1. Who we are and who this policy covers
In short: SAAD ICT runs Muyasir Portal. This policy covers website visitors, agency staff who use the portal, and the people whose records agencies keep in it.
Muyasir Portal (the "Service") is provided by SAAD ICT, Mogadishu, Somalia ("we", "us"). This policy applies to:
- visitors to our website at muyasir.com;
- staff of Hajj and Umrah agencies who use the Service ("Authorised Users");
- pilgrims, travellers, applicants, employees, suppliers and other people whose details an agency records in the Service;
- people who contact us by email or through the website contact form.
Questions and requests about privacy can be sent to info@muyasir.com. This policy is written in English, which is the binding version; Somali and Arabic translations are provided for convenience.
2. Our role: controller or processor
In short: For pilgrim and customer records, the agency decides and is responsible; we process the data for it. For our own website, accounts and support, we are responsible.
Each agency that uses the Service decides which people it records, why and for how long. For that data ("Customer Data") the agency is the data controller and SAAD ICT is its data processor: we store and process it only to provide the Service to that agency and according to its instructions.
SAAD ICT is the controller for the data it handles for its own purposes: website visitors, enquiries, Authorised User accounts, security records, and the agency's subscription and billing records.
If you are a pilgrim, traveller or employee of an agency and have a question about your record, please contact that agency first: it controls your data. We will help the agency respond.
3. What we collect
In short: What we hold depends on how you interact with us. Agencies record identity, travel and payment details about pilgrims; we record account and security details about users.
3.1 Website visitors
- Our public website sets no cookies and uses no analytics, advertising or tracking tools.
- Like any website, our hosting provider receives technical information when a page is requested, such as your IP address, browser type and the page requested, and keeps it in short-lived server logs for security and troubleshooting.
- If you use the contact form, we receive your name, email address and message. To prevent abuse we also store a one-way, salted scrambling (hash) of your IP address and a short description of your browser. We cannot turn the hash back into your IP address.
3.2 Authorised Users (agency staff)
- Account details: full name, email address, phone number (optional), profile photo (optional), role, permissions and the agency you belong to.
- Sign-in data: your password, which is stored only as a one-way hash by our authentication service; one-time sign-in codes, which are stored only as a hash and expire after 10 minutes; and records of verified sign-in sessions.
- Activity records: which records were created, changed or deleted, by whom and when, and administrative actions such as inviting or disabling users. These help agencies keep an audit trail and help us investigate problems.
- Technical data generated when you use the Service, such as IP address and browser information in security and server logs.
3.3 Records agencies keep (Customer Data)
Depending on how an agency uses the Service, it may record the following about the people it serves or employs:
| Category | Examples |
|---|---|
| Identity | Full name (including in Arabic), gender, date of birth, nationality, photo |
| Travel documents | Passport number and expiry date, passport copy, visa number and visa copy, other document numbers |
| Contact | Phone number, email address, emergency contact name and phone number |
| Travel and pilgrimage | Bookings, packages, trips, flights, tickets, hotels, rooms, transport, groups and itineraries |
| Payments | Amounts, dates, payment method and reference, invoices, receipts, refunds, balances |
| Health (only if needed) | Medical notes, medical status and health documents for Hajj, where the agency needs them for the person's safety and care |
| Applications | Name, phone number, passport copy and notes submitted through an agency's own website application form |
| Employees of the agency | Name, nationality, passport number, phone number, photo, salary and employment contract details |
| Suppliers and drivers | Names, phone numbers and email addresses |
3.4 Public verification pages
When someone scans a QR code on a document issued through the Service, we record the time the record was last checked. We do not identify the person who scanned it. A salted hash of the requesting IP address is kept briefly to prevent automated misuse.
4. Why we use personal data and on what basis
In short: To run the Service, keep it secure, support you, bill agencies and meet legal duties. Never for advertising.
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing the Service to an agency: storing and displaying its records, generating documents, invoices, ID cards and manifests | Customer Data, account details | Performance of our contract with the agency; for Customer Data, the agency's own legal basis |
| Creating and securing accounts: sign-in, two-step verification, permissions | Account and sign-in data | Performance of contract; our legitimate interest in security |
| Protecting the Service against abuse, fraud and attacks | Security logs, hashed IP addresses, bot-protection signals | Legitimate interest in security; legal obligations |
| Sending service emails: invitations, sign-in codes, password resets, daily summaries, departure alerts and subscription reminders | Name, email address, relevant record details | Performance of contract; legitimate interest |
| Answering enquiries and providing support by email | Contact details, messages | Legitimate interest in responding; steps before a contract |
| Managing subscriptions and billing | Agency and administrator contact details, payment records | Performance of contract; legal obligations (tax, accounting) |
| Complying with the law and defending legal claims | Relevant records | Legal obligation; legitimate interest |
We do not use personal data for advertising, we do not build marketing profiles, and we do not sell or rent personal data to anyone.
5. Sensitive data
In short: Passport copies and health information need extra care. Agencies should record them only when necessary; we store them privately and restrict access.
Passport and visa copies, dates of birth and especially health information deserve extra protection. Agencies are responsible for recording health information only where it is necessary for a person's safety and care during travel and for having the legal basis and consent the law requires.
- Uploaded documents and photos are stored in private storage and are never public. They can only be opened by signed-in users of the same agency through temporary links that expire.
- Public verification pages never show passport copies or health information, and show document numbers only in part.
- Agencies should grant access to sensitive records only to the staff who need it.
6. Passport scanning (OCR)
In short: Passport scanning happens inside your browser. The image is not sent to any scanning service, and no automated decisions are made.
When a user scans a passport to pre-fill a form, the text recognition runs inside the user's own browser. The passport image is not sent to any external recognition service for this purpose. To run, the browser downloads the recognition engine from a public software distribution network, which receives the user's IP address like any website would.
The result only pre-fills fields that the user must check. The Service does not use it, or any other data, to make automated decisions about any person.
9. Where data is stored
In short: The database and files are stored in the European Union. The application servers run in the United States. Data therefore leaves Somalia.
- The database, uploaded files and backups are stored in a data centre in Stockholm, Sweden, in the European Union.
- The application servers that process requests run in the United States, and pages may be delivered through a global content network closer to the visitor.
- Our email delivery provider and Cloudflare may process data in other countries.
This means personal data is transferred outside Somalia and outside the country of the agency. We use providers that apply strong security and contractual commitments to protect data wherever it is processed, and all data travels over encrypted connections.
10. How long we keep data
In short: Security records are cleaned automatically within days. Agency records are kept while the subscription is active, then deleted within 90 days.
| Data | How long |
|---|---|
| One-time sign-in codes | Valid for 10 minutes; deleted automatically 1 day after they expire |
| Verified sign-in sessions | Valid for 12 hours; deleted automatically 7 days after they expire |
| Invitation links | Valid for 15 minutes |
| Anti-abuse records (hashed IP addresses and phone identifiers) | Deleted automatically after 7 days |
| Public verification links | Pilgrim and traveller links expire after 180 days by default and can be revoked earlier by the agency |
| Customer Data | For as long as the agency's subscription is active and the agency keeps the record, then as described below |
| Records deleted in the Service | Hidden immediately and kept only so that mistakes can be undone and the audit trail stays complete; permanently deleted with the rest of the agency's data at the end of its subscription, or earlier on request |
| Activity and audit records | For the life of the agency's account |
| After a subscription ends | The agency may request an export for 90 days; after that its Customer Data is deleted |
| Backups | Overwritten automatically on a rolling basis within 7 days |
| Contact-form and email enquiries | As long as needed to handle the enquiry and any follow-up; you can ask us to delete them |
| Subscription and billing records | As long as tax, accounting and legal requirements require |
11. How we protect data
In short: Encryption, separation between agencies enforced by the database, two-step sign-in, private files and activity logs.
- Encrypted connections (HTTPS) for all traffic, and encryption of stored data by our infrastructure providers.
- Separation between agencies is enforced by rules inside the database itself, so one agency's users cannot read or change another agency's records.
- Two-step sign-in: a password plus a one-time email code, with limits on attempts and on how often codes can be requested.
- Bot protection on the sign-in and password-reset pages, and rate limits on public pages and forms.
- Private file storage: documents and photos are never public and open only through temporary signed links.
- Role-based permissions, so each user sees and changes only what their role allows.
- Activity logging of changes to records and of administrative actions.
- Masked document numbers on public verification pages, and strict browser security rules that limit which external services the site can contact.
12. Your rights
In short: You can ask to see, correct, delete or export your data, or object to how it is used. Pilgrims should contact their agency first.
Depending on the law that applies to you, you may have the right to:
- access the personal data held about you and receive a copy;
- have inaccurate or incomplete data corrected;
- have your data deleted, or its use restricted;
- object to certain uses of your data;
- receive your data in a portable format;
- withdraw consent, where processing is based on consent;
- complain to the data protection authority in your country.
If your data is held by an agency (for example as a pilgrim, traveller or employee), please contact that agency, which is responsible for your record. For data we control, or if you cannot reach the agency, email info@muyasir.com. We may need to confirm your identity first, and we aim to respond within 30 days. We do not charge for reasonable requests.
13. Children
In short: Only adults use the Service. Agencies may record children who travel, with their guardian's consent.
Authorised Users must be at least 18 years old. Agencies may record details of children who travel with their families; the agency is responsible for obtaining any consent required from a parent or guardian. Our website is not directed at children.
14. Security incidents
In short: If a breach affects your data, we act quickly and tell the agencies concerned.
If we become aware of a security incident that affects personal data, we will act promptly to contain it, investigate it and reduce its effects. We will inform affected agencies without undue delay, and where possible within 72 hours of confirming the incident, with the information they need to meet their own obligations. Where the law requires, we or the agency will also inform the authorities and the people affected.
15. Changes to this policy
In short: We update this page when the Service changes, and tell agencies about important changes.
We will update this policy when our practices or the Service change. The effective date and version at the top of this page show the latest update. We will notify agencies' administrators of material changes by email or in the Service before they take effect.
16. Contact
In short: How to reach us about privacy.
SAAD ICT, Mogadishu, Somalia. Privacy and data requests: info@muyasir.com. Website: muyasir.com.