Privacy Policy

Tour Africa Travel

PRIVACY POLICY

How we collect, use, and protect your personal data

Effective 1 May 2026 POTRAZ Compliant

BCD Tour Africa Travel is committed to protecting your personal data and respecting your privacy in accordance with the Cyber and Data Protection Act [Chapter 12:07], as regulated by the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ).

SECTION 01

Introduction

BCD Tour Africa Travel is a travel agency registered and operating in Zimbabwe. We are committed to protecting your personal data and respecting your privacy in accordance with the Cyber and Data Protection Act [Chapter 12:07], as regulated by the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), and any other applicable data protection legislation.

This Privacy Policy explains how we collect, use, process, store, and protect your personal information when you use our travel services, visit our website, or otherwise interact with us. It also describes your rights in relation to your personal data and how to contact us if you have questions or concerns.

We encourage you to read this Policy carefully. By using our services or providing us with your personal data, you acknowledge that you have read and understood this Policy.

SECTION 02

Data Controller

BCD Tour Africa Travel is the Data Controller responsible for determining how and why your personal data is processed. Our contact details are set out at the end of this Policy.

SECTION 03

Our Data Protection Principles

We process personal data in accordance with the following principles:

  • ◆ Lawfulness, fairness, and transparency — we process data lawfully and openly
  • ◆ Purpose limitation — data is collected for specified, explicit, and legitimate purposes
  • ◆ Data minimisation — we collect only what is necessary for the stated purpose
  • ◆ Accuracy — we take reasonable steps to keep your data accurate and up to date
  • ◆ Storage limitation — data is retained only as long as necessary
  • ◆ Integrity and confidentiality — we apply appropriate security measures
  • ◆ Accountability — we are responsible for and can demonstrate compliance

SECTION 04

Personal Data We Collect

In the course of providing our travel services, we may collect and process the following categories of personal data:

4.1

Identity Information

  • Full name (as per passport or national ID)
  • National ID number
  • Passport number, issuing country, and expiry date
  • Date of birth
  • Gender
  • Nationality and citizenship
4.2

Contact Information

In line with requirements from the International Air Transport Association (IATA) and our service obligations, we collect:

  • Primary mobile number (with country code)
  • Alternative or home telephone number
  • Email address (personal and/or work)
  • Residential and/or work address
  • Emergency contact details (name, relationship, phone number)
4.3

Travel and Immigration Information

  • Flight itineraries, ticket details, and booking references
  • Hotel, accommodation, and car hire bookings
  • Visa applications and supporting documents
  • Travel history (where required by airlines or immigration authorities)
  • Frequent flyer numbers and travel preferences (e.g. seat, meal)
  • Next-of-kin information (where applicable)
4.4

Financial Information

  • Proof of payment (bank transfer references, mobile money such as EcoCash or OneMoney)
  • Billing and invoicing details
  • Corporate or personal payment card details, processed securely via third-party providers
  • Bank account information where required for refunds
4.5

Employment and Organisational Information

  • Company or organisation name (for corporate or NGO travel)
  • Job title, department, and work contact details
  • Travel authorisation and approval documentation
  • Cost centre or budget code
4.6

Technical and Usage Information

When you visit our website, we may automatically collect:

  • IP address and approximate geographical location
  • Browser type, version, and device information
  • Pages visited, links clicked, and time spent on pages
  • Referral source and website navigation paths
4.7

Sensitive Personal Data

Where strictly necessary, and only with your explicit consent, we may collect:

  • Health information (e.g. vaccination certificates, medical fitness for travel)
  • Special assistance requirements (e.g. mobility, dietary, or medical needs)

You are never required to provide sensitive personal data unless it is essential to fulfil your travel arrangements or comply with a legal requirement.

SECTION 05

How We Collect Personal Data

We collect personal data through the following means:

  • Directly from you when you enquire about, book, or use our services, including via email, phone, in person, or through our website
  • From your employer or organisation where we provide corporate travel management services
  • From third-party travel service providers such as airlines, hotels, Global Distribution Systems (GDS), and visa processing agencies
  • Through our website using cookies and similar technologies (see Section 10)
  • From publicly available sources or government authorities where required by law

SECTION 06

Lawful Basis for Processing

We process your personal data on one or more of the following legal bases:

  • ◆ Performance of a contract — to book and fulfil your travel arrangements
  • ◆ Legal obligation — to comply with immigration, aviation, taxation, and other regulatory requirements
  • ◆ Legitimate interests — to manage our business, improve our services, and prevent fraud
  • ◆ Consent — where you have given us clear consent to process your data for a specific purpose, such as direct marketing or sensitive personal data

Where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out before the withdrawal.

SECTION 07

Purposes for Which We Use Your Data

Your personal data is used to:

  • Book and manage flights, hotels, car hire, and all other travel services
  • Issue tickets, itineraries, and travel documentation
  • Facilitate visa and immigration applications
  • Process payments and manage invoicing and refunds
  • Communicate travel confirmations, updates, disruptions, and advisories
  • Provide customer support before, during, and after your trip
  • Comply with legal and regulatory obligations (e.g. IATA, POTRAZ, immigration authorities)
  • Send you relevant travel offers, promotions, and newsletters — where you have consented
  • Analyse website usage to improve our online services
  • Protect against fraud, security threats, and unauthorised use of our systems

SECTION 08

Sharing of Personal Data

We may share your personal data with the following categories of third parties, strictly to the extent necessary for the stated purpose:

8.1

Travel Service Providers

  • Airlines, rail and ground transport operators, hotels, cruise lines, and other suppliers required to fulfil your bookings
  • Global Distribution Systems (GDS) used to make reservations
  • Destination management companies and tour operators
8.2

Government and Regulatory Authorities

  • Embassies and visa processing authorities
  • Immigration, customs, and border control agencies
  • Tax authorities and financial regulators, where required by law
8.3

Payment Processors

Financial transactions are handled by our authorised payment service providers, including Direct Pay Online and mobile money platforms. We share only the transaction data necessary to process your payment or refund. Please refer to each provider's privacy policy for further information.

8.4

Our Service Providers

  • IT service providers, cloud hosting, and data storage providers
  • Legal, accounting, and professional advisers
  • Insurers and risk managers
8.5

Your Employer or Organisation

Where we provide corporate travel management services, we may share booking and travel data with your employer or their designated representatives for reporting, policy compliance, and auditing purposes.

8.6

Legal Disclosures

We may disclose your data where required to do so by law, court order, or to protect the rights, property, or safety of BCD Tour Africa Travel, our clients, or others.

All third-party recipients are required to handle your data in accordance with applicable data protection standards and are not permitted to use your data for their own independent purposes.

SECTION 09

International Transfers of Personal Data

Due to the international nature of travel, your personal data may need to be transferred to, and processed in, countries outside Zimbabwe. Such transfers are necessary to fulfil your travel arrangements (for example, sharing your data with an overseas airline or hotel).

Where your personal data is transferred internationally, we ensure that:

  • The transfer is to a country with adequate data protection standards; or
  • Appropriate safeguards are in place, such as standard contractual clauses; or
  • The transfer is necessary to perform the contract between you and us (e.g. booking a flight); or
  • You have given your explicit consent to the transfer

Our website hosting facilities are located in the United Kingdom, the United States of America, and the Netherlands. We take reasonable steps to ensure your data is protected in these jurisdictions.

SECTION 10

Cookies and Website Technologies

A cookie is a small text file placed on your device by a website. We use cookies and similar tracking technologies on our website to:

  • Ensure the website functions correctly
  • Remember your preferences across visits
  • Analyse website usage through tools such as Google Analytics
  • Improve your browsing experience

You can control or delete cookies through your browser settings. Disabling cookies may affect the functionality of certain parts of our website. Where required by law, we will request your consent before placing non-essential cookies.

For more information on managing cookies, please refer to your browser's help documentation or visit www.aboutcookies.org.

SECTION 11

Data Security

We implement appropriate technical and organisational measures to protect your personal data against:

  • Unauthorised access, disclosure, or use
  • Loss, theft, or destruction
  • Accidental alteration or damage

These measures include password-protected systems, encrypted data transmission, restricted staff access, and regular security reviews.

However, no method of transmission over the Internet is completely secure. While we strive to protect your personal data, we cannot guarantee absolute security and you provide data to us at your own risk. Please do not send us sensitive personal data such as full payment card numbers via unencrypted email.

If you believe your data has been compromised, please contact us immediately using the details in Section 17.

SECTION 12

Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes described in this Policy, or as required by law. When determining retention periods, we consider:

  • The nature of the data and the purpose for which it was collected
  • Legal and regulatory obligations (e.g. tax records, aviation regulations)
  • The possibility of legal proceedings or disputes in which the data may be relevant

When personal data is no longer required, it is securely deleted or anonymised. You may request deletion of your data at any time, subject to our legal obligations to retain certain records.

SECTION 13

Your Rights

Under the Cyber and Data Protection Act [Chapter 12:07] and, where applicable, other data protection legislation, you have the following rights in relation to your personal data:

Right of access

to request a copy of the personal data we hold about you

Right to rectification

to request correction of inaccurate or incomplete data

Right to erasure

to request deletion of your data in certain circumstances

Right to restrict processing

to request that we limit how we use your data

Right to object

to object to processing based on legitimate interests or for direct marketing

Right to data portability

to receive your data in a structured, machine-readable format

Right to withdraw consent

at any time where processing is based on consent

Right to complain

to lodge a complaint with the relevant supervisory authority

To exercise any of these rights, please contact us using the details in Section 17 below. We will respond within 30 days. In some cases we may need to verify your identity before processing your request.

We do not charge a fee for handling reasonable requests, but we reserve the right to charge an administrative fee for manifestly unfounded or excessive requests.

SECTION 14

Children's Privacy

Our services are not directed at children under the age of 18 acting independently. We do not knowingly collect personal data directly from children without the involvement of a parent or guardian.

Where travel arrangements involve minors, we collect and process the necessary data only to the extent required to fulfil those arrangements, with the consent of the accompanying adult.

SECTION 15

Complaints

If you are dissatisfied with how we have handled your personal data, you are entitled to lodge a complaint with the:

Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ)

We would, however, appreciate the opportunity to address your concerns before you approach a regulatory authority. Please contact us in the first instance using the details below.

SECTION 16

Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we do, we will revise the Effective Date at the top of this document and, where appropriate, notify you by email or a notice on our website.

We encourage you to review this Policy periodically to stay informed about how we protect your information.

SECTION 17

Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or the way we handle your personal data, please contact our Data Protection Officer:

Data Protection Officer

BCD Tour Africa Travel

Address
3 Hampton Court
34 Baines Avenue
Harare, Zimbabwe

We aim to respond to all enquiries within 5 business days.

Questions about your data?

Speak to our Data Protection Officer — we usually respond within 5 business days.

Notifications

No notifications

Special Offers

No active offers at the moment.

All Holiday Packages