Privacy Policy
This policy explains how Jentix handles personal data, in both of the capacities in which we operate. Where terms like "Jentix", "we", "us" and "our" are used, they refer to Jentix Ltd.
1Who we are
Jentix is a travel data analytics platform provided by Jentix Ltd, a company registered in England and Wales (company number 16873303), with its registered office at 82a James Carter Road, Bury St. Edmunds, IP28 7DE ("Jentix", "we", "us", "our").
We are registered with the Information Commissioner's Office (ICO), registration number ZC188184.
For any questions about this policy or about how we handle personal data, contact us at tyrone@jentix.co.uk.
2About this policy and our two roles
Jentix handles personal data in two different capacities, and it is important to understand which applies to you.
For some people, we are the data controller — meaning we decide how and why their data is used. This applies to visitors to our website, the individual users who hold login accounts on the Jentix platform, and the business and billing contacts of the organisations we work with. This policy explains what we do with that data.
For traveller and booking data, we act as a data processor. When a travel management company or travel agency uses Jentix to analyse its booking data, that organisation is the data controller and decides how the data is used; we simply process it on their documented instructions to provide our service. If you are a traveller whose booking information appears in Jentix, the travel management company that made your booking is responsible for your data, and you should contact them to exercise your rights or ask questions about it. We explain this further in section 8.
3The personal data we collect, and why
If you visit our website, we may collect limited technical information such as your IP address and basic usage information necessary to operate and secure the site, together with any details you choose to give us when you contact us or make an enquiry (such as your name, email address, and the content of your message). We use this to respond to you and to run and protect our website.
If you are a user of the Jentix platform, we collect your name, email address, login credentials, and records of your activity within the platform. This includes security and audit logs: we record sign-ins and failed sign-in attempts (with the IP address they came from), and changes made to settings, permissions and other configuration, attributed to the account that made them. We use this to give you access to the service, to keep your account and your organisation's data secure, to investigate suspected misuse, to provide support, and to operate the platform properly.
If a travel management company shares a secure report link with you, we record the email address the link is issued to and, when the link is opened, the time and IP address of the access. We use this to keep shared reports secure and to show the issuing organisation that their report reached the right recipient.
If you are a business or billing contact of an organisation we work with, we collect your name, work contact details, and any billing information needed to administer the agreement and issue invoices. We use this to manage our relationship with your organisation, provide support, and handle billing.
4Our legal bases for processing
Where we act as controller, we rely on the following legal bases under UK data protection law. We process data to perform our contract with you or your organisation, or to take steps at your request before entering into a contract. We rely on our legitimate interests to operate, secure, support and improve our service — including security monitoring, audit logging and fraud prevention — to manage our business relationships, and to respond to enquiries, provided those interests are not overridden by your rights. Where we are required to, we process data to comply with a legal obligation. Where we rely on consent, you may withdraw it at any time.
5Who we share your data with
We do not sell your personal data, and we do not share it with advertising networks. We do not use third-party advertising or third-party analytics services.
We do use a small number of trusted service providers ("sub-processors") to run our platform:
- Railway — application hosting EU · Amsterdam
- Neon — database hosting UK · London
- Mailjet — transactional email, such as sign-in and billing messages EU
- Microsoft 365 — archiving of source data exports UK / EU
- Geoapify — hotel location look-ups EU
- OpenAI — (i) standardising hotel reference data such as hotel names and addresses; and (ii) generating written summaries of aggregated analytics (see the AI-generated summaries section). In both cases the information we send is limited by design and contains no personal data — hotel identity and location details in the first case, and aggregated figures only (with names, email addresses and identifiers excluded and screened out) in the second United States
Each of these providers is bound by contract to protect your data and to use it only for the purposes of providing their service to us. We may also disclose personal data where required to do so by law, or to a professional adviser under a duty of confidentiality.
6AI-generated summaries
We use artificial intelligence to turn travel data into short, plain-English summaries — for example, a narrative of how spend and bookings have moved over a recent period. This feature is designed so that the AI never has access to personal data.
The AI model has no access to our database. Each night, an automated job builds a small pack of pre-calculated, aggregated figures, and the AI's only role is to phrase them; it does not calculate, estimate or add anything. The information sent is limited to aggregated and derived metrics — such as total spend and booking counts, period-on-period percentage movements, traveller counts, spend by travel type, committed future travel, booking lead-time statistics and CO2 totals. Where a client organisation permits it, the top few reference values (such as cost centres) may be included as percentages, and only after an automated screen has removed anything resembling a name, email address or telephone number.
No personal data is sent to the AI. Traveller and consultant names, email addresses, booking references, per-person records, free-text fields and agency financial information are excluded by design and by automated checks before anything is sent. Client company names may appear in agency-level summaries as business information.
This processing is carried out by OpenAI, via its API in the United States under appropriate safeguards. Our OpenAI organisation is configured not to share any API data with OpenAI for model training or improvement; in line with OpenAI's API data-usage policy, API data is not used to train its models and is retained for up to 30 days solely for abuse monitoring before deletion.
Each summary — the aggregated figures sent and the generated text — is stored as an audit record and kept for 24 months, then deleted. The feature is off by default and can be switched off at organisation, client and per-field level; turning it off removes any existing AI-written text. These summaries are descriptive only and involve no automated decision-making that produces legal or similarly significant effects.
7Where your data is stored and international transfers
Your personal data is stored and processed within the United Kingdom and the European Economic Area, except for the limited hotel reference-data processing and the AI summary processing described above, which involve a transfer to the United States. Where personal data is transferred outside the UK or EEA, we ensure appropriate safeguards required by UK data protection law are in place. As noted, the data used for both of those purposes is limited by design and is not intended to contain personal data.
8Traveller and booking data (our role as processor)
When your travel management company or agency uses Jentix, we process the booking data they provide — which can include traveller names, contact details, and travel details — solely on their instructions and in order to provide our analytics service to them. In relation to this data, that organisation is the controller and we are the processor. Our analytics service may include AI-generated summaries of this data; as described in the AI-generated summaries section, those summaries are built from aggregated figures and no personal data is sent to the AI provider.
If you are a traveller and you want to access your data, correct it, or exercise any other right, you should contact the travel management company or agency that made your booking, as they are responsible for it.
If they ask us to assist them in responding to your request, we will do so.
9How long we keep your data
We keep personal data only for as long as we need it. Data relating to the organisations we work with, and the booking data we process for them, is retained for the duration of our agreement with that organisation and deleted within 30 days of the agreement ending, unless we are required to keep it for longer by law. Account data for platform users is kept while the account is active. Security and audit logs — sign-in records, settings-change records and secure-link access records — are kept for 24 months and then deleted. AI summary records — the aggregated figures sent to the AI and the generated text — are kept for 24 months and then deleted. Enquiry and correspondence data is kept only for as long as needed to deal with the matter and for a reasonable period afterwards.
10How we protect your data
We take the security of personal data seriously. We encrypt data in transit using TLS, and data in our database is encrypted at rest. Access to systems and data is restricted to authorised personnel on a role-based basis, and multi-factor authentication is enforced on administrative and infrastructure accounts. We keep the security and audit logs described in section 3 so that sign-ins and configuration changes can be traced to the account that made them; these logs are visible only to authorised Jentix personnel. We do not use third-party analytics, advertising, or error-monitoring services that would process your data.
11Your rights
Under UK data protection law you have the right to access the personal data we hold about you, to have inaccurate data corrected, to have your data erased in certain circumstances, to restrict or object to our processing in certain circumstances, and to data portability where it applies. Where we rely on consent, you can withdraw it at any time.
To exercise any of these rights in relation to data for which we are the controller, contact us at tyrone@jentix.co.uk. If your request relates to traveller or booking data, please contact your travel management company or agency, as explained in section 8. We will respond to valid requests within the time limits set by law.
12Cookies
We use only the cookies necessary for our website and platform to function, such as session and security cookies that keep you signed in and protect against fraudulent requests. We do not use advertising cookies or third-party analytics cookies.
13Complaints
If you have a concern about how we handle your personal data, please contact us first so we can try to resolve it. You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator, at ico.org.uk or by calling 0303 123 1113.
14Changes to this policy
We may update this policy from time to time. The date at the top shows when it was last changed, and any material changes will be reflected here.
15Contact us
Jentix Ltd82a James Carter Road, Bury St. Edmunds, IP28 7DE
Email: tyrone@jentix.co.uk
