Clear rules for a secure multi-tenant platform.
These terms explain how Hoggaan Portal is provided to Hajj and Umrah companies, how tenant data is protected, and how responsibilities are divided between Hoggaan Travels, tenant companies, and authorized users.
Last updated: 2026-08-10
Important legal role distinction
When Hoggaan Travels uses the Portal for its own travel operations, Hoggaan Travels acts as data controller. When another Hajj or Umrah company uses the Portal, that tenant controls its own customer and operational data, while Hoggaan Travels operates the platform as data processor on the tenant's instructions.
Controller & Processor Roles
Hoggaan Travels
Hoggaan Travels operates Hoggaan Portal. It is controller for its own business data and processor for data managed by independent tenant companies.
Tenant Company
Each tenant manages its own users, pilgrims, trips and records and decides why that data is collected and used.
Using the same platform does not merge tenant data or change who controls it.
Platform Agreement
A tenant subscribes to Hoggaan Portal for its organization and creates authorized user accounts for staff.
- The tenant is responsible for the people it authorizes to use its account.
- The Portal may only be used for lawful business operations.
- Credentials must not be shared with unauthorized persons.
- Access must be removed when a user no longer needs it.
Tenant Responsibilities
The tenant decides what customer information belongs in its workspace and must have a lawful reason to collect and use it.
- Only upload data genuinely needed for Hajj, Umrah, travel, finance, staffing or related lawful operations.
- Provide required privacy information to pilgrims, customers, staff and other data subjects.
- Keep records accurate and correct errors promptly.
- Do not upload medical or other sensitive information unless genuinely necessary and lawfully permitted.
- Give users only the access they need.
Customer Data & Ownership
Tenant control
The tenant keeps control and rights over the data it places in its workspace.
No routine Hoggaan access
Hoggaan staff do not routinely open or view an independent tenant's operational records.
Limited platform use
Tenant data is used to run, secure, support and maintain the Portal—not to market Hoggaan Travels' travel services to another company's customers.
Tenant isolation
Each company has its own workspace. One tenant must not be able to view another tenant's records.
Data We Process
| Category | Examples | Purpose | Typical role |
|---|---|---|---|
| Tenant & User Account | Company name, user name, role, email, phone, authentication and account status | Account administration, access control, support and security | Hoggaan may be controller for platform account/admin data |
| Identity & Documents | Full name, nationality, date of birth, passport number/copy, photo, visa details | Pilgrim/customer administration, travel documents and verification | Tenant controller / Hoggaan processor |
| Travel & Hajj/Umrah Operations | Trips, flights, PNR/tickets, hotels, rooms, groups, transport and itinerary | Travel and pilgrimage operations | Tenant controller / Hoggaan processor |
| Contact & Emergency | Phone, email, address if provided, emergency contact details | Communication, coordination and emergency support | Tenant controller / Hoggaan processor |
| Medical / Health | Limited health or assistance information where needed | Safety, support and operational accommodation where lawfully necessary | Tenant controller / Hoggaan processor |
| Payment & Audit References | Amount, method, transaction/reference number, payer mobile number where recorded, receiving-bank reference | Reconciliation, accounting and audit trail | Usually tenant controller / Hoggaan processor |
| Technical & Security | Login events, IP/device information where generated, audit events, session/security logs | Security, authentication, troubleshooting and auditability | Hoggaan may be controller or processor depending on purpose |
| Support & Communications | Support requests, notices and operational communications | Support, incident handling and service administration | Depends on context |
The Portal is designed for data minimization. Tenants should not store information simply because a field or upload function is available.
Medical & Sensitive Information
Medical information is not a standard requirement, but a tenant may record limited health information during Hajj or another operation where it is genuinely necessary.
- Do not upload medical information unless it is genuinely needed.
- Restrict access to staff who need it.
- Do not use medical information for unrelated profiling or marketing.
- Remove it when no longer required, subject to lawful retention duties.
Security & Tenant Isolation
Tenant separation
Records are scoped to the correct company workspace and authorized users.
Least privilege
Users should receive only the permissions needed for their work.
Protected infrastructure
The service uses hosted infrastructure and security controls intended to protect data during storage, transit and access.
Auditability
Relevant operational and security actions may be logged for accountability and investigation.
Service Providers & Subprocessors
Hoggaan Portal relies on trusted infrastructure and service providers to host and operate the platform.
Hosting & International Transfers
Production data is hosted using Supabase infrastructure on AWS in the eu-north-1 region. This means data may be stored or processed outside Somalia.
OCR & Document Extraction
The Portal may use OCR to read text from uploaded documents and pre-fill fields. OCR assists data entry; it does not decide whether a person may travel, receive a visa, or qualify for a service.
Retention, Export & Deletion
| Stage | Retention | What happens |
|---|---|---|
| Active subscription | For the duration of the service | Tenant controls and manages its Customer Data, subject to applicable retention duties. |
| After cancellation / termination | 3 months | Customer Data remains in a limited retention period for export, recovery or orderly closure, then is scheduled for deletion. |
| Backups | According to the platform backup lifecycle | Deleted data may remain temporarily in protected backups until expiry or overwrite. |
| Required records | As required by applicable law or legitimate security/dispute needs | Only the minimum necessary records may be kept beyond the normal deletion period. |
Tenants should export data they need before the three-month post-cancellation period ends.
Data-Subject Rights
People whose data is stored in a tenant workspace should normally contact that tenant first because the tenant controls the data. Hoggaan will assist where processor assistance is required.
- Access personal data where applicable.
- Ask for inaccurate data to be corrected.
- Request deletion or restriction where applicable.
- Object to certain processing where applicable.
- Request portability where applicable.
- Raise concerns about unlawful or unfair processing.
Security Incidents & Breaches
If a security incident affects tenant data, Hoggaan Travels will investigate, contain it and inform the affected tenant when notification is required.
Acceptable Use
- Do not use the Portal for unlawful, fraudulent or unauthorized purposes.
- Do not attempt to access another tenant's workspace or bypass permissions.
- Do not upload data you have no lawful right to process.
- Do not interfere with service security, availability or integrity.
- Do not share accounts with unauthorized persons.
Subscriptions & Service Operation
Subscription prices, enabled modules and billing terms are those agreed with the tenant when the service is ordered.
- The tenant pays the agreed subscription fees.
- The Portal may receive maintenance, security and feature updates.
- Temporary interruptions may occur for maintenance, incidents or third-party infrastructure failures.
- Unless a separate SLA says otherwise, this page does not promise a specific uptime percentage.
Termination
When a tenant ends the service, user access may be disabled and the tenant should export required records. Customer Data is retained for three months and then deleted, subject to limited legal, dispute, security and backup exceptions.
Applicable Law & Regulatory Cooperation
The Portal is operated from Somalia and is intended to be run in accordance with applicable Somali law, including applicable data-protection requirements. Each tenant must also follow laws and sector rules applicable to its own operations.
Change Log
- Rewritten for Hoggaan Portal as a B2B multi-tenant platform, including controller/processor roles, tenant isolation, sensitive data, subprocessors, eu-north-1 hosting, OCR, rights, incidents, and three-month post-termination retention.