, as explained in Section 13.

5. Data Minimisation

We aim to collect only the personal data that is reasonably necessary for the purposes described in this policy. Where a field on our website or in our forms is optional, this will generally be indicated; where information is mandatory, this is because we cannot provide the relevant service (for example, processing a Booking or responding to an enquiry) without it. We periodically review the data fields we collect to ensure they remain necessary and proportionate to our stated purposes.

6. Information We Collect Directly From You

When you make an enquiry or a Booking, or otherwise communicate with us, we may collect: your full name, date of birth, gender (where relevant to a Booking, such as passport details), postal address, email address, telephone and WhatsApp number; passport and visa details, frequent flyer or loyalty numbers, and dietary or accessibility requirements where relevant to your Travel Arrangements; payment card details, which are processed securely by our payment providers as described in our Payment Policy; details of the passengers travelling with you (which you confirm you are authorised to provide to us); and any other information you choose to share with us, for example in the free-text field of our contact form, in a WhatsApp message, or in correspondence with our travel consultants.

7. Information We Collect Automatically

When you visit our website, we and our third-party analytics providers may, subject to your cookie preferences, automatically collect certain technical information, including your IP address, browser type and version, device type, operating system, referring website, pages viewed, time spent on each page, and general location data derived from your IP address. This information is collected using cookies and similar technologies, as described in more detail in our Cookie Policy.

8. Information We Receive From Third Parties

We may receive information about you from third parties, including Suppliers who confirm booking details back to us, payment processors who confirm successful or failed transactions, and publicly available sources such as company registries or publicly accessible social media profiles, where relevant to verifying a booking or preventing fraud. Where we receive personal data about you from a third party, we will handle it in accordance with this Privacy Policy and will, where required by law, inform you of the source.

9. Special Category Data

In some cases, arranging your Travel Arrangements may require us to process special category data under UK GDPR, such as information about a medical condition, disability, or (in limited circumstances) religious dietary or observance requirements. We only collect this information where you have chosen to provide it to us in order for us to arrange appropriate assistance or accommodations with a Supplier — our legal basis for processing this data is that it is necessary for reasons of substantial public interest or, more commonly, that you have given your explicit consent by voluntarily providing it to us for this purpose. We treat this data with an enhanced level of confidentiality, restricting internal access to those staff who need it to arrange your Travel Arrangements, and sharing it only with the Suppliers who strictly need it to fulfil your request.

10. How We Use Your Information

We use your personal data for the following purposes and on the following legal bases under UK GDPR: to provide you with quotations and to process your Booking (performance of a contract, or steps prior to entering into a contract, at your request); to communicate with you about your Booking, including confirmations, itinerary changes, and travel advisories (performance of a contract, and our legitimate interest in keeping you informed); to comply with our legal and regulatory obligations, including anti-money laundering, sanctions screening and fraud prevention checks (legal obligation); to send you marketing communications where you have consented to receive them (consent, which you may withdraw at any time); to improve our website and services through analytics (legitimate interest, subject to your cookie preferences); to maintain the security of our website and systems (legitimate interest); and to resolve complaints, defend legal claims and enforce our legal rights (legitimate interest and legal obligation).

11. Marketing Communications

Where you have opted in to receive our newsletter or promotional communications (for example, by submitting your email address through our newsletter sign-up form), we will send you offers, travel inspiration and updates by email. You can unsubscribe at any time by clicking the unsubscribe link included in every marketing email we send, or by contacting us directly using the details in Section 25. Opting out of marketing communications will not affect our ability to send you essential service communications relating to a confirmed Booking, such as itinerary changes or payment reminders.

12. Fraud Prevention and Verification

To protect you, us, and our Suppliers from fraud, we may process your personal data, including payment and booking information, for the purposes of verifying your identity, detecting and preventing fraudulent transactions, and complying with anti-money laundering obligations. This may involve checking information you provide against records held by fraud prevention agencies, payment processors, or publicly available sources. Our legal basis for this processing is our legitimate interest in preventing fraud and our legal obligations under applicable financial crime legislation.

13. Sharing Your Information with Suppliers

In order to arrange your Travel Arrangements, we must share relevant personal data (such as passenger names, dates of birth, passport details and special requirements) with the airlines, hotels, tour operators, insurers and other Suppliers involved in fulfilling your Booking, including our IATA-accredited host travel agency, Brightsun Travel (IATA 3856). Some Suppliers are located outside the UK, and by making a Booking that involves international travel, you acknowledge that your data will necessarily be transferred to the relevant destination country or countries and to Suppliers located there, as is standard and unavoidable practice in the international travel industry.

14. Sharing Your Information with Service Providers

We also share personal data with trusted third-party service providers who perform functions on our behalf, including payment processing, website hosting, email delivery, IT support, and, where enabled, analytics. These service providers are only permitted to use your personal data for the specific purposes for which we engage them, acting on our instructions, and we require them to implement appropriate technical and organisational security measures to protect your data, generally formalised through a written data processing agreement.

15. Business Transfers

If we are ever involved in a merger, acquisition, restructuring, or the sale of all or part of our business or assets, your personal data may be transferred as part of that transaction. Where this happens, we will ensure the receiving party is bound by obligations that are consistent with this Privacy Policy, and we will notify you of any such transfer and of any choices you may have in relation to your data, where required by law.

16. Sharing With Regulators and Law Enforcement

We may disclose your personal data to regulators, law enforcement agencies, courts or other public authorities where we are required to do so by law, where necessary to comply with a legal obligation, or where necessary to establish, exercise or defend our legal rights or those of a third party.

17. International Data Transfers

Where we transfer personal data outside the United Kingdom, whether to a Supplier fulfilling your Travel Arrangements (for example, an overseas hotel or destination management company) or to a service provider, we take steps to ensure an adequate level of protection is applied, including relying on UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, or other appropriate safeguards recognised under UK data protection law, where such mechanisms are required and available. In some cases, the transfer of your data internationally is an unavoidable and necessary part of arranging travel to your chosen destination, and by booking that Travel Arrangement you acknowledge that such a transfer will take place.

18. Data Retention

We retain your personal data for as long as necessary to fulfil the purposes for which it was collected, including to provide our services, to comply with our legal, tax and accounting obligations (which commonly require records to be kept for a minimum of six years from the end of the relevant financial year), to resolve disputes, and to enforce our agreements. Where you have made an enquiry but not proceeded to a Booking, we will retain your details for a reasonable period to allow us to follow up, after which they will be securely deleted or anonymised if no further contact is made. Where you have unsubscribed from marketing, we retain a minimal record of your unsubscribe request to ensure we do not contact you again in error.

19. Data Accuracy

We take reasonable steps to keep the personal data we hold about you accurate and up to date. Because much of the information we hold (such as passport numbers and contact details) is provided directly by you, it is important that you inform us promptly of any changes, particularly before travel, as inaccurate information (for example, a passenger name that does not match a passport) can result in denied boarding or additional Supplier charges, as explained in our Terms & Conditions.

20. Data Security

We implement appropriate technical and organisational measures designed to protect your personal data against unauthorised access, alteration, disclosure or destruction, including encryption of data in transit, access controls limiting staff access to personal data on a need-to-know basis, secure storage of physical and electronic records, and regular review of our security practices. While we take reasonable steps to protect your data, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.

21. Your Rights Under UK GDPR

Subject to certain conditions and exemptions set out in law, you have the right to: request access to a copy of the personal data we hold about you; request correction of inaccurate or incomplete data; request erasure of your data in certain circumstances; request that we restrict our processing of your data; object to our processing of your data, including for direct marketing purposes; request that your data be provided to you, or transferred to another organisation, in a structured, commonly used, machine-readable format (data portability); and withdraw consent at any time where our processing is based on consent, without affecting the lawfulness of processing carried out before you withdrew consent.

22. How to Exercise Your Rights

To exercise any of the rights set out in Section 21, please contact us using the details in Section 25, providing enough information to allow us to identify you and verify your request. We will respond to your request within one calendar month, save where the request is complex, in which case this period may be extended by a further two months, and we will explain why the extension is necessary. There is normally no charge for exercising your rights, unless your request is manifestly unfounded, excessive or repetitive, in which case we may charge a reasonable administrative fee or decline to act on the request, as permitted by law.

23. Automated Decision-Making

We do not use your personal data for any form of solely automated decision-making, including profiling, that produces legal or similarly significant effects concerning you. Any pricing, availability or eligibility decisions relating to your Travel Arrangements involve a human travel consultant.

24. Children's Privacy

Our website and services are intended for use by adults. Where a Booking includes a child or infant travelling as part of your party, we collect the minimum information necessary (such as name and date of birth) to arrange their Travel Arrangements, provided by the Lead Passenger, who confirms they have the authority to provide this information on the child's behalf. We do not knowingly collect personal data directly from children under the age of 16 through independent use of our website, and if we become aware that we have inadvertently done so, we will take steps to delete that information.

25. Cookies

Our website uses cookies and similar tracking technologies to operate correctly, remember your preferences, and, subject to your consent, understand how visitors use our site. Full details of the cookies we use, their purpose, and how you can manage your preferences are set out in our Cookie Policy.

26. How We Balance Our Legitimate Interests

Where we rely on "legitimate interests" as our legal basis for processing (for example, to keep our website secure, to carry out analytics, or to communicate with you about a Booking), we carry out an assessment to ensure that our interest in processing your data is not overridden by your own interests, rights and freedoms. This involves considering whether the processing is necessary, proportionate, and within your reasonable expectations given our relationship with you. If you would like more information about a specific legitimate interest assessment, please contact us using the details in Section 28.

27. Communicating With You by WhatsApp

Where you choose to contact us via WhatsApp, or provide us with a WhatsApp number so that we can contact you about your enquiry or Booking, we process the content of those messages, your phone number, and associated metadata (such as the time a message was sent) in the same way as other personal data described in this policy. WhatsApp is operated by a third party, and your use of WhatsApp is also subject to WhatsApp's own terms and privacy policy. We recommend you avoid sending highly sensitive information (such as full card numbers) via WhatsApp or any other messaging platform.

28. Anonymised and Aggregated Data

We may create anonymised or aggregated data from your personal data, for example by combining information about visitor numbers or booking trends across many customers so that no individual can reasonably be identified from it. Because this aggregated data is no longer personal data once it has been genuinely anonymised, we may use it for any business purpose, including analysing which destinations are most popular or reporting on general website usage trends, without the restrictions that apply to personal data under this policy.

29. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices, our services, our Suppliers, or applicable law. Where we make material changes, we will take reasonable steps to notify you, for example by displaying a notice on our website. We encourage you to review this policy periodically. The date at the top of this page indicates when it was last revised.

30. A Summary of Your Data Journey

To bring the above sections together: when you first contact us, typically via our website, telephone or WhatsApp, we collect the contact and enquiry details described in Section 6. As your enquiry progresses towards a Booking, we collect further details necessary to arrange your Travel Arrangements, including passenger and passport information. We share the minimum necessary information with the relevant Suppliers, including Brightsun Travel for flight ticketing, to deliver your Travel Arrangements. Throughout this process, and for a period afterwards as described in Section 18, we retain your data securely, use it only for the purposes described in this policy, and give you the rights described in Section 21 to access, correct or in some cases erase it. If at any point you have questions about where your data stands in this journey, please contact us using the details in Section 32.

31. Complaints

If you have concerns about how we handle your personal data, we encourage you to contact us first so that we can try to resolve the issue directly and promptly. You also have the right to lodge a complaint with the UK's independent data protection regulator, the Information Commissioner's Office (ICO), via ico.org.uk or by telephone on 0303 123 1113, at any time, if you believe your data protection rights have been infringed.

32. Contact Us

If you have any questions about this Privacy Policy or how we handle your personal data, please contact us on (0203) 983-6853, via WhatsApp, or through our Contact Us page. Our registered office address is Office 8168, 321-323 High Road, Chadwell Heath, Essex, United Kingdom, RM6 6AX.

mail

Inspiration Delivered Straight to Your Inbox

Be the first to know about incoming travel news and exclusive discounts from Talvania Global Ltd!

cookie

We use cookies to keep our site working properly and, with your permission, to understand how it's used and improve your experience. See our Cookie Policy for details.

call Call Us: (0203) 983-6853
chat