Legal
Privacy notice
This notice explains what personal information Naseem's Travel collects when you use this website or book a tour with us, why we use it, who we share it with, and the rights you have over it under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Last updated: 2 September 2026
Draft prepared for review
This document is a working draft written for Naseem's Travel to review. It has not been checked by a lawyer, and it contains gaps where facts about the business are not yet known — each one is marked in amber below. It must be reviewed and approved by a qualified solicitor before this website accepts real bookings or takes payment from customers.
Who we are
Naseem's Travel is the data controller for the personal information described in this notice. That means we decide why and how it is used, and we are responsible for looking after it.
- Trading name
- Naseem's Travel
- Registered company name
- To be completed before launch — registered company name
- Company number
- To be completed before launch — Companies House number
- Registered office
- To be completed before launch — registered office address
- VAT number
- To be completed before launch — VAT number, or confirmation that the business is not VAT registered
- ICO registration
- To be completed before launch — ICO data protection register entry (ZA…)
- travel@naseemus.com
- Telephone
- +44 79 8526 9296
Some entries above are still outstanding and must be completed before this site takes a real booking.
We have not appointed a Data Protection Officer. We are not required to under Article 37 of the UK GDPR, because we are not a public authority and our core activities do not involve large-scale monitoring or large-scale processing of special category data. Any question about this notice should go to travel@naseemus.com.
What we collect
Information you give us
- Identity and contact details — your name, email address and telephone number, and the same for the other people travelling with you when you give them to us.
- Booking details — the tour and departure date you choose, the number of adults and children, room requirements, your travel dates and any special requests.
- Traveller documentation — where a supplier requires it, passport details, nationality, date of birth and next-of-kin information, collected at the point it is actually needed rather than at enquiry.
- Health, dietary and accessibility information — only where you choose to tell us, so that we can arrange suitable food, rooms, transport or assistance. Health information is special category data under Article 9 of the UK GDPR and is treated with extra care.
- Correspondence — the content of emails, messages and enquiry forms you send us, and notes of telephone calls.
Information created when you use the site
- Account information — your email address and the one-time codes used to sign you in. We do not operate passwords, so we hold none.
- Technical information — your IP address, the pages you request, the date and time, and your browser and device type, recorded in ordinary server logs by us and by our hosting provider.
- Preferences stored in your browser — your chosen language and currency, your sign-in token and any part-completed booking form, all held on your own device. These are described in full in our cookie policy.
The site does not currently run any analytics, advertising or social media tracking. If that changes we will update this notice and ask for your consent first.
Payment information
At present this website does not take card payments. When you complete a booking you choose a payment method, and a member of our team contacts you to arrange payment; no card number, expiry date or security code is entered on this site or stored by us. When online card payments are introduced, the card details will be collected and processed by a regulated payment provider, and we expect to receive only the outcome of the payment, the amount, and the card type and last four digits.
To be completed before launch
Name the payment provider once it is chosen, add it to the list of recipients below, and confirm whether card details are entered on the provider’s own hosted page.
Why we use it, and our lawful bases
We only use your personal information where the law allows. In practice we rely on four lawful bases.
Performance of a contract — Article 6(1)(b)
- Taking and confirming your booking and issuing your travel documents.
- Passing on the details a supplier needs, so that hotels, guides, drivers, airlines and rail operators can deliver your trip.
- Taking payment, issuing invoices and handling refunds.
- Contacting you before, during and after your trip about your arrangements.
Legitimate interests — Article 6(1)(f)
Where we rely on legitimate interests we have considered whether our interest is overridden by your rights, and concluded that it is not. We rely on it to:
- answer enquiries from people who have not yet booked;
- keep the website and your account secure, and prevent and detect fraud;
- keep a record of what was agreed, and defend or bring legal claims;
- understand which tours are of interest so that we can improve what we offer.
You can object to any of this at any time — see your rights below.
Consent — Article 6(1)(a)
- Sending you marketing emails about tours and offers, where you have asked to receive them. You can withdraw consent at any time using the unsubscribe link in any message or by emailing us; withdrawal does not affect anything we sent beforehand.
- Storing or reading anything on your device that is not strictly necessary, if we ever introduce it.
Where you give us health, dietary or accessibility information we rely on your explicit consent under Article 9(2)(a), and we use it only to make the arrangements you have asked for.
Legal obligation — Article 6(1)(c)
- Keeping accounting and tax records.
- Meeting our obligations under the Package Travel and Linked Travel Arrangements Regulations 2018 and consumer protection law.
- Responding to lawful requests from the authorities.
Sending information outside the UK
Our tours take place in Uzbekistan, and in neighbouring countries on some itineraries. To arrange them we have to send your details to hotels, guides, transport operators and local agents based there. Uzbekistan is not covered by UK adequacy regulations, which means the UK Government has not decided that it offers a level of data protection equivalent to the United Kingdom’s.
We make these transfers on the following basis:
- Necessary for your contract. Where a transfer is necessary to perform the contract between you and us — booking your hotel room or your seat, for example — we rely on Article 49(1)(b) of the UK GDPR. Without the transfer the trip cannot be arranged.
- Contractual safeguards. Where we use an overseas supplier on a continuing basis, we put in place the UK International Data Transfer Agreement, or the UK Addendum to the European Commission’s standard contractual clauses, and carry out a transfer risk assessment before the transfer begins.
We send only what the supplier genuinely needs, and we will make a copy of the relevant safeguards available to you on request.
How long we keep it
We keep personal information only for as long as we need it, and then delete it or anonymise it. Our working retention periods are:
- Booking and payment records — six years from the end of the financial year in which your trip finished, to meet HMRC record-keeping requirements and to cover the limitation period for contract claims.
- Enquiries that do not become bookings — To be completed before launch — retention period for unconverted enquiries (24 months proposed)
- Marketing consents — until you withdraw consent, after which we keep a minimal suppression record so that we do not contact you again.
- Website and server logs — To be completed before launch — log retention period, to be confirmed with the hosting provider
- Health, dietary and accessibility notes — To be completed before launch — retention period for special category data (deletion shortly after the trip is proposed)
To be completed before launch
The full retention schedule must be settled and signed off, and the periods above confirmed, before launch.
How we keep it safe
We take appropriate technical and organisational measures to protect your information, including encryption of traffic to and from this website, access controls so that staff see only what they need, sign-in by one-time code rather than reusable passwords, and regular updating of the software we run. No system is perfectly secure, but if a breach occurs that is likely to result in a risk to your rights and freedoms we will report it to the Information Commissioner’s Office within 72 hours, and tell you without undue delay where the risk to you is high.
Your rights
Under the UK GDPR you have eight rights over your personal information.
- The right to be informed — to know what we do with your information. That is what this notice is for.
- The right of access — to ask for a copy of the personal information we hold about you, and an explanation of how we use it.
- The right to rectification — to have inaccurate information corrected and incomplete information completed.
- The right to erasure — to ask us to delete your information where we no longer need it, where you withdraw the consent we relied on, or where you object and we have no overriding grounds. It does not apply where we are required by law to keep records.
- The right to restrict processing — to ask us to pause our use of your information, for example while we check whether it is accurate.
- The right to data portability — to receive the information you gave us, where we use it by consent or for a contract and process it by automated means, in a structured, commonly used, machine-readable format, and to have it sent to another organisation where that is technically feasible.
- The right to object — to object to processing based on our legitimate interests, and an absolute right to object to direct marketing, which we will always stop on request.
- Rights relating to automated decision-making and profiling — not to be subject to a decision made solely by automated means that produces a legal or similarly significant effect on you. We do not make any such decisions.
You may also withdraw consent at any time where consent is the basis we rely on. To exercise any of these rights, email travel@naseemus.com. We will respond within one month, and will tell you if we need to extend that by up to two further months because the request is complex. There is normally no charge. We may ask you for information to confirm your identity before we act.
How to complain
If you are unhappy with how we have handled your personal information, please tell us first at travel@naseemus.com so that we have the chance to put it right.
You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection:
- Online at ico.org.uk
- By telephone on 0303 123 1113
- By post to the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Complaining to the ICO does not affect your right to take your own legal action.
Changes to this notice
We may update this notice as our business changes — for example when online card payments or website analytics are introduced. The date at the top shows when it was last revised. Where a change materially affects how we use information you have already given us, we will tell you directly.
Contact us
For anything in this notice, including a request to exercise your rights, write to travel@naseemus.com or call +44 79 8526 9296. Our postal address is the registered office shown in Who we are.
