EC261 Compliance

Privacy notice

This tool holds a carrier's own operations data so that the carrier can meet the deadlines the air passenger rights rules set. The carrier is the controller of that data. We are its processor and act on its instructions.

Who is responsible

Data controller for the account itself (the people who sign in): Armen Sarkisian, Komitas 57, 0032 Yerevan, Armenia. Questions: privacy@vitersoft.com. For passenger data, the controller is the carrier whose account holds it.

What is held about a passenger

A journey reference, the airports, the scheduled and actual times, whether a rerouting was taken, how much notice a cancellation had, and an e-mail address — the last only so that the notice the rules require can be sent. Nothing else survives the import.

The importer refuses dates of birth, passport and document numbers, addresses, seat numbers, special service codes, payment details, loyalty numbers and names, and lists every refused column on screen after the import. A special service code is health data about a named person, and it has no part in working out what is owed.

Who else sees it

Where a model is used, and where it is not

The notice under Article 7(4) and the acknowledgement under Article 7(9) are assembled by code from the carrier's own row, word for word. No model sees them and no model writes them.

A reasoned reply — the letter that pays or refuses — is also assembled by code, and may then be passed to a language model to smooth the wording. The model is instructed to change no figure, no date and no reference and to add nothing; what comes back is checked against the same record before anybody sees it, and a letter carrying a figure, a date or a court case that is not in the record is refused rather than shown as ready. A person at the carrier then reads it and approves it. Nothing is sent to a passenger without that.

What the model receives is the letter: a journey reference, the airports, the dates, the amount, the circumstance the carrier invoked and the titles of the documents behind it. It does not receive the passenger's address — the address is not in the letter — and it never receives a name, because the importer refuses names. The request is routed only to providers that keep nothing and train on nothing (“zero data retention”). Where the carrier's deployment has no model configured, the letter is simply the template, and nothing leaves at all.

How long

A passenger's address is erased once the carrier can no longer be asked about them: the nine months Article 7(9) gives them to submit a request, and then the carrier's own retention period — 24 months unless the carrier sets another figure in its settings and its data processing agreement. Where a request was made, the period runs from the day it was answered instead. A nightly sweep does it and writes down how many rows it touched.

What survives is the compliance record: which journey, what was owed, when the notice was due and whether it went. It names nobody, and it is what an authority asks for. Expired sign-in links are deleted outright.

A carrier can delete its account and everything in it from the settings screen: the journeys, the notices and the messages sent with them, the requests and complaints, the evidence files in storage, the drafts and the audit log. Nothing is held back.

Cookies

One: the sign-in cookie, which holds the carrier and the person and nothing else. The analytics are configured without cookies and without local storage, so there is no banner to click.