Business Partners Privacy Notice

Last updated - December 2018

Basic information about the processing of personal data 
Data controller Amadeus IT Group, S.A.

C/Salvador de Madariaga 1, 28027 Madrid, Spain
Purpose of processing personal data  Amadeus customers: To provide Amadeus products and services, manage accounts, and manage Amadeus’ relationship with Amadeus customers. 

Amadeus service providers: To manage accounts and manage Amadeus' relationship with service providers.   
Legal grounds for processing Performance of a contract
Legitimate interest 
Recipients of the personal data Amadeus affiliates, third party service providers who may include professional advisers, regulators, and authorities where disclosure is required by law. 
Legal rights You have a right to access, review, and restrict processing of personal data, and the right to lodge a complaint with a supervisory authority. 
   

Amadeus Customers - Business Partners Privacy Notice

This Amadeus Business Partners Privacy Notice (“Privacy Notice”) describes how Amadeus (“Amadeus”) collects and processes personal data provided by Amadeus Business Partners. Personal data provided by Amadeus Business Partners includes the personal data of employees, contractors, and other points of contact from companies or organizations with which Amadeus has a commercial relationship; this includes personal data (not including personal data of travelers) provided by the Amadeus Global Distribution System (“Amadeus GDS”) Users (such as, airlines, hotels, and travel agencies); other companies and organizations that may use non-Amadeus GDS services; and third party service providers (collectively referred to in this Privacy Notice as “Amadeus Business Partners”).  

This Privacy Notice does not apply to personal data that may be collected or processed by Amadeus for other purposes, such as through Amadeus websites, Amadeus HR or recruitment services, or the personal data of travelers included in travel information processed in the Amadeus GDS. Where personal data is collected for other purposes, the relevant privacy notice will be provided explaining the purpose the personal data is being processed for.   

This Privacy Notice applies to personal data Amadeus processes provided by, or on behalf of, Amadeus Business Partners, globally. Processing of Amadeus Business Partner personal data may be subject to agreements between Amadeus and Amadeus Business Partners. Other information that is not personal data will be processed in accordance with the contractual agreements with Amadeus Business Partners. This Privacy Notice should be read together with other privacy notices that may be provided on specific occasions when personal data is collected or processed. This Privacy Notice supplements other privacy notices and is not intended to override them. 

 

Who is processing the personal data?

Amadeus Group is made up of different legal entities under the control of Amadeus IT Group S.A. This Privacy Notice is issued on behalf of Amadeus Group. When a reference is made to Amadeus, it refers to the relevant company in the Amadeus Group responsible for processing personal data. Where a specific privacy notice has been provided, the details of the Amadeus entity which is data controller will be provided in the specific privacy notice, in the absence of a specific privacy notice, Amadeus IT Group S.A. is the data controller of the personal data.    

Amadeus has a Chief Privacy Officer who is responsible for overseeing questions in relation to this Privacy Notice. If you have any questions about this Privacy Notice, including any requests to exercise your legal rights as described below, please contact the Chief Privacy Officer using the details set out in the ‘Legal rights’ section of this Privacy Notice.

 

What personal data is processed and how is this personal data collected? 

Personal data means information about an identified or identifiable individual. It does not include information where an individual cannot be identified e.g. non-personal or aggregated data. Amadeus process personal data that is collected from individuals and personal data that is provided by Amadeus Business Partners and from third parties.   

Amadeus process different kinds of personal data that can be grouped together as follows:

  • Identity data – includes name, user name, or other identifier
  • Contact data – includes address, email address, and telephone number
  • Technical data – includes IP address, login data, browsing actions, and patterns
  • Commercial/Usage data – includes information about how Amadeus products and services are used
  • Profile data – includes information about interests, preferences, feedback, and survey responses
  • Marketing and communications data – includes preferences for receiving marketing from Amadeus and communication preferences. 

 

What is the personal data used for and what is the legal basis for processing?

Amadeus use personal data to provide services that an Amadeus Business Partner has requested; provide support services; for fraud prevention purposes; protect the security of Amadeus products and services and Amadeus Business Partners; to perform internal business processes (such as testing and quality assurance); and other uses compatible with providing the services. For marketing and communication personal data is used to personalize the content of communications.

The legal basis for processing personal data is:

  • The processing is necessary for the performance of a contract that Amadeus has or is about to enter into with an Amadeus Business Partner; or
  • Where the processing of personal data is necessary for Amadeus’ legitimate business interests. Where personal data is processed for legitimate interests, the privacy impact on the individual whose data is being processed will be considered.

 

Who is the personal data shared with?

Amadeus may share personal data with its affiliates, agents, and third party service providers such as suppliers of information technology services, security services, and legal, financial/accounting service providers, and other similar professional advisers. 

Amadeus may also share personal data with third parties, if Amadeus choose to sell, transfer, or merge parts of the business or assets. If there is a change of control of the business those who purchase the business or part of may use personal data in the same way as set out under this Privacy Notice. 

Where such disclosure takes place, Amadeus requires the appropriate technical and organizational security measures to be in place to protect personal data, and for personal data to be processed lawfully.     

Amadeus only allows affiliates and third party service providers to process personal data on behalf of Amadeus for specified purposes and in accordance with Amadeus’ instructions. 

Further information on the affiliates and third party service providers that Amadeus uses to process personal data on their behalf can be requested through using the contact details found in the ‘Legal rights’ section of this Privacy Notice. When requesting this information please make reference to information about affiliates and third party service providers so that the relevant information can be provided.

Amadeus may also disclose personal data as required by law, subpoena, or regulation, or when requested by a government, law enforcement authority, or as otherwise required or permitted by law. 

 

International transfers of traveler personal data

When Amadeus shares personal data with its affiliates and third party service providers who process personal data on behalf of Amadeus, this will involve transferring personal data outside the European Economic Area (“EEA”). When personal data is transferred to another country it will continue to receive adequate protection through contractual or other arrangements put in place with affiliates and third party service providers. For these transfers at least one of the following appropriate safeguards will be implemented:

  • Personal data will be transferred to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission;
  • Standard data protection clauses approved by the European Commission which give personal data transferred the same protection it has in EEA; or
  • With affiliates and third party service providers based in the US, Privacy Shield which gives personal data similar protection it has in EEA.

Further information on the appropriate safeguards used when transferring personal data outside the EEA can be requested through using the contact details found in the ‘Legal rights’ section of this Privacy Notice. When requesting this information please make a reference to the transfer of personal data outside the EEA.

 

Data security and integrity

Amadeus has taken the appropriate technical and organizational security measures to protect personal data from loss or unlawful processing. When personal data is processed on behalf of Amadeus, access is limited to those who have a business need to know, and personal data will be processed in accordance with the instructions of Amadeus and those who have access are subject to a duty of confidentiality.

Amadeus has in place procedures to deal with any suspected personal data breach and will notify individuals and any applicable regulator of a breach where legally required to do so. 

 

Data retention

Amadeus retains personal data for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. 

Details of retention periods for different types of personal data can be found in specific privacy notices or can be made available upon request through using the contact details set out in the ‘Legal rights’ section of this Privacy Notice.

When requesting this information please make a reference to data retention periods.

 

Legal rights

Under certain circumstances individuals can exercise rights under data protection laws. Individuals may exercise these rights relating to their own personal data or contact Amadeus for other data protection related questions by emailing dataprotection@amadeus.com,  or writing to our Chief Privacy Officer at Amadeus IT Group, S.A. C/Salvador de Madariaga 1, 28027 Madrid, Spain. 

Amadeus will require authentication of the identity of the individual wishing to exercise their rights under data protection laws, and may require additional information to assist in responding to requests.

For the following rights please make a reference to the following in the request:

Right to access (Amadeus Business Partners): ‘Request for access to personal data’

Right to information (Amadeus Business Partners):

  • ‘Amadeus affiliates and third party service  providers who process personal data on behalf of Amadeus’
  • ‘Transfers to third countries – information about data transfers outside EEA’

Right to information (Amadeus Business Partners) about: ‘Retention periods of personal data’

 

Your rights

Amadeus intends to carefully address any request and/or claim from you, as well as carefully process personal data. You are entitled to file any claim or complaint before the relevant data protection authorities if the answer provided by Amadeus does not meet your expectations.

 

Updates 

This Privacy Notice is published by Amadeus IT Group S.A. and may be changed at any time. The date it was last updated is shown here 5th December 2018.