Legal

Privacy Policy

This policy explains what personal data FlyJanuary.org collects when you enquire about or book travel with us, why we hold it, who we share it with, and the rights you have over it.

Last updated:

Who we are

FlyJanuary.org ("we", "us") is a travel agency specialising in January departures. For the purposes of UK data protection law we are the data controller for the personal data described in this policy.

[PLACEHOLDER — registered company name, company number and registered office address]
Correspondence address: 71–75 Shelton Street, London WC2H 9JQ, United Kingdom
Email: hello@flyjanuaryorg.com
Telephone: +44 20 4525 1180

What data we collect

We collect only what we need to quote for and arrange your travel.

When you make an enquiry

  • Your name, email address and telephone number
  • Your departure airport, destination, travel dates and number of travellers
  • Your approximate budget and anything you tell us in the message field

When you book

  • Full names exactly as shown on passports, and dates of birth
  • Passport number, issue and expiry dates, and nationality
  • Billing address and payment details
  • Frequent flyer numbers, seat and meal preferences
  • Where you choose to tell us: accessibility requirements, dietary requirements and relevant medical information. Some of this is special category data and we treat it accordingly — see below.

When you use this website

  • Your email address, if you subscribe to fare alerts
  • Technical and usage data collected through cookies and similar technologies, described in ourcookie policy

Why we use it, and our lawful basis

PurposeLawful basis
Responding to your enquiry and preparing a quotationLegitimate interests / steps prior to a contract
Booking flights, accommodation and transfers on your behalfPerformance of a contract
Checking passport validity, visa and entry requirementsPerformance of a contract
Passing accessibility, dietary or medical needs to suppliersExplicit consent
Sending fare alerts and marketing emailsConsent, withdrawable at any time
Keeping financial and booking recordsLegal obligation
Improving this website and our serviceLegitimate interests

Special category data

Health, accessibility and dietary information can reveal sensitive details about you. We collect it only where you volunteer it so that we can arrange what you have asked for, we rely on your explicit consent, we share it only with the specific supplier who needs it, and we delete it once the trip is complete and any claim period has passed.

Who we share it with

We do not sell your data. We share it only where it is necessary to deliver the travel you have asked us to arrange:

  • Airlines, hotels, transfer companies, tour operators and cruise lines named on your itinerary
  • Global distribution systems and booking platforms used to issue tickets
  • Payment processors, who handle card details directly — we do not store full card numbers
  • Visa and travel authorisation services, where you have asked us to assist
  • Our professional advisers — accountants, insurers and lawyers — where genuinely required
  • Government and border authorities, where we are legally obliged to provide passenger information

International transfers

International travel necessarily involves sending data abroad. If you book a hotel in Thailand, we must send your name to that hotel. Where we transfer personal data outside the UK we rely on UK adequacy regulations where they exist, or on appropriate safeguards such as the International Data Transfer Agreement or standard contractual clauses. Where a transfer is strictly necessary to perform the contract you have asked us to arrange, we may rely on that necessity.

How long we keep it

  • Enquiries that do not become bookings: up to 24 months, then deleted
  • Booking and financial records: 7 years, to meet HMRC and accounting obligations
  • Passport details: deleted once the trip is complete and any claim window has closed
  • Special category data: deleted once the trip is complete
  • Marketing consent records: until you withdraw consent, plus a short period to evidence the withdrawal

Your rights

Under UK GDPR you have the right to:

  • Be informed about how we use your data — that is this policy
  • Request a copy of the data we hold about you
  • Have inaccurate data corrected
  • Ask us to erase your data, where we have no overriding legal reason to keep it
  • Ask us to restrict processing while a concern is investigated
  • Object to processing carried out under legitimate interests
  • Request portability of data you provided to us
  • Withdraw consent at any time, without affecting processing already carried out

To exercise any of these, email hello@flyjanuaryorg.com. We will respond within one month. We may ask you to verify your identity first.

Marketing

We send fare alerts only to people who have asked for them. Every email carries a one-click unsubscribe link, and we act on unsubscribes immediately. We do not pass your details to third parties for their own marketing.

Security

We use encrypted connections, restrict access to personal data to staff who need it, and hold booking data in access-controlled systems. No transmission over the internet is completely secure, so we cannot guarantee absolute security, but we take these obligations seriously and review them regularly.

Children

Our services are aimed at adults. Where a booking includes children, we collect their details from the responsible adult making the booking and use them only for that trip.

Complaints

Please raise any concern with us first — we would rather fix it directly. If you remain dissatisfied you can complain to the Information Commissioner's Office, the UK supervisory authority, at ico.org.uk.

Changes to this policy

We update this policy when our practices change. The date at the top of this page shows when it was last revised. Material changes affecting existing clients will be notified by email.

See also our terms and conditions, cookie policy and disclaimer. To talk to a human about any of this, get in touch.