This Policy details our commitment to protecting the privacy of individuals who visit our Marketing Website (“Website Visitors”), or who are registered to use the products and services which are sold as an Enterprise SaaS to organisations (the “Subscribers”), or who attend or register to attend sponsored events or other events at which Trobexis participates (“Attendees”). For the purposes of this Policy, the term, “Website”, shall refer to the marketing website www.gettrobexis.com and the term “Application” shall refer to the Enterprise SaaS solution available at www.trobexis.com/tonexxxxxx/ (xxxxxx being the unique url for each subscriber).
Controller of Personal Information
Any provider of services such as a Travel Agency, GDS providers, Airlines, hotel, or car rental companies will also separately be a “data controller”. You can access the privacy policies of those providers from them directly.
Scope of this Policy
In this Policy, personal information means information relating to an identified or identifiable natural person. An identifiable person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, an identification number, location data, and online identifier or to one or more factors specific to his/her physical, physiological, genetic, mental, economic, cultural, or social identity. The use of information collected through our Service shall be limited to the purpose of providing the Service for which the Subscribers has engaged.
Except for Account Information (as defined below) and other information we collect in connection with your registration or authentication into our Services (as defined below), this Policy does not apply to our security and privacy practices in connection with your access to and use of the Services. These security and privacy practices, including how we protect, collect, and use electronic data, text, messages, communications, or other materials submitted to and stored within the Services by You (“Service Data”), are detailed in and governed by the Trobexis Contractual Agreement signed between the Subscriber organisation and Trobexis Pty Ltd.
Subscribers to our Services are solely responsible for establishing policies for and ensuring compliance with all applicable laws and regulations, as well as any and all privacy policies, agreements or other obligations, relating to the collection of personal information in connection with the use of our Services by individuals (also referred to as “data subjects”) with whom our Subscribers interact. If you are an individual who interacts with a Subscriber using our Services, then you will be directed to contact our Subscriber for assistance with any requests or questions relating to your personal information.
We collect information under the direction of our Subscribers and have no direct relationship with individuals whose personal information we process in connection with our Subscriber’s use of our Services. If you are an individual (such as an employee, or contractor of one of our Subscribers) who interacts with a Subscriber using our Services would either like to amend your contact information or no longer wish to be contacted by one of our Subscribers that use our Services, please contact the Subscriber that you interact with directly.
We may transfer personal information to companies that help us provide our Services. Transfers to subsequent third parties for these purposes are governed by the Service Agreements with our Subscribers.
What types of personal information do we collect and retain?
We collect the following categories of personal information:
- Information you provide to your Subscriber to complete and manage a Subscriber user profile and travel arrangements within the Application.
- Information to be able to communicate with you from using the Contact Us form on the Website.
- Information about your travel arrangements.
- Information about the travel in the past.
- Information about your device and your location if you have been browsing on trobexis.com, for example your IP address or unique User ID. An IP address (i.e. Internet Protocol address) is a numeric code that can act as a unique identifier for your computer or other device.
- Attendee Information - We may ask for and may collect personal information such as your name, address, phone number and email address when you register for or attend a sponsored event or other events at which any member of Trobexis participates.
- Analytics - We collect analytics information when you use the Website to help us improve them. We may also share anonymous data about your actions on our Websites with third-party service providers of analytics services. We do not link the information we store within the analytics software to any personally identifiable information you submit within the mobile application.
When and why do we collect ‘sensitive personal data’?
Certain categories of personal information, such as that about ethnicity, Gender, are special categories of data requiring additional protection under European Union and UK data protection law and is referred to here as “sensitive personal data”. Generally, we try to limit the circumstances where we collect and process sensitive personal data. Examples of where we may collect and process ’sensitive personal data’ includes the following:
- Where a Subscriber has specific legislative or internal policies requiring compliance rules to differ based on personal information (like providing accommodation in same gender groupings).
- Where a Subscriber requires specific country of work entry requirements to be met before employment and travel can be executed, like Passport, and Visa documents, Medical Approvals, Blood test validities, Skill and position certifications, and Work Site Access Documents to be recorded.
- Where a third-party service requires information to fulfil their service to Trobexis or the Subscriber, like Airlines requiring D.O.B, Gender, Passport, Visa details.
- In addition, you may have requested services (such as a meal preference) which is not ’sensitive data’ but may imply or suggest your religion, health, or other information.
How Long do we keep your Personal Information?
We will keep your information for as long as we need it for the purpose it is being processed for. For example, where the subscriber needs to plan and book travel through the Application (managed on your behalf or by yourself) we will keep the information related to the bookings, so we can communicate with third parties to fulfil the specific travel arrangements you have made. After that we will keep the information for a period which enables us to handle any reporting, queries or concerns relating to the travel.
We can delete it securely, or anonymise it, when there is no longer a legal or Subscriber need for it to be retained.
How We Use Information That We Collect
The General Uses of the Data:
We may use the information we collect about you (including personal information, to the extent applicable) for a variety of purposes, including to:
- provide, operate, maintain, and improve the Application;
- enable you to access and use the Services;
- process and complete transactions, and send you related information, including travel itineraries and travel related information;
- send transactional messages, including responses to your comments, questions, and requests; provide customer service and support;
- investigate and prevent unauthorized access to the Services, and other illegal activities;
- for other purposes for which we obtain your consent.
Legal Basis for Processing (EEA only):
If you are an individual from the European Economic Area (EEA), our legal basis for collecting and using the personal information will depend on the personal information concerned and the specific context in which we collect it. However, we will normally collect personal information from you only where:
- we have your consent to do so,
- where we need the personal information to perform a contract with your Subscriber (e.g. to deliver the Trobexis Services they have contracted), or
- where the processing is in our or a third party’s legitimate interest. In some cases, we may also have a legal obligation to collect personal information from you or may otherwise need the personal information to protect our Subscribers, your vital interests or those of another person.
If we ask you to provide personal information to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your personal information is mandatory or not (as well as of the possible consequences if you do not provide your personal information).
Similarly, if we collect and use your personal information in reliance on our (or a third party’s) legitimate interests which are not already described in this Notice, we will make clear to you at the relevant time what those legitimate interests are.
Additional Rights for EEA and Certain Other Territories:
If you are from certain territories (such as the EEA), you may have the right to exercise additional rights available to you under applicable laws. If your information was provided through a Subscriber relationship with Trobexis, you may need to contact the Subscriber in the first instance.
- Right of erasure: In certain circumstances, you may have a broader right to erasure of personal information that we hold about you – for example, if it is no longer necessary in relation to the purposes for which it was originally collected. Please note, however, that we may need to retain certain information for record keeping purposes, to complete transactions or to comply with our legal obligations.
- Right to object to processing: You may have the right to request that Trobexis stop processing your personal information.
- Right to restrict processing: You may have the right to request that we restrict processing of your personal information in certain circumstances (for example, where you believe that the personal information we hold about you is inaccurate or unlawfully held).
- Right to data portability: In certain circumstances, you may have the right to be provided with your personal information in a structured, machine readable and commonly used format and to request that we transfer the personal information to another data controller without hindrance.
For the Website - If you would like to exercise such rights, please contact us at the contact details in Section 2. We will consider your request in accordance with applicable laws. To protect your privacy and security, we may take steps to verify your identity before complying with the request.
For the Application - If you would like to exercise such rights, please contact the Subscriber in the first instance. We will consider the request in accordance with applicable laws.
You also have the right to complain to a data protection authority about our collection and use of your personal information.
Sharing of Information Collected
Third-Party Service Providers:
We share information, including personal information, with our third-party service providers that we use to provide other services for us. These third-party service providers may have access to or process your personal information for providing these services for us.
Compliance with Laws and Law Enforcement Requests; Protection of Our Rights:
In certain situations, we may be required to disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. We may disclose personal information to respond to subpoenas, court orders, or legal process, or to establish or exercise our legal rights or defend against legal claims. We may also share such information if we believe it is necessary to investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, violations of our Service Agreement, or as otherwise required by law.
English Version Controls
Non-English translations of this Policy are provided for convenience only. In the event of any ambiguity or conflict between translations, the English version is authoritative and controls.
©2020 Trobexis Pty Ltd