Saudi Reiser is committed to handling personal data in a secure, lawful and transparent way.
This privacy policy explains what personal data we may collect when you visit saudireiser.com, contact us or use our services. It also describes why we process the data, who it may be shared with, how long it is stored, and what rights you have.
Processing takes place in accordance with the EU General Data Protection Regulation (GDPR), the Norwegian Personal Data Act and other relevant legislation.
Personal data is information that can be linked directly or indirectly to an identifiable person. This may include name, email address, phone number, IP address and the content of an enquiry.
1. Who is the data controller?
The data controller for personal data processed via saudireiser.com is:
- Legal company name
- [JURIDISK SELSKAPSNAVN]
- Brand and website
- Saudi Reiser – saudireiser.com
- Organisation number
- [ORGANISASJONSNUMMER]
- Address
- [POSTADRESSE], [POSTNUMMER OG STED], Norge
- Email
- kontakt@saudireiser.com
The data controller determines the purposes of the processing of personal data and the means used.
Saudi Reiser has not appointed a data protection officer. Privacy enquiries can therefore be sent to kontakt@saudireiser.com.
Back to contents
2. What personal data do we process?
The data we process depends on how you use the website and which services you use.
a. Information you give us
When you submit the contact form or contact us directly, we may process:
- Name
- Email address
- Phone number
- What the enquiry concerns
- The content of the message
- Preferred language
- Other information you choose to provide
If you ask for help planning a trip, we may later need information such as:
- Preferred destination and route
- Travel dates
- Number of travellers
- Length of the trip
- Budget
- Travel wishes and preferences
- Information necessary to prepare or follow up a travel proposal
Please avoid sending sensitive or special categories of personal data through the ordinary contact form unless it is necessary and we have explicitly asked for it.
b. Information collected automatically
When you visit the website we may process limited technical data such as:
- IP address
- Time of the visit
- Browser type
- Operating system and device type
- Pages visited
- Error and security logs
- Language selection
- Cookie and consent settings
Necessary technical data is used for secure operation, debugging, prevention of misuse and remembering your choices.
Analytics or marketing data is only processed where relevant and where you have given the necessary consent.
Back to contents
3. Where do we get the data from?
We normally receive personal data:
- Directly from you
- Through the contact form
- By email
- When you request a travel proposal
- When you sign up for a possible newsletter
- Through necessary technical logs
- Through cookies and similar technology where valid consent has been given
If we receive information about other travellers from you, please make sure you are entitled to share it and that the individuals concerned have received the necessary information.
Back to contents
4. Purposes and legal bases
We only process personal data when we have a valid legal basis.
Purposes and legal bases| Purpose | Examples of processing | Legal basis |
|---|
| Responding to enquiries | Contact form, email and questions about travel | Processing is necessary to take steps at your request prior to a possible agreement, GDPR Article 6(1)(b). In some cases processing may rely on our legitimate interest in answering general enquiries, Article 6(1)(f). |
|---|
| Preparing and following up travel proposals | Travel wishes, travel dates, number of travellers and contact details | Steps taken at your request before an agreement, or performance of a contract, Article 6(1)(b). |
|---|
| Administering bookings and delivering services | Customer follow-up, reservations and necessary communication | Performance of a contract, Article 6(1)(b). |
|---|
| Meeting legal obligations | Accounting, bookkeeping and documentation requirements | Legal obligation, Article 6(1)(c). |
|---|
| Newsletter and electronic marketing | Travel tips, inspiration and offers | Consent, Article 6(1)(a), together with relevant rules on electronic marketing. |
|---|
| Security and prevention of misuse | Logs, rate limiting, debugging and form protection | Legitimate interest in secure and stable operation, Article 6(1)(f). |
|---|
| Optional cookies and tracking | Analytics, functional services and marketing | Consent, Article 6(1)(a), together with applicable electronic communications rules. |
|---|
| Handling legal claims | Documentation, disputes and legal follow-up | Legitimate interest, Article 6(1)(f), or legal obligation where applicable. |
|---|
Where processing relies on legitimate interest, we balance our need against the interests, rights and freedoms of the individual.
Where processing relies on consent, that consent can be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Back to contents
5. Contact form and enquiries
When you use the contact form on saudireiser.com we use the data to:
- Receive the enquiry
- Answer your questions
- Understand what trip or help you want
- Follow up a possible travel proposal
- Prevent spam and misuse
- Document necessary customer communication
The contact form sends enquiries to kontakt@saudireiser.com.
The enquiry is also stored securely in the website database so we can follow it up and prevent misuse of the form. Submission, storage and email delivery are operated by the website's platform provider, see section 8.
Suppliers used to send or store enquiries only receive the data necessary to deliver the service.
Back to contents
6. Newsletter and marketing
If Saudi Reiser offers a newsletter, we only send electronic marketing when we have a valid basis for doing so.
For consent-based newsletters:
- Signing up must be voluntary
- The consent must be kept separate from cookie consent
- It must be clear what the subscriber is signing up for
- Unsubscribing must be easy
- The consent must be documentable
You can withdraw your consent at any time using the unsubscribe link in the email or by contacting us at kontakt@saudireiser.com.
No newsletter distribution is currently running from saudireiser.com. This section describes how a future newsletter would be handled.
Back to contents
7. Cookies and similar technology
Saudi Reiser uses necessary cookies and similar technology so the website works securely and correctly.
With your consent we may also use optional technologies for:
- Functional services
- Analytics and statistics
- Marketing
You can always:
- Accept all optional categories
- Reject optional categories
- Customise your choices
- Withdraw or change your consent later
Rejecting optional cookies is just as easy as accepting them.
The cookie system uses the following categories:
- NecessaryAlways active
- Required for the website to work: security, navigation, language preference, form security and storing your cookie choice. These cannot be turned off.
- Functional
- Optional features such as embedded maps, videos, review widgets and other interactive third-party content.
- Analytics
- Statistics about traffic and usage so we can improve the content and performance of the site.
- Marketing
- Advertising pixels, remarketing, conversion tracking and cross-site tracking.
A detailed and up-to-date overview of active cookies, storage technologies, suppliers, purposes and durations is available in the cookie declaration.
Non-necessary cookies and similar technologies are not activated before you have given valid consent.
Back to contents
8. Sharing of personal data
We do not sell your personal data.
We may share necessary personal data with suppliers that help us with:
- Operation and hosting
- Email delivery
- Storage of contact enquiries
- IT security
- Analytics, where consent has been given
- Payment and booking, if such services are introduced
- Accounting and statutory documentation
- Travel delivery and partners where necessary to deliver an agreed service
- It follows from law
- A public authority has a legal basis to require it
- It is necessary to establish, exercise or defend a legal claim
- You have asked for or consented to the sharing
Suppliers currently in use
The list is maintained centrally in the website's supplier register and only shows services actually active in production.
Active suppliers and data processors| Supplier | Service | Categories of personal data | Purpose | Processing location | Privacy |
|---|
| Lovable | Web hosting, database for contact enquiries and delivery of email from the form | Name, email address, phone number, enquiry type, message content, language, timestamp and technical logs | Operating the website, storing enquiries securely and delivering notification email to Saudi Reiser | Stated by the supplier | Privacy policy |
|---|
| Google Fonts (Google Ireland Ltd.) | Delivery of the Playfair Display and Inter typefaces | IP address plus browser and device information sent when font files are requested | Displaying the website typography correctly | EU/EEA, may include the USA | Privacy policy |
|---|
Suppliers processing personal data on our behalf are subject to relevant agreements and security requirements, including data processing agreements where GDPR Article 28 requires them.
We may also disclose data when:
Back to contents
9. Transfers outside the EU and EEA
Some suppliers may process personal data outside the EU and EEA.
If personal data is transferred to a country outside the EU and EEA, we make sure the transfer has a valid legal basis. This may for example be:
- An adequacy decision from the European Commission
- The European Commission's standard contractual clauses, SCC
- Other valid transfer mechanisms under the GDPR
We also assess the need for supplementary safeguards where necessary.
In the current setup, fonts are loaded from Google Fonts. During that request your IP address is sent to Google, which may involve processing outside the EU/EEA. Other active suppliers are listed in section 8.
Back to contents
10. Retention period
We do not store personal data longer than necessary for the purpose it was collected for.
The retention period depends on factors such as:
- What the data concerns
- Whether the enquiry leads to a customer relationship
- Contract and delivery needs
- Statutory documentation requirements
- The need to handle questions, complaints or legal claims
Ordinary contact enquiries
Enquiries that do not lead to a customer relationship are normally deleted or anonymised no later than 12 months after the case is closed, unless longer retention is necessary.
Travel enquiries and quotes
Data linked to travel proposals may normally be stored for up to 24 months after the last contact, unless it forms part of an active customer relationship or we have another valid need.
Customer and contract data
Data necessary to perform a contract is stored for the duration of the customer relationship and afterwards for as long as necessary for documentation and possible claims.
Accounting data
Accounting material is retained for the period required by applicable bookkeeping and accounting rules.
Newsletter
Data is stored until consent is withdrawn or the subscription ends, with limited documentation of the consent where necessary.
Security logs
Technical logs are only stored for as long as necessary for security, debugging and prevention of misuse.
Cookie consent
The cookie choice is stored for up to 6 months in the first-party cookie sr_consent, or until the consent is changed or withdrawn. See the cookie declaration for details.
Deletion of stored contact enquiries is currently done manually according to the routine above. Automatic deletion will be set up before the 12-month period expires for the first enquiries.
Back to contents
11. Information security
We use appropriate technical and organisational measures to protect personal data against:
- Unauthorised access
- Unlawful use or sharing
- Alteration
- Loss
- Destruction
- Other personal data breaches
The measures may include:
- Access control
- Secure connections
- Encryption where relevant
- Restriction of access
- Logging
- System updates
- Secure storage of secret keys
- Routines for security incidents
- Deletion and data minimisation
No internet transmission or digital storage solution can be guaranteed to be entirely free of risk. We nevertheless work to keep the level of security appropriate to the risk of the processing.
Back to contents
12. Children's privacy
Saudi Reiser's services are primarily aimed at adults planning or booking travel.
We do not knowingly ask children to submit personal data directly through the website.
In Norway, the age limit is 13 years for children to consent themselves to processing related to information society services offered directly to children. For younger children, consent must be given or approved by a parent or guardian where the rules on children's consent apply.
Parents or guardians who believe a child has sent us personal data without the necessary basis can contact us at kontakt@saudireiser.com.
Back to contents
13. Your rights
Depending on the circumstances, you may have the right to:
- Receive information about the processing
- Request access to the personal data we hold about you
- Request correction of inaccurate data
- Request erasure of data
- Request restriction of processing
- Object to processing based on legitimate interest
- Receive certain data in a structured, machine-readable format
- Request that data be transferred to another controller where the conditions for data portability are met
- Withdraw a consent
- Lodge a complaint with the supervisory authority
These rights are not absolute. Lawful exceptions may apply, for example where data must be retained to meet a legal obligation or to handle a legal claim.
To exercise your rights, contact kontakt@saudireiser.com. Please write «Personvern» in the subject line.
We respond without undue delay and normally within one month. For complex or extensive requests, the deadline may be extended in accordance with the GDPR. You will be informed if that happens.
To prevent unauthorised access, we may ask for information needed to confirm your identity. We do not ask for more information than necessary.
Back to contents
14. Automated decisions and profiling
Saudi Reiser does not make decisions based solely on automated processing that produce legal effects or similarly significantly affect you.
If this changes, this policy will be updated and you will receive the information and rights that follow from GDPR Article 22.
Any analytics or marketing tools may only be used in accordance with your choices in the cookie system.
Back to contents
15. Links and external websites
The website may contain links to external websites and services.
External suppliers are themselves responsible for their processing of personal data. We recommend reading their privacy policies before providing personal data.
Saudi Reiser is not responsible for the content or privacy practices of independent external websites.
Back to contents
16. Changes to this policy
We may update the privacy policy if:
- Our services change
- We start using new suppliers
- The processing of personal data changes
- Regulations or authority guidance change
- We improve the description of our privacy work
The latest version is always available on this page.
For significant changes we provide clear information where necessary. The date of the latest update is always shown at the top of the page.
Back to contents
17. Contact and complaints
For questions about privacy or the processing of personal data, contact:
You have the right to complain to Datatilsynet if you believe your personal data is processed in breach of the rules.
You may also contact another competent supervisory authority in the EU or EEA where relevant.
Back to contents
18. Legal sources
The links open official sources in a new tab.
Back to contents