SECURITY AND GDPR

Your pilgrims' data stays protected

Passports, contact details, payments: an Umrah agency handles sensitive personal data. Here is what OmraDesk does to protect it — every point below is in place today and verifiable in the application.

Hosted in the European Union · Data processing agreement (DPA) available for signature

What protects your data, concretely

Seven measures, all in place today.

Hosted in the European Union

Platform data is hosted and backed up in the European Union. The only transfers outside the EU are the ones you trigger yourself, file by file, to the Saudi visa routes.

Each agency isolated in its own space

Your files, documents and conversations are partitioned: an agency never sees another agency's data.

Roles and permissions per job

Adviser, accounting, operations, management: each user accesses what they need. Access is granted and revoked by your agency's administrator.

Audit log of sensitive operations

Viewing and downloading passports, payment changes, exports: sensitive operations are logged with the user, the date and the file concerned.

Expiring download links

A shared document (passport, visa, rooming list) is served through a link that expires after five minutes. A link pasted into a conversation does not give indefinite access to the file.

Automatic passport purge

Passport copies are deleted automatically six months after the pilgrim's return. You do not keep identity documents without reason, and you do not have to think about it.

GDPR-compliant processing, DPA for signature

OmraDesk acts as a processor under the GDPR: a data processing agreement (Article 28) is available for signature, and the privacy policy details each processing activity.

Frequently asked questions

Where is my agency's data hosted?

In the European Union, with backups also located in the European Union. The only data leaving the EU is what you send yourself to a visa route (eVisa, Nusuk or a partner) for a given file — the step required to obtain the pilgrim's visa, triggered by your agency and never automatically.

Who can access my pilgrims' files?

The users of your agency to whom you have assigned a role, within the limits of that role. Access is created and revoked by the agency administrator, each agency is isolated from the others, and sensitive operations (viewing a passport, exporting, changing a payment) are logged with the user and the date.

Can I sign a data processing agreement (DPA)?

Yes. A processing agreement compliant with Article 28 of the GDPR is available for signature for every client agency. It sets out the processing carried out, the security measures and the conditions for returning or deleting data at the end of the contract. Request it at contact@omradesk.com.

A question about security or GDPR?

Write to us or request the DPA: we reply within one business day.

Security and GDPR: how OmraDesk protects your data | OmraDesk