Privacy Policy

Effective Date: 20 January 2026 Last Updated: 20 August 2026

FBT DMC and its affiliated companies and entities ("FBT DMC", "we", "us", or "our") respect your privacy and are committed to protecting personal information entrusted to us.

This Privacy Policy explains how we collect, use, disclose, store and protect personal information when you access or use the FBT DMC Partner Portal, our websites, applications, booking platforms, APIs, travel services and related products and services (collectively, the "Services").

This Privacy Policy applies to travel agents, business partners, corporate customers, suppliers, users, travelers and other individuals whose personal information may be processed through our Services.

By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy.

1. About FBT DMC

FBT DMC is a global Destination Management Company and B2B travel services provider offering travel products and services including accommodation, tours, activities, transfers, transportation, destination services, group travel, MICE and related travel arrangements.

Data Controller / Responsible Entity:

FBT DMC Legal Entity: FBT DMC Registered Address: Unit No 417 City Avenue Building Port Saeed Deria Dubai, UAE, PO Box-6263 Country: United Arab Emirates Email: Website:

Where required by applicable law, a local affiliate, subsidiary, representative or other FBT DMC entity may act as the relevant data controller or joint controller for particular processing activities.

2. Scope of This Privacy Policy

This Privacy Policy applies to information collected through:

FBT DMC websites

FBT DMC B2B Portal

Agent accounts

Booking systems

Mobile applications

APIs and technology integrations

Email communications

Customer and agent support

Supplier and partner systems

Online forms

Offline business interactions

Travel bookings and service delivery

This Privacy Policy does not apply to third-party websites, applications or services that are not controlled by FBT DMC.

3. Information We Collect

Depending on your relationship with FBT DMC, we may collect the following categories of information.

3.1 Account and Agent Information

For B2B agents and business users, we may collect:

Full name

Company name

Job title

Business email address

Business telephone number

Country

Business address

Login credentials

Agent ID

User ID

Account status

Credit information

Wallet information

Transaction history

Booking history

Communication history

3.2 Traveler Information

When a booking or travel service is requested, we may process:

Passenger name

Date of birth

Gender where required

Nationality

Passport information

Passport number

Passport expiry date

Visa information

Contact information

Travel dates

Flight information

Hotel information

Special travel requirements

Emergency contact information

Other information required to provide the requested travel service

Travel agents are responsible for ensuring that they have the appropriate authority or legal basis to provide traveler information to us.

3.3 Booking and Transaction Information

We may collect:

Booking reference

Travel itinerary

Destination

Hotel and room information

Tour and activity information

Transfer information

Supplier information

Booking status

Cancellation information

Invoice information

Payment status

Refund information

Credit information

Wallet transactions

Commission information

3.4 Payment Information

For payments and financial transactions, we may process:

Payment method

Transaction amount

Currency

Payment reference

Bank information where required

Invoice information

Payment status

Refund information

Where payment processing is handled by third-party payment providers, your payment card information may be collected and processed directly by those providers.

FBT DMC does not intend to store full payment-card information unless necessary and legally permitted for the relevant service.

3.5 Technical Information

When you use our websites or portal, we may automatically collect:

IP address

Browser type

Device type

Operating system

Login information

Session information

Date and time of access

Pages visited

Portal activity

Cookies and similar technologies

Security and authentication information

Error and diagnostic information

4. How We Use Personal Information

We may use personal information for the following purposes:

Providing Travel Services

Process bookings

Confirm reservations

Arrange hotels

Arrange transportation

Arrange tours and activities

Process visa-related services

Provide airport and destination services

Communicate itinerary information

Handle cancellations and amendments

Process refunds

B2B Agent Management

Create and manage agent accounts

Verify agent identity and business information

Manage agent access

Manage agent wallet and credit

Process agent payments

Manage commissions

Generate invoices and statements

Monitor account activity

Provide account support

Business Operations

Manage suppliers

Process contracts

Perform reconciliation

Maintain financial records

Conduct audits

Prevent fraud

Detect unauthorized activity

Maintain internal records

Communications

We may use your information to:

Respond to enquiries

Provide booking updates

Send transaction notifications

Send account notifications

Provide support

Send service-related communications

Send marketing communications where permitted by applicable law

Security

We may process information to:

Protect our systems

Prevent unauthorized access

Detect fraud

Investigate security incidents

Protect users, employees and business partners

Enforce our terms and policies

5. Legal Basis for Processing

Where applicable data-protection laws require a legal basis, we may process personal information on one or more of the following grounds:

Contract

Where processing is necessary to provide a requested service, process a booking, manage an account or perform a contract.

Legal Obligation

Where processing is necessary to comply with applicable laws, regulations, accounting requirements, immigration requirements, tax requirements or regulatory obligations.

Legitimate Interests

Where processing is necessary for legitimate business interests, including:

Operating and improving our Services

Managing business relationships

Preventing fraud

Protecting our systems

Maintaining security

Managing financial and commercial records

We will consider applicable privacy rights when relying on legitimate interests.

Consent

Where required, we may request your consent before processing certain information, including certain marketing communications or other processing activities.

You may withdraw consent where consent is the legal basis for processing.

6. Travel and Sensitive Information

Some travel information may be considered sensitive or special-category information under applicable laws.

Examples may include:

Health-related travel requirements

Disability or accessibility information

Religious meal requirements

Biometric information where applicable

Other information that may be classified as sensitive under local law

We only request or process such information where necessary for the requested service, where permitted by law, or where an appropriate legal basis or consent exists.

7. Information Received From Third Parties

We may receive personal information from:

Travel agents

Corporate customers

Airlines

Hotels

Tour operators

Transportation providers

Visa service providers

Technology providers

Payment providers

Suppliers

Business partners

Where an agent or business partner provides personal information to us, that party is responsible for ensuring that it has the appropriate legal authority to provide the information and that the relevant individuals have received any required privacy notices.

8. Sharing Personal Information

We may share information with trusted third parties where necessary to provide our Services.

These may include:

Hotels

Airlines

Cruise companies

Tour operators

Transportation companies

Local DMC partners

Visa service providers

Activity providers

Payment processors

Banks and financial institutions

Technology providers

Cloud hosting providers

CRM providers

Communication providers

Customer-support providers

Fraud-prevention providers

Professional advisers

Auditors

Government authorities

Immigration and border authorities

Law-enforcement agencies where legally required

We do not sell personal information as a commercial product.

9. International Data Transfers

Because FBT DMC operates in international travel markets, personal information may be processed or transferred between different countries.

These countries may have different data-protection laws from the country in which the information was originally collected.

Where applicable law requires safeguards for international transfers, we will implement appropriate mechanisms, which may include:

Adequacy decisions

Standard contractual clauses

Appropriate contractual protections

Other legally recognized transfer mechanisms

For individuals protected by the GDPR, international transfers will be handled in accordance with applicable GDPR requirements.

10. Data Security

We use reasonable technical and organizational measures designed to protect personal information against:

Unauthorized access

Unauthorized disclosure

Loss

Destruction

Alteration

Misuse

Accidental disclosure

Security measures may include:

Encryption

Access controls

Authentication

Role-based permissions

Secure hosting

Monitoring

Logging

Backup systems

Security testing

Employee access controls

However, no internet-based system can be guaranteed to be completely secure.

11. Account Security

B2B portal users are responsible for maintaining the confidentiality of:

Username

Password

Authentication credentials

OTPs

API credentials

Other account-access information

You must immediately notify FBT DMC if you believe your account has been compromised or accessed without authorization.

12. Cookies and Similar Technologies

Our websites and portal may use cookies and similar technologies to:

Maintain login sessions

Remember preferences

Improve website performance

Understand website usage

Improve security

Analyze traffic

Provide relevant communications where permitted

Where required by applicable law, we will request consent before using non-essential cookies.

You may control cookies through your browser or our cookie-management tools where available.

13. Marketing Communications

Where permitted by applicable law, we may send information about:

Travel products

New destinations

B2B offers

Promotions

Special rates

New services

Events

Business updates

You may unsubscribe from marketing communications at any time by using the unsubscribe option in the communication or contacting us.

Service-related communications, such as booking confirmations, payment notices and security notifications, may continue even if you opt out of marketing communications.

14. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy.

Retention periods may depend on:

The type of information

The purpose of processing

The duration of the business relationship

Booking requirements

Accounting requirements

Tax requirements

Legal obligations

Dispute resolution

Fraud prevention

Regulatory requirements

When information is no longer required, we may securely delete, anonymize or otherwise dispose of it in accordance with applicable law.

15. Your Privacy Rights

Depending on your country and applicable law, you may have rights including:

Right to access your personal information

Right to request correction of inaccurate information

Right to request deletion

Right to request restriction of processing

Right to object to certain processing

Right to data portability

Right to withdraw consent

Right to object to direct marketing

Right to information about processing

Right to lodge a complaint with a relevant data-protection authority

These rights may be subject to legal limitations and exceptions.

For individuals covered by the GDPR, these rights include the rights of access, rectification, erasure, restriction, portability and objection, subject to the conditions of applicable law.

16. How to Exercise Your Rights

To submit a privacy request, contact:

Privacy Team Email: Subject: Privacy Request

Please include:

Full name

Email address

Country of residence

Nature of your request

Relevant account or booking reference, if applicable

We may need to verify your identity before processing certain requests.

17. Children's Privacy

The FBT DMC B2B Portal is primarily intended for businesses, travel professionals and adults.

We do not knowingly use the Services to directly market to children.

Where travel services involve minors, information relating to minors may be processed only where necessary to provide the requested travel service and in accordance with applicable law.

18. Third-Party Websites and Services

Our Services may contain links to third-party websites or integrations.

Examples may include:

Airlines

Hotels

Payment providers

Visa providers

Travel suppliers

Government websites

Technology providers

FBT DMC is not responsible for the privacy practices of third-party websites or services.

We recommend reviewing the privacy policies of those third parties before providing personal information.

19. Data Breach and Security Incidents

If we become aware of a personal-data breach affecting individuals, we will assess the incident and take appropriate action in accordance with applicable law.

Where notification is legally required, we will notify the relevant regulatory authority and/or affected individuals within the applicable statutory timeframe.

20. Automated Decision-Making

FBT DMC may use automated systems for certain operational purposes, such as:

Fraud detection

Security monitoring

Account-risk assessment

Booking validation

System recommendations

Where applicable law provides rights concerning automated decision-making or profiling, we will provide the information and safeguards required by that law.

21. Business Transfers

If FBT DMC or any relevant business, asset or group company is involved in:

Merger

Acquisition

Reorganization

Sale of assets

Investment

Corporate restructuring

personal information may be transferred as part of the transaction, subject to applicable privacy laws and appropriate safeguards.

22. Compliance With Applicable Laws

FBT DMC operates across international travel markets and may be subject to different privacy and data-protection requirements depending on the location of the individual, the nature of the Services and the location of processing.

These may include, where applicable:

UAE Personal Data Protection Law

EU General Data Protection Regulation (GDPR)

UK data-protection legislation

Applicable United States privacy laws

Applicable privacy laws in other countries where we operate or provide Services

The UAE Personal Data Protection Law establishes requirements concerning the processing, confidentiality and protection of personal data and includes provisions concerning cross-border transfers.

This Privacy Policy is intended to provide a common global framework, while specific local privacy notices or additional rights may apply where required by local law.

23. Data Controller and Processor Relationships

In the B2B travel environment, FBT DMC may act as:

Data Controller

Data Processor

Joint Controller

depending on the service and the relationship with the relevant business partner.

For example, an agent may provide traveler information to FBT DMC to arrange travel services. In such circumstances, the respective responsibilities of the parties may be governed by the applicable agreement and data-protection law.

Where required, FBT DMC may enter into a Data Processing Agreement or other appropriate data-protection agreement with business partners.

24. Financial and Transaction Records

Because the FBT DMC B2B Portal supports commercial transactions, agent wallets, credit facilities, invoices, payments, commissions and settlements, transaction records may be retained for accounting, audit, tax, fraud-prevention and legal purposes.

The use of USD or another currency does not change our commitment to protecting personal information. Currency information may form part of transaction records where necessary to process and reconcile B2B transactions.

25. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

Changes to our Services

Changes to technology

Changes to business operations

Changes to applicable laws

Regulatory requirements

Changes to our data-processing practices

The updated version will be published on this page with a revised "Last Updated" date.

Where required by applicable law, we will provide additional notice of material changes.

26. Contact Us

For questions, concerns or requests relating to privacy or personal information, contact:

FBT DMC – Privacy Team

Email: Website: Registered Company: FBT Adventures Travels LLC Registered Address: Unit No 417 City Avenue Building Port Saeed Deria Dubai, UAE, PO Box-6263 Country: United Arab Emirates

For data-protection requests, please use the subject:

"Data Privacy Request – FBT DMC"

27. Governing Law

This Privacy Policy is intended to operate alongside applicable data-protection and privacy laws.

Nothing in this Privacy Policy is intended to limit any mandatory privacy rights available to an individual under the laws applicable to that individual.

Where a specific local privacy law provides greater protection or additional rights, those mandatory requirements will apply to the extent required by law.

28. Acceptance

By using the FBT DMC B2B Portal or submitting personal information through our Services, you acknowledge that you have read this Privacy Policy.

Where consent is required by applicable law, we will obtain consent through an appropriate consent mechanism.

FBT DMC Global B2B Travel Distribution Platform