Skip to content

Privacy Policy

WE HAVE CREATED THIS PRIVACY POLICY BECAUSE WE HIGHLY VALUE YOUR PERSONAL DATA.

THIS PRIVACY POLICY INCLUDES IMPORTANT INFORMATION WITH RESPECT TO YOUR PERSONAL DATA.

The terms appearing in this Privacy Policy will have the definition set forth in the Terms and Conditions unless otherwise specified in this document.

 

1. Privacy Statement

1.1. FixRefund Cyprus Ltd., HE 465193 (“FixRefund” or “We”) offers specialized claim management services to individual seeking Compensation from airlines pursuant to instances of Flight Disruptions and as specified in the Terms and Conditions (the “Services”). FixRefund operates and manages the www.fixrefund.com website (“The Website”).

1.2. THIS PRIVACY POLICY REFERS TO THE Services AND THE Website AND RELATES TO FixRefund’s Clients, POTENTIAL Clients, Passengers, Additional Passengers, END-USERS, EMPLOYEES AND SERVICE PROVIDERS.

1.3. This Privacy Policy sets forth FixRefund’s policy with respect to any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person etc. (“Personal Data”).  “Non-Personal Data” is therefore any information that does not relate to an identified or identifiable natural person.

1.4. The limitations and requirements in this Privacy Policy relate only to our gathering, use, disclosure, transfer, and storage / retention of Personal Data, and do not apply to Non-Personal Data.

 

2. Data That We Use, Receive, Collect, Process or Store and How We Use It:

2.1. Using, receiving, collecting, processing or storing Personal Data is not our primary purpose.  FixRefund uses, receives, collects, processes or stores only Personal Data necessary to provide the Services and operate its business.

2.2. However, in the course of operating our business, We might use, receive, collect, process or store Personal Data relating to actual or prospective clients, service providers, contractors, suppliers, employees, users of our websites, and other individuals — solely as required for the provision of our Services or for the proper conduct of our business operations. This Personal Data may includes:

2.2.1. Full names, gender, dates of birth, citizenships, signatures examples, any information that appears in passports, phone numbers, email addresses, residential or business addresses, company names, and financial data such as billing details, bank account information, or credit card information, as required to provide our Services;

2.2.2. Travel-related information, including passport numbers, scans or photographs of passports, flight tickets, boarding passes, flight dates, flight numbers, departure and arrival destinations, and additional documentation and information necessary to validate eligibility for Compensation;

2.2.3. Information as detailed in Sections ‎2.1 and ‎2.2.2 above concerning the Passenger and the Additional Passengers, including, familial relationship to the Client, and relevant contact details, where claims are submitted on behalf of family members or travel companions;

2.2.4. Technical and usage data collected through interactions with our Website and Services, such as IP addresses, browser types and versions, pages visited, timestamps, time spent on each page, unique device identifiers, and diagnostic or analytical information;

 

3. Sources of Personal Data Not Collected Directly from the Data Subject

In some cases, We may collect Personal Data about individuals from third parties. This may include flight companions or legal representatives submitting claims on behalf of other passengers. Where applicable, We ensure that such parties have obtained appropriate authorization or consent from the relevant individuals.

 

4. COOKIES

4.1. We use cookies and similar tracking technologies to monitor activity on our Website and Services, to store certain information, enhance user experience, support functionality, and analyze performance.

4.2. Cookies are sent to your browser from a website and stored on your device. In addition to cookies, We may use other tracking technologies such as beacons, tags, and scripts to collect and analyze usage data and improve the quality of our Services.

4.3. You can instruct your browser to refuse all cookies or to alert you when a cookie is being sent. However, please note that disabling cookies may affect the availability or functionality of certain features of our Services.

4.4. Some cookies are strictly necessary for the operation of the Website and do not require your consent. Others — such as analytics or preference cookies — will only be activated based on your explicit consent, in accordance with applicable data protection laws. Examples of cookies We use:

4.4.1. Session Cookies – Essential for the proper functioning of our Website and Services. These cookies are typically deleted when you close your browser.

4.4.2. Preference Cookies – Used to remember your settings and preferences (such as language or region), enhancing your browsing experience.

4.4.3. Security Cookies – Used for security purposes, including the detection of authentication abuses and the protection of user sessions.

4.5. We may also use third-party services (such as Google Analytics) that place their own cookies in order to collect aggregated usage data. You will be given the opportunity to manage your cookie preferences upon your first visit to our Website via our cookie consent banner.

4.6. We may use Personal Data as follows:

4.6.1. Providing Our Services: in order to deliver and operate our compensation claim services, including processing flight and identity-related documentation, managing your case, communicating with you, and handling payments or refunds.

4.6.2. Responding to Your Requests: If you provide Personal Data for a specific purpose — for example, contacting us via email or form — We will use it solely to fulfill that purpose, such as responding to your inquiry or resolving an issue.

4.6.3. Internal Business Operations: We may use Personal Data internally to better understand customer needs, improve our Services, enforce our contracts and this Privacy Policy, detect or prevent misconduct, and perform administrative and operational functions (e.g., payroll, supplier management, accounting).

4.6.4. Marketing Purposes: With your explicit consent, We may use your Personal Data to send marketing communications about Services, features, or promotions that We believe may interest you. If by mistake you receive direct marketing without your specific consent or wish to opt-out, please contact us at [email protected].

4.6.5. Statistical Analysis: Personal Data provided to us by you may be used by us for statistical reports containing aggregated information.

4.6.6. Security and Fraud Prevention: Personal Data may be used to protect our systems and Services, including detecting and preventing fraud, cyberattacks, phishing, identity theft, or unauthorized access and data leakage, to confirm the validity of software licenses, to resolve disputes and to enforce our agreements.

FixRefund does not engage in automated decision-making or profiling that produces legal effects concerning individuals or similarly significantly affects them, within the meaning of Article 22(1) of the GDPR.

4.6.7. Data Retention, archives: We retain and archive Personal Data for as long as necessary to operate our business and provide the Services, to meet our contractual obligations and comply with law and regulations – subject to our retention policies and this Privacy Policy.

We apply specific retention periods to different categories of Personal Data, based on the nature of the data and legal requirements:

4.6.7.1. Personal Data related to service claims: retained for up to 7 years from the conclusion of the claim to comply with contractual and legal obligations;

4.6.7.2. Marketing data: retained until consent is withdrawn where consent is considered as legal basis; and/or where the legal basis is legitimate interest – where the legitimate interest is revoked.

4.6.7.3. Website analytics and cookie data: retained in accordance with our Cookie Policy and applicable law.

4.6.8. Transfer, sharing, and disclosure: We may share your Personal Data with our partners, contractors, and service providers who process Personal Data on FixRefund’s behalf to perform certain business-related functions. When doing so, We ensure that they are bound to maintain the confidentiality and security of Personal Data in accordance with this Privacy Policy.

4.6.9. Cloud products: We may need to share Personal Data with our cloud service providers. For example, to assist FixRefund in maintaining and securing the Websites or providing its services, cloud service providers may require access to Personal Data. In such cases, We ensure that our cloud service providers are bound to maintain the confidentiality and security of Personal Data in accordance with this Privacy Policy.

4.6.10. Development and customer service team: We may need to share Personal Data with our development and customer service team. For example, to provide customer service and support or to assist in protecting and securing our systems and services, our development and customer service team may have access to Personal Data. In such cases, We ensure that our development and customer service teams are bound to maintain the confidentiality and security of Personal Data in accordance with this Privacy Policy.

4.6.11. In the event of a corporate sale, merger, reorganization, dissolution, or similar event, Personal Data may be part of the transferred assets. You acknowledge and agree that any successor to or acquirer of FixRefund (or its assets) will continue to have the right to use your Personal Data and other information in accordance with this Privacy Policy.

4.6.12. We may disclose your Personal Data if required to do so by law in order to (for example) respond to a subpoena or request from law enforcement, a court or a government agency (including in response to public authorities to meet national security or law enforcement requirements), or in the good faith belief that such action is necessary to:

4.6.12.1. comply with legal obligations or regulatory requests,

4.6.12.2. defend our rights or property,

4.6.12.3. investigate suspected wrongdoing,

4.6.12.4. protect the safety of users or the public, or

4.6.12.5. protect against legal liability.

4.6.13. Other Purposes: If We intend to use any Personal Data in any manner that is not consistent with this Privacy Policy, you will be informed of such anticipated use prior to or at the time the Personal Data is processed.

4.6.14. Non-Personal Data: Since Non-Personal Data cannot be used to identify you, We may use such data in any way permitted by law.

 

5. Processing Personal Data

We process Personal Data only when We have a legal basis to do so under Article 6 of the General Data Protection Regulation (GDPR). The legal bases We rely on include:

5.1. Performance of a contract: where processing is necessary to provide our Services, including the submission and handling of claims against Airlines.

5.2. Legal obligation: where We are required to comply with legal or regulatory obligations, such as retention for tax or law enforcement purposes.

5.3. Consent: where you have provided clear, informed consent, such as for receiving marketing communications or the use of non-essential cookies.

5.4. Legitimate interests: where the processing is necessary for the purposes of our legitimate interests, such as fraud prevention, service improvement, or IT security, and where such interests are not overridden by your fundamental rights.

 

6. How we store information and transfer it:

6.1. FixRefund takes appropriate technical and organizational measures to safeguard the Personal Data it processes. We store and process Personal Data using secure third-party cloud-based service providers who are contractually bound to maintain confidentiality and security in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR), such as:

6.1.1. Microsoft Office 365 (for Microsoft privacy policy see https://privacy.microsoft.com/en-us/privacystatement).

6.1.2. FixRefund stores data collected by the Websites on Microsoft AZURE cloud services.  For Microsoft Azure Privacy policy and TOU please refer to https://azure.microsoft.com/en-us/support/legal/. FixRefund’s primary database storage located in Europe.

6.1.3. Salesforce cloud services which comply with the GDPR in the delivery of their services, certify compliance with the EU-U.S. Privacy Shield Framework and is ISO 27001, 27017, 27018 certified.

6.2. Personal Data may be processed by third party service providers. We only transfer to such providers the minimum data required to perform their services. The data is transferred only to service providers who approved by us and that allow compliance with the GDPR.

 

7. INTERNATIONAL DATA TRANSFERS.

7.1. Personal Data may be transferred, stored, and processed in countries outside the EU or European Economic Area (EEA) (“Third Countries”). Such transfer to Third Countries may include countries that do not ensure the same level of data protection laws as required by EU privacy laws. In such cases, We implement information security techniques, technical measures, or third parties’ contractual obligations to ensure that such Personal Data is maintained at the same security and confidentiality levels as other Personal Data that FixRefund administers.

7.2. We may transfer Personal Data to Israel. Israel has been recognized by the EU as having an adequate level of protection for Personal Data.

 

8. Security of Personal Data

8.1. We are strongly committed to the protection of your Personal Data, and We take commercially reasonable technical steps, of the sort commonly accepted in our industry, to keep your Personal Data secure and to protect it from loss, misuse, or alteration. However, no network, server, database, Internet, or e-mail transmission is ever fully secure or error free. Therefore, you should take special care in deciding what information you disclose.

If you notice a risk or any security violations, please report to us at [email protected], so that We can attempt to resolve it as soon as possible.

8.2. We recommend that you use, disclose, and share your Personal Data with caution and don’t give out Personal Data unless it is necessary, as We cannot guarantee the security of data over the Internet and cannot control the actions of other users of the Services with whom you choose to share Personal Data.

 

9. YOUR RIGHTS.

9.1. Access, Updates, Corrections, Deletions, Restrictions. Complaints With Supervisory Authority.

9.1.1. You have the right to request access to some of your Personal Data being stored by us; you can also ask to correct, update, or delete any inaccurate Personal Data that We process about you – all are subject to our policies and applicable law and regulations. In order to exercise these rights, please contact us at: [email protected].

9.1.2. We may retain your Personal Data for any period permitted or required under applicable laws. Even if We delete your Personal Data it may persist on backup or archival media for an additional period of time due to technical issues or for legal, tax, or regulatory reasons, or for legitimate and lawful business purposes.

9.1.3. You have the right to restriction of processing if one of the following apply:

9.1.3.1. The accuracy of the Personal Data is contested by you.

9.1.3.2. Unlawful processing has occurred, and you object to deletion of the Personal Data and request the restriction of its use instead.

9.1.3.3. Your service provider no longer needs the Personal Data for the purposes of the original processing, but the data is required by you for the establishment, exercise, or defense of legal claims.

9.1.3.4. You have objected to processing, and the verification of whether the legitimate grounds of your service provider override yours is pending.

If you wish to object to processing, please contact us at [email protected].

If you have the right to lodge a complaint with data protection supervisory authorities, We would appreciate your contacting us first in order to solve the issue for the benefit of all parties. Please contact us by email at [email protected]. Our supervisory authorities are the, Office of the Commissioner for Personal Data Protection of the Republic of Cyprus.

 

10. Data Protection Officer

While FixRefund is not required to appoint a Data Protection Officer under Article 37 of the GDPR, the company has voluntarily appointed a DPO to oversee and manage data protection matters. The DPO is authorized to handle all privacy-related inquiries, concerns, and communications. You may contact our DPO at: [email protected].

 

11. General

11.1. This Privacy Policy applies only to Personal Data that you provide to us.

11.2. This Privacy Policy applies only to the Services and Website. It does not apply to third party’s websites or services, even if they link to our Websites or Services. The existence of a link from a third party’s website or services to our Websites or Services does not imply that We endorse or have reviewed the third-party’s websites or services. We suggest contacting such third parties directly for information on their privacy policies.

11.3. You provide Personal Data to us consensually either on a case by case basis or in a broader contractual context.

11.4. We will use your Personal Data in a manner that is consistent with this Privacy Policy and applicable laws and regulations.

 

12. Changes in terms

12.1. The Services, our business, and the regulatory environment in which they function may change from time to time. As a result, at times it may be necessary for us to make changes to this Privacy Policy. We reserve the right, in our sole discretion, to update or modify this Privacy Policy at any time. Modifications to this Privacy Policy will be posted to the Websites with a change to the “Last updated” date at the top of this Privacy Policy.

12.2. Please review this Privacy Policy periodically, especially before you provide any Personal Data or information. This Privacy Policy was last updated on the date indicated above. Your continued use of the Services following the effectiveness of any modifications to this Privacy Policy constitutes acceptance of those modifications. If any modification to this Privacy Policy is not acceptable to you, your sole remedy is to cease accessing, browsing, and otherwise using the Websites or the Services.

 

13. Dispute Resolution

13.1. If you have a complaint about FixRefund’s privacy practices, please write to us at: [email protected]. We will work with you to attempt to resolve your complaint.

13.2. The laws of the Republic of Cyprus govern this Privacy Policy. The competent courts in the district of Larnaca in Cyprus have exclusive jurisdiction with regard to any dispute that may arise in connection with this Privacy Policy.

13.3. If you believe that FixRefund has not met any of the provisions of this privacy policy, please inform FixRefund as soon as possible by sending an email to: [email protected].

 

Privacy Policy, Ver. 1.0, published on June 8, 2026