Security & compliance
Privacy, security, POPIA and data protection information for travel companies and their customers.
Voyagr Enterprise Security & POPIA Overview
A privacy-by-design overview of how Voyagr protects data and supports POPIA compliance.
Document Purpose
This document provides an overview of the security, privacy and data protection controls implemented within the Voyagr platform.
Voyagr is designed using privacy-by-design principles, with controls intended to assist travel companies in protecting traveller information and meeting their obligations under the Protection of Personal Information Act (POPIA).
Voyagr provides a secure technology platform, while each customer remains responsible for ensuring their own lawful processing of personal information.
1. Company & Platform Overview
Voyagr is a travel operations platform that enables travel companies to manage:
- Leads
- Customers
- Traveller profiles
- Quotes
- Payments
- Bookings
- Communications
- Reporting
- Operational workflows
The platform is designed for multi-tenant SaaS deployment, allowing multiple travel companies to use Voyagr while maintaining logical separation of their data.
2. POPIA Roles & Responsibilities
Responsible Party
The travel company using Voyagr remains the Responsible Party for the personal information of its customers and travellers. Examples include:
- Traveller details
- Passport information
- Contact information
- Travel preferences
- Booking history
The travel company determines why information is collected, what information is required, and who it is shared with.
Operator
Voyagr acts as an Operator/service provider processing information on behalf of the travel company. Voyagr processes information only to provide platform functionality, according to customer instructions, and for agreed operational purposes.
3. Data Protection Principles
Data minimisation
Voyagr only collects information required for travel operations. Required information includes traveller name, contact details and passport information when required for international travel. Sensitive information unrelated to travel fulfilment is not collected.
Purpose limitation
Personal information is used for travel quotations, booking management, customer communication, operational reporting and service improvement. Information is not sold or used for unrelated purposes.
Retention management
Voyagr supports configurable retention policies. Retention rules are configured at the platform level and surfaced to company managers where applicable. Deletion workflows are handled in line with legal requirements and platform configuration.
4. Data Security Architecture
Multi-tenant security
Voyagr uses tenant isolation controls. Each travel company operates within its own protected environment. Controls include role-based access control, database-level security policies, tenant data separation and permission validation. A user from one company cannot access another company's information.
5. User Access Management
Role-based access control
Voyagr supports controlled user permissions. Examples include:
- Super Admin: platform management and security oversight.
- Company Manager: company-wide operational access.
- Travel Consultant: access based on assigned permissions.
- Customer: limited access to their own information.
Access security
Controls include authentication, permission checks, audit logging and session management.
6. Super Admin Security Controls
Super Admin actions are treated as high-risk activities. Voyagr records user identity, date/time, action performed, module accessed, reason for access and changes made. Sensitive actions require additional accountability, such as viewing personal information, changing permissions, exporting data or modifying security settings.
7. AI Security & Privacy Controls
Voyagr Sentinel uses AI to improve platform reliability. AI capabilities include error analysis, performance monitoring, operational recommendations and platform health insights.
AI privacy principles:
- Voyagr AI does analyse technical events, system performance, operational risks and platform health.
- Voyagr AI does not train models using customer data, share customer information between companies, or process unnecessary traveller information.
8. Voyagr Sentinel AI Platform Monitoring
Voyagr Sentinel provides platform health monitoring for database health, application errors, integration status, payment events and communication failures. It identifies increasing error rates, failed integrations, performance degradation and security anomalies. AI recommendations are generated from de-identified technical data only.
9. Data Encryption & Protection
Voyagr applies security controls including secure data transmission, protected authentication, controlled database access and restricted administrative privileges. Sensitive integration credentials are encrypted at rest using AES-256-GCM.
10. Third-Party Integrations
Voyagr integrates with external services where required, including payment providers, email providers, WhatsApp providers, travel suppliers and mapping providers. Each integration is reviewed based on data shared, purpose, security controls and provider responsibilities.
11. Payment Security
Voyagr does not store sensitive payment information such as card numbers or banking credentials. Payment processing is handled through approved payment providers. Voyagr stores operational payment information such as transaction references, payment status and the booking/payment relationship.
12. Audit Logging
Voyagr maintains audit trails for important activities. Logged activities include user access, administrative changes, security events, consent actions and data requests. Audit logs support accountability, investigation and compliance reporting.
13. Data Subject Rights Support
Voyagr supports processes for:
- Access requests: customers may request information held about them.
- Correction requests: incorrect information can be updated.
- Deletion requests: requests can be processed according to legal requirements.
- Processing information: customers can request information about how data is used.
14. POPIA Compliance Management
Voyagr supports privacy notices, consent management, agreement tracking, data processing agreements, audit reporting and security monitoring.
15. Incident Response
In the event of a security incident, Voyagr supports detection, investigation, containment and documentation. Customer notification processes are followed where required. Formal incident response procedures are maintained as part of Voyagr's operational processes.
16. Business Continuity
Voyagr maintains operational resilience through monitoring, error tracking, backup processes, controlled deployments and platform health checks.
17. Enterprise Customer Responsibilities
Customers using Voyagr remain responsible for obtaining lawful consent, training employees, managing internal access, ensuring lawful processing and maintaining accurate traveller information.
18. Security Questionnaire Summary
Where is data stored?
Voyagr uses secure cloud infrastructure providers with appropriate security controls.
Who can access customer data?
Only authorised users with appropriate permissions.
Can one company see another company's data?
No. Tenant separation controls prevent cross-company access.
Does Voyagr use AI?
Yes. AI is used for operational intelligence and platform monitoring. AI does not use customer data for training.
How is traveller information protected?
Through access controls, tenant isolation, audit trails, privacy-by-design architecture and monitoring.
Does Voyagr support POPIA?
Voyagr is designed with POPIA principles and controls to assist customers in meeting their obligations.
Enterprise Security & Privacy Overview
Version: 1.0 · Review frequency: annual or when significant platform changes occur.
Security FAQ
Quick answers to common security and data protection questions.
Where is data stored?
Voyagr uses secure cloud infrastructure providers with appropriate security controls.
Who can access customer data?
Only authorised users with appropriate permissions can access customer data within their own company.
Can one company see another company's data?
No. Voyagr is multi-tenant by design, and tenant separation controls prevent cross-company access.
Does Voyagr use AI?
Yes. AI is used for operational intelligence and platform monitoring. AI does not use customer data for training and only receives de-identified technical data.
How is traveller information protected?
Through access controls, tenant isolation, audit trails, privacy-by-design architecture and ongoing monitoring.
Does Voyagr support POPIA?
Voyagr is designed with POPIA principles and controls to assist travel companies in meeting their obligations.
Does Voyagr store payment card details?
No. Payment processing is handled by approved payment providers. Voyagr stores transaction references, payment status and the relationship between bookings and payments.
What happens if there is a security incident?
Voyagr supports detection, investigation, containment and documentation. Customer notification processes are followed where required.
How can I request my data?
Contact the travel company using Voyagr to request access, correction or deletion of your personal information.
Your Privacy on Voyagr
How Voyagr collects, uses and protects your personal information.
Your privacy matters
Voyagr is a travel operations platform used by travel companies to manage bookings, quotes, customer records and communications. This notice explains how Voyagr handles personal information in the platform.
What information is collected
Voyagr collects information needed to deliver travel services, such as names, contact details, travel preferences and passport details when required for international travel. Information is only collected when it is necessary for travel fulfilment.
How information is used
Information is used to create quotes, manage bookings, communicate with travellers, produce operational reports and improve the service. It is not sold or used for unrelated purposes.
Who is responsible
The travel company using Voyagr is the Responsible Party for your personal information. Voyagr acts as the Operator, processing information on behalf of that travel company according to their instructions.
Security and access
Voyagr uses role-based access control, tenant isolation, audit logs and encrypted integration credentials to protect information. Each travel company can only see its own data.
Your rights
You may request access to your information, ask for corrections, request deletion where applicable, or ask how your information is being processed. Contact the travel company you are dealing with to exercise these rights.
AI and automation
Voyagr uses AI for platform health monitoring and operational insights. AI analysis only uses de-identified technical data and does not use customer information for training.