PRIVACY POLICY FOR WORKTRIPS BUSINESS TRAVEL
1. Introduction
This WorkTrips business travel privacy policy (“Policy”) describes the rules for processing personal data in connection with the use of the WorkTrips platform and the handling of business travel arranged through it. In particular, we explain what personal data we process, for what purposes and on what legal bases, to whom the data may be disclosed, how long it is retained, and what rights are available to data subjects.
WorkTrips provides corporate clients with access to an IT system in a SaaS model, enabling the organisation of business travel, in particular the search and booking of accommodation, flights, rail journeys and other travel-related services (“Platform”). The Platform is made available to persons indicated by the corporate client (“Partner”).
In connection with the use of the Platform, the roles of the participants in the data processing process depend on the purpose and stage of processing. With respect to personal data entered into the Platform before a booking is made in order to enable use of the Platform or organise business travel, the Partner (or, as applicable, the Group Entity) remains the data controller, while WorkTrips acts as a processor within the meaning of Article 28 GDPR.
From the moment a booking is made, WorkTrips acts as a separate controller of personal data to the extent necessary to handle the booking, issue vouchers, settlements, changes, cancellations, complaints and to perform legal obligations related to the booking. WorkTrips is also the controller of personal data processed in connection with the conclusion and performance of the agreement with the Partner, settlements, accounting and tax obligations, complaints handling and ensuring the security of the Platform.
2. Personal data controller
The controller of personal data within the scope described in this Policy is WorkTrips spółka z ograniczoną odpowiedzialnością with its registered office in Poznań (60–603), Poland,
Al. Wielkopolska 67/3, entered in the register of entrepreneurs kept by the District Court
Poznań – Nowe Miasto and Wilda in Poznań, 8th Commercial Division of the National Court Register under KRS number 0000952583, NIP 7812031945, REGON 521168839, share capital PLN 5,000.00, hereinafter referred to as the “Company” or “WorkTrips”.
For matters concerning the processing of your personal data, you may contact us by e-mail
at: rodo@worktrips.com or in writing to the Company’s registered office address.
WorkTrips is the controller of personal data only to the extent that the data is processed for its own purposes and personal data is related to booking handling from the moment the booking is made.
In particular, WorkTrips acts as the controller of personal data in connection with:
- handling bookings, issuing vouchers, settlements, handling changes, cancellations and complaints, and performing legal obligations related to bookings;
- concluding and performing the agreement with the Partner;
- fulfilling accounting and tax obligations;
- handling complaints;
- ensuring the security of the Platform.
With respect to personal data entered into the Platform before a booking is made, the Partner remains the data controller, while WorkTrips acts as a processor within the meaning of Article 28 GDPR.
The Partner may also process personal data for its own purposes, in particular in connection with organising business travel and settling expenses, personnel management or monitoring compliance with applicable internal policies. In this respect, the Partner remains a separate controller of personal data.
3. Who does this Policy apply to?
This Policy applies to all persons whose personal data is processed by WorkTrips in connection with the operation of the Platform. Data may be obtained directly from the data subject or from the Partner or persons acting on its behalf (details in Section 4). Depending on how the data is entered into the Platform, we distinguish the following categories of data subjects:
3.1. Users with access to the Platform
Persons who have a user account and access to the Platform. This includes both persons who organise business travel themselves and persons with administrative rights, e.g. to make bookings for other persons, manage user profiles, approve travel or configure the Partner’s settings. One person may hold more than one of the above roles, and the scope of available features and permissions depends on the Platform configuration adopted by the Partner.
3.2. Users without access to the Platform
Persons whose data has been entered into the Platform by the Partner or a person acting on its behalf, without creating a user account. Such persons do not have an account or access to the Platform, and their data is processed for the purpose of organising business travel on their behalf.
3.3. Guests
Persons added to a specific booking without previously creating a profile in the Platform. Guests do not have an account or access to the Platform. Their data is used for the purposes of the given booking. If necessary to organise subsequent business travel, a guest’s data may be saved in the Platform as a user profile without access to the Platform, in accordance with the Partner’s configuration and instructions.
4. Scope of collected personal data
In connection with the operation of the Platform, we process personal data to an extent depending on the person’s role, the type of services booked, the Platform configuration adopted by the Partner and the requirements of travel service providers. We disclose data only to the extent necessary to provide a given service or booking.
Providing basic data (first name, surname, e-mail address, telephone number) is necessary to create a profile or make a booking. Providing additional data (e.g. date of birth, travel document details) is voluntary when creating the profile, but may be required for a specific booking if this results from the nature of the service, the provider’s requirements or the booking channel. In that case, the Platform informs the user during the booking process that specific data must be supplemented.
The Platform is not intended for collecting special categories of data within the meaning of Article 9 GDPR. Please do not provide such data unless it is necessary to provide a specific travel service. If such data is exceptionally provided, it will be processed only to the extent necessary to fulfil the reported need and on the appropriate legal grounds set out in Article 9(2) GDPR.
We process the following categories of data:
4.1. Identification and contact details
First name and surname, e-mail address, telephone number.
4.2. Traveller profile data
Data provided by the user or entered by the Partner, in particular: date of birth, gender, nationality, travel document details, loyalty programme details, travel preferences and other information required to carry out a specific trip.
WorkTrips does not store scans or photographs of identity documents.
4.3. Booking, travel and organisational data
Data related to searching, booking, changing, cancelling and carrying out travel, in particular information on the route, dates, booking and ticket numbers, type of service, booking status and travel-related documents such as tickets, vouchers, booking confirmations, insurance policies and settlement documents.
The Platform may also process organisational data assigned by the Partner, such as department, position, cost centre, project, employee identifier and information concerning travel policy and approval paths.
4.4. Financial and settlement data
Information on the payment method assigned to the booking, booking value, costs of individual services, payment status and limited transaction data (e.g. transaction identifier). As a rule, WorkTrips does not process full payment card data. If payment is made through an external payment service provider, payment instrument data is processed in that provider’s systems.
4.5. Data from communication with support staff
The content of correspondence, requests, attachments and information concerning the course and handling of the matter.
4.6. Technical and security data
Data related to the use of the Platform and ensuring its security, in particular user identifier, assigned role and scope of permissions, IP address, session and device identifiers, information on the browser and operating system used, activity logs and error data. The rules concerning cookies and similar technologies are described in a separate section.
4.7. Location data
The Platform offers a volutnary location-sharing feature (Traveller tracker). If the user enables this function, WorkTrips processes data on the user’s current position (GPS), visible only to authorised persons on the Partner’s side. The function may be disabled at any time without affecting the ability to use the Platform. Location data is not transferred to travel service providers. Detailed information on the legal bases and rules for processing location data is provided in Section 5.
5. Source of personal data
5.1. Data obtained directly from you
If you are a user with access to the Platform (Section 3.1), you provide some of the data yourself – during registration, when completing your traveller profile, making bookings, using Platform functionalities or contacting WorkTrips support.
We provide the information required under Article 13 GDPR in connection with obtaining data – in particular when access to the Platform is first granted, within this Policy, and with respect to optional functions or additional categories of data – also in the context of using those functions.
5.2. Data obtained from the Partner or persons acting on its behalf
If you are a user without access to the Platform (Section 3.2) or a guest (Section 3.3), your data has been provided to the Platform by the Partner or a person acting on its behalf (e.g. a person with administrative rights or another person making a booking on behalf of the Partner).
Some data of a user with access to the Platform may also come from the Partner – e.g. business e-mail address, organisational data or information needed to configure the profile.
The Partner, as a separate controller with respect to its own operations, should have an appropriate legal basis for providing data to WorkTrips and should inform the persons whose data it provides. This does not exclude the information obligations performed by WorkTrips in accordance with applicable provisions. The legal nature of the transfer of data between the Partner and WorkTrips depends on the purpose and stage of processing and the roles of the parties described in Section 1. In particular, with respect to personal data processed by WorkTrips as a processor, the transfer of data takes place as part of entrusting processing in accordance with Article 28 GDPR, whereas in the case of processing by the Partner and WorkTrips as separate controllers, it may constitute disclosure of data between independent controllers.
5.3. Data obtained from identity or authentication service providers
If logging into the Platform takes place using an external identity provider (the Partner’s SSO or a Google account), we may receive from such provider the data necessary for authentication and account linking – e.g. user identifier, first name and surname, e-mail address, organisation name – to the extent depending on the configuration of the solution and the scope of data made available by the provider.
5.4. Performance of the information obligation by WorkTrips
If we obtain personal data not directly from you, we perform our information obligation in accordance with Article 14 GDPR by providing or making available information on processing in a manner appropriate to the circumstances in which the data was obtained. In the case of business travel, the Partner should provide you with information concerning the processing of personal data related to organising business travel and using the Platform.
If you believe that you have not received sufficient information about the processing of your data, you may contact WorkTrips directly to obtain full information and exercise the rights described in Section 10.
6. Purposes of data processing and legal bases
The purposes and legal bases described in this Section apply only to cases where WorkTrips acts as the controller of personal data. To the extent that WorkTrips processes personal data on behalf of the Partner as a processor, the purposes and legal bases of processing are determined by the Partner as the data controller.
As the Controller, we process your personal data only for specified, explicit and legitimate purposes, on the legal bases indicated below.
Where processing is based on WorkTrips’ legitimate interest (Article 6(1)(f) GDPR), we have assessed whether our interest does not override your rights and freedoms. You have the right to object to such processing at any time – details are provided in Section 10.
6.1. User account management
Creating and maintaining user accounts, authentication, access management, assigning and enforcing roles and permissions, identifying users within the Platform and ensuring access security.
Legal basis: Article 6(1)(f) GDPR – WorkTrips’ legitimate interest in enabling the Partner and users authorised by the Partner to use the Platform for the purpose of organising business travel.
6.2. Organisation of business travel
Organising business travel, in particular making bookings, transferring data to travel service providers and booking intermediaries to the extent necessary to fulfil the booking, handling changes and cancellations and providing travel-related services.
For this purpose, we may also use organisational data provided by the Partner and operate Platform configuration mechanisms set by the Partner (in particular travel policies, cost limits, approval paths and assignment of costs to the Partner’s organisational structures).
Legal basis: Article 6(1)(f) GDPR – WorkTrips’ legitimate interest in enabling the organisation of business travel within the Platform.
6.3. Handling loyalty programmes
Transferring loyalty programme data to service providers in order to accrue points or use programme benefits. Providing loyalty programme data is entirely voluntary and does not affect the ability to make a booking.
Legal basis: Article 6(1)(f) GDPR – WorkTrips’ legitimate interest in improving travel handling in accordance with the data provided by the user or by a person authorised by the Partner.
6.4. Operational communication and support
Sending booking confirmations, travel documents, change notifications, handling requests and enquiries, and contacting users in matters related to travel performance.
Legal basis: Article 6(1)(f) GDPR – WorkTrips’ legitimate interest in ensuring continuity of travel handling and an appropriate quality of support.
6.5. Settlements and payment handling
Assigning costs to the Partner’s organisational structures, preparing settlement statements, verifying payment statuses, handling corrections and refunds.
Legal basis: Article 6(1)(f) GDPR – WorkTrips’ legitimate interest in properly settling services with the Partner.
6.6. Accounting and tax documentation
Processing data contained in accounting and tax documents (invoices, payment confirmations, settlement documents) to the extent and for the period required by law, in particular accounting and public-law receivables regulations.
Legal basis: Article 6(1)(c) GDPR – compliance with a legal obligation to which WorkTrips is subject.
6.7. Platform security
Detecting and preventing unauthorised activities, maintaining security logs, diagnosing failures, creating backups and restoring data after incidents.
Legal basis: Article 6(1)(f) GDPR – WorkTrips’ legitimate interest in ensuring the ICT security of the Platform and data protection.
6.8. Development and improvement of the Platform
Analysing the use of Platform functions, detecting errors, and improving stability and usability. To the broadest extent possible, we use aggregated or anonymised data; if the use of personal data is necessary for analysis, we process it only to the minimum extent necessary.
Legal basis: Article 6(1)(f) GDPR – WorkTrips’ legitimate interest in developing and improving the Platform.
6.9. Compliance with legal obligations
Processing data in order to comply with legal obligations other than accounting and tax obligations – in particular in response to requests from authorised authorities (courts, prosecutor’s offices, police, tax authorities, data protection authority), provided that the request is based on an appropriate legal basis.
Legal basis: Article 6(1)(c) GDPR – compliance with a legal obligation to which WorkTrips is subject.
6.10. Establishment, exercise or defence of claims
Documenting the course of bookings, communication and service performance to the extent necessary to establish, exercise or defend claims.
Legal basis: Article 6(1)(f) GDPR – WorkTrips’ legitimate interest in legal protection.
6.11. Location sharing (Traveller tracker)
If you enable the location-sharing function, WorkTrips processes data concerning your current position (GPS) in order to enable the Traveller tracker functionality. Location is visible only to authorised persons on the Partner’s side who have appropriate permissions.
Enabling this function is entirely voluntary. You may disable it at any time without any consequences. Location sharing also requires confirmation in the browser or on the device.
Only the current location is processed – WorkTrips does not store location history. Location data is not transferred to travel service providers or used to perform bookings.
Legal basis: Article 6(1)(a) GDPR – consent expressed by actively enabling the function. You may withdraw your consent at any time, and withdrawal does not affect the lawfulness of processing carried out before withdrawal.
If, in connection with the organisation of business travel, special categories of data within the meaning of Article 9 GDPR are exceptionally provided, we process them only to the extent necessary to handle the reported need and on the basis of an appropriate condition under Article 9(2) GDPR.
7. Data recipients
In connection with the provision of our services, we may disclose or entrust the processing of your personal data to selected recipients – always, however, only to the minimum extent necessary to achieve a given processing purpose.
7.1. Partner
Data concerning your business travel and bookings is available to the Partner through the Platform functionalities (e.g. administration panel, reports).
Access is granted to persons authorised by the Partner within the scope resulting from the permissions assigned to them.
The Partner is a separate data controller with respect to its own purposes (Section 1).
7.2. Travel service providers
In order to perform bookings, we transfer data to service providers – such as airlines, hotels, rail carriers, vehicle rental companies and insurers – to the extent required to perform a given service. The scope of data depends on the type of service and the provider’s requirements.
As a rule, travel service providers act as separate data controllers.
7.3. Booking intermediaries
In order to provide access to offers from multiple providers, we use booking intermediaries such as global distribution systems (GDS) and offer aggregators. These intermediaries participate in searching offers, making bookings, issuing travel documents and handling changes and cancellations.
With respect to operations carried out in their own systems, these intermediaries generally process data as separate controllers. However, the specific role of a given entity may depend on the cooperation model, type of service and technical architecture of the relevant solution. If, in a specific case, an intermediary processes data solely on WorkTrips’ instructions, we ensure that a data processing agreement is concluded in accordance with Article 28 GDPR.
7.4. Payment service providers
Data necessary to perform payments (e.g. amount, transaction identifier) may be transferred to payment service providers (payment operators, banks). As a rule, payment service providers act as separate data controllers with respect to payment processing and obligations arising from regulations governing the provision of payment services.
7.5. Processors
To the extent necessary to maintain the Platform and provide services, we use providers who process data on our behalf and on our instructions (processors within the meaning of Article 28 GDPR) – in particular providers of IT services, communication services and user support tools. We have concluded a data processing agreement with each such entity. These entities may not use the entrusted data for their own purposes.
7.6. Authentication service provider
If logging in takes place using an external identity provider, including the Partner’s SSO system or a Google account, authentication data is exchanged between the Platform and the provider of the relevant login mechanism to the extent necessary to authenticate the user and ensure access to the Platform.
In the case of login via a Google account, this provider is Google Ireland Limited / Google LLC, which act as separate controllers with respect to account management and authentication processes.
In the case of login via the Partner’s SSO system, the controller of data processed within that system is generally the Partner or the provider of its identity solution, in accordance with the rules applicable in the given authentication environment.
7.7. Public authorities
In cases provided for by law, we may disclose data to public authorities (e.g. courts, prosecutor’s offices, law enforcement authorities, tax authorities, data protection authority) – only within the limits of a legal obligation and on the basis of a request grounded in legal provisions.
7.8. Advisers and professional service providers
To the extent necessary to conduct our business, we may disclose personal data to entities providing professional services to us, in particular law firms, tax advisers, auditors and accounting service providers. These entities process data as separate controllers or processors, depending on the nature of the services provided and the legal basis for processing.
8. Transfers of data outside the EEA
Due to the international nature of business travel and the use of booking intermediaries and IT service providers, your personal data may be transferred to countries outside the European Economic Area (EEA).
8.1. When a transfer may occur
A transfer of data outside the EEA may occur in particular where: a booking intermediary or IT service provider used by us is established outside the EEA or processes data in infrastructure located outside the EEA; you book travel to a country outside the EEA and the data must be transferred to the service provider in that country; you use login with an external identity provider (e.g. a Google account).
8.2. Safeguards applied
Where data is transferred outside the EEA, we apply the mechanisms provided for in Chapter V GDPR, in particular:
- an adequacy decision (Article 45 GDPR) – where the European Commission has found that a third country ensures an adequate level of protection. With respect to entities established in the USA, this applies in particular to entities certified under the EU–US Data Privacy Framework (DPF);
- standard contractual clauses (Article 46(2)(c) GDPR) – adopted by the European Commission, in the module appropriate to the relationship between the parties. In the case of transfers based on SCCs, we assess whether the law of the recipient country does not undermine the effectiveness of the safeguards applied and, where necessary, implement additional protective measures;
- exceptions provided for in Article 49 GDPR – only exceptionally, where the transfer is necessary to perform a specific travel service or booking concerning the given person, and the application of the mechanisms provided for in Chapter V GDPR is not possible or not appropriate in the circumstances.
8.3. Further transfers in the booking chain
Data transferred to booking intermediaries or travel service providers may subsequently be processed or further transferred by those entities in accordance with the rules applicable in their own systems and relationships with further recipients. With respect to such further operations, those entities are responsible as separate controllers for the lawfulness of their own processing.
8.4. Right to information
You have the right to obtain information on the safeguards applied to transfers of data outside the EEA and – to the extent required by law – a copy of the relevant contractual provisions (excluding confidential information). To do so, please contact us (contact details in Section 2).
9. Data retention period
We retain your personal data for the period necessary to achieve the purposes described in Section 6 and then delete or anonymise it. If the same data is used for several purposes for which different retention periods apply, we apply the longest period appropriate for the given dataset. Once the purpose justifying a shorter retention period ceases, the data is no longer used for that purpose.
Retention periods for individual categories of data:
9.1. User profile data (with and without access to the Platform)
We retain profile data for the entire period of activity of the account or profile. After deactivation of the account or profile, in particular in connection with the end of the Partner’s cooperation with WorkTrips, deletion of the profile, termination of the relationship between you and the Partner, or breach of the Platform terms of use, profile data is deleted or anonymised within the retention cycle adopted by WorkTrips, unless further retention is necessary for the reasons indicated in Section 9.6.
9.2. Guest data
If the data was used solely for the purposes of a one-time booking, we retain it until the end of the trip and related settlements, and then delete or anonymise it within the adopted retention cycle. If guest data was subsequently saved as a user profile without access to the Platform (Section 3.2), we apply the rules applicable to profile data referred to in Section 9.1.
9.3. Booking and travel data
We retain booking and travel data for the duration of the agreement with the Partner and then for the period necessary to settle services, handle any complaints, clarify matters related to travel performance and establish, exercise or defend claims.
9.4. Accounting and tax documentation
We retain data contained in accounting and tax documentation for the period required by law, in particular accounting and tax liability regulations.
9.5. Data from communication with support
We retain correspondence, requests and other data related to handling a matter for the period necessary to handle the request and then for the period justified by the need to document the course of handling, clarify the matter and establish, exercise or defend claims.
9.6. Extension of the retention period
After the periods indicated above expire, the data is deleted or anonymised, unless further retention is necessary to establish, exercise or defend claims, comply with a legal obligation or in connection with pending proceedings, an inspection or other explanatory proceedings.
In such cases, we retain the data for the period necessary to achieve the relevant purpose.
9.7. Technical data, logs and backups
We retain technical data and system logs for the period resulting from the need to ensure security, detect incidents, diagnose errors and maintain continuity of Platform operation, in accordance with the retention rules adopted by WorkTrips for technical data. Personal data may also be contained in backup copies of Platform systems. Backups are secured, encrypted and stored with limited access. Data deleted from production systems is removed from backups within the adopted backup rotation cycle.
10. Rights of data subjects
In connection with the processing of your personal data by WorkTrips as a controller, you have the following rights under GDPR:
10.1. Right of access to data
You have the right to obtain confirmation as to whether we process your personal data and, where this is the case, to access it and receive a copy of the personal data undergoing processing.
We will also provide you with information, including on the purposes of processing, categories of data, recipients, planned retention period and the rights available to you.
10.2. Right to rectification
You have the right to request correction of your personal data if it is outdated, incomplete or incorrect.
In many cases, you may update basic profile data yourself by logging into your account on the Platform and editing your profile.
For users who do not have access to the Platform, rectification may be made by contacting us (or through the Partner, who may notify us of the need to update data or change the data independently).
10.3. Right to erasure
In certain situations, you may request erasure of your personal data. You have this right, for example, where: (i) the data is no longer necessary for the purposes for which it was collected, (ii) you have withdrawn consent to processing (to the extent that consent was the basis for processing) and we have no other legal basis, (iii) you have successfully objected to the processing of your data, (iv) the data was processed unlawfully, or (v) there is a legal obligation to erase the data.
Please remember that in some cases we may not be able to erase your data immediately – this mainly applies where processing is still necessary due to our legal obligations (e.g. retention of financial documentation) or for the establishment, exercise or defence of claims. In such a situation, we will inform you of the reasons for refusing to comply with the request and of the expected time of erasure.
10.4. Right to restriction of processing
You have the right to request that we temporarily restrict the processing of your personal data in the following cases: (i) where you contest the accuracy of the data (for a period enabling us to verify its accuracy), (ii) where processing is unlawful but you oppose erasure of the data and request restriction of its use instead, (iii) where we no longer need the data for our purposes but you need it to establish, exercise or defend claims, or (iv) where an objection to processing has been lodged – pending verification whether our overriding interest prevails over the grounds of the objection. During the restriction period, we will only store your data (or use it only to the extent necessary due to claims or legal obligations).
10.5. Right to data portability
To the extent that your data is processed on the basis of your consent or for the performance of a contract with you, and where the processing is carried out by automated means-you have the right to receive from us your personal data in a structured, commonly used and machine-readable format and the right to have us transmit that data directly to another controller, where technically feasible. Due to the operating model of the Platform, this right may apply only to some data or specific features. Please remember that the right to data portability does not cover data processed solely on the basis of our legitimate interest.
10.6. Right to object to processing
You have the right to object at any time – on grounds relating to your particular situation – to the processing of your personal data based on our legitimate interest (Article 6(1)(f) GDPR). After an objection is lodged, we will stop processing your data for these purposes unless we demonstrate compelling legitimate grounds which, under the law, override your interests, rights and freedoms(for example where further processing is necessary to pursue or defend claims).
Please note that accepting an objection to the processing of data necessary to provide certain Platform features may result in your inability to continue using those features or to organise travel through the Platform.
10.7. Right to withdraw consent
If any processing of your data is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal. Within the Platform, we process personal data mainly on other legal bases, as described above, so consent may only concern additional, voluntary functionalities (in which case we will separately ask you for consent).
10.8. Right to lodge a complaint with a supervisory authority
If you believe that we process your personal data unlawfully or infringe your rights, you have the right to lodge a complaint with the competent supervisory authority. In Poland, this authority is the President of the Personal Data Protection Office.
More information on how to lodge a complaint is available on the PUODO website https://uodo.gov.pl/pl/p/kontakt. Before lodging a complaint, however, we encourage you to contact us – we will try to clarify any concerns and improve our actions if, in your opinion, any irregularity has occurred.
To exercise your rights, you may contact us at any time using the contact details provided in Section 2.
11. Cookies and similar technologies
In connection with the use of the Platform, WorkTrips may use cookies and similar technologies. Detailed information on the solutions used by WorkTrips is provided in the Cookie Policy.
12. Changes to the Policy
We may update this Policy in connection with changes in the scope of services, development of the Platform or changes in legal regulations.
The current version of the Policy will be published on our website.
The current version of the Policy is effective from the date of its publication indicated below.
Date of last update: [15.07.2026].


