Privacy notice
This tool holds a carrier's own operations data so that the carrier can meet the deadlines the air passenger rights rules set. The carrier is the controller of that data. We are its processor and act on its instructions.
Who is responsible
Data controller for the account itself (the people who sign in): Armen Sarkisian, Komitas 57, 0032 Yerevan, Armenia. Questions: privacy@vitersoft.com. For passenger data, the controller is the carrier whose account holds it.
What is held about a passenger
A journey reference, the airports, the scheduled and actual times, whether a rerouting was taken, how much notice a cancellation had, and an e-mail address — the last only so that the notice the rules require can be sent. Nothing else survives the import.
The importer refuses dates of birth, passport and document numbers, addresses, seat numbers, special service codes, payment details, loyalty numbers and names, and lists every refused column on screen after the import. A special service code is health data about a named person, and it has no part in working out what is owed.
Who else sees it
- Cloudflare, Inc. (EU region) — runs the application.
- Supabase (EU, Frankfurt) — the database and the file store. The public keys hold no rights at all; only our server reads it.
- Sendinblue SAS, 9-17 rue Salneuve, 75017 Paris, France (trading as Brevo) — sends the sign-in links and the notices to passengers. It receives the address and the text of the message. Brevo lægger et usynligt billede i hver mail, så det registreres, når en mail åbnes, og omtrent hvorfra. Vi beder ikke om det, ser ikke på det og kan ikke slå det fra pr. mail — målt 19.09.2026, begge dokumenterede muligheder blev prøvet. Selve login-linket bliver ikke skrevet om og går ikke gennem Brevo. / Brevo puts an invisible image in every letter it sends, so it registers when a letter is opened and from roughly where. We do not ask for that, do not look at it and cannot switch it off per message — measured 19.09.2026, both documented switches were tried. The sign-in link itself is not rewritten and does not go through Brevo.
- PostHog (EU, Germany) — counts how the tool is used: numbers and categories, never a passenger, a booking reference or a carrier's name.
- OpenRouter, Inc. — smooths the wording of a reasoned reply, and only that, routed to providers that keep nothing and train on nothing. Off where no key is configured. See the section below.
Where a model is used, and where it is not
The notice under Article 7(4) and the acknowledgement under Article 7(9) are assembled by code from the carrier's own row, word for word. No model sees them and no model writes them.
A reasoned reply — the letter that pays or refuses — is also assembled by code, and may then be passed to a language model to smooth the wording. The model is instructed to change no figure, no date and no reference and to add nothing; what comes back is checked against the same record before anybody sees it, and a letter carrying a figure, a date or a court case that is not in the record is refused rather than shown as ready. A person at the carrier then reads it and approves it. Nothing is sent to a passenger without that.
What the model receives is the letter: a journey reference, the airports, the dates, the amount, the circumstance the carrier invoked and the titles of the documents behind it. It does not receive the passenger's address — the address is not in the letter — and it never receives a name, because the importer refuses names. The request is routed only to providers that keep nothing and train on nothing (“zero data retention”). Where the carrier's deployment has no model configured, the letter is simply the template, and nothing leaves at all.
How long
A passenger's address is erased once the carrier can no longer be asked about them: the nine months Article 7(9) gives them to submit a request, and then the carrier's own retention period — 24 months unless the carrier sets another figure in its settings and its data processing agreement. Where a request was made, the period runs from the day it was answered instead. A nightly sweep does it and writes down how many rows it touched.
What survives is the compliance record: which journey, what was owed, when the notice was due and whether it went. It names nobody, and it is what an authority asks for. Expired sign-in links are deleted outright.
A carrier can delete its account and everything in it from the settings screen: the journeys, the notices and the messages sent with them, the requests and complaints, the evidence files in storage, the drafts and the audit log. Nothing is held back.
Cookies
One: the sign-in cookie, which holds the carrier and the person and nothing else. The analytics are configured without cookies and without local storage, so there is no banner to click.