
Thomalex typical implementation process:
Initial Consultation & Requirements Gathering: Thomalex collaborates with the client to understand agency structure, workflow needs, preferred integrations (GDS, suppliers), and any branding or white-label requirements.
System Configuration & Branding: The software is configured to agency-specific workflows, policies, and branding (logos, domain settings). Custom modules or dashboards are set up at this stage.
Integration Setup: Connects to required GDS systems (like Amadeus, Sabre), NDC content, hotel bed banks (Booking.com, HotelBeds), and payment processors. Optional API integrations with back-office, CRM, or HR systems are established if needed.
User Training & Onboarding: Key staff receive training on booking processes, approvals, dashboards, reporting tools, and client management. Support is provided via email, chat, or calls throughout onboarding.
Testing & Validation: A short period of real-world user testing ensures workflows are correct and integrations perform seamlessly. Adjustments are made as necessary.
Thomalex can be extensively customized to fit specific business needs across multiple areas of its platform. Here are key data points demonstrating its flexibility and customizability:
White-Label Branding: Thomalex allows agencies to fully brand their booking platforms and admin dashboards. You can customize with your agency's logo, brand colors, domain names, and background styles, creating a unique look aligned with your identity.
Customizable Booking Widgets: The booking widget is highly flexible—choose between simple and more advanced Expedia-like forms—and customize colors (background, buttons, labels, menu), widget types, and pre-selected search defaults (hotel, car, or flight). This widget can be seamlessly integrated with your own website, and customizations extend to both appearance and functionality.
Email and Communication Customization: Agencies can tailor email templates for booking confirmations, cancellations, and error notifications. Custom CSS lets you align the emails with your brand, add agency logos, and toggle information displays depending on business type (corporate vs leisure). Email address visibility and custom messaging are easily controlled via settings.
Workflow and Approval Configuration: You can configure multi-level approval flows, triggers, and reminders, as well as fine-tune trip policies and justifications required for various business scenarios. Custom fields such as cost centers, custom PNR remarks, and policy enforcement can be set for different corporate clients.
Custom Modules and Feature Toggles: Thomalex supports the setup and activation/deactivation of module features—for example, enabling or disabling roundtrip, one-way, or multi-destination flight booking, or integrating specific supplier content (like Amadeus, Sabre, Booking.com, or HotelBeds). This modular approach allows each agency to tailor workflows and interface elements according to client needs.
API Integrations for Business Tools: The platform includes APIs for third-party integrations. Agencies can connect Thomalex to their back-office, CRM, HR, accounting, or marketing systems—enabling sync of traveler data, automation of business processes, and implementation of custom workflows.
Advanced Reporting and Dashboard Customization: Reporting dashboards are configurable, allowing tailored analytics and operational views such as booking trends, cost savings, top destinations, and compliance metrics for different user roles.
Automated AI-Based Workflows: For businesses seeking advanced automation, Thomalex offers AI-driven workflows that can automatically interpret and process email-based reservation requests according to an agency’s business logic and policies.
Flexible Deployment & Custom Solutions: Recent collaborations (e.g., with JR Technologies) emphasize Thomalex’s unique ability to deliver custom development—bespoke technology solutions and tailored implementation, ranging from rapid widget deployments to complex API-driven integrations.
Thomalex offers a training and support structure for new users, designed to ensure a smooth onboarding experience and efficient ongoing system use.
Personalized Onboarding: Upon signing a contract, new clients receive personalized credentials and a custom URL for their agency's branded booking site. The onboarding usually begins with direct communication from a Thomalex Support Manager who provides guidance and resources to start using the system.
Step-by-Step Documentation: Thomalex offers detailed, role-specific online documentation. This includes tutorials for both administrators and agents, covering site setup, dashboard navigation, booking workflows, approval processes, and customizations (such as branding and adding custom fields).
Free Online Training: The platform offers access to exclusive online training sessions aimed at business owners and agency staff, with a focus on features, best practices, and workflow optimization.
Rapid Deployment: Thomalex is known for fast implementation timelines. Some sources indicate that onboarding and training can be completed in less than 24 hours for straightforward cases, and typically within a few days to 2–4 weeks for more complex agency requirements.
Contextual Help: Users can access in-platform help features designed to assist with interface navigation, though some reviews suggest there is potential to expand these with more on-the-spot tips.
24/7 Global Support: Thomalex, especially after its merger with JR Technologies, offers around-the-clock technical support across time zones, ensuring users have access to assistance whenever needed.
Support Ticket System: Users can open support tickets directly through the Thomalex support portal, track status updates, and communicate with the support team for troubleshooting or feature requests.
Extensive Knowledge Base: A searchable online knowledge base addresses frequently asked questions, platform errors, configuration tips, and troubleshooting guides, empowering users to resolve common issues independently.
Thomalex has implemented a set of security measures to protect user and client data within its travel management platform:
Encryption of Sensitive Data: Sensitive information such as credit card numbers and social security numbers is protected using robust encryption protocols. Data sent over the internet—including payment information—is encrypted to prevent unauthorized access during transmission.
Access Controls and Limitations: Personally identifiable information (PII) is accessible only to a limited number of qualified employees who need it to perform their duties. All staff are familiar with the company’s security policies and practices, and access is granted on a strict need-to-know basis.
Regular Security Audits: Thomalex conducts audits of its security systems and processes regularly. This helps identify and address potential vulnerabilities and ensures ongoing compliance with security best practices.
Login and Session Security: The platform uses login data (including IP addresses and browser types) for trend analysis and added security. Security cookies are used to automatically log users out after periods of inactivity, minimizing the risk of unauthorized access from unattended devices.
Vendor and Service Provider Controls: While Thomalex may partner with third-party vendors (for functions like payment processing), these vendors only have access to user data when necessary and are expected to disclose their own use of personal information. Thomalex’s privacy practices do not extend to partners, but data sharing is minimal and purposeful.
Fraud Protection: Thomalex integrates with services like ClearSale to provide fraud protection, leveraging algorithmic analysis to detect and reject potentially suspicious transactions before they are processed.
Protocols for Legal & Safety Compliance: PII will be disclosed if required by law or if necessary to protect user safety. This includes compliance with court orders, subpoenas, or legitimate safety requests.
User Rights and Data Management: Users can access, rectify, or delete their personal information, restrict processing, and exercise other rights under data protection law. While data can be deactivated, some residual data may remain due to backup protocols.
Data Storage Security: Data is securely stored and not accessible to outside parties except as outlined above. Thomalex maintains commercially reasonable measures to ensure site security, although no system is entirely immune to breaches.
Structured Release Notes: Each software update is accompanied by detailed release notes, published on the Thomalex support portal. These notes outline new features, improvements, fixes, and any changes affecting workflows or integrations.
Automatic & Admin-Driven Deployment: For cloud-hosted users, most updates are managed centrally by Thomalex and applied automatically, ensuring all clients benefit from enhancements and security fixes with minimal disruption.
Client Notifications: Significant or potentially disruptive updates are typically communicated to clients through direct notifications or announcements, allowing for awareness and preparation for new features or UI changes.
Continuous Improvement: Recent updates have introduced both new functional capabilities (such as SSO integrations and expanded approval rule options) and workflow optimizations, reflecting a process of continuous,
incremental improvement based on customer feedback and industry evolution.
Thomalex’s privacy policy outlines its approach to data ownership and portability, emphasizing user rights and compliance with data protection laws:
Data Ownership & User Rights: Users retain significant control over their data. Thomalex customers have the right to access, correct, and delete personal data relating to them. They can also object to the processing of this data by submitting a request in writing. Thomalex ensures that personally identifiable information (PII) is accessible only to qualified employees and is not sold or misused.
Data Portability: Thomalex explicitly states that users have the right to data portability under data protection law. This means users can request a copy of their personal data in a structured, commonly used, and machine-readable format, which can be transferred to another provider if desired. This is in line with established privacy regulations such as GDPR.
Access and Deletion: Users can update personally identifiable information, correct inaccuracies, or request deletion of their account and data by contacting Thomalex via email. While full deletion may be limited by backup and record-keeping procedures, the company restricts retained data to legal or operational requirements and ensures it is not used for other purposes.
Security and Compliance: All user data is stored securely. Thomalex conducts regular audits of its security processes and emphasizes compliance with legal requests and user consent for any changes to privacy practices.
Thomalex travel management software meets several critical compliance standards focused on payment security and data protection:
PCI DSS Compliance: Thomalex is designed to be compliant with the Payment Card Industry Data Security Standard (PCI DSS), ensuring that sensitive cardholder data is securely processed and stored. This includes robust encryption protocols, access controls, and regular audits to safeguard payment information and prevent unauthorized access or breaches.
GDPR and Data Protection Laws: Thomalex aligns with the General Data Protection Regulation (GDPR) as well as similar global data protection laws. This enables users to exercise rights such as data access, correction, deletion, and portability. The company restricts access to personally identifiable information and provides mechanisms for users to control their data, demonstrating diligence in privacy and regulatory compliance.
Information Security Best Practices: Security measures include regular system audits, session security, limited internal data access, and fraud prevention integrations. These practices collectively support compliance with a range of industry security standards, providing a secure foundation for agencies handling regulated data.