Privacy Notice

Tiger Holidays · Legal

1. Who we are

PAXIMUM UK LTD operates tigerholidays.co.uk and is a controller of personal information used for website operation, booking administration, customer service, payment administration, fraud prevention and marketing. PAXIMUM UK LTD is registered in England and Wales under company number 12357513 at 12 Savoy Parade, Southbury Road, Enfield, Middlesex, England, EN1 1RT.

For flight-inclusive packages organised and protected by CARIA HOLIDAYS LTD, Caria is an independent controller for the personal information it requires to organise and perform the package, meet legal obligations and provide ATOL protection. Caria is registered in England and Wales under company number 09913824 at the same registered office and holds ATOL 11211.

Privacy contact: [email protected]

2. Information we collect

identity and traveller details, including name, title, date of birth, nationality and booking reference;

contact details, including email address, telephone number and postal address where needed;

passport, travel-document and Advance Passenger Information where required for the itinerary;

booking details, including flights, accommodation, transfers, room occupancy, meals and special requests;

payment and transaction information, including payment status, tokens and limited card information supplied by the payment provider;

customer-service correspondence, complaints, claims and evidence;

technical and security information, including IP address, device/browser information, security events and strictly necessary cookie or storage identifiers;

marketing preferences where you choose to receive marketing;

accessibility, mobility, dietary or health information where you ask us to arrange assistance.

3. Why we use your information

PurposePrimary lawful basis
Search, quote, book and administer travel servicesContract / steps at your request before contract.
Perform the package and coordinate suppliersContract; legal obligations.
Take payments, issue refunds and reconcile transactionsContract; legal obligations; legitimate interests.
Customer service, disruption support, complaints and claimsContract; legal obligations; legitimate interests.
Fraud prevention, account security and cyber-securityLegitimate interests; legal obligations where applicable.
Aviation, border, tax, accounting and regulatory complianceLegal obligation.
Direct marketingConsent or the PECR soft opt-in where all legal conditions are met.
Health/accessibility assistanceArticle 9 condition, normally separate explicit consent for the requested assistance.

4. Health and accessibility information

Health, disability or accessibility information may be special-category personal data. We collect only the information needed to arrange the requested assistance. Where we rely on explicit consent, you will be given a separate, specific opt-in. Consent is not implied merely because a form is submitted.

5. Who we share information with

CARIA HOLIDAYS LTD for organisation of applicable packages and ATOL protection;

airlines, hotels, transfer providers, destination-management companies and other travel suppliers;

SAN TSG / the TourVisio operating entity in Türkiye, acting as a processor for booking-platform operation and support, subject to contract;

payment providers, acquiring banks and fraud-prevention providers;

cloud, security, email and communication providers;

professional advisers, insurers and claims handlers where necessary;

police, immigration, border, tax, courts, regulators and other authorities where required or permitted by law.

6. International transfers

Travel bookings may require personal information to be transferred outside the United Kingdom, including to destination countries and suppliers. Our booking technology and support also involve restricted transfers from the UK to a processor in Türkiye.

For the UK-to-Türkiye processor transfer, PAXIMUM requires a written processor agreement, the current UK International Data Transfer Agreement (IDTA) or another valid UK transfer safeguard, and a documented transfer risk assessment. Contractual and technical controls include data minimisation, access controls, MFA, encryption in transit, logging, incident response, restrictions on onward transfer and deletion/return obligations.

Where a destination supplier needs information to perform your travel contract, another lawful transfer mechanism or applicable statutory exception may be used as appropriate.

7. Retention

RecordRetention baseline
Booking, contract, payment and invoice records7 years after travel completion, subject to accounting/legal review.
Enquiries that do not become bookings12 months after last contact.
Complaints and claims6 years after closure, or longer where a live claim or legal hold requires it.
Marketing recordsUntil withdrawal/objection, with a suppression record retained as necessary to respect opt-out.
Security and fraud logsUp to 24 months, longer where required for an incident or claim.
Cookie/storage recordsFor the duration stated in the Cookie Policy and as technically necessary.

8. Your rights

access your personal information;

correct inaccurate or incomplete information;

request erasure where the law allows;

request restriction of processing;

object to processing based on legitimate interests;

object at any time to direct marketing;

request data portability where applicable;

withdraw consent where processing relies on consent;

complain to the UK Information Commissioner's Office.

9. Marketing

We may send electronic marketing where you have consented or where the PECR soft opt-in applies. You can unsubscribe using the link in a marketing email. Booking confirmations, payment notices, disruption alerts and other service communications are not marketing.

10. Data protection complaints

If you have a concern about how we use personal information, email [email protected] and state that it is a data protection complaint. We will acknowledge the complaint within 30 days and will investigate and respond without undue delay. You may also complain to the Information Commissioner's Office.

11. Security

We use technical and organisational measures intended to protect personal information, including access controls, authentication, encryption in transit, security logging, vulnerability management, supplier controls and incident-response procedures.

12. Changes

We may update this Privacy Notice. The current version and effective date will be displayed on this page. Material changes will be highlighted where appropriate.

Version 1.0 · Effective 14 August 2026

Travel Advice & Safety

Before you travel, check your government's latest advice on health, safety, local laws and entry requirements for your destination on the official travel advisory website.


ATOL Protected

Your peace of mind matters to us. Every flight-inclusive holiday booked through this website is financially protected under the ATOL scheme, so your money and your trip home are always covered.


Why Book With Us

From price-match guarantees to flexible, low-deposit bookings, we're committed to making your next holiday easy, affordable and worry-free. See all our guarantees.