Travel Advice & Safety
Before you travel, check your government's latest advice on health, safety, local laws and entry requirements for your destination on the official travel advisory website.
Tiger Holidays · Legal
PAXIMUM UK LTD operates tigerholidays.co.uk and is a controller of personal information used for website operation, booking administration, customer service, payment administration, fraud prevention and marketing. PAXIMUM UK LTD is registered in England and Wales under company number 12357513 at 12 Savoy Parade, Southbury Road, Enfield, Middlesex, England, EN1 1RT.
For flight-inclusive packages organised and protected by CARIA HOLIDAYS LTD, Caria is an independent controller for the personal information it requires to organise and perform the package, meet legal obligations and provide ATOL protection. Caria is registered in England and Wales under company number 09913824 at the same registered office and holds ATOL 11211.
Privacy contact: [email protected]
identity and traveller details, including name, title, date of birth, nationality and booking reference;
contact details, including email address, telephone number and postal address where needed;
passport, travel-document and Advance Passenger Information where required for the itinerary;
booking details, including flights, accommodation, transfers, room occupancy, meals and special requests;
payment and transaction information, including payment status, tokens and limited card information supplied by the payment provider;
customer-service correspondence, complaints, claims and evidence;
technical and security information, including IP address, device/browser information, security events and strictly necessary cookie or storage identifiers;
marketing preferences where you choose to receive marketing;
accessibility, mobility, dietary or health information where you ask us to arrange assistance.
| Purpose | Primary lawful basis |
|---|---|
| Search, quote, book and administer travel services | Contract / steps at your request before contract. |
| Perform the package and coordinate suppliers | Contract; legal obligations. |
| Take payments, issue refunds and reconcile transactions | Contract; legal obligations; legitimate interests. |
| Customer service, disruption support, complaints and claims | Contract; legal obligations; legitimate interests. |
| Fraud prevention, account security and cyber-security | Legitimate interests; legal obligations where applicable. |
| Aviation, border, tax, accounting and regulatory compliance | Legal obligation. |
| Direct marketing | Consent or the PECR soft opt-in where all legal conditions are met. |
| Health/accessibility assistance | Article 9 condition, normally separate explicit consent for the requested assistance. |
Health, disability or accessibility information may be special-category personal data. We collect only the information needed to arrange the requested assistance. Where we rely on explicit consent, you will be given a separate, specific opt-in. Consent is not implied merely because a form is submitted.
CARIA HOLIDAYS LTD for organisation of applicable packages and ATOL protection;
airlines, hotels, transfer providers, destination-management companies and other travel suppliers;
SAN TSG / the TourVisio operating entity in Türkiye, acting as a processor for booking-platform operation and support, subject to contract;
payment providers, acquiring banks and fraud-prevention providers;
cloud, security, email and communication providers;
professional advisers, insurers and claims handlers where necessary;
police, immigration, border, tax, courts, regulators and other authorities where required or permitted by law.
Travel bookings may require personal information to be transferred outside the United Kingdom, including to destination countries and suppliers. Our booking technology and support also involve restricted transfers from the UK to a processor in Türkiye.
For the UK-to-Türkiye processor transfer, PAXIMUM requires a written processor agreement, the current UK International Data Transfer Agreement (IDTA) or another valid UK transfer safeguard, and a documented transfer risk assessment. Contractual and technical controls include data minimisation, access controls, MFA, encryption in transit, logging, incident response, restrictions on onward transfer and deletion/return obligations.
Where a destination supplier needs information to perform your travel contract, another lawful transfer mechanism or applicable statutory exception may be used as appropriate.
| Record | Retention baseline |
|---|---|
| Booking, contract, payment and invoice records | 7 years after travel completion, subject to accounting/legal review. |
| Enquiries that do not become bookings | 12 months after last contact. |
| Complaints and claims | 6 years after closure, or longer where a live claim or legal hold requires it. |
| Marketing records | Until withdrawal/objection, with a suppression record retained as necessary to respect opt-out. |
| Security and fraud logs | Up to 24 months, longer where required for an incident or claim. |
| Cookie/storage records | For the duration stated in the Cookie Policy and as technically necessary. |
access your personal information;
correct inaccurate or incomplete information;
request erasure where the law allows;
request restriction of processing;
object to processing based on legitimate interests;
object at any time to direct marketing;
request data portability where applicable;
withdraw consent where processing relies on consent;
complain to the UK Information Commissioner's Office.
We may send electronic marketing where you have consented or where the PECR soft opt-in applies. You can unsubscribe using the link in a marketing email. Booking confirmations, payment notices, disruption alerts and other service communications are not marketing.
If you have a concern about how we use personal information, email [email protected] and state that it is a data protection complaint. We will acknowledge the complaint within 30 days and will investigate and respond without undue delay. You may also complain to the Information Commissioner's Office.
We use technical and organisational measures intended to protect personal information, including access controls, authentication, encryption in transit, security logging, vulnerability management, supplier controls and incident-response procedures.
We may update this Privacy Notice. The current version and effective date will be displayed on this page. Material changes will be highlighted where appropriate.
Version 1.0 · Effective 14 August 2026
Before you travel, check your government's latest advice on health, safety, local laws and entry requirements for your destination on the official travel advisory website.
Your peace of mind matters to us. Every flight-inclusive holiday booked through this website is financially protected under the ATOL scheme, so your money and your trip home are always covered.
From price-match guarantees to flexible, low-deposit bookings, we're committed to making your next holiday easy, affordable and worry-free. See all our guarantees.