Privacy Policy
Effective 21 September 2026
1. Responsible party and scope
- 1.1. Travel African Time (Pty) Ltd, registration number 2019/334030/07, is a South African travel company and tour operator. References to “Travel African Time”, “we”, “us” and “our” are references to Travel African Time (Pty) Ltd.
- 1.2. This Privacy Policy applies to website visitors, enquirers, clients, travellers, newsletter subscribers, authorised representatives and any person whose personal information is provided to us in connection with an enquiry, proposed journey, booking or travel service.
- 1.3. For purposes of the Protection of Personal Information Act, 2013 (“POPIA”), we are the responsible party in respect of personal information for which we determine the purpose and means of processing. Equivalent terms, including “controller” and “personal data”, may apply under other applicable data-protection laws.
- 1.4. We do not sell personal information. We process personal information only for lawful purposes connected with our business, the provision of travel services and the purposes described in this Policy.
2. Personal information we may collect
The personal information processed will depend upon the nature of the enquiry, journey or relationship and may include:
- 2.1. Identity and contact information: names, titles, residential and billing addresses, email addresses, telephone numbers, nationality, country of residence and date of birth.
- 2.2. Travel-document information: passport number, full name as shown in a passport, country of issue, issue and expiry dates, and copies of passports, visas or other documents required to arrange travel.
- 2.3. Journey and preference information: destinations, proposed dates, accommodation and activity preferences, rooming arrangements, travel companions, prior journeys booked through us, loyalty details and special-occasion information.
- 2.4. Special personal information: dietary requirements, allergies, medical considerations, disabilities, accessibility or mobility requirements and other health-related information reasonably necessary to arrange appropriate and safe travel services.
- 2.5. Emergency and family information: emergency contacts and information concerning children or other persons travelling in the same party.
- 2.6. Booking and financial information: quotations, invoices, payment status, transaction references and information required for refunds, reconciliation, accounting and statutory records. Payment-card information submitted through a secure payment-provider page is processed by that provider and is not stored by our public website.
- 2.7. Communication records: enquiry forms, correspondence, call notes, messages, feedback, complaints and records relating to services provided.
- 2.8. Marketing information: newsletter subscriptions, communication preferences and records of consent, withdrawal or objection.
- 2.9. Website and technical information: IP address, browser and device information, pages viewed, referring source, approximate location or currency preference, and cookie or analytics information described in section 12.
3. Sources of personal information
- 3.1. We ordinarily collect personal information directly from the person concerned through an enquiry, consultation, booking, email, telephone call, message, form or document.
- 3.2. Information may also be supplied by a lead traveller, family member, travel companion, authorised representative or referring travel professional. A person who provides another person’s information must be authorised to do so and must make this Policy available to that person.
- 3.3. We may receive booking, service or travel information from accommodation providers, airlines, charter operators, transfer companies, guides, destination-management companies, insurers, payment providers and other suppliers involved in a journey.
- 3.4. We may receive limited information through our website, analytics services, newsletter platform, social-media channels, referrals and public or authorised sources where reasonably necessary and lawful.
4. Purposes of processing
We may process personal information for the following purposes:
- 4.1. to respond to enquiries and understand the composition, requirements and preferences of a travelling party;
- 4.2. to research, design, cost and present a private journey or travel proposal;
- 4.3. to obtain availability, make and administer reservations, issue travel documents and coordinate the services comprising a journey;
- 4.4. to communicate before, during and after travel, including changes, payment deadlines, passport-expiry reminders and material service, entry, health or safety information;
- 4.5. to ensure continuity of service where another authorised member of our team is required to assist;
- 4.6. to process payments and refunds, maintain accounting and tax records, prevent fraud and comply with legal and regulatory obligations;
- 4.7. to manage emergencies, complaints, insurance matters, legal claims and the security of travellers, our personnel and our systems;
- 4.8. to maintain an appropriate client and travel history for service continuity and the management of our ongoing client relationships;
- 4.9. to improve our journeys, website, communications and service through feedback and proportionate analysis; and
- 4.10. to send travel news, journal content and other direct marketing where permitted by law.
5. Lawful grounds for processing
- 5.1. Depending upon the circumstances, we process personal information where it is necessary to take steps at a person’s request before entering into a contract, to perform a contract, to comply with a legal obligation, to protect a legitimate interest that is not overridden by the person’s rights, or with consent.
- 5.2. Special personal information, including relevant health or accessibility information, will be processed only where permitted under POPIA or another applicable law. This may include express consent, a legal obligation, or the protection of a person’s vital interests in an emergency.
- 5.3. Where information is required to design, book or safely manage a journey, failure to provide that information may prevent us or a supplier from providing all or part of the requested service.
- 5.4. We do not make decisions producing legal or similarly significant effects through solely automated processing.
6. Disclosure to travel suppliers and service providers
- 6.1. We do not sell personal information and do not disclose it for an unrelated commercial purpose.
- 6.2. In order to plan and deliver a journey, we may disclose the information reasonably required by relevant hotels, lodges, camps, villas, airlines, charter operators, transfer companies, guides, destination-management companies, activity providers and other travel suppliers.
- 6.3. We may disclose information to payment providers, insurers or travel-protection providers, visa or immigration advisers, emergency-assistance providers, professional advisers and providers of technology, communication, document storage, website hosting, analytics and information-security services.
- 6.4. Travel suppliers and other service providers may process information only for the relevant service, their legal obligations or another lawful purpose. Certain suppliers act as independent responsible parties and their own privacy policies may apply.
- 6.5. We may disclose information where required by law, regulation, court order or lawful governmental request, or where reasonably necessary to protect a person, our legal rights, or the security and integrity of our operations.
- 6.6. Information may be disclosed in connection with a lawful merger, reorganisation, financing, sale or transfer of all or part of our business, subject to appropriate confidentiality and data-protection safeguards.
- 6.7. We will obtain appropriate permission before publishing an identifiable client testimonial, photograph or story, unless another lawful basis clearly applies.
7. International travel and cross-border transfers
- 7.1. The performance of international travel services may require relevant information to be transferred to suppliers, authorities or service providers in a destination or transit country, including a country whose privacy laws differ from those of South Africa.
- 7.2. Our principal operations are based in South Africa. Certain cloud, communication and travel-service providers may process information in other countries.
- 7.3. We take reasonable steps to ensure that cross-border transfers comply with section 72 of POPIA and any other applicable law. Depending upon the circumstances, this may involve adequate legal protection, contractual safeguards, consent, performance of a contract or another lawful transfer basis.
- 7.4. Information disclosed across borders will be limited to what is reasonably necessary for the relevant booking, service, safety or legal purpose.
8. Security and confidentiality
- 8.1. Passport information, health information, private travel documents and financial records are confidential and are not intended for public display.
- 8.2. We maintain appropriate and reasonable technical and organisational safeguards. These may include controlled access, authentication, audit records, secure document storage, encryption where appropriate, supplier controls and duties of confidentiality.
- 8.3. Access is restricted to authorised persons who require the information to perform their functions. External service providers are required to protect information and to process it only for authorised purposes.
- 8.4. No system or transmission method is entirely secure. We assess reasonably foreseeable risks and review safeguards as appropriate, but cannot warrant absolute security.
- 8.5. Clients should use an appropriately secure method when sending passports or other sensitive documents and should inform us promptly if information may have been sent to the incorrect recipient or otherwise compromised.
9. Retention and destruction
- 9.1. Personal information is retained only for as long as reasonably required for the purpose for which it was collected, a compatible purpose, or a legal, tax, accounting, insurance or dispute-resolution requirement.
- 9.2. Enquiry and client-history records may be retained for an appropriate period to permit follow-up, service continuity and the management of returning-client relationships. Booking and financial records are retained for the periods required by applicable law and legitimate business obligations.
- 9.3. Passport copies, health information and other sensitive travel documents are subject to separate review and will not be retained longer than reasonably required for the journey, supplier requirements, safety, legal obligations or a continuing client instruction.
- 9.4. Direct-marketing records are retained until a person unsubscribes, withdraws consent or objects, subject to retaining a minimal suppression record necessary to give effect to that choice.
- 9.5. When information is no longer required, it will be securely deleted, destroyed or de-identified, subject to lawful backup and archival cycles.
10. Direct marketing
- 10.1. We may send travel news, journal content and journey inspiration where a person has subscribed or where direct marketing to an existing client is otherwise permitted by applicable law.
- 10.2. A recipient may unsubscribe by using the link in a marketing email or by contacting us. An objection to marketing will not prevent necessary communication concerning an enquiry, booking or journey.
- 10.3. We do not authorise another business to use personal information for its own direct marketing unless the person concerned has authorised that use or applicable law otherwise permits it.
11. Children
- 11.1. Our website and services are directed to adults arranging travel. We do not knowingly invite a child to submit personal information directly through the website.
- 11.2. Where a journey includes a child, a parent, guardian or properly authorised adult may provide information reasonably required to arrange appropriate services and comply with travel, safety or legal requirements.
- 11.3. Children’s information is processed with particular care, is limited to relevant lawful purposes and is disclosed only where reasonably necessary and permitted.
12. Cookies, browser storage and analytics
- 12.1. Our website uses essential browser storage or similar technology where reasonably necessary for security, core operation and the retention of a visitor’s privacy and currency choices.
- 12.2. Optional analytics technology may be used only in accordance with the preference selected through our cookie settings. Analytics assist us in understanding how the website is found and used, which pages are useful and whether an enquiry arose from website content.
- 12.3. Analytics information may include IP address, browser and device type, approximate location, referring source, pages viewed and interaction events. We do not use website analytics to represent that a visitor has selected travel dates or to expose private traveller or supplier information.
- 12.4. On a first visit, a person may accept optional analytics, reject optional analytics or manage the available preference. Declining optional analytics does not prevent access to the website.
- 12.5. A person may withdraw or change the preference at any time by selecting “Privacy settings” in the website footer. The browser may also be configured to restrict or delete cookies, although certain preferences may then not operate as intended.
- 12.6. Links to third-party websites, social platforms and services are governed by those organisations’ own privacy and cookie practices.
13. Rights of data subjects
Subject to POPIA and any other applicable law, a person may have the right to:
- 13.1. request confirmation of whether we hold personal information concerning that person and request access to it;
- 13.2. request correction, updating, completion, destruction or deletion of information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, unlawfully obtained or no longer authorised to be retained;
- 13.3. object, on reasonable grounds, to processing based upon legitimate interests and object at any time to processing for direct marketing;
- 13.4. withdraw consent where processing relies upon consent, without affecting the lawfulness of processing before withdrawal;
- 13.5. request restriction or portability where the applicable law provides such a right; and
- 13.6. lodge a complaint with the Information Regulator of South Africa or another competent supervisory authority.
We may require reasonable proof of identity and authority before responding. Rights are subject to lawful limitations, including statutory retention obligations, privilege, the rights of other persons and other grounds permitted by law. Any applicable limitation will be explained.
14. Security compromises
Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will investigate, contain and address the security compromise and will notify the Information Regulator and affected data subjects as required by POPIA or another applicable law. Notification may be delayed where a competent authority lawfully requires such delay.
15. Amendments to this Policy
We may amend this Policy to reflect changes to our services, systems or legal obligations. The current version and effective date will be published on this page. Where an amendment materially affects the use of information already entrusted to us, we will take reasonable steps to bring the amendment to the attention of affected persons and will obtain consent where required by law.
16. Contact details and complaints
Privacy enquiries, objections and requests may be sent to mikhail@travelafricantime.com or trips@travelafricantime.com.
Travel African Time (Pty) Ltd
Registration number: 2019/334030/07
De Villiers Way, Glencairn, Cape Town, South Africa, 7975
If a concern is not resolved, a complaint may be submitted to the Information Regulator of South Africa.
Questions may be sent to trips@travelafricantime.com.
Return to our welcome page