Company & Data Protection Policy
JD Travels is committed to conducting its business responsibly
and protecting the personal information entrusted to it by
customers, employees, suppliers, business partners and other
individuals.
This policy sets out the principles and standards JD Travels
follows when handling personal information.
It supports JD Travels' commitment to compliance with the
Protection of Personal Information Act 4 of 2013 (POPIA)
and other applicable legal requirements.
Purpose
The purpose of this policy is to establish principles for:
- Collecting personal information
- Processing personal information
- Storing personal information
- Protecting personal information
- Sharing personal information
- Retaining personal information
- Deleting or disposing of personal information
- Responding to data-subject requests
- Responding to security compromises
Scope
This policy applies to JD Travels employees, directors, contractors, service providers and other persons who process or have authorised access to personal information on behalf of JD Travels.
Personal Information
For purposes of this policy, personal information includes information relating to an identifiable individual or entity where protected by applicable law.
Examples may include:
- Names
- Contact details
- Identification information
- Passport information
- Travel information
- Booking information
- Payment-related information
- Correspondence
- Online identifiers
- Technical information
Lawful Processing
JD Travels will seek to process personal information lawfully and for a specific, reasonable and legitimate purpose.
Personal information should only be collected where it is reasonably necessary for the relevant business, contractual, legal or other lawful purpose.
Collection of Information
JD Travels will endeavour to:
- Collect information directly from the relevant individual where reasonably possible
- Explain the purpose for which information is collected
- Avoid collecting unnecessary information
- Keep information relevant to the purpose for which it is processed
Consent and Other Lawful Grounds
Where consent is required, JD Travels will seek appropriate consent from the relevant data subject.
Personal information may also be processed where another lawful basis applies, including where processing is necessary to perform a contract, comply with a legal obligation or protect legitimate interests, where permitted by applicable law.
Data Security
JD Travels will implement reasonable technical and organisational safeguards designed to protect personal information against:
- Unauthorised access
- Loss
- Theft
- Unauthorised disclosure
- Unlawful processing
- Accidental destruction
- Unauthorised alteration
Access to personal information should be restricted to authorised persons who require access for legitimate business purposes.
Accuracy
JD Travels will take reasonable steps to ensure that personal information in its possession is accurate, complete and, where necessary, kept up to date.
Where an individual identifies inaccurate information, JD Travels will take reasonable steps to correct it.
Retention and Disposal
Personal information should not be retained indefinitely without a legitimate reason.
JD Travels will retain information for periods appropriate to the purpose for which it was collected and any applicable legal, contractual, accounting or regulatory requirements.
When information is no longer required, it should be securely deleted, destroyed or otherwise disposed of where appropriate.
Data Subject Rights
Subject to applicable law, individuals may have rights to:
- Request access to personal information
- Request correction of inaccurate information
- Request deletion where legally permissible
- Object to certain processing
- Object to direct marketing
- Raise concerns regarding the processing of their personal information
Requests should be directed to the JD Travels Information Officer.
Third-Party Service Providers
Where JD Travels appoints third-party service providers to process personal information on its behalf, JD Travels will seek to ensure that appropriate confidentiality, security and data-protection requirements are established.
Third-party service providers may include technology providers, hosting companies, payment providers, airlines, accommodation providers, tour operators and other travel-related suppliers.
Security Compromises
JD Travels will maintain procedures for identifying, assessing and responding to security compromises involving personal information.
Where POPIA requires notification, JD Travels will notify the Information Regulator and affected data subjects in accordance with the applicable requirements.
The Information Regulator states that security compromises must be reported and that notifications are submitted through its eServices process.
Training and Awareness
JD Travels will take reasonable steps to ensure that employees and relevant service providers understand their responsibilities regarding personal information.
This may include privacy awareness, security practices, confidentiality requirements and appropriate handling of customer information.
Monitoring and Review
JD Travels will periodically review its data-processing activities, security practices and policies and make reasonable updates where necessary.
Information Officer
The designated Information Officer for JD Travels is:
Zubeir Jacobs
Email: zubeir@jdtravels.co.za
General enquiries regarding JD Travels' privacy practices may also be sent to:
info@jdtravels.co.za
Contact Details
JD Travels
Lochiel
Athlone
Cape Town
7764
South Africa