Effective Date: June 18, 2026
1. GENERAL PROVISIONS
1.1. This Privacy Policy determines the procedure for collecting, storing, protecting, and processing the personal data of users of the fiora.az website (hereinafter — the «Website»).
1.2. The owner of the Website and the personal data operator is a natural person holding the status of a taxpayer of the Republic of Azerbaijan (VÖEN: 7701208082), hereinafter referred to as the «Operator».
1.3. The contact email address of the Operator for personal data matters is: info@fiora.az.
1.4. The use of the Website, registration on the Website, or making a booking signifies the unconditional consent of the User to this Policy and the conditions for processing their personal information specified herein.
1.5. This Policy has been developed in accordance with the Law of the Republic of Azerbaijan «On Personal Data» No. 998-IIIQ and other regulatory legal acts of the Republic of Azerbaijan.
2. CATEGORIES OF COLLECTED PERSONAL DATA
2.1. The Operator collects the following data provided voluntarily by the User during registration or when booking services, hotels, and routes:
- User’s first name and last name;
- Contact phone number;
- Email address (e-mail).
2.2. The Website does not explicitly request, collect, or store the passport data of Users within the booking interfaces, except for cases provided for in clause 4.4 of this Policy.
2.3. Payment card data (card number, expiration date, CVV/CVC code) is processed exclusively by licensed third-party payment gateways (including epoint.az, split.az, split.com planned for integration). The Operator does not store full payment card details, except for International Bank Account Numbers (IBAN) when required for settlements.
2.4. The Website automatically collects anonymous technical data via cookies, IP addresses, and web browser parameters to save user preferences and ensure the correct operation of the Website’s functionality.
3. PURPOSES OF PERSONAL DATA PROCESSING
3.1. The User’s personal data is processed exclusively for the following purposes:
- Registration and identification of the User on the Website;
- Arranging, processing, and confirming bookings of hotels, tourist routes, and other related services;
- Providing feedback, customer support, and handling inquiries using automated systems, including the Ollama AI intelligent chatbot and notifications in the Telegram messenger;
- Sending transactional notifications and booking confirmations to the User, accommodation representatives (reception), and the Operator;
- Providing information about promotions, special offers, and hotel news (subject to the User’s consent).
4. DATA TRANSFER TO THIRD PARTIES AND GOVERNMENT AUTHORITIES
4.1. The Operator guarantees the confidentiality of personal data and does not transfer it to third parties for commercial or marketing purposes, except in the cases provided for in clauses 4.2 and 7.5 of this Policy.
4.2. To fulfill booking obligations, the User’s data (name, phone, email) is transferred to the respective accommodation facilities (hotels, guides) solely to the extent necessary to provide the service.
4.3. Personal data may be transferred to authorized state bodies of the Republic of Azerbaijan solely on the basis of law and within official legal procedures upon detection of offences.
4.4. In compliance with migration legislation, the Operator gives notice of the planned implementation of functionality for automated notification to the State Migration Service of the Republic of Azerbaijan regarding the registration and temporary stay of foreign citizens at accommodation facilities.
5. DATA STORAGE, PROTECTION, AND SECURITY
5.1. Personal data is stored in electronic form in secure databases on the Operator’s own server.
5.2. To protect the transmitted data, an SSL encryption protocol is applied, ensuring information confidentiality during its transmission over the Internet.
5.3. The Operator takes maximum technical and organizational measures to protect personal data from unauthorized access, modification, disclosure, or destruction.
6. USER RIGHTS AND CONTACT INFORMATION
6.1. The User has the right to receive information regarding the processing of their personal data, as well as the right to request clarification, blocking, or destruction if the data is incomplete or outdated, by sending a request to: info@fiora.az.
7. WHATSAPP AND INSTAGRAM MESSAGES (AI ASSISTANT)
7.1. Hotels listed on the Website may connect their own Instagram account or WhatsApp Business number to the Fiora AI assistant. The connection is made by the hotel itself through the official authorization flow of Meta Platforms, Inc.
7.2. Upon connection, the Operator receives from Meta: the hotel’s Instagram account ID and username (or WhatsApp phone number ID) and the access token required to receive and send messages on behalf of the hotel.
7.3. When a guest writes to the hotel, the Operator receives: the sender ID assigned by the platform, the sender’s public name, the message text, and voice messages if the guest sends them.
7.4. This data is used solely to let the assistant answer the guest’s questions about the hotel. It is not used for advertising, is not sold, and is not shared with anyone except the recipients listed in clause 7.5.
7.5. To generate a reply, the message text is sent to language model providers: Anthropic, Google, Groq, DeepSeek, or the Operator’s own server running a local model. Providers process the text only to generate the reply. Voice messages are transcribed into text and are not stored on the Operator’s server: the audio file is never written to disk, and the link to it is deleted immediately after transcription.
7.6. Conversations are stored in the hotel’s panel and are accessible to the staff of that hotel and to the Operator. The hotel may disconnect its account at any time, after which no new messages are received. A guest may request deletion of their conversation by writing to info@fiora.az; such requests are fulfilled within 30 days.
Рус
Aze
Tür