NAC Travel Privacy Policy and Personal Information Notice
Version: 2026.07.13 Effective date: 13 July 2026
This Privacy Policy explains how NAC Travel International Pty Ltd (“NAC Travel”, “NAC Holidays”, “we”, “us” or “our”) collects, uses, stores, shares and protects personal information when you use nac-travel.org, holiday.nac-travel.org, related portals, mobile services, agent services or direct support channels. It is intended to provide the notification contemplated by the Protection of Personal Information Act 4 of 2013 (“POPIA”) and to support transparent processing under other applicable privacy laws.
1. Responsible party and contact
NAC Travel International Pty Ltd is the responsible party for personal information processed for its travel, immigration, education, customer-support, fraud-prevention and business-administration purposes. Our office is at AMR Office Park, 3 Concorde East Road, Bedfordview, Johannesburg, South Africa, 2008. You may contact us through the website support facilities, by telephone at +27 12 023 0485, by WhatsApp at +27 69 156 3755, or by written delivery to the office. Privacy and access requests should be marked for the Information Officer.
2. Application and legal framework
Our processing is primarily governed by POPIA, including its conditions for lawful processing, data-subject rights, security safeguards, direct-marketing requirements, rules for children, automated decision-making and transfers outside South Africa. Electronic acceptance and records are also handled with regard to the Electronic Communications and Transactions Act 25 of 2002. Consumer and sector-specific requirements may apply to particular services. Where we offer services to persons protected by another privacy law, such as the EU General Data Protection Regulation, we apply the relevant additional requirements to the extent that law applies.
3. Information we collect
Depending on the service, we may collect:
- identity information, including full name, title, date of birth, nationality, gender where required by a supplier, passport or identity-document details;
- contact information, including email, telephone, WhatsApp number, residential or postal address and emergency contacts;
- travel information, including origin, destination, dates, passenger categories, cabin, accommodation preferences, loyalty details, special-service requests and itinerary history;
- booking and transaction information, including selected services, customer-facing totals, invoices, payment status, gateway references, refunds and chargeback records;
- visa, immigration, education, employment or supporting documents where you purchase those services;
- health, accessibility, dietary, religious or other special information where needed to arrange a requested service and lawfully permitted;
- information about children where a parent, guardian or competent person books for them;
- agent, partner or corporate information, including membership, client authority, commissions, contracts and audit records;
- technical and security information, including IP address, session identifiers, device and browser information, reCAPTCHA results, login records, search signatures, fraud indicators and audit logs;
- communications, including emails, calls, messages, support requests, recordings where lawfully made, acceptance evidence and complaint records;
- marketing preferences, consent, objections, unsubscribe history and campaign interaction information.
4. How information is collected
We collect information directly from you when you complete a form, create an account, conduct a qualified search, communicate with us, upload a document, make a payment or accept terms. We may also receive information from an authorised family member, employer, agent, school, partner, airline, hotel, payment provider, identity-verification service, government authority, publicly available source or another supplier involved in your request.
5. Purposes of processing
We process personal information to:
- identify and communicate with you;
- qualify searches and prevent automated or abusive use;
- retrieve, compare, store and present relevant flight, hotel and package options;
- assign one relevant NAC consultant profile to your booking;
- save progress, provide secure resume links and send incomplete-booking reminders;
- confirm availability, prepare quotations, create invoices and process payments;
- arrange ticketing, accommodation, insurance, transfers, visa or other requested services;
- share necessary information with the selected supplier and verify fulfilment;
- provide account, agent, customer-support, complaint and refund services;
- meet tax, accounting, anti-fraud, sanctions, legal, regulatory and recordkeeping obligations;
- protect the platform, customers, suppliers and NAC Travel;
- analyse service performance using aggregated or appropriately de-identified information;
- send optional marketing where permitted and consented to.
6. Lawful justification
Depending on the circumstances, processing is justified because it is necessary to conclude or perform a contract with you; required by law; protects a legitimate interest of you, NAC Travel or a third party; is necessary for proper performance of a public-law duty by an authority; or is based on voluntary, specific and informed consent. We do not rely on marketing consent for operational booking communications. You may withdraw consent where processing is based on consent, but withdrawal does not invalidate prior lawful processing or prevent processing required for an existing contract or law.
7. Mandatory and optional information
Fields needed to identify travellers, secure the search, create a booking, meet supplier rules or process payment are mandatory. If you do not provide them, we may be unable to retrieve current options or complete the service. Marketing consent is optional and is not a condition of booking. Special personal information is requested only where relevant and should not be submitted unnecessarily.
8. Search, provider and internal commercial information
We may use paid information services, supplier systems and internal databases to prepare travel options. Provider identity, provider URL, procurement timestamps, supplier amounts, NAC Travel margins and agent commissions are confidential internal operational information. They are retained for audit, security, accounting and service management but are not displayed to customers. Customer-facing pages show the airline or service actually proposed and the final NAC customer total.
9. Automated tools and human oversight
We use automated tools to validate form completeness, detect duplicates, apply rate limits, calculate currency equivalents, assign a consultant profile, prioritise follow-up and support the preparation of options. These tools assist operations; they do not remove human oversight for sensitive matters, disputed price changes, ticketing approval, complaints, visa decisions or other material exceptions. You may request meaningful human review where an applicable law provides that right.
10. reCAPTCHA, fraud prevention and security logs
reCAPTCHA or a similar service may process device, interaction and network information to distinguish legitimate users from automated traffic. We also use session binding, CSRF protection, idempotency keys, signed links, hashing, rate limits and audit logs. Security information may be retained for a reasonable period to investigate fraud, abuse, cyber incidents or disputes.
11. Sharing with recipients
We share only information reasonably necessary for the relevant purpose with:
- airlines, hotels, accommodation providers, tour operators, transfer companies, insurers and other selected suppliers;
- payment gateways, banks, card networks and fraud-prevention providers;
- authorised agents, partners, schools, immigration professionals or consultants involved in your service;
- hosting, email, messaging, document, analytics, security and technical operators under appropriate duties;
- government, border, immigration, tax, law-enforcement, court or regulatory bodies where required or lawfully justified;
- professional advisers, auditors and insurers subject to confidentiality;
- a purchaser or successor in a lawful business restructuring, subject to appropriate safeguards.
We do not sell personal information to advertisers. Suppliers and payment providers may process information under their own privacy notices where they determine their own purposes.
12. Cross-border transfers
International travel necessarily involves recipients outside South Africa. We may transfer information to an airline, hotel, authority, partner or technical operator in another country where the recipient is subject to a law, binding agreement, corporate rules, consent or another safeguard recognised by applicable law, or where the transfer is necessary for the contract or your benefit. Privacy protections in the destination country may differ from South African law.
13. Children
We process a child’s information only through a parent, guardian or other competent person, where necessary for travel or another lawful purpose, or where another legal authorisation applies. The adult must ensure the information is accurate and must not permit a child to submit booking information unsupervised. We limit access to children’s information and do not use it for independent behavioural marketing.
14. Special personal information
Health, disability, dietary, religious, biometric, criminal or other sensitive information is processed only where necessary, authorised by law or consented to as required. It may be shared with a supplier solely to provide the requested assistance, such as wheelchair support, medical clearance or a dietary request. Please provide the minimum information necessary.
15. Payment information
NAC Travel generally relies on approved payment gateways or banks to process card or account information. We may receive transaction references, status, payer name, amount, fraud indicators and limited payment metadata. We do not intentionally store full card security codes. Never send card security details through ordinary email or messaging unless an approved secure process expressly requests them.
16. Consultant avatars and communications
A booking is assigned one customer-facing NAC consultant profile, selected according to route or service needs. The same profile may appear in results, reminders, payment updates and ticketing communications. Internal teams and automated workflows may support that consultant, but customer communications will not display multiple competing consultant avatars for the same booking unless a formal handover is necessary and explained.
17. Service reminders
If a booking is incomplete, we may send operational reminders with the chosen itinerary, travel dates, passenger count, last recorded customer total, current stage and a secure resume link. These messages are necessary to provide the requested service and are not optional advertising. We limit reminder frequency and stop reminders when the booking is completed, cancelled, expired or objected to where appropriate.
18. Direct marketing
Optional promotional email, SMS, WhatsApp or similar marketing is sent only where permitted by POPIA and other applicable rules. Marketing consent is separate from booking acceptance. Every electronic marketing communication will provide an appropriate way to opt out. We maintain suppression records to respect objections and withdrawals.
19. Cookies and similar technologies
We use essential cookies for sessions, security, preferences, authentication and booking progress. We may use measurement or marketing technologies where permitted and configured. Browser controls may block cookies, but essential booking functions may then fail. Local storage may retain a display-currency preference without storing payment-card information.
20. Information quality
We take reasonable steps to keep information accurate, complete and updated, but we rely on you and authorised suppliers. You should correct account and traveller details promptly and verify all itinerary documents. We may ask for supporting evidence before changing identity, payment or ticketing records.
21. Retention
We retain information only for as long as reasonably necessary for the purpose, contract, legal duty, dispute, accounting, fraud prevention or evidential need. Search and security logs may be kept for shorter operational periods; bookings, invoices, payment and tax records may be retained for legally required periods; unresolved complaints, chargebacks or litigation records may be retained until final resolution. When retention is no longer justified, information is securely deleted, destroyed, anonymised or de-identified, subject to backup cycles and legal holds.
22. Security safeguards
Measures may include access controls, least-privilege permissions, encryption in transit, password hashing, secure cookies, CSRF protection, reCAPTCHA, rate limiting, signed resume links, audit logs, backup controls, provider confidentiality, vulnerability management and staff or agent obligations. No system is perfectly secure. You must protect passwords and links, use a secure device and notify us promptly of suspicious activity.
23. Security incidents
If personal information is reasonably believed to have been accessed or acquired by an unauthorised person, we will investigate and take containment and remedial measures. Where POPIA or another applicable law requires notification, we will notify the Information Regulator and affected data subjects as soon as reasonably possible, subject to lawful delay or security restrictions.
24. Your rights
Subject to applicable law, you may request confirmation of whether we hold personal information about you; request access; ask for correction or deletion of inaccurate, excessive, outdated, unlawfully obtained or no-longer-authorised information; object to certain processing; withdraw consent; object to direct marketing; request restriction; and complain to the Information Regulator or another competent authority. We may require proof of identity and may refuse or limit a request where law permits, including to protect another person, privileged information, fraud investigations or legal obligations.
25. Access and correction process
Submit a request through the website support channel or deliver it to the Information Officer at the office address. State your full name, contact details, relevant booking or account reference, the right being exercised and sufficient detail to locate the information. We will respond within the period required by applicable law or explain any permitted extension, fee or refusal.
26. Complaints
Please first contact NAC Travel so that we can investigate. You may also complain to the Information Regulator of South Africa using the Regulator’s current official complaint channels. Nothing in this Policy removes any right to approach a court or another competent authority.
27. Agent and partner responsibilities
Agents and partners must collect client information lawfully, obtain authority, use it only for the instructed service, protect it, avoid unauthorised exports or disclosure and comply with NAC Travel’s agreements. Paid membership does not permit an agent to search for fictitious clients, expose confidential supplier information or reuse client data for unrelated marketing.
28. External links
Our platform may link to an airline, payment gateway, insurer or other external site. That organisation’s privacy notice applies to its independent processing. A link does not authorise the external organisation to access your NAC Travel account or conversation.
29. Changes and version control
We may update this Policy to reflect legal, supplier, technology or business changes. The current version and effective date will be published. Material changes affecting an active booking may be communicated or presented for fresh acknowledgement. Acceptance records store the version and content hash shown at the time.
30. Acknowledgement
By acknowledging this Policy, you confirm that you understand the described processing, including necessary sharing with travel suppliers and cross-border recipients, security verification, secure booking reminders and retention of acceptance evidence. Marketing remains optional and is controlled separately.