Cancel Craft Your AdventureAre you sure you want to cancel your adventure?

Only Afrika Ltd Privacy Policy

Last Updated: 26 April 2026

1. Who We Are

Only Afrika Ltd is a UK-registered tour operator (Company No. 16340551).
Registered Office: 1st Floor, Cromwell House, 14 Fulwood Place, London, WC1V 6HZ

Data Protection Officer: admin@onlyafrika.co.uk

2. What Personal Data We Collect

Data Type

Examples

Purpose

Identity/Contact

Name, email, phone, address, passport

Booking fulfilment, ABTOT documentation

Payment Details

Card number, billing address (not stored)

Transaction processing

Special Category

Dietary needs, health conditions

Service customisation

Technical

IP address, browser type, cookies

Website optimisation

Marketing Preferences

Subscription choices

Consent-based communications

3. How We Use Your Data

Purpose

Legal Basis

Process bookings & payments

Contractual necessity

Provide ABTOT protection docs

Legal obligation (PTRs 2018)

Share with suppliers (e.g., lodges)

Legitimate interests

Marketing communications

Your consent

Fraud prevention

Legal obligation

4. Who We Share With

  • Essential Partners:
    • DMC’s, Lodges, Transport providers
    • Faremine (flight partner) for ATOL compliance
    • ABTOT for financial protection records
  • Legal Requirements: HMRC, border authorities, law enforcement
  • International Transfers: To South Africa/Namibia/Botswana under UK GDPR “adequacy decisions”

5. Data Retention

Data Type

Retention Period

Booking records

6 years post-travel (UK law)

Financial transactions

7 years (HMRC compliance)

Marketing consents

Until withdrawal of consent

Passport copies

Deleted after trip completion

6. Your Rights

You have the right to:

  • Access your personal data (free within 30 days)
  • Correct inaccurate information
  • Erase data (“right to be forgotten”)
  • Restrict processing
  • Data portability
  • Object to marketing
  • Withdraw consent (email admin@onlyafrika.co.uk)

7. Cookies & Tracking

  • We use essential cookies for booking functionality
  • Optional analytics cookies (Google) require consent
  • Control via browser settings or our Cookie Preference Centre

8. Security Measures

  • Encrypted payments (PCI DSS compliant)
  • Secure servers with firewall protection
  • Staff data protection training
  • Regular security audits

9. ABTOT Compliance

  • Booking data shared with ABTOT for bonding requirements
  • Financial protection records retained per ABTOT guidelines

10. Complaints

Contact our DPO first. Unresolved? Lodge a complaint with:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF: www.ico.org.uk/concerns

11. Policy Updates

We review this annually. Material changes will be: