Privacy Policy shall apply to the use of www.dibtravel.com and other websites and applications of “Search Pages” which belong to DIB Services AB, Box 6067, 102 31 Stockholm, org.no.559036-8758, “DIB”. DIB Travel is a branch of the company DIB Services AB.
1.1 When the User performs booking through DIB, he/she is required to submit certain personal data (name, e-mail address, telephone number, address, sex/age). Those data are stored and used in order to enable the User to book a hotel, for the purpose of communication with the User and, if required, for sending newsletters of DIB.
1.2 DIB records the purchases made by the Buyer so that the Buyer can see an overview of past purchases when logging into the User Account. In addition, DIB uses such data for statistical purposes and in order to improve user experience on the website.
1.3 DIB also uses cookies for collecting the information on visits to the website by the User as described below.
2.1 The User agrees to receive newsletters, offers and information on purchases, sale and mediation related to goods and services. This can be performed electronically (ex. via e-mail, sms messages, push notifications through applications) or by telephone and regular mail, and it can be sent by, for example, dibtravel.com and business partners. Therefore, DIB can transfer internally collected User data (name, e-mail address, telephone number, sex, age, area of interest, past purchases and sales, etc.).
2.2 The User can withdraw his/her consent related to marketing at any time by sending an e-mail to [email protected].
3.1 Personal data of Users shall only be given to the companies such as, for example, business partners, transportation firms, IT suppliers and providers of payment services to DIB and only to the extent required for processing the purchase orders and in order to ensure the undisturbed functioning of websites as well as for mediation services. This means, for example, that personal data of Users shall be transmitted to the hotels with which DIB cooperates.
4.1 All personal data communicated by the User to DIB shall be kept in a safe database with dibtravel.com and shall be treated as confidential. When the User purchases through DIB websites, all information related to such transactions are encrypted.
5.1 The User can, at any time, inspect the registered personal data by accessing his/her User Account. The User can also make possible changes to data. For security reasons the User may not change name or surname. If the User wishes to change his/her name, the User is required to directly contact DIB via e-mail [email protected]. If the User no longer wishes to be a client of dibtravel.com, he/she can announce that at any time through his/her User Account or via e-mail to [email protected].
6.1 When you register for Dib Services AB we ask for information such as your name, email address, billing address, or payment information. Members who only sign up for the account are not required to enter any payment details.
6.2 Dib Services AB uses collected information for the following general purposes: products and services provision, billing, identification and authentication, services improvement, contact, and research.
7.1 DIB uses cookies in order to provide the best possible experience to the User during the visit to the Search Page. Cookies are small textual files stored in the hard disk of a computer, smartphone or other IT equipment. This enables recognition of the computer / IP address and collection of information on visited websites and used functionalities.
7.2 If the User does not want to use cookies, cookies can be disabled in the browser. Please note that in this case certain services and functionalities cannot be used for reason that they use cookies for memorizing your activities.
7.3 DIB uses cookies to provide better experience on the website, to memorise the User’s activities during the use of DIB’s website and for ongoing improvement of the content and functions of the website. DIB also uses cookies in order to make the marketing suitable for its needs and for statistical data on the use of the website.
7.4 Some cookies are deleted when the browser is closed, while others are kept for a longer period of time.
7.5 DIB also uses independent cookies, i.e. those set by others. Those are, for example, the companies which help us estimate, analyse and create our offers, advertisements and contents.
8.1 Dib Services AB uses third-party vendors and hosting partners to provide the necessary hardware, software, networking, storage, and related technology required to run Dib services. Although Dib Services AB owns the code, databases, and all rights to the Dib Services AB application, you retain all rights to your data.
9.1 If you choose to provide Dib Services AB with your information, you consent to the transfer and storage of that information on our servers located in Germany.
9.2 For European Union and Swiss residents, any questions or concerns regarding the use or disclosure of your information should be directed to Dib Services AB by sending an email to [email protected] . We will investigate and attempt to resolve complaints and disputes regarding use and disclosure of your information in accordance with this Privacy Policy. For complaints that cannot be resolved, and consistent with the Safe Harbor Enforcement Principle, we have committed to cooperate with data protection authorities located within Switzerland or the European Union (or their authorized representatives).
10.1 If you are located in the European Union, you are entitled to the following rights with regard to your personal information and data:
10.1.1 Right of access to your personal data, to know what information about you we hold
10.1.2 Right to correct any incorrect or incomplete personal data about yourself that we hold
10.1.3 Right to restrict/suspend our processing of your personal data
10.1.4 Right to complain to a supervisory authority if you believe your privacy rights are being violated
10.1.5 Additional rights that may apply to you in certain instances:
10.1.5.1 Right of data portability (if our processing is based on consent and automated means)
10.1.5.2 Right to withdraw consent at any time (if processing is based on consent)
10.1.5.3 Right to object to processing (if processing is based on legitimate interests)
10.1.5.4 Right to object to processing of personal data for direct marketing purposes
10.1.5.5 Right of erasure of your personal data from our system (“right to be forgotten”) if certain grounds are met
10.1.5.6 To exercise your privacy rights, you can email us at the address given below in the ‘Questions’ section of this Privacy Policy
11.1 Dib Services AB may periodically update this policy. We will notify you about significant changes in the way we treat personal information by sending a notice to the primary email address specified in your Dib Services AB primary account holder account or by placing a prominent notice on our site.
12.1 If you need more information or if you have any questions please contact us at [email protected].
In this privacy notice, we describe what personal data about you that we use and why, including your rights under the General Data Protection Regulation (GDPR).
This privacy notice applies to the DIB Travel Group, including:
When referring to "DIB", "we", "us" or "our", this means the relevant DIB company or companies that are responsible (either as separate controllers or joint controllers) for the processing of your personal data. For more information, see the section "Responsibility for the use of your personal data" below.
This privacy notice covers you who:
In this privacy notice, "website" means dibtravel.com and app.dibtravel.com.
When referring to "travel portal", this means DIB's travel portal available for users via app.dibtravel.com or the "DIB Travel" app
If you are a user of the travel portal and DIB Services AB has a business relationship with the organisation that you represent, DIB Services AB is responsible (as controller) for the processing of your personal data.
If you are a user of the travel portal and DIB Denmark ApS has a business relationship with the organisation that you represent, DIB Denmark ApS and DIB Services AB are responsible together (as joint controllers) for the processing of your personal data.
If you are a user of the travel portal and DIB Norge AS has a business relationship with the organisation that you represent, DIB Norge AS and DIB Services AB are responsible together (as joint controllers) for the processing of your personal data.
DIB has entered into an Intra-Group Data Transfer Agreement (IGDTA), including an arrangement under article 26 of the GDPR, that sets out the roles and responsibilities of each DIB entity when processing your personal data. You have the right to obtain the essence of this arrangement upon request. This privacy notice also reflects the key elements of that arrangement.
If you visit our website, app or other digital channels, DIB Services AB is responsible (as controller) for the processing of your personal data collected through cookies and other tracking technologies.
The DIB company that is responsible (as controller) for the processing of your personal data under this privacy notice is normally the DIB company:
In the below table we describe what categories of personal data that we process with examples of types of personal data covered by each category.
| Categories of personal data | Examples of types of personal data |
|---|---|
| Account details | Username, password, user profile |
| Background check data | Results from background checks, for example KYC checks |
| Communication data | Content in e-mail and other forms of communication |
| Contact information | Address, e-mail address, phone number |
| Event data | Type of event, participants, preferences |
| Feedback data | Feedback, opinions, answers from surveys |
| Identity data | Name, personal identity number, signature |
| Organisational data | Title, position and the company or organisation that you work for |
| Payment data | Payment card details, payment method, amount |
| Picture, video and audio material | Video, photos, audio recordings |
| Technical data | Type of device, IP address, version of web browser and operating system |
| Travel and logistics data | Travel itinerary, hotel or other accommodation details, travel preferences, including dietary preferences and allergies, as well as accessibility needs and health related requirements |
| Travel documentation | Personal data included in passports, visas and national ID cards (for example full name, passport/visa number, nationality, date and place of birth, sex, photo and signature, type of visa, duration of stay/validity period), as well as travel tickets (for example booking reference, destination and other itinerary details) and loyalty travel data |
| User generated data | Click and visit statistics on the website, user preferences, interactions when using the website and other digital channels |
The personal data that we collect about you is mainly collected directly from yourself when you provide your personal data to us, for example when you contact or otherwise communicate with us, use our travel portal or visit our website or other digital channels.
We also collect, where necessary, personal data from other sources as described below.
We collect and use personal data for various purposes. The purposes for which we in practice process your personal data may, however, vary depending on your relationship with us or how you interact with us.
To read more about which personal data, which legal basis that we rely on for the processing of your personal data for each purpose and for how long your personal data is stored in relation to the relevant categories of individuals, please see our detailed information on our use of personal data.
We share your personal data with external recipients where necessary for the purposes described in this privacy notice. These recipients act as controllers for their own processing of your personal data, unless stated otherwise.
For more details on the purposes for which we share your data and the legal bases for such sharing, please see our detailed information on our use of personal data, which outlines the external recipients associated with each processing purpose.
We also transfer personal data to service providers that we have engaged (including group companies) when necessary for the purposes for which we process personal data as described in this privacy notice.
These service providers (including group companies) provide, for example, IT, financial and other administrative services, development services and communication services to us. The service providers which process personal data on our behalf and in accordance with our instructions act as data processors in relation to us. These service providers may not process your personal data for their own purposes and are legally and contractually obligated to protect your personal data.
As a main rule, we store your personal data within the EU/EEA. However, in certain cases, we transfer your personal data to recipients located in third countries outside the EU/EEA, for example to service providers engaged by us.
To ensure an essentially equivalent level of protection for your personal data when transferred (or otherwise made available) to service providers in third countries which do not provide an adequate level of protection, we generally rely on the EU Commission's adopted standard contractual clauses for international transfers according to decision 2021/914 and implement supplementary measures as necessary to ensure an essentially equivalent level of protection for your personal data as provided under the EU GDPR.
We also rely upon adequacy decisions issued by the EU Commission where personal data is transferred to countries and recipients covered by such decisions (i.e. where the EU Commission has determined that such country and/or recipient provides an adequate protection). By way of example, this includes the EU-US Data Privacy Framework for transfers to the United States.
Moreover, where relevant, we rely on specific provisions in Article 49 of the GDPR, such as where the transfer is necessary for the performance of a contract between us and you or is necessary to conclude such contract.
You have the following rights in relation to your personal data under the GDPR:
We do not carry out any automated individual decision-making which have legal effects or similar significant effects on you.
Please note that each right above comes with certain caveats and exemptions. This means that these rights only may be successfully exercised in certain situations. For more information on your rights and when they apply, see for example the information provided by the Swedish Authority for Privacy Protection available on their website.
If you wish to exercise your rights at any time, please contact us on the contact details under section 8 "If you have any questions" below.
If possible, we would grateful if you use the e-mail address that you have registered with us or used when you have previously been in contact with us. This would make it easier for us to manage your request.
You have the right to lodge a complaint with your supervisory authority. Contact details to the data protection authorities in the EU/EEA can be found here.
Please contact us by e-mail at [email protected] if you have any questions about this privacy notice, how we use your personal data or if you wish to exercise your rights.
You can also find contact details to each DIB entity here: https://dibtravel.com.
In this detailed information on our use of personal data, we explain the purposes for which we use personal data, the categories of personal data processed for each purpose, our legal basis for the use, for how long we store personal data and with which external recipients (in their role as controllers) that we share your personal data for each purpose.