Legal
Privacy Policy
This policy explains what personal data FlyJanuary.org collects when you enquire about or book travel with us, why we hold it, who we share it with, and the rights you have over it.
Last updated:
Who we are
FlyJanuary.org ("we", "us") is a travel agency specialising in January departures. For the purposes of UK data protection law we are the data controller for the personal data described in this policy.
[PLACEHOLDER — registered company name, company number and registered office address]
Correspondence address: 71–75 Shelton Street, London WC2H 9JQ, United Kingdom
Email: hello@flyjanuaryorg.com
Telephone: +44 20 4525 1180
What data we collect
We collect only what we need to quote for and arrange your travel.
When you make an enquiry
- Your name, email address and telephone number
- Your departure airport, destination, travel dates and number of travellers
- Your approximate budget and anything you tell us in the message field
When you book
- Full names exactly as shown on passports, and dates of birth
- Passport number, issue and expiry dates, and nationality
- Billing address and payment details
- Frequent flyer numbers, seat and meal preferences
- Where you choose to tell us: accessibility requirements, dietary requirements and relevant medical information. Some of this is special category data and we treat it accordingly — see below.
When you use this website
- Your email address, if you subscribe to fare alerts
- Technical and usage data collected through cookies and similar technologies, described in ourcookie policy
Why we use it, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Responding to your enquiry and preparing a quotation | Legitimate interests / steps prior to a contract |
| Booking flights, accommodation and transfers on your behalf | Performance of a contract |
| Checking passport validity, visa and entry requirements | Performance of a contract |
| Passing accessibility, dietary or medical needs to suppliers | Explicit consent |
| Sending fare alerts and marketing emails | Consent, withdrawable at any time |
| Keeping financial and booking records | Legal obligation |
| Improving this website and our service | Legitimate interests |
Special category data
Health, accessibility and dietary information can reveal sensitive details about you. We collect it only where you volunteer it so that we can arrange what you have asked for, we rely on your explicit consent, we share it only with the specific supplier who needs it, and we delete it once the trip is complete and any claim period has passed.
Who we share it with
We do not sell your data. We share it only where it is necessary to deliver the travel you have asked us to arrange:
- Airlines, hotels, transfer companies, tour operators and cruise lines named on your itinerary
- Global distribution systems and booking platforms used to issue tickets
- Payment processors, who handle card details directly — we do not store full card numbers
- Visa and travel authorisation services, where you have asked us to assist
- Our professional advisers — accountants, insurers and lawyers — where genuinely required
- Government and border authorities, where we are legally obliged to provide passenger information
International transfers
International travel necessarily involves sending data abroad. If you book a hotel in Thailand, we must send your name to that hotel. Where we transfer personal data outside the UK we rely on UK adequacy regulations where they exist, or on appropriate safeguards such as the International Data Transfer Agreement or standard contractual clauses. Where a transfer is strictly necessary to perform the contract you have asked us to arrange, we may rely on that necessity.
How long we keep it
- Enquiries that do not become bookings: up to 24 months, then deleted
- Booking and financial records: 7 years, to meet HMRC and accounting obligations
- Passport details: deleted once the trip is complete and any claim window has closed
- Special category data: deleted once the trip is complete
- Marketing consent records: until you withdraw consent, plus a short period to evidence the withdrawal
Your rights
Under UK GDPR you have the right to:
- Be informed about how we use your data — that is this policy
- Request a copy of the data we hold about you
- Have inaccurate data corrected
- Ask us to erase your data, where we have no overriding legal reason to keep it
- Ask us to restrict processing while a concern is investigated
- Object to processing carried out under legitimate interests
- Request portability of data you provided to us
- Withdraw consent at any time, without affecting processing already carried out
To exercise any of these, email hello@flyjanuaryorg.com. We will respond within one month. We may ask you to verify your identity first.
Marketing
We send fare alerts only to people who have asked for them. Every email carries a one-click unsubscribe link, and we act on unsubscribes immediately. We do not pass your details to third parties for their own marketing.
Security
We use encrypted connections, restrict access to personal data to staff who need it, and hold booking data in access-controlled systems. No transmission over the internet is completely secure, so we cannot guarantee absolute security, but we take these obligations seriously and review them regularly.
Children
Our services are aimed at adults. Where a booking includes children, we collect their details from the responsible adult making the booking and use them only for that trip.
Complaints
Please raise any concern with us first — we would rather fix it directly. If you remain dissatisfied you can complain to the Information Commissioner's Office, the UK supervisory authority, at ico.org.uk.
Changes to this policy
We update this policy when our practices change. The date at the top of this page shows when it was last revised. Material changes affecting existing clients will be notified by email.
See also our terms and conditions, cookie policy and disclaimer. To talk to a human about any of this, get in touch.