Last updated: 21 September 2026
This Privacy Policy explains how Blackrock International CSP LLC, trading as Blackrock Technologies, Processes Personal Data (both defined below) when you visit our website at blackrockts.com, available in English at /en and in Arabic at /ar (the Website), contact us, apply for a job with us or deal with us as a business contact or partner, and what rights you have.
In this policy, Personal Data means any information relating to an identified or identifiable individual, and Process and Processing mean any operation on Personal Data, such as collecting, storing, using, sharing or deleting it. Blackrock, we, us and our mean Blackrock International CSP LLC, and you means the individual whose Personal Data we Process.
1. Who we are
The Website is operated by Blackrock International CSP LLC, which trades as Blackrock Technologies. Blackrock is a travel-technology company that provides B2B, B2C and corporate booking platforms, a back-office system and WebAdmin, supplier connectivity, custom engineering and AI agents to travel businesses across the Gulf Cooperation Council (GCC) region and beyond, including in Europe. Blackrock Technologies has offices in Dubai (United Arab Emirates), Riyadh (Saudi Arabia), Cairo (Egypt) and Edinburgh (United Kingdom).
For the Personal Data described in this policy, Blackrock is the controller: the organisation that decides why and how it is Processed. Where any of the Data Protection Laws (section 3) uses a different term for that role, "controller" means that role.
You can contact us at info@blackrockts.com or through our contact form at /contact (the Contact Form); see section 21. Please send privacy questions and requests to those contact details, and we will direct them to the right person within Blackrock.
2. Scope of this policy
2.1 Who and what this policy covers
This policy applies to Personal Data that we Process about:
- visitors to the Website;
- people who contact us through the Contact Form or by email, including to request a demonstration, apply to become a partner, make a general enquiry or ask to meet us at a trade event;
- people who apply for a job with us; and
- individuals at partners, prospective partners, clients and prospective clients, and individuals whose details we receive in connection with trade events (together, Business Contacts).
2.2 What this policy does not cover
Blackrock's products (booking platforms, WebAdmin and AI agents) Process client data under separate written agreements with Blackrock's clients, and this policy does not apply to that data. For questions about Personal Data Processed through a platform provided to a travel business, ask that travel business. If you are a Blackrock client, see your agreement or ask your usual Blackrock contact. If you are unsure whom to ask, write to info@blackrockts.com and we will direct your question. This policy does cover the business contact details of individuals at clients that we hold for our own relationship with them. It does not cover Personal Data Processed through the platforms we provide. This policy also does not cover Blackrock's own employees and workers.
2.3 Illustrative content
The product screens, demonstration data and some images and illustrations on the Website are illustrative. They do not necessarily show real clients, people, offices or results.
2.4 Relationship to the Terms of Use
Please read this policy together with our Terms of Use, which govern your use of the Website. If the Terms of Use and this policy conflict on the Processing of Personal Data, this policy prevails. This policy is a notice of how we Process Personal Data and does not limit any right you have under the Data Protection Laws.
Your use of the Website, or your agreement to the Terms of Use, is not in itself consent to the Processing of Personal Data. We rely on consent only where this policy says so (sections 7, 8 and 10) and, where we do, we ask for it for the specific purpose concerned.
3. Which laws apply and how this policy works
Depending on who you are and where you are, Personal Data about you may be protected by one or more of the following laws (together, the Data Protection Laws):
- United Arab Emirates: Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the UAE PDPL);
- Saudi Arabia: the Personal Data Protection Law, issued by Royal Decree No. M/19 of 1443H, as amended (the Saudi PDPL);
- Egypt: Personal Data Protection Law No. 151 of 2020 (the Egyptian PDPL);
- United Kingdom: the UK General Data Protection Regulation (the UK GDPR) and the Data Protection Act 2018;
- European Union: Regulation (EU) 2016/679, the General Data Protection Regulation (the EU GDPR); and
- any other law relating to the protection of Personal Data that applies to the Processing concerned, including the law of another GCC country or of the country where you live or work.
The UAE PDPL, the Saudi PDPL and the Egyptian PDPL are together the PDPLs.
Which law applies to a particular item of Processing depends on the circumstances, including where you are and where we or our Service Providers (section 9) operate. This policy is one document for all of them: it describes one set of rights (section 13), exercisable to the extent the laws that apply to you provide for them, gives the lawful basis and PDPL equivalent for each purpose (section 7), and adds region notes where the laws differ (sections 7, 10, 13 and 14). Nothing in it limits a right you have under the mandatory provisions of the Data Protection Laws, which prevail if they conflict with it.
4. What Personal Data we collect
4.1 Personal Data you give us
The Contact Form. The Contact Form is used for demonstration requests, partner applications, general enquiries and requests to meet us at trade events. It collects:
- first name and last name;
- work email address;
- company;
- phone number (optional);
- country (optional);
- areas of interest;
- a message (optional);
- the type of enquiry;
- the event, when your request comes from an events page on the Website; and
- the language of the page you were using.
The Contact Form also contains a hidden anti-spam field, which a person is not expected to complete and which helps us to identify automated submissions.
The email boxes on the Website. An email address entered in an email box on the home page, in the footer or on some other pages is passed to the Contact Form in the page address (URL). A page address can be kept in your browser history and recorded in the Server Logs (section 4.2), so the email address may appear in both.
Email. If you email us, we receive your email address, your message and any attachments.
Job applications. Applications are received by email at careers@blackrockts.com. We Process what you send, which may include your name, contact details, curriculum vitae, and employment and education history.
Records we create. We may keep notes of our communications with you and of the status of your enquiry or application.
4.2 Personal Data we collect automatically
When your browser requests pages from the Website, standard server and hosting logs (the Server Logs) record your IP address, the date and time, the address (URL) requested, your browser type and the referring page. We use them for security and diagnostics (section 7.2).
4.3 Personal Data we receive from others
- Referrals of Business Contacts. A colleague, client, partner or other person may give us your name and business contact details, and you may give us someone else's. If you give us Personal Data about another person, you must be entitled to do so and, where the law requires, must have told that person about this policy.
- Event contacts. If your details are given to us at or in connection with a trade event, whether by you or by someone else, we Process them under this policy.
If we obtain Personal Data about you from someone else, we will give you the information in this policy, or tell you where to find it, when we first contact you or as the Data Protection Laws that apply otherwise require. You may ask us for the source of your Personal Data.
5. What the Website does not use, and Sensitive Data
The Website is a marketing website. At the date of this policy it has no user accounts or login, payments or e-commerce, user-generated content or comments, newsletter sign-up or chat widget. It uses Google Analytics to understand how visitors use it (section 6); it does not use Google Ads, remarketing or advertising, or social-media tracking pixels or scripts. It serves its own fonts and images rather than loading them from third-party services. No AI processing of visitors' Personal Data takes place on the Website.
Sensitive Data. We do not seek information that the Data Protection Laws treat as special-category or sensitive, such as health, racial or ethnic origin, religious or political beliefs, sex life or sexual orientation, trade union membership, criminal records, genetic or biometric data, or financial or credit information (Sensitive Data). Please do not include Sensitive Data, or payment card, passport or identity numbers, in the Contact Form, in emails to us or in a job application. We do not need them to respond to an enquiry, and if we receive them we may delete or redact them.
6. Cookies, local storage and similar technologies
Analytics. The Website uses Google Analytics, provided by Google, to understand how visitors use it, for example which pages are viewed, how visitors arrive at the Website, an approximate location derived from your IP address, and your device and browser type. Google Analytics sets cookies for this purpose (typically named _ga and _ga_<container ID>) to recognise you as the same visitor between visits. Google Processes this data on our behalf; see Google's Privacy Policy (policies.google.com/privacy) for how Google itself handles data. We do not pass your name or contact details to Google Analytics, and we do not use Google Ads, remarketing or advertising cookies.
Opting out. You can install the Google Analytics opt-out browser add-on, or use your browser's settings to block or delete cookies; the Website works normally without analytics cookies, though we then have no record of that visit to help us improve it.
Local storage. If you switch between light and dark mode, the Website stores one item, called "theme", in your browser's local storage. It records your light or dark colour preference so that the Website is displayed in the colour mode you chose. It stays on your own device and is not sent to Blackrock. You can remove it by clearing the site data in your browser settings.
Consent. Where the Data Protection Laws that apply to you require your consent before Google Analytics' cookies are set, we obtain it in the way that law requires before that happens, with a way to withdraw it.
If this changes further. If we introduce advertising, remarketing or other cookies beyond Google Analytics, we will update this policy and, where the law requires, obtain your consent, with a way to withdraw it, before they are used.
7. Why we use Personal Data and our lawful bases
We use Personal Data only where the Data Protection Laws that apply allow it, and we rely on the lawful bases set out below.
7.1 The lawful bases and their PDPL equivalents
Under the UK GDPR and the EU GDPR we rely on the four bases below. The PDPLs set out their own grounds, and the equivalent of each basis is given.
- Consent: you have agreed to the Processing. PDPL equivalent: consent.
- Contract: the Processing is necessary to take steps at your request before entering into a contract with you, or to perform one. PDPL equivalent: the ground, if any, in the relevant PDPL that permits Processing without consent where it is necessary to perform a contract to which you are a party or to take steps at your request before entering into one.
- Legal obligation: the Processing is necessary to comply with a legal obligation. PDPL equivalent: the ground, if any, in the relevant PDPL that permits Processing without consent where it is necessary to comply with an obligation under the law that applies to us.
- Legitimate interests: the Processing is necessary for our legitimate interests or those of a third party, and your interests, rights and freedoms do not override them. PDPL equivalent: the legitimate-interests ground where the relevant PDPL recognises it for the Processing concerned.
Where a PDPL does not recognise a basis named for a purpose, we rely on the ground that PDPL provides for that purpose, which may be your consent, and we do not carry out the Processing without one. Where we rely on consent we say so, and you may withdraw it (section 13).
7.2 Purposes and bases
For each purpose, the PDPL ground is the equivalent of the basis named, to the extent the relevant PDPL provides one (section 7.1).
- Responding to enquiries and demonstration requests, including arranging meetings at trade events. Basis: legitimate interests (responding to people who contact us and running our business).
- Steps before a contract, including assessing partner applications. Basis: contract or, where you act for a company, legitimate interests.
- Recruitment, meaning assessing applications, communicating with applicants and keeping records. Basis: contract (steps at your request before an employment or engagement contract); legitimate interests (a fair and efficient recruitment process); legal obligation, where a law requires the Processing; and consent, where we ask to keep an application for future vacancies.
- Security and fraud prevention, using the Server Logs and the hidden anti-spam field to protect the Website and our systems and to detect spam, abuse, fraud and unauthorised access. Basis: legitimate interests; and legal obligation, where a law requires us to keep Personal Data secure.
- Legal obligations, claims and requests from authorities, meaning complying with laws, court orders and lawful requests, and establishing, exercising or defending legal claims. Basis: legal obligation and, for legal claims, legitimate interests (protecting our legal position).
- Diagnostics and maintaining the Website, meaning using the Server Logs to diagnose faults and maintain the performance and reliability of the Website. Basis: legitimate interests.
- Marketing follow-up where allowed, meaning sending Business Contacts and enquirers information about our services and events, and following up after events (section 8). Basis: your consent where the Data Protection Laws that apply require it; otherwise legitimate interests, where those laws allow marketing on that basis.
- Dealing with privacy requests and complaints, including keeping a record of opt-outs and objections so that we respect them. Basis: legal obligation, where a law requires us to respond; otherwise legitimate interests (respecting your choices and showing that we comply).
- Business administration and corporate transactions, meaning managing business relationships and records, obtaining professional advice, and preparing for or carrying out a merger, sale, financing or reorganisation (section 9). Basis: legitimate interests; and legal obligation, where records must be kept.
7.3 Consent, and providing Personal Data
Consent. Where we rely on consent, you may withdraw it at any time (section 13) without affecting earlier Processing. Your use of the Website, or your agreement to the Terms of Use, is not in itself consent (section 2.4).
Submitting a request. When you send us a request through the Contact Form or by email, you ask us to use your Personal Data to respond to it. Where a PDPL requires your consent for that Processing, you give it by submitting the request, and you may withdraw it at any time as described in section 13. Where the UK GDPR or the EU GDPR applies, we rely on the bases in section 7.2 for that Processing and not on consent. Submitting a request is not consent to marketing where the law requires separate consent (section 8).
Providing Personal Data. Providing Personal Data through the Contact Form is voluntary, but we need the fields that are not marked optional to deal with your request.
8. Marketing and communications
Follow-up to your enquiry. When you send a demonstration request, partner application, general enquiry or event meeting request, we use your details to reply and follow up, for example to arrange a demonstration or meeting and to send information you asked for. The Website does not offer a newsletter sign-up.
Other communications. If we contact Business Contacts or people who have made an enquiry with information about our services, events or news, beyond a reply to their request, we do so only where the Data Protection Laws that apply allow it and, where they require your consent, only with your consent.
Opting out. You can object to or opt out of marketing from us at any time, free of charge, by emailing info@blackrockts.com, using the Contact Form or following any opt-out instructions in the message. We will stop within the time required by applicable law, and we may keep a minimal record of your request so that we respect it. Opting out does not stop messages needed to deal with a request you have made or to meet a legal obligation.
9. Who we share Personal Data with
We share Personal Data with the following categories of recipient, and only as far as we consider needed for the purposes in section 7.
- Service providers: companies that Process Personal Data on our behalf and on our instructions (Service Providers), such as providers of hosting, analytics (Google Analytics, section 6) and other technology and business services.
- Blackrock offices: our offices in Dubai, Riyadh, Cairo and Edinburgh and, where any of them operates through a separate legal entity, that entity.
- Professional advisers: lawyers, accountants, auditors and other advisers, and insurers, who are, where appropriate, subject to confidentiality obligations.
- Authorities: courts, regulators, law-enforcement bodies and other public authorities, where the law requires or permits disclosure.
- A buyer in a business transfer: a prospective or actual buyer, investor or successor, and their advisers, if we merge with, sell or reorganise all or part of our business or assets, subject to confidentiality.
Safeguards. Where the Data Protection Laws that apply require a written contract with a Service Provider, we enter into one that allows the Service Provider to Process Personal Data only on our instructions, unless the law requires otherwise, and requires appropriate confidentiality and security. We share only the Personal Data that a recipient reasonably needs for its purpose. A recipient that is a controller in its own right is responsible for its own compliance. Personal Data shared between Blackrock offices or entities is used for the purposes in section 7, is protected by the measures described in section 12 and, where it crosses borders, is subject to section 10.
10. International transfers
Blackrock operates in the United Arab Emirates, Saudi Arabia, Egypt and the United Kingdom, and Service Providers may operate in other countries. Personal Data may therefore be transferred to, stored in or accessed from those and other countries whose data protection laws may differ from those of the country where you are.
Where the Data Protection Laws restrict a transfer or set conditions for it, we use the safeguards that the applicable law requires, which may include one or more of the following:
- Adequacy: the destination is recognised as providing an adequate level of protection under the UK GDPR, the EU GDPR or an equivalent recognition under a PDPL. Where a country is not so recognised, we rely on another safeguard.
- Standard contractual clauses: the standard contractual clauses approved by the European Commission and, for transfers from the United Kingdom, the International Data Transfer Agreement or the International Data Transfer Addendum to those clauses, each as issued or approved by the competent authority.
- Equivalent contractual protections: written terms giving protections equivalent to those the applicable Data Protection Law requires, including any approval, notification or condition that a PDPL requires for a transfer out of the United Arab Emirates, Saudi Arabia or Egypt.
- Other lawful grounds: another ground the applicable law allows, such as your explicit consent, or necessity for a contract with you or for steps at your request.
To ask about the safeguards for a particular transfer, write to info@blackrockts.com. Where the law provides, we will give you a copy or summary of them, and we may redact commercially sensitive information.
11. How long we keep Personal Data
We keep Personal Data for as long as is necessary for the purposes for which we collected it (section 7), and no longer than the applicable law requires or permits. We do not apply one period to all Personal Data. To decide how long is necessary, we consider:
- the purpose for which we hold it and whether we can achieve it in another way;
- any legal, regulatory, tax, accounting or reporting obligation to keep it, and whether we may need it to establish, exercise or defend legal claims or to deal with a complaint or dispute;
- for enquiries, partner applications and Business Contacts, whether a relationship is continuing or may reasonably be expected to continue, and the need to record any objection or opt-out;
- for job applications, the needs of the recruitment process and, where you agree or the law otherwise permits, considering you for future vacancies; and
- the nature and sensitivity of the Personal Data and the risk of harm from unauthorised use or disclosure.
We keep the Server Logs for as long as is needed for security and diagnostics, and the "theme" item (section 6) stays on your device until you clear it. When Personal Data is no longer needed, we will delete or anonymise it, subject to any legal obligation to keep it. If deletion is not immediately possible, for example because it is held in a back-up, we keep it securely and restrict its use until it can be deleted.
12. Security
We use technical and organisational measures that we consider appropriate to protect Personal Data against accidental or unlawful loss, alteration, unauthorised disclosure and unauthorised access, taking into account the risks and the nature of the Personal Data. Depending on the Personal Data concerned, they may include limiting access to people who need it for their work, confidentiality obligations, security controls on our systems and, where the Data Protection Laws require, security terms in our contracts with Service Providers (section 9).
No method of transmission over the internet or of electronic storage is completely secure, and we cannot guarantee absolute security. If a Personal Data breach occurs that we are required to notify, we will notify the competent regulator and the affected individuals as and when the Data Protection Laws that apply require.
13. Your rights
Subject to the Data Protection Laws that apply to you, and to the conditions and exceptions in them, you have the following rights.
13.1 The rights
- Information: to be told how we Process your Personal Data, as this policy does, and to receive further information on request.
- Access: to confirm whether we Process your Personal Data and to receive a copy with information about the Processing, such as its purposes, recipients and source.
- Rectification: to have inaccurate Personal Data corrected and incomplete Personal Data completed.
- Erasure: to have Personal Data deleted in the circumstances the law provides, for example where it is no longer needed, you withdraw consent or the Processing is unlawful.
- Restriction: to ask us to limit how we use Personal Data in the circumstances the law provides, for example while we check its accuracy.
- Portability: where the Processing is based on consent or on a contract and is carried out by automated means, to receive the Personal Data you provided in a structured, commonly used and machine-readable format and, where technically feasible, to have it transmitted to another controller.
- Objection: to object, on grounds relating to your situation, to Processing based on legitimate interests (we will stop unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or need the Personal Data for legal claims), and to object to direct marketing at any time, free of charge (we will then stop using your Personal Data for that purpose).
- Withdrawal of consent: to withdraw consent at any time where we rely on it.
- No solely automated decisions: not to be subject to a decision based solely on automated Processing that has legal or similarly significant effects on you. We do not take such decisions in connection with the Website (section 15).
- Complaint: to complain to a regulator (section 14) and, where the law allows, to seek a remedy before a court.
13.2 Region notes
- United Kingdom and European Union: the rights apply in the form set out in the UK GDPR and the EU GDPR.
- United Arab Emirates, Saudi Arabia and Egypt: your rights are those that the UAE PDPL, the Saudi PDPL or the Egyptian PDPL gives you. Where the relevant PDPL does not provide a right listed above, or provides it on different conditions, we will apply that PDPL to your request and, if we cannot do what you ask, tell you why. The scope of portability, erasure and objection in particular may differ.
13.3 How to exercise your rights
- How to ask: email info@blackrockts.com or use the Contact Form, stating your name, how we can contact you, the right you wish to exercise and the Personal Data concerned. Please do not include Sensitive Data or payment card, passport or identity numbers.
- Identity: we may ask for information reasonably needed to confirm who you are and, if someone else makes the request for you, that they are authorised to do so, and we may decline to act until we have it. Please do not send copies of identity documents with your request. If we need to confirm who you are, we will tell you what we need and how to send it.
- Fee: none, unless the law allows one. Where a request is manifestly unfounded, excessive or repeated, the law may allow us to charge a reasonable fee or to refuse it, and we will explain if we do.
- Time: we will respond within the time required by applicable law and will tell you if the law allows more time for a complex request.
- Exceptions: your rights are not absolute. We may limit or refuse a request where the law allows, for example to protect the rights of others or where we must keep the Personal Data, and where the law requires it we will tell you why.
14. Complaints and regulators
If you have a concern, please contact us first at info@blackrockts.com so that we can try to resolve it. We will acknowledge your complaint and deal with it without undue delay and within the time required by applicable law. You do not have to contact us first, and you may complain at any time to the competent authority in your country, for example:
- United Arab Emirates: the UAE Data Office.
- Saudi Arabia: the Saudi Data and AI Authority (SDAIA).
- Egypt: the Personal Data Protection Centre.
- United Kingdom: the Information Commissioner's Office (ICO).
- European Union: the supervisory authority of the EU Member State where you live or work or where the alleged infringement took place.
- Elsewhere: the data protection authority of the country where you live or work.
- Any successor: the successor to, or other competent authority in place of, any of the above.
15. Automated decision-making and profiling
We do not make decisions about you based solely on automated Processing, including profiling, that have legal effects concerning you or similarly significantly affect you, in connection with the Website. No AI processing of visitors' Personal Data takes place on the Website (section 5). The hidden anti-spam field on the Contact Form helps us to identify automated submissions and is not used to make decisions that have legal or similarly significant effects on you. If this changes, we will update this policy and give you any information and rights that the law requires.
16. Children
The Website is not directed at anyone under the age of 18, and we do not knowingly collect Personal Data from anyone under that age. If you believe that a person under 18 has given us Personal Data, please contact us at info@blackrockts.com and we will take steps to delete it where appropriate.
17. Third-party links and services
The Website contains ordinary links to third parties: LinkedIn, X and Instagram in the footer, and links that open ChatGPT, Claude or Perplexity in a new tab with a prepared question about Blackrock. Those services are operated by third parties under their own terms and privacy policies, are not part of the Website and are not covered by this policy. If you follow a link, your browser connects to that third party, which may collect Personal Data about you, such as your IP address and anything you submit, under its own policies. The prepared question is contained in the link, and once the service has opened, your use of it is between you and the provider. We do not control those services or how they Process Personal Data, so please read their policies.
18. Job applicants, Business Contacts and partners
18.1 Job applicants
We Process the information in your application (section 4.1) and our records of the recruitment process to assess your application, communicate with you, arrange interviews and keep records, on the bases in section 7.2. It is seen by people at Blackrock who are involved in recruiting for the vacancy, in any of our offices, and by our Service Providers (sections 9 and 10). We keep it as described in section 11, including, where you agree or the law otherwise permits, to consider you for future vacancies. Providing the information in an application is voluntary, but we cannot consider an application without the information needed to assess it. We do not ask applicants for Sensitive Data, and you should not include it (section 5). Unless we ask for them, please do not include a photograph, date of birth, nationality, marital status or identity document numbers in your application. You have the rights in section 13.
18.2 Business Contacts and partners
We Process your name, work email address, company, role and other business contact details, your communications with us, any partner application and your interactions with us at events, obtained from you or from someone who refers you, including in connection with trade events (section 4.3). We use them to respond to you, manage partnerships and business relationships, follow up after events, keep records, comply with the law and, where allowed, send relevant communications, on the bases in section 7.2. If you contact us on behalf of a company, we Process your Personal Data in your capacity as that company's representative. You can opt out of marketing at any time (section 8), and you have the rights in section 13 whether or not you act for a company.
19. Changes to this policy
We may update this policy from time to time. We will publish the updated policy on this page and change the "Last updated" date. Please check this page from time to time for changes.
A change is material if it significantly affects how we use your Personal Data or your rights, for example a new purpose for Processing, a new category of Personal Data or of recipient, the introduction of cookies or similar technologies, or a change to the lawful basis we rely on. For a material change we will take reasonable steps to notify you, for example by a prominent notice on the Website or, where we hold your email address and the law permits us to contact you, by email. Where the law requires your consent to a change, we will ask for it before the change applies to you.
Other changes, such as corrections and clarifications, take effect when we publish them. This version takes effect on 21 September 2026 and replaces the version last updated on 14 March 2025. The version last updated on 14 March 2025 also referred to Google Analytics and Google Ads: this version explains our current use of Google Analytics in section 6, and confirms that we do not use Google Ads.
20. Language
This policy is written in English. An Arabic version may be made available for convenience. If the English text and any Arabic translation differ, the English text prevails to the extent permitted by law.
21. Contact for questions and requests
For questions about this policy, or to exercise any of your rights, contact us:
- Email: info@blackrockts.com, for general enquiries and privacy requests.
- Contact Form: /contact.
- Job applications: careers@blackrockts.com. Privacy questions and requests, including those about a job application, should be sent to info@blackrockts.com or made through the Contact Form.