KITE AND COMPASS TRAVEL LTD
Privacy Policy
Last updated: 11 August 2026 Version: 1.0
1. In short
We are a UK travel agency. To plan and book your trip we need to know things about you — who you are, where you want to go, who is travelling with you, and eventually your passport details.
This policy explains, in plain terms:
-
what we collect
-
why we collect it
-
who else sees it
-
how long we keep it
-
what you can tell us to do about it
If you only read one section, read section 12 — Your rights.
2. Who we are
Kite and Compass Travel Ltd is the data controller for the personal data described in this policy. That means we decide what is collected and why, and we are legally accountable for it.
Item
Detail
Company name
Kite and Compass Travel Ltd
Registered in
England and Wales
Company number
17327689
Registered office
Collingwood Buildings, 38 Collingwood Street, Newcastle upon Tyne, NE1 1JF
Email for privacy questions
ICO registration reference
ZC219705
Kite and Compass Travel Ltd is an independent travel advisor under InteleTravel UK, ABTA membership P7384. InteleTravel UK are appointed agents of our ATOL-protected suppliers.
InteleTravel UK Limited is registered in England and Wales, company number 10983417, registered office 2nd Floor Nucleus House, 2 Lower Mortlake Road, Richmond, TW9 2JA.
We do not have a Data Protection Officer. UK GDPR does not require us to appoint one at our size and type of processing. Privacy questions come to Warren at the address above.
3. What we collect
3.1 What you tell us on the enquiry form
Our enquiry form is at forms.kiteandcompasstravel.co.uk. Depending on the type of trip you select, it asks for:
Category
Specific information
Identity and contact
Your name, email address, telephone number, postal address
Your party
Number of adults, number of children, ages of children
The trip
Budget, departure and return dates, whether dates are flexible, regions of interest, specific destinations, departure city, type(s) of holiday wanted, whether you want travel insurance
Air travel
Frequent flyer programmes, cabin class preference, seat row and location preference
Cruise
Loyalty programmes, itinerary, cruise length, pre/post-cruise nights, cabin class, beverage plan
Hotel and resort
Loyalty programmes, number of nights, number and arrangement of rooms, room type, resort features wanted
Car rental
Loyalty programmes, car category, add-ons
Package tours
Escorted or independent, activity level
Your tastes
Hotels you have enjoyed, cruise lines and resorts you have enjoyed, activities you enjoy when travelling, anything else you choose to tell us
The last row matters. It is free text. Whatever you type there, we receive. Please only tell us what you want us to know.
3.2 What we need later, if you book
Once you decide to book, we collect what the airline, cruise line, hotel or tour operator requires:
-
Full name exactly as it appears on your passport
-
Date of birth
-
Passport number, issuing country and expiry date
-
Nationality
-
Emergency contact details
-
Any special requirements you tell us about (see 3.4)
-
Booking references, payment status and dates
We collect this only when it is needed for a live booking, not at enquiry stage.
3.3 Information about other travellers
Source
What we may receive
InteleTravel UK Limited
Booking confirmations, commission records, supplier correspondence relating to your trip
Travel suppliers
Number of adults, number of children, ages of children
Publicly available sources
Occasionally, business contact details for corporate enquiries
Referrals
If an existing client refers you, we receive your name and contact details from them. We will tell you who referred you the first time we contact you.
If you enquire or book on behalf of other people — family, friends, a group — you are giving us their personal data too.
You must have their permission to do that, and you must show them this policy. We rely on you having done so. If someone in your party would rather deal with us directly, they can email us and we will.
3.4 Health, accessibility and dietary information
We do not ask for this. But if you tell us — a mobility need, an allergy, a dietary requirement, a medical condition that affects travel — we will use it to make your trip work, and we will pass it to the relevant supplier.
Under UK GDPR this is special category data and gets extra protection. Our lawful basis for using it is your explicit consent, given at the moment you tell us. You can withdraw that consent at any time, though we may then be unable to arrange the assistance you need.
We do not share it with anyone beyond the supplier who needs it to deliver the service.
3.5 What happens if you do not give us the information
​You are never obliged to give us anything. But some of it we cannot work without.
Information
Do you have to give it?
What happens if you don't
Enquiry form details
No — it is voluntary
We cannot plan a trip for you, because we would not know what you want or how to reach you
Passport details, full name, date of birth
Yes, once you are booking — this is a contractual and in some cases legal requirement
The booking cannot be made. Airlines and cruise lines will not issue tickets without it, and border authorities require it.
Special requirements
No
We will arrange the trip, but we cannot arrange assistance we do not know you need
Marketing consent
No
Nothing. You still get the same service.
3.6 Information collected automatically on our website
When you visit our website we collect technical information through cookies and similar technology — see section 13.
3.7 Information from other sources
4. Why we use your data, and our lawful basis
UK GDPR requires us to have a lawful basis for every use of your data. Here is ours, use by use.
What we do
Why
Lawful basis
Respond to your enquiry and prepare quotes and proposals
You asked us to plan a trip
Legitimate interests — responding to an enquiry you initiated. Before a contract exists, this is our basis; it becomes contractual once you engage us.
Match your enquiry to suitable suppliers
To recommend options that fit your trip and budget
Legitimate interests — providing a useful service you asked for
Make and manage your booking
To deliver what you have paid for
Performance of a contract​
Pass your details to airlines, hotels, cruise lines and tour operators
They cannot issue tickets or reservations without them
Performance of a contract​
Take and process payments, and manage refunds
To complete your booking
Performance of a contract​
Pass your details to InteleTravel UK Limited
Bookings are administered and commission is paid through our host agency
Performance of a contract and legitimate interests — operating our business
Handle special requirements you disclose
To make your trip work for you
Explicit consent (special category data)
Keep accounting and tax records
We are legally required to
Legal obligation — Companies Act 2006, HMRC requirements
Meet border, security and immigration requirements (e.g. Advance Passenger Information)
Airlines and governments require it
Legal obligation​
Handle complaints, disputes and insurance claims
To resolve problems and defend claims
Legitimate interests — establishing, exercising or defending legal claims
Keep our systems secure and prevent fraud
To protect you and us
Legitimate interests — security
Send you marketing about trips and offers
To tell you about things you may want
Consent (if you are an enquirer) or legitimate interests / soft opt-in (if you have booked with us before).
See section 14.
Analyse website traffic and run advertising
To understand what works and reach the right people
Consent, given through our cookie banner
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights and concluded it is not. You can ask us for that assessment, and you can object — see section 12.
5. Children's data
Our enquiry form asks for the number of children in your party and their ages. If you book, we will also need each child's full name, date of birth and passport details. We collect this because airlines, hotels and tour operators price and configure travel by age, and because passport and border requirements apply to children as they do to adults. We collect nothing beyond what the booking requires.
Our services are not directed at children. We do not knowingly accept enquiries from anyone under 18. Children's data reaches us only through a parent or guardian making a booking, and we handle it on the same footing as everyone else's — with the same rights, exercisable by the parent or guardian.
If you believe we hold a child's data we should not have, email us and we will delete it.
6. Automated processing
We use an automated system that reads your enquiry — destination regions, budget, party size, trip length and holiday type — and scores our supplier list to suggest which suppliers might suit you.
Two things to be clear about:
-
It produces a suggestion, not a decision. A human consultant reads it, and decides what to actually recommend to you.
-
It has no legal or similarly significant effect on you. It does not decide whether we work with you, what you pay, or whether you can book.
You are therefore not subject to automated decision-making within the meaning of Article 22 of the UK GDPR. We describe this anyway, because you should know how your enquiry is handled.
We do not profile you for advertising purposes beyond the website tracking described in section 13.
7. Who we share your data with
7.1 Our host agency
InteleTravel UK Limited receives your booking data. Bookings are placed and commission is administered through them. They handle your data under their own privacy policy and their own ABTA obligations.
7.2 Travel suppliers
To make your booking work, we pass your details to the businesses actually providing your trip:
-
Airlines
-
Hotels, resorts and accommodation providers
-
Cruise lines
-
Tour operators and destination management companies
-
Car hire companies
-
Transfer and excursion providers
-
Travel insurance providers, if you buy through us
Each of these is a separate data controller. Once your data reaches them, their own privacy policy governs what they do with it. We pass on what the booking requires and no more.
7.3 Technology providers who process data on our behalf
These companies hold or handle your data under contract, on our instructions only. They cannot use it for their own purposes.
Provider
What they do
Where data is held
Tally BV
Hosts our enquiry form
Belgium (EU)
Pipedrive OÜ
Our CRM — holds enquiry and booking records​
Estonia (EU) / EU data centres
Pipedream Inc.
Moves data automatically from the form into the CRM
United States
Qwilr Pty Ltd
Builds and hosts the proposals we send you
Australia
Wix.com Ltd
Hosts our website
Israel / EU and US data centres
Google LLC / Google Ireland Ltd
Business email, document storage, website analytics
EU and United States
Meta Platforms Ireland Ltd
Advertising measurement on our website
EU and United States
Notion Labs Inc.
Internal documentation and our supplier directory
United States
Notion holds our supplier records and internal documentation. It is not where client records live — those are in Pipedrive.
7.4 Others
Who
When
Our accountant and professional advisers
Accounts, tax, legal advice
HMRC, Companies House
Where legally required
Border and immigration authorities
Advance Passenger Information and similar legal requirements
Insurers and legal representatives
If there is a claim or dispute
A purchaser
If the business is ever sold or merged, subject to the same protections
We do not sell your personal data. We never have and we will not.
8. Sending data outside the UK
Some of the providers above are outside the UK. UK GDPR allows this only with proper safeguards. Here is what protects each transfer.
Destination
Safeguard
EEA (Belgium, Estonia, Ireland)
UK adequacy regulations — the UK recognises the EEA as providing equivalent protection
Israel (Wix)
UK adequacy regulations
United States (Pipedream, Google, Meta, Notion)
UK Extension to the EU–US Data Privacy Framework, where the provider is certified; otherwise the UK International Data Transfer Addendum to the EU Standard Contractual Clauses
Australia (Qwilr)
UK International Data Transfer Agreement, plus a transfer risk assessment. Australia does not benefit from a UK adequacy decision.
Travel suppliers worldwide
Where a supplier is outside the UK and no adequacy decision applies, the transfer is necessary for the performance of your contract with them, or to conclude it — Article 49(1)(b) and (c) UK GDPR. This is unavoidable: we cannot book you a hotel in Thailand without sending your name to Thailand.
You can ask us for a copy of the safeguards applying to any specific transfer.
9. How long we keep your data
Record
Kept for
Why
Enquiries that never became a booking
24 months from your last contact with us
Travel planning cycles are long; people come back. After that there is no reason to hold it.
Client and booking records
6 years after your last booking
6 years after your last booking
Passport details
Deleted once travel is complete and no claim is outstanding
We have no reason to keep them after that
Special requirements / health information
Deleted once travel is complete
Same
Accounting and tax records
6 years from the end of the accounting period
Legal obligation
Marketing consent records
Until you unsubscribe, plus 2 years
To prove we had your consent
Website analytics
As set by each cookie — see section 13
-
At the end of these periods we delete your data or anonymise it so it can no longer identify you.
10. How we keep your data safe
Measure
What it means
Access control
Only the people who need your data can reach it
Encryption in transit
All connections between our systems use TLS
Encryption at rest
Our CRM and storage providers encrypt stored data
Credential management
System credentials are held in secure environment variables, never written into code, and rotated
Two-factor authentication
On every business system that supports it
Vendor selection
We use established providers with published security and GDPR commitments
Data minimisation
We collect what the booking needs, and nothing extra
No system is perfectly secure, and we will not pretend otherwise. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours, and if the risk to you is high, we will tell you directly and without undue delay.
11. Payments
We do not hold your card details. Payments are taken by the supplier, by InteleTravel UK Limited, or through a regulated payment provider. Card numbers do not enter our CRM. If anyone claiming to be from Kite and Compass asks you to email or text card details, it is not us. Please tell us immediately.
12. Your rights
You have the following rights over your personal data. They are free to exercise, and we will respond within one calendar month.
Right
What it means in practice
Be informed
To know what we do with your data — this policy
Access
To get a copy of everything we hold about you
Rectification
To have anything wrong corrected
Erasure
To have your data deleted — sometimes called "the right to be forgotten"
Restriction
To have us pause using your data while a dispute is sorted out
Portability
To receive the data you gave us in a machine-readable format, or have us send it to another provider
Object
To tell us to stop processing based on legitimate interests. For direct marketing this is absolute — we must stop, no argument.
Withdraw consent
Where we rely on consent, to take it back at any time. This does not affect anything done before you withdrew it.
Not be subject to automated decisions
See section 6 — this does not currently arise
How to exercise them
Email warren@kiteandcompasstravel.co.uk. Tell us which right you are using and what you want. We may ask you to confirm your identity — we are not going to hand your data to someone pretending to be you.
Limits, stated honestly
Erasure is not absolute. If you have booked with us, we must keep certain records for accounting and legal reasons for 6 years. We will delete everything we are not legally required to keep, and tell you exactly what remains and why.
Access requests during a live booking may exclude information whose disclosure would breach a supplier's confidentiality.
If you are not happy with how we handle it
Please tell us first — we would rather fix it. But you have the right to go straight to the regulator:
​
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
www.ico.org.uk
13. Cookies and website tracking
Cookies are small files a website puts on your device. Some are necessary; most are not.
Type
What it does
Do we need your consent?
Strictly necessary
Makes the site work — page loading, security, remembering your cookie choices. Set by Wix.
No — the law exempts these
Analytics
Wix Analytics and Google Analytics 4. Tells us which pages people read, how they arrived, and where they leave.
Yes
Advertising
Meta Pixel. Measures whether our advertising works and allows us to show ads to people who have visited the site.
Yes
Nothing beyond strictly necessary cookies loads until you agree. Our cookie banner lets you accept all, reject all, or choose. You can change your mind at any time through the cookie settings link in the site footer.
You can also block or delete cookies in your browser settings. Blocking strictly necessary cookies will break parts of the site.
Our site does not respond to "Do Not Track" browser signals, because there is no agreed standard for what a website should do with one.
Note: Google Analytics and Meta Pixel are being implemented in August 2026. Until they are live, only Wix's strictly necessary cookies and built-in analytics operate.
14. Marketing
We are not currently sending marketing emails. When we start, here is how it will work.
If you have enquired but not booked: we will only email you marketing if you have opted in. We will ask clearly and separately, and we will not pre-tick the box.
If you have booked with us: we may send you information about similar travel services under the "soft opt-in" rule in the Privacy and Electronic Communications Regulations. You will be given the chance to opt out when we collect your details, and in every message after that.
Every marketing email will have a working one-click unsubscribe link. Using it stops marketing immediately and permanently.
Unsubscribing from marketing does not stop service emails about a trip you have booked — confirmations, changes, reminders. Those are part of delivering your booking, and you cannot opt out of them while a booking is live.
​
We do not share your details with other companies for their marketing. Ever.
15. Links to other websites
Our website and our proposals link to airlines, hotels, cruise lines and other travel businesses. Once you click through, you are on their site under their privacy policy, not ours. We are not responsible for how they handle your data. It is worth reading their policy before you hand anything over.
16. Changes to this policy
We will update this policy when our practices change — for example when we launch new services or add a new technology provider.
The version number and date at the top always tell you which version you are reading. If we make a change that significantly affects how we use your data, we will contact clients directly rather than relying on you to notice.
Change history
Version
Date
Change
1.0
11 August 2026
First published
17. Contact us
Channel
Detail
Post
Kite and Compass Travel Ltd, Collingwood Buildings, 38 Collingwood Street, Newcastle upon Tyne, NE1 1JF
We aim to answer privacy questions within five working days, and formal rights requests within one calendar month.
Kite and Compass Travel Ltd is registered in England and Wales, company number 17327689.
Kite and Compass Travel Ltd is an independent travel advisor under InteleTravel UK, ABTA membership P7384. InteleTravel UK are appointed agents of our ATOL-protected suppliers.