Beyond Raw Data / TourIQ
Data Protection and Privacy Policy
Public privacy policy for customers, tour operators, staff users, and other data subjects.
1. Who we are
Beyond Raw Data operates TourIQ, a tour operations platform for bookings, payments, customer records, staff workflows, reporting, receipts, and related tourism business tools. In this policy, "we", "us", and "our" refer to Beyond Raw Data and TourIQ.
This policy is drafted for compliance with the Constitution of Kenya, the Data Protection Act, 2019, and the Data Protection (General) Regulations, 2021. It should be reviewed by Kenyan counsel before publication.
2. Roles
- Tour operators and organizations
- Where an operator uses TourIQ to manage its own customers, staff, bookings, and payments, that operator is normally the data controller for its business records.
- Beyond Raw Data
- Beyond Raw Data may act as an independent controller for its own account administration, security, billing, support, and legal compliance records, and as a processor where it processes operator data on behalf of an operator.
- Data subjects
- Data subjects include customers, passengers, staff users, admins, vendors, guides, drivers, and other identifiable persons whose personal data is processed in TourIQ.
3. Personal data we process
- Identity and contact data: names, email addresses, phone numbers, nationality, ID or passport details where collected by an operator.
- Booking and travel data: package, itinerary, dates, participants, passenger counts, preferences, notes, and booking status.
- Payment data: amount, currency, method, provider reference, payment status, receipt data, reconciliation notes, and refund or chargeback records.
- Account and staff data: user profile, organization, role, permissions, authentication identifiers, audit logs, and support records.
- Operational data: vehicles, guides, drivers, vendors, expenses, invoices, taxes, quotations, diary entries, and reports.
- Technical data: IP address, device/browser information, timestamps, logs, error reports, cookies, and security events.
- Sensitive data only where necessary: health, accessibility, family details, passport/ID data, biometric or child-related information if an operator chooses to record it for a lawful travel or safety purpose.
4. Why we process personal data
- To create and manage user accounts and organization access.
- To manage bookings, participants, packages, payments, receipts, invoices, expenses, and reports.
- To support operators in customer service, trip administration, reconciliation, and business reporting.
- To secure the platform, prevent fraud, troubleshoot errors, and maintain audit trails.
- To comply with law, tax, accounting, regulatory, court, and law enforcement obligations.
- To send service communications and, only where lawful, marketing communications.
5. Lawful bases
We process personal data where at least one lawful basis applies, including consent, contract performance, legal obligation, vital interests, public interest or official authority where applicable, and legitimate interests that are not overridden by the rights and freedoms of the data subject.
6. Sharing and processors
We may share data with authorized operator users, payment providers, hosting and database providers, messaging providers, email providers, analytics and monitoring providers, professional advisers, regulators, courts, and law enforcement where legally required. We require processors to use appropriate confidentiality, security, and data protection safeguards.
7. Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, unless longer retention is required or permitted by law, contract, accounting, tax, fraud prevention, dispute resolution, or regulatory obligations. When data is no longer required, it will be deleted, anonymised, pseudonymised, or securely restricted according to the retention schedule.
8. Data subject rights
Subject to legal limits, data subjects may request access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and information about processing. Requests should be sent to the contact listed in this policy and must include enough information to verify identity and locate the relevant record.
Access requests should be handled within 7 days where the Kenyan General Regulations apply. Erasure and rectification requests should be handled within 14 days where the Regulations apply, unless a lawful exception or legal hold applies.
9. Security
We use administrative, technical, and organizational safeguards including role-based access, authentication, least-privilege permissions, audit logs where available, encryption in transit, backups, vendor controls, and incident response procedures. No system is perfectly secure, but we work to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and unauthorized access.
10. Breaches
Where a personal data breach creates a real risk of harm, we will assess notification obligations to the Office of the Data Protection Commissioner, affected controllers, affected data subjects, and relevant parties within the applicable statutory timelines.
11. International transfers
TourIQ may use cloud providers or processors outside Kenya. Where personal data is transferred outside Kenya, we will assess and document appropriate safeguards and transfer conditions required by Kenyan data protection law.
12. Contact
Data protection contact: [insert Beyond Raw Data privacy email]
Physical address: [insert registered office address]
Company registration number: [insert registration number]
Online submission
Ask a privacy or data protection question
Request ID: TIQ-PQX-20260718-9BE1C0. Complete this online, download a copy for your records, then submit it to Beyond Raw Data.