Legal Document

Privacy Policy

Learn how we securely handle, encrypt, and respect corporate and traveler data across our distributed travel tech systems.

Last updated: September 15, 2026

1. Introduction

Techeffic ("we", "us", "our") values the integrity and privacy of your corporate structures and traveler profile databases. This Privacy Policy details our stringent programmatic methods for collecting, transmitting, and securely safeguarding metadata and personal information across our enterprise travel technology platforms.

By accessing or using any Techeffic product-including our Travel System, Omni Channel Suite, Accounting System, or HR System-you acknowledge and agree to the terms set forth in this policy. We encourage you to read this document carefully.

2. Information We Collect

We collect information to resolve high-concurrency booking paths, execute dynamic packaging routines, and secure multi-currency ledgers. The types of data we process fall into two primary categories.

2a. Information You Provide

This includes any data you actively submit through our platform interfaces, API integrations, or customer onboarding flows:

  • Corporate account credentials, traveler profiles, and administrator identities.

  • Payment and billing details including card tokenization records and bank references.

  • Travel preferences, frequent flyer numbers, passport and visa information.

  • Support tickets, feedback forms, and direct communications with our team.

2b. Information Collected Automatically

When you interact with our systems, we automatically collect technical and behavioral data to maintain platform integrity:

  • IP addresses, device identifiers, and browser/agent metadata.

  • Session logs, API call timestamps, and feature usage telemetry.

  • GDS transaction identifiers, PNR references, and booking lifecycle events.

  • Performance metrics and error reports to support system diagnostics.

3. How We Use Your Information

Under strict programmatic security protocols, collected traveler profiles and XML data structures are utilized exclusively for the following purposes:

  • Real-time GDS booking and PNR synchronization across Amadeus, Sabre, and Travelport.

  • Automated settlement with consolidators, accounting layers, and financial reconciliation.

  • Continuous, programmatic fraud detection, risk scoring, and chargeback prevention.

  • Delivering personalized travel recommendations and corporate policy enforcement rules.

  • Complying with regulatory requirements including IATA obligations and local tax reporting.

  • Improving platform performance, reliability, and feature development roadmaps.

4. Legal Basis for Processing

We process personal information under the following legal grounds as defined by GDPR and regional MENA electronic commerce provisions:

  • Contract Performance — processing required to fulfill your booking or service agreement.

  • Legitimate Interests — fraud prevention, platform security, and business analytics.

  • Legal Obligation — compliance with applicable tax, finance, and travel regulations.

  • Consent — marketing communications and optional tracking features where elected.

5. Cookies and Tracking Technologies

Our system utilizes secure session tokens and cookies to maintain agent markups, multi-step state selections, and active booking carts without data leakage. We deploy the following cookie categories:

  • Strictly Necessary — authentication, fraud signals, session continuity.

  • Functional — remembering language, currency, and booking preferences.

  • Analytics — aggregated, anonymized usage data for platform improvement.

  • Marketing — optional; used only with explicit consent for targeted communications.

Cookie Preferences

You can manage your cookie preferences below. Strictly necessary cookies cannot be disabled as they are required for the platform to function.

Analytics Cookies

Aggregated usage data to improve our platform

Marketing Cookies

Used for personalized communications

6. How We Share Information

Traveler inputs are exclusively dispatched to specified GDS channels and selected airline/hotel consolidators strictly to fulfill booking contracts. We do not sell personal data to third parties.

6a. Third-Party Services

We engage carefully vetted third-party processors under strict data processing agreements (DPAs):

  • GDS Providers (Amadeus, Sabre, Travelport) for flight and hotel booking resolution.

  • Payment gateways and card networks for transaction settlement and fraud control.

  • Cloud infrastructure vendors (AWS, Azure) under ISO 27001 certification agreements.

  • Analytics and monitoring tools used solely for operational performance measurement.

6b. International Data Transfers

As a distributed travel technology platform serving MENA, Europe, and global markets, certain data may be processed in jurisdictions outside your country of residence. All cross-border transfers are governed by Standard Contractual Clauses (SCCs) or equivalent legal mechanisms to ensure adequate protection in line with GDPR Article 46.

7. Data Retention

We retain personal data for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required by law or regulatory obligation. Key retention windows include:

  • Active Account Data — retained for the duration of your active subscription plus 12 months.

  • Booking & Transaction Records — up to 7 years for financial audit and tax compliance purposes.

  • Support Communications — retained for 3 years to support dispute resolution.

  • Analytics & Logs — aggregated data anonymized after 24 months; raw logs deleted after 90 days.

8. Data Security

All databases are stored in certified cloud infrastructure, utilizing AES-256 encryption at rest and secure transport layers (TLS 1.3) during transmission. Our security architecture includes:

  • Role-based access control (RBAC) with principle of least privilege across all system layers.

  • Multi-factor authentication (MFA) enforced for all administrator and corporate accounts.

  • Continuous vulnerability scanning, penetration testing, and security patch cadence.

  • SOC 2 Type II audit compliance with annual third-party security assessments.

Despite our rigorous security measures, no internet-based system can guarantee absolute security. We encourage you to use strong, unique passwords and report any suspected unauthorized access to security@techeffic.com immediately.

9. Your Privacy Rights

Subject to regional regulatory requirements, you hold sovereign rights over your archived customer data records. These rights include:

  • Right of Access — request a copy of the personal data we hold about you.

  • Right to Rectification — request correction of inaccurate or incomplete data.

  • Right to Erasure — request deletion of data where no overriding legal basis exists.

  • Right to Restrict Processing — limit how we use your data during a dispute or review.

  • Right to Data Portability — receive your data in a structured, machine-readable format.

  • Right to Object — object to processing based on legitimate interests or direct marketing.

To exercise any of these rights, please submit a verifiable request to privacy@techeffic.com. We will respond within 30 days in accordance with applicable regulations.

10. Marketing Communications

We may send you product updates, platform announcements, and travel technology insights where you have provided consent or where a legitimate interest exists under applicable law.

  • You may opt out of marketing emails at any time using the unsubscribe link in any communication.

  • Transactional and service-related communications (e.g. booking confirmations) are not marketing and will continue regardless of marketing preferences.

  • You may update your communication preferences at any time via your account settings or by contacting privacy@techeffic.com.

11. Children's Privacy

Techeffic products and services are designed exclusively for corporate enterprise use and are not directed at individuals under the age of 16. We do not knowingly collect personal information from minors. If we become aware that data from a person under 16 has been processed without appropriate consent, we will promptly delete such information. If you believe a minor's data has been submitted to our systems, please contact privacy@techeffic.com immediately.

12. Changes to This Privacy Policy

We reserve the right to update this Privacy Policy periodically to reflect changes in our data practices, legal obligations, or platform capabilities. When material changes occur, we will:

  • Update the "Last Updated" date at the top of this document.

  • Notify active account administrators via email at least 14 days before changes take effect.

  • Display a prominent notice within the platform dashboard for 30 days following any update.

Continued use of Techeffic services following notice of changes constitutes acceptance of the revised policy. We encourage you to review this page periodically.

13. Contact Us

To exercise your personal data access privileges, raise a privacy concern, or interface directly with our Data Protection Officer, please reach us through the following channels:

Privacy Officer

privacy@techeffic.com

For data access requests and GDPR inquiries

General Support

support@techeffic.com

For platform issues and account-related queries

Techeffic Technologies

5th District, New Administrative Capital, Cairo, Egypt

Registered under Egyptian Companies Law No. 159 of 1981

End of Privacy Policy — September 15, 2026