GDPR & Data Protection

This page explains how Ziyara.io complies with the EU General Data Protection Regulation (GDPR), the UK GDPR, and equivalent data protection laws. It supplements our Privacy Policy.

Our two roles: controller and processor

Ziyara.io acts in two distinct roles under the GDPR:

If you are a pilgrim whose data was entered by a travel agency, that agency is the controller of your data. Please direct requests to access, correct, or delete your data to your agency first — we assist agencies in fulfilling such requests without undue delay.

Data Processing Agreement (DPA)

We offer all agency customers a Data Processing Agreement in accordance with Article 28 GDPR. You can review it at ziyara.io/dpa. A countersigned copy is available on request at info@ziyara.io.

Special categories of data

Records relating to Umrah and Hajj travel can indirectly reveal religious beliefs, which are a special category of personal data under Article 9 GDPR. Ziyara.io processes such data exclusively as a processor, on the instructions of the agency, which as controller is responsible for having a lawful basis (typically the pilgrim's explicit consent as part of the booking). We apply heightened security measures to all pilgrim data, as described below.

Legal bases (where Ziyara.io is controller)

We process customer account and website data on the basis of contract performance (Art. 6(1)(b)), legitimate interests such as service security and improvement (Art. 6(1)(f)), legal obligations (Art. 6(1)(c)), and consent where required, for example for non-essential cookies (Art. 6(1)(a)).

Where data is stored and how it is protected

Sub-processors

We use a small number of vetted service providers to operate the platform (hosting, file storage, e-mail, SMS/WhatsApp delivery, push notifications, payments, error monitoring, website analytics). The current list, including locations and safeguards, is published at ziyara.io/subprocessors. We inform agency customers before adding or replacing sub-processors that process pilgrim data.

International transfers

Core service data stays in the EU. Where a sub-processor transfers personal data outside the EEA/UK (for example for push notifications, error monitoring or website analytics), we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs), adequacy decisions, or the EU–US Data Privacy Framework.

Your rights

You have the right to access, rectify, erase, restrict processing, receive a copy of (data portability), and object to the processing of your personal data. Agency customers can additionally export their complete data (ZIP archive) and request account deletion directly from the agency panel at any time. To exercise any right, contact info@ziyara.io — we respond within 30 days. You may also lodge a complaint with your local supervisory authority.

Data breach notification

In the event of a personal data breach affecting pilgrim data, we notify the affected agencies without undue delay after becoming aware of it, with the information they need to meet their own 72-hour notification obligation under Article 33 GDPR.

Retention and deletion

We retain personal data for as long as the agency's account is active or as required by law. After a confirmed account deletion, live data is deleted within 30 days; residual copies in encrypted backups expire with the backup rotation shortly thereafter. Agencies can also delete individual pilgrim records themselves at any time.

Contact

Data protection questions and requests: info@ziyara.io


See also: Data Processing Agreement · Sub-processors · Privacy Policy