- Scope
- Poland / European Union
- Document status
- production ready
- Questions
- support@airreclaim.com
1. Security approach
AirReclaim handles identity, travel, claim, document, Authorization, communication, and payout information. Nova Group Sp. z o.o. applies technical and organizational measures designed to protect confidentiality, integrity, availability, and accountability throughout the service.
Security is risk-based. No website or electronic transmission can be guaranteed to be completely secure, but we work to reduce preventable risk and respond appropriately to suspected incidents.
2. Payment security
Where online payments, card verification, or payment authentication are used, AirReclaim may use Stripe, Worldline, or another regulated payment provider.
- Full card details are entered into or transmitted through the payment provider's secure interface.
- AirReclaim does not store full card details.
- We ordinarily receive a payment token, status, limited payer or transaction information, and fraud or authentication results needed for reconciliation and support.
- Payment providers may use device, cookie, authentication, and transaction data to prevent fraud and meet financial or card-network duties.
- Strong customer authentication or another verification step may be required.
Using a payment provider reduces AirReclaim's direct handling of card data but does not remove our responsibility to secure our own systems and integration.
3. Account security
Account and claim access may be protected through:
- verified sign-in methods;
- short-lived session tokens and secure session management;
- role-based access;
- re-authentication for sensitive actions;
- rate limiting and abuse controls;
- audit and security event logging;
- session revocation;
- restricted administrative access; and
- identity or authority verification before disclosure or payout.
We may suspend a session, restrict an account, or request additional verification where activity appears unusual or creates a risk to a Claimant, payment, document, or system.
4. Data and document protection
Security measures can include:
- encrypted connections for data in transit;
- provider-supported encryption for stored data;
- private storage and controlled document access;
- least-privilege access;
- separation of customer and administrative permissions;
- malware scanning and file-type validation;
- secure upload and download methods;
- backup and recovery controls;
- logging and monitoring;
- secrets and credential management;
- vulnerability and dependency management;
- retention and deletion controls; and
- contractual and security assessment of service providers.
Access to personal data is limited to people and providers who need it for an authorized purpose.
5. Authorization and payout controls
Because an Authorization can permit claim submission and receipt of Compensation, we may retain evidence such as the document version, signature or approval event, timestamp, authentication result, and completion record.
Payout controls may include verification of the Claimant, bank-account holder, account details, recovered amount, Service Fee, sanctions status, duplicate-payment risk, and transaction history. A payout can be paused while a material inconsistency or compliance issue is investigated.
6. AI-assisted processing
AI-assisted tools may be used for document extraction, classification, inconsistency detection, summarization, or preparation of suggested communications.
We apply data minimization, access controls, provider terms, task-specific instructions, and human control appropriate to the function. Sensitive information should not be included where it is not needed. Material legal-sensitive or payout actions are not approved solely by an AI output.
7. Service-provider security
AirReclaim can depend on providers for hosting, databases, authentication, electronic signatures, communications, document processing, analytics, payments, and flight data.
We seek to use providers with security and privacy controls appropriate to the data and function. Providers receive only the data reasonably needed for their role and are subject to contractual obligations where required.
A provider's certification, security statement, or availability does not guarantee that AirReclaim or the provider will never experience an incident.
8. Customer responsibilities
You can help protect your account and Claim by:
- using a strong, unique sign-in method;
- protecting access to your email account;
- not sharing sign-in links or verification codes;
- checking that you are using the airreclaim.com domain;
- signing out on shared devices;
- keeping your device and browser updated;
- reviewing payout details carefully;
- treating unexpected requests for documents or payment with caution; and
- reporting suspicious activity promptly.
AirReclaim will not ask you to reveal a password or one-time code by email.
9. Security incident response
When we become aware of a suspected security incident, we assess the scope, contain the issue where possible, preserve relevant evidence, address the cause, and evaluate legal notification duties.
Where required by law, we will notify the competent authority and affected individuals without undue delay. A communication may describe the nature of the incident, likely consequences, measures taken, and steps the recipient can take.
We may provide updates as reliable information becomes available. Security considerations can limit details that would increase risk or prejudice an investigation.
10. Responsible disclosure
Security researchers and users may report a suspected vulnerability to:
Please include:
- the affected page, endpoint, or function;
- a clear description of the issue and potential impact;
- reproducible steps using non-destructive methods;
- screenshots, logs, or proof that do not expose another person's data;
- the date and environment tested; and
- a safe way to contact you.
Please do not:
- access, retain, alter, or disclose another person's data;
- disrupt availability or degrade the service;
- use social engineering, phishing, physical intrusion, denial-of-service methods, or destructive testing;
- upload malware;
- demand payment or threaten disclosure; or
- publish the issue before we have had a reasonable opportunity to investigate and reduce risk.
We aim to acknowledge a responsible security report within up to 14 days. This disclosure channel does not create a promise of payment, employment, immunity, or a reward program. Activity must remain lawful and proportionate.
11. Suspicious messages and fraud
Verify that website links use the airreclaim.com domain. Be cautious where a message:
- pressures you to pay an unexpected fee;
- asks for a password or one-time code;
- requests payout to an unrelated person;
- claims guaranteed Compensation;
- asks you to install remote-access software; or
- uses a lookalike domain.
Forward suspicious AirReclaim-related messages to security@airreclaim.com. Do not include unnecessary sensitive information.
12. Contact
Security reports: security@airreclaim.com
General support: support@airreclaim.com
Nova Group Sp. z o.o.
Żurawia 6/12 Lok. 745
00-503 Warszawa, Poland
