Skip to content
Legal

Privacy Policy

Last updated: June 2026. How Kairos Momenta collects, uses, and protects your personal data.

1. Overview

Kairos Momenta Travel Agency LLC (“Kairos Momenta”, “we”, “us”) operates a travel technology platform that aggregates flights, stays, and car rental inventory from airlines, hotel groups, consolidators, and GDS providers. This policy explains what personal data we collect, why we collect it, how we use it, and the rights you have over it.

This policy applies to all visitors and registered users of kairosmomenta.com and to travelers who complete bookings through our platform. By using our services, you consent to the practices described here.

2. Data controller

Kairos Momenta Travel Agency LLC is the data controller for personal data processed in the United States. Our regional hub, KairoNexus Voyages Limited, acts as a data processor for personal data processed in Uganda and the broader East African Community.

For all GDPR and CCPA requests, the lead supervisory authority is the relevant data protection authority in the user's jurisdiction. Our Data Protection Officer can be reached at dpo@kairosmomenta.com.

3. Data we collect

We collect the following categories of personal data:

  • Account data — name, email, hashed password, optional profile image, account role.
  • Booking data — itinerary details, passenger information, contact details, booking references.
  • Search data — origin, destination, dates, and filters entered into our booking widget.
  • Support data — case numbers, message content, and correspondence with our support team.
  • Usage data — anonymized analytics, IP address, device type, and browser fingerprint.
  • Payment data — handled exclusively by our PCI-DSS Level 1 processor; we retain only the last four digits and a card fingerprint.

4. How we use your data

We use personal data for the following purposes:

  • To operate the booking platform and confirm reservations.
  • To communicate itinerary updates, gate changes, and cancellations.
  • To provide customer support and resolve disputes.
  • To improve search relevance, autocomplete, and fare ranking.
  • To detect and prevent fraud, abuse, and unauthorized access.
  • To send marketing communications where you have opted in.
  • To comply with legal, tax, and aviation record-keeping obligations.

6. Sharing and disclosure

We share personal data only with the categories of recipients necessary to deliver the service:

  • Airlines, hotel groups, and car rental operators to fulfill bookings.
  • GDS providers (Amadeus, Sabre, Travelport) for live inventory.
  • Payment processors (Stripe) for transaction handling.
  • Cloud infrastructure providers (AWS, Cloudflare) for hosting and CDN.
  • Email and SMS providers for transactional and marketing messages.

We never sell personal data. We disclose data to law enforcement only where compelled by valid legal process.

7. International transfers

Kairos Momenta operates across multiple jurisdictions. Personal data may be transferred between the United States, Uganda, and the European Economic Area. Where required, we rely on Standard Contractual Clauses approved by the European Commission, supplemented by transfer impact assessments and technical safeguards such as encryption in transit and at rest.

8. Data retention

We retain personal data for the following periods:

  • Active account data — until you delete your account.
  • Booking records — 7 years for tax and aviation compliance.
  • Support case records — 3 years after resolution.
  • Payment fingerprints — for the lifetime of the account plus 90 days.
  • Marketing consent — until you unsubscribe, plus 30 days.

9. Security architecture

Security is designed into our infrastructure, not bolted on. Our architecture includes:

  • TLS 1.3 for all data in transit.
  • AES-256 encryption for data at rest.
  • PCI-DSS Level 1 compliant payment handling.
  • Bcrypt password hashing with a work factor of 10.
  • Principle-of-least-privilege access controls and audit logging.
  • Quarterly third-party penetration testing.

10. Cookies and tracking

We use cookies for authentication, session continuity, and anonymized analytics. We do not use cookies for cross-site advertising. You can manage cookies through your browser settings or our cookie preferences banner.

11. Your GDPR rights

If you are in the EEA or UK, you have the right to:

  • Access the personal data we hold about you (Article 15).
  • Rectify inaccurate or incomplete data (Article 16).
  • Erasure of your personal data (Article 17).
  • Restrict processing (Article 18).
  • Data portability (Article 20).
  • Object to processing (Article 21).
  • Withdraw consent at any time (Article 7).

12. Your CCPA rights

If you are a California resident, you have the right to know what personal data we collect, request deletion, request opt-out of sale (we do not sell data), and not be discriminated against for exercising these rights. Submit requests through dpo@kairosmomenta.com.

13. Children's privacy

Our services are not directed to children under 13 (or the applicable age in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

14. Marketing communications

We send marketing emails only to subscribers who complete our double opt-in flow. You can unsubscribe at any time using the link in every email or through your account settings.

15. Payment processing

Payment card data is tokenized at the point of entry by our PCI-DSS Level 1 processor and never touches our infrastructure in raw form. We retain only the last four digits and a card fingerprint for fraud detection and refund routing.

17. Changes to this policy

We may update this policy from time to time. Material changes will be announced at least 30 days before they take effect. The “last updated” date at the top of this page reflects the most recent revision.

18. Contacting the DPO

Our Data Protection Officer can be reached at dpo@kairosmomenta.com for privacy questions, data subject requests, and direct legal correspondence. We acknowledge all requests within 72 hours and respond within 30 days.