DEEM Global Privacy Notice
This Global Privacy Notice applies to (i) individuals who visit Deem’s websites (“Visitors”), (ii) employees and individual contractors of companies who use Deem services either via a contract directly with Deem or via an authorized Deem re-seller (companies that use Deem services being Deem’s “Customers” for the purposes of this Global Privacy Notice) who book travel via our product and services (“Travelers”) and (iii) business contacts at our customers, our vendors who provide us with services, and other companies which we may have a commercial relationship with (collectively “Business Contacts”). This Global Privacy Notice does not cover how we process Personal Data of job applicants (click here to view our Careers Privacy Notice).
Our privacy practices may vary among the countries and US states in which we operate or in which you reside to reflect local practices and legal requirements.
If you have any questions regarding Deem’s Global Privacy Notice or associated practices, please contact us at privacy@deem.com.
Personal Data We Collect
We collect and process personal information with your consent or as required to meet our legitimate obligations such as providing services to our customers, meet our contractual and legal requirements, ensure compliance, and protect the security of our systems and customers.
If you are a Traveler, we may collect and process the following Personal Data about you:
- Name
- Email address
- Date of birth
- Gender
- Marital status
- Customer employee ID number
- Languages spoken/preferences
- Home address
- Phone number
- Business address
- Business phone number
- Credit/debit card information
- Geolocation (if using a Deem mobile app)
- Name of employer
- Travel itinerary details
- Passport number
- Visa details
- Wheelchair request/allergies/disability information or religious requests e.g. special meal required
- Corporate loyalty program details
- Emergency contact details
- Information from customer's financial or human resources systems where applicable
If you are a Visitor of our websites and mobile applications, or a Business Contact at our customers or vendors, we may collect and process the following Personal Data about you:
- Contact information such as name, phone number, and email address
- Customer Ordering & Support Data such as details of enquiries raised and transaction details (such as details of services ordered)
- Marketing and Communications Data including your marketing and communication preferences, responses to surveys and feedback on our product and services
- Technical Data such as username and other log-in information, IP address and other online identifiers, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our websites, applications and products,
- Website Usage Data such as information about how you use our websites, products, applications and services, dates, times and duration of visits to our sites (including whether you are a repeat or first-time visitor), and log data.
- Location information, such as the real-time geographic location of the device on which you install our mobile applications based on your consent
Sensitive Data
We do not usually collect any Sensitive Data about you (this may include details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation,political opinions, trade union membership, information about your health, and genetic and biometric data). In some cases, travel bookings may contain Sensitive Data about Travelers if this information is inputted into the booking by you (e.g. dietary conditions or accessibility requirements which may reveal a health condition). You provide your consent to the processing of Sensitive Data when inputting it into the booking.
We also do not collect information about criminal convictions and offences about you.
How we collect and use your Personal Data
We will only collect and process Personal Data where we have a lawful basis to do so. We process your Personal Data based on:
- the performance of a contract that we have entered into or are about to enter into with our Customers (your employer or a travel management company your employer has engaged with).
- our legitimate business interests (for example, when we send you market research surveys to analyze how our products and services are used to enable us to improve them in the future).
- your consent to receive marketing communications about our products and services where you have requested them and your consent to process any Sensitive Data you provide to us.
- for compliance with a legal obligation which we are subject to (for example, when you are a Business Contact and we use a third-party provider to carry out background and sanction checks as required under international laws).
We may process your Personal Data without your consent, where this is required or permitted by law.
We may collect your Personal Data from the following sources:
We will only collect and process Personal Data where we have a lawful basis to do so. We process your Personal Data based on:
- the performance of a contract that we have entered into or are about to enter into with our Customers (your employer or a travel management company your employer has engaged with).
- our legitimate business interests (for example, when we send you market research surveys to analyze how our products and services are used to enable us to improve them in the future).
- your consent to receive marketing communications about our products and services where you have requested them and your consent to process any Sensitive Data you provide to us.
- for compliance with a legal obligation which we are subject to (for example, when you are a Business Contact and we use a third-party provider to carry out background and sanction checks as required under international laws).
We may process your Personal Data without your consent, where this is required or permitted by law.
We may collect your Personal Data from the following sources:
- directly from you. For example, when you request information or a service from us, register for a Deem product or provide your Personal Data to us by using one of Deem’s websites or mobile applications or if you interact or communicate with us on social media.
- indirectly from you. For example, when we automatically collect usage details during your interaction with our products or our websites.
- from third parties. For example, from (i) our parent, affiliate or subsidiary companies (ii) travel vendors, including but not limited to Deem customers’ chosen global distribution service provider (GDS), airlines, hotels, rail operators, tour companies, car rental companies, travel insurance or cruise operator or other travel providers that may make their content available via the Services, (iii) our Customers that obtain our products and services for use by their customers or employees (such as your employer that uses our Services), (iv) our service providers that provide services on our behalf (such as sub-contractors in technical, payment and delivery services, analytics providers, search information providers, credit reference agencies, providers of background information and sanction checking tools), which may provide some of your Personal Data to us, (v) lead generation companies as a source of information for business contact information where permitted by law, (vi) from social media websites through which you may access our sites or communicate with us.
We collect and use your Personal Data for the following business purposes:
Manage travel bookings: to process travel bookings and expense reporting on behalf of our Customers; travel confirmations and other service-related communications; perform billing and accounting functions related to the travel and provide Deem’s Customers with information regarding transactions completed by their employees or customers using Deem.
Communication and customer support: to communicate with you to carry out our contractual obligations; provide you with product updates, product patches and fixes, provide you with product customizations and other similar operational communications; to send notices about changes to our terms, conditions and policies; to provide you with helpdesk and other customer support services.
Marketing: to communicate with you about new products and services, events, promotional and advertising materials that may be useful, relevant, or otherwise of interest to you; to administer surveys and questionnaires, or new competitions or sales promotions that you may enter; analyze and enhance our marketing communications and strategies (including by identifying when emails sent to you have been received and read).
Perform internal business processes: to conduct billing and accounting functions; quality assurance, testing, research, for analytics and statistical purposes (for example, using aggregated data to analyze travel trends); for product development and enhancement and for other internal business processes.
Operation of our websites and products: to operate and manage our websites and products; providing content to you, including analyzing trends and statistics regarding Visitors' use of our websites and mobile applications, and the transactions visitors conduct on our websites; displaying advertising and other information to you; and communicating and interacting with you via our websites and products.
IT security: for the management of our systems (including login records and access details, where you access our systems); to conduct IT security audits; to detect and manage vulnerabilities and security incidents.
Risk management and fraud prevention: for audit, compliance vendor management and other risk management purposes; for loss prevention and anti-fraud activities.
Legal compliance and investigations: to detect, investigate and prevent illegal or fraudulent activity in accordance with applicable laws; to ensure compliance with our legal and regulatory obligations under applicable laws and with industry standards; to establish, exercise and defend our legal rights; to comply with lawful requests received from law enforcement agencies, public and regulatory authorities or other organizations.
Corporate transactions: to carry out re-organizations, mergers, joint ventures, acquisitions, and other similar business operations.
Deem will not collect additional categories of Personal Data or use the Personal Data we collected for materially different, unrelated, or incompatible purposes without providing you with notice.
Cookies
Deem uses cookies and similar technologies within its websites and products to carry out user analytics which we use to improve the user experience of those who use our products and services. We also use cookies to record user sessions in our products and services to assist with trouble shooting and improve our customer’s experiences in using our products. For more information about the cookies we use, please see our Cookie Policy.
Disclosure of your Personal Data
We may disclose your Personal Data to the following categories of third parties:
- to other group companies, as required for business administration purposes.
- to travel vendors such as GDS providers and travel suppliers who are involved in the fulfillment of travel-related services for you, such as airlines, hotels, travel agencies, car rental companies, car and taxi services, reservation aggregators and other merchants.
Many of the Deem products and services are designed to facilitate and enhance consumers' ability to interact with and obtain products and services from third parties. This business model requires Deem to share information about you with various travel vendors and other third parties. These third parties are not our service providers or agents; they may process the Personal Data that we provide to them in accordance with their own privacy practices and privacy notices. If you are using Deem products or services that a Deem business customer (such as your employer) obtained on your behalf, you must contact the relevant business customer to deactivate your account.
- to service providers who process your Personal Data on our behalf to help us provide our products and services, such as suppliers of software development services, business processing service providers, contact center service providers, training providers, market research companies, marketing and branding agencies who help us with our website maintenance and marketing campaigns, computer maintenance providers, third party providers of credit card processing, authentication and fraud prevention services.
- to third–party social networking and media websites, such as Facebook and LinkedIn, for marketing and advertising on those websites.
- to law enforcement agencies, public and regulatory authorities or other organizations to answer their lawful requests or to comply with a judicial proceeding, court order, or legal process; or as otherwise required or permitted by law, subpoena, or regulation.
When we use de-identified data (as defined by applicable US privacy laws), we maintain it in de-identified form, and we do not attempt to re-identify the information.
We do not sell Personal Data for the purpose of allowing third parties to conduct direct marketing for their own products or services.
Unless described in this Global Privacy Notice, Deem does not share, sell, rent, or trade any information with third parties for their promotional purposes.
International Transfers of Personal Data
Deem stores Personal Data on servers in the United States. Your Personal Data may also be processed by staff operating in other countries who work for us or for one of our vendors.
Depending on your country of residence, your Personal Data may be processed and stored outside of the country where you are located. Certain data protection rules may apply to the cross-border transfer of your Personal Data. If you are an employee, an individual contractor or a customer of one of Deem’s customers and Deem is holding your Personal Data on their behalf, the transfer of your Personal Data to Deem will rely on the safeguards put in place by Deem’s customer who can provide more information on their respective safeguards.
In the event that Deem transfers Personal Data of users in the EEA or the UK to a country outside of the EEA/UK which does not have an adequacy decision it will implement appropriate safeguards for the transfer.
Marketing Emails
Deem sends you marketing, promotion and sales emails only with your prior consent. You may tailor your marketing preferences or choose not to receive marketing email communications from us by clicking on the unsubscribe link in the marketing emails you receive from us or by visiting here.
Links to Other Web Sites
The Deem website may provide links to third-party websites for your convenience and information. If you access those links, you will leave the Deem website. Deem does not control those sites or their privacy practices, which may differ from Deem's practices. We do not endorse or make any representations about third-party websites. The personal information you choose to provide to or that is collected by these third-party websites is not covered by this Global Privacy Notice. We encourage you to review the privacy policy of any company before submitting your personal information.
Data Retention
We retain Personal Data no longer than is necessary to comply with legal obligations and to fulfil legitimate business and compliance purposes.
Your Privacy Rights
Data privacy laws in the EU, UK, US and some other countries grant individuals privacy rights regarding their Personal Data.
Depending on where you live, in certain circumstances and subject to certain exceptions, you may have some or all the following privacy rights:
- Right to request access to your personal data – you may have the right to request access to the Personal Data we hold about you.
- Right of Rectification – you may have the right to request correction of the Personal Data that we hold about you where it is incomplete or inaccurate.
- Right of Erasure – under data protection laws you may have the right to ask us to erase or remove your Personal Data where there is no good reason for us to continue to process it. You also have the right to ask us to delete or remove your Personal Data where you have successfully exercised your Right to Object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your Personal Data to comply with local law. Please note that we may not always be able to comply with your request for erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
- Right of Portability – you may have the right to obtain and reuse the Personal Data that you have provided to us.
- Right to Restrict – you may have the right to ‘block’ or suppress the processing by us of your Personal Data in certain circumstances.
- Right to Object – you may have the right to object to the processing of your own Personal Data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You may also have the right to object where we are processing your Personal Data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
- Right to withdraw consent – you may have the right to withdraw consent at any time where we are relying on consent to process your Personal Data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
- Right to non-discrimination - you may have the right not to receive discriminatory treatment for exercising your privacy rights.
- Right to opt-out - you may have the right to opt-out of the sale and/or sharing of your Personal Data (as “sale” and “share” are defined in applicable data protection laws), the right to opt-out of the processing of your Personal Data for purposes of profiling and/or for purposes of targeted advertising.
- Right to limit the use and disclosure of your sensitive Personal Data processed for purposes authorized by applicable data protection laws.
These rights only apply in certain circumstances.
If you are an employee, an individual contractor or a customer of one of Deem’s customers and Deem is holding your Personal Data on their behalf, you must contact your company to exercise any of these rights or if you have questions about them. Please note that if you contact Deem direct to exercise one of these rights, we will need to inform your employer as the data controller for your Personal Data.
Any requests to exercise these rights, questions or complaints relating to your Personal Data should be directed to Deem at privacy@deem.com or to the Legal Department at the addresses specified below. Deem retains the right to use reasonable measures to authenticate the identity of any person who makes a request in respect of their Personal Data or otherwise raises any questions.
Once we receive your inquiry, we will investigate the matter and respond to you promptly and within applicable legal timelines if any.
Deem c/o Travelport
One Axis Park, 10 Hurricane Way
Langley, Berkshire SL3 8AG
Attention: Legal Department.
T: +44 (0) 1753 288000
F: +44 (0) 1753 288001
OR
Deem c/o Travelport
300 Galleria Parkway
Atlanta, Georgia 30339
USA
Attention: Legal Department.
T: +1 770 563 7400
F: +1 770 563 7878
Children's Privacy
Deem does not knowingly collect information from children under the age of 13 and does not target its websites to children under 13. If we learn that a user is under 13 years of age, we will promptly delete any personal data that the individual has provided to us. We encourage parents and guardians to take an active role in their children's online activities and interests.
Updates and Effective Date
This Global Privacy Notice may be updated periodically and without prior notice to you to reflect changes in our personal information practices. We will post a prominent notice on our websites to notify you of any significant changes to our Global Privacy Notice and indicate at the bottom of the notice when it was most recently updated. Your continued use of our Services (directly or indirectly) following the posting of changes to our Global Privacy Notice constitutes your acceptance of such changes.
Effective Date: This Global Privacy Notice was last updated 10 June 2025.
Previous version can be accessed here.