traveldestination.info

    Personal Data Protection Policy

    Last Updated: January 15, 2025

    Introduction - Our Commitment to Data Protection

    traveldestination.info ("we," "our," or "us") is committed to protecting and respecting your privacy. This Personal Data Protection Policy explains how we collect, use, disclose, and safeguard your personal data in compliance with the Singapore Personal Data Protection Act 2012 (PDPA), the General Data Protection Regulation (GDPR), and other applicable privacy laws and regulations.

    We operate a lead generation business model focused on the travel and tourism industry. We organize promotional campaigns, lucky draws, and contests to engage users and generate qualified leads for our business partners in the travel sector. Your participation in our campaigns means you consent to the collection and use of your personal data as described in this policy.

    Important: By submitting your personal information through our platform, you acknowledge that you have read, understood, and agree to this Personal Data Protection Policy.

    What Personal Data We Collect

    How We Collect Your Data

    Direct Collection

    • β€’ Registration forms and contest entries
    • β€’ Email subscriptions and newsletters
    • β€’ Contact forms and inquiries
    • β€’ Survey responses and feedback

    Automatic Collection

    • β€’ Cookies and tracking pixels
    • β€’ Analytics tools (Google Analytics, etc.)
    • β€’ Server logs and session data
    • β€’ Device and browser information

    Third-Party Sources

    • β€’ Social media platforms (with consent)
    • β€’ Partner websites and affiliates
    • β€’ Public databases and directories
    • β€’ Data enrichment services

    Communication Channels

    • β€’ Email correspondence
    • β€’ Phone conversations (with consent)
    • β€’ Chat and messaging services
    • β€’ Customer support interactions
    Purpose of Data Collection

    We collect your personal data for specific, legitimate purposes in accordance with PDPA requirements:

    1

    Lucky Draws and Contests

    To enter you into promotional campaigns, verify eligibility, and distribute prizes to winners.

    2

    Lead Generation

    To generate qualified leads for our business partners.

    3

    Marketing Communications

    To send promotional offers, travel deals, newsletters, and personalized recommendations (with your consent).

    4

    Service Improvement

    To analyze user behavior, improve our platform, and enhance user experience.

    How We Use Your Data

    Your personal data is used for the following operational purposes:

    Processing Leads

    Qualify, segment, and route leads to appropriate partners based on your preferences and profile.

    Partner Sharing

    Share your information with verified travel agencies, tour operators, and hospitality partners (with consent).

    Campaign Management

    Administer contests, verify entries, select winners, and fulfill prize deliveries.

    Communications

    Send transactional emails, promotional offers, newsletters, and important notifications.

    Analytics & Research

    Analyze trends, measure campaign effectiveness, and conduct market research.

    Compliance & Legal

    Comply with legal obligations, enforce terms, prevent fraud, and protect our rights.

    Lead Generation Transparency: We monetize our platform by connecting interested travelers with qualified service providers. When you submit your information, you may receive communications from our partners who offer travel-related products and services.

    Data Sharing & Disclosure

    Important Disclosure: As a lead generation platform, we share your personal data with third-party business partners and lead buyers. This is a core part of our business model.

    We may share your data with:

    Data Protection Standards: All third parties we work with are required to maintain appropriate technical and organizational measures to protect your personal data.

    Your Rights Under PDPA/GDPR

    Under the Singapore PDPA and GDPR (if applicable), you have the following rights regarding your personal data:

    πŸ” Right to Access

    Request a copy of all personal data we hold about you, including how it's being used and who it's shared with.

    ✏️ Right to Correction

    Request correction of any inaccurate, incomplete, or outdated personal data we hold about you.

    πŸ—‘οΈ Right to Erasure (Right to be Forgotten)

    Request deletion of your personal data, subject to legal retention requirements and legitimate business needs.

    🚫 Right to Withdraw Consent

    Withdraw your consent for marketing communications and data sharing at any time, without affecting prior processing.

    πŸ“¦ Right to Data Portability

    Receive your personal data in a structured, commonly used, machine-readable format for transfer to another service.

    ⏸️ Right to Restrict Processing

    Request limitation on how we process your data in certain circumstances, such as during disputes about accuracy.

    βš–οΈ Right to Object

    Object to processing based on legitimate interests, direct marketing, or profiling.

    How to Exercise Your Rights

    To exercise any of these rights, please contact our Data Protection Officer at pdpa@traveldestination.info. We will respond to your request within 30 days as required by law.

    Data Security Measures

    We implement comprehensive technical, administrative, and physical security measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction:

    Technical Safeguards

    • βœ“256-bit SSL/TLS encryption for data transmission
    • βœ“Encrypted databases and secure cloud storage
    • βœ“Multi-factor authentication for system access
    • βœ“Firewalls and intrusion detection systems
    • βœ“Regular security patches and updates

    Administrative Controls

    • βœ“Role-based access control (RBAC)
    • βœ“Regular employee training on data protection
    • βœ“Confidentiality agreements with staff and partners
    • βœ“Data minimization and need-to-know principles
    • βœ“Incident response and breach notification procedures

    Physical Security

    • βœ“Secure data centers with 24/7 monitoring
    • βœ“Access control to physical facilities
    • βœ“Redundant power and network infrastructure
    • βœ“Disaster recovery and backup systems

    Monitoring & Compliance

    • βœ“Regular security audits and penetration testing
    • βœ“Vulnerability assessments and risk management
    • βœ“Compliance with ISO 27001 standards
    • βœ“Automated threat detection and response

    Important: While we implement robust security measures, no system is 100% secure. We cannot guarantee absolute security but continuously work to enhance our protection mechanisms.

    Data Retention Period

    We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected and to comply with legal obligations:

    Active Campaigns

    Data is retained for the duration of active lucky draws, contests, or promotional campaigns you're entered in, plus 90 days for winner verification and prize fulfillment.

    Marketing Communications

    If you've consented to marketing communications, we retain your data until you withdraw consent or for a maximum of 2 years of inactivity, whichever comes first.

    Lead Generation

    Leads shared with partners are retained for up to 12 months to allow partners to follow up and for quality assurance purposes.

    Legal & Compliance Records

    Certain data may be retained longer to comply with legal, tax, accounting, or regulatory requirements (typically 7 years in Singapore).

    Deleted Accounts

    Upon account deletion or data erasure request, we delete or anonymize your data within 30 days, except where retention is legally required.

    Note: After the retention period, personal data is securely deleted, anonymized, or aggregated for statistical purposes only, where individual identification is no longer possible.

    Contact Our Data Protection Officer

    For any questions, concerns, or requests regarding your personal data, data protection, or this policy, please don't hesitate to contact our dedicated Data Protection Officer:

    traveldestination.info - Data Protection Officer

    Company:traveldestination.info
    Response:Within 30 days (as required by PDPA)

    πŸ“‹ What to Include in Your Request

    • β€’ Your full name and email address
    • β€’ Nature of your request (access, correction, deletion, etc.)
    • β€’ Any relevant details or references
    • β€’ Proof of identity (if required for security)

    ⏱️ Response Timeline

    • β€’ Acknowledgment: Within 3 business days
    • β€’ Simple requests: 5-10 business days
    • β€’ Complex requests: Up to 30 days (PDPA requirement)
    • β€’ Extensions will be communicated if needed

    βœ“ We're Here to Help: Your privacy matters to us. Our DPO team is committed to resolving your concerns promptly and professionally. All inquiries are treated with confidentiality and respect.

    Policy Updates

    We may update this Personal Data Protection Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. The "Last Updated" date at the top of this page indicates when the most recent changes were made. We encourage you to review this policy periodically.

    For material changes, we will notify you via email or prominent notice on our website at least 30 days before the changes take effect.

    Governing Law & Jurisdiction

    This policy is governed by and construed in accordance with the laws of Singapore. Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the Singapore courts.

    For users in the European Union, this policy also complies with GDPR requirements, and you retain all rights granted under GDPR.

    Last Updated: January 15, 2025

    Version 2.0 - Effective Date: January 15, 2025