Privacy Policy

Privacy Policy

Effective and last reviewed: 31 July 2026

This policy explains how Quest Travel (“Quest Travel”, “we”, “us” or “our”), the trading name of شركة البحث للسياحة والسفر ذات مسؤولية محدودة, handles personal data relating to travellers, website visitors, business partners, suppliers and people who contact us. We apply Jordan’s Personal Data Protection Law No. 24 of 2023 and other applicable Jordanian requirements. The EU General Data Protection Regulation (“GDPR”) and other laws apply where their territorial rules are met.

1. Controller and privacy contact

For website enquiries and travel services contracted directly with Quest Travel, the controller is شركة البحث للسياحة والسفر ذات مسؤولية محدودة, a Jordanian limited liability company registered under company number 65405 and national establishment number 200190172, with its current public office at Wasfi At-Tall St., Amman 11953, Jordan.

Privacy requests and complaints may be sent to info@questtravel-jo.com or by telephone at +962 (6) 401 7366. When an overseas tour operator, employer, association or other client supplies traveller data, that organisation may also be a controller and Quest Travel may process information on its instructions for the agreed local services.

2. Data we collect

  • Identity and contact data: name, title, nationality, postal or email address, telephone number and emergency contact.
  • Travel-service data: requested dates and services, accommodation or transport preferences, booking references, passport or identification details where needed, and communications about an enquiry or confirmed service.
  • Sensitive data: health, dietary, mobility, accessibility or similar information only where relevant to safety or requested service delivery.
  • Business data: employer, agency, supplier role, work contact details, contracts, correspondence and account records.
  • Transaction data: invoice, payment status, currency and related accounting information. The payment method and any external payment provider will be identified when payment is requested.
  • Website and device data: IP address, browser/device information, pages visited, approximate location, consent choices and security logs.
  • Marketing preferences: newsletter subscription, language and communication choices.

Fields marked as required in a form or confirmation are necessary to respond, meet a legal requirement or provide the requested service. Optional fields may be left blank, although this may limit our ability to tailor or safely deliver a service.

3. Sources of data

We receive data directly from you through forms, email, telephone, messaging and service communications. We may also receive it from an authorised family member, travel companion, overseas tour operator, travel agent, employer, corporate organiser, event organiser, supplier or referral partner. If you give us another person’s data, you must be authorised to do so and make this policy available to them.

4. Why and on what basis we use data

  • Enquiries and services: to answer requests, prepare proposals, take steps before a contract, confirm and deliver services, communicate operational information and provide assistance.
  • Legal and financial duties: to keep accounting records, respond to authorities, prevent fraud and meet applicable legal obligations.
  • Legitimate interests: to operate and secure the website, administer business relationships, improve services, maintain records and defend legal claims, after considering the effect on individuals.
  • Consent: for optional marketing, non-essential cookies and sensitive health or accessibility information where consent is the appropriate legal basis. Consent may be withdrawn at any time without affecting earlier lawful processing.
  • Vital interests: in a genuine emergency where processing is necessary to protect a person and another lawful basis is not available.

We do not treat ordinary browsing as blanket consent. Where GDPR applies to health or similar special-category data, we seek explicit consent unless another Article 9 condition is documented. Please provide only the minimum information needed.

5. Sharing

We share only what is reasonably necessary with selected hotels, transport companies, guides, venues, restaurants, activity providers and other suppliers involved in a requested service. We may also use website hosting, security, analytics, email, newsletter, map, form and IT providers; professional advisers; banks or payment providers; and public authorities where lawfully required.

Recipients may act as independent controllers or as processors under contract. We do not sell personal data. We require service providers handling data on our behalf to use it only for authorised purposes and to apply appropriate confidentiality and security protections.

6. International transfers

Travel delivery and our use of global technology providers can require data to be accessed or transferred outside the country where it was collected, including to Jordan and to a traveller’s destination or supplier location. We apply the approvals, contracts and safeguards required by Jordanian law.

Where GDPR applies and the destination is not covered by an adequacy decision, we rely on an applicable safeguard such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where appropriate, or on a lawful derogation for a transfer necessary to perform a requested contract. You may request information about the relevant safeguard and a copy subject to permitted redactions by contacting us.

7. Retention

We retain personal data only for as long as needed for the purpose collected. The period is determined by the status and duration of an enquiry or service relationship; accounting, tax and regulatory requirements; supplier and contract obligations; limitation periods; safety and incident needs; and the time needed to establish, exercise or defend claims.

Unconfirmed enquiries and marketing records are reviewed periodically and deleted or anonymised when no longer needed. Consent records are retained for as long as necessary to demonstrate and manage the choice. Sensitive service information is restricted and removed when it is no longer needed, unless a legal or claims-related reason requires continued retention. You may ask for the retention criteria applying to your record.

8. Security and incidents

We use proportionate organisational and technical measures intended to protect personal data, including access controls, role-based handling, supplier controls and secure communication and hosting measures appropriate to the risk. No internet service is completely secure, so please avoid sending unnecessary passport, health or financial information through open channels.

We investigate suspected personal-data incidents and notify affected individuals and the competent authority when and within the time required by applicable law.

9. Cookies and analytics

Necessary cookies support security, language, consent and basic website functions. Optional cookies may support analytics, preferences, embedded content or advertising. Optional cookies should be used only after the required consent. You can accept, reject or change choices through the cookie banner or the consent-preferences control. The Cookie Policy identifies the cookies currently detected, their purpose, provider and duration.

10. Marketing

We send newsletters or promotional messages only where there is a lawful basis. You can unsubscribe using the link in a message or by contacting us. Operational messages about an enquiry or confirmed service are not marketing and may continue where necessary.

11. Your rights

Subject to the law that applies, you may request access to your data and information about its use; correction of inaccurate data; deletion; restriction or objection; a portable copy; withdrawal of consent; and review of a decision based solely on automated processing. You may also object to direct marketing at any time.

We may ask for information needed to verify identity and authority. We will respond within the applicable legal period and explain any lawful restriction. Quest Travel does not intend to make decisions producing legal or similarly significant effects solely by automated means. If that changes, we will provide the required information and safeguards.

12. Complaints

Please first contact info@questtravel-jo.com so we can investigate. You also have the right to complain to Jordan’s competent Personal Data Protection authority or, where GDPR applies, to the supervisory authority in the EU/EEA country of your habitual residence, workplace or the alleged infringement. Contact details for Jordan’s Personal Data Protection Unit are available through the Ministry of Digital Economy and Entrepreneurship at modee.gov.jo.

13. Children

The website is not directed to children acting independently. Information about a child should be provided only by a parent, guardian or properly authorised organiser and only where necessary for the requested service. We apply additional care and seek the approvals required by law.

14. External links and policy updates

External sites and platforms have their own privacy practices. We may update this policy to reflect legal, operational or technology changes. The effective and review dates above show the current version; material changes will be communicated when required.

15. Contact

Quest Travel
Trading name of شركة البحث للسياحة والسفر ذات مسؤولية محدودة
Wasfi At-Tall St., Amman 11953, Jordan
Email: info@questtravel-jo.com
Telephone: +962 (6) 401 7366
Website: questtravel-jo.com

At Quest Travel Jordan - DMC , We believe every journey should be an unforgettable experience. Whether you're planning luxury, FIT, Travel , MICE , Groups , or tailor - made programs and deliver seamless planning and authentic experiences across Jordan.



+962 6 4017366


info@questtravel-jo.com

Quest Travel Jordan – DMC, Wasfi Al Tal Street, Amman

GDPR

  • Privacy Consent

Privacy Consent

By submitting this form, I confirm that I have read and agree to the Privacy Policy. I consent to Quest Travel Jordan – DMC processing my personal data to respond to my inquiry.