Peace Flight Hub is a dedicated digital distribution platform wholly owned and operated by Peace Travel and Tour Ltd, a Private Limited Company legally incorporated in England and Wales under Company Registration Number: 11000329. We operate out of our physical headquarters at 38 High Street Harlesden, London, United Kingdom, NW10 4LS. This comprehensive privacy charter details exactly how we manage, protect, and process passenger records in strict conformity with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA), and the Privacy and Electronic Communications Regulations (PECR).
1. Comprehensive Scope of Personal Information Collection
To process secure flight queries, optimize routing matrix alternatives, and execute manual re-ticketing tasks under our IATA Accreditation (91201390) and ATOL License (11434), we gather distinct data tiers through your direct web entries, digital transmissions, or real-time telephone consults via our mainline (020 8965 0364):
- Primary Identity Details: Full legal passenger names (matching official international travel passports), dates of birth, gender designations, passport numbers, issue/expiry metrics, and nationality vectors.
- Direct Contact Coordinates: Active personal telephone lines, geographic billing or residential addresses, and corporate or personal email addresses.
- Technical Digital Telemetry: Internet Protocol (IP) locations, device fingerprints, unique browser environments, cookie tracking parameters, Google Click Identifiers (gclid), and dynamic conversion tracking markers.
- Itinerary and Logistical Records: Passenger Name Records (PNR), booking reference strings, seat allocation selections, specialized meal profiles, and emergency medical clearance or mobility assistance parameters.
- Transactional and Billing Information: Secure payment tokens, card issuing banks, billing addresses, and payment confirmation logs. We strictly enforce a protocol where full credit card numbers are never stored in plain-text arrays.
2. Legal Frameworks & Operational Objectives for Data Use
In absolute compliance with UK GDPR Article 6, we process data only where a distinct lawful basis applies—primarily the fulfillment of a travel contract, compliance with aviation safety regulations, or under explicit legitimate commercial interest:
- Contractual Fulfillment: Utilizing your details to query Global Distribution Systems (GDS), reserve live seat segments, and finalize electronic ticket generations.
- Independent Agency Assistance: Managing manual date adjustments, route changes, cabin upgrades, spelling corrections, and cancellation logs within the operating carriers' reservation portals on your direct request.
- Live Telephony Verification & Security: Audio recordings of incoming customer interactions to our London office are processed strictly for quality review, accurate transaction logging, protection against payment fraud, and the internal validation of manual itinerary modification agreements.
3. Strict Multi-Layered Data Security Protocols
Our structural data protection network incorporates advanced technical and administrative firewalls designed to mitigate unauthorized access, disclosure, or altering of customer records:
- Data Encryption Standards: All web forms, session connections, and transaction interfaces are wrapped in active Secure Sockets Layer (SSL) transport protocols.
- Payment Security (PCI-DSS): Digital financial authorizations are pushed instantly through tokenized gateways. Staff are barred from retaining, transcribing, or storing raw card data on local devices or physical documents.
- Restricted Access Frameworks: Internal system credentials to GDS terminals and customer databases are limited exclusively to certified, accredited travel agents actively handling your specific booking file.
4. Data Sharing Constraints and System Transfers
To finalize travel contracts, Peace Flight Hub transfers relevant passenger information strictly to essential industry entities, including executing international air carriers, global IATA clearing centers, and national border control agencies.
Strict Prohibition Against Marketing Disclosures: Peace Travel and Tour Ltd guarantees that customer identity data, phone records, and email addresses are never sold, leased, rented, or distributed to independent advertising agencies, lead brokers, or peripheral third parties for commercial promotion.
5. Retention Mandates
Personal records are held within our active operational datastores exclusively for the period necessary to complete your travel itinerary, finalize post-ticketing carrier financial settlements, manage potential dispute timelines, and satisfy corporate accounting requirements set out by the UK Civil Aviation Authority (CAA) and HM Revenue & Customs (HMRC).
6. Your Rights Under UK GDPR Frameworks
As a resident of the United Kingdom, you hold statutory rights regarding your personal information, including the right to request a comprehensive copy of the data we retain, request rapid correction of typing errors, restrict specific processing parameters, or command complete system erasure where contractual obligations have completed.
To submit a formal Data Subject Access Request (DSAR) or update your compliance preferences, contact our designated data officer directly by emailing reservation@peaceflighthub.com or by filing a written letter to our physical business location: Peace Travel and Tour Ltd, 38 High Street Harlesden, London, NW10 4LS.