LEGAL
Privacy Notice
This notice explains what personal data USTOUR collects through this website, why and on what legal basis it is processed, how long it is kept, who receives it and what rights you have. It has been prepared in accordance with the requirements of the EU General Data Protection Regulation (GDPR) and applies alongside the data-protection law of North Macedonia, where USTOUR is established.
1 · Data controller
Ustur Dooel Skopje (trading as USTOUR) — Macedonia Square No.1/1-0, 1000 Skopje, North Macedonia
Email: [email protected] · Phone: +389 70 773 884
USTOUR is a destination management company serving travel agencies and tour operators. If you contact us on behalf of an agency, we process your details as the agency's representative.
2 · What data we collect
You can browse the site without sharing any personal data. We collect data only when you submit one of the forms below.
Contact / quote request form
- Full name and phone number
- Email address and preferred time to be contacted (optional)
- Your note about the request
- The page the request came from, so we understand which service you are interested in
- The itinerary preferences you select in the Itinerary Planner (route, duration, group size, concept, period, service selections) and, optionally, your agency's name
Group price quote form
- The contact details listed above
- The itinerary you are interested in, planned date, group size and room type
At the quotation stage we do not ask for passenger details such as traveller names or dates of birth; those are shared only once an operation is confirmed, and outside this website.
Technical data
When a form is submitted, a one-way hash (an irreversible fingerprint) of your IP address is stored for up to 24 hours to prevent automated abuse. The IP address itself is not stored.
Visit statistics
We measure how often pages are viewed. This measurement does not identify you: no personal profile is built, no cookies are set for it, it is not used for advertising and nothing is shared with advertising networks.
3 · Purposes and legal bases
- Handling your request: contacting you, preparing an itinerary or quotation and planning the operation. Legal basis: steps taken at your request prior to entering into a contract, and performance of the contract (GDPR Art. 6(1)(b)); for the details you choose to add, your consent (Art. 6(1)(a)).
- Service quality and site improvement: understanding which services attract interest, using aggregated, non-identifying statistics. Legal basis: our legitimate interest in running and improving the website (Art. 6(1)(f)).
- Preventing abuse of the forms: the short-lived IP hash described above. Legal basis: legitimate interest in the security of the service (Art. 6(1)(f)).
- Legal obligations: record-keeping and retention required by applicable law (Art. 6(1)(c)).
We do not use your data for automated decision-making or profiling, and we do not send marketing messages unless you have asked for them.
4 · Retention
Form data is kept for no longer than 24 months after your request is closed. If the request leads to a contract, the data needed for that contract is kept for as long as the law on commercial and tax records requires. At the end of the period the data is deleted or anonymised. You can ask for earlier deletion at any time (see section 8).
The IP hash used against abuse is deleted automatically within 24 hours.
5 · Who receives the data and where it is stored
Your data is not sold, rented or passed to third parties for marketing. It is processed by the following processors, each bound by a data-processing agreement:
- Supabase — the database where form submissions are stored. Our project runs in the European Union (Ireland, AWS eu-west-1).
- Netlify — hosting and delivery of the website through a global content-delivery network. Page requests are served from the location nearest to you; form data is not stored by Netlify.
- Google Workspace — our email service, used to send you a confirmation of your request and to correspond with you.
- If your request turns into a tour operation, the data needed to run that operation (names on a rooming list, arrival details) is shared with our suppliers in the destination countries — hotels, transport and guide services — only to the extent necessary.
Where a recipient is located outside the European Economic Area, the transfer relies on the European Commission's standard contractual clauses or on an adequacy decision. USTOUR itself is established in North Macedonia, whose data-protection law is aligned with the GDPR.
6 · Security
Data is transmitted over encrypted connections (TLS) and stored in a database protected by access controls: only authorised USTOUR staff can read form submissions, through an authenticated administration panel. Access is limited to what each role needs.
7 · Cookies
This site uses no advertising or tracking cookies, which is why you see no cookie banner. The only technical record kept in your browser is a session flag that stops the opening sequence from playing twice in the same visit; it is deleted when you close the tab and does not identify you. The administration panel used by our staff sets a login cookie, which is not relevant to visitors.
8 · Your rights
Under the GDPR and equivalent local law you have the right to:
- Access the personal data we hold about you and receive a copy;
- Rectification of inaccurate or incomplete data;
- Erasure of your data where there is no longer a reason to keep it;
- Restriction of processing while a request is being examined;
- Data portability — receiving the data you gave us in a structured, machine-readable format;
- Object to processing based on legitimate interest;
- Withdraw consent at any time, without affecting processing carried out before withdrawal;
- Lodge a complaint with a supervisory authority: the Personal Data Protection Agency of North Macedonia, the data-protection authority of your own EU or EEA country, or, for residents of Türkiye, the Personal Data Protection Authority (KVKK).
To exercise any of these rights, write to [email protected]. We respond without undue delay and in any case within one month; if a request is complex we may extend this by two further months and will tell you why. We may ask you to confirm your identity before acting on a request.
9 · Children
Our services are offered to travel professionals. We do not knowingly collect personal data from children under 16; if you believe a child has submitted a form, contact us and we will delete the data.
10 · Changes
This notice may be updated as our services or legal obligations change. The current version is always published on this page and the date above is updated.
