In short
- We collect the traveller identity details, identity documents and payment references
needed to make a booking and to meet our verification obligations under Indian law.
- We share them with the suppliers who must have them to deliver the service, and with our
payment aggregator to process payment. We do not sell personal data, and we do
not use it for any unrelated purpose.
- We never see, handle or store card numbers. Card and banking credentials are
entered on the payment provider's own hosted page.
- We are the data fiduciary, and processing is governed by
the Digital Personal Data Protection Act, 2023.
- To ask what we hold, correct it, or have it deleted, email
[email protected].
1. Who we are
TDMC Global Travel Rep LLP operates DMC Quote, a business-to-business
travel booking platform for travel agencies. We are the data fiduciary for the personal data
described in this policy.
- Registered office
- CS, 3rd Floor, Office No. 47, Ansal Plaza,
Sector-1, Vaishali, Ghaziabad,
Uttar Pradesh 201014, India
- GSTIN
- 09AAXFT4187G1ZC
- Governing statute
- The Digital Personal Data Protection Act, 2023
- Data queries
- [email protected]
2. What we collect
From the travel agency
- Agency name, registered address, GSTIN or equivalent tax registration, and the
know-your-customer pack required to open an account.
- Contact details of the people at the agency who use the platform — name, work email,
telephone number and job role.
- Account credentials, and a log of activity within the agent portal.
About travellers, supplied to us by the agency
- Name, date of birth, nationality and contact details as required by the supplier.
- Identity documents where the booking or the law requires them — passport, visa, and the
lead traveller's PAN card.
- Permanent Account Number for verification against the income-tax record, where the rupee
payment route is used.
- Flight details for the journey, and any special requirements the traveller has asked to
be passed to a hotel or operator.
About payments
- Payment references, amounts, currency, the rate applied, and the settlement record.
- Not card numbers. Card, UPI and netbanking credentials are entered directly on
Cashfree Payments India Private Limited's hosted systems. We receive only a
reference and a result.
Automatically, when you use this website
- IP address, browser and device type, pages viewed, and the time of the visit — used to
keep the platform secure and working, and to understand which pages are useful.
- Cookies necessary to keep you logged in and to remember your preferences.
3. Why we hold it, and on what basis
- To perform the booking. Suppliers cannot issue a voucher or admit a guest without
the traveller's name and, for many destinations, their document details.
- To meet verification and compliance obligations. PAN verification, know-your-
customer checks and sanctions screening are conditions of operating the rupee payment
route and of Indian law, not optional extras.
- To process payment and to investigate a disputed or failed one.
- To keep the records the law requires us to keep, including tax records and the
audit trail of what was accepted at checkout.
- To operate and secure the platform, and to communicate with the agency about its
bookings.
The agency confirms to us that it holds each traveller's consent to pass their personal data
and identity documents to us for these purposes, and that the information given is true. We
rely on that confirmation and are not obliged to look behind it.
4. Who we share it with
- Suppliers — hotels, transport operators, attraction operators, guides and local
ground handlers — who must have the traveller's details to deliver the service booked.
They receive only what that service requires.
- Our payment aggregator, Cashfree Payments India Private Limited, to process
payment and to run PAN verification against the income-tax record.
- Professional advisers and auditors, where they need it to advise us, under a duty
of confidence.
- Government authorities, regulators, courts or law enforcement, where we are
required to disclose it or where we must report a suspected offence.
- Companies within the Travel DMC Group, where they operate part of the service on
our behalf, under the same obligations that apply to us.
We do not sell personal data. We do not share it with advertisers or data brokers, and we
do not use it for any purpose unrelated to the booking.
5. Where it goes
Travel is cross-border by nature: a booking in Bali is delivered by a supplier in Indonesia,
and their staff must receive the traveller's details to deliver it. Personal data may
therefore be transferred outside India to the country where the service is provided, and to
the group company arranging it. We transfer only what the supplier needs, and only to
countries to which such transfer is permitted.
6. How long we keep it
- Booking and payment records are retained for as long as the tax and accounting law of
India requires — currently a minimum of eight years from the end of the relevant
financial year.
- Verification and compliance files are retained for the period the applicable
anti-money-laundering and exchange control rules require.
- Identity documents no longer required for either purpose are deleted.
- Documents withdrawn by the agency are removed from view but retained in the audit
record, because what was submitted and withdrawn is itself part of the compliance
file.
- Website analytics data is retained in aggregate form only after 26 months.
7. How we protect it
- The platform is served over TLS, and access to booking and compliance records is
restricted to staff who need it for their role.
- Identity documents are held in access-controlled storage, separate from the general
booking record.
- Card and banking credentials never reach our systems — they are handled entirely by our
PCI-DSS compliant payment aggregator on its own hosted pages.
- We keep an audit trail of access to compliance files.
- No system is perfectly secure. Where a breach is likely to affect you, we will notify
you and the Data Protection Board as the law requires.
8. Your rights
Under the Digital Personal Data Protection Act, 2023, you may ask us to:
- Tell you what we hold about you and who we have shared it with.
- Correct or complete anything inaccurate or out of date.
- Erase personal data we are no longer required to retain. Records we are obliged
to keep for tax or compliance purposes are retained for as long as the relevant law
requires, and no longer.
- Withdraw consent where processing rests on consent. Withdrawing consent for data
a supplier needs will usually mean the booking cannot proceed.
- Nominate another person to exercise these rights in the event of your death or
incapacity.
- Complain to us, and — if we do not resolve it — to the Data Protection Board of
India.
Email [email protected] and we
will respond within the period the law prescribes. Where a request concerns a traveller
whose data was supplied to us by an agency, we may need to route it through that agency,
since they hold the relationship and the consent.
9. Cookies
We use cookies that are necessary to keep you signed in to the agent portal, to keep your
session secure, and to remember display preferences. We also use analytics cookies to
understand which pages agencies find useful. You can block cookies in your browser, but the
agent portal will not stay signed in without the necessary ones.
10. Changes to this policy
We may revise this policy. The version and effective date are shown at the top of this page.
A later revision does not change the basis on which data was processed before it, and where
a change materially affects how we handle your data we will tell account holders directly.
Contact us about this policy
Write to us before raising a query with your bank or card issuer. We can
almost always resolve it faster from our own record of the transaction, and
our Terms & Conditions ask you to come to us first.
- Company
- TDMC Global Travel Rep LLP
- Registered office
- CS, 3rd Floor, Office No. 47, Ansal Plaza,
Sector-1, Vaishali, Ghaziabad,
Uttar Pradesh 201014, India
- GSTIN
- 09AAXFT4187G1ZC
- Payments & refunds
- [email protected]
- Sales & bookings
- [email protected]
- Telephone
-
+91 78380 07208 (India)
·
+65 8034 8190 (Singapore)
- Hours
- Monday to Saturday, 09:00–18:00 India Standard Time (GMT+5:30)