Privacy
Privacy notice
Notice version 2026-08 — this version identifier is recorded with every consent we capture.
This notice describes what we do with your personal data. The retention periods below are the ones our deletion jobs enforce; the erasure window is the one our backups actually follow.
Who controls your data
The data controller is Worldmaster International Travel, Philippines.
Our Data Protection Officer (DPO) is DPO Placeholder, reachable at dpo@example.test.
You can file any data-subject request — access, erasure, correction, objection, or withdrawal of consent — by writing to dsr@example.test. We answer every request within 30 days.
What we collect and how long we keep it
We collect only what a travel booking needs.
Each class below is deleted automatically once its retention period elapses, unless a legal hold (for example a dispute or a regulatory requirement) requires us to keep specific records longer.
- Passport scans — kept for 365 days after upload.
- Government ID images — kept for 365 days after upload.
- Payment proof images — kept for 180 days after upload.
- Inquiry and contact details (name, email, phone, message) — kept for 730 days. Contact-form messages and inquiries that never became bookings are deleted automatically on that schedule; once an inquiry becomes a booking — quoted, taking payments, or holding documents — it is kept as a business record until you ask us to erase it.
- Account email and password — kept until you ask us to erase them.
- Consent records and the tamper-evident audit trail — retained as our accountability evidence under the Philippine Data Privacy Act (RA 10173), even after erasure of your other data. They record that processing happened, never document contents.
Who processes data for us
Exactly two processors handle your data on our behalf, and this list is closed:
netcup GmbH — hosting of the application and database, on servers located in Germany, and delivery of our email.
Cloudflare, Inc. — content delivery, DNS, and bot mitigation. Cloudflare sees request metadata (such as your IP address) as traffic passes its network, and is contractually bound as a processor.
We do not use any other email provider, analytics provider, or advertising network. Your data is not sold, rented, or used for profiling.
Encryption at rest — and what it does not protect against
Documents you upload (passports, IDs, payment proofs) are encrypted at rest with AES-256-GCM before they touch the disk, and the database stores no key material alongside them.
This encryption is designed against specific threats: a physically stolen server disk or backup archive, and a leak of stored files alone. In those scenarios an attacker obtains ciphertext without its key.
It does NOT protect against the compromise of a full application account with legitimate access to decrypted data, a compromised member of our staff, or an attacker who controls the running application.
Those risks are addressed instead by role-based access control, the audit trail, least-privilege roles, and two-factor sign-in for staff accounts where it has been enabled for that account.
Erasure — immediate in live systems, bounded in backups
Erasure takes effect in our live systems immediately, and in our backups within 30 days of your request being carried out.
Backups older than that window are destroyed as part of the regular rotation, so a copy of erased data cannot outlive it. Live systems and backups follow different clocks, and this page states both honestly.
If a legal hold applies to specific records (an ongoing dispute, or a legal obligation to preserve), we will tell you which records we must keep and why, and erase everything else.
Your rights
Under RA 10173 you have the following rights, free of charge. Write to dsr@example.test to exercise any of them.
Each request is tracked with its statutory deadline, and every action we take on it is recorded in the audit trail described above.
- Access the data we hold about you — we hand you a complete export.
- Ask us to correct it.
- Object to specific processing.
- Withdraw a consent you previously gave.
- Ask us to erase it.