voya
Section 10

Trust is a feature surface, not a policy page.

A travel app holds passport data, live location, payment instruments and personal preferences. Every one of those has a control the traveller can actually operate.

Consent register — traveller-operable
Personalisation & memory
Withdrawable at any time, with immediate effect.
Location while travelling
Withdrawable at any time, with immediate effect.
Marketing communications
Off by default. Transactional messages are unaffected.
Partner data sharing at booking
Withdrawable at any time, with immediate effect.
Analytics & product improvement
Withdrawable at any time, with immediate effect.
Crash diagnostics
Withdrawable at any time, with immediate effect.
Data subject rights
Export my data

Machine-readable JSON: profile, trips, bookings, memory, consents, messages.

Delete my account

Erasure of profile, memory and embeddings. Financial records retained where law requires.

UAE PDPL
Data residencyAWS me-central-1 (UAE)
Lawful basisContract · consent · legitimate interest
Consent logImmutable, timestamped, versioned
Cross-border transferOnly to booked partners, minimum fields
Breach notification72 h runbook
GDPR
Access & portabilitySelf-serve export
ErasureSelf-serve, ≤30 days
RectificationMemory editable in-app
ObjectionPersonalisation toggle
DPA with partnersRequired before go-live
What we never do
  • · Sell traveller data.
  • · Store card numbers — tokenised at the PSP, PCI scope stays out of VOYA.
  • · Train third-party models on traveller conversations.
  • · Keep hidden preference profiles the traveller cannot see or delete.