BANI. Travels & Tours
  • Flights
  • Hotels
  • Visa
  • About Us
  • Book Now

Privacy Policy

Comprehensive Data Governance & Information Security Standards

1. Scope & Systemic Overview

Bani Travels ("Data Controller", "Company", "We", "Us") operates in strict compliance with applicable statutory data protection frameworks, including the General Data Protection Regulation (GDPR) and regional data protection statutes. This Privacy Policy sets forth the terms governing the collection, processing, storage, transfer, and safeguarding of Personally Identifiable Information (PII) collected from customers, users, and site visitors ("Data Subjects").

2. Categories of Personally Identifiable Information (PII) Collected

In order to execute contractually binding travel reservations and fulfill regulatory requirements, the Company processes the following data categories:

  • Biographical & Identificatory Data: Full legal name, gender, date of birth, place of birth, citizenship status, passport serial numbers, visa grant details, and national identification credentials.
  • Contact & Communication Metadata: Residential address, electronic mail addresses, telecommunication numbers, and emergency contact protocols.
  • Financial & Payment Records: Credit/debit card numbers, cardholder verification data, bank routing numbers, and billing history processed through PCI-DSS compliant payment gateways.
  • Travel & Logistics Metadata: Passenger Name Records (PNR), Frequent Flyer numbers, dietary requirements, medical assistance requests, lodging preferences, and travel insurance coverage parameters.
  • Technical & Telemetric Data: Internet Protocol (IP) addresses, browser telemetry, device identifiers, session logs, and cookie tracking metrics collected during portal navigation.

3. Lawful Bases and Purposes of Processing

The processing of PII is executed under distinct lawful grounds as prescribed by applicable data privacy regulations:

  • Performance of Contract: Facilitating ticketing, hotel reservations, visa clearance processing, and ancillary travel arrangements with third-party vendors.
  • Legal & Regulatory Compliance: Fulfilling mandatory border control reporting, immigration filings, taxation records, and anti-money laundering (AML) regulatory audits.
  • Legitimate Business Interests: Executing fraud detection, risk mitigation, network security diagnostics, and business analytics.
  • Explicit Consent: Distributing direct marketing communications and processing special category data (e.g., medical mobility or dietary restrictions). Consent may be withdrawn by the Data Subject at any time without retroactive effect.

4. Third-Party Disclosures & Cross-Border Data Transfers

To perform contracted services, the Company may disclose relevant PII to third-party entities under strict confidentiality agreements:

  • Travel Service Providers: Commercial air carriers, hotel operators, global distribution systems (GDS), ground transport managers, and travel insurance underwriters.
  • Governmental & Consular Authorities: Diplomatic missions, border control agencies, immigration bureaus, and law enforcement authorities pursuant to statutory mandates.
  • Cross-Border Data Flows: PII may be transferred to and processed in jurisdictions outside the Data Subject's state of residence. Such transfers are executed utilizing legally recognized safeguards, such as Standard Contractual Clauses (SCCs) or adequacy decisions.

5. Data Retention Protocols

PII shall be retained only for as long as necessary to fulfill the operational purposes for which it was originally collected, or to comply with statutory legal, accounting, and tax retention periods (typically up to 7 years following contract execution). Upon expiration of applicable retention thresholds, PII shall be permanently anonymized or securely destroyed.

6. Data Subject Statutory Rights

Subject to statutory conditions, Data Subjects retain the following legally enforceable rights regarding their PII:

  • Right of Access & Rectification: The right to request copies of stored PII and request corrections to inaccurate or incomplete records.
  • Right to Erasure ("Right to be Forgotten"): The right to demand the deletion of PII where processing is no longer legally warranted.
  • Right to Restriction & Objection: The right to restrict or object to specific processing operations, including automated profiling and direct marketing.
  • Right to Data Portability: The right to receive PII in a structured, commonly used, machine-readable format for transfer to another controller.

7. Technical Data Protection & Security Controls

The Company employs multi-layered technical and organizational security measures, including Transport Layer Security (TLS) encryption, AES-256 at-rest encryption, restricted access controls, firewalls, and continuous security audits to protect PII against accidental loss, unauthorized access, alteration, or disclosure.

8. Privacy Officer Contact Details

To exercise statutory privacy rights or submit inquiries concerning data protection governance, Data Subjects may contact our Data Protection Officer at bookings@banitravels.com.

Bani Travels

Crafting sacred & global journeys since 2005.

Quick Links

  • About Us
  • Privacy Policy
  • Refund & Return Policy
  • Contact Us

Services

  • Flights
  • Hotels
  • Visa
  • Insurance

Contact

๐Ÿ“ž IN: +91 94655-77876

Office :- 148/7 Jaina Nagar Basti Sheikh Jalandhar 144002

โœ‰ bookings@banitravels.com

© 2026 Bani Travels. All rights reserved.

ATAS & IATA Accredited