GDPR Compliance

Last Updated: July 12, 2026

Our Commitment to GDPR Compliance

TravelWires is committed to protecting the privacy and personal data of all visitors from the European Union and European Economic Area. We comply with the General Data Protection Regulation (GDPR) and implement appropriate technical and organizational measures to ensure your data is processed lawfully, fairly, and transparently.

This page explains your rights under GDPR and how we fulfill our obligations as a data controller.

Data Controller Information

Name: TravelWires
Website: www.travelwires.com (https://www.travelwires.com/)
Privacy Inquiries: privacy@travelwires.com
General Contact: office@travelwires.com

Your Rights Under GDPR

As an individual in the EU/EEA, you have the following rights regarding your personal data:

1. Right to Access (Article 15)

You have the right to obtain confirmation that we are processing your personal data and to receive a copy of that data.

How to exercise: Submit a request through your Account Privacy Dashboard (https://www.travelwires.com/account/privacy/) or email privacy@travelwires.com

Response time: Within 30 days (may extend to 90 days for complex requests with advance notice)

2. Right to Rectification (Article 16)

You have the right to have inaccurate personal data corrected and incomplete data completed.

How to exercise:

• Update your information directly in Account Settings
• Email privacy@travelwires.com with corrections
Response time: Within 30 days

3. Right to Erasure / “Right to be Forgotten” (Article 17)

You have the right to request deletion of your personal data when:

• The data is no longer necessary for the purposes it was collected
• You withdraw consent and there is no other legal basis for processing
• You object to processing and there are no overriding legitimate grounds
• The data has been unlawfully processed
• Erasure is required for compliance with a legal obligation
Limitations: We may retain data when required by law (e.g., tax records, legal obligations)

How to exercise: Email privacy@travelwires.com with subject “GDPR Erasure Request”

Response time: Within 30 days

4. Right to Restriction of Processing (Article 18)

You have the right to restrict processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.

How to exercise: Email privacy@travelwires.com with specific restriction requests

Response time: Within 30 days

5. Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

Available formats: JSON, CSV, XML

How to exercise: Request data export through Account Privacy Dashboard (https://www.travelwires.com/account/privacy/) or email privacy@travelwires.com

Response time: Within 30 days

6. Right to Object (Article 21)

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.

Direct Marketing: You can opt-out at any time by clicking “Unsubscribe” in any marketing email or adjusting preferences in Account Settings

Other Processing: Email privacy@travelwires.com with your objection and reasoning

Response time: Immediate for marketing opt-out; 30 days for other objections

7. Right Not to Be Subject to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you.

Our Practice: We do not engage in automated decision-making that produces legal or similarly significant effects.

Legal Basis for Data Processing

We process your personal data based on the following legal grounds under GDPR Article 6:

Consent (Article 6(1)(a))

• Marketing communications (newsletter, service updates, event notifications)
• Analytics cookies and tracking technologies
• Personalized content recommendations

You can withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

Contract Performance (Article 6(1)(b))

• Account creation and management
• Press release distribution services
• Payment processing
• Customer support

Legal Obligation (Article 6(1)(c))

• Tax and accounting record retention
• Compliance with court orders and legal processes
• Data breach notification requirements

Legitimate Interests (Article 6(1)(f))

• Website security and fraud prevention
• Service improvement and analytics (with balancing test)
• Internal business operations

We conduct balancing tests to ensure our legitimate interests do not override your rights and freedoms.

What Personal Data We Collect

Information You Provide

• Account registration data (name, email, company details, phone number)
• Press release content and uploaded media files
• Payment information (processed securely by PCI-DSS compliant third parties)
• Communications and support requests
• Profile preferences and distribution settings

Automatically Collected Data

• Technical information (IP address, device type, browser, operating system)
• Usage analytics (pages visited, time spent, content viewed)
• Performance data (loading times, error reports)
• Approximate location (city/country level based on IP address)
Cookies and Tracking Technologies

We use cookies with your consent. You can manage cookie preferences through our Cookie Consent Manager available in the website footer.

Cookie Categories:

• Essential: Required for site functionality (cannot be disabled)
• Analytics: Google Analytics for performance monitoring (opt-in)
• Marketing: Advertising and remarketing (explicit consent required)
See our Cookie Policy (https://www.travelwires.com/legal/cookie-policy/) for detailed information.

How We Use Your Data

We use your personal data for the following purposes:

• Service Delivery: Processing and distributing press releases to our network
• Account Management: User authentication and service access
• Communication: System notifications, support responses, service updates
• Analytics: Platform performance and user experience improvement
• Marketing: Industry news and updates (with separate consent)
• Security: Fraud prevention and system protection
• Legal Compliance: Meeting regulatory requirements

Data Sharing and International Transfers

Third-Party Processors

We share personal data only with processors who provide adequate GDPR protection:

• Analytics: Google Analytics (anonymized IP, privacy-compliant settings)
• Email Services: Mailchimp (GDPR-compliant processors with Standard Contractual Clauses)
• Cloud Infrastructure: Cloudflare (EU-US Data Privacy Framework certified)
• Distribution Network: Travel industry publications (with your consent)
All processors are bound by Data Processing Agreements compliant with GDPR Article 28.

International Data Transfers

When we transfer personal data outside the EU/EEA, we use appropriate safeguards:

• European Commission Standard Contractual Clauses (2021 version)
• EU-US Data Privacy Framework (for adequacy-certified processors)
• Binding Corporate Rules where applicable
• Transfer Impact Assessments as required by Schrems II decision

Data Security Measures

We implement appropriate technical and organizational measures to protect your personal data:

Technical Measures

• Encryption: TLS 1.3 for data in transit, AES-256 for data at rest
• Access Controls: Role-based permissions with multi-factor authentication
• Security Monitoring: 24/7 intrusion detection and automated threat response
• Regular Testing: Annual penetration testing and vulnerability assessments

Organizational Measures

• Staff Training: Quarterly privacy and security awareness programs
• Data Processing Agreements: Contracts with all third-party processors
• Incident Response Plan: Documented procedures with 72-hour breach notification
• Privacy by Design: Data protection integrated into all new systems

Data Breach Notification

In the event of a personal data breach, we will:

1. Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (GDPR Article 33)
2. Notify affected individuals without undue delay if the breach poses a high risk to their rights and freedoms (GDPR Article 34)
3. Provide information about the nature of the breach, likely consequences, and measures taken
You can report suspected data breaches to privacy@travelwires.com.

Consent Management

You have full control over your consent preferences:

Marketing Communications

• Newsletter: Account Settings → Communications → Newsletter (On/Off)
• Service Updates: Account Settings → Communications → Updates (On/Off)
• Event Notifications: Account Settings → Communications → Events (On/Off)

Data Processing

• Analytics Consent: Account Settings → Privacy → Analytics (On/Off)
• Personalization: Account Settings → Privacy → Personalized Experience (On/Off)
• Cookie Preferences: Click “Cookie Preferences” in website footer

Withdrawing Consent

• Click “Unsubscribe” in any marketing email
• Update preferences in Account Settings
• Email privacy@travelwires.com with “Withdraw Consent” subject

Withdrawal of consent does not affect the lawfulness of processing before withdrawal.

Children’s Privacy

We do not knowingly process personal data of children under 16 years of age without verifiable parental consent, in compliance with GDPR Article 8.

If we discover we have collected data from a child without proper consent, we will delete it immediately.

Parents or guardians can contact privacy@travelwires.com to exercise rights on behalf of their children.

Supervisory Authority

You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your:

• Habitual residence
• Place of work
• Place of the alleged infringement

Find your supervisory authority: https://edpb.europa.eu/about-edpb/about-edpb/members_en

We encourage you to contact us first at privacy@travelwires.com to resolve any concerns.

How to Exercise Your Rights

Online Portal

1. Log into your account
2. Navigate to Privacy Dashboard (https://www.travelwires.com/account/privacy/)
3. Submit your request through the appropriate form

Email Request

Send requests to privacy@travelwires.com with:

• Your full name and registered email address
• Specific right you wish to exercise
• Identity verification (government-issued ID may be required)

Response Timeline

• Standard requests: Within 30 days
• Complex requests: Up to 90 days with advance notice
• Free of charge for the first request; reasonable fee may apply for manifestly unfounded or excessive requests

Data Protection Impact Assessments

We conduct Data Protection Impact Assessments (DPIAs) for processing activities that pose high risks to individual rights and freedoms, in accordance with GDPR Article 35.

We review and update our GDPR compliance practices regularly:

• Annual internal audits of data processing activities
• Regular staff training on GDPR requirements
• Monitoring of regulatory guidance and case law developments
• Policy updates to reflect changes in processing or legal requirements

Next scheduled review: January 12, 2027

Contact Our Data Protection Officer

For GDPR-specific inquiries, contact our Data Protection Officer:

Response time: Within 5 business days for initial acknowledgment

For general privacy questions: privacy@travelwires.com

Additional Resources

• Full Privacy Policy: www.travelwires.com/legal/privacy-policy/
• Cookie Policy: www.travelwires.com/legal/cookie-policy/
• Terms of Service: www.travelwires.com/legal/terms-of-service/

Legal Disclaimer

This GDPR Compliance page is designed to provide clear, accessible information about your rights and our obligations under the General Data Protection Regulation (EU) 2016/679. This page supplements our comprehensive Privacy Policy and does not replace it.

For complete details about our data practices, please refer to our Privacy Policy.