Skip to main content
Legal Document

Privacy Policy

Our commitment to protecting your personal data and respecting your privacy rights

Effective Date: 8/6/2026 | Last Updated: 8/6/2026

Jurisdiction: Singapore | Company: The Index Labs Pte. Ltd.

1. Privacy Overview

Our commitment to protecting your privacy

PRIVACY BY DESIGN

THE INDEX LABS PTE. LTD. ("TRAVAIO", "WE", "US") IS COMMITTED TO PROTECTING YOUR PERSONAL DATA AND RESPECTING YOUR PRIVACY RIGHTS IN ACCORDANCE WITH APPLICABLE PRIVACY LAWS.

Company Information

Data Controller: The Index Labs Pte. Ltd.

Registered Address: 7 Temasek Boulevard, #12-07, Suntec Tower One, Singapore 038987

Contact: contact@travaio.co

Data Protection Officer: dpo@travaio.co

This Privacy Policy Covers

Personal Data Collection:
  • • What data we collect and why
  • • Legal basis for processing
  • • How we use your information
  • • Data sharing and third parties
Your Privacy Rights:
  • • Access, correction, and deletion
  • • Data portability and objection
  • • GDPR and CCPA compliance
  • • How to exercise your rights

2. Data We Collect

Types of personal information we process

Account Information

Registration Data: Email address (email), name, password (encrypted)

Profile Data: Travel preferences (travel preferences), dietary restrictions, accessibility needs

Subscription Data: Billing information, payment methods, subscription tier

Travel Information

Location Data: Search locations, trip destinations, current location (if permitted)

Itinerary Data: Created itineraries, saved places, travel dates

Booking Data: Hotel and activity bookings made through our platform

Technical Information

Device Data: IP address, browser type, operating system, device identifiers

Usage Data: Pages visited, features used, time spent, click patterns

Performance Data: Load times, error logs, crash reports

Communication Data

Support Communications: Help requests, feedback, support tickets

Marketing Communications: Email preferences, newsletter subscriptions

AI Interactions: Conversations with our AI travel assistant

Data Collection Principles

We collect only data that is necessary for providing our travel planning services, improving user experience, and meeting legal requirements. All sensitive data is encrypted and processed securely.

3. How We Use Your Data

Purposes and processing activities

Primary Service Delivery

  • • Generate personalized travel itineraries and personalized recommendations using AI
  • • Provide location-based recommendations and suggestions
  • • Enable booking of hotels, activities, and experiences
  • • Manage your account, preferences, and subscription
  • • Process payments and handle billing

Platform Improvement

  • • Analyze usage patterns to enhance our AI algorithms
  • • Monitor performance and fix technical issues
  • • Conduct research and development for new features
  • • Optimize user interface and experience
  • • Train and improve our machine learning models

Communication & Support

  • • Respond to your inquiries and provide customer support
  • • Send important service updates and notifications
  • • Deliver marketing communications (with consent)
  • • Notify you about new features and improvements
  • • Process feedback and feature requests

Legal & Security

  • • Comply with legal obligations and regulatory requirements
  • • Prevent fraud, abuse, and security threats
  • • Enforce our terms of service and policies
  • • Resolve disputes and legal claims
  • • Maintain records for audit and compliance purposes

5. Data Sharing & Third Parties

Who we share your data with and why

Essential Service Providers

Cloud Infrastructure

AWS, Google Cloud (data hosting, computing)

AI Services

Google Cloud (AI processing for itinerary generation)

Payment Processing

Stripe (payment transactions)

Maps & Location

Google Maps API (geocoding, mapping)

Travel & Booking Partners

Hotel Providers: When you book accommodations through our platform

Activity Partners: For experience bookings and tour reservations

Travel APIs: For real-time pricing and availability information

Data shared only as necessary to complete bookings

Analytics & Monitoring

Datadog: Application performance monitoring and error tracking

Analytics Services: Aggregated, anonymized usage statistics

Security Services: Fraud detection and security monitoring

Data Protection Standards

All third-party partners are contractually bound by data protection agreements, undergo security assessments, and must comply with applicable privacy laws. We never sell your personal data.

6. International Data Transfers

Cross-border data processing and safeguards

Global Service Delivery

As a Singapore-based company providing global travel services, we may transfer your personal data internationally to deliver our services effectively and securely.

Primary Data Locations

Asia-Pacific Region:
  • • Singapore (Primary data center)
  • • Australia (Backup and disaster recovery)
  • • Japan (Regional processing)
Other Regions:
  • • United States (AI processing, cloud services)
  • • European Union (EU user data processing)
  • • Canada (Additional cloud infrastructure)

Transfer Safeguards

EU-Singapore Trade Agreement

Transfers to Singapore benefit from adequacy decisions and trade agreement protections

Standard Contractual Clauses (SCCs)

EU-approved SCCs for all transfers to countries without adequacy decisions

Data Processing Agreements

Binding contracts with all processors ensuring GDPR-level protection

Technical & Organizational Measures

Encryption, access controls, and security measures for all international transfers

7. Cookies & Tracking Technologies

How we use cookies and similar technologies

Types of Cookies We Use

Essential Cookies
Required

Necessary for basic website functionality and security

  • • Session authentication and login state
  • • Security tokens and CSRF protection
  • • Load balancing and server routing
  • • Cookie consent preferences
Functional Cookies
Optional

Enhance your experience with personalized features

  • • User preferences and settings
  • • Language and region selection
  • • Recently searched locations
  • • Interface customization
Analytics Cookies
Optional

Help us understand how our service is used

  • • Page views and user interactions
  • • Feature usage and performance metrics
  • • Error tracking and debugging
  • • A/B testing and optimization
Marketing Cookies
Optional

Enable personalized marketing and advertising

  • • Targeted advertisements and promotions
  • • Social media integration
  • • Email marketing effectiveness
  • • Cross-platform user identification

Managing Your Cookie Preferences

You can control cookie settings through:

  • • Our cookie consent banner (appears on first visit)
  • • Browser settings (disable/clear cookies)
  • • Account settings (for registered users)
  • • Third-party opt-out tools (Google Analytics, etc.)

Third-Party Tracking

Google Services: Maps API, Analytics (with IP anonymization)

Datadog RUM: Real user monitoring for performance optimization

Social Media: When you interact with social sharing features

All third-party services comply with applicable privacy laws and our data protection standards.

8. Data Security Measures

How we protect your personal information

Security-First Approach

We implement industry-standard security measures and follow security best practices to protect your data from unauthorized access, alteration, disclosure, or destruction.

Technical Safeguards

Encryption

AES-256 encryption at rest, TLS 1.3 in transit

Authentication

Multi-factor authentication, secure session management

Access Controls

Role-based access, principle of least privilege

Network Security

Firewalls, VPCs, DDoS protection, WAF

Operational Security

Monitoring

Continuous security monitoring, anomaly detection

Incident Response

Documented procedures, rapid response team

Vulnerability Management

Regular security audits, penetration testing

Staff Training

Security awareness, privacy training programs

Infrastructure Security

Cloud Security
  • • AWS/GCP security services
  • • SOC 2 compliant hosting
  • • Regular backup and recovery
  • • Geo-distributed infrastructure
Application Security
  • • Secure coding practices
  • • OWASP compliance
  • • Regular security testing
  • • Dependency scanning
Database Security
  • • Encrypted database storage
  • • Row-level security (RLS)
  • • Automated backups
  • • Query monitoring

Security Incident Reporting

If you suspect any security incident or unauthorized access to your account, please immediately contact us at contact@travaio.co or through our support channels.

9. Data Retention Policies

How long we keep your data and why

Retention Principles

We retain personal data only as long as necessary for the purposes for which it was collected, to comply with legal obligations, or to establish, exercise, or defend legal claims.

Retention Periods by Data Type

Account Data
Active Account

Profile Information

Retained while account is active + 30 days after deletion request

Authentication Data

Passwords immediately deleted, tokens expire automatically

Travel Data
User-Controlled

Itineraries & Trips

Retained until user deletion or account closure + 90 days

Booking Information

7 years (tax/accounting requirements)

Usage & Analytics
Automated

Usage Logs

90 days (security & troubleshooting)

Analytics Data

26 months (aggregated, pseudonymized)

Communication Data
Support

Support Tickets

3 years (quality assurance & training)

Marketing Emails

Until unsubscribe + compliance requirements

Financial Data
Legal Requirement

Payment Records

7 years (tax & regulatory requirements)

Refund Records

7 years (dispute resolution & compliance)

Automated Deletion Process

Scheduled Reviews: Monthly automated scans identify data eligible for deletion

Secure Deletion: Multi-pass overwriting ensures data cannot be recovered

Backup Purging: Backups are automatically purged according to retention schedules

Third-Party Coordination: Deletion requests are propagated to all data processors

User Control

You can request deletion of your personal data at any time through your account settings or by contacting us. Some data may be retained longer if required by law or for legitimate business purposes.

10. Your Privacy Rights

Universal privacy rights available to all users

Your Rights Matter

Regardless of your location, we respect your fundamental privacy rights and provide mechanisms to exercise control over your personal data.

Access & Information Rights

Right to Access

Request a copy of all personal data we hold about you

Right to Information

Understand how your data is processed and shared

Data Portability

Export your data in machine-readable formats

Control & Correction Rights

Right to Rectification

Correct inaccurate or incomplete personal data

Right to Erasure

Request deletion of your personal data

Right to Object

Object to certain processing activities

How to Exercise Your Rights

Account Settings

Self-service options for registered users:

  • • Update profile information
  • • Download your data
  • • Delete account and data
  • • Manage privacy preferences
Contact Us

For complex requests or assistance:

  • • Email: privacy@travaio.co
  • • Data requests: dpo@travaio.co
  • • Support portal: help.travaio.co
  • • Response time: 30 days
Identity Verification

Security measures for data requests:

  • • Account authentication required
  • • Additional ID verification may be needed
  • • Secure delivery of sensitive data
  • • Audit trail maintenance

Rights Limitations

Some rights may be limited by legal requirements, legitimate interests, or technical constraints. We will explain any limitations when responding to your requests.

11. GDPR Rights (EU Users)

Enhanced rights for European Union residents

GDPR Compliance

If you are located in the European Union, you have additional rights under the General Data Protection Regulation (GDPR) that strengthen your data protection.

Enhanced GDPR Rights

Right to Restriction

Limit how we process your data while maintaining storage

Right to Data Portability

Receive your data in structured, machine-readable format

Right to Object

Object to processing based on legitimate interests or direct marketing

Automated Decision-Making Rights

No Automated Decisions

Right not to be subject to fully automated decision-making

Human Intervention

Request human review of automated decisions affecting you

Explanation Rights

Understand the logic behind automated processing

GDPR-Specific Procedures

Response Timeframes
  • • Standard requests: 1 month
  • • Complex requests: Up to 3 months
  • • Urgent data breaches: 72 hours
  • • Right to be informed of delays
Data Subject Requests
  • • No fees for reasonable requests
  • • Charges for excessive requests
  • • Verification procedures required
  • • Secure delivery mechanisms

Supervisory Authority Rights

You have the right to:

  • • Lodge a complaint with your local data protection authority
  • • Seek judicial remedy if unsatisfied with our response
  • • Contact the Singapore Personal Data Protection Commission as our lead authority
  • • Request assistance from your national DPA for cross-border complaints

EU Data Protection Officer

Contact: dpo@travaio.co
Address: c/o The Index Labs Pte. Ltd., 7 Temasek Boulevard, #12-07, Suntec Tower One, Singapore 038987
Role: Dedicated point of contact for all GDPR-related inquiries and complaints

12. CCPA Rights (California Users)

California Consumer Privacy Act rights and protections

CCPA Protection

California residents have specific privacy rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).

CCPA Consumer Rights

Right to Know

Information about personal information collected, used, disclosed

Right to Delete

Request deletion of personal information we have collected

Right to Opt-Out

Opt-out of the sale or sharing of personal information

CPRA Enhanced Rights

Right to Correct

Request correction of inaccurate personal information

Right to Limit

Limit use and disclosure of sensitive personal information

Right to Portability

Obtain a copy of personal information in portable format

Personal Information Categories

We Collect:
  • • Identifiers (name, email, IP address)
  • • Commercial information (bookings, preferences)
  • • Internet activity (usage data, interactions)
  • • Geolocation data (with consent)
  • • Professional information (business travel)
Sensitive Information:
  • • Account login credentials
  • • Payment card information (tokenized)
  • • Precise geolocation (with consent)
  • • Health/accessibility preferences
  • • Dietary restrictions and preferences

Sale and Sharing Disclosure

No Sale of Personal Information

We do not sell personal information as defined by CCPA. We may share information with service providers and partners as described in this privacy policy, but this does not constitute a "sale" under CCPA.

How to Exercise CCPA Rights

Request Methods
  • • Email: privacy@travaio.co
  • • Online form: travaio.co/ccpa-request
  • • Account settings (for registered users)
Verification Process
  • • Identity verification required
  • • 2-3 pieces of identifying information
  • • Additional verification for sensitive requests
  • • Authorized agent procedures available

13. Children's Privacy

Special protections for users under 18

Child Protection Commitment

We are committed to protecting the privacy and safety of children who may use our services, in compliance with COPPA, GDPR-K, and other applicable children's privacy laws.

Age Requirements

Under 13 (US/Global)

Service not available without parental consent

Under 16 (EU)

Parental consent required for account creation

13-17 Years

Limited account with enhanced protections

Special Protections

Limited Data Collection

Only essential data for service provision

No Targeted Marketing

No behavioral advertising to minors

Enhanced Security

Additional security measures and monitoring

Parental Rights and Controls

Parental Consent
  • • Verifiable parental consent required
  • • Consent verification via credit card
  • • Digital signature with government ID
  • • Video conference verification available
Parental Access
  • • Review child's personal information
  • • Request deletion of child's data
  • • Refuse further data collection
  • • Modify account restrictions

Teen Account Features

For users aged 13-17, we provide:

Enhanced Privacy
  • • Default privacy-protective settings
  • • Limited data sharing with third parties
  • • No location tracking without consent
  • • Simplified privacy controls
Content Restrictions
  • • Age-appropriate travel recommendations
  • • Restricted booking capabilities
  • • No alcohol/adult entertainment venues
  • • Enhanced content filtering

Report Concerns

If you believe a child under 13 has provided personal information without parental consent, or have concerns about a minor's use of our service, please contact us immediately at: contact@travaio.co

14. Automated Decision Making

AI and automated processing transparency

AI-Powered Travel Planning

Our service uses AI and automated systems to enhance your travel planning experience. We believe in transparency about how these systems work and your rights regarding automated decisions.

Automated Processing We Use

Itinerary Generation

AI algorithms create personalized travel recommendations

Fraud Detection

Automated systems detect suspicious account activity

Content Filtering

Automated moderation of user-generated content

Human Oversight

Account Decisions

Human review for account suspensions or restrictions

Complex Disputes

Human agents handle complex customer issues

Appeal Process

Human review available for automated decisions

How Our AI Systems Work

Travel Recommendation Engine

Our AI analyzes your preferences, travel history, and global travel data to suggest personalized itineraries.

Input Factors:

  • • Your stated preferences
  • • Past travel behavior
  • • Seasonal travel patterns
  • • Location popularity data

Processing Logic:

  • • Machine learning algorithms
  • • Natural language processing
  • • Collaborative filtering
  • • Real-time optimization
Security and Fraud Prevention

Automated systems monitor account activity and transactions for security threats.

Monitoring Areas:

  • • Login patterns and locations
  • • Payment card transactions
  • • Account behavior changes
  • • Booking pattern analysis

Response Actions:

  • • Additional verification requests
  • • Temporary account restrictions
  • • Human team notifications
  • • Escalation procedures

Your Rights Regarding Automated Decisions

Right to Explanation
  • • Understand how AI recommendations are made
  • • Request details about decision logic
  • • Learn about data factors used
  • • Get human-readable explanations
Right to Human Review
  • • Request human review of automated decisions
  • • Appeal automated account actions
  • • Contest AI-generated recommendations
  • • Seek manual override when appropriate

Algorithm Transparency

We regularly audit our AI systems for bias, fairness, and accuracy. You can request more information about how our algorithms affect your experience by contacting: contact@travaio.co

15. Marketing Communications

How we handle marketing emails and promotional content

Consent-Based Marketing

We only send marketing communications to users who have explicitly opted in. You can control your preferences and unsubscribe at any time.

Types of Marketing Communications

Newsletter & Updates

Travel tips, destination guides, and platform updates

Promotional Offers

Special deals, discounts, and exclusive promotions

Personalized Recommendations

Travel suggestions based on your preferences and history

Consent and Preferences

Opt-In Required

Explicit consent needed for all marketing emails

Granular Control

Choose specific types of communications you want

Easy Unsubscribe

One-click unsubscribe in every marketing email

Marketing Data We Use

Personalization Data
  • • Travel preferences and interests
  • • Past destinations and booking history
  • • Seasonal travel patterns
  • • Engagement with previous emails
Targeting Criteria
  • • Geographic location and time zone
  • • Subscription tier and account status
  • • Language and communication preferences
  • • Opt-in date and source

How to Manage Your Marketing Preferences

Account Settings

Update preferences in your account:

  • • Marketing preferences panel
  • • Email frequency settings
  • • Content type selections
  • • Complete opt-out option
Email Links

Use links in marketing emails:

  • • One-click unsubscribe button
  • • Preference management center
  • • Subscription update options
  • • Report spam/unwanted content
Direct Contact

Contact us directly:

  • • Email: contact@travaio.co
  • • Marketing inquiries: contact@travaio.co

Marketing Compliance

Legal Compliance
  • • CAN-SPAM Act (US)
  • • GDPR consent requirements (EU)
  • • CASL compliance (Canada)
  • • Local anti-spam regulations
Best Practices
  • • Clear sender identification
  • • Honest subject lines
  • • Physical address disclosure
  • • Prompt unsubscribe processing

Transactional vs. Marketing

Important service notifications (booking confirmations, security alerts, etc.) are not marketing communications and cannot be unsubscribed from, as they are essential for service delivery.

16. Data Breach Notification

How we handle and communicate security incidents

Incident Response Commitment

While we implement robust security measures to prevent data breaches, we have comprehensive procedures in place to respond quickly and transparently if an incident occurs.

Detection and Assessment

Continuous Monitoring

Continuous security monitoring and threat detection systems

Rapid Assessment

Immediate evaluation of scope, impact, and affected data

Containment

Swift action to contain and stop the breach from spreading

Response Team Activation

Security Team

Technical experts for incident containment and analysis

Legal Team

Compliance and regulatory notification coordination

Communications

User and stakeholder notification management

Notification Timeline

Regulatory Notifications

GDPR Requirements (EU Users):

  • • Supervisory authority: 72 hours
  • • Affected users: Without undue delay
  • • High risk breaches: Immediate notification

Other Jurisdictions:

  • • CCPA (California): As required by law
  • • Singapore PDPA: Within 3 days
  • • Other local requirements: Per jurisdiction
User Notifications

High-Risk Breaches:

  • • Email notification: Within 72 hours
  • • In-app notification: Immediate
  • • Website banner: Within 24 hours
  • • Direct communication if needed

Low-Risk Breaches:

  • • Privacy policy update notification
  • • Annual transparency report inclusion
  • • Available upon request
  • • No individual notification required

What We'll Tell You

Incident Details
  • • Nature of the security incident
  • • Types of personal data involved
  • • Approximate number of affected users
  • • When the breach occurred and was discovered
Impact Assessment
  • • Likely consequences of the breach
  • • Risk assessment for affected users
  • • Whether sensitive data was compromised
  • • Current status of the investigation
Response Actions
  • • Steps we've taken to address the breach
  • • Measures to prevent similar incidents
  • • Law enforcement involvement if applicable
  • • Additional security measures implemented
User Actions
  • • Recommended steps to protect yourself
  • • Whether you need to change passwords
  • • How to monitor for suspicious activity
  • • Contact information for questions

Prevention and Learning

After any security incident, we conduct thorough post-incident reviews to identify improvements and prevent future occurrences. We'll share relevant findings in our annual transparency report.

Report Security Issues

If you discover a security vulnerability or suspect a breach, please report it immediately to: contact@travaio.co or through our support channels.

17. Business Transfers

Data handling during mergers, acquisitions, or asset sales

Business Continuity

In the event of corporate transactions, we ensure your personal data remains protected and your privacy rights are preserved throughout the process.

Types of Business Transfers

Mergers & Acquisitions

When our company merges with or is acquired by another entity

Asset Sales

Sale of business assets, including customer databases

Corporate Restructuring

Internal reorganizations affecting data processing entities

Bankruptcy/Insolvency

Data handling during financial difficulties or closure

Data Protection Requirements

Equivalent Protection

Successor must provide equal or better privacy protection

Legal Compliance

All transfers must comply with applicable privacy laws

User Rights Preservation

Your privacy rights remain intact after any transfer

Contractual Obligations

Binding agreements to protect user data

Due Diligence Process

Privacy Impact Assessment

We Evaluate:

  • • Acquiring party's privacy practices
  • • Data security capabilities
  • • Compliance with privacy laws
  • • Historical privacy performance

Requirements:

  • • Maintain equivalent protection standards
  • • Honor existing user preferences
  • • Preserve data minimization practices
  • • Implement proper security measures
Legal Safeguards

Contractual Protections:

  • • Data processing agreements
  • • Privacy policy compliance clauses
  • • User rights preservation requirements
  • • Breach notification obligations

Ongoing Monitoring:

  • • Regular compliance audits
  • • Privacy practice reviews
  • • User complaint tracking
  • • Enforcement mechanisms

User Notification and Rights

Notification Timeline
  • • 30 days advance notice (when possible)
  • • Email to registered users
  • • Website announcement
  • • In-app notification for active users
Information Provided
  • • Identity of the acquiring party
  • • Reason for the transfer
  • • Changes to privacy practices (if any)
  • • Your options and rights

Your Options During Business Transfers

Before Transfer
  • • Object to the data transfer (where legally permitted)
  • • Request deletion of your personal data
  • • Export your data before the transfer
  • • Update your privacy preferences
After Transfer
  • • Exercise rights with the new data controller
  • • Request information about new privacy practices
  • • Opt-out of new processing activities
  • • File complaints with supervisory authorities

Commitment to Users

We will never transfer your data to parties who cannot provide adequate protection or who intend to use your data in ways inconsistent with this privacy policy without your explicit consent.

18. Policy Updates & Changes

How we handle privacy policy modifications

Living Document

This privacy policy is a living document that may be updated to reflect changes in our practices, services, legal requirements, or to improve clarity and transparency.

Reasons for Updates

Legal Changes

New privacy laws, regulations, or court decisions

Service Changes

New features, integrations, or service modifications

Practice Improvements

Enhanced privacy practices or security measures

Clarity & Transparency

Better explanations or additional detail

Types of Changes

Material Changes

Significant changes affecting your privacy rights

Non-Material Changes

Minor updates, clarifications, or corrections

Administrative Changes

Contact information or organizational updates

Technical Updates

Changes to technical descriptions or processes

Notification Process

Material Changes

Notification Methods:

  • • Email notification to all users
  • • Prominent website banner
  • • In-app notification
  • • Push notification (mobile users)

Timeline:

  • • 30 days advance notice minimum
  • • 60 days for significant changes
  • • Immediate for urgent legal requirements
  • • Reminder 7 days before effective date
Non-Material Changes

Notification Methods:

  • • Updated "Last Modified" date
  • • Website privacy page update
  • • Optional email notification
  • • Changelog on privacy page

Timeline:

  • • Effective immediately upon posting
  • • No advance notice required
  • • Monthly summary of minor changes
  • • Annual comprehensive review

Your Options When We Update

Before Changes Take Effect
  • • Review the updated policy carefully
  • • Contact us with questions or concerns
  • • Export your data if you disagree with changes
  • • Delete your account if desired
After Changes Take Effect
  • • Continued use indicates acceptance
  • • Exercise your privacy rights under new terms
  • • File complaints with supervisory authorities
  • • Seek legal remedies if applicable

Version Control and Archives

Version Management
  • • Each version is numbered and dated
  • • Clear changelog with update summaries
  • • Effective dates for all changes
  • • Links to previous versions
Historical Access
  • • Previous versions available for 5 years
  • • Archive accessible via privacy page
  • • Downloadable PDF versions
  • • Comparison tools between versions

Stay Informed

Subscribe to our privacy policy updates mailing list at privacy@travaio.co to receive notifications about all policy changes, including minor updates and clarifications.

19. Contact & Data Protection Officer

How to reach us with privacy questions and concerns

We're Here to Help

We are committed to addressing your privacy questions, concerns, and requests promptly and transparently. Multiple contact channels are available for your convenience.

Primary Contact Information

Company Details
Legal Entity:
The Index Labs Pte. Ltd.
Registration:
Singapore Company Registration
Address:
7 Temasek Boulevard, #12-07
Suntec Tower One
Singapore 038987
General Contact
Email:
contact@travaio.co

Privacy-Specific Contacts

Data Protection Officer
Email:
dpo@travaio.co
Role:
Privacy rights, data requests, GDPR compliance
Response Time:
Within 5 business days
Specialized Teams
Privacy Inquiries:
privacy@travaio.co
EU Users:
dpo@travaio.co
California Residents:
privacy@travaio.co

How to Contact Us

Email Support

Best for detailed privacy requests and questions

General: contact@travaio.co
Privacy: privacy@travaio.co
DPO: dpo@travaio.co
Postal Mail

For formal complaints or legal matters

Privacy Officer
The Index Labs Pte. Ltd.
7 Temasek Boulevard, #12-07
Suntec Tower One
Singapore 038987

Response Times and Process

Standard Requests
  • • General inquiries: 2-3 business days
  • • Privacy questions: 5 business days
  • • Data access requests: 30 days
  • • Account deletion: 10 business days
Complex Requests
  • • GDPR requests: Up to 3 months
  • • Legal compliance matters: Variable
  • • Technical investigations: 2-4 weeks
  • • Formal complaints: 30-45 days

Supervisory Authorities

If you're not satisfied with our response, you can contact these authorities:

Singapore (Lead Authority)
  • Personal Data Protection Commission
  • Website: pdpc.gov.sg
  • Email: enquiries@pdpc.gov.sg
European Union
  • Your Local Data Protection Authority
  • Find your DPA: edpb.europa.eu
  • European Data Protection Board
  • Cross-border complaint procedures

Emergency Contact

For urgent security matters or suspected data breaches, contact us immediately: contact@travaio.co and request emergency support.