AboutToursDestinationsHotelsContact
EN
EnglishРусский

Voresta Tours

Private journeys, cultural depth and meticulous ground handling across Jordan.

Voresta Tours

Amman, Jordan, Al Madinah Al Munawarah St. Complex No. 197

Company registration: 24104

Tourism licence: 21185

24 Hours

TermsPrivacy

Privacy

Privacy policy

How Voresta Tours handles enquiry and guest information.

Last updated: August 5, 2026

This policy explains how Voresta Tours, a Jordan-based tour operator trading as Voresta Tours, handles personal data under Jordan's Personal Data Protection Law No. 24 of 2023 and, where it applies, the EU General Data Protection Regulation (GDPR).

1. Who is responsible for your data

Data controller
Voresta Tours
Registered address
Amman, Jordan, Al Madinah Al Munawarah St. Complex No. 197
Company registration
24104
Tourism licence
21185
Privacy email
info@vorestatours.com
Privacy telephone
+962791302929

2. Personal data we collect

  • Contact and booking details, including names, addresses, email, telephone, nationality, travel dates, group size, preferences and correspondence.
  • Passport, visa, identity, flight and arrival information when needed to arrange or operate a booking.
  • Payment and transaction information. Card details should be handled by the named payment provider; Voresta normally receives confirmation and transaction references rather than full card data.
  • Health, mobility, allergy and dietary information that you choose to provide so services can be delivered safely. This may be sensitive data.
  • Details about accompanying travellers that the lead traveller supplies. The lead traveller must ensure they are authorised to share those details and provide this policy to them.
  • Enquiry content and limited technical security logs generated when the website or systems are used.

Please do not send passport, payment or health information through the general contact form unless Voresta specifically asks for it through an appropriate channel.

3. Why we use data and our legal bases

ProcessingPurposeLegal basis
Enquiries and quotationsReply, design an itinerary, price services and take steps requested before a contract.Steps before entering a contract; legitimate interests in responding and operating the business.
Bookings, passports, flights and companion detailsReserve and deliver accommodation, transport, guiding, tickets, entry and support.Performance of a contract; legal obligations; legitimate interests in safe trip operations.
Payments and financial recordsTake payment, prevent fraud, issue records and meet tax/accounting duties.Contract; legal obligation; legitimate interests in fraud prevention and claims.
Health, allergy, dietary and accessibility detailsAdapt arrangements and protect travellers' wellbeing.Your explicit consent; where strictly necessary, protection of vital interests or another basis permitted by applicable law.
Service messages and emergency supportCommunicate changes, coordinate suppliers and assist during travel.Contract; vital interests in an emergency; legitimate interests in safe operations.
MarketingSend news or offers only where requested or otherwise lawfully permitted.Consent, which may be withdrawn at any time.
Website and security logsKeep services reliable, investigate abuse and protect systems.Legitimate interests in network and information security; legal obligations where applicable.

4. Who receives personal data

Only the minimum data needed for a service is shared. Recipients may include:

  • Hotels, camps, restaurants and other accommodation or hospitality partners.
  • Drivers, guides and local operational partners.
  • Airlines, ticketing, transfer and transport providers.
  • Payment, email, hosting, IT security and booking providers.
  • Professional advisers and insurers where necessary.
  • Jordanian immigration, tourism, police, tax, judicial or other authorities when law requires it.

The named technology-provider list has not yet been completed in the admin settings. It must be verified before production publication.

Voresta does not sell personal data.

5. International transfers

Voresta operates in Jordan, so information supplied by European travellers is processed in Jordan. Jordan is not currently listed by the European Commission as a country covered by an EU adequacy decision. Suppliers may also process data in other countries.

Where GDPR transfer rules apply, Voresta will use an available lawful mechanism appropriate to the transfer, such as European Commission Standard Contractual Clauses with relevant providers, additional technical and organisational safeguards, or a limited GDPR Article 49 derogation where a transfer is necessary to perform the travel contract. You may ask for information about the applicable safeguard.

6. GDPR Article 27 EU representative

Assessment in progress. Because Voresta offers travel services to people in the EU and may process sensitive travel information, the occasional-processing exemption should not be assumed. An EU representative should be appointed before regular EU-facing processing unless documented legal advice confirms an exemption.

7. Retention and deletion

  • Unconverted enquiries: deleted after 24 months.
  • Booking, contract, invoice and transaction records: normally retained for 7 years after the trip or longer only where a legal claim, tax rule or authority requires it.
  • Passport and flight-operation copies: deleted or securely anonymised after the trip and reconciliation, normally within 90 days, unless law or an active claim requires longer.
  • Health, allergy and dietary details: deleted within 30 days after the trip unless you ask Voresta to retain them for a future booking or a legal need applies.
  • Routine technical security logs: retained for up to 90 days unless needed to investigate an incident.

When a period ends, records are deleted or irreversibly anonymised, including from active systems; backup copies expire through the backup rotation. Deletion requests are also communicated to relevant recipients where required.

8. Cookies and tracking

The public website is currently configured without optional analytics or advertising trackers. It uses only functionality necessary to display pages, protect forms and deliver requested services. If optional tracking is added, this section and a consent control must be updated before it is activated.

9. Security and breaches

Voresta uses access controls, encryption in transit, protected administrative access, data minimisation, backups, supplier review and staff procedures appropriate to the risk. No system can be guaranteed completely secure. If a breach creates a legal notification duty, Voresta will notify the competent authority and affected people within the applicable time limits.

10. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, objection and a portable copy of data you provided. You may withdraw consent at any time without affecting earlier lawful processing. You may also object to direct marketing and ask not to be subject to a decision based solely on automated processing that has legal or similarly significant effects. Voresta does not currently use such automated decision-making.

To exercise a right, contact info@vorestatours.com. Voresta may need to verify your identity and will normally respond within the period required by the applicable law.

You may complain to Jordan's Personal Data Protection Directorate or Council. If the GDPR applies to you, you may also complain to the data protection authority in the EU/EEA country where you live, work or believe an infringement occurred.

11. Children and policy changes

A parent or guardian must provide information for a child and authorise its use. Voresta will update this policy when processing or legal requirements change and will show the new “Last updated” date. Material changes will be communicated where required.