AirReclaim

Choose language

Available languages

More languages

Back to legal center

Legal and compliance

Security

How AirReclaim protects accounts, documents, payments, provider access, and responsible security reports.

Effective date
21 Jul 2026
Last updated
21 Jul 2026
Operator
Nova Group Sp. z o.o.
Scope
Poland / European Union
Document status
production ready

1. Security approach

AirReclaim handles identity, travel, claim, document, Authorization, communication, and payout information. Nova Group Sp. z o.o. applies technical and organizational measures designed to protect confidentiality, integrity, availability, and accountability throughout the service.

Security is risk-based. No website or electronic transmission can be guaranteed to be completely secure, but we work to reduce preventable risk and respond appropriately to suspected incidents.

2. Payment security

Where online payments, card verification, or payment authentication are used, AirReclaim may use Stripe, Worldline, or another regulated payment provider.

  • Full card details are entered into or transmitted through the payment provider's secure interface.
  • AirReclaim does not store full card details.
  • We ordinarily receive a payment token, status, limited payer or transaction information, and fraud or authentication results needed for reconciliation and support.
  • Payment providers may use device, cookie, authentication, and transaction data to prevent fraud and meet financial or card-network duties.
  • Strong customer authentication or another verification step may be required.

Using a payment provider reduces AirReclaim's direct handling of card data but does not remove our responsibility to secure our own systems and integration.

3. Account security

Account and claim access may be protected through:

  • verified sign-in methods;
  • short-lived session tokens and secure session management;
  • role-based access;
  • re-authentication for sensitive actions;
  • rate limiting and abuse controls;
  • audit and security event logging;
  • session revocation;
  • restricted administrative access; and
  • identity or authority verification before disclosure or payout.

We may suspend a session, restrict an account, or request additional verification where activity appears unusual or creates a risk to a Claimant, payment, document, or system.

4. Data and document protection

Security measures can include:

  • encrypted connections for data in transit;
  • provider-supported encryption for stored data;
  • private storage and controlled document access;
  • least-privilege access;
  • separation of customer and administrative permissions;
  • malware scanning and file-type validation;
  • secure upload and download methods;
  • backup and recovery controls;
  • logging and monitoring;
  • secrets and credential management;
  • vulnerability and dependency management;
  • retention and deletion controls; and
  • contractual and security assessment of service providers.

Access to personal data is limited to people and providers who need it for an authorized purpose.

5. Authorization and payout controls

Because an Authorization can permit claim submission and receipt of Compensation, we may retain evidence such as the document version, signature or approval event, timestamp, authentication result, and completion record.

Payout controls may include verification of the Claimant, bank-account holder, account details, recovered amount, Service Fee, sanctions status, duplicate-payment risk, and transaction history. A payout can be paused while a material inconsistency or compliance issue is investigated.

6. AI-assisted processing

AI-assisted tools may be used for document extraction, classification, inconsistency detection, summarization, or preparation of suggested communications.

We apply data minimization, access controls, provider terms, task-specific instructions, and human control appropriate to the function. Sensitive information should not be included where it is not needed. Material legal-sensitive or payout actions are not approved solely by an AI output.

7. Service-provider security

AirReclaim can depend on providers for hosting, databases, authentication, electronic signatures, communications, document processing, analytics, payments, and flight data.

We seek to use providers with security and privacy controls appropriate to the data and function. Providers receive only the data reasonably needed for their role and are subject to contractual obligations where required.

A provider's certification, security statement, or availability does not guarantee that AirReclaim or the provider will never experience an incident.

8. Customer responsibilities

You can help protect your account and Claim by:

  • using a strong, unique sign-in method;
  • protecting access to your email account;
  • not sharing sign-in links or verification codes;
  • checking that you are using the airreclaim.com domain;
  • signing out on shared devices;
  • keeping your device and browser updated;
  • reviewing payout details carefully;
  • treating unexpected requests for documents or payment with caution; and
  • reporting suspicious activity promptly.

AirReclaim will not ask you to reveal a password or one-time code by email.

9. Security incident response

When we become aware of a suspected security incident, we assess the scope, contain the issue where possible, preserve relevant evidence, address the cause, and evaluate legal notification duties.

Where required by law, we will notify the competent authority and affected individuals without undue delay. A communication may describe the nature of the incident, likely consequences, measures taken, and steps the recipient can take.

We may provide updates as reliable information becomes available. Security considerations can limit details that would increase risk or prejudice an investigation.

10. Responsible disclosure

Security researchers and users may report a suspected vulnerability to:

security@airreclaim.com

Please include:

  • the affected page, endpoint, or function;
  • a clear description of the issue and potential impact;
  • reproducible steps using non-destructive methods;
  • screenshots, logs, or proof that do not expose another person's data;
  • the date and environment tested; and
  • a safe way to contact you.

Please do not:

  • access, retain, alter, or disclose another person's data;
  • disrupt availability or degrade the service;
  • use social engineering, phishing, physical intrusion, denial-of-service methods, or destructive testing;
  • upload malware;
  • demand payment or threaten disclosure; or
  • publish the issue before we have had a reasonable opportunity to investigate and reduce risk.

We aim to acknowledge a responsible security report within up to 14 days. This disclosure channel does not create a promise of payment, employment, immunity, or a reward program. Activity must remain lawful and proportionate.

11. Suspicious messages and fraud

Verify that website links use the airreclaim.com domain. Be cautious where a message:

  • pressures you to pay an unexpected fee;
  • asks for a password or one-time code;
  • requests payout to an unrelated person;
  • claims guaranteed Compensation;
  • asks you to install remote-access software; or
  • uses a lookalike domain.

Forward suspicious AirReclaim-related messages to security@airreclaim.com. Do not include unnecessary sensitive information.

12. Contact

Security reports: security@airreclaim.com
General support: support@airreclaim.com

Nova Group Sp. z o.o.
Żurawia 6/12 Lok. 745
00-503 Warszawa, Poland