PRIVACY & DATA PROTECTION

Your data, handled properly.

What we collect to run your claim, why we need it, how long we keep it, and the control you keep over it at all times.

Last updated: 15 September 2026

GDPR compliant

Data is processed under the EU General Data Protection Regulation as data controller.

Encrypted storage

Passports, boarding passes and banking proof are stored encrypted in a private, access-controlled storage.

Never sold

We never sell or rent your data. It is shared only with the airline, courts or authorities handling your case.

1. Who controls your data

Flayder ApS, Bredgade 36, 4th floor, 1260 København K, Denmark (CVR 44 21 87 09) is the data controller. For any privacy question or request, write to hello@flayder.com.

2. What we collect

We collect only what is required to assess and pursue your claim:

  • Identity and contact details: full name, email, phone number and address.
  • Flight details: flight number, date, route and disruption type.
  • Documents you upload: boarding pass, passport or ID, and proof of account ownership.
  • Banking details needed to transfer your compensation (only where required for payout).
  • Your signed power of attorney and signature image.
  • Technical data: language preference, IP address and device/browser information for security.

3. Why we process it (legal basis)

We process your data to perform the claim service you requested (contract), to comply with legal and accounting obligations (legal obligation), and to secure our platform and prevent fraud (legitimate interest). Marketing communication is sent only with your consent, which you can withdraw at any time.

4. Who we share it with

Your data is shared only with the airline against which the claim is filed, with courts, enforcement bodies or regulators if the case proceeds, with our payment provider to release your compensation, and with the service providers that host our systems — all bound by strict data-processing agreements. We never sell, rent or share your data for third-party advertising.

5. How long we keep it

Claim files and supporting documents are retained for up to 6 years after the case is closed, to cover the limitation periods that apply in the relevant jurisdictions and statutory accounting duties. Data collected for users who never submit a claim is deleted within 12 months. You can request earlier deletion at any time.

6. Security

We protect your data with technical and organisational measures, including:

  • Encryption of documents at rest and of all traffic in transit (TLS).
  • Row-level access control: only you can see your claim in your personal area; only authorised staff can see it in the internal case system.
  • Strict admin access, session-based authentication and anti-abuse protections across the site.

7. Cookies

We use essential cookies and browser storage to keep you signed in, remember your language and operate the site. We do not use third-party advertising or cross-site tracking cookies.

8. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data or complete incomplete data.
  • Delete your data ('right to be forgotten'), subject to legal retention duties.
  • Restrict or object to processing, and receive your data in a portable format.
  • Withdraw consent at any time, without affecting earlier processing.

9. Complaints

You can lodge a complaint with your national data protection authority. In Denmark this is the Datatilsynet. We would, of course, appreciate the chance to resolve any concern directly first — write to hello@flayder.com.

This policy is a summary of how we handle personal data. The full record of processing activities is available on request.