PRIVACY & COOKIE POLICY

MetroMobilityOps
Amsterdam, The Netherlands
Last Updated: 20 October 2025

1. Introduction

MetroMobilityOps (“we”, “us”, or “our”) operates a managed travel booking and reservation system used by travel providers, mobility planners, and related organisations across Europe and international markets.

Our platform supports continuous booking operations, itinerary coordination, and partner fulfilment workflows. This Privacy & Cookie Policy explains how we collect, use, process, transfer, and protect personal data in accordance with:

  • EU General Data Protection Regulation (GDPR)
  • UK GDPR and Data Protection Act 2018
  • Applicable United States state privacy laws

2. Our Role in the Travel Ecosystem

Data Controller (Corporate & Website Data)
We act as a data controller when processing personal data for our own business operations, including enquiries, commercial engagement, recruitment, and vendor management.

Data Processor (Passenger & Booking Data)
When operating booking and reservation environments on behalf of travel providers, airlines, mobility operators, or agencies, MetroMobilityOps acts as a data processor (or service provider under U.S. law). The client organisation remains the data controller and determines the purpose and lawful basis of processing passenger data.

We process booking-related personal data only under documented contractual instructions.

3. Categories of Personal Data Processed

A. Business & Corporate Contact Data

  • Name
  • Organisation
  • Job title
  • Business email address
  • Business telephone number
  • Correspondence and enquiry information

B. Passenger & Booking Data (Processed on Behalf of Clients)

  • Traveller names
  • Booking reference numbers
  • Itinerary details
  • Travel segments and schedules
  • Partner fulfilment details
  • Contact information associated with reservations
  • Operational notes related to booking fulfilment
  • User access credentials and activity logs

Important: MetroMobilityOps does not independently determine how passenger data is used. We do not use booking data for marketing or profiling.

C. Technical & Platform Data

  • IP address
  • Browser and device information
  • Authentication logs
  • System access timestamps
  • Operational performance metrics

4. Special Category Data

In certain travel contexts, passenger data may include special category data (such as accessibility requirements or health-related travel information).

Where such data is processed:

  • It is processed strictly under client instruction
  • Processing is limited to what is operationally necessary
  • Access is restricted on a role-based basis
  • Enhanced security controls are applied

5. Legal Basis for Processing (EU/UK)

Where we act as controller, processing is based on:

  • Contractual necessity
  • Legitimate business interests
  • Compliance with legal obligations
  • Consent (where required)

Where we act as processor, the legal basis is determined by the client acting as data controller.

6. U.S. Privacy Framework Alignment

Under applicable U.S. state privacy laws:

  • MetroMobilityOps does not sell personal information
  • We do not share personal information for cross-context behavioural advertising
  • We process booking data solely for business purposes under contractual instruction

Where required, individuals may have rights to access, correct, delete, or limit processing of their personal information.

7. Passenger Data Safeguards

Given the operational sensitivity of travel booking data, MetroMobilityOps applies specific safeguards:

  • Encryption of data in transit using industry-standard protocols
  • Encryption or logical protection of data at rest
  • Role-based access control
  • Multi-factor authentication where appropriate
  • Structured logging and monitoring
  • Segregation of client environments
  • Documented incident response procedures

We do not use passenger data for data mining, resale, or analytics beyond operational support and system stability.

8. Data Sharing

We may share personal data only where necessary with:

  • Client organisations (as controllers)
  • Travel fulfilment partners acting under client authority
  • Secure hosting providers
  • Technology service providers
  • Professional advisers
  • Regulators where legally required

All third parties are subject to contractual confidentiality and data protection obligations.

9. International Transfers

Travel operations frequently involve cross-border coordination.

Where personal data is transferred outside the European Economic Area or the United Kingdom, we rely on:

  • Standard Contractual Clauses (SCCs)
  • UK International Data Transfer Agreements (IDTAs)
  • Adequacy decisions (where applicable)
  • Contractual processor obligations aligned with GDPR

10. Data Retention

We retain personal data only for as long as necessary to:

  • Provide contracted services
  • Maintain operational integrity
  • Comply with legal obligations

Passenger and booking data retention periods are governed by client contracts and applicable regulatory requirements.

11. Data Subject Rights (EU & UK)

Where applicable, individuals have the right to:

  • Access their personal data
  • Request rectification
  • Request erasure
  • Restrict or object to processing
  • Data portability
  • Lodge a complaint with a supervisory authority

Requests relating to booking data should generally be directed first to the travel provider or booking organisation acting as data controller.

12. Cookies

Our website uses cookies to ensure security, functionality, and service improvement.

13. Types of Cookies

Essential Cookies – Required for site operation and security.

Analytics Cookies – Used to improve clarity and usability. Deployed only with consent where legally required.

Marketing Cookies – We do not use behavioural advertising cookies.

14. Managing Cookie Preferences

Users may manage cookie preferences via our cookie banner or browser settings. Consent can be withdrawn at any time.

15. Security Governance

MetroMobilityOps maintains documented internal policies covering:

  • Access control
  • Incident response
  • Vendor management
  • Change management
  • Business continuity

Security controls are designed to support continuous booking operations without compromising data protection standards.

16. Children’s Data

Our services are directed at travel organisations and professionals. We do not directly market to or intentionally collect data from children via our website.

17. Updates

This Privacy & Cookie Policy may be updated periodically. The latest version will always be available on our website with the updated revision date.

18. Contact

For privacy-related enquiries:
privacy@metromobilityops.com
Amsterdam, The Netherlands