1. Overview
Kairos Momenta Travel Agency LLC (“Kairos Momenta”, “we”, “us”) operates a travel technology platform that aggregates flights, stays, and car rental inventory from airlines, hotel groups, consolidators, and GDS providers. This policy explains what personal data we collect, why we collect it, how we use it, and the rights you have over it.
This policy applies to all visitors and registered users of kairosmomenta.com and to travelers who complete bookings through our platform. By using our services, you consent to the practices described here.
2. Data controller
Kairos Momenta Travel Agency LLC is the data controller for personal data processed in the United States. Our regional hub, KairoNexus Voyages Limited, acts as a data processor for personal data processed in Uganda and the broader East African Community.
For all GDPR and CCPA requests, the lead supervisory authority is the relevant data protection authority in the user's jurisdiction. Our Data Protection Officer can be reached at dpo@kairosmomenta.com.
3. Data we collect
We collect the following categories of personal data:
- Account data — name, email, hashed password, optional profile image, account role.
- Booking data — itinerary details, passenger information, contact details, booking references.
- Search data — origin, destination, dates, and filters entered into our booking widget.
- Support data — case numbers, message content, and correspondence with our support team.
- Usage data — anonymized analytics, IP address, device type, and browser fingerprint.
- Payment data — handled exclusively by our PCI-DSS Level 1 processor; we retain only the last four digits and a card fingerprint.
4. How we use your data
We use personal data for the following purposes:
- To operate the booking platform and confirm reservations.
- To communicate itinerary updates, gate changes, and cancellations.
- To provide customer support and resolve disputes.
- To improve search relevance, autocomplete, and fare ranking.
- To detect and prevent fraud, abuse, and unauthorized access.
- To send marketing communications where you have opted in.
- To comply with legal, tax, and aviation record-keeping obligations.
5. Legal basis for processing
Under GDPR Article 6, we process personal data on the following legal bases:
- Contract — to fulfill bookings and provide the service you requested.
- Legal obligation — to maintain records required by tax, aviation, and anti-money-laundering law.
- Consent — for marketing communications and optional analytics cookies.
- Legitimate interest — for fraud detection and platform security, balanced against your privacy rights.
7. International transfers
Kairos Momenta operates across multiple jurisdictions. Personal data may be transferred between the United States, Uganda, and the European Economic Area. Where required, we rely on Standard Contractual Clauses approved by the European Commission, supplemented by transfer impact assessments and technical safeguards such as encryption in transit and at rest.
8. Data retention
We retain personal data for the following periods:
- Active account data — until you delete your account.
- Booking records — 7 years for tax and aviation compliance.
- Support case records — 3 years after resolution.
- Payment fingerprints — for the lifetime of the account plus 90 days.
- Marketing consent — until you unsubscribe, plus 30 days.
9. Security architecture
Security is designed into our infrastructure, not bolted on. Our architecture includes:
- TLS 1.3 for all data in transit.
- AES-256 encryption for data at rest.
- PCI-DSS Level 1 compliant payment handling.
- Bcrypt password hashing with a work factor of 10.
- Principle-of-least-privilege access controls and audit logging.
- Quarterly third-party penetration testing.
11. Your GDPR rights
If you are in the EEA or UK, you have the right to:
- Access the personal data we hold about you (Article 15).
- Rectify inaccurate or incomplete data (Article 16).
- Erasure of your personal data (Article 17).
- Restrict processing (Article 18).
- Data portability (Article 20).
- Object to processing (Article 21).
- Withdraw consent at any time (Article 7).
12. Your CCPA rights
If you are a California resident, you have the right to know what personal data we collect, request deletion, request opt-out of sale (we do not sell data), and not be discriminated against for exercising these rights. Submit requests through dpo@kairosmomenta.com.
13. Children's privacy
Our services are not directed to children under 13 (or the applicable age in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
14. Marketing communications
We send marketing emails only to subscribers who complete our double opt-in flow. You can unsubscribe at any time using the link in every email or through your account settings.
15. Payment processing
Payment card data is tokenized at the point of entry by our PCI-DSS Level 1 processor and never touches our infrastructure in raw form. We retain only the last four digits and a card fingerprint for fraud detection and refund routing.
16. Third-party links
Our platform links to airlines, hotels, and consolidators. Their privacy practices are governed by their own policies, not this one. We encourage you to review their policies before submitting personal data.
17. Changes to this policy
We may update this policy from time to time. Material changes will be announced at least 30 days before they take effect. The “last updated” date at the top of this page reflects the most recent revision.
18. Contacting the DPO
Our Data Protection Officer can be reached at dpo@kairosmomenta.com for privacy questions, data subject requests, and direct legal correspondence. We acknowledge all requests within 72 hours and respond within 30 days.