Flightremedy Privacy Policy

Last updated: 23 July 2026

Version 1.0 | Effective 23 July 2026

This policy explains how FLIGHTREMEDY (Pty) Ltd (registration number 2026/554635/07, registered address 2 Nebiolo Way, Stellenbosch, 7600, South Africa) collects and uses personal information under the Protection of Personal Information Act 4 of 2013 (“POPIA”). We are the “responsible party” for your information.

Information Officer: Rayner van Wyk, info@flightremedy.com.

1. What we collect

  • Identity and contact details: name, email, phone number, and for minors, date of birth and the identity of the signing parent or guardian.
  • Claim information: booking reference, flight numbers and dates, boarding passes, booking confirmations, correspondence with the airline, and occasionally passport or ID details where an airline or court requires proof of identity.
  • Payment details: your South African bank account details, used only to pay you.
  • Signature and audit records: your electronic signature, and the timestamp, IP address and device information captured when you sign.
  • Website data: technical data and cookies, as described in our Cookie Policy.

We collect this directly from you. We do not buy data about you or sell data to anyone.

2. Why we use it

We use personal information only for these purposes: assessing whether your flight qualifies; preparing, submitting and enforcing the compensation claim; proving the cession or our authority to airlines, courts, regulators and dispute-resolution bodies; paying you; meeting legal obligations (tax, accounting, fraud prevention); handling complaints; and improving our website. Our lawful grounds under POPIA are performance of our contract with you, compliance with law, and our legitimate interest in running and protecting the business. Where we rely on consent (for example optional marketing emails), you can withdraw it at any time.

3. Children

We process a child’s information only when a parent or legal guardian provides it and signs for the child, which POPIA permits with the consent of a competent person. We use it only to pursue the child’s claim.

4. Who we share it with

  • Airlines against which your claim is made, and bodies paying on their behalf.
  • Enforcement partners: law firms, registered debt-collection service providers and claims-enforcement businesses in the country where the claim must be enforced (mainly the Netherlands, Germany, France and the United Kingdom).
  • Courts, tribunals, ADR schemes and national enforcement bodies handling your claim.
  • Service providers who process data for us under contract: Vercel (website hosting and infrastructure, United States), Supabase (database, file storage and authentication, hosted in its European Union region, AWS Frankfurt, Germany), Resend (transactional email, United States), Wise (receiving compensation payments from airlines and paying out to you, United Kingdom), our South African bank, our e-signature provider, and our accountants and auditors.
  • Advertising and analytics partners (Google and Meta) receive limited technical data through cookies only with your consent via our cookie banner, as described in our Cookie Policy. We send electronic direct marketing only as permitted by section 69 of POPIA.

We share only what each recipient needs, and our service providers may act only on our instructions under written agreements (POPIA section 19 and 21 safeguards).

5. Sending information outside South Africa

Pursuing an EU or UK claim requires transferring personal information (typically name, contact details, booking reference, flight details, and occasionally passport data) to recipients in the EU, UK and other countries. We do this on the following POPIA section 72 grounds:

(a) Adequate protection: recipients in the EU and UK are subject to the GDPR and UK GDPR, laws that provide protection substantially similar to POPIA, and our contracts with enforcement partners and service providers bind them to equivalent safeguards;

(b) Contract performance: the transfer is necessary to perform our contract with you, since the claim can only be enforced where the airline or court is; and

(c) Consent: by accepting these terms and our T&Cs you consent to these transfers for these purposes.

Where a recipient is in a country without an adequate data protection law (for example, our hosting and email providers in the United States), we transfer only under a written agreement imposing POPIA-equivalent protections.

6. How long we keep it

We keep claim files for 5 years after the claim is finally closed (paid, abandoned or cancelled), because tax law requires us to keep transaction records and because claims can be reopened or disputed. Signature and audit records are kept for the same period, since they prove the cession. We then delete or anonymise the information, unless a live dispute requires longer retention.

7. Security

We protect personal information with encryption in transit and at rest, access controls, and contractual obligations on every service provider. If a breach creates a real risk of harm, we will notify the Information Regulator and affected people as POPIA section 22 requires.

8. Your rights

You may: ask what information we hold about you and get a copy; ask us to correct or delete information; object to processing based on legitimate interests; withdraw consent where processing rests on consent; and refuse marketing. To exercise any right, email the Information Officer at info@flightremedy.com. We respond within a reasonable time and never charge for a first request. Deleting information that we need to run a live claim may mean we can no longer pursue it; we will tell you before that happens.

If you are unhappy with our answer, you may complain to the Information Regulator (South Africa): complaints.IR@inforegulator.org.za, inforegulator.org.za.

9. A note on the GDPR

Our customers are South African residents and we direct our service at South Africa, so the EU GDPR does not directly govern our relationship with you. Our EU and UK counterparties handle your information under the GDPR and UK GDPR once it reaches them, and we handle it in a way designed to be compatible with those laws, so your information does not lose protection by crossing borders. If we later offer the service to people located in the EU or UK, we will review whether the GDPR applies directly to us before doing so.

10. Changes and contact

We may update this policy; material changes will be notified by email or on the website, with the effective date shown above. Questions: info@flightremedy.com.