Privacy policy

Your personal data is used only to respond to your requests and organise your services. This page explains which data, why, and what your rights are under the General Data Protection Regulation (GDPR).

Data controller

The data controller is Fatma Travel Service & Partners, whose contact details are given in the legal notice. For any question about your data, write to the agency's email address.

Data we collect

When you fill in a form (contact, quote, booking, parcel shipping):

  • your name, email address and phone number;
  • the details of your request: destination, dates, number of travellers, service requested, message;
  • for a parcel: the names, phone numbers and addresses of the sender and recipient, and a description of the contents.

When you contact us by phone, WhatsApp or email, we receive the information you choose to share. For a visa application, other documents may be requested at the agency; they are not collected through this website.

For the website's security, technical data (IP address, browser type, errors encountered) is processed temporarily to block abuse and fix faults.

Why we use it

  • responding to your request and sending you a quote — pre-contractual steps taken at your request (Art. 6(1)(b) GDPR);
  • organising and following up the services you book — performance of a contract (Art. 6(1)(b));
  • meeting our accounting, tax and legal obligations — legal obligation (Art. 6(1)(c));
  • protecting the website against abuse and keeping it running properly — legitimate interest (Art. 6(1)(f)).

We do not sell your data or use it for advertising.

Who has access

Only the agency team handles your requests. To provide the services you ask for, some data is passed on to the partners concerned: airlines, hotels, insurers, carriers, vehicle rental companies.

The website also relies on technical providers acting on our behalf: website hosting (Vercel), database (Neon), email delivery (Resend), abuse protection (Upstash) and error tracking (Sentry).

Some of these providers may process data outside the European Union. These transfers are covered by the safeguards provided for by the GDPR, such as the European Commission's standard contractual clauses or the EU–US Data Privacy Framework.

How long we keep it

  • request not followed up: 24 months at most after our last contact;
  • customer file: for the duration of the service, then for the periods required by Belgian accounting and tax law;
  • technical security data: a few days to a few weeks.

Cookies

This website uses no advertising cookies and no audience measurement tool. Only items strictly necessary for it to work may be stored in your browser; they do not require consent.

Your rights

You may at any time request access to your data, its correction or deletion, restriction of processing, object to it or request its portability. Write to us by email; we reply within one month.

If you believe your rights are not being respected, you can lodge a complaint with the Belgian Data Protection Authority (APD/GBA), rue de la Presse 35, 1000 Brussels — www.dataprotectionauthority.be.

Safety

Exchanges with the website are encrypted (HTTPS) and access to requests is restricted to the agency team. Do not send us a copy of your passport or any sensitive document through the form: bring them to the agency or ask us for the safest way.

Last updated: 4 October 2026

Legal notice