Privacy Policy
Last updated 8 August 2026
This policy explains what happens to the information you send us through this website. It is written to be read, not to be survived — if anything here is unclear, write to us and we will answer in plain language.
Who is responsible for your data
The data controller is JPB Tech Solution, trading as Hotels Worldwide, 51 Bracken Road, D18 CV48, Dublin, Ireland. Registered in Ireland, company number 721636.
For any question about your data, or to exercise the rights described below, contact [email protected] or write to the postal address above.
What we collect, and why
| What | Why | Lawful basis |
|---|---|---|
| Room requests — your name, company, work email, phone, and the booking details you enter (city, airport, dates, number of rooms and crew, meal plan, flight and tail references, notes) | To source hotel rooms and quote you a rate — that is, to take the steps you asked for before a contract | Article 6(1)(b) — steps at your request prior to a contract |
| Demo requests — your name, role, company, operation type, email, phone, preferred call-back time and any message | To call you back at the time you chose and discuss whether our service suits your operation | Article 6(1)(f) — our legitimate interest in responding to a business enquiry you initiated |
| Technical records — IP address, request time, browser user-agent, in server and security logs | To keep the site available and to detect abuse of the forms | Article 6(1)(f) — our legitimate interest in the security of our systems |
We ask only for what a coordinator needs to act on your request. We do not buy contact data, we do not build profiles, and there is no automated decision-making or profiling of any kind.
Cookies and tracking — essentially none
This website sets no cookies and embeds no advertising or social media trackers. Nothing is stored in your browser, which is why you are not being asked to dismiss a cookie banner. The only measurement we run is Cloudflare Web Analytics — a privacy-first, cookieless service that counts page visits in aggregate without storing anything on your device, fingerprinting you, or following you across sites. Our security provider may set a strictly necessary cookie to identify abusive traffic; it is not used to track you across sites.
Spam protection — Cloudflare Turnstile
Our contact and request forms are protected by Cloudflare Turnstile, a privacy-preserving alternative to traditional CAPTCHAs. Turnstile runs invisibly when you submit a form and evaluates technical signals from your browser solely to distinguish people from automated abuse; it does not show you puzzles, does not track you across sites, and is not used for advertising. The processing is described in Cloudflare's Turnstile Privacy Addendum. Legal basis: Article 6(1)(f) — our legitimate interest in keeping the forms usable and our systems secure.
Who else sees your information
Only those who need to in order to do the job:
- Hotels and accommodation suppliers — when you ask us to source or book rooms, we pass on what the hotel needs to hold and honour the reservation. This is unavoidable: it is the service itself.
- Our service providers — the companies that host our systems, deliver this website securely, and carry our email. They act on our instructions only, under contract, and may not use your data for their own purposes.
We do not sell personal data, and we do not share it for anyone else's marketing.
Transfers outside the EEA
Some of our providers, and many hotels, are outside the European Economic Area. Where that happens we rely on the European Commission's standard contractual clauses or an adequacy decision. Where you ask us to book a hotel outside the EEA, sending your booking details to that hotel is necessary to perform the service you requested.
How long we keep it
- Enquiries that do not become bookings — 24 months from your last contact with us, then deleted.
- Client records — for as long as we work together, and afterwards for as long as the law requires us to keep accounting and tax records (six years in Ireland).
- Security and server logs — a short rolling period, then overwritten.
Your rights
Under the GDPR you may ask us to:
- give you a copy of the personal data we hold about you;
- correct anything inaccurate;
- delete it, where we have no continuing need or legal duty to keep it;
- restrict or object to how we use it — including, at any time, to stop contacting you;
- provide it in a portable, machine-readable form.
Write to [email protected]. We answer within one month. You will never be charged for asking, and asking will never affect the service you receive.
If you think we have handled your data badly, you can complain to the Irish supervisory authority: the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28. We would rather you told us first, so we can put it right.
How we protect it
Traffic to this site is encrypted in transit. Our booking systems are access-controlled, each member of staff seeing only what their role requires, and client records are separated so that one client can never see another's. Access is logged.
Changes
If this policy changes materially we will update the date at the top and, where the change affects you directly, tell you.
See also our legal notice.