Legal · Compliance

Privacy Policy

Effective date: 1 January 2026 · Last updated: 9/22/2026

This Privacy Policy explains how Dreampath Odyssey Travel Management Company Limited(“Dreampath”, “we”, “us”) collects, uses, discloses and protects your personal data. It is issued in compliance with the Kenya Data Protection Act, 2019 (the “Act”) and the regulations issued under it by the Office of the Data Protection Commissioner (ODPC).

Company details — to be completed before publication

The following fields must be filled in by Dreampath Odyssey Travel Management Company Limited. Do not treat the bracketed values as accurate.

Registered office address
[TO BE COMPLETED]
ODPC data-controller registration no.
[TO BE COMPLETED]
Data Protection Officer — name
[TO BE COMPLETED]
Data Protection Officer — email
[TO BE COMPLETED]

1. Who we are (Data Controller)

Dreampath Odyssey Travel Management Company Limited is the data controller for personal data processed through this platform. We are registered in Kenya and our registered office is in Thika, Kiambu County.

2. Personal data we collect

  • Account data: name, email address, phone number, agency membership, role.
  • Traveller data: passenger names, dates of birth, passport / ID numbers, contact details, itinerary preferences.
  • Booking & ticketing data: reservation records, PNRs, e-ticket numbers, fare and commercial terms.
  • Financial data: invoice amounts, payment references, currency, sales-ledger entries. We do not store full card numbers.
  • Technical data: IP address, device / browser type, authentication logs, MFA activity, timestamps.
  • Audit data: a tamper-evident record of security-relevant actions taken in the platform.

3. Lawful bases for processing (s.30 of the Act)

  • Contract: to book, ticket, invoice and deliver the travel services you request.
  • Legal obligation: to comply with tax, accounting, anti-money-laundering and aviation regulations.
  • Legitimate interests: to secure the platform, prevent fraud, and improve our services — balanced against your rights.
  • Consent: for optional marketing communications. You may withdraw consent at any time.

4. How we use your data

We use personal data to operate the reservation, ticketing, finance, CRM and reporting functions of the platform; to authenticate you (including multi-factor authentication); to communicate about bookings and invoices; to detect and investigate security incidents; and to meet our legal, tax and audit obligations.

5. Disclosures to third parties

We share personal data only where necessary, with:

  • Airlines, hotels, tour operators, GDS providers and other travel suppliers to fulfil your booking.
  • Payment processors, banks (including Kenya Commercial Bank for KES remittance) and tax authorities.
  • Cloud infrastructure and security service providers acting as our data processors under written agreements.
  • Regulatory or law-enforcement bodies where we are legally required to disclose.

6. Cross-border transfers (s.48–50)

Some of our sub-processors and travel suppliers operate outside Kenya. Where personal data is transferred outside Kenya, we rely on one of the safeguards permitted by the Act — including adequacy determinations, contractual safeguards, or your explicit consent — and we assess each transfer for the level of protection provided.

7. Retention

We keep booking, ticketing and financial records for the periods required by Kenyan tax and aviation law (typically 7 years). Account and audit records are retained for the life of the account plus a reasonable period thereafter for legal, dispute-resolution and security purposes. When retention expires, data is deleted or irreversibly anonymised.

8. Security

We implement organisational and technical safeguards including row-level access control, encryption in transit, rate-limiting and brute-force protection on authentication, mandatory multi-factor authentication for privileged roles, and a tamper-evident audit trail. Security incidents affecting personal data will be reported to the ODPC within 72 hours as required by the Act, and to affected data subjects without undue delay where a high risk exists.

9. Your rights (Part V of the Act)

As a data subject you have the right to:

  • Be informed of the use of your personal data.
  • Access the personal data we hold about you.
  • Object to the processing of your personal data.
  • Correction and deletion of false or misleading data.
  • Withdraw consent where processing is based on consent.
  • Data portability, where technically feasible.

To exercise any of these rights, contact our DPO at dpo@dreampathodyssey.com. We will respond within the statutory timelines. You also have the right to lodge a complaint with the Office of the Data Protection Commissioner at odpc.go.ke.

10. Cookies and analytics

We use strictly necessary cookies to keep you signed in and to protect the platform against abuse. We do not sell personal data or use cross-site advertising trackers.

11. Children

The platform is intended for use by travel professionals and adult travellers. We do not knowingly collect personal data of children under 18 except where provided by a parent or guardian in the context of a family travel booking.

12. Changes to this policy

We may update this policy from time to time. Material changes will be notified through the platform. The “Last updated” date above indicates the current version.

13. Contact

Dreampath Odyssey Travel Management Company Limited
Thika, Kiambu County, Kenya
DPO: dpo@dreampathodyssey.com

14. Cookies and similar technologies

Our public website uses a small number of cookies and equivalent browser storage. We group them into three categories and ask for your choice before any non-essential category is used:

  • Strictly necessary — sign-in, session integrity, security and your cookie preference itself. These cannot be switched off.
  • Analytics — anonymous counts of page views and button clicks on our landing page. No name, email or IP address is stored against these counts.
  • Marketing — measuring which campaigns bring agencies to DreamPath.

You can accept all, reject non-essential, or customise your choice in the consent banner shown on your first visit, and change it at any time from the “Cookie settings” link in the website footer. Rejecting non-essential cookies does not restrict access to the site.

15. Terms of service (summary)

Access to the DreamPath Odyssey platform is granted per tenant under a written service agreement. In summary: you are responsible for the accuracy of the data you enter and for the credentials issued to your users; you may not attempt to access another tenant’s records or probe the platform’s security controls; we provide the service on a commercially reasonable-efforts basis, maintain tenant-level isolation and audit logs, and process your data only on your instructions as described in this notice. The signed service agreement governs in the event of any conflict with this summary.