LEGAL
Privacy Policy
Introduction
This Privacy Policy describes how Vcantine Travel and Trade Ltd ("Provider") collects, processes, stores, and protects personal data obtained through the MBT website ("Platform"). The Platform is provided to Corporate Clients ("Clients") for the purpose of managing employee travel bookings. By using the Platform, the Client acknowledges and agrees to the practices described herein.
Categories of Personal Data Collected
1. Client account information:
- Company name
- Billing address
- Tax ID
- Point of contact
- Administrators
2. Employee Information:
- Full name
- Contact information (email, phone, etc)
- Job title, department, and organizational details
- Travel document details (Passport or Identification information), Frequent flyer numbers, seat preferences, etc required for travel
- Optional travel preferences
- Travel booking data: flight, hotel, train reservations, itinerary, travel dates, billing, and payment details (corporate card or virtual card metadata), booking history
- Communications: Support tickets, emails, messages, and notes stored in the system
- Payment information: We may collect or process payment card information directly or via third-party payment processors. We do not necessarily store all card data
3. Booking and Travel Information:
- Flight, hotel, and related reservation details
- Travel dates, destinations, and itineraries
- Approval workflow reasons
- Policy-compliance data
4. Technical and Usage information:
- IP address and device identifiers
- Browser and system information
- Access logs and usage activity
- Cookies and similar tracking technologies
How We Use Information
- Provide and operate the Platform, process bookings, manage approvals and travel policies.
- Billing: invoicing and processing payments.
- Communicate with Clients and Users about bookings, changes, notifications, and support.
- Improve and personalize Services, analytics, and reporting.
- Detect, prevent, and mitigate fraud and security incidents.
- Comply with legal obligations and respond to law enforcement requests.
- Legal Basis for Processing (where applicable, e.g., GDPR)
- Performance of a contract: Processing necessary to provide the Platform and perform booking services.
- Legitimate interests: Improving our Services, fraud prevention, and security (balanced against data subject rights).
- Consent: For certain communications and where required for processing special categories of data.
- Legal obligations: Compliance with legal and tax obligations.
Purposes of Processing
Personal data is processed for the following purposes:
- Company name
- Billing address
- Tax ID
- Point of contact
- Administrators
The Provider does not sell personal data to third parties.
Legal Basis for Processing
Depending on the jurisdiction, the Provider may process personal data on the basis of:
- Performance of a contract
- Legitimate business interests
- Compliance with legal obligations
- Consent, where required by applicable law
Data Sharing and Disclosure
Personal data may be shared with:
- Travel suppliers and service providers: Airlines, hotels, ground transfers and other travel service providers
- Payment processors and financial institutions
- IT service providers, including hosting and analytics partners
- Government or regulatory authorities when legally required
- Third-party integrations: Travel management partners, expense systems, HR systems, and other integrations authorised by the Client
- Service providers and contractors: hosting providers, analytics providers, customer support vendors
- Affiliates and successors: in connection with corporate restructuring or mergers
- Legal and regulatory: To comply with legal process, law enforcement, or to protect rights, safety, or property.
- Aggregated/Anonymised data: We may use anonymised data for analytics and product improvement.
- All third parties are subject to confidentiality and data protection obligations.
Data Retention
Personal data will be retained:
- For as long as the Client maintains an active account
- As necessary to fulfil legal, regulatory, or audit requirements
- In accordance with the Client's internal data retention policies, where applicable
Data may be anonymised for long-term statistical or analytical use. We retain personal data as needed to provide Services, fulfil contractual obligations, prevent fraud, and comply with legal obligations. Retention periods vary by data type; deleted data may remain in backups for a limited time.
Security Measures
The Provider implements appropriate technical and organisational measures to safeguard personal data, including:
- Encryption of data in transit and at rest
- Access controls and authentication mechanisms
- Continuous monitoring and security audits
- Secure data center infrastructure
While the Provider employs industry-standard protections, no system can guarantee absolute security.
Client Responsibilities
The Client is responsible for:
- Managing user access and permissions
- Ensuring the accuracy and lawfulness of personal data provided
- Complying with applicable data protection laws, including obligations as a data controller (e.g., GDPR)
International Data Transfers
Personal data may be transferred to jurisdictions outside the Client's country. The Provider ensures that such transfers are conducted in compliance with applicable laws, and subject to appropriate safeguards, including:
- Standard contractual clauses
- Adequacy decisions
- Secure transfer mechanisms
Data Subject Rights
Depending on applicable law, employees may have rights to:
- Access their personal data
- Request correction or deletion
- Restrict or object to processing
- Request data portability
Such requests must be submitted through the Client, who acts as the data controller.
Cookies and Tracking
We use cookies and similar technologies for functionality, analytics, security, and advertising (where applicable). Clients can configure cookie settings via their browser; some features may require cookies.
Data Controller and Processor Roles
Client acts as the data controller for employee/traveler personal data in many cases and is responsible for obtaining consents and providing privacy notices to employees as required; the typically acts as a data processor for Client data and will process such data per Client instructions and this Policy.
Third-Party Links and Integrated Services
The Platform may contain links or integrate with third-party services. We are not responsible for their privacy practices. Clients should review third- party policies.
Changes to This Policy
We may update this Policy. Material changes will be communicated via the Platform, email, or Client administrator notifications.
Amendments to This Policy
The Provider may update this Policy periodically. Material changes will be communicated to the Client. Continued use of the Platform constitutes acceptance of the updated Policy.