Privacy Policy
Global International Travel Pty Ltd — ABN 20 783 443 838
1. About this Policy
We manage personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We also comply with the Notifiable Data Breaches (NDB) scheme and applicable e-marketing laws (including the Spam Act 2003). By using our website or services you consent to this Policy.
2. What we collect
We collect only what is reasonably necessary to arrange travel and run our business, such as: identity/contact details; travel documents (passport/visa, frequent-flyer IDs); booking preferences; limited payment details processed via PCI-compliant providers (we don’t store full card numbers); communications with our team (email/SMS/WhatsApp); and website analytics/cookie data. Sensitive information (e.g., health or accessibility needs, dietary requirements that may reveal beliefs) is collected only with your consent where needed to arrange travel. If you provide information about someone else (e.g., a co-traveller), you confirm you’re authorised to do so and have informed them of this Policy.
3. How we collect it
Directly from you (phone, email, forms, social, in person), from your authorised representative, or from suppliers assisting with your booking (airlines, hotels, ground partners). We also use cookies and similar tech on our site (see Section 12). Client support & communications: You may provide information to our team through support channels (for example, email, phone, WhatsApp/SMS or web forms). To resolve issues and deliver service, we may ask for contact details, booking references, screenshots or documents relevant to your request.
4. Why we use it
To: arrange and manage your bookings; issue travel documents and handle changes; verify identity and reduce fraud; process payments; provide tailored client care; send service updates; improve our operations and website; comply with legal obligations; and—if you opt in—send marketing/event updates you can opt out of anytime.
5. Our lawful basis (international frameworks)
Where international laws such as the EU/UK GDPR apply, we rely on: contract performance, consent (e.g., sensitive data, marketing), legitimate interests (service improvement, security), and legal obligation (record-keeping).
6. Disclosures we make
We may disclose personal information to: Travel suppliers (airlines, hotels, cruise lines, DMCs, insurers, embassies/consulates where needed); Service providers who host our systems, email/CRM, itinerary tools, support, or payments—bound by confidentiality/data-protection terms; Government/regulators where required or authorised by law; Others with your consent. We do not sell or rent client lists. Service portals & integrations: Some services are delivered through secure third-party platforms (for example, booking engines, itinerary builders, payment gateways, airline/hotel portals). If you link or access these platforms, they may receive personal information as needed to provide the service.
7. Cross-border disclosure (APP 8)
Because travel is global, we routinely disclose information to overseas recipients relevant to your itinerary. We take reasonable steps to ensure those recipients handle your information consistently with the APPs (including contractual safeguards and due diligence). Where that isn’t practicable, we’ll seek your express consent to proceed.
8. Data storage, security & staff obligations
We store information in secure cloud environments located in Australia and trusted overseas locations (e.g., Singapore/US). We apply proportionate technical and organisational measures—access controls, authentication, encryption in transit where appropriate, logging and periodic reviews—and require confidentiality and privacy training for all staff and contractors. We retain records only as long as needed; travel/finance records are typically kept up to seven years, then securely deleted or de-identified. Where deletion is not immediately possible (for example, because data sits in backups), we segregate and securely store it until deletion is feasible. Passport scans & verification: Where passport/ID scans are required, we minimise copies, restrict access, and delete or de-identify them when no longer needed.
9. Marketing & your choices
We comply with the Spam Act and Do Not Call rules. Marketing is sent only with consent or where reasonably expected from our relationship. Every message includes a working unsubscribe; we honour opt-outs promptly and maintain suppression lists.
10. Your rights (access, correction, anonymity)
You may request access to, or correction of, your information at any time; we’ll respond within a reasonable period and generally at no cost. You may interact with us anonymously or under a pseudonym where lawful and practicable. Notice to corporate travellers: Where your travel is arranged by your employer, that organisation may direct or access certain booking information (e.g., reports or compliance data).
11. Data portability (where applicable)
Where permitted by law, you may request a copy of certain personal information in a structured, commonly used and machine-readable format.
12. Cookies, analytics & social features
Our site uses cookies for functionality, performance and analytics. You can refuse cookies in your browser; some features may not work. We use third-party tools (e.g., Google Analytics, Meta Pixel) which may collect usage data via cookies. Social media features & widgets: Our services may include social features or widgets (e.g., share buttons) governed by the provider’s privacy policy.
13. Automated decision-making / profiling
We do not make decisions that significantly affect your rights or interests based solely on automated processing. If that changes, we’ll provide the disclosures required by law.
14. Data breaches
If we suspect an eligible data breach likely to cause serious harm, we will promptly assess and notify affected individuals and the OAIC in line with the NDB scheme.
15. International data transfers (EU/UK residents)
If you are located in the EU/UK, we rely on appropriate transfer mechanisms such as Standard Contractual Clauses (and UK addenda) or other safeguards recognised by applicable law.
16. Change of control
If we undergo a reorganisation, merger or sale, personal information may transfer to the successor entity subject to this Policy.
17. Children
We collect children’s details only with consent from a parent or legal guardian and only as necessary to arrange travel. If you believe a child has provided us information without appropriate consent, please contact us and we will take steps to delete it.
18. Updates to this Policy
If we make material changes, we will post an updated notice on our website and, where appropriate, notify you by email. Prior versions are available on request.
Contact us
Privacy Officer — Global International Travel Pty Ltd
enquiries@globalinternationaltravel.com.au
+61 (3) 9826 9600
Suite 202, 505 Toorak Road, Toorak VIC, Australia
If you’re not satisfied with our response, contact the OAIC: oaic.gov.au / 1300 363 992.