1. Controller and privacy contact
The controller is TGZ Holding B.V., trading as Flymoney Legal Services, Jonkerbosplein 52, 6534 AB Nijmegen, The Netherlands. Privacy requests may be sent to post@flymoney.eu or submitted through the secure privacy portal.
2. Scope and roles
This notice covers the public website, claim assessment, customer and business portals, partner and lawyer access, communications, documents, payments, security and audit processes. Flymoney acts as controller for its own purposes. In individual collaborations a recipient may be an independent controller or act as processor; the specific role is recorded in the internal processing and service-provider register.
3. Purposes and legal bases
We process data for pre-contractual assessment and contract performance, creation and handling of passenger claims, communications, evidence management, claim enforcement, administration, fraud and abuse prevention, IT security, establishment or defence of legal claims, compliance with legal obligations and handling of data subject rights. Depending on the activity, legal bases include Article 6(1)(b), (c) or (f) GDPR and, where genuinely required, consent under Article 6(1)(a) GDPR. Legitimate interests include secure platform operation, abuse prevention, accountability and the establishment or defence of claims; the interests and rights of the individual are assessed for the relevant processing.
4. Categories of personal data
We may process identification and contact data, date of birth, address and payment details, flight, booking and ticket data, information about accompanying passengers and minors, communications, uploaded documents, payment and accounting data, portal and authentication data, IP address, user agent, timestamps, security events, audit data, consent and contract snapshots and outputs of internal rule-based document and case analyses. Special-category data should not be submitted unless necessary; where exceptionally relevant, the specific legal basis is assessed separately.
5. Sources of data and Article 14 GDPR
Data normally comes directly from the individual. It may also come from accompanying passengers or legal representatives, business customers, travel agencies, partners, lawyers, airlines, public flight and legal sources or communications concerning a claim. Where data is not obtained directly from the individual, Flymoney assesses the information duties under Article 14 GDPR and any applicable statutory exceptions.
6. Requirement to provide data
Certain information is necessary for claim assessment, contract performance, identification of the journey, communications or payment. Without necessary flight, booking, passenger or contact details, a case may not be capable of assessment or handling. Voluntary information is treated as voluntary.
7. Recipients
Recipients may include operating airlines, authorised lawyers or debt-collection providers, courts and public authorities, banks and payment providers and technical service providers for hosting, email, signing, security or other necessary functions. Access is limited by purpose, role and authorisation. Service providers and their contractual or controller status are maintained in an internal register.
8. International transfers
Flymoney prefers processing within the European Economic Area. Where a provider processes or makes data accessible outside the EEA, Flymoney assesses whether an adequacy decision, appropriate safeguards such as standard contractual clauses or another lawful mechanism applies. The specific transfer position is documented in the service-provider register.
9. Website, cookies and external content
Under the current configuration Flymoney does not use Google Analytics, Matomo, retargeting or marketing tracking cookies. Strictly necessary cookies support functions such as login, session management and protection against cross-site request forgery. Public media hosted by an external provider may transmit technical connection data to that host when retrieved; Flymoney aims to limit such dependencies to what is necessary.
10. Portals, security and logging
Security measures include role- and object-based access controls, secure sessions, audit logs, malware scanning, hashes, security events, rate limits and technical logs. Security and audit data is retained only as long as necessary for security, evidence, investigation and legal requirements.
11. Internal analysis and automated decision-making
Flymoney may use internal rule-based analysis of documents and case data to identify missing information, inconsistencies or review points. Under the current system architecture there is no solely automated decision producing legal or similarly significant effects within the meaning of Article 22 GDPR. A legally or economically significant decision is intended to remain capable of human review.
12. Retention and erasure
Retention is determined by data category, process stage, limitation and evidential needs, statutory retention duties and legal defence. Flymoney maintains retention rules in an internal register. Expired periods automatically generate candidates for erasure, anonymisation or legal hold. Export files generated through the privacy portal are available for a limited period and then technically purged.
13. Right of access
Under Article 15 GDPR individuals may request information about processing and a copy of their personal data. The scope may be limited by the rights of others and statutory exceptions.
14. Rectification, erasure and restriction
Subject to Articles 16 to 18 GDPR, individuals may request rectification, erasure or restriction. An erasure request does not require immediate destruction where mandatory retention, evidential needs or legal defence require continued storage. In such cases processing is restricted where appropriate and the decision is documented.
15. Data portability
Where Article 20 GDPR applies, personal data provided by the individual can be received in a structured, commonly used and machine-readable format. A machine-readable export can be generated in the secure portal; broader access rights remain unaffected.
16. Right to object
Where processing is based on Article 6(1)(e) or (f) GDPR, an objection may be made under Article 21 GDPR on grounds relating to the individual's particular situation. Flymoney records the objection, reviews the specific legal basis and restricts the relevant processing during necessary review where appropriate.
17. Withdrawal of consent
Consent may be withdrawn at any time for the future. Lawfulness of processing before withdrawal remains unaffected. Not all Flymoney processing relies on consent; contract, legal obligation or legitimate interests may continue independently.
18. Deadlines and identity verification
Data subject requests are handled without undue delay and in principle within the statutory one-month period. For complex or numerous requests the period may be extended within the limits of the GDPR; the individual is informed of the extension and reasons. Where there are reasonable doubts, additional information may be requested to confirm identity.
19. Personal data breaches
Personal data breaches are documented with awareness time, risk, affected data, consequences and measures. Where statutory conditions are met, notification is made to the competent supervisory authority within the legal deadline and, in cases of high risk, affected individuals are also informed.
20. DPIAs and service-provider oversight
Processing likely to result in high risk is subject to a data protection impact assessment. Service providers are recorded and reviewed by role, data categories, location, contractual basis, subprocessors, security and international transfers.
21. Right to complain
Individuals may lodge a complaint with a competent data protection supervisory authority. Flymoney also asks that privacy concerns be sent to post@flymoney.eu or through the secure privacy portal so the matter can be handled in an auditable workflow.
22. Version and changes
This privacy notice is reviewed when processing, technology or law changes materially. The published version applies; material changes are versioned and included in the legal-currentness review process.