- Scope
- Poland / European Union
- Document status
- production ready
- Questions
- support@airreclaim.com
1. Who controls your personal data
The controller of personal data processed through airreclaim.com and the AirReclaim passenger compensation recovery service is:
Nova Group Sp. z o.o.
Żurawia 6/12 Lok. 745
00-503 Warszawa
Poland
Tax ID / VAT ID: PL7011215529
KRS: 0001117840
REGON: 529224431\
Privacy contact: privacy@airreclaim.com
Nova Group Sp. z o.o. operates the AirReclaim brand. References to “AirReclaim,” “we,” “us,” and “our” mean Nova Group Sp. z o.o.
2. Scope
This Policy explains how we process personal data when you:
- visit airreclaim.com;
- use the compensation checker;
- create or access an account;
- submit, manage, or track a Claim;
- upload documents or complete an Assignment, Authorization, withdrawal, or reassignment;
- contact support or make a complaint;
- receive or provide payout information;
- interact with analytics or advertising technologies subject to your choices; or
- communicate with us, an Airline, an authority, or a service provider in connection with a Claim.
The Cookies Policy provides additional information about cookies, local storage, analytics, consent, and advertising technologies.
3. Personal data we may process
Depending on how you use the Services, we may process the following categories.
3.1 Identity and contact data
- name and surname;
- date of birth where needed to identify a passenger or limitation period;
- postal address;
- email address;
- nationality or country of residence where relevant to the Claim;
- identity-document data where an Airline, authority, payout provider, or legal process requires it; and
- guardian, representative, or fellow-passenger details.
3.2 Flight, booking, and disruption data
- Airline, flight number, route, date, scheduled and actual times;
- booking reference, ticket, boarding pass, itinerary, seat, and passenger details;
- delay, cancellation, denied boarding, missed connection, and cause information;
- Airline messages, rejection reasons, offers, refunds, vouchers, and payments;
- prior claim, authority, alternative dispute resolution, or court history; and
- expense or care information where relevant to an accepted scope.
3.3 Claim ownership, route and legal-document data
- uploaded correspondence, booking records, receipts, travel documents, and evidence;
- electronic signature, signature timestamp, authentication information, and completion evidence;
- Service Route, primary enforcement country, routing-rule version and route-decision reason;
- Assignment, Authorization, notice of assignment, withdrawal and reassignment status;
- ownership history and title-chain audit records;
- document metadata; and
- information extracted or classified from documents.
Documents can incidentally contain information that is not needed for the Claim. Please redact unrelated data where possible.
3.4 Account, communication, and support data
- account identifiers and authentication events;
- messages, support requests, complaints, and responses;
- language and communication preferences;
- claim status and activity history; and
- delivery, opening, and technical metadata associated with service communications where used for security, evidence, or delivery assurance.
3.5 Payout and transaction data
- bank-account holder, IBAN or equivalent payout details, currency, and payment status;
- amount recovered, Service Fee, net payout, invoice, and accounting records;
- identity, sanctions, fraud-prevention, and financial-crime checks where required; and
- limited payment status or token information received from Stripe, Worldline, banks, or other payment providers.
We do not store full payment-card details.
3.6 Device, usage, consent, and security data
- IP address, browser, device, operating system, language, time zone, and approximate location;
- pages viewed, events, referral source, session and conversion data;
- cookie and consent choices;
- account access, security alerts, rate-limit, and fraud signals;
- diagnostic, error, and audit data; and
- identifiers generated by analytics, authentication, payment, or security providers, subject to applicable consent requirements.
3.7 Marketing data
- consent status;
- campaign source and engagement;
- communication preferences; and
- records needed to respect an opt-out.
3.8 Special-category and sensitive information
AirReclaim does not seek health, biometric, religious, political, trade-union, sexual-life, or similar sensitive data for ordinary compensation claims. Such information may appear incidentally in a document or become relevant to establish, exercise, or defend a legal claim. We process it only where necessary and where an applicable condition under Article 9 GDPR exists, such as explicit consent or necessity for legal claims.
4. How we obtain data
We obtain data:
- directly from you;
- from a guardian, representative, booking contact, or fellow passenger acting with authority;
- from Airlines, airports, handling agents, authorities, alternative dispute resolution bodies, courts, or qualified professionals;
- from flight-status, schedule, airport, and aviation-data providers;
- from authentication, electronic-signature, payment, communications, analytics, advertising, fraud-prevention, and hosting providers;
- from public sources where lawfully relevant to a Claim; and
- through your use of the website and account.
If you provide another person's data, you confirm that you are entitled to do so and have given that person information about this processing where required.
5. Purposes and legal bases
| Purpose | Data typically used | GDPR legal basis |
|---|---|---|
| Provide a Preliminary Check and answer pre-contract questions | Contact, flight, route, disruption, device, and checker data | Steps requested before a contract, Article 6(1)(b) |
| Create an account and authenticate users | Identity, contact, account, session, and security data | Contract, Article 6(1)(b); legitimate interests in secure access, Article 6(1)(f) |
| Determine and record the Service Route | Residence, route, Airline, flight, legal-framework and workflow data | Steps requested before a contract and contract, Article 6(1)(b); legitimate interests in lawful routing and auditability, Article 6(1)(f) |
| Acquire, notify, own, prepare, submit and manage a Full Ownership Claim | Identity, flight, booking, Assignment, evidence, ownership, communication and claim data | Contract, Article 6(1)(b); establishment, exercise and defence of legal claims and legitimate interests, Article 6(1)(f) |
| Prepare and manage Passenger-First assistance | Identity, flight, booking, Authorization, customer-submission, evidence, communication and claim data | Contract, Article 6(1)(b); legitimate interests in effective assistance, Article 6(1)(f) |
| Communicate with Airlines, authorities, dispute bodies, and qualified professionals | Claim, identity, Authorization, evidence, and communication data | Contract, Article 6(1)(b); legal claims and legitimate interests, Article 6(1)(f) |
| Receive Full Ownership Compensation, calculate the Recovery Share, invoice Passenger-First fees, and make payouts | Identity, ownership, payout, transaction, accounting, invoice and claim data | Contract, Article 6(1)(b); legal obligations, Article 6(1)(c); legitimate interests in payment reconciliation, Article 6(1)(f) |
| Process withdrawal and reassign a Claim | Identity, Assignment, service activity, communication, settlement and notice data | Contract and legal obligations, Articles 6(1)(b) and 6(1)(c); legal claims, Article 6(1)(f) |
| Meet tax, accounting, consumer, data-protection, sanctions, and other legal requirements | Identity, transaction, claim, consent, and audit data | Legal obligation, Article 6(1)(c) |
| Prevent fraud, duplicate claims, abuse, security incidents, and unlawful access | Identity, device, account, logs, documents, transaction, and risk data | Legitimate interests in protecting users, funds, claims, and systems, Article 6(1)(f); legal obligation where applicable, Article 6(1)(c) |
| Provide support, handle complaints, and establish or defend rights | Contact, claim, communication, evidence, and transaction data | Contract, Article 6(1)(b); legitimate interests and legal claims, Article 6(1)(f); legal obligation where applicable, Article 6(1)(c) |
| Improve service quality, diagnose errors, and maintain auditability | Usage, diagnostics, claim workflow, support, and security data | Legitimate interests in reliable and accountable operations, Article 6(1)(f) |
| Measure website use with consent-based analytics | Cookie, device, usage, and conversion data | Consent, Article 6(1)(a), where consent is required |
| Measure advertising, create audiences, and personalize advertising | Advertising identifiers, consent signals, conversion, campaign, and usage data | Consent, Article 6(1)(a) |
| Use strictly cookieless aggregate analytics | Aggregate page and source information without persistent visitor identifiers | Legitimate interests, Article 6(1)(f), where the configured method does not require consent |
| Send optional marketing communications | Contact, preferences, and engagement data | Consent, Article 6(1)(a), or another lawful basis permitted for existing-customer communications |
| Establish, exercise, or defend a Claim involving special-category data | Relevant evidence and claim data | Article 9(2)(f), or explicit consent under Article 9(2)(a), as applicable |
Where we rely on legitimate interests, we consider the necessity and impact of the processing and apply safeguards. You may object as described below.
6. Contractual and required data
Information marked as required in the claim flow is necessary to assess or handle the Claim, authenticate the account, comply with legal duties, or make a payout. If required information is not provided, we may be unable to complete the check, determine the Service Route, execute or verify an Assignment or Authorization, accept the Claim, communicate with the Airline, process a customer submission, or transfer funds.
Optional analytics and marketing consent is not required to use the core service.
7. AI-assisted processing and human involvement
We may use AI-assisted tools to:
- extract structured information from uploaded documents;
- classify evidence and correspondence;
- identify inconsistencies or missing information;
- summarize Airline messages;
- compare flight facts with passenger-rights criteria; and
- prepare suggested customer or Airline communications.
We apply access controls, data minimization, instructions to service providers, and human oversight appropriate to the task. The rules engine may recommend a Service Route, but material route exceptions and legal holds are reviewable by a person. AirReclaim does not rely solely on automated processing to make a decision that produces legal effects or similarly significant effects for you. You may request human intervention, express your view, or contest an assessment by contacting privacy@airreclaim.com or support@airreclaim.com.
8. Recipients and service providers
We share personal data only where necessary and proportionate. Recipients may include:
- Airlines, airports, handling agents, claims agents, debtors, and their representatives;
- passenger-rights authorities, enforcement bodies, alternative dispute resolution bodies, courts, bailiffs, translators, and qualified legal professionals;
- flight-data and aviation-information providers;
- hosting, database, private-storage, backup, cybersecurity, malware-scanning, document-processing, and technical support providers;
- authentication and account providers, including Clerk where configured;
- electronic-signature and Authorization providers;
- communications and email-delivery providers;
- payment and payout providers, banks, Stripe, and Worldline where used;
- analytics and product-measurement providers, including Google Analytics 4, Plausible Analytics, and PostHog where configured;
- advertising providers, including Google Ads, subject to consent;
- Cookiebot CMP by Usercentrics for consent management;
- AI service providers acting under contractual and technical restrictions;
- accountants, auditors, insurers, and professional advisers; and
- competent public authorities where disclosure is required or lawfully necessary.
Service providers acting as processors are bound by data-processing terms. Some providers, particularly payment, banking, fraud-prevention, regulatory, or public-authority recipients, may act as independent controllers for their own legal purposes.
9. Payments and payment-provider roles
Where Stripe or Worldline is used, the provider may collect card, device, transaction, authentication, and fraud-prevention data directly through its secure interface. AirReclaim ordinarily receives transaction status, payer details needed for reconciliation, risk information, and a payment token rather than full card data.
Stripe, Worldline, a bank, or another payment institution may act:
- as our processor for specific technical payment functions;
- as an independent controller where it must comply with financial, fraud-prevention, anti-money-laundering, sanctions, card-network, or regulatory duties; or
- in another role described in its own privacy information.
10. International data transfers
Recipients may process data outside Poland or the European Economic Area. Where personal data is transferred to a country without an applicable European Commission adequacy decision, we use an approved transfer mechanism, such as the European Commission's Standard Contractual Clauses, together with supplementary safeguards where appropriate.
Safeguards may include data minimization, access restrictions, encryption, regional processing options, contractual limits, transfer assessments, and procedures for government-access requests. You may request information about the relevant safeguards by contacting privacy@airreclaim.com.
11. Retention
We keep personal data only for as long as reasonably necessary for the purpose, legal obligations, dispute periods, and the establishment or defense of claims.
| Data or record | Typical retention approach |
|---|---|
| Preliminary Check not converted into an accepted Claim | Up to 12 months, unless a shorter period is selected or retention is needed to answer a request or prevent abuse |
| Active Claim and account | For the duration of the Claim and account relationship |
| Closed Claim, supporting documents, Assignment or Authorization, title-chain notices, and material correspondence | Generally up to 6 years after closure, subject to longer or shorter mandatory periods and any continuing dispute |
| Payout, invoice, tax, and accounting records | For the period required by Polish tax and accounting law, generally at least 5 years after the end of the relevant tax year |
| Support request unrelated to a Claim | Generally up to 3 years after resolution |
| Security, access, and diagnostic logs | Generally up to 12 months; longer where needed to investigate an incident, fraud, or legal claim |
| Consent and opt-out evidence | For the life of the consent or opt-out and generally up to 3 years afterward to demonstrate compliance |
| Marketing contact data | Until consent is withdrawn, an objection is received, or the data is no longer useful, plus a limited suppression record |
| Unnecessary or rejected document uploads | Deleted or isolated as soon as reasonably practicable, generally within 90 days, unless required for security evidence, a complaint, or a legal hold |
| Consent-based analytics data | According to the configured provider setting, generally 2 to 14 months for user-level event data, while relevant cookies may last up to 24 months |
| Cookieless aggregate analytics | Retained as aggregate statistics without a persistent visitor profile |
Retention can be extended where necessary for litigation, regulatory requests, fraud prevention, enforcement of a contract, or protection of a Claimant's rights. When data is no longer needed, it is deleted, anonymized, or securely isolated.
12. Your GDPR rights
Subject to the conditions and exceptions in applicable law, you may request:
- access to your personal data and a copy;
- correction of inaccurate or incomplete data;
- erasure;
- restriction of processing;
- portability of data you provided where processing is based on consent or contract and carried out by automated means;
- objection to processing based on legitimate interests;
- withdrawal of consent at any time, without affecting processing before withdrawal;
- human intervention concerning a qualifying automated decision; and
- information about international-transfer safeguards.
Send requests to privacy@airreclaim.com. To protect you and other Claimants, we may verify identity and authority. We normally respond within one month, subject to lawful extensions for complex or numerous requests.
You may opt out of marketing at any time by using the unsubscribe method in the message or contacting privacy@airreclaim.com. Cookie consent can be changed through the cookie settings widget on the website.
13. Right to complain
You may lodge a complaint with the supervisory authority in the European Union country of your habitual residence, workplace, or the place of the alleged infringement.
The Polish supervisory authority is:
President of the Personal Data Protection Office
Personal Data Protection Office
ul. Stanisława Moniuszki 1A
00-014 Warszawa
Poland
You may contact us first so we have an opportunity to address the concern, but this is not a condition of making a complaint.
14. Children and fellow passengers
The Services are not directed to children acting independently. A Claim involving a minor must be submitted by a parent, guardian, or authorized adult. We process a minor's data only as needed for the Claim and may request evidence of authority.
For a group or family Claim, each adult Claimant must authorize the relevant processing and representation, unless another lawful authority applies.
15. Security
We use technical and organizational measures designed to protect personal data, including controlled access, authentication, encrypted communications, private document storage, logging, backups, provider management, and incident procedures. No online system can be guaranteed to be completely secure.
Security concerns may be reported to security@airreclaim.com.
16. Changes to this Policy
We may update this Policy to reflect changes in law, providers, technology, supported Claims, or processing. The current version will be published at airreclaim.com with its effective date. Material changes affecting an active service relationship will be communicated where required.
17. Contact
Privacy questions and rights requests: privacy@airreclaim.com
Nova Group Sp. z o.o.
Żurawia 6/12 Lok. 745
00-503 Warszawa, Poland
