1. Who are we
The Travel Corporation NZ Limited is a company registered in 131 New North Road., Auckland, New Zealand under the registration number (09) 300 1560. Our registered address is 131 New North Road., Auckland, New Zealand. All references to Trafalgar, 'we', 'us', 'our' are references to Trafalgar, its group, subsidiaries and sister companies. If you have any questions or concerns about this privacy notice, or Trafalgar’s personal data policies or practices, please contact us either by e-mail to firstname.lastname@example.org or email@example.com, or by post to PO Box 68-640, Auckland, 1145.
We are the Data Controller for the purposes of the matters detailed in this Privacy Notice.
2. What Personal Data Do We Collect
Depending on the situation, we may collect the following information:
- Your name and contact details.
- Your COVID-19 vaccination status, including the date of administration of the last dose.
- Where you have accepted to take rapid SARS-CoV-2 medical testing, the date and time of the test. If it is negative, we will not record the result of the test, which will only be processed by a qualified health professional in accordance with local regulations. If the result is positive and results in us being unable to continue to provide you with our services, we will retain the information for as long as is necessary to demonstrate that our withdrawal of services was reasonable.
- Where authorised by local regulations or where you agree, we may collect your temperature before giving you access to our services/premises or to a public area. On such occasions we do not record this information, which is deleted immediately, unless the readings are not within acceptable levels in which case we may refuse access and we may retain the data in order to demonstrate that our refusal of access was reasonable.
- If you have agreed to the use of facial recognition, we may collect your biometric information to access certain areas. We will always offer an alternative, such as badges, to the use of facial recognition. Our facial recognition features are not implemented on our CCTV systems, and will always be offered as a separate system.
- When you have accepted or where required by local regulations, we may collect your name, contact details, date, time and location of your presence in the premises we manage for contact tracing purposes. If you notify us that you have been tested positive, we will not record this information, but only the date, time and location of the risk in order for us be able to notify the relevant customers that may have been exposed, unless otherwise required by law.
- Your information regarding pre-existing health conditions, when you choose to share this information with us. We will only record the existence of such pre-existing health condition, and no detail on your health condition itself. Any detailed information will be processed through a qualified health professional in accordance to local regulations.
- Your medical insurance information, as required by tourism and travel regulations.
3. Why Do We Collect Personal Data
Depending on the situation, we collect and process your personal data for the Following purposes:
- To offer to our customers, on a voluntary basis, rapid SARS-CoV-2 medical tests;
- To verify the vaccination status of our customers to
- protect the safety and well-being of passengers and employees,
- respect the local COVID-19 restrictions in locations where vaccination is a condition for entry
- To check body temperature prior to giving access to public areas and our premises, to protect the health and safety of our customers, staff, contractors and suppliers;
- To offer to our customers, on a voluntary basis, an alternative contact-less authentication method, such as facial recognition;
- To record attendance in certain premises we manage, in order to notify our customers if they have been exposed to a risk and to recommend to self-isolate;
- If you choose to share such information with us, to record if you have a particular risk to your health so we can take any additional measure appropriate to ensure your safety;
- To record your medical insurance information as required by health regulations.
4. What Are Our Legal Grounds to Collect and Process Your Personal Data
We rely on the following legal bases to collect and process your personal data:
- Your explicit consent.;
- To perform the contract you have with us;
- To comply with a legal obligation: when we are required to collect and process your information because we have a legal requirement to do so in some jurisdictions ;
- To comply with public health regulations;
- To protect your vital interest: when required by the circumstances, we may process your data to protect your vital interests or the vital interests of other individuals;
- Our legitimate interests: we may process your data because it is our legitimate interests to do so, or the legitimate interests of others.
5. Special Category Data
Depending on the circumstances, we rely on the following legal bases to collect and process your health and biometric data:
- Your explicit consent;
- To comply with a legal obligation: when we are required to collect and process your information because we have a legal requirement to do so in some jurisdictions, in particular to protect and safeguard public health;
- To comply with public health regulations;
- To protect your vital interests, when you are not legally or physically able to give consent.
6. Who Are We Sharing Your Personal Data With
We will not share data with third parties other than as documented in our regular privacy notice. However, in some circumstances, your data may be shared with:
- Public authorities, in particular health authorities, if we have a legal obligation to do so;
- Our providers, including qualified health professionals in line with local regulations, and our biometric solutions providers.
We will not share your data outside of the European Economic Area (EEA) except when:
- It is necessary to perform your contract with us (for instance, because you are travelling outside the EEA);
- We have the legal obligation to do so.
7. How Long Do We Keep Your Data For
We will endeavour to record your personal data, especially your health data, only for the time strictly necessary for the purposes set out in this privacy notice. This includes the following periods:
- For the time of your tour or travel;
- 15 days to one month after your visit to our premises, unless a longer period is required by law;
- For as long as necessary to comply with our legal obligations, contractual requirements or the establishment, exercise or defence of legal claims;
We will delete/destroy your personal data immediately after the relevant retention period above is reached.
8. How Do We Protect Your Data
We will always collect and process your data, in particular health and biometric information, with due care and we will keep this data separate from our other regular business processing activities.
The information you share with us under the scope of this Privacy Notice will be secured by additional technical and organisational measures and only staff required to see this information will be able to access it on a “need-to-know” basis.
Paper-based records will be kept securely in locked cabinets. Digital records will be kept in encrypted and separate databases or folders with strict access controls in place.
9. What Are My Rights and How Do I Exercise Them
You have the right to:
- be informed of any data processing;
- access to your personal data;
- rectify your personal data;
- erase your personal data, in some circumstances;
- restrict processing of your personal data, in some applicable circumstances;
- data portability, in applicable circumstances;
- object to the processing of your personal data, in some circumstances;
- to withdraw consent to the processing of your personal data, where applicable.