2. PII WE COLLECT
While providing travel services, Ovation collects PII that is necessary to complete a reservation with an airline carrier, hotel, car rental agency, or other supplier named on a traveler’s itinerary (a “Travel Supplier”). Upon a Client’s request, Ovation may also collect employment-related PII such as an employee identification number, department or department number. The specific elements of PII that Ovation may process in connection with providing travel services include, but are not limited to:
- Passenger First Name;
- Passenger Last Name;
- Passenger Middle Initial;
- Passenger Salutation;
- Date of Birth;
- Employee Identification Number/Employee ID;
- Ticket/Document Number;
- Original Issue Ticket/Document Number;
- Passport Number;
- TSA Known Redress Number;
- Airline Frequent Flyer Number;
- Credit Card Information; and
- Passenger Name Record (PNR) Reference
On the Website, we may collect the following information from you that may constitute PII:
- Job title;
- Company name;
- Phone number;
- Email address; and
- Information included in your job application including, but not limited to, information included in your resume.
The software used on the Website automatically collects the following information that may constitute PII:
- Website use event data such as which links or buttons you have clicked and the pages you have viewed;
- The type of device you are using to access the Website;
- The IP address from which you access the Website; and
- The name and version of the device operating system.
The logging technology used on the Website automatically collects the URL of the site from which you came and the site to which you are going when you leave the Website.
We may place a "cookie" on the hard drive of the device that you use to access the Website. Cookies are text files that are saved on the hard drive of your device by means of your browser, enabling us to recognize your browser for purposes such as saving your preferences and directing relevant content to you. Most of the currently available browsers give you the option of managing cookies by, for example, disabling them entirely, accepting them individually, and deleting saved cookies from your hard drive. We would like to remind you that if you completely disable cookies on your browser, you might not be able to use some features of the Website.
Google Analytics is an element of the Website. By using cookies, Google Analytics collects and stores data such as time of visit, pages visited, time spent on each page of the website, the IP address, and the type of operating system used in the devices used to access the Website. By using a browser plugin provided by Google, you can opt out of Google Analytics. We also use other services that analyze, track, and distribute information collected on the Website for analysis and marketing purposes.
Finally, we may periodically conduct surveys. Participation in any Ovation survey is completely voluntary. Ovation takes the information received from individuals responding to surveys and combines (or aggregates) it with the responses of other Clients to create broader, generic responses to the survey questions (such as gender, age, residence, hobbies, education, employment, industry sector, or other demographic information).
We generally process PII on the basis of (i) consent; (ii) a contract, such as a travel management agreement; (iii) a legal obligation imposed on us; or (iv) our legitimate interest to process PII. Such legitimate interests include our ability to provide our travel products and services to our clients and travelers that use our services.
3. THE PURPOSES FOR WHICH WE USE PII
We use the PII for the following purposes:
- To provide, operate, develop, and improve our travel products and services;
- To improve Client and traveler customer service;
- To communicate with you;
- To operate, develop, improve, and protect the Website;
- To market research and electronic direct marketing, in accordance with applicable law;
- To audit and analyze the Website;
- For recruiting purposes;
- To ensure the technical functionality and security of the Website.
- To prevent and investigate fraud and other misuses;
- To comply with laws, regulations, or legal requests for the PII;
- To protect Ovation, its employees, affiliates and other clients;
- To protect our rights and/or our property;
- To personalize user experience; and
- To ensure the technical functionality and security of the Website.
4. HOW WE DISCLOSE PII
We may disclose the PII we collect to the following categories of third parties:
- The global distribution systems (“GDS”), a software-based service for making travel reservations;
- Service providers such as Travel Suppliers or other third party services providers necessary to the operation of our business, Our clients that request the data relating to travel services utilized by their employees;
- Subcontractors such as travel support service providers;
- Industry reporting authorities and other entities necessary in providing travel services;
- To public authorities, such as law enforcement, if we are legally required to do so or if we need to protect our rights or the rights of third parties.
Moreover, we may disclose information to third parties in an aggregate format that does not constitute PII and does not allow for the direct identification of individual users of the Website or individual travelers.
5. YOUR RIGHTS
You have the following rights with respect to the PII we hold about you:
The right to access PII we hold about you: if you would like to access PII we hold about you, please contact your employer (i.e. our client) or submit a request to email@example.com. Ovation will respond to inquiries directed to firstname.lastname@example.org within forty-five (45) calendar days.
The right to have incomplete, incorrect, outdated, or unnecessary PII corrected, deleted, or updated. If you have questions regarding the correction, deletion, or updating of the PII we hold about you, please contact your employer (i.e. our client) or contact us at email@example.com.
The right to opt out of receiving electronic direct marketing communications from us: All electronic direct marketing communications that you may receive from us, such as e-mail messages and SMS-messages, gives you an option of not receiving such communications from us in the future. If you have any additional questions about electronic direct marketing received from us, please contact us at firstname.lastname@example.org.
If you wish to limit the use or disclosure of PII about you to a third party, including requests to “opt out,” you must contact your employer (i.e., Ovation’s client) or submit a request to email@example.com.
6. DATA RETENTION
Records of new reservations and past reservations (collectively “Reservations”) are kept for six (6) years from the date of booking. If you are no longer employed by a Client, with the exception of Reservations, we will delete PII included in your personal profile immediately following the termination of your employment, provided that such termination has been communicated by the Client to us. If your employer discontinues the use of our travel services, with the exception of Reservations, we shall remove all profile information associated with your employer as soon as reasonably practicable upon discontinuing providing travel services to your employer.
Ovation maintains a data security program to protect PII, which includes commercially reasonable administrative, technical and physical safeguards designed to (i) protect the security and confidentiality of such PII; (ii) identify, assess and protect against any reasonably foreseeable internal and external threats, risks or hazards to the security or integrity of such PII; and (iii) protect against unauthorized access to or use of such PII.
Ovation currently utilizes the Secure Sockets Layers (SSL) protocol and firewalls to safeguard PII. In addition, access to PII is restricted to employees who have a “need to know,” and those employees must use passwords to access the PII. For a more detailed description, please see Ovation’s Security Policy (available to Ovation’s Clients upon request). Although Ovation makes every effort to ensure the protection, integrity and security of Ovation’s network and systems, Ovation cannot guarantee or warrant that the security measures will protect PII that we process.
8. PRIVACY SHIELD
9. PII ABOUT CHILDREN
10. YOUR CALIFORNIA PRIVACY RIGHTS
California Civil Code Section 1798.83 permits users that are residents of California to request certain information regarding Ovation’s disclosures of PII to third parties for such third parties’ direct marketing purposes. If you are a California resident and would like to make such a request, please email us at firstname.lastname@example.org.
The California Online Privacy Protection Act (“CalOPPA”) requires Ovation to disclose how it responds to Do Not Track Signals in your web browser. Ovation does not interpret or respond to Do Not Track Signals. You may set your web browser to not accept new cookies or web beacons or disable cookies altogether. Please note that doing so may hinder your experience on the Website. Please see the Help section of your browser for instructions on managing security preferences.
Effective date: December 13, 2017