Booking a premium cabin means handing over a passport number and a card. This is exactly what we do with both — what we collect, who receives it, how long we keep it, and how to get it back or have it deleted.
Buybusinessclass Travel, Inc. ("buybusinessclass", "we") is a travel agency incorporated in Delaware with its principal office at 180 North Stetson Avenue, Chicago, IL, 60601, United States. When you search, book or manage a trip with us, we decide why and how your personal data is processed — we are the data controller for that activity.
Our Data Protection Officer can be reached at info@buybusinessclass.com. For travellers in the European Union and the United Kingdom, our representative under Article 27 GDPR is named in the same mailbox's auto-reply.
Air travel is unusually data-hungry: a carrier cannot issue a ticket without a full legal name, and a border agency will not accept a passenger without document details. We collect what is needed to book you and no more.
Some service requests reveal information that data-protection law treats as sensitive. A wheelchair request implies a mobility condition; a kosher or halal meal may imply a religious belief. We only ask for these when you choose to request the service.
Where the request concerns health or accessibility we rely on your explicit consent, which you can withdraw at any time by contacting the concierge — though withdrawing it means the carrier can no longer guarantee the assistance. Meal preferences are passed to the airline as a service code only.
We do not use automated decision-making that produces legal effects for you. Fraud screening may flag a transaction for manual review, but a person makes the final call on any booking we decline.
International travel means international data flows. If you fly from London to Doha, your details will be processed in the United Kingdom, Qatar and the United States, and possibly in any country you transit.
Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on an adequacy decision where one exists, and otherwise on the European Commission's Standard Contractual Clauses together with a transfer risk assessment. Transfers required to perform your travel contract are additionally covered by Article 49(1)(b) GDPR. Copies of the safeguards we use are available on request.
No system is perfect. If a breach is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours and tell you directly without undue delay.
Depending on where you live, you can exercise some or all of the following. We do not charge for these requests and we do not treat you differently for making one.
California residents may additionally request disclosure of the categories of personal information collected and shared, and may opt out of "sharing" as that term is defined by the CCPA. We do not sell personal information and have not done so in the preceding twelve months.
Our service is not directed at children, and we do not knowingly create accounts for anyone under 16. We do process the details of children travelling as passengers, supplied by the adult making the booking, who must be entitled to provide them. If you believe a child's data has reached us in any other way, contact us and we will delete it.
We will post any revision here and update the effective date. Where a change materially affects how we use data you have already given us, we will tell you by email before it takes effect and, where the law requires it, ask for your consent again.
Write to info@buybusinessclass.com or Buybusinessclass Travel, Inc., 180 North Stetson Avenue, Chicago, IL, 60601, United States. We reply to written enquiries within five business days.