Privacy

Privacy policy

Privacy policy for saudireiser.com

Last updated: 31 July 2026

Saudi Reiser is committed to handling personal data in a secure, lawful and transparent way.

This privacy policy explains what personal data we may collect when you visit saudireiser.com, contact us or use our services. It also describes why we process the data, who it may be shared with, how long it is stored, and what rights you have.

Processing takes place in accordance with the EU General Data Protection Regulation (GDPR), the Norwegian Personal Data Act and other relevant legislation.

Personal data is information that can be linked directly or indirectly to an identifiable person. This may include name, email address, phone number, IP address and the content of an enquiry.

1. Who is the data controller?

The data controller for personal data processed via saudireiser.com is:

Legal company name
[JURIDISK SELSKAPSNAVN]
Brand and website
Saudi Reiser – saudireiser.com
Organisation number
[ORGANISASJONSNUMMER]
Address
[POSTADRESSE], [POSTNUMMER OG STED], Norge
Email
kontakt@saudireiser.com

The data controller determines the purposes of the processing of personal data and the means used.

Saudi Reiser has not appointed a data protection officer. Privacy enquiries can therefore be sent to kontakt@saudireiser.com.

Back to contents

2. What personal data do we process?

The data we process depends on how you use the website and which services you use.

a. Information you give us

When you submit the contact form or contact us directly, we may process:

  • Name
  • Email address
  • Phone number
  • What the enquiry concerns
  • The content of the message
  • Preferred language
  • Other information you choose to provide

If you ask for help planning a trip, we may later need information such as:

  • Preferred destination and route
  • Travel dates
  • Number of travellers
  • Length of the trip
  • Budget
  • Travel wishes and preferences
  • Information necessary to prepare or follow up a travel proposal

Please avoid sending sensitive or special categories of personal data through the ordinary contact form unless it is necessary and we have explicitly asked for it.

b. Information collected automatically

When you visit the website we may process limited technical data such as:

  • IP address
  • Time of the visit
  • Browser type
  • Operating system and device type
  • Pages visited
  • Error and security logs
  • Language selection
  • Cookie and consent settings

Necessary technical data is used for secure operation, debugging, prevention of misuse and remembering your choices.

Analytics or marketing data is only processed where relevant and where you have given the necessary consent.

Back to contents

3. Where do we get the data from?

We normally receive personal data:

  • Directly from you
  • Through the contact form
  • By email
  • When you request a travel proposal
  • When you sign up for a possible newsletter
  • Through necessary technical logs
  • Through cookies and similar technology where valid consent has been given

If we receive information about other travellers from you, please make sure you are entitled to share it and that the individuals concerned have received the necessary information.

Back to contents

4. Purposes and legal bases

We only process personal data when we have a valid legal basis.

Purposes and legal bases
PurposeExamples of processingLegal basis
Responding to enquiriesContact form, email and questions about travelProcessing is necessary to take steps at your request prior to a possible agreement, GDPR Article 6(1)(b). In some cases processing may rely on our legitimate interest in answering general enquiries, Article 6(1)(f).
Preparing and following up travel proposalsTravel wishes, travel dates, number of travellers and contact detailsSteps taken at your request before an agreement, or performance of a contract, Article 6(1)(b).
Administering bookings and delivering servicesCustomer follow-up, reservations and necessary communicationPerformance of a contract, Article 6(1)(b).
Meeting legal obligationsAccounting, bookkeeping and documentation requirementsLegal obligation, Article 6(1)(c).
Newsletter and electronic marketingTravel tips, inspiration and offersConsent, Article 6(1)(a), together with relevant rules on electronic marketing.
Security and prevention of misuseLogs, rate limiting, debugging and form protectionLegitimate interest in secure and stable operation, Article 6(1)(f).
Optional cookies and trackingAnalytics, functional services and marketingConsent, Article 6(1)(a), together with applicable electronic communications rules.
Handling legal claimsDocumentation, disputes and legal follow-upLegitimate interest, Article 6(1)(f), or legal obligation where applicable.

Where processing relies on legitimate interest, we balance our need against the interests, rights and freedoms of the individual.

Where processing relies on consent, that consent can be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

Back to contents

5. Contact form and enquiries

When you use the contact form on saudireiser.com we use the data to:

  • Receive the enquiry
  • Answer your questions
  • Understand what trip or help you want
  • Follow up a possible travel proposal
  • Prevent spam and misuse
  • Document necessary customer communication

The contact form sends enquiries to kontakt@saudireiser.com.

The enquiry is also stored securely in the website database so we can follow it up and prevent misuse of the form. Submission, storage and email delivery are operated by the website's platform provider, see section 8.

Suppliers used to send or store enquiries only receive the data necessary to deliver the service.

Back to contents

6. Newsletter and marketing

If Saudi Reiser offers a newsletter, we only send electronic marketing when we have a valid basis for doing so.

For consent-based newsletters:

  • Signing up must be voluntary
  • The consent must be kept separate from cookie consent
  • It must be clear what the subscriber is signing up for
  • Unsubscribing must be easy
  • The consent must be documentable

You can withdraw your consent at any time using the unsubscribe link in the email or by contacting us at kontakt@saudireiser.com.

No newsletter distribution is currently running from saudireiser.com. This section describes how a future newsletter would be handled.

Back to contents

7. Cookies and similar technology

Saudi Reiser uses necessary cookies and similar technology so the website works securely and correctly.

With your consent we may also use optional technologies for:

  • Functional services
  • Analytics and statistics
  • Marketing

You can always:

  • Accept all optional categories
  • Reject optional categories
  • Customise your choices
  • Withdraw or change your consent later

Rejecting optional cookies is just as easy as accepting them.

The cookie system uses the following categories:

NecessaryAlways active
Required for the website to work: security, navigation, language preference, form security and storing your cookie choice. These cannot be turned off.
Functional
Optional features such as embedded maps, videos, review widgets and other interactive third-party content.
Analytics
Statistics about traffic and usage so we can improve the content and performance of the site.
Marketing
Advertising pixels, remarketing, conversion tracking and cross-site tracking.

A detailed and up-to-date overview of active cookies, storage technologies, suppliers, purposes and durations is available in the cookie declaration.

Non-necessary cookies and similar technologies are not activated before you have given valid consent.

Back to contents

8. Sharing of personal data

We do not sell your personal data.

We may share necessary personal data with suppliers that help us with:

  • Operation and hosting
  • Email delivery
  • Storage of contact enquiries
  • IT security
  • Analytics, where consent has been given
  • Payment and booking, if such services are introduced
  • Accounting and statutory documentation
  • Travel delivery and partners where necessary to deliver an agreed service
  • It follows from law
  • A public authority has a legal basis to require it
  • It is necessary to establish, exercise or defend a legal claim
  • You have asked for or consented to the sharing

Suppliers currently in use

The list is maintained centrally in the website's supplier register and only shows services actually active in production.

Active suppliers and data processors
SupplierServiceCategories of personal dataPurposeProcessing locationPrivacy
LovableWeb hosting, database for contact enquiries and delivery of email from the formName, email address, phone number, enquiry type, message content, language, timestamp and technical logsOperating the website, storing enquiries securely and delivering notification email to Saudi ReiserStated by the supplierPrivacy policy
Google Fonts (Google Ireland Ltd.)Delivery of the Playfair Display and Inter typefacesIP address plus browser and device information sent when font files are requestedDisplaying the website typography correctlyEU/EEA, may include the USAPrivacy policy

Suppliers processing personal data on our behalf are subject to relevant agreements and security requirements, including data processing agreements where GDPR Article 28 requires them.

We may also disclose data when:

Back to contents

9. Transfers outside the EU and EEA

Some suppliers may process personal data outside the EU and EEA.

If personal data is transferred to a country outside the EU and EEA, we make sure the transfer has a valid legal basis. This may for example be:

  • An adequacy decision from the European Commission
  • The European Commission's standard contractual clauses, SCC
  • Other valid transfer mechanisms under the GDPR

We also assess the need for supplementary safeguards where necessary.

In the current setup, fonts are loaded from Google Fonts. During that request your IP address is sent to Google, which may involve processing outside the EU/EEA. Other active suppliers are listed in section 8.

Back to contents

10. Retention period

We do not store personal data longer than necessary for the purpose it was collected for.

The retention period depends on factors such as:

  • What the data concerns
  • Whether the enquiry leads to a customer relationship
  • Contract and delivery needs
  • Statutory documentation requirements
  • The need to handle questions, complaints or legal claims

Ordinary contact enquiries

Enquiries that do not lead to a customer relationship are normally deleted or anonymised no later than 12 months after the case is closed, unless longer retention is necessary.

Travel enquiries and quotes

Data linked to travel proposals may normally be stored for up to 24 months after the last contact, unless it forms part of an active customer relationship or we have another valid need.

Customer and contract data

Data necessary to perform a contract is stored for the duration of the customer relationship and afterwards for as long as necessary for documentation and possible claims.

Accounting data

Accounting material is retained for the period required by applicable bookkeeping and accounting rules.

Newsletter

Data is stored until consent is withdrawn or the subscription ends, with limited documentation of the consent where necessary.

Security logs

Technical logs are only stored for as long as necessary for security, debugging and prevention of misuse.

Cookie consent

The cookie choice is stored for up to 6 months in the first-party cookie sr_consent, or until the consent is changed or withdrawn. See the cookie declaration for details.

Deletion of stored contact enquiries is currently done manually according to the routine above. Automatic deletion will be set up before the 12-month period expires for the first enquiries.

Back to contents

11. Information security

We use appropriate technical and organisational measures to protect personal data against:

  • Unauthorised access
  • Unlawful use or sharing
  • Alteration
  • Loss
  • Destruction
  • Other personal data breaches

The measures may include:

  • Access control
  • Secure connections
  • Encryption where relevant
  • Restriction of access
  • Logging
  • System updates
  • Secure storage of secret keys
  • Routines for security incidents
  • Deletion and data minimisation

No internet transmission or digital storage solution can be guaranteed to be entirely free of risk. We nevertheless work to keep the level of security appropriate to the risk of the processing.

Back to contents

12. Children's privacy

Saudi Reiser's services are primarily aimed at adults planning or booking travel.

We do not knowingly ask children to submit personal data directly through the website.

In Norway, the age limit is 13 years for children to consent themselves to processing related to information society services offered directly to children. For younger children, consent must be given or approved by a parent or guardian where the rules on children's consent apply.

Parents or guardians who believe a child has sent us personal data without the necessary basis can contact us at kontakt@saudireiser.com.

Back to contents

13. Your rights

Depending on the circumstances, you may have the right to:

  • Receive information about the processing
  • Request access to the personal data we hold about you
  • Request correction of inaccurate data
  • Request erasure of data
  • Request restriction of processing
  • Object to processing based on legitimate interest
  • Receive certain data in a structured, machine-readable format
  • Request that data be transferred to another controller where the conditions for data portability are met
  • Withdraw a consent
  • Lodge a complaint with the supervisory authority

These rights are not absolute. Lawful exceptions may apply, for example where data must be retained to meet a legal obligation or to handle a legal claim.

To exercise your rights, contact kontakt@saudireiser.com. Please write «Personvern» in the subject line.

We respond without undue delay and normally within one month. For complex or extensive requests, the deadline may be extended in accordance with the GDPR. You will be informed if that happens.

To prevent unauthorised access, we may ask for information needed to confirm your identity. We do not ask for more information than necessary.

Back to contents

14. Automated decisions and profiling

Saudi Reiser does not make decisions based solely on automated processing that produce legal effects or similarly significantly affect you.

If this changes, this policy will be updated and you will receive the information and rights that follow from GDPR Article 22.

Any analytics or marketing tools may only be used in accordance with your choices in the cookie system.

Back to contents

15. Links and external websites

The website may contain links to external websites and services.

External suppliers are themselves responsible for their processing of personal data. We recommend reading their privacy policies before providing personal data.

Saudi Reiser is not responsible for the content or privacy practices of independent external websites.

Back to contents

16. Changes to this policy

We may update the privacy policy if:

  • Our services change
  • We start using new suppliers
  • The processing of personal data changes
  • Regulations or authority guidance change
  • We improve the description of our privacy work

The latest version is always available on this page.

For significant changes we provide clear information where necessary. The date of the latest update is always shown at the top of the page.

Back to contents