1. Who we are (Data Controller)
Dreampath Odyssey Travel Management Company Limited is the data controller for personal data processed through this platform. We are registered in Kenya and our registered office is in Thika, Kiambu County.
- Data Protection Officer (DPO): dpo@dreampathodyssey.com
- General enquiries: privacy@dreampathodyssey.com
2. Personal data we collect
- Account data: name, email address, phone number, agency membership, role.
- Traveller data: passenger names, dates of birth, passport / ID numbers, contact details, itinerary preferences.
- Booking & ticketing data: reservation records, PNRs, e-ticket numbers, fare and commercial terms.
- Financial data: invoice amounts, payment references, currency, sales-ledger entries. We do not store full card numbers.
- Technical data: IP address, device / browser type, authentication logs, MFA activity, timestamps.
- Audit data: a tamper-evident record of security-relevant actions taken in the platform.
3. Lawful bases for processing (s.30 of the Act)
- Contract: to book, ticket, invoice and deliver the travel services you request.
- Legal obligation: to comply with tax, accounting, anti-money-laundering and aviation regulations.
- Legitimate interests: to secure the platform, prevent fraud, and improve our services — balanced against your rights.
- Consent: for optional marketing communications. You may withdraw consent at any time.
4. How we use your data
We use personal data to operate the reservation, ticketing, finance, CRM and reporting functions of the platform; to authenticate you (including multi-factor authentication); to communicate about bookings and invoices; to detect and investigate security incidents; and to meet our legal, tax and audit obligations.
5. Disclosures to third parties
We share personal data only where necessary, with:
- Airlines, hotels, tour operators, GDS providers and other travel suppliers to fulfil your booking.
- Payment processors, banks (including Kenya Commercial Bank for KES remittance) and tax authorities.
- Cloud infrastructure and security service providers acting as our data processors under written agreements.
- Regulatory or law-enforcement bodies where we are legally required to disclose.
6. Cross-border transfers (s.48–50)
Some of our sub-processors and travel suppliers operate outside Kenya. Where personal data is transferred outside Kenya, we rely on one of the safeguards permitted by the Act — including adequacy determinations, contractual safeguards, or your explicit consent — and we assess each transfer for the level of protection provided.
7. Retention
We keep booking, ticketing and financial records for the periods required by Kenyan tax and aviation law (typically 7 years). Account and audit records are retained for the life of the account plus a reasonable period thereafter for legal, dispute-resolution and security purposes. When retention expires, data is deleted or irreversibly anonymised.
8. Security
We implement organisational and technical safeguards including row-level access control, encryption in transit, rate-limiting and brute-force protection on authentication, mandatory multi-factor authentication for privileged roles, and a tamper-evident audit trail. Security incidents affecting personal data will be reported to the ODPC within 72 hours as required by the Act, and to affected data subjects without undue delay where a high risk exists.
9. Your rights (Part V of the Act)
As a data subject you have the right to:
- Be informed of the use of your personal data.
- Access the personal data we hold about you.
- Object to the processing of your personal data.
- Correction and deletion of false or misleading data.
- Withdraw consent where processing is based on consent.
- Data portability, where technically feasible.
To exercise any of these rights, contact our DPO at dpo@dreampathodyssey.com. We will respond within the statutory timelines. You also have the right to lodge a complaint with the Office of the Data Protection Commissioner at odpc.go.ke.
10. Cookies and analytics
We use strictly necessary cookies to keep you signed in and to protect the platform against abuse. We do not sell personal data or use cross-site advertising trackers.
11. Children
The platform is intended for use by travel professionals and adult travellers. We do not knowingly collect personal data of children under 18 except where provided by a parent or guardian in the context of a family travel booking.
12. Changes to this policy
We may update this policy from time to time. Material changes will be notified through the platform. The “Last updated” date above indicates the current version.
13. Contact
Dreampath Odyssey Travel Management Company Limited
Thika, Kiambu County, Kenya
DPO: dpo@dreampathodyssey.com
15. Terms of service (summary)
Access to the DreamPath Odyssey platform is granted per tenant under a written service agreement. In summary: you are responsible for the accuracy of the data you enter and for the credentials issued to your users; you may not attempt to access another tenant’s records or probe the platform’s security controls; we provide the service on a commercially reasonable-efforts basis, maintain tenant-level isolation and audit logs, and process your data only on your instructions as described in this notice. The signed service agreement governs in the event of any conflict with this summary.
