Personal Data Protection Policy
- INTRODUCTION
- PADDYS TRAVEL is a tourism company dedicated to the sale of tourist services nationwide through service intermediation, which includes: sale of transport tickets, private transfers, lodging and food services, tourist packages and full days located in C. mamaco Retiro Moyopata – Parcco | Limatambo – Anta – Cusco – Peru, is obliged to comply with current Peruvian legislation on the protection of personal data, Law No. 29733 on the Protection of Personal Data and its complementary provisions.
- Therefore, PADDYS TRAVEL is committed to: • The collection and use of personal information. • Ensuring the quality and security of the information. • Respecting the rights of individuals with respect to information about themselves.
- PADDYS TRAVEL is committed to the protection, handling, and proper processing of personal data to which it has access in the ordinary course of its business. This commitment includes the continuous review and improvement of the organization’s processes to ensure the adequate protection of such personal data and adherence to the guidelines established by PADDYS TRAVEL for the collection and processing of personal data, thereby ensuring respect for the rights of data subjects and compliance with current regulations. This Policy may be supplemented by additional procedures, rules, and/or guidelines that further develop the provisions of this document, provided they are aligned with its guiding principles.
- AIM
- The purpose of this document is to establish uniform principles, practices and responsibilities regarding the processing of personal data in which PADDYS TRAVEL is involved.
- SCOPE
- This document applies to all PADDYS TRAVEL processes that will use personal data of customers intended to be contained in the different databases of PADDYS TRAVEL and its processing.
- This Policy will be fully understood and complied with by all PADDYS TRAVEL employees and suppliers. For the purposes of interpreting this Policy, the definitions contained in the Law, and in particular those included below, apply.
- DEFINITIONS
- Personal data: Any information that identifies a natural person or that can be identified by reasonably used means. For example, national identity document number, physical address, full name. Sensitive data: Personal data consisting of biometric data that can, by itself, identify the data subject; data relating to racial or ethnic origin; economic income; political, religious, philosophical, or moral opinions or beliefs; union membership; and health-related information.
- Processing of personal data: Any operation or technical procedure, automated or not, that allows the collection, recording, organization, storage, retention, processing, modification, retrieval, consultation, use, blocking, erasure, communication by transfer or dissemination, or any other form of processing that facilitates access, correlation, or interconnection of personal data. In short, the processing of personal data governs all possible forms of use and processing of personal data within the organization, from its receipt to its eventual deletion or retention.
- Consent: Prior, free, unambiguous, and express authorization that the data subject must grant to authorize the processing of their personal data. • Prior: It must be obtained before collection. • Free: It must not be forced or conditional. • Unambiguous and express: There must be no doubt about its manifestation, and it must be recorded in some tangible medium. • Personal data bank: An organized set of personal data, automated or not, regardless of the medium, whether physical, magnetic, digital, optical, or other, on which it is created, and regardless of the form or method of its creation, formation, storage, organization, and access.
- Owner of the personal data bank: A natural person, private legal entity, or public entity that determines the purpose and content of the personal data bank, the processing of such data, and the security measures. Controller of the personal data bank: Any natural person, private legal entity, or public entity that, alone or jointly with another, processes personal data on behalf of the owner of the personal data bank. Anonymization procedure: The processing of personal data that prevents the identification of, or does not identify, the data subject. The procedure is irreversible. De-identification procedure: The processing of personal data that prevents the identification of, or does not identify, the data subject.
- COMPLIANCE OFFICER
- PADDYS TRAVEL will assign and communicate the corresponding responsibilities to all staff and suppliers for compliance with this Policy.
- The General Management will be responsible for reviewing this Policy annually and making any necessary adjustments within PADDYS TRAVEL . This Management will also be responsible for resolving any questions related to the application and scope of this Policy.
- Notwithstanding the foregoing, all PADDYS TRAVEL employees, as well as all suppliers and third parties with whom PADDYS TRAVEL engages in the ordinary course of its business and who have access to or process personal data, are subject to compliance with this Policy. Finally, no PADDYS TRAVEL employee shall act on behalf of the Company in any way that constitutes a violation of the Law.
- CONFIDENTIALITY
- This Policy is for the internal and exclusive use of PADDYS TRAVEL and is therefore confidential. Any use other than that indicated is prohibited and must be expressly authorized in writing by General Management.
- Personal data accessed or processed by PADDYS TRAVEL employees or related third parties may not be processed or used in any way without the prior consent of the data subject, even after the termination of their relationship with PADDYS TRAVEL , except for the exceptions regulated by law.
- In the case of employees who, due to the nature of their duties, have access to confidential and sensitive personal information, PADDYS TRAVEL will endeavor to develop specific training and awareness programs. Those involved in the processing of personal data are bound by professional secrecy and confidentiality regarding such data. This obligation will continue even after the termination of their relationship with PADDYS TRAVEL.
- BEGINNING
All PADDYS TRAVEL employees must permanently comply with the principles established in the Law detailed below:
- PADDYS TRAVEL will process personal data in accordance with the law. The collection of personal data by fraudulent, unfair, or illegal means is prohibited.
- PADDYS TRAVEL may not process personal data without the prior, express, unequivocal and free consent of the owner as necessary, except for the exceptions provided for by law.
- PADDYS TRAVEL will collect personal data, clearly indicating the purpose for which it is collected, which must be specific, explicit, and lawful. The personal data processed may not be used for purposes other than or incompatible with those for which it was obtained, except with the data subject’s consent. In this regard, PADDYS TRAVEL will implement measures that guarantee: • The collection, storage, and retention of personal data comply with the principles of proportionality and purpose limitation. • The adequate protection of personal data by complying with appropriate technical and legal security measures. It should be noted that PADDYS TRAVEL Investments…
- All processing of personal data carried out by PADDYS TRAVEL must be adequate, relevant and not excessive for the purpose for which they were collected.
- The personal data processed by PADDYS TRAVEL must be truthful, accurate, and, where possible, up-to-date, necessary, relevant, and appropriate for the purpose for which it was collected. It must be stored in a way that guarantees its security and only for as long as necessary to fulfill the purpose of the processing, respecting applicable legal retention periods for documents and information.
- PADDYS TRAVEL and any third parties entrusted with the processing of personal data must adopt the necessary and appropriate technical, organizational, and legal measures to guarantee the security of personal data against various risks, such as accidental loss or destruction due to unauthorized access, covert use, or infection by malware or computer viruses. These measures will be established, communicated, and, where necessary, updated by PADDYS TRAVEL.
- Adequate level of protection. If PADDYS TRAVEL carries out international transfers of personal data, it must guarantee a sufficient level of protection for the personal data it will process or, at least, equivalent to that provided for in the Law.
- Rights of personal data holders. PADDYS TRAVEL will have a simple and free procedure to address the rights of personal data holders contemplated in the Law: (i) information, (ii) access, (iii) updating, (iv) inclusion, (v) rectification, (vi) deletion, (vii) prevent the supply, (viii) opposition and (ix) objective processing.
Therefore, PADDYS TRAVEL will: • Take the necessary measures to inform the data subject of their rights under the Law. • Take measures to allow the data subject to keep their personal data updated. • Respond in a timely manner and in accordance with the law to requests and inquiries related to the rights of data subjects. The following guidelines will apply to the processes for addressing the rights of data subjects: • The deletion or rectification of personal data will not be permitted when it affects the rights or legitimate interests of PADDYS TRAVEL, its shareholders, employees, or directors, or of third parties, or when there is a legal obligation to retain the personal data. • PADDYS TRAVEL may refuse certain requests when the disclosure of personal data could compromise or hinder ongoing judicial or administrative proceedings.
- TRANSFER OF PERSONAL DATA
- Personal data processed by PADDYS TRAVEL may only be transferred to third parties for purposes related to the legitimate interests of both the transferor and the transferee, and with the prior, express, free, unambiguous, and informed consent of the data subject. Such consent will not be required in cases permitted by law.
- COLLECTION OF SENSITIVE DATA
- PADDYS TRAVEL will inform the data subject of this situation prior to collecting their data. It will only collect personal and/or sensitive data when strictly necessary and in compliance with the principles of purpose limitation and proportionality. When the collection and processing of such data derives from compliance with a legal obligation, PADDYS TRAVEL will inform the data subject of this situation prior to collecting their data.
- DISCLOSURE OF PERSONAL DATA
PADDYS TRAVEL will not disclose personal data to third parties except when:
- a) Is necessary for the purpose for which they were collected; such as in the provision of services through third parties and suppliers
- b) The data subject is informed before disclosure or at the time of collection of the personal data.
- c) The owner of the personal data gives his prior and express consent.
- d) Consent is not required by law.
- e) Personal data are required by public entities within the scope of their legal powers and duties.
- f) Personal data is necessary to satisfy legitimate requirements of a company interested in acquiring any of PADDYS TRAVEL’s operations, with the prior consent of the data subject; or,
- g) Access to personal data is by auditors, lawyers, and other professionals bound by professional secrecy.
- DELETION OF PERSONAL DATA
- Once the processing of personal data has been completed and the purpose limitation principle has been met, and provided there is no legal mandate or reason justifying the retention of the personal data, PADDYS TRAVEL will proceed to delete it from its records. Alternatively, PADDYS TRAVEL may apply de-identification processes, or equivalent methods, when for any commercial, statistical, or market analysis reason it justifies the convenience of retaining such data. PADDYS TRAVEL will define in due course the respective procedures necessary for the deletion of personal data.
- LIST OF SANCTIONS
- Any employee who violates this Policy will be considered to have committed a serious offense and will be subject to disciplinary action. PADDYS TRAVEL will take the disciplinary measures it deems appropriate in cases of employee non-compliance with the obligations stipulated herein.
- POLICY DISSEMINATION AND COMPLIANCE
PADDYS TRAVEL will strive to:
- i) Comply with the provisions of this Policy;
- ii) To make this Policy known, observe and respect it for every employee;
- iii) Publish this Policy in easily accessible locations; and
- iv) Subscribe to confidentiality obligations with employees, users, contractors and third parties who access the personal data included in the databases.