Privacy
How Voresta Tours handles enquiry and guest information.
Last updated:
This policy explains how Voresta Tours, a Jordan-based tour operator trading as Voresta Tours, handles personal data under Jordan's Personal Data Protection Law No. 24 of 2023 and, where it applies, the EU General Data Protection Regulation (GDPR).
Please do not send passport, payment or health information through the general contact form unless Voresta specifically asks for it through an appropriate channel.
| Processing | Purpose | Legal basis |
|---|---|---|
| Enquiries and quotations | Reply, design an itinerary, price services and take steps requested before a contract. | Steps before entering a contract; legitimate interests in responding and operating the business. |
| Bookings, passports, flights and companion details | Reserve and deliver accommodation, transport, guiding, tickets, entry and support. | Performance of a contract; legal obligations; legitimate interests in safe trip operations. |
| Payments and financial records | Take payment, prevent fraud, issue records and meet tax/accounting duties. | Contract; legal obligation; legitimate interests in fraud prevention and claims. |
| Health, allergy, dietary and accessibility details | Adapt arrangements and protect travellers' wellbeing. | Your explicit consent; where strictly necessary, protection of vital interests or another basis permitted by applicable law. |
| Service messages and emergency support | Communicate changes, coordinate suppliers and assist during travel. | Contract; vital interests in an emergency; legitimate interests in safe operations. |
| Marketing | Send news or offers only where requested or otherwise lawfully permitted. | Consent, which may be withdrawn at any time. |
| Website and security logs | Keep services reliable, investigate abuse and protect systems. | Legitimate interests in network and information security; legal obligations where applicable. |
Only the minimum data needed for a service is shared. Recipients may include:
The named technology-provider list has not yet been completed in the admin settings. It must be verified before production publication.
Voresta does not sell personal data.
Voresta operates in Jordan, so information supplied by European travellers is processed in Jordan. Jordan is not currently listed by the European Commission as a country covered by an EU adequacy decision. Suppliers may also process data in other countries.
Where GDPR transfer rules apply, Voresta will use an available lawful mechanism appropriate to the transfer, such as European Commission Standard Contractual Clauses with relevant providers, additional technical and organisational safeguards, or a limited GDPR Article 49 derogation where a transfer is necessary to perform the travel contract. You may ask for information about the applicable safeguard.
Assessment in progress. Because Voresta offers travel services to people in the EU and may process sensitive travel information, the occasional-processing exemption should not be assumed. An EU representative should be appointed before regular EU-facing processing unless documented legal advice confirms an exemption.
When a period ends, records are deleted or irreversibly anonymised, including from active systems; backup copies expire through the backup rotation. Deletion requests are also communicated to relevant recipients where required.
The public website is currently configured without optional analytics or advertising trackers. It uses only functionality necessary to display pages, protect forms and deliver requested services. If optional tracking is added, this section and a consent control must be updated before it is activated.
Voresta uses access controls, encryption in transit, protected administrative access, data minimisation, backups, supplier review and staff procedures appropriate to the risk. No system can be guaranteed completely secure. If a breach creates a legal notification duty, Voresta will notify the competent authority and affected people within the applicable time limits.
Subject to applicable law, you may request access, correction, deletion, restriction, objection and a portable copy of data you provided. You may withdraw consent at any time without affecting earlier lawful processing. You may also object to direct marketing and ask not to be subject to a decision based solely on automated processing that has legal or similarly significant effects. Voresta does not currently use such automated decision-making.
To exercise a right, contact info@vorestatours.com. Voresta may need to verify your identity and will normally respond within the period required by the applicable law.
You may complain to Jordan's Personal Data Protection Directorate or Council. If the GDPR applies to you, you may also complain to the data protection authority in the EU/EEA country where you live, work or believe an infringement occurred.
A parent or guardian must provide information for a child and authorise its use. Voresta will update this policy when processing or legal requirements change and will show the new “Last updated” date. Material changes will be communicated where required.