1. Who We Are
FlightRefund.io ApS (“FlightRefund”, “we”, “us”) is the data controller responsible for your personal data. We are registered at [COMPANY ADDRESS], [CITY, POSTCODE, COUNTRY].
This Privacy Policy explains how we collect, use, and protect your personal data when you use our services at https://flightrefund.io. It is written in compliance with the EU General Data Protection Regulation (GDPR) and applicable national law.
2. Data We Collect
We collect the following categories of personal data:
2.1 Data you provide directly
- Full name and home address
- Email address
- Flight details (flight number, date, route)
- Bank account information (IBAN and bank name) for payout purposes
- Any additional documentation you provide in support of your claim
2.2 Data we collect automatically
- IP address (collected at the time of claim submission as proof of consent)
- Timestamps of key actions (claim submission, consent acceptance)
- Browser type and device information (for security and fraud prevention)
2.3 Data from third parties
- Flight status and delay data from AeroDataBox and similar aviation data providers, used to verify your claim
3. How We Use Your Data
We use your personal data for the following purposes:
- Claim processing: To assess your eligibility, prepare claim letters, and communicate with airlines and National Enforcement Bodies on your behalf
- Communication: To send you updates about your claim by email
- Payment: To transfer your compensation payout to the bank account you provided
- Legal compliance: To maintain records of consent and authorisation as required by law
- Fraud prevention: To detect and prevent fraudulent claims
We do not use your data for marketing without your explicit consent.
4. Legal Basis for Processing
We process your personal data under the following legal bases (GDPR Article 6):
- Contract performance (Art. 6(1)(b)): Processing your name, address, email, flight details, and bank information is necessary to provide our claim management services
- Consent (Art. 6(1)(a)): Where you have explicitly agreed to these terms, including granting us Power of Attorney
- Legitimate interests (Art. 6(1)(f)): Fraud prevention and security
- Legal obligation (Art. 6(1)(c)): Where we are required to retain records by applicable law
6. Data Retention
We retain your personal data for the following periods:
- Active claims: For the duration of your claim plus 5 years, to comply with legal record-keeping requirements and defend against potential disputes
- Consent records: 5 years from the date of consent, as required for legal compliance
- Bank details: Deleted within 30 days of successful payout or claim closure
You may request earlier deletion subject to our legal obligations (see Section 7).
7. Your Rights
Under the GDPR, you have the following rights:
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data, subject to our legal obligations
- Restriction: Request that we restrict processing of your data in certain circumstances
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, contact us at legal@flightrefund.io. We will respond within 30 days.
8. Security
We take the security of your personal data seriously. We implement appropriate technical and organisational measures including:
- Encryption in transit (HTTPS/TLS) and at rest
- Access controls limiting who can access sensitive data
- Row-level security policies on our database
- Regular security reviews of our infrastructure
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR Article 33.
10. Contact & Complaints
For any privacy-related questions or to exercise your rights, contact our data protection contact at:
- Email: legal@flightrefund.io
- Address: FlightRefund.io ApS, [COMPANY ADDRESS], [CITY, POSTCODE, COUNTRY]
You also have the right to lodge a complaint with the supervisory authority in your country. In Denmark, this is Datatilsynet (datatilsynet.dk).