COVID-19 Privacy Notice
Due to the current public health situation, The Travel Corporation and our brands may temporarily collect additional information from customers, including health or biometric information. In some countries, such information is considered as “sensitive” or “special categories of personal data”.
The Travel Corporation will always treat the information we collect from customers, in particular health and biometric information, with the highest standards of care and in line with all applicable legal requirements and guidelines from public authorities. The Travel Corporation complies with the EU General Data Protection Regulation 2016/679 (GDPR), the UK Data Protection Act 2018 and all amendments, any other legislation relating to personal data and all other local or national legislation and regulatory requirements in force from time to time which apply to us relating to the use of your personal data.
The purpose of this specific privacy notice is to inform our customers of what personal data The Travel Corporation collects, for which purposes and under which legal grounds we may process it during the SARS-CoV-2 pandemic.
WHO ARE WE?
We are the Data Controller for the purposes of the matters detailed in this Privacy Notice.
WHAT PERSONAL DATA DO WE COLLECT?
- Your name and contact details.
- Your COVID-19 vaccination status, including the date of administration of the last dose.
- Where you have accepted to take rapid SARS-CoV-2 medical testing, the date and time of the test. If it is negative, we will not record the result of the test, which will only be processed by a qualified health professional in accordance with local regulations. If the result is positive and results in us being unable to continue to provide you with our services, we will retain the information for as long as is necessary to demonstrate that our withdrawal of services was reasonable.
- Where authorised by local regulations or where you agree, we may collect your temperature before giving you access to our services/premises or to a public area. On such occasions we do not record this information, which is deleted immediately, unless the readings are not within acceptable levels in which case we may refuse access and we may retain the data in order to demonstrate that our refusal of access was reasonable.
- If you have agreed to the use of facial recognition, we may collect your biometric information to access certain areas. We will always offer an alternative, such as badges, to the use of facial recognition. Our facial recognition features are not implemented on our CCTV systems, and will always be offered as a separate system.
- When you have accepted or where required by local regulations, we may collect your name, contact details, date, time and location of your presence in the premises we manage for contact tracing purposes. If you notify us that you have been tested positive, we will not record this information, but only the date, time and location of the risk in order for us be able to notify the relevant customers that may have been exposed, unless otherwise required by law.
- Your information regarding pre-existing health conditions, when you choose to share this information with us. We will only record the existence of such pre-existing health condition, and no detail on your health condition itself. Any detailed information will be processed through a qualified health professional in accordance to local regulations.
- Your medical insurance information, as required by tourism and travel regulations.
WHY DO WE COLLECT PERSONAL DATA?
- To offer to our customers, on a voluntary basis, rapid SARS-CoV-2 medical tests;
- To verify the vaccination status of our customers to
- protect the safety and well-being of passengers and employees,
- respect the local COVID-19 restrictions in locations where vaccination is a condition for entry
- To check body temperature prior to giving access to public areas and our premises, to protect the health and safety of our customers, staff, contractors and suppliers;
- To offer to our customers, on a voluntary basis, an alternative contact-less authentication method, such as facial recognition;
- To record attendance in certain premises we manage, in order to notify our customers if they have been exposed to a risk and to recommend to self-isolate;
- If you choose to share such information with us, to record if you have a particular risk to your health so we can take any additional measure appropriate to ensure your safety;
- To record your medical insurance information as required by health regulations.
WHAT ARE OUR LEGAL GROUNDS TO COLLECT AND PROCESS YOUR PERSONAL DATA?
- Your explicit consent.;
- To perform the contract you have with us;
- To comply with a legal obligation: when we are required to collect and process your information because we have a legal requirement to do so in some jurisdictions ;
- To comply with public health regulations;
- To protect your vital interest: when required by the circumstances, we may process your data to protect your vital interests or the vital interests of other individuals;
- Our legitimate interests: we may process your data because it is our legitimate interests to do so, or the legitimate interests of others.
WHO ARE WE SHARING YOUR PERSONAL DATA WITH?
- Public authorities, in particular health authorities, if we have a legal obligation to do so;
- Our providers, including qualified health professionals in line with local regulations, and our biometric solutions providers.
- It is necessary to perform your contract with us (for instance, because you are travelling outside the EEA);
- We have the legal obligation to do so.
HOW LONG DO WE KEEP YOUR DATA FOR?
- For the time of your tour or travel;
- 15 days to one month after your visit to our premises, unless a longer period is required by law;
- For as long as necessary to comply with our legal obligations, contractual requirements or the establishment, exercise or defence of legal claims;
We will delete/destroy your personal data immediately after the relevant retention period above is reached.
HOW DO WE PROTECT YOUR DATA?
The information you share with us under the scope of this Privacy Notice will be secured by additional technical and organisational measures and only staff required to see this information will be able to access it on a “need-to-know” basis.
Paper-based records will be kept securely in locked cabinets. Digital records will be kept in encrypted and separate databases or folders with strict access controls in place.
WHAT ARE MY RIGHTS AND HOW DO I EXERCISE THEM?
- be informed of any data processing;
- access to your personal data;
- rectify your personal data;
- erase your personal data, in some circumstances;
- restrict processing of your personal data, in some applicable circumstances;
- data portability, in applicable circumstances;
- object to the processing of your personal data, in some circumstances;
- to withdraw consent to the processing of your personal data, where applicable.
If you wish to exercise any of your rights, please contact us either by e-mail to firstname.lastname@example.org, by telephone on 01 481 714334 or by post to Travel House, Rue du Manoir, St Peter Port, Guernsey, GY1 2JH, Channel Islands.
You will not have to pay a fee to exercise any of your rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances and we will explain the reasons in our response to you.
You also have the right to make a complaint at any time to the relevant supervisory authority, for example the Information Commissioner’s Office in the UK.
Further information about your rights is included in our standard Privacy Notice which this Notice supplements.