Login

Legal

Privacy notice

This notice explains what personal information Naseem's Travel collects when you use this website or book a tour with us, why we use it, who we share it with, and the rights you have over it under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Last updated: 2 September 2026

Draft prepared for review

This document is a working draft written for Naseem's Travel to review. It has not been checked by a lawyer, and it contains gaps where facts about the business are not yet known — each one is marked in amber below. It must be reviewed and approved by a qualified solicitor before this website accepts real bookings or takes payment from customers.

Who we are

Naseem's Travel is the data controller for the personal information described in this notice. That means we decide why and how it is used, and we are responsible for looking after it.

Trading name
Naseem's Travel
Registered company name
To be completed before launch — registered company name
Company number
To be completed before launch — Companies House number
Registered office
To be completed before launch — registered office address
VAT number
To be completed before launch — VAT number, or confirmation that the business is not VAT registered
ICO registration
To be completed before launch — ICO data protection register entry (ZA…)

Some entries above are still outstanding and must be completed before this site takes a real booking.

We have not appointed a Data Protection Officer. We are not required to under Article 37 of the UK GDPR, because we are not a public authority and our core activities do not involve large-scale monitoring or large-scale processing of special category data. Any question about this notice should go to travel@naseemus.com.

What we collect

Information you give us

  • Identity and contact details — your name, email address and telephone number, and the same for the other people travelling with you when you give them to us.
  • Booking details — the tour and departure date you choose, the number of adults and children, room requirements, your travel dates and any special requests.
  • Traveller documentation — where a supplier requires it, passport details, nationality, date of birth and next-of-kin information, collected at the point it is actually needed rather than at enquiry.
  • Health, dietary and accessibility information — only where you choose to tell us, so that we can arrange suitable food, rooms, transport or assistance. Health information is special category data under Article 9 of the UK GDPR and is treated with extra care.
  • Correspondence — the content of emails, messages and enquiry forms you send us, and notes of telephone calls.

Information created when you use the site

  • Account information — your email address and the one-time codes used to sign you in. We do not operate passwords, so we hold none.
  • Technical information — your IP address, the pages you request, the date and time, and your browser and device type, recorded in ordinary server logs by us and by our hosting provider.
  • Preferences stored in your browser — your chosen language and currency, your sign-in token and any part-completed booking form, all held on your own device. These are described in full in our cookie policy.

The site does not currently run any analytics, advertising or social media tracking. If that changes we will update this notice and ask for your consent first.

Payment information

At present this website does not take card payments. When you complete a booking you choose a payment method, and a member of our team contacts you to arrange payment; no card number, expiry date or security code is entered on this site or stored by us. When online card payments are introduced, the card details will be collected and processed by a regulated payment provider, and we expect to receive only the outcome of the payment, the amount, and the card type and last four digits.

To be completed before launch

Name the payment provider once it is chosen, add it to the list of recipients below, and confirm whether card details are entered on the provider’s own hosted page.

Why we use it, and our lawful bases

We only use your personal information where the law allows. In practice we rely on four lawful bases.

Performance of a contract — Article 6(1)(b)

  • Taking and confirming your booking and issuing your travel documents.
  • Passing on the details a supplier needs, so that hotels, guides, drivers, airlines and rail operators can deliver your trip.
  • Taking payment, issuing invoices and handling refunds.
  • Contacting you before, during and after your trip about your arrangements.

Legitimate interests — Article 6(1)(f)

Where we rely on legitimate interests we have considered whether our interest is overridden by your rights, and concluded that it is not. We rely on it to:

  • answer enquiries from people who have not yet booked;
  • keep the website and your account secure, and prevent and detect fraud;
  • keep a record of what was agreed, and defend or bring legal claims;
  • understand which tours are of interest so that we can improve what we offer.

You can object to any of this at any time — see your rights below.

Consent — Article 6(1)(a)

  • Sending you marketing emails about tours and offers, where you have asked to receive them. You can withdraw consent at any time using the unsubscribe link in any message or by emailing us; withdrawal does not affect anything we sent beforehand.
  • Storing or reading anything on your device that is not strictly necessary, if we ever introduce it.

Where you give us health, dietary or accessibility information we rely on your explicit consent under Article 9(2)(a), and we use it only to make the arrangements you have asked for.

Legal obligation — Article 6(1)(c)

  • Keeping accounting and tax records.
  • Meeting our obligations under the Package Travel and Linked Travel Arrangements Regulations 2018 and consumer protection law.
  • Responding to lawful requests from the authorities.

Who we share it with

We do not sell your personal information, and we do not share it for anyone else’s marketing. We share it only with the organisations needed to deliver your trip and to run our business:

  • Hotels and other accommodation providers in Uzbekistan and any other country on your itinerary — usually names, dates and room requirements.
  • Local ground handlers, guides and drivers who run the tour on the ground.
  • Airlines, rail operators and other transport providers — names as shown on your passport, dates of birth and document details where these are required for ticketing and for border and security checks.
  • Our payment provider, once online payments are introduced, and our bank.
  • Our email and messaging provider, which sends booking confirmations, sign-in codes and, where you have asked for them, marketing emails.
  • Our hosting and IT providers, who store the website and its database on our behalf.
  • Professional advisers — accountants, insurers and lawyers — where they need it in order to advise us.
  • Public authorities, where we are required by law to disclose information.

Every supplier that processes personal information on our behalf is bound by a written contract under Article 28 of the UK GDPR requiring it to keep the information secure and to use it only on our instructions. Hotels, airlines and local operators generally act as controllers in their own right for the information they receive, and handle it under their own privacy notices.

To be completed before launch

List the named processors actually used — hosting provider, email provider, payment provider and any CRM — before launch, and confirm that a data processing agreement is signed with each.

Sending information outside the UK

Our tours take place in Uzbekistan, and in neighbouring countries on some itineraries. To arrange them we have to send your details to hotels, guides, transport operators and local agents based there. Uzbekistan is not covered by UK adequacy regulations, which means the UK Government has not decided that it offers a level of data protection equivalent to the United Kingdom’s.

We make these transfers on the following basis:

  • Necessary for your contract. Where a transfer is necessary to perform the contract between you and us — booking your hotel room or your seat, for example — we rely on Article 49(1)(b) of the UK GDPR. Without the transfer the trip cannot be arranged.
  • Contractual safeguards. Where we use an overseas supplier on a continuing basis, we put in place the UK International Data Transfer Agreement, or the UK Addendum to the European Commission’s standard contractual clauses, and carry out a transfer risk assessment before the transfer begins.

We send only what the supplier genuinely needs, and we will make a copy of the relevant safeguards available to you on request.

How long we keep it

We keep personal information only for as long as we need it, and then delete it or anonymise it. Our working retention periods are:

  • Booking and payment records — six years from the end of the financial year in which your trip finished, to meet HMRC record-keeping requirements and to cover the limitation period for contract claims.
  • Enquiries that do not become bookings — To be completed before launch — retention period for unconverted enquiries (24 months proposed)
  • Marketing consents — until you withdraw consent, after which we keep a minimal suppression record so that we do not contact you again.
  • Website and server logs — To be completed before launch — log retention period, to be confirmed with the hosting provider
  • Health, dietary and accessibility notes — To be completed before launch — retention period for special category data (deletion shortly after the trip is proposed)

To be completed before launch

The full retention schedule must be settled and signed off, and the periods above confirmed, before launch.

How we keep it safe

We take appropriate technical and organisational measures to protect your information, including encryption of traffic to and from this website, access controls so that staff see only what they need, sign-in by one-time code rather than reusable passwords, and regular updating of the software we run. No system is perfectly secure, but if a breach occurs that is likely to result in a risk to your rights and freedoms we will report it to the Information Commissioner’s Office within 72 hours, and tell you without undue delay where the risk to you is high.

Your rights

Under the UK GDPR you have eight rights over your personal information.

  1. The right to be informed — to know what we do with your information. That is what this notice is for.
  2. The right of access — to ask for a copy of the personal information we hold about you, and an explanation of how we use it.
  3. The right to rectification — to have inaccurate information corrected and incomplete information completed.
  4. The right to erasure — to ask us to delete your information where we no longer need it, where you withdraw the consent we relied on, or where you object and we have no overriding grounds. It does not apply where we are required by law to keep records.
  5. The right to restrict processing — to ask us to pause our use of your information, for example while we check whether it is accurate.
  6. The right to data portability — to receive the information you gave us, where we use it by consent or for a contract and process it by automated means, in a structured, commonly used, machine-readable format, and to have it sent to another organisation where that is technically feasible.
  7. The right to object — to object to processing based on our legitimate interests, and an absolute right to object to direct marketing, which we will always stop on request.
  8. Rights relating to automated decision-making and profiling — not to be subject to a decision made solely by automated means that produces a legal or similarly significant effect on you. We do not make any such decisions.

You may also withdraw consent at any time where consent is the basis we rely on. To exercise any of these rights, email travel@naseemus.com. We will respond within one month, and will tell you if we need to extend that by up to two further months because the request is complex. There is normally no charge. We may ask you for information to confirm your identity before we act.

How to complain

If you are unhappy with how we have handled your personal information, please tell us first at travel@naseemus.com so that we have the chance to put it right.

You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection:

  • Online at ico.org.uk
  • By telephone on 0303 123 1113
  • By post to the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

Complaining to the ICO does not affect your right to take your own legal action.

Changes to this notice

We may update this notice as our business changes — for example when online card payments or website analytics are introduced. The date at the top shows when it was last revised. Where a change materially affects how we use information you have already given us, we will tell you directly.

Contact us

For anything in this notice, including a request to exercise your rights, write to travel@naseemus.com or call +44 79 8526 9296. Our postal address is the registered office shown in Who we are.