Privacy
Short version: this site stores nothing about you. If you send an enquiry, we get what you wrote in the email, and we use it to answer you.
Last updated 15 August 2026
Who is responsible
Sahel & Fjord AS, company no. 912 345 678, Torggata 12, 0181 Oslo, Norway, is the controller for the personal data described here. Questions go to post@sahelfjord.no.
What the site does — and does not do
This site sets no cookies. It has no analytics, no tracking pixels, no share buttons and no embedded maps or videos.
It also fetches nothing from anywhere else: fonts, images and scripts all sit on the same server as the page. That is not a turn of phrase — it is enforced by a Content Security Policy that blocks everything else. Your browser talks to one domain while you are here, and no third party learns that you visited us.
Which is why there is no consent banner either. We do not ask permission to track you, because we do not track you.
The form sends us nothing
The enquiry form is not an ordinary form. What you type stays in your browser. When you press “send”, we open your email client with the text filled in, and you send it yourself.
Nothing goes to a server on the way, and nothing is stored on the site. Change your mind before you press send in your email client and we never saw any of it.
Once you have sent an enquiry
Then we have an email from you. It usually holds your name, email address, number of travellers, preferred route and timing, and whatever you wrote.
We use it to answer you and put together a proposal. The legal basis is steps taken at your request prior to entering a contract, GDPR Article 6(1)(b).
If no trip comes of it, we delete the correspondence after 12 months.
Once you actually book
Then we need more, and some of it is information we could not ask for without a reason:
- Full name as printed in your passport, date of birth and passport number — the airline and some hotels require it.
- Phone number and a next-of-kin contact for the trip.
- Allergies, dietary needs and any health information you choose to give us.
Health data is a special category of personal data. We process it only with your explicit consent, Article 9(2)(a), and only so far as it is needed to run the trip safely. You can withdraw consent at any time — but we may then have to decline responsibility for whatever it covered.
Who gets to see it
- The airline, if we book for you.
- The hotel or lodge you are staying at.
- The local guide and driver on the ground.
- Our accountant, for what has to be booked.
We do not sell data, and we do not use it for marketing unless you asked us to.
Transfers to the Gambia and Senegal
That is where the trip goes and where our partners are. Neither the Gambia nor Senegal is covered by a European Commission adequacy decision.
The transfer is still lawful, because it is necessary to perform the contract with you — Article 49(1)(b). We send only what the partner actually needs: name, dates and any dietary requirements. Passport numbers go to the airline, not to the lodge.
The server and its logs
The site is hosted by Netlify, who act as our processor. Like all web hosting they keep access logs with IP address, timestamp and which file was requested. We do not use those logs to follow visitors, and we do not join them to anything else.
How long we keep it
- Enquiry with no booking
- 12 months
- Travel documents and correspondence
- 3 years after the trip
- Invoices and vouchers
- 5 years, as Norwegian accounting law requires
- Health information
- Deleted once the trip is over
Your rights
You can ask for a copy of what we hold on you, have errors corrected, have it deleted, have it handed over in a machine-readable format, and object to the processing. Write to post@sahelfjord.no and we answer within 30 days.
If you think we are handling your data wrongly, you can complain to the Norwegian Data Protection Authority. We would like to hear it from you first, but that is not a precondition.