PREMIER AIRLINES PRIVACY POLICY
Effective date: 01 July 2026
1. Introduction
Welcome to Premier Airlines. Your privacy is important to us.
Premier Airlines ("we," "us," or "our") operates our airline services, website, and mobile applications (collectively, the "Service"). This Privacy Policy explains how we collect, use, share, and safeguard your personal data when you interact with us or use our services.
This Policy applies to all customers, passengers, suppliers, agents, tour operators, and visitors to our premises or digital platforms. By using our Service, you agree to the collection and use of information in accordance with this Policy.
This Policy should be read together with our Terms and Conditions. Where there is a conflict, this Policy will prevail.
2. Definitions
"Service" means the airline services, website, and mobile applications operated by Premier Airlines.
"Personal Data" means data about a living individual who can be identified from that data, either alone or in combination with other information in our possession.
"Usage Data" means data collected automatically from the use of our Service, such as page visit duration.
"Cookies" are small files stored on your device.
"Data Controller" means the entity that determines the purposes and means of processing personal data. For this Policy, we are the Data Controller of your data.
"Data Processor" means any person who processes data on our behalf.
"Data Subject" is any living individual who is the subject of Personal Data.
"User" means the individual using our Service, including customers, passengers, agents, and visitors.
3. Personal Data We Collect
We collect different types of personal information when you interact with us or use our services:
3.1 Identification Information
Your name, date of birth, nationality, passport or ID number, visa details, photograph, and frequent flyer numbers.
3.2 Contact Details
Your email address, phone number, postal address, and emergency contact information.
3.3 Travel Details
Flight bookings, itineraries, baggage information, seat and meal preferences, and travel companion details.
3.4 Financial Information
Payment card details, bank account information, and transaction records for ticketing and related services.
3.5 Communication Data
Records of calls, emails, chats, feedback, and complaints.
3.6 Online Usage Data
IP address, browser type and version, device information, cookies, pages visited, time and date of visit, and other diagnostic data.
3.7 Location Data
Booking or check-in location, and mobile app location data (with your permission).
3.8 CCTV and Visitor Records
When you visit our premises, we may collect CCTV recordings, visitor register details (name, contact, vehicle registration, ID number) for safety and security purposes.
3.9 Sensitive Personal Data
We may collect sensitive data with extra protection, including:
- Health Information – to provide special assistance, meet dietary needs, or comply with health regulations.
- Biometric Data – for identification purposes (with consent where required).
- Children's Data – collected only with verified parental or guardian consent.
Sensitive data is collected only for specific purposes, with a valid legal basis, and is kept secure and confidential.
4. How We Collect Your Data
We collect personal data when you:
- Book a flight
- Create an account or join our loyalty program
- Check in for a flight
- Contact our customer service
- Use our website or mobile app
We may also receive personal data from third parties you interact with, such as travel agents, partner airlines, and tour operators. In some cases, we may collect data from public sources or government authorities to verify travel documents.
5. How We Use Your Data
We process your personal data only when we have a valid legal reason. Our main purposes include:
| Purpose | Legal Basis |
|-------------|-----------------|
| Providing services you request (bookings, ticketing, payments, check-in, baggage, customer support) | Contract performance |
| Regulatory compliance (passenger information to authorities, aviation security, fraud prevention, tax records) | Legal obligation |
| Customer service and business operations (responding to inquiries, sending travel updates, improving services, audits) | Legitimate interests |
| Marketing and promotions (sending offers, route updates, loyalty program information) | Consent or legitimate interest |
| Safety, security, and emergencies | Vital interests |
| Loyalty programs and personalization | Contract or legitimate interests |
We never share your details with third parties for their marketing without your explicit consent.
6. Your Rights as a Data Subject
Under Kenya's Data Protection Act, 2019, you have the following rights over your personal data:
1. Right to be Informed – to know how and why your data is collected and used.
2. Right of Access – to request confirmation of whether we process your data and receive a copy.
3. Right to Rectification – to have inaccurate or incomplete data corrected.
4. Right to Erasure ("Right to be Forgotten") – to request deletion of your data when no longer needed, subject to legal retention obligations.
5. Right to Restriction – to request temporary suspension of processing in certain cases.
6. Right to Object – to object to processing based on legitimate interests, or to stop all direct marketing.
7. Right to Data Portability – to receive your data in a structured, machine-readable format.
8. Right to Withdraw Consent – to withdraw consent for any processing based on it at any time.
9. Right to Lodge Complaints – to complain to the Office of the Data Protection Commissioner (ODPC) if you believe your rights have been infringed.
To exercise your rights, contact us using the details in Section 12 below. We will respond within statutory timelines (typically 7–30 days) at no cost, unless requests are manifestly unfounded or excessive.
7. With Whom We Share Your Data
We may share your personal data with trusted third parties only for legitimate purposes and never sell it. Key categories include:
1. Government & Regulatory Authorities – immigration, customs, security, law enforcement, and health authorities, as legally required.
2. Partner Airlines & Travel Partners – for code-share flights, loyalty programs, or bundled services (hotels, tours).
3. Service Providers – IT/cloud hosting, payment processors, marketing tools, analytics providers, and fraud prevention services, all bound by strict contracts.
4. Mobile Money Providers – for transaction verification and processing.
5. Financial Institutions – to facilitate and verify financial transactions.
6. Airport & Ground Handling Agents – for check-in, boarding, baggage handling, and special assistance.
7. Corporate Group or Alliance Members – for flight coordination and loyalty program administration.
8. Emergency or Medical Services – to protect vital interests in health or safety emergencies.
9. Auditors, Lawyers & Advisors – for professional advice and legal matters, under confidentiality obligations.
10. Law Enforcement or Legal Requests – when required by law or court order.
11. Business Transfers – in the event of a merger, acquisition, or sale of business assets, subject to appropriate safeguards.
In all cases, we share only the minimum necessary data and require compliance with data protection laws.
8. International Data Transfers
Because air travel is global, your personal data may be transferred across borders – for example, to partner airlines abroad or to cloud servers outside Kenya. We comply with data protection laws on international transfers.
Safeguards we use:
- Adequate Jurisdictions – if data goes to countries with privacy laws deemed equivalent to Kenya's, we rely on adequacy decisions.
- Appropriate Safeguards – for other countries, we use contracts with approved data protection clauses, binding corporate rules, or certification schemes.
- Contract or Legal Necessity – some transfers are essential for your travel or to handle legal matters.
- Consent – if no adequacy finding or safeguards apply, we will request your explicit consent.
- Sensitive Data – transfers of sensitive data outside Kenya require both safeguards and your explicit consent.
9. How Long We Keep Your Data
We keep your personal data only as long as needed to fulfil the purposes in this Policy or meet legal requirements.
### General Retention Guidelines:
- Customer & Booking Data – kept until your flight and related services are complete, plus the legally required period for financial/tax records (e.g., 7 years).
- Loyalty Program Data – kept while you are a member; deleted or anonymised shortly after membership ends.
- Marketing Data – kept until you unsubscribe or withdraw consent.
- Legal/Dispute Records – kept as long as required by law or until any dispute is resolved.
- Recruitment Data – kept as per recruitment notices (e.g., about 1 year for unsuccessful candidates).
Once data is no longer needed, it is securely deleted, erased, or anonymised.
10. Security of Your Data
We take the security of your personal data very seriously.
Our Security Measures Include:
- Technical Safeguards – encryption of sensitive data in transit and at rest, HTTPS/TLS, secure servers, firewalls, intrusion detection, password protection, two-factor authentication, and role-based access controls.
- Organizational & Physical Safeguards – access limited to staff and service providers who need it; staff trained in data protection and bound by confidentiality; secure premises; controlled entry; CCTV; secure destruction of paper records.
- Administrative Measures – company-wide data protection policy, regular audits, incident response plan, DPO oversight, and ongoing privacy training for employees.
- Measures by Our Partners – third-party service providers are contractually required to apply appropriate security measures.
What You Can Do:
- Keep your booking reference, ticket information, and loyalty account login details confidential.
- Use strong, unique passwords and log out when using shared devices.
- Be cautious of phishing attempts – we will never ask for sensitive information via email or social media.
No system is 100% secure. In the event of a data breach that poses a high risk to your rights, we will notify you without undue delay.
11. Third-Party Links and Services
Our website and mobile applications may include links to third-party websites, plugins, or applications. These are provided for your convenience but are not operated or controlled by us.
We do not control or endorse the privacy practices of these third parties. We strongly recommend reviewing the privacy notices of any third-party service before sharing your personal data.
12. Contact Us
For any questions, feedback, or requests relating to this Privacy Policy or the handling of your personal data, please contact our Data Protection Officer:
- Email: privacy@premierairlines.com
- Phone: +254709007000
- Postal Address: Data Protection Officer, Premier Airlines, Crater Automobile Building, P.O Box 40720-00100 Nairobi,Kenya.
We will acknowledge and respond to all inquiries within the legally required timeframe, typically 7 to 30 days.
If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC):
- Website: https://www.odpc.go.ke
- Email: complaint@odpc.go.ke
13. Updates to This Privacy Policy
We may revise this Privacy Policy periodically to reflect changes in our data handling practices, business operations, or to comply with new legal requirements. The "Effective date" at the top shows when changes were last made.
We encourage you to review the Policy regularly. Continued use of our services after updates will be considered acceptance of the revised terms. If any material change affects how we process your personal data, we will seek your consent when required by law.
---
This Privacy Policy is based on industry standards and is intended to comply with Kenya's Data Protection Act, 2019. For any clarifications, please contact us.