PRIVACY RIGHTS / DATA SUBJECT ACCESS REQUESTS (DSAR)

Effective Date: 24 August 2026
Last Updated: 24 August 2026

Company: BETZONE s.r.o.
Platform: Travellin
Jurisdiction of establishment: Czech Republic
General enquiries: info@travellin.info
Booking enquiries: bookings@travellin.info
Privacy enquiries: privacy@travellin.info
Telephone: +420 732 844 855


1. Purpose of This Page

Travellin respects the privacy and data-protection rights of individuals whose personal data it processes.

This page explains how an individual may exercise applicable rights concerning personal data processed by BETZONE s.r.o., the operator of the Travellin platform.

It provides particular information concerning Data Subject Access Requests (“DSARs”), together with information concerning other rights available under applicable data-protection legislation.

For individuals whose personal data are subject to the EU General Data Protection Regulation (Regulation (EU) 2016/679 — “GDPR”), these rights arise principally under Articles 12 to 22 GDPR.

For individuals whose personal data are subject to UK data-protection law, corresponding rights arise principally under the UK GDPR and the Data Protection Act 2018.

For individuals protected by Swiss data-protection law, applicable rights arise principally under the Federal Act on Data Protection (“FADP”) and its implementing legislation.

Additional rights may apply under mandatory local legislation depending upon the individual’s jurisdiction and the circumstances of the processing.


2. Who Is Responsible for Your Personal Data?

The relevant data controller is generally:

BETZONE s.r.o.
Platform: Travellin
Jurisdiction of establishment: Czech Republic

Privacy enquiries should be directed to:

Email: privacy@travellin.info
Telephone: +420 732 844 855

Where another entity acts as the controller for a particular processing activity, this will be identified in the applicable privacy information where required.

Where a third-party travel supplier independently determines the purposes and means of processing customer information, that supplier may be a separate controller.

Accordingly, a request concerning a supplier’s independent processing may need to be addressed to that supplier.

Travellin will provide reasonable assistance in identifying the appropriate organisation where this is necessary and legally appropriate.


3. What Is a DSAR?

A Data Subject Access Request (“DSAR”) is a request by an individual for access to personal data concerning that individual and, where applicable, the additional information required by data-protection law.

Under Article 15 GDPR, an individual generally has the right to obtain confirmation as to whether personal data concerning them are being processed and, where that is the case, access to the personal data together with prescribed information concerning the processing.

A DSAR is commonly used to understand:

  • whether an organisation holds personal data about the requester;
  • what personal data are held;
  • why the data are processed;
  • the categories of personal data involved;
  • who receives or may receive the data;
  • how long the data are retained;
  • whether data are transferred internationally;
  • the source of personal data not obtained directly from the individual; and
  • whether automated decision-making or profiling is involved, where applicable.

The right of access is an important transparency right, but it is subject to statutory limitations and exemptions.


4. What Personal Data May Be Covered?

Depending upon the individual’s relationship with Travellin, personal data may include information such as:

  • name;
  • contact details;
  • account information;
  • booking information;
  • passenger or guest information;
  • correspondence;
  • transaction information;
  • payment-related information;
  • customer-support records;
  • technical identifiers;
  • device information;
  • IP-related information where applicable;
  • preferences;
  • consent records;
  • marketing preferences;
  • security and fraud-prevention information;
  • communications with Travellin; and
  • other information constituting personal data under applicable law.

Travellin will determine the scope of a request according to the applicable statutory definition of personal data.

Not every item associated with an account or transaction necessarily constitutes personal data belonging to the requester.


5. How to Submit a DSAR

A DSAR may be submitted by contacting:

privacy@travellin.info

The request should preferably contain sufficient information to enable Travellin to:

  1. identify the requester;
  2. understand that a data-access request is being made;
  3. locate the relevant account or records; and
  4. communicate the response securely.

A requester does not generally need to use particular legal wording.

For example, a request stating:

“I would like to know what personal data Travellin holds about me and request a copy of that information under applicable data-protection law.”

may constitute a valid access request.

Travellin will assess the substance of a request rather than reject it merely because the requester has not used the term “DSAR” or cited a particular statutory provision.


6. Identity Verification

Travellin may need to verify the identity of a requester before disclosing personal data.

This is necessary to protect individuals against unauthorised disclosure of personal information.

Where identity verification is reasonably required, Travellin may request information necessary to establish that the requester is the relevant data subject or is legitimately authorised to act on the data subject’s behalf.

Travellin will seek to avoid requesting excessive information.

Where possible, verification will be performed using information already associated with the relevant account or transaction.

Travellin will not normally require unnecessary identification documents merely as a matter of routine.

Where identification documentation is genuinely necessary, Travellin will explain the reason for the request.


7. Requests Made by Representatives

A person may submit a request on behalf of another individual where legally authorised to do so.

Examples may include:

  • a formally authorised representative;
  • a solicitor or legal adviser;
  • a parent or guardian where legally entitled to act;
  • an authorised attorney; or
  • another person with appropriate authority.

Travellin may require evidence of the representative’s authority before releasing personal data.

The representative should provide sufficient information to establish both:

  1. the identity of the data subject; and
  2. the representative’s authority to act.

8. Time Limit for Responding

Under Article 12(3) GDPR, a controller must generally respond to a data-subject request without undue delay and in any event within one month of receipt.

Where the request is complex or a large number of requests have been received, the response period may, where legally permitted, be extended by up to a further two months.

Where an extension is required, the requester must be informed within the original response period and given the reasons for the delay.

The UK GDPR contains corresponding provisions concerning the response period.

Travellin will seek to respond as promptly as reasonably practicable and will not use an extension merely as a matter of convenience.


9. Requests Which Are Manifestly Unfounded or Excessive

Data-protection legislation permits controllers, in specified circumstances, to refuse to act on or charge a reasonable fee for requests which are manifestly unfounded or excessive, particularly because of their repetitive character.

Such provisions will be applied cautiously.

Travellin will consider the circumstances of each request individually.

A requester will not be treated as making an excessive request merely because they exercise their statutory rights more than once where there is a legitimate reason for doing so.

Where Travellin relies upon a statutory ground for refusing to act or for charging a fee, the requester will be informed of the applicable reason and, where required, the available complaint or judicial remedies.


10. Electronic Responses

Where a DSAR is submitted electronically, Travellin will generally provide the response electronically unless:

  • the requester asks for another format;
  • another format is required for security reasons;
  • another format is more appropriate in the circumstances; or
  • applicable law requires otherwise.

Where technically appropriate, commonly used electronic formats may be used.

Travellin will take reasonable measures to prevent personal data contained in a DSAR response from being disclosed to an unauthorised person.


11. Right of Access

Subject to applicable exemptions, the right of access enables an individual to obtain:

  1. confirmation as to whether personal data concerning them are being processed;
  2. access to those personal data; and
  3. information concerning the processing required by applicable law.

This may include information concerning:

  • purposes of processing;
  • categories of personal data;
  • recipients or categories of recipients;
  • retention periods;
  • rights of rectification, erasure or restriction;
  • the right to complain to a supervisory authority;
  • the source of data not obtained directly from the individual;
  • international transfers; and
  • automated decision-making, including profiling, where applicable.

12. Copy of Personal Data

Where the right of access applies, the requester is generally entitled to receive a copy of the personal data undergoing processing.

The first copy will generally be provided without charge under GDPR and UK GDPR principles.

Additional copies may be subject to a reasonable fee where permitted by law, taking into account administrative costs.

A copy of personal data does not necessarily mean that the requester is entitled to receive every internal document, database, communication or business record in its original form.

The statutory right concerns access to personal data and prescribed information, subject to applicable legal limitations.


13. Rights of Other Individuals

A DSAR may contain information concerning other individuals.

Travellin must consider the rights and freedoms of those individuals before disclosing such information.

For example, correspondence may contain:

  • another traveller’s contact information;
  • employee information;
  • supplier personnel information;
  • third-party payment information; or
  • confidential information concerning another individual.

Travellin may therefore redact or withhold information where disclosure would unlawfully affect another person’s rights or where another legal exemption applies.

This does not mean that Travellin will automatically withhold an entire document merely because it contains third-party information.

Where reasonably possible, relevant personal data will be disclosed while protecting third-party information.


14. Commercially Confidential Information

A DSAR does not necessarily create an unrestricted right to receive confidential business information, trade secrets, proprietary algorithms or information protected by another person’s legal rights.

Where an exemption or restriction applies, Travellin will assess whether the information can nevertheless be disclosed in an appropriately limited form.

The objective is to balance the data subject’s statutory access right with other legally protected interests.


15. Right to Rectification

Under Article 16 GDPR, individuals have the right to obtain rectification of inaccurate personal data concerning them.

Individuals may also have the right to complete incomplete personal data, taking into account the purposes of processing.

A rectification request may be submitted to:

privacy@travellin.info

The requester should identify:

  • the information believed to be inaccurate or incomplete;
  • the correction requested; and
  • where reasonably appropriate, supporting information.

Travellin will assess the request and amend personal data where required by applicable law.


16. Right to Erasure

Individuals may have a right to request deletion of personal data under Article 17 GDPR, commonly known as the “right to be forgotten”.

The right is not absolute.

Erasure may not be required where processing is necessary, for example, for:

  • compliance with a legal obligation;
  • exercising freedom of expression and information;
  • establishment, exercise or defence of legal claims;
  • reasons of public interest recognised by law; or
  • other circumstances specified by applicable legislation.

Travellin will assess each erasure request according to the applicable legal grounds and retention obligations.


17. Right to Restriction of Processing

In circumstances specified by Article 18 GDPR, an individual may request restriction of processing.

This may apply, for example, where:

  • the accuracy of personal data is contested;
  • processing is unlawful but the individual prefers restriction rather than erasure;
  • Travellin no longer needs the data but the individual requires them for legal claims; or
  • the individual has objected to processing and the applicable assessment remains pending.

Restricted data may generally only be processed in accordance with the applicable statutory exceptions.


18. Right to Object

Where processing is based on legitimate interests or another legal basis permitting an objection, individuals may have a right to object.

Where personal data are processed for direct marketing, including profiling related to direct marketing, individuals generally have an unconditional right to object to such processing.

Marketing objections may be submitted through:

privacy@travellin.info

or, where available, by using the unsubscribe or marketing-preference mechanism included in the relevant communication.


19. Direct Marketing

Travellin may use personal data for direct marketing where lawful and where an appropriate legal basis exists.

Individuals may object to direct marketing at any time.

An objection to direct marketing will not normally affect the individual’s ability to maintain or use a Travellin account or complete a booking, although certain transactional communications may still be necessary.

Transactional communications, such as booking confirmations, payment notifications, security notices or legally required communications, are not necessarily direct marketing and may continue where necessary.


20. Automated Decision-Making and Profiling

Where applicable, individuals may have rights concerning automated decision-making, including profiling, under Article 22 GDPR and corresponding UK GDPR provisions.

Not every automated process constitutes “automated decision-making” within the meaning of Article 22.

For example, automated systems used to:

  • sort search results;
  • display available services;
  • calculate prices;
  • detect fraud;
  • personalise content; or
  • provide recommendations

do not automatically constitute legally significant automated decision-making producing the effects contemplated by Article 22.

Where legally relevant automated decision-making takes place, Travellin will provide the information and rights required by applicable law.


21. Data Portability

Where the statutory requirements of Article 20 GDPR are satisfied, an individual may have the right to receive certain personal data in a structured, commonly used and machine-readable format and to transmit those data to another controller.

Data portability generally applies where:

  • processing is based on consent or contract; and
  • processing is carried out by automated means.

The right does not apply to every category of personal data or every processing activity.


22. International Data Transfers

Travellin may use suppliers, processors and technology infrastructure located in jurisdictions outside the European Economic Area, the United Kingdom or Switzerland.

Where personal data are transferred internationally, Travellin will use appropriate safeguards required or recognised by applicable law.

Depending upon the jurisdiction and circumstances, these may include:

  • adequacy decisions;
  • standard contractual clauses;
  • UK transfer mechanisms;
  • recognised Swiss safeguards;
  • approved contractual protections; or
  • other lawful transfer mechanisms.

Further information is provided in the Travellin Privacy Policy.


23. Data Retention

Travellin does not retain personal data indefinitely merely because they have once been collected.

Retention periods depend upon factors including:

  • the purpose for which data were collected;
  • contractual requirements;
  • legal obligations;
  • accounting requirements;
  • tax requirements;
  • limitation periods;
  • dispute resolution;
  • fraud prevention;
  • security;
  • regulatory requirements; and
  • legitimate business needs permitted by law.

Some information may therefore remain available after an account is closed or a booking has been completed where retention is legally or legitimately required.


24. Booking and Supplier Data

Travel bookings may require Travellin to process information concerning passengers, guests and other travellers.

Depending upon the service, this may include information necessary for:

  • ticketing;
  • accommodation reservations;
  • passenger identification;
  • supplier fulfilment;
  • customer support;
  • payment;
  • fraud prevention;
  • legal compliance; and
  • travel documentation.

Where the relevant supplier independently determines the purposes and means of processing, the supplier may be a separate controller.

A DSAR directed to Travellin does not necessarily provide access to all data held independently by every supplier.

Where appropriate, Travellin will explain the distinction and identify the relevant supplier where reasonably possible.


25. Payment Information

Travellin may process transaction-related information necessary to administer payments and bookings.

Full payment-card information may be processed or stored by a regulated third-party payment service provider rather than Travellin.

Where Travellin does not possess the requested payment information, it cannot provide data that it does not hold.

The relevant payment provider may be the appropriate controller for certain payment-processing information.


26. Children’s Data

Travellin is not intended to encourage children to provide personal information independently where doing so would be unlawful.

Where a booking contains information concerning a child, the data may nevertheless be processed where necessary for travel arrangements, contractual performance, legal obligations or another lawful purpose.

A DSAR concerning a child or a request made by a parent or guardian will be handled according to applicable law and the legal authority of the requester.


27. Security of DSAR Responses

Because DSAR responses may contain sensitive personal information, Travellin may use security measures such as:

  • account authentication;
  • identity verification;
  • secure electronic delivery;
  • password protection;
  • encrypted transmission;
  • controlled access; or
  • other reasonable technical and organisational measures.

A requester should not send unnecessary sensitive information by ordinary email.

Travellin may provide instructions for secure verification where necessary.


28. If Travellin Cannot Locate Your Data

If Travellin does not hold personal data relating to the requester, it will communicate that fact where appropriate.

However, absence of data in Travellin’s systems does not necessarily mean that another independent supplier or service provider does not hold the individual’s information.

The requester may therefore need to contact the relevant supplier separately.

Travellin will not manufacture, infer or disclose information merely to satisfy a DSAR.


29. Complaints About Data Processing

If an individual believes that Travellin has processed personal data unlawfully, the individual should first contact:

privacy@travellin.info

Travellin will investigate the matter in accordance with its internal procedures and applicable law.

Individuals also have the right to complain to the competent data-protection supervisory authority.

For an organisation established in the Czech Republic, the competent supervisory authority is generally the Office for Personal Data Protection (Úřad pro ochranu osobních údajů / UOOU), subject to the applicable GDPR rules concerning the competent supervisory authority and the individual’s circumstances.

Under Article 77 GDPR, an individual may lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement.


30. UK Data-Protection Complaints

Individuals whose data are protected by UK data-protection legislation may complain to the Information Commissioner’s Office (“ICO”) where they believe their data-protection rights have been infringed.

Travellin encourages individuals to contact the company first so that the matter can be investigated and, where appropriate, resolved.

Nothing in this procedure removes an individual’s statutory right to complain directly to the competent supervisory authority.


31. Swiss Data-Protection Complaints

Where Swiss data-protection law applies, an individual may have rights to complain to the competent Swiss authority, including the Federal Data Protection and Information Commissioner (“FDPIC”), subject to the applicable statutory framework.

Travellin will cooperate with competent authorities as required by applicable law.


32. UK GDPR and Data Protection Act 2018

For UK-related processing, Travellin recognises the rights provided by the UK GDPR and the Data Protection Act 2018.

These include, subject to statutory conditions and exemptions:

  • access;
  • rectification;
  • erasure;
  • restriction;
  • objection;
  • data portability;
  • rights concerning automated decision-making; and
  • rights concerning certain direct-marketing activities.

The precise UK legal framework may differ from EU GDPR requirements following the UK’s separate legal and regulatory development.


33. Swiss FADP

Where Swiss data-protection law applies, Travellin will take account of the revised Federal Act on Data Protection (FADP) and applicable implementing provisions.

The revised FADP entered into force on 1 September 2023.

Swiss rights and terminology may differ in certain respects from the GDPR framework.

Where Swiss law applies, the applicable Swiss statutory provisions shall determine the scope of the individual’s rights.


34. No Charge for Ordinary Requests

Travellin will not ordinarily charge a fee for exercising statutory data-subject rights.

Where applicable law permits a reasonable fee or permits Travellin to refuse to act because a request is manifestly unfounded or excessive, Travellin may rely upon that statutory provision.

Any such decision will be communicated to the requester with the reasons required by law.


35. What to Include in a DSAR

To help Travellin process a request efficiently, the requester should provide:

Subject: Data Subject Access Request — [Full Name]

Requested right: Access / Rectification / Erasure / Restriction / Objection / Portability / Other

Full name: [Name]

Email address associated with Travellin: [Email]

Account or booking reference, if known: [Reference]

Description of request: [Details]

Preferred response format: [Electronic / Other]

The requester should not provide passwords, full payment-card numbers or other unnecessary authentication credentials.


36. DSAR Procedure

Travellin’s standard procedure is:

Step 1 — Receipt

The request is received through the privacy contact channel.

Step 2 — Identification

Travellin determines whether identity verification is reasonably necessary.

Step 3 — Scope

Travellin determines the nature and scope of the request.

Step 4 — Data Search

Relevant systems and records are searched within the lawful scope of the request.

Step 5 — Legal Review

Applicable exemptions, third-party rights, confidentiality obligations and other legal restrictions are assessed.

Step 6 — Response

The requester receives the applicable information, correction, deletion, restriction, explanation or other response.

Step 7 — Further Rights

Where applicable, the response explains complaint or appeal rights.


37. Data-Protection Principles

Travellin’s processing of personal data is based upon the applicable principles of data protection, including, where GDPR applies:

  • lawfulness, fairness and transparency;
  • purpose limitation;
  • data minimisation;
  • accuracy;
  • storage limitation;
  • integrity and confidentiality; and
  • accountability.

These principles inform Travellin’s approach to customer requests and personal-data management.


38. Relationship with the Privacy Policy

This page should be read together with the full Travellin Privacy Policy.

The Privacy Policy provides broader information concerning:

  • categories of personal data;
  • purposes of processing;
  • legal bases;
  • recipients;
  • processors;
  • international transfers;
  • cookies and similar technologies;
  • retention;
  • security;
  • profiling;
  • data-subject rights; and
  • contact procedures.

Where this DSAR page and the Privacy Policy describe the same legal right, both documents should be interpreted consistently.


39. Legal Basis for This Procedure

This procedure is designed principally with reference to:

Regulation (EU) 2016/679 (GDPR), including Articles 12–22;

UK GDPR;

Data Protection Act 2018;

Swiss Federal Act on Data Protection (FADP);

and applicable implementing, supervisory and national legislation.

The GDPR requires controllers to facilitate the exercise of data-subject rights and to provide information concerning action taken on a request within the applicable statutory period.


40. International Scope

Travellin is an international platform.

The data-protection law applicable to a particular individual may depend upon:

  • residence;
  • location;
  • citizenship where legally relevant;
  • the nature of the services offered;
  • the location of processing;
  • the establishment of the controller;
  • the territorial scope of the relevant legislation; and
  • other legally relevant circumstances.

Accordingly, the rights described on this page are not intended to limit rights granted by mandatory local law.

Where local law provides additional or stronger protections, those protections shall apply where legally required.


41. No Waiver of Statutory Rights

Nothing in this page:

  • excludes a statutory data-protection right;
  • restricts a right unlawfully;
  • prevents an individual from contacting a supervisory authority;
  • limits a judicial remedy;
  • authorises unlawful processing; or
  • removes a mandatory legal obligation imposed upon Travellin.

Where this page conflicts with mandatory applicable data-protection law, the mandatory law shall prevail.


42. Contact Details

All privacy-rights requests should preferably be directed to:

BETZONE s.r.o.
Platform: Travellin
Jurisdiction of establishment: Czech Republic

Privacy enquiries: privacy@travellin.info
General enquiries: info@travellin.info
Booking enquiries: bookings@travellin.info
Telephone: +420 732 844 855

For DSARs, use:

privacy@travellin.info


43. Final Statement

Travellin recognises that individuals have meaningful rights concerning their personal data.

A person should be able to understand whether their personal data are being processed, why the data are processed, what categories of information are involved, who may receive the information, how long it is retained and what legal rights are available.

Where an individual has a statutory right of access, Travellin will facilitate that right in accordance with applicable law.

Where other statutory rights apply, including rectification, erasure, restriction, objection or portability, Travellin will assess and process the request in accordance with the relevant legal requirements.

Identity verification may be used where reasonably necessary to prevent unauthorised disclosure.

Requests will be handled within the statutory time limits applicable to the relevant jurisdiction.

Travellin will seek to protect both the rights of the requesting individual and the lawful rights of other individuals, suppliers, employees, commercial partners and other persons whose information may be affected by a request.

Nothing in this procedure is intended to prevent an individual from exercising rights directly with a competent supervisory authority or court where such rights are available.

Company: BETZONE s.r.o.
Platform: Travellin
Jurisdiction of establishment: Czech Republic
Privacy enquiries: privacy@travellin.info
Telephone: +420 732 844 855

Effective Date: 24 August 2026
Last Updated: 24 August 2026

Travellin Assistant Online
1

Hi! I'm your
Travellin Travel Assistant

How can I help you today?

Scroll to Top