Last updated: 23 July 2026
Version 1.0 | Effective 23 July 2026
This policy explains how FLIGHTREMEDY (Pty) Ltd (registration number 2026/554635/07, registered address 2 Nebiolo Way, Stellenbosch, 7600, South Africa) collects and uses personal information under the Protection of Personal Information Act 4 of 2013 (“POPIA”). We are the “responsible party” for your information.
Information Officer: Rayner van Wyk, info@flightremedy.com.
We collect this directly from you. We do not buy data about you or sell data to anyone.
We use personal information only for these purposes: assessing whether your flight qualifies; preparing, submitting and enforcing the compensation claim; proving the cession or our authority to airlines, courts, regulators and dispute-resolution bodies; paying you; meeting legal obligations (tax, accounting, fraud prevention); handling complaints; and improving our website. Our lawful grounds under POPIA are performance of our contract with you, compliance with law, and our legitimate interest in running and protecting the business. Where we rely on consent (for example optional marketing emails), you can withdraw it at any time.
We process a child’s information only when a parent or legal guardian provides it and signs for the child, which POPIA permits with the consent of a competent person. We use it only to pursue the child’s claim.
We share only what each recipient needs, and our service providers may act only on our instructions under written agreements (POPIA section 19 and 21 safeguards).
Pursuing an EU or UK claim requires transferring personal information (typically name, contact details, booking reference, flight details, and occasionally passport data) to recipients in the EU, UK and other countries. We do this on the following POPIA section 72 grounds:
(a) Adequate protection: recipients in the EU and UK are subject to the GDPR and UK GDPR, laws that provide protection substantially similar to POPIA, and our contracts with enforcement partners and service providers bind them to equivalent safeguards;
(b) Contract performance: the transfer is necessary to perform our contract with you, since the claim can only be enforced where the airline or court is; and
(c) Consent: by accepting these terms and our T&Cs you consent to these transfers for these purposes.
Where a recipient is in a country without an adequate data protection law (for example, our hosting and email providers in the United States), we transfer only under a written agreement imposing POPIA-equivalent protections.
We keep claim files for 5 years after the claim is finally closed (paid, abandoned or cancelled), because tax law requires us to keep transaction records and because claims can be reopened or disputed. Signature and audit records are kept for the same period, since they prove the cession. We then delete or anonymise the information, unless a live dispute requires longer retention.
We protect personal information with encryption in transit and at rest, access controls, and contractual obligations on every service provider. If a breach creates a real risk of harm, we will notify the Information Regulator and affected people as POPIA section 22 requires.
You may: ask what information we hold about you and get a copy; ask us to correct or delete information; object to processing based on legitimate interests; withdraw consent where processing rests on consent; and refuse marketing. To exercise any right, email the Information Officer at info@flightremedy.com. We respond within a reasonable time and never charge for a first request. Deleting information that we need to run a live claim may mean we can no longer pursue it; we will tell you before that happens.
If you are unhappy with our answer, you may complain to the Information Regulator (South Africa): complaints.IR@inforegulator.org.za, inforegulator.org.za.
Our customers are South African residents and we direct our service at South Africa, so the EU GDPR does not directly govern our relationship with you. Our EU and UK counterparties handle your information under the GDPR and UK GDPR once it reaches them, and we handle it in a way designed to be compatible with those laws, so your information does not lose protection by crossing borders. If we later offer the service to people located in the EU or UK, we will review whether the GDPR applies directly to us before doing so.
We may update this policy; material changes will be notified by email or on the website, with the effective date shown above. Questions: info@flightremedy.com.