SECTION 01
Introduction
BCD Tour Africa Travel is a travel agency registered and operating in Zimbabwe. We are committed to protecting your personal data and respecting your privacy in accordance with the Cyber and Data Protection Act [Chapter 12:07], as regulated by the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), and any other applicable data protection legislation.
This Privacy Policy explains how we collect, use, process, store, and protect your personal information when you use our travel services, visit our website, or otherwise interact with us. It also describes your rights in relation to your personal data and how to contact us if you have questions or concerns.
We encourage you to read this Policy carefully. By using our services or providing us with your personal data, you acknowledge that you have read and understood this Policy.
SECTION 02
Data Controller
BCD Tour Africa Travel is the Data Controller responsible for determining how and why your personal data is processed. Our contact details are set out at the end of this Policy.
SECTION 03
Our Data Protection Principles
We process personal data in accordance with the following principles:
- ◆ Lawfulness, fairness, and transparency — we process data lawfully and openly
- ◆ Purpose limitation — data is collected for specified, explicit, and legitimate purposes
- ◆ Data minimisation — we collect only what is necessary for the stated purpose
- ◆ Accuracy — we take reasonable steps to keep your data accurate and up to date
- ◆ Storage limitation — data is retained only as long as necessary
- ◆ Integrity and confidentiality — we apply appropriate security measures
- ◆ Accountability — we are responsible for and can demonstrate compliance
SECTION 04
Personal Data We Collect
In the course of providing our travel services, we may collect and process the following categories of personal data:
Identity Information
- Full name (as per passport or national ID)
- National ID number
- Passport number, issuing country, and expiry date
- Date of birth
- Gender
- Nationality and citizenship
Contact Information
In line with requirements from the International Air Transport Association (IATA) and our service obligations, we collect:
- Primary mobile number (with country code)
- Alternative or home telephone number
- Email address (personal and/or work)
- Residential and/or work address
- Emergency contact details (name, relationship, phone number)
Travel and Immigration Information
- Flight itineraries, ticket details, and booking references
- Hotel, accommodation, and car hire bookings
- Visa applications and supporting documents
- Travel history (where required by airlines or immigration authorities)
- Frequent flyer numbers and travel preferences (e.g. seat, meal)
- Next-of-kin information (where applicable)
Financial Information
- Proof of payment (bank transfer references, mobile money such as EcoCash or OneMoney)
- Billing and invoicing details
- Corporate or personal payment card details, processed securely via third-party providers
- Bank account information where required for refunds
Employment and Organisational Information
- Company or organisation name (for corporate or NGO travel)
- Job title, department, and work contact details
- Travel authorisation and approval documentation
- Cost centre or budget code
Technical and Usage Information
When you visit our website, we may automatically collect:
- IP address and approximate geographical location
- Browser type, version, and device information
- Pages visited, links clicked, and time spent on pages
- Referral source and website navigation paths
Sensitive Personal Data
Where strictly necessary, and only with your explicit consent, we may collect:
- Health information (e.g. vaccination certificates, medical fitness for travel)
- Special assistance requirements (e.g. mobility, dietary, or medical needs)
You are never required to provide sensitive personal data unless it is essential to fulfil your travel arrangements or comply with a legal requirement.
SECTION 05
How We Collect Personal Data
We collect personal data through the following means:
- Directly from you when you enquire about, book, or use our services, including via email, phone, in person, or through our website
- From your employer or organisation where we provide corporate travel management services
- From third-party travel service providers such as airlines, hotels, Global Distribution Systems (GDS), and visa processing agencies
- Through our website using cookies and similar technologies (see Section 10)
- From publicly available sources or government authorities where required by law
SECTION 06
Lawful Basis for Processing
We process your personal data on one or more of the following legal bases:
- ◆ Performance of a contract — to book and fulfil your travel arrangements
- ◆ Legal obligation — to comply with immigration, aviation, taxation, and other regulatory requirements
- ◆ Legitimate interests — to manage our business, improve our services, and prevent fraud
- ◆ Consent — where you have given us clear consent to process your data for a specific purpose, such as direct marketing or sensitive personal data
Where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
SECTION 07
Purposes for Which We Use Your Data
Your personal data is used to:
- Book and manage flights, hotels, car hire, and all other travel services
- Issue tickets, itineraries, and travel documentation
- Facilitate visa and immigration applications
- Process payments and manage invoicing and refunds
- Communicate travel confirmations, updates, disruptions, and advisories
- Provide customer support before, during, and after your trip
- Comply with legal and regulatory obligations (e.g. IATA, POTRAZ, immigration authorities)
- Send you relevant travel offers, promotions, and newsletters — where you have consented
- Analyse website usage to improve our online services
- Protect against fraud, security threats, and unauthorised use of our systems
SECTION 08
Sharing of Personal Data
We may share your personal data with the following categories of third parties, strictly to the extent necessary for the stated purpose:
Travel Service Providers
- Airlines, rail and ground transport operators, hotels, cruise lines, and other suppliers required to fulfil your bookings
- Global Distribution Systems (GDS) used to make reservations
- Destination management companies and tour operators
Government and Regulatory Authorities
- Embassies and visa processing authorities
- Immigration, customs, and border control agencies
- Tax authorities and financial regulators, where required by law
Payment Processors
Financial transactions are handled by our authorised payment service providers, including Direct Pay Online and mobile money platforms. We share only the transaction data necessary to process your payment or refund. Please refer to each provider's privacy policy for further information.
Our Service Providers
- IT service providers, cloud hosting, and data storage providers
- Legal, accounting, and professional advisers
- Insurers and risk managers
Your Employer or Organisation
Where we provide corporate travel management services, we may share booking and travel data with your employer or their designated representatives for reporting, policy compliance, and auditing purposes.
Legal Disclosures
We may disclose your data where required to do so by law, court order, or to protect the rights, property, or safety of BCD Tour Africa Travel, our clients, or others.
All third-party recipients are required to handle your data in accordance with applicable data protection standards and are not permitted to use your data for their own independent purposes.
SECTION 09
International Transfers of Personal Data
Due to the international nature of travel, your personal data may need to be transferred to, and processed in, countries outside Zimbabwe. Such transfers are necessary to fulfil your travel arrangements (for example, sharing your data with an overseas airline or hotel).
Where your personal data is transferred internationally, we ensure that:
- The transfer is to a country with adequate data protection standards; or
- Appropriate safeguards are in place, such as standard contractual clauses; or
- The transfer is necessary to perform the contract between you and us (e.g. booking a flight); or
- You have given your explicit consent to the transfer
Our website hosting facilities are located in the United Kingdom, the United States of America, and the Netherlands. We take reasonable steps to ensure your data is protected in these jurisdictions.
SECTION 10
Cookies and Website Technologies
A cookie is a small text file placed on your device by a website. We use cookies and similar tracking technologies on our website to:
- Ensure the website functions correctly
- Remember your preferences across visits
- Analyse website usage through tools such as Google Analytics
- Improve your browsing experience
You can control or delete cookies through your browser settings. Disabling cookies may affect the functionality of certain parts of our website. Where required by law, we will request your consent before placing non-essential cookies.
For more information on managing cookies, please refer to your browser's help documentation or visit www.aboutcookies.org.
SECTION 11
Data Security
We implement appropriate technical and organisational measures to protect your personal data against:
- Unauthorised access, disclosure, or use
- Loss, theft, or destruction
- Accidental alteration or damage
These measures include password-protected systems, encrypted data transmission, restricted staff access, and regular security reviews.
However, no method of transmission over the Internet is completely secure. While we strive to protect your personal data, we cannot guarantee absolute security and you provide data to us at your own risk. Please do not send us sensitive personal data such as full payment card numbers via unencrypted email.
If you believe your data has been compromised, please contact us immediately using the details in Section 17.
SECTION 12
Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes described in this Policy, or as required by law. When determining retention periods, we consider:
- The nature of the data and the purpose for which it was collected
- Legal and regulatory obligations (e.g. tax records, aviation regulations)
- The possibility of legal proceedings or disputes in which the data may be relevant
When personal data is no longer required, it is securely deleted or anonymised. You may request deletion of your data at any time, subject to our legal obligations to retain certain records.
SECTION 13
Your Rights
Under the Cyber and Data Protection Act [Chapter 12:07] and, where applicable, other data protection legislation, you have the following rights in relation to your personal data:
Right of access
to request a copy of the personal data we hold about you
Right to rectification
to request correction of inaccurate or incomplete data
Right to erasure
to request deletion of your data in certain circumstances
Right to restrict processing
to request that we limit how we use your data
Right to object
to object to processing based on legitimate interests or for direct marketing
Right to data portability
to receive your data in a structured, machine-readable format
Right to withdraw consent
at any time where processing is based on consent
Right to complain
to lodge a complaint with the relevant supervisory authority
To exercise any of these rights, please contact us using the details in Section 17 below. We will respond within 30 days. In some cases we may need to verify your identity before processing your request.
We do not charge a fee for handling reasonable requests, but we reserve the right to charge an administrative fee for manifestly unfounded or excessive requests.
SECTION 14
Children's Privacy
Our services are not directed at children under the age of 18 acting independently. We do not knowingly collect personal data directly from children without the involvement of a parent or guardian.
Where travel arrangements involve minors, we collect and process the necessary data only to the extent required to fulfil those arrangements, with the consent of the accompanying adult.
SECTION 15
Complaints
If you are dissatisfied with how we have handled your personal data, you are entitled to lodge a complaint with the:
Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ)
We would, however, appreciate the opportunity to address your concerns before you approach a regulatory authority. Please contact us in the first instance using the details below.
SECTION 16
Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we do, we will revise the Effective Date at the top of this document and, where appropriate, notify you by email or a notice on our website.
We encourage you to review this Policy periodically to stay informed about how we protect your information.
SECTION 17
Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or the way we handle your personal data, please contact our Data Protection Officer:
Data Protection Officer
BCD Tour Africa Travel
- Phone
- +263 242 798410-1
- Address
-
3 Hampton Court
34 Baines Avenue
Harare, Zimbabwe - Website
- www.tourafricatravel.com
We aim to respond to all enquiries within 5 business days.