1. Introduction
Agadir Explore Tours ("Get Agadir", "we", "us") is committed to protecting and respecting your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who has access to it, and the rights you have over it.
This policy applies to visitors of getagadir.com and to customers who book tours, activities, or transfers with us in Agadir, Taghazout, and across Morocco.
2. Data Controller
Agadir Explore Tours, based in Agadir, Morocco, is the data controller responsible for your personal data within the meaning of Moroccan Law No. 09-08 on the protection of personal data and, where applicable, the EU General Data Protection Regulation (GDPR) for residents of the European Economic Area.
3. Personal Data We Collect
3.1 Data you give us directly
- Contact details: full name, email address, phone number (often WhatsApp), country of residence.
- Booking data: chosen tour or activity, date, number of participants, hotel or pickup address in Agadir/Taghazout, language preference.
- Activity-specific data: participant age, approximate weight (for quad or buggy allocation), dietary needs, medical conditions relevant to safety (e.g. pregnancy, mobility).
- Payment data: we do not store full card numbers. We may retain proof of payment and the last four digits of any card used.
- Correspondence: the content of messages you send us by email, WhatsApp, contact form, or social media.
3.2 Data collected automatically
- Device and browsing information: IP address, browser type, screen size, pages visited, referring URL.
- Location data: approximate country and city derived from your IP, used for fraud prevention and language selection.
- Cookies and similar technologies — see our Cookie Policy.
3.3 Data from third parties
Where you book through an agency or partner, we may receive the booking data they share with us in order to deliver the Service.
4. How We Use Your Data
We process your personal data for the following purposes:
- Service delivery: confirming and operating your Booking, organising pickup, and adapting the activity to your needs.
- Communication: sending booking confirmations, itinerary changes, weather updates, and responding to your questions.
- Payment: processing deposits, balances, and refunds, and preventing fraud.
- Safety and legal compliance: keepingincident records, cooperating with local authorities, and meeting Moroccan tourism and tax requirements.
- Improvement: analysing how the Site is used, fixing issues, and improving our tours and listings.
- Marketing: with your explicit consent, sending occasional offers and travel inspiration. You can unsubscribe at any time from any marketing message.
5. Legal Bases for Processing (GDPR)
For EEA residents we rely on the following legal bases:
- Contract: to deliver the Booking you have requested.
- Legal obligation: to meet tax, accounting, and safety record-keeping duties.
- Legitimate interests: fraud prevention, Site security, and improving our Services, balanced against your privacy rights.
- Consent: for marketing, on-site tracking cookies, and any sensitive medical data you volunteer.
- Vital interests: in an emergency affecting a participant's health or safety.
6. Data Sharing and Recipients
We share personal data only where necessary:
- With the local Supplier (guide, driver, venue) delivering your Service, limited to what they need to operate it safely.
- With payment and booking platform providers to process your payment.
- With WhatsApp, email, and SMS providers to deliver our messages to you.
- With Moroccan public authorities where required by law.
- With analytics and hosting providers acting as data processors under contract.
We do not sell your personal data. Where a Supplier is based outside Morocco, we share only the minimum data needed to deliver the Service and require equivalent confidentiality.
7. International Data Transfers
Because some providers (hosting, analytics, map services) are located outside Morocco, your data may be processed in those countries. We rely on appropriate safeguards such as standard contractual clauses and selected providers with adequate data-protection practices. For EEA residents, transfers outside the EEA are carried out under recognised GDPR safeguards.
8. Data Retention
We keep your personal data only as long as necessary:
- Booking and payment records: up to 7 years for accounting and tax obligations.
- Safety and incident records: up to 7 years after the event.
- Marketing data: until you unsubscribe, or 2 years after your last interaction.
- Web analytics and logs: up to 13 months, then aggregated or deleted.
After the retention period we either delete the data or anonymise it so it can no longer identify you.
9. Security Measures
We apply reasonable technical and organisational measures to protect your data, including restricted internal access, encrypted connections (HTTPS), and regular review of our systems. No online transmission is fully secure, so we cannot guarantee absolute security, but we act promptly on any confirmed incident.
10. Your Rights
Depending on your country, you may have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erasure ("right to be forgotten") where retention is no longer justified.
- Restrict or object to processing, including marketing.
- Data portability: receive your data in a structured, machine-readable format.
- Withdraw consent at any time, without affecting the lawfulness of prior processing.
- Lodge a complaint with the competent supervisory authority.
To exercise any right, contact us using the details in Section 12. We will reply within one month (extendable by two months for complex requests).
11. Children's Privacy
The Site is not directed at children under 16 acting alone. Bookings for minors are made by a parent or guardian. We process a child's data only to deliver the Service and we apply enhanced care to data such as age, medical notes, and photographs. Please do not send us data about anyone under 16 outside a confirmed Booking.
13. Changes to This Policy
We may update this Privacy Policy to reflect legal changes or new features of our Services. The "Last updated" date above indicates the latest revision. Where the changes are material, we will highlight them on the Site or notify customers with active Bookings.