Privacy Policy
1. Who We Are
Tamara Pather (Pty) Ltd (Registration: 2025/465576/07) is the responsible party for personal information processed in connection with our travel and concierge services.
2. What We Collect
- Identity & contact data — name, email, phone/WhatsApp, postal address.
- Travel preferences & itinerary data — destinations, dates, companion details, special requests.
- Booking data — reservation numbers, ticket details, supplier confirmations.
- Payment-related data — amounts, invoice details and transaction references (card numbers are processed by our payment gateway and are not stored by us).
- Communications — email and WhatsApp messages, voice notes where relevant.
- Website data — enquiry form submissions, device and usage data (see Cookie Policy).
3. How We Use Your Data
- To curate, quote, book, and deliver travel and concierge services.
- To manage changes, cancellations, and support requests.
- To process payments, invoicing, and accounting.
- To communicate with you (email, phone, WhatsApp).
- To personalise experiences and improve our services.
- To comply with legal, tax, and regulatory obligations.
4. Lawful Basis (POPIA)
We process personal information in accordance with POPIA’s conditions for lawful processing, including:
- Consent where required (e.g., direct marketing by electronic means).
- Contract to provide requested travel/concierge services.
- Legal obligation (e.g., financial record-keeping, fraud prevention).
- Legitimate business purposes consistent with POPIA’s processing limitation and purpose specification requirements.
5. Sharing with Third Parties
We share data only as necessary to deliver your services:
- Travel suppliers (airlines, hotels, DMCs, transfer providers, event organisers).
- Technology providers (e.g., Travefy for itinerary/CRM, website hosting, email service providers).
- Payment processors and anti-fraud providers.
- Professional advisors (accountants, auditors) where required by law.
We do not sell personal information.
6. Cross-Border Transfers
Because travel is global, information may be transferred to or stored in countries outside South Africa (e.g., where suppliers or technology providers are located). We take reasonable steps to ensure that recipients are subject to laws, binding agreements, or safeguards that uphold standards of protection comparable to POPIA.
7. Security Safeguards
- Access controls and role-based permissions.
- Encryption in transit where supported.
- Vendor due diligence and confidentiality undertakings.
- Staff awareness and need-to-know access.
- Incident response processes and regulatory notifications where required.
8. Data Retention
- Booking and financial records: retained as required by law (typically a minimum of 5 years for tax/accounting).
- Enquiry data and routine correspondence: retained for up to 24 months to support follow-up and service quality.
- If you request deletion, we will retain only what is necessary to meet legal obligations or resolve disputes.
9. Your Rights
- Access your personal information we hold.
- Request correction or deletion where appropriate.
- Object to or restrict certain processing.
- Withdraw consent (e.g., marketing) at any time.
- Lodge a complaint with the Information Regulator (South Africa).
10. WhatsApp Communications
- We communicate with many clients via WhatsApp for speed and convenience.
- WhatsApp is a third‒party platform with its own terms and privacy policy.
- Please do not send full card numbers or passwords over WhatsApp.
- Key booking decisions and changes may be summarised in writing (email/itinerary) for clarity.
11. Payments & Fraud Prevention
- Online payments are processed by our payment gateway; we do not store card numbers.
- We may share limited data with fraud prevention services to protect clients and the Company.
- Invoices may be issued and reconciled via our accounting tools.
12. Website Forms & Travefy CRM
- Enquiry and booking forms collect the information needed to respond and provide quotes.
- We may store itineraries and client details securely in Travefy as our CRM/itinerary tool.
- By submitting forms, you authorise us to process your information for the stated purposes.
13. Marketing Communications
- We send marketing only with your consent or where permitted by law.
- You can opt-out at any time via the link provided or by contacting us.
14. Cookies & Analytics
We use cookies and similar tracking technologies on this website. Please see our Cookie Policy for details and control options.
15. Changes to this Policy
We may update this Privacy Policy from time to time. The “Last Updated†date will reflect the latest version.
16. Contact & Information Officer
For privacy enquiries or to exercise your rights, please contact our Information Officer:
- Name: [Insert Information Officer Name]
- Email: [Insert dedicated privacy email, e.g., privacy@yourdomain.co.za]
- Postal Address: [Insert business postal address]
We also maintain a PAIA/POPIA manual, available on request.
Tamara Pather (Pty) Ltd • Registration: 2025/465576/07 Effective: 01 September 2025