Privacy policy
Information on the processing of personal data under the GDPR and Austrian data protection law. Draft version — the final text must be reviewed by a lawyer before going live.
Only the German version of this page is legally binding. This translation is provided for convenience.
1. Controller
The controller within the meaning of the GDPR is the company named in the legal notice. Contact details for data protection requests: see legal notice or the email address listed on this page.
2. Data we collect
Booking form: name, email address, phone number, flight type, preferred date, body weight (required for flight safety), payment data (processed exclusively by the payment provider).
Contact form: name, email address, optional phone number, message.
Voucher orders: name and email of the purchaser and optionally of the recipient.
Server logs: IP address, time of access, page requested, browser type — technically necessary for operation and abuse prevention.
Cookies and statistics: strictly necessary cookies (language preference, consent status) and — only with explicit consent — anonymised audience measurement.
3. Purpose and legal basis
Performance of a contract (Art. 6(1)(b) GDPR): handling bookings, vouchers and payments.
Legitimate interest (Art. 6(1)(f) GDPR): secure and stable operation of the website, answering enquiries.
Consent (Art. 6(1)(a) GDPR): statistics cookies and newsletter, revocable at any time.
Legal obligation (Art. 6(1)(c) GDPR): tax and commercial retention duties.
4. Retention periods
Contact enquiries: until the matter is settled, no longer than 24 months.
Booking and invoice data: 7 years pursuant to § 132 BAO (Austrian Federal Fiscal Code).
Voucher data: until expiry of validity (3 years) plus statutory retention periods.
Cookie consent: 12 months, after which you are asked again.
5. Processors we use
Supabase — database hosting and storage of form data (EU servers).
Stripe Payments Europe Ltd. — online payment processing. We never receive full card details.
Resend — sending of transactional emails (booking confirmation, voucher, replies to enquiries).
Regiondo GmbH — booking handling, where this channel is actively used.
MapTiler / OpenFreeMap — map delivery. Loading the map transmits your IP address to the map provider.
Open-Meteo — live weather data; no personal data is transmitted.
PLACEHOLDER: this list must be reconciled with the services actually used before going live; a data processing agreement is required for each.
6. Disclosure to third parties
Personal data is disclosed only to the processors listed above and to authorities where legally required. Data is never sold.
7. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection. Consent given may be withdrawn at any time with effect for the future.
Supervisory authority: Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at.
8. Cookie settings
Your cookie choice is stored locally in your browser and requested again after 12 months. You can change it at any time via the “Cookie settings” link in the page footer.
9. Data security
The website is delivered exclusively over an encrypted connection (TLS/HTTPS). Access to stored form data is restricted to authorised persons.
Last updated: 2026-09-04
