WHAT IS OUR ROLE IN RELATION TO YOUR PERSONAL DATA?
For the purposes of data protection laws, we, Kazakh Trading Company and TourAsia Travel Agency, are a data controller in respect of the personal data you provide us with.
WHAT IS MY PERSONAL DATA AND WHAT DO YOU MEAN BY PROCESS?
When we refer to personal data, we mean any information which relates to an identified or identifiable individual. Where we refer to process or processing, we mean anything which we may do with your personal data including collecting, storing, using, disclosing to third parties and erasing it.
WHAT PERSONAL INFORMATION DO WE COLLECT FROM THE PEOPLE THAT VISIT OUR BLOG, WEBSITE OR APP?
We collect personal contact information from visitors of our site when they provide it. This includes name, address, phone and email. We also may collect credit card information for online e-commerce transactions.
WHEN DO WE COLLECT INFORMATION?
We collect information from you when you register on our site, place an order, subscribe to a newsletter, respond to a survey, fill out a form, Use Live Chat, Open a Support Ticket or enter information on our site.
Where you wish to make/request a booking, the personal data we may need to collect and process is likely to include:
- Names of all persons travelling
- Contact details (such as telephone number, postal and e-mail addresses) of the person making the booking
- Passport information of all persons travelling
- Travel insurance details for all persons travelling
- Dietary information where applicable
- Emergency contact / next of kin details (names and telephone numbers) for all persons travelling
- Credit / debit card or other payment information for the person making the booking
information in respect of any medical condition, disability or reduced mobility which may affect you or anyone travelling with you – this comes within special categories of personal data (see below)
For an inquiry, the personal data we will need to process is likely to include the name and contact details of the person making the inquiry.
For a booking or booking inquiry, we will process your personal data (other than any data which comes within special categories of personal data – see below) on the basis that this is necessary for the performance of your contract with us, or to enable us to take steps at your request prior to your entering into a contract with us. We may also need to do so to comply with a legal obligation to which we are subject or in order to protect your vital interests (for example, in an emergency situation).
If you wish to receive brochures or other promotional material from us, we will need your name and the contact details applicable to the form of communication you have consented to. For example, if you wish to receive information by email, we will need your email address.
WHAT ARE SPECIAL CATEGORIES OF PERSONAL DATA?
Personal data which concerns your health or which reveals your racial or ethnic origin or your sexual orientation are special categories of personal data. Other information also comes within special categories but this is unlikely to be relevant to the booking and provision of travel arrangements.
Generally speaking, the processing of special categories of personal data requires your explicit consent.
Accordingly, information concerning any disability, medical condition or restricted mobility which may affect your travel arrangements (and related requirements) as well as dietary restrictions which may disclose your religious beliefs are special categories of personal data. We will ask for your consent to our processing this information at the time you make your booking or your booking inquiry.
WHO MAY WE PROVIDE YOUR PERSONAL DATA TO?
Where you make a booking or request to reserve a booking, appropriate personal data will be passed on to the relevant suppliers of your chosen arrangements together with any other third party who needs this information so that we can arrange for your holiday to be provided.
Suppliers and other third parties are likely to include the following, depending on the arrangements booked:
- In-country transport operators
- Hotels and the providers of other forms of accommodation
- Overseas ground agents
- Tour managers and guides
- Excursion and activity operators
- Travel insurance providers
- Credit card companies / banks in respect of payments
The information may also be provided to government / public authorities such as customs or immigration if required by them, or as required by law.
We may also make personal data available to other companies who provide services on our behalf, such as mailing brochures and marketing material.
We only provide third parties with the personal data they require in order to deliver their services. Other than in relation to government / public authorities (over whom we have no control), we will take appropriate steps which are intended to ensure that anyone to whom we pass your personal data for any reason agrees to keep it secure, only uses it for the purposes of providing their services and does not collect any personal data from you in the course performing their services.
HOW DO WE USE YOUR INFORMATION?
We may use the information we collect from you when you register, make a purchase, sign up for our newsletter, respond to a survey or marketing communication, surf the website, or use certain other site features in the following ways:
- To personalize your experience and to allow us to deliver the type of content and product offerings in which you are most interested.
- To improve our website in order to better serve you.
- To allow us to better service you in responding to your customer service requests.
- To administer a contest, promotion, survey or other site feature.
- To quickly process your transactions.
- To ask for ratings and reviews of services or products
- To follow up with you after correspondence (live chat, email or phone inquiries)
WHERE WILL WE PROCESS YOUR PERSONAL DATA?
Your personal data may be processed within the USA, Kazakhstan and/or any other country(ies) of the European Economic Area (EEA). EEA countries are all member states of the European Union together with Norway, Iceland and Liechtenstein.
We may also process personal data outside the EEA. Data protection laws may not be as strong outside the EEA as they are in the EEA. Personal data will not be transferred to a country outside the EEA unless (1) the country to which it is transferred is one which the European Commission considers to provide an adequate level of data protection or (2) the personal data is transferred to a company which is required by our contract with them only to deal with the data in accordance with our instructions and to maintain appropriate security to protect the personal data which we are satisfied they have or (3) we are obliged to provide the personal data to a government / public authority in order to provide your holiday.
HOW DO WE PROTECT YOUR INFORMATION?
We take appropriate technical and organizational measures to protect against unauthorized or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data, which is appropriate to the harm that might result from the unauthorized or unlawful processing or accidental loss, destruction or damage and the nature of the data to be protected, having regard to the state of technological development and the cost of implementing any measures.
Our website is scanned on a regular basis for security holes and known vulnerabilities in order to make your visit to our site as safe as possible.
Your personal information is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems, and are required to keep the information confidential. In addition, all sensitive/credit information you supply is encrypted via Secure Socket Layer (SSL) technology.
All transactions are processed through a gateway provider and are not stored or processed on our servers.
CAN WE USE YOUR PERSONAL DATA TO SEND YOU INFORMATION ABOUT OUR HOLIDAYS OR OTHER SERVICES IN THE FUTURE?
We will only retain and use your personal data for marketing purposes where you have specifically consented to this or we are permitted to do in accordance with data protection laws (including as set out below).
We may send you email marketing where we comply with the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR). PECR permits us to email you information about the travel services we offer where you have previously provided us with your email address in the course of entering into a contract with us for holiday / travel arrangements or negotiations for such arrangements and we wish to email you marketing material about our similar services or products. You will of course be given the opportunity to opt out of receiving such email marketing communications when you first provide us with your email address and whenever we send you any email marketing.
Where you have previously requested or agreed to receive information about our travel services from us by post, we may continue to send you such information in the same way until you ask us not to (which you can do by telephone, email or post). Everything we send you will tell you what you should do if you no longer wish to hear from us. We will send you this information as this is necessary for the purposes of our legitimate interests in communicating with you unless it is or becomes clear that our interests are overridden by your interests or fundamental rights and freedoms in which case we will cease communicating with you.
You may provide your consent to receiving marketing information from us by opting to receive marketing material either online or by telephone. You may also choose in what ways you are happy to receive communications from us. You may, for example, be happy to receive information and offers by post and email but not by telephone.
CAN YOU WITHDRAW YOUR CONSENT TO OUR PROCESSING YOUR PERSONAL DATA?
Yes, you can withdraw your consent to receiving marketing material or other communications from us, either generally or in any particular way, at any time by emailing us at email@example.com or you can telephone us.
HOW CAN YOU FIND OUT WHAT INFORMATION WE ARE HOLDING ABOUT YOU?
You are entitled to ask us (by letter or email) what personal data of yours is being held or processed, for what purpose and to whom it may be or has been disclosed. No fee will be charged for responding to this request unless it is obviously unfounded or excessive or we have previously provided the same information.
We promise to respond to your request without delay and in any event within 1 month unless the request is complex or you have made numerous requests in which case we may be able to extend our response time by a further 2 months.
WHAT SHOULD YOU DO IF THE PERSONAL DATA WE ARE HOLDING IS INACCURATE, OUT OF DATE OR INCOMPLETE?
If you believe this is the case, please tell us by email as soon as possible. We will rectify the problem within 1 month or within 3 months if the rectification request is complex.
HOW LONG CAN WE RETAIN AND PROCESS YOUR PERSONAL DATA?
We will not process your personal data in a form which enables you to be personally identified for any longer than is necessary in order to fulfill the purpose for which it was originally collected or for any other legitimate business purpose.
Where your personal data has been provided for the purpose of the holiday arrangements or other services you have contracted, we are entitled to retain this data for a period of 6 years after those arrangements have been completed. In certain limited circumstances, we may be able to retain it for a longer period.
If you have consented to receiving marketing communications from us, we may continue to use your personal data for this purpose until you withdraw your consent or otherwise for as long as we reasonably consider your consent remains valid and effective.
CAN YOU ASK US TO DELETE YOUR PERSONAL DATA?
Yes, you can ask us to erase your personal data in certain circumstances, for example where you have withdrawn your consent to further marketing material where the data in question has only been processed for this purpose. However, this is not always the case. Please see the previous paragraph for further information on the period of time we may retain personal data.
DOES YOUR WEBSITE USE ‘COOKIES’?
You can choose to have your computer warn you each time a cookie is being sent, or you can choose to turn off all cookies. You do this through your browser settings. Since browser is a little different, look at your browser’s Help Menu to learn the correct way to modify your cookies.
If users disable cookies in their browser some site features may not work.
We do not sell, trade, or otherwise transfer to outside parties your Personally Identifiable Information unless we provide users with advance notice. This does not include website hosting partners and other parties who assist us in operating our website, conducting our business, or serving our users, so long as those parties agree to keep this information confidential. We may also release information when it’s release is appropriate to comply with the law, enforce our site policies, or protect ours or others’ rights, property or safety.
However, non-personally identifiable visitor information may be provided to other parties for marketing, advertising, or other uses.
Occasionally, at our discretion, we may include or offer third-party products or services on our website. These third-party sites have separate and independent privacy policies. We therefore have no responsibility or liability for the content and activities of these linked sites. Nonetheless, we seek to protect the integrity of our site and welcome any feedback about these sites.
GOOGLE AND FACEBOOK AND THIRD PARTY COOKIES
Google’s advertising requirements can be summed up by Google’s Advertising Principles. They are put in place to provide a positive experience for users. https://support.google.com/adwordspolicy/answer/1316548?hl=en
We, along with third-party vendors such as Google or Facebook use first-party cookies (such as the Google Analytics cookies) and third-party cookies (such as the DoubleClick or Facebook cookie) or other third-party identifiers together to compile data regarding user interactions with ad impressions and other ad service functions as they relate to our website. We have implemented Demographics and Interests Reporting.
Users can set preferences for how Google advertises to you using the Google Ad Settings page. Alternatively, you can opt out by visiting the Network Advertising Initiative Opt Out page or by using the Google Analytics Opt Out Browser add on.
CALIFORNIA ONLINE PRIVACY PROTECTION ACT
According to CalOPPA, we agree to the following:
- Users can visit our site anonymously.
- You can change your personal information by emailing us or calling us
HOW DOES OUR SITE HANDLE DO NOT TRACK SIGNALS?
We honor Do Not Track signals and Do Not Track, plant cookies, or use advertising when a Do Not Track (DNT) browser mechanism is in place.
DOES OUR SITE ALLOW THIRD-PARTY BEHAVIORAL TRACKING?
Yes, we allow third-party behavioral tracking.
COPPA (CHILDREN ONLINE PRIVACY PROTECTION ACT)
When it comes to the collection of personal information from children under the age of 13 years old, the Children’s Online Privacy Protection Act (COPPA) puts parents in control. The Federal Trade Commission, United States’ consumer protection agency, enforces the COPPA Rule, which spells out what operators of websites and online services must do to protect children’s privacy and safety online.
We do not specifically market to children under the age of 13 years old.
FAIR INFORMATION PRACTICES
The Fair Information Practices Principles form the backbone of privacy law in the United States and the concepts they include have played a significant role in the development of data protection laws around the globe. Understanding the Fair Information Practice Principles and how they should be implemented is critical to comply with the various privacy laws that protect personal information.
In order to be in line with Fair Information Practices we will take the following responsive action, should a data breach occur:
We will notify the users via in-site notification, within 7 business days
We also agree to the Individual Redress Principle which requires that individuals have the right to legally pursue enforceable rights against data collectors and processors who fail to adhere to the law. This principle requires not only that individuals have enforceable rights against data users, but also that individuals have recourse to courts or government agencies to investigate and/or prosecute non-compliance by data processors.
CAN SPAM ACT
The CAN-SPAM Act is a law that sets the rules for commercial email, establishes requirements for commercial messages, gives recipients the right to have emails stopped from being sent to them, and spells out tough penalties for violations.
We collect your email address in order to:
- Send information, respond to inquiries, and/or other requests or questions
- Process orders and to send information and updates pertaining to orders.
- Send you additional information related to your product and/or service
- Market to our mailing list or continue to send emails to our clients after the original transaction has occurred.
To be in accordance with CANSPAM, we agree to the following:
- Not use false or misleading subjects or email addresses.
- Identify the message as an advertisement in some reasonable way.
- Include the physical address of our business or site headquarters.
- Monitor third-party email marketing services for compliance, if one is used.
- Honor opt-out/unsubscribe requests quickly.
- Allow users to unsubscribe by using the link at the bottom of each email.
If at any time you would like to unsubscribe from receiving future emails, you can email us at firstname.lastname@example.org
Follow the instructions at the bottom of each email and we will promptly remove you from ALL correspondence.
TourAsia Travel Agency
Kazakhstan, 050060, Almaty
Baikadamov str., 30 — 1
Phone: +7 (727) 376 57 13