ITL Holidays Global

Privacy Policy

Your privacy matters to us. This policy explains how ITL Holidays Global collects, uses, and protects your personal information when you engage with our services.

Plain-language summary: ITL Holidays Global collects your personal information to plan and deliver travel services on your behalf. We do not sell your data. We share it only with the suppliers needed to fulfil your journey. You have the right to access, correct, or delete your data at any time. This policy tells you exactly how.

Who We Are

ITL Holidays Global is the travel and tourism arm of the ITL Group, a conglomerate with over 45 years of global operating history. We provide travel management services — including leisure holidays, corporate travel, MICE, visa support, accommodation, flights, and related services — to travellers across India, the Gulf Cooperation Council (GCC), and Western markets including the United Kingdom.

For the purposes of this Privacy Policy, ITL Holidays Global acts as the data controller in respect of personal data collected through our website, enquiry forms, WhatsApp communications, email correspondence, and in-person interactions.

Registered address and company details: [Company registration details — to be updated by client]

Information We Collect

We collect personal information when you enquire about our services, make a booking, use our website, communicate with us, or travel with us. The types of information we may collect include:

2.1 Information You Provide Directly

  • Identity information: Full name, date of birth, nationality, passport details, gender
  • Contact information: Email address, phone number, WhatsApp number, postal address
  • Travel details: Destination preferences, travel dates, number of travellers, accommodation preferences, dietary requirements, accessibility needs
  • Payment information: Billing address and payment method details (processed securely through authorised payment gateways — we do not store full card details)
  • Communications: Enquiry forms, email correspondence, WhatsApp messages, and any other communications you send us
  • Corporate information: For MICE and corporate clients, company name, job title, and corporate travel policy details

2.2 Information Collected Automatically

  • IP address and device information when you visit our website
  • Browser type, operating system, and referring URLs
  • Pages visited, time spent on pages, and click behaviour (via cookies and analytics tools)

2.3 Sensitive Personal Information

In certain circumstances, we may need to process sensitive personal data — such as dietary requirements (which may reveal religious beliefs) or accessibility or medical requirements necessary to arrange appropriate travel services. We will only collect and use such information where it is strictly necessary to provide the service you have requested, and we will seek your explicit consent where required by applicable law.

How We Use Your Information

We use the personal information we collect for the following purposes:

Purpose Description
Service Delivery To arrange and manage your travel bookings, including flights, accommodation, visas, transfers, and all associated services.
Enquiry Handling To respond to your travel enquiries and provide quotations, itinerary proposals, and service information.
Communication To send booking confirmations, travel documents, itinerary updates, and essential service notifications.
Customer Support To assist you before, during, and after your journey — including emergency travel support.
Visa & Immigration To prepare and submit visa applications on your behalf, requiring identity and passport information.
Legal Compliance To meet our obligations under applicable law, including financial regulations, anti-money laundering requirements, and data protection laws.
Marketing To send you travel inspiration, offers, and newsletters — only where you have provided consent or we have a legitimate interest. You may opt out at any time.
Website Improvement To analyse how our website is used and improve the user experience.

Legal Basis for Processing

Where applicable data protection legislation requires us to identify a legal basis for processing your personal data, we rely on the following:

  • Contract performance: Processing necessary to perform a contract with you or to take steps at your request before entering into a contract — for example, arranging your booking.
  • Legal obligation: Processing necessary to comply with our legal obligations — for example, financial record-keeping or visa submission requirements.
  • Legitimate interests: Processing for our legitimate business interests, including improving our services, fraud prevention, and direct marketing to existing clients — provided these interests are not overridden by your rights.
  • Consent: Where you have given us clear, informed consent — for example, subscribing to marketing communications or providing sensitive personal data for travel planning purposes.

For travellers based in the European Economic Area (EEA) or United Kingdom, we process your data in accordance with the UK GDPR and, where applicable, the EU General Data Protection Regulation (GDPR).

Sharing Your Information

We do not sell, rent, or trade your personal information to any third party for their own marketing purposes. We share your information only in the following circumstances:

  • Travel suppliers: Airlines, hotels, cruise lines, visa authorities, ground transportation providers, and other suppliers necessary to fulfil your booking. These parties receive only the information required to provide their specific service.
  • ITL Group companies: We may share your information with other entities within the ITL Group where necessary to deliver services — for example, ITL Healthcare for medical travel or ITL World for travel management.
  • Payment processors: Authorised payment gateway providers who process transactions on our behalf and who are bound by their own data security standards.
  • Government and regulatory authorities: Immigration authorities, embassies, and consulates in connection with visa applications; financial regulators and law enforcement agencies where required by law.
  • Professional advisers: Legal, accounting, and insurance advisers bound by professional confidentiality obligations.
  • Technology service providers: Cloud hosting, email, CRM, and analytics providers who process data on our behalf under data processing agreements.

All third parties with whom we share your data are required to maintain the security and confidentiality of your information and are prohibited from using it for any purpose beyond the services they provide to us.

Cookies & Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience and understand how visitors use our site. Cookies are small text files stored on your device.

Types of Cookies We Use

Cookie Type Purpose Duration
Essential Required for the website to function correctly. Cannot be disabled. Session
Analytics Help us understand how visitors interact with the site (e.g. Google Analytics). All data is anonymised. Up to 2 years
Functional Remember your preferences such as language and location settings. Up to 1 year
Marketing Track visits across websites to show relevant advertisements. Only used with your consent. Up to 90 days

You can control or disable cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of our website. Where required by law, we will obtain your consent before placing non-essential cookies.

Data Retention

We retain your personal information for as long as necessary to fulfil the purposes for which it was collected, including for the satisfaction of any legal, accounting, or reporting requirements.

  • Booking records: Retained for a minimum of 7 years from the date of travel to comply with financial and tax regulations.
  • Enquiry records: Retained for up to 3 years from the date of last contact if no booking is made.
  • Marketing data: Retained until you unsubscribe or withdraw consent, after which your data is removed from marketing lists within 30 days.
  • Passport and visa documents: Deleted within 90 days of successful visa issuance or application closure, unless retention is required by law.
  • Website analytics data: Retained in anonymised form for up to 26 months.

When your data is no longer required, it is securely deleted or anonymised in accordance with our data destruction procedures.

Your Rights

Depending on your location and applicable data protection law, you may have the following rights in relation to your personal data:

  • Right of access: To request a copy of the personal data we hold about you.
  • Right to rectification: To request that we correct any inaccurate or incomplete personal data.
  • Right to erasure: To request that we delete your personal data, subject to certain legal exceptions.
  • Right to restrict processing: To request that we limit how we use your data in certain circumstances.
  • Right to data portability: To receive your personal data in a structured, machine-readable format.
  • Right to object: To object to our processing of your personal data for direct marketing or based on legitimate interests.
  • Right to withdraw consent: Where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at privacy@itlholidaysglobal.com. We will respond to all requests within 30 days. In some cases, we may need to verify your identity before processing your request.

If you are based in the UK or EEA and believe we have not handled your data correctly, you have the right to lodge a complaint with the relevant supervisory authority — the Information Commissioner's Office (ICO) in the UK, or your local data protection authority in the EEA.

International Data Transfers

As a global travel company serving clients across India, the GCC, and Western markets, the nature of our services requires us to transfer personal data internationally. For example, booking a flight requires your data to be shared with the relevant airline, which may be based in a different country.

When we transfer personal data outside the United Kingdom or European Economic Area, we ensure that appropriate safeguards are in place, including:

  • Transfers to countries with an adequacy decision from the relevant authority
  • Standard Contractual Clauses approved by the European Commission or UK ICO
  • Binding corporate rules where applicable
  • Your explicit consent, where required

For transfers necessary to fulfil travel bookings (such as hotel or airline reservations), such transfers are necessary for the performance of a contract in your interests.

Data Security

We take the security of your personal information seriously. We have implemented appropriate technical and organisational measures to protect your data against unauthorised access, accidental loss, alteration, disclosure, or destruction.

  • Secure HTTPS encryption on our website and all data transmissions
  • Access controls and role-based permissions for staff handling personal data
  • Regular staff training on data protection and information security
  • Secure storage of physical documents containing personal information
  • Due diligence on third-party suppliers regarding their data security practices

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and, where required, inform you directly without undue delay.

If you suspect that your personal information has been compromised or misused in connection with your interactions with ITL Holidays Global, please contact us immediately at privacy@itlholidaysglobal.com.

Children's Privacy

Our services are designed for adults aged 18 and over. We do not knowingly collect personal data directly from children under the age of 18. Where a booking includes child travellers, we collect information about those children solely from the parent or guardian making the booking, for the sole purpose of arranging travel services.

If you believe we have inadvertently collected personal data from a child without appropriate parental consent, please contact us immediately at privacy@itlholidaysglobal.com and we will take steps to delete that information.

Third-Party Links

Our website may contain links to third-party websites, including airline booking portals, hotel websites, visa application platforms, and partner services. These websites have their own privacy policies and we have no responsibility or liability for their content or practices.

We encourage you to read the privacy policy of every website you visit before providing any personal information.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable law. When we make material changes, we will update the "Last Updated" date at the top of this page and, where appropriate, notify you by email or through a prominent notice on our website.

We encourage you to review this Privacy Policy periodically. Your continued use of our services after any changes constitutes your acceptance of the updated policy.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or the way we handle your personal data, please contact us through any of the following channels:

Enquiries: info@itlholidaysglobal.com

We aim to respond to all privacy-related enquiries within 5 business days and to resolve all substantive requests within 30 days.