1. Introduction
At TRIPMAX LTD ("we", "our", or "us"), we are committed to upholding the highest standards of data security, privacy, and confidentiality. This Privacy Policy details how we collect, process, and safeguard your personal information in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Information We Collect
To provide tailored visa advice and compile consulate-compliant application files, we may collect:
- Identity Data: Full legal name, date of birth, nationality, passport details, and UK BRP / visa status;
- Contact Data: Telephone number, WhatsApp number, physical address, and email address;
- Financial Data: Bank statements, employment confirmation letters, and payslips (solely for verifying subsistence proof as demanded by consulates);
- Travel Itinerary Data: Flight dates, hotel reservations, and travel purpose details;
- Technical Data: IP address, browser type, and interaction records on our website.
3. How We Use Your Data
Your data is used strictly for legitimate contractual and legal purposes, including:
- Assessing your Schengen visa eligibility and scheduling appointments with VFS Global, TLScontact, or consulates;
- Drafting personalized consulate cover letters, flight itineraries, and hotel booking vouchers;
- Issuing certified Schengen travel medical insurance certificates;
- Communicating case updates, appointment confirmations, and instructions via WhatsApp or email.
4. Stripe Payment Processing Security
All payment transactions are processed securely through Stripe Payments Europe Ltd.
- Stripe is certified to PCI-DSS Level 1 (the highest standard in payment security).
- TRIPMAX LTD does not store, process, or view your full debit/credit card numbers or CVV codes on our servers.
- Transactions are tokenized and encrypted with 256-bit SSL technology.
5. Web3Forms Form Submissions
Inquiries submitted through our website contact forms are processed securely via Web3Forms. Information is transmitted encrypted over HTTPS and forwarded directly to our encrypted business email inboxes. We do not sell or lease your personal information to any third-party marketing brokers.
6. Data Retention & Security
We retain documentation files only for the period necessary to complete your application filing, fulfill statutory accounting requirements, or manage appeals. Once your travel is completed, sensitive financial records and passport scans are securely deleted from our active operational systems.
7. Your UK GDPR Rights
Under UK data protection laws, you possess the right to:
- Access: Request copies of the personal data we hold about you;
- Rectification: Request correction of inaccurate or incomplete information;
- Erasure: Request the deletion of your personal records ("Right to be Forgotten");
- Object / Restrict: Restrict processing of your data under specific conditions.
To exercise any of these rights, please contact our Data Protection Officer at info@tripmax.co.uk.
8. Regulatory Authority
You have the right to lodge a complaint with the UK's independent data authority, the Information Commissioner's Office (ICO) (ico.org.uk), if you believe your data has been handled improperly.