|
Controller |
Merlin Travel Group Limited |
|
Company number |
SC634186 |
|
Registered / correspondence address |
Merlin House, Mossland Road, Glasgow G52 4XZ |
|
Privacy contact |
Data Protection Lead – gdpr@merlintravelgroup.co.uk |
This notice explains how Merlin Travel Group Limited (“MTG”, “we”, “us” or “our”) collects, uses, stores and shares personal information and the rights available to you.
|
Important This Privacy Notice is designed for MTG’s public website. It is separate from MTG’s internal Data Protection Policy, employee privacy information, Cookie Notice and contractual data-protection terms with members, suppliers and processors. |
This Privacy Notice applies to personal information we process about:
Employees and workers are covered by separate internal privacy information.
Merlin Travel Group Limited is a data controller where we decide why and how personal information is processed.
MTG operates a network of independently owned travel businesses. Members may also be data controllers in their own right where they use personal information for their own business purposes, including their own customer records, relationship management and marketing. If you book through an MTG member, you should also read that member’s privacy notice.
Where an authorised third-party travel agent sells an MTG Holidays product, that agent may also process personal information for its own purposes and provide relevant booking information to MTG.
The exact role of each organisation can depend on the booking and the processing activity. This notice explains MTG’s use of personal information.
Names, titles, postal addresses, email addresses, telephone numbers and other contact details.
Destinations, travel dates, itineraries, flights, accommodation, cruises, transfers, excursions, booking references, room or cabin requirements, travel preferences and details of other people travelling with you.
Dates of birth, nationality, passport details, passport expiry dates and copies of travel documents where they are needed for a booking or travel requirement.
Amounts paid, payment status, transaction references, refunds and limited payment information. Where card payments are made through a secure payment provider, card details are entered into the provider’s secure environment. MTG staff do not ordinarily see or retain full card numbers or card security codes.
Occasionally, bank account details may be collected where they are needed to make a refund. We delete them when the refund is complete and the details are no longer needed.
Information about disability, mobility, medical needs, dietary requirements, allergies or other special assistance where relevant to the travel arrangements.
Emails, letters, telephone notes, messages, complaints, requests and other correspondence about a booking, enquiry or business relationship.
IP addresses, browser and device information, login activity, system activity and security logs. We use this information for security, system administration, troubleshooting and service improvement, not for behavioural advertising or customer profiling.
Names, roles, work contact details, contractual information and correspondence relating to members, agents, suppliers and other business partners.
CVs, work history, qualifications, contact details and other information provided by job applicants.
We process information about children where they are included in family or group travel arrangements. This may include their name, date of birth, passport information, travel details and relevant accessibility or special-assistance requirements.
This information is normally provided by a parent, guardian, lead passenger or another adult authorised to make the booking rather than being collected directly from the child.
If you provide personal information about another traveller, you should ensure that you are authorised to provide it and, where appropriate, that the traveller is aware that their information will be used to arrange and administer the travel.
We may receive personal information:
We do not obtain customer personal information from data brokers or purchased consumer marketing lists.
The table below summarises our main processing activities and the lawful bases we normally rely on. The precise basis can depend on the circumstances.
|
Purpose |
Examples |
Typical lawful basis |
|
Enquiries and quotations |
Responding to enquiries, preparing quotes, reserving or checking travel arrangements before booking. |
Steps at your request before entering a contract; legitimate interests where appropriate. |
|
Making and administering bookings |
Confirming travel services, maintaining booking records, issuing confirmations, ATOL Certificates, vouchers and other documents. |
Contract; legal obligation where applicable. |
|
Payments and refunds |
Taking and reconciling payments, issuing receipts, processing refunds and managing payment queries. |
Contract; legal obligation; legitimate interests in financial administration and preventing misuse. |
|
Travel operations and customer support |
Schedule changes, disruption support, amendments, cancellations, complaints, assistance and emergency communications. |
Contract; legal obligation; legitimate interests in providing and protecting our services. |
|
Passenger information and regulatory requirements |
Providing information required for ticketing, API, manifests, security, immigration, ATOL or other travel and regulatory requirements. |
Contract; legal obligation. |
|
Health and special assistance |
Arranging mobility assistance, dietary requirements, medical or accessibility support. |
Contract or another Article 6 basis plus an Article 9 condition, usually explicit consent. In an emergency, another lawful condition may apply where permitted by law. |
|
Security and system operation |
Access control, audit logs, troubleshooting, system administration and service improvement. |
Legitimate interests in keeping systems secure and operating services effectively; legal obligation where applicable. |
|
Member, agent and supplier relationships |
Administering contracts, operational communications, supplier information and business support. |
Contract; legitimate interests in managing our business relationships. |
|
B2B marketing |
Relevant supplier, product or business communications to members, agents, suppliers and established business contacts. |
Legitimate interests or consent where required, subject to PECR and the recipient’s right to object. |
|
Recruitment |
Assessing applications, contacting candidates and maintaining recruitment records. |
Steps before entering an employment contract; legitimate interests; legal obligation where applicable. |
|
Legal, regulatory and claims matters |
Compliance, audits, regulatory enquiries, legal claims, professional advice and insurance matters. |
Legal obligation; legitimate interests in establishing, exercising or defending legal rights. |
Where we rely on legitimate interests, those interests may include operating and administering our travel business, protecting customers and systems, preventing misuse, maintaining accurate records, improving services, managing member and supplier relationships, resolving disputes and establishing, exercising or defending legal rights. We consider the necessity of the processing and balance these interests against the rights and interests of the people whose information we use.
Some information is required so that we can provide a quotation, enter into or perform a travel contract, make a supplier booking, take payment or comply with legal or regulatory requirements.
If you do not provide information that is necessary for those purposes, we may be unable to provide a quotation, make or administer the booking, arrange requested assistance or allow a particular travel service to be provided.
Information about health, disability and certain other matters is given additional protection under data-protection law. We only collect and use this information where it is relevant to the travel arrangements, assistance requested or another legitimate purpose permitted by law.
Where appropriate, we ask for explicit consent before using or sharing special category information with relevant travel suppliers. Explicit consent can be withdrawn, but withdrawal does not affect processing that was lawful before it was withdrawn and may mean that we can no longer arrange the requested assistance.
In an urgent medical or welfare situation, we may process or share relevant information where another legal condition applies, for example where this is necessary to protect someone’s vital interests and the person is unable to give consent.
We only share information where there is a legitimate need to do so and, where appropriate, only the information reasonably necessary for the purpose. Recipients may include:
Where another organisation acts as our processor, we require appropriate contractual data-protection obligations. Where another organisation is an independent controller, it is responsible for its own processing of the information it receives.
MTG members are independently owned businesses. A member normally has access within MTG systems only to its own customers and bookings. The same principle applies to member access within PTS.
Authorised MTG Head Office staff may have wider access where this is required for central functions such as administration, supplier payments, compliance, financial protection, disruption support, customer assistance and complaints.
Access is restricted according to role and legitimate business need.
Members may be able to download or export certain customer information and documents. Members are required under their arrangements with MTG to protect that information, use appropriate security measures and only disclose it where necessary for the booking, authorised by the customer or otherwise permitted or required by law.
Where MTG Connect is in use, it provides booking, documentation, payment and customer-account functionality. The system is provided and operated for MTG by Go Appily.
Customers may be given access to a secure client portal where they can view relevant booking information, documents, payments and personal information.
Customers choose their own account credentials. MTG staff do not have access to customers’ passwords. Secure reset procedures are used where account recovery is required.
Customers may request deletion of an online account. This does not necessarily mean that all underlying booking or transaction information can be deleted if we must retain it for contractual, regulatory, accounting, complaint-handling or legal reasons.
Where enabled within MTG Connect or another approved MTG system, automated or AI-assisted features may help prepare, classify or process travel documents such as quotations, booking confirmations, ATOL Certificates, payment receipts and travel vouchers.
MTG does not currently use AI or automated processing to make decisions about customers that are based solely on automated processing and have legal or similarly significant effects.
Technology providers processing personal information on MTG’s behalf are subject to appropriate contractual and data-protection requirements.
Travel is international by nature. To provide travel services, we may need to send or make personal information available to organisations outside the UK, for example an overseas airline, hotel, cruise company, transfer provider or destination management company.
Countries outside the UK may have different data-protection laws. Where a transfer is a restricted transfer under UK data-protection law, we use an appropriate transfer mechanism where required. This may include:
The mechanism used depends on the destination, recipient and nature of the transfer. You may contact gdpr@merlintravelgroup.co.uk for more information about the safeguards relevant to a particular transfer.
MTG may communicate directly with customers where necessary to administer travel arrangements. These communications may include booking confirmations, payment receipts, balance reminders, travel documents, requests for information, supplier or schedule changes, disruption information, emergency communications, refund information and complaint correspondence.
Depending on the circumstances and the contact details or preferences available to us, communications may be made by email, telephone, SMS, WhatsApp or another appropriate messaging service.
These communications are operational or service communications and are not general direct marketing.
MTG does not use members’ end-customer databases to send those customers general MTG marketing, newsletters or promotional offers.
Individual MTG members are responsible for their own marketing activities and must comply with applicable data-protection and electronic-marketing law.
MTG may send relevant B2B communications to existing members, agents, suppliers and established business contacts. The rules can differ depending on the type of business recipient and the communication method. We apply UK GDPR and PECR requirements where they apply.
You can object to direct marketing at any time and we will stop using your personal information for that purpose.
Our website may use cookies and similar technologies, including Google Analytics.
Where consent is legally required for a cookie or similar technology, we use a consent mechanism so that the relevant technology is not set until the required choice has been made.
Further information about the cookies we use, their purposes and how to change preferences should be provided in our separate Cookie Notice.
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected and to meet applicable contractual, legal, regulatory, accounting, complaint-handling and claims requirements.
|
Record type |
Normal retention approach |
|
Booking records, confirmations, payment records and related customer communications |
Normally 6 years after completion of the booking or travel. |
|
Passport copies and similar travel documents |
Deleted when no longer required for the booking, legal or compliance purpose. |
|
Bank details collected specifically to make a refund |
Deleted when the refund is complete and the information is no longer needed. |
|
Enquiries and quotations that do not become bookings |
Normally up to 6 years where needed for business records, complaint handling or legal claims, and shorter where there is no continuing need. |
|
Member, supplier and B2B agent contracts, business contacts and related correspondence |
For the relationship and normally 6 years afterwards. |
|
Unsuccessful job applications and CVs |
Normally up to 2 years. |
|
Technical and security logs |
For a period appropriate to the security, troubleshooting and system-administration purpose, then deleted or anonymised. |
We may retain information for longer where this is reasonably necessary because of an ongoing complaint, legal claim, regulatory matter, fraud concern or other legal requirement.
We may retain aggregated or genuinely anonymised information for reporting and analysis where it no longer identifies an individual.
We use appropriate technical and organisational measures designed to protect personal information against accidental or unlawful loss, misuse, alteration, disclosure or access.
Members are also expected to take appropriate steps to protect customer information they hold or obtain through MTG systems.
No electronic system can be guaranteed to be completely secure, but we take reasonable and proportionate measures to protect the information entrusted to us.
MTG maintains procedures for identifying, assessing, recording and responding to personal-data breaches.
Where required by law, we will notify the Information Commissioner’s Office and affected individuals within the applicable legal timescales.
MTG members are required to notify MTG promptly of actual or suspected personal-data breaches involving MTG customer information or personal information obtained through MTG systems.
Depending on the circumstances and the lawful basis for the processing, you may have the right to:
These rights are not absolute and exemptions may apply. We may need to verify your identity before acting on a request.
To exercise a right, contact gdpr@merlintravelgroup.co.uk.
|
Your right to object You have the right to object to our use of your personal information where we rely on legitimate interests. You have an absolute right to object to the use of your personal information for direct marketing. If you object to direct marketing, we will stop using your information for that purpose. |
If you are concerned about how MTG has collected, used, stored or shared your personal information, you can make a data-protection complaint to us.
Please contact:
Data Protection Lead
Merlin Travel Group Limited
Merlin House
Mossland Road
Glasgow G52 4XZ
gdpr@merlintravelgroup.co.uk
We will provide a clear route for complaints, acknowledge a data-protection complaint within 30 days, investigate it appropriately without undue delay, keep the complainant appropriately informed, and communicate the outcome without undue delay.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data-protection regulator. We would welcome the opportunity to address your concern first, but contacting us does not affect your right to complain to the ICO.
ICO website: ico.org.uk
MTG does not currently make decisions about customers based solely on automated processing that have legal or similarly significant effects. If this changes, we will update this notice and provide the information and safeguards required by law.
We may update this Privacy Notice from time to time to reflect changes to our services, systems, suppliers, business arrangements or applicable law.
The latest version will be published on our website and will show the date from which it applies.
Published 01 September 2026