Privacy Policy

How Blackrock Technologies collects, uses, shares and protects personal data when you use our website or contact us, and the rights you have.

Last updated: 21 September 2026

This Privacy Policy explains how Blackrock International CSP LLC, trading as Blackrock Technologies, Processes Personal Data (both defined below) when you visit our website at blackrockts.com, available in English at /en and in Arabic at /ar (the Website), contact us, apply for a job with us or deal with us as a business contact or partner, and what rights you have.

In this policy, Personal Data means any information relating to an identified or identifiable individual, and Process and Processing mean any operation on Personal Data, such as collecting, storing, using, sharing or deleting it. Blackrock, we, us and our mean Blackrock International CSP LLC, and you means the individual whose Personal Data we Process.

1. Who we are

The Website is operated by Blackrock International CSP LLC, which trades as Blackrock Technologies. Blackrock is a travel-technology company that provides B2B, B2C and corporate booking platforms, a back-office system and WebAdmin, supplier connectivity, custom engineering and AI agents to travel businesses across the Gulf Cooperation Council (GCC) region and beyond, including in Europe. Blackrock Technologies has offices in Dubai (United Arab Emirates), Riyadh (Saudi Arabia), Cairo (Egypt) and Edinburgh (United Kingdom).

For the Personal Data described in this policy, Blackrock is the controller: the organisation that decides why and how it is Processed. Where any of the Data Protection Laws (section 3) uses a different term for that role, "controller" means that role.

You can contact us at info@blackrockts.com or through our contact form at /contact (the Contact Form); see section 21. Please send privacy questions and requests to those contact details, and we will direct them to the right person within Blackrock.

2. Scope of this policy

2.1 Who and what this policy covers

This policy applies to Personal Data that we Process about:

2.2 What this policy does not cover

Blackrock's products (booking platforms, WebAdmin and AI agents) Process client data under separate written agreements with Blackrock's clients, and this policy does not apply to that data. For questions about Personal Data Processed through a platform provided to a travel business, ask that travel business. If you are a Blackrock client, see your agreement or ask your usual Blackrock contact. If you are unsure whom to ask, write to info@blackrockts.com and we will direct your question. This policy does cover the business contact details of individuals at clients that we hold for our own relationship with them. It does not cover Personal Data Processed through the platforms we provide. This policy also does not cover Blackrock's own employees and workers.

2.3 Illustrative content

The product screens, demonstration data and some images and illustrations on the Website are illustrative. They do not necessarily show real clients, people, offices or results.

2.4 Relationship to the Terms of Use

Please read this policy together with our Terms of Use, which govern your use of the Website. If the Terms of Use and this policy conflict on the Processing of Personal Data, this policy prevails. This policy is a notice of how we Process Personal Data and does not limit any right you have under the Data Protection Laws.

Your use of the Website, or your agreement to the Terms of Use, is not in itself consent to the Processing of Personal Data. We rely on consent only where this policy says so (sections 7, 8 and 10) and, where we do, we ask for it for the specific purpose concerned.

3. Which laws apply and how this policy works

Depending on who you are and where you are, Personal Data about you may be protected by one or more of the following laws (together, the Data Protection Laws):

The UAE PDPL, the Saudi PDPL and the Egyptian PDPL are together the PDPLs.

Which law applies to a particular item of Processing depends on the circumstances, including where you are and where we or our Service Providers (section 9) operate. This policy is one document for all of them: it describes one set of rights (section 13), exercisable to the extent the laws that apply to you provide for them, gives the lawful basis and PDPL equivalent for each purpose (section 7), and adds region notes where the laws differ (sections 7, 10, 13 and 14). Nothing in it limits a right you have under the mandatory provisions of the Data Protection Laws, which prevail if they conflict with it.

4. What Personal Data we collect

4.1 Personal Data you give us

The Contact Form. The Contact Form is used for demonstration requests, partner applications, general enquiries and requests to meet us at trade events. It collects:

The Contact Form also contains a hidden anti-spam field, which a person is not expected to complete and which helps us to identify automated submissions.

The email boxes on the Website. An email address entered in an email box on the home page, in the footer or on some other pages is passed to the Contact Form in the page address (URL). A page address can be kept in your browser history and recorded in the Server Logs (section 4.2), so the email address may appear in both.

Email. If you email us, we receive your email address, your message and any attachments.

Job applications. Applications are received by email at careers@blackrockts.com. We Process what you send, which may include your name, contact details, curriculum vitae, and employment and education history.

Records we create. We may keep notes of our communications with you and of the status of your enquiry or application.

4.2 Personal Data we collect automatically

When your browser requests pages from the Website, standard server and hosting logs (the Server Logs) record your IP address, the date and time, the address (URL) requested, your browser type and the referring page. We use them for security and diagnostics (section 7.2).

4.3 Personal Data we receive from others

If we obtain Personal Data about you from someone else, we will give you the information in this policy, or tell you where to find it, when we first contact you or as the Data Protection Laws that apply otherwise require. You may ask us for the source of your Personal Data.

5. What the Website does not use, and Sensitive Data

The Website is a marketing website. At the date of this policy it has no user accounts or login, payments or e-commerce, user-generated content or comments, newsletter sign-up or chat widget. It uses Google Analytics to understand how visitors use it (section 6); it does not use Google Ads, remarketing or advertising, or social-media tracking pixels or scripts. It serves its own fonts and images rather than loading them from third-party services. No AI processing of visitors' Personal Data takes place on the Website.

Sensitive Data. We do not seek information that the Data Protection Laws treat as special-category or sensitive, such as health, racial or ethnic origin, religious or political beliefs, sex life or sexual orientation, trade union membership, criminal records, genetic or biometric data, or financial or credit information (Sensitive Data). Please do not include Sensitive Data, or payment card, passport or identity numbers, in the Contact Form, in emails to us or in a job application. We do not need them to respond to an enquiry, and if we receive them we may delete or redact them.

6. Cookies, local storage and similar technologies

Analytics. The Website uses Google Analytics, provided by Google, to understand how visitors use it, for example which pages are viewed, how visitors arrive at the Website, an approximate location derived from your IP address, and your device and browser type. Google Analytics sets cookies for this purpose (typically named _ga and _ga_<container ID>) to recognise you as the same visitor between visits. Google Processes this data on our behalf; see Google's Privacy Policy (policies.google.com/privacy) for how Google itself handles data. We do not pass your name or contact details to Google Analytics, and we do not use Google Ads, remarketing or advertising cookies.

Opting out. You can install the Google Analytics opt-out browser add-on, or use your browser's settings to block or delete cookies; the Website works normally without analytics cookies, though we then have no record of that visit to help us improve it.

Local storage. If you switch between light and dark mode, the Website stores one item, called "theme", in your browser's local storage. It records your light or dark colour preference so that the Website is displayed in the colour mode you chose. It stays on your own device and is not sent to Blackrock. You can remove it by clearing the site data in your browser settings.

Consent. Where the Data Protection Laws that apply to you require your consent before Google Analytics' cookies are set, we obtain it in the way that law requires before that happens, with a way to withdraw it.

If this changes further. If we introduce advertising, remarketing or other cookies beyond Google Analytics, we will update this policy and, where the law requires, obtain your consent, with a way to withdraw it, before they are used.

7. Why we use Personal Data and our lawful bases

We use Personal Data only where the Data Protection Laws that apply allow it, and we rely on the lawful bases set out below.

7.1 The lawful bases and their PDPL equivalents

Under the UK GDPR and the EU GDPR we rely on the four bases below. The PDPLs set out their own grounds, and the equivalent of each basis is given.

Where a PDPL does not recognise a basis named for a purpose, we rely on the ground that PDPL provides for that purpose, which may be your consent, and we do not carry out the Processing without one. Where we rely on consent we say so, and you may withdraw it (section 13).

7.2 Purposes and bases

For each purpose, the PDPL ground is the equivalent of the basis named, to the extent the relevant PDPL provides one (section 7.1).

7.3 Consent, and providing Personal Data

Consent. Where we rely on consent, you may withdraw it at any time (section 13) without affecting earlier Processing. Your use of the Website, or your agreement to the Terms of Use, is not in itself consent (section 2.4).

Submitting a request. When you send us a request through the Contact Form or by email, you ask us to use your Personal Data to respond to it. Where a PDPL requires your consent for that Processing, you give it by submitting the request, and you may withdraw it at any time as described in section 13. Where the UK GDPR or the EU GDPR applies, we rely on the bases in section 7.2 for that Processing and not on consent. Submitting a request is not consent to marketing where the law requires separate consent (section 8).

Providing Personal Data. Providing Personal Data through the Contact Form is voluntary, but we need the fields that are not marked optional to deal with your request.

8. Marketing and communications

Follow-up to your enquiry. When you send a demonstration request, partner application, general enquiry or event meeting request, we use your details to reply and follow up, for example to arrange a demonstration or meeting and to send information you asked for. The Website does not offer a newsletter sign-up.

Other communications. If we contact Business Contacts or people who have made an enquiry with information about our services, events or news, beyond a reply to their request, we do so only where the Data Protection Laws that apply allow it and, where they require your consent, only with your consent.

Opting out. You can object to or opt out of marketing from us at any time, free of charge, by emailing info@blackrockts.com, using the Contact Form or following any opt-out instructions in the message. We will stop within the time required by applicable law, and we may keep a minimal record of your request so that we respect it. Opting out does not stop messages needed to deal with a request you have made or to meet a legal obligation.

9. Who we share Personal Data with

We share Personal Data with the following categories of recipient, and only as far as we consider needed for the purposes in section 7.

Safeguards. Where the Data Protection Laws that apply require a written contract with a Service Provider, we enter into one that allows the Service Provider to Process Personal Data only on our instructions, unless the law requires otherwise, and requires appropriate confidentiality and security. We share only the Personal Data that a recipient reasonably needs for its purpose. A recipient that is a controller in its own right is responsible for its own compliance. Personal Data shared between Blackrock offices or entities is used for the purposes in section 7, is protected by the measures described in section 12 and, where it crosses borders, is subject to section 10.

10. International transfers

Blackrock operates in the United Arab Emirates, Saudi Arabia, Egypt and the United Kingdom, and Service Providers may operate in other countries. Personal Data may therefore be transferred to, stored in or accessed from those and other countries whose data protection laws may differ from those of the country where you are.

Where the Data Protection Laws restrict a transfer or set conditions for it, we use the safeguards that the applicable law requires, which may include one or more of the following:

To ask about the safeguards for a particular transfer, write to info@blackrockts.com. Where the law provides, we will give you a copy or summary of them, and we may redact commercially sensitive information.

11. How long we keep Personal Data

We keep Personal Data for as long as is necessary for the purposes for which we collected it (section 7), and no longer than the applicable law requires or permits. We do not apply one period to all Personal Data. To decide how long is necessary, we consider:

We keep the Server Logs for as long as is needed for security and diagnostics, and the "theme" item (section 6) stays on your device until you clear it. When Personal Data is no longer needed, we will delete or anonymise it, subject to any legal obligation to keep it. If deletion is not immediately possible, for example because it is held in a back-up, we keep it securely and restrict its use until it can be deleted.

12. Security

We use technical and organisational measures that we consider appropriate to protect Personal Data against accidental or unlawful loss, alteration, unauthorised disclosure and unauthorised access, taking into account the risks and the nature of the Personal Data. Depending on the Personal Data concerned, they may include limiting access to people who need it for their work, confidentiality obligations, security controls on our systems and, where the Data Protection Laws require, security terms in our contracts with Service Providers (section 9).

No method of transmission over the internet or of electronic storage is completely secure, and we cannot guarantee absolute security. If a Personal Data breach occurs that we are required to notify, we will notify the competent regulator and the affected individuals as and when the Data Protection Laws that apply require.

13. Your rights

Subject to the Data Protection Laws that apply to you, and to the conditions and exceptions in them, you have the following rights.

13.1 The rights

13.2 Region notes

13.3 How to exercise your rights

14. Complaints and regulators

If you have a concern, please contact us first at info@blackrockts.com so that we can try to resolve it. We will acknowledge your complaint and deal with it without undue delay and within the time required by applicable law. You do not have to contact us first, and you may complain at any time to the competent authority in your country, for example:

15. Automated decision-making and profiling

We do not make decisions about you based solely on automated Processing, including profiling, that have legal effects concerning you or similarly significantly affect you, in connection with the Website. No AI processing of visitors' Personal Data takes place on the Website (section 5). The hidden anti-spam field on the Contact Form helps us to identify automated submissions and is not used to make decisions that have legal or similarly significant effects on you. If this changes, we will update this policy and give you any information and rights that the law requires.

16. Children

The Website is not directed at anyone under the age of 18, and we do not knowingly collect Personal Data from anyone under that age. If you believe that a person under 18 has given us Personal Data, please contact us at info@blackrockts.com and we will take steps to delete it where appropriate.

17. Third-party links and services

The Website contains ordinary links to third parties: LinkedIn, X and Instagram in the footer, and links that open ChatGPT, Claude or Perplexity in a new tab with a prepared question about Blackrock. Those services are operated by third parties under their own terms and privacy policies, are not part of the Website and are not covered by this policy. If you follow a link, your browser connects to that third party, which may collect Personal Data about you, such as your IP address and anything you submit, under its own policies. The prepared question is contained in the link, and once the service has opened, your use of it is between you and the provider. We do not control those services or how they Process Personal Data, so please read their policies.

18. Job applicants, Business Contacts and partners

18.1 Job applicants

We Process the information in your application (section 4.1) and our records of the recruitment process to assess your application, communicate with you, arrange interviews and keep records, on the bases in section 7.2. It is seen by people at Blackrock who are involved in recruiting for the vacancy, in any of our offices, and by our Service Providers (sections 9 and 10). We keep it as described in section 11, including, where you agree or the law otherwise permits, to consider you for future vacancies. Providing the information in an application is voluntary, but we cannot consider an application without the information needed to assess it. We do not ask applicants for Sensitive Data, and you should not include it (section 5). Unless we ask for them, please do not include a photograph, date of birth, nationality, marital status or identity document numbers in your application. You have the rights in section 13.

18.2 Business Contacts and partners

We Process your name, work email address, company, role and other business contact details, your communications with us, any partner application and your interactions with us at events, obtained from you or from someone who refers you, including in connection with trade events (section 4.3). We use them to respond to you, manage partnerships and business relationships, follow up after events, keep records, comply with the law and, where allowed, send relevant communications, on the bases in section 7.2. If you contact us on behalf of a company, we Process your Personal Data in your capacity as that company's representative. You can opt out of marketing at any time (section 8), and you have the rights in section 13 whether or not you act for a company.

19. Changes to this policy

We may update this policy from time to time. We will publish the updated policy on this page and change the "Last updated" date. Please check this page from time to time for changes.

A change is material if it significantly affects how we use your Personal Data or your rights, for example a new purpose for Processing, a new category of Personal Data or of recipient, the introduction of cookies or similar technologies, or a change to the lawful basis we rely on. For a material change we will take reasonable steps to notify you, for example by a prominent notice on the Website or, where we hold your email address and the law permits us to contact you, by email. Where the law requires your consent to a change, we will ask for it before the change applies to you.

Other changes, such as corrections and clarifications, take effect when we publish them. This version takes effect on 21 September 2026 and replaces the version last updated on 14 March 2025. The version last updated on 14 March 2025 also referred to Google Analytics and Google Ads: this version explains our current use of Google Analytics in section 6, and confirms that we do not use Google Ads.

20. Language

This policy is written in English. An Arabic version may be made available for convenience. If the English text and any Arabic translation differ, the English text prevails to the extent permitted by law.

21. Contact for questions and requests

For questions about this policy, or to exercise any of your rights, contact us:

Back to homepage