Last updated: 03.07.2026
Website: https://freedom-travel.at/
Contact: [email protected]
This Privacy Statement explains how personal data is collected and used when you visit our website, search for flights, create an account, book flight tickets, manage passengers, contact customer service, request after-sales services such as refunds or rebookings, or otherwise use Freedom Travel's online travel booking services in Europe.
This Privacy Statement should be read together with our Cookie Statement, which explains how we use cookies, pixels, tags, and similar technologies on the website.
When we refer to "Freedom Travel," "we," "us," or "our," we mean the joint controllers named below, unless the context clearly indicates that only one of them is meant.
If you provide personal data about another passenger, for example when booking a ticket for a family member, colleague, or other traveler, you should make this Privacy Statement available to that passenger wherever possible.
For the processing described in this Privacy Statement, the following entities act as joint controllers:
OTA&A GmbH manages the website https://freedom-travel.at/ and acts as the main point of contact for users in the European Economic Area.
Aviata LLP participates in the operation, development, configuration, security, and maintenance of the online travel booking platform and related systems.
Freedom Travel and Aviata LLP have entered into a joint controllership arrangement pursuant to Article 26 GDPR.
Under this arrangement:
You may exercise your GDPR rights against either of the joint controllers. For your convenience, you may contact us at: [email protected]
We process various types of personal data, depending on how you use our services.
Website and Technical Data
When you visit the website, we may process the following data:
When you search for flights, we process search parameters such as:
In the initial search phase, this information may not directly identify you. However, it may be linked to your account, browser, device, or booking session if you continue with a booking or are logged in.
When you create or use an account, we may process the following data:
When you book a ticket or add passenger information, we may process the following data:
Providing information about passenger identity, travel documents, and contact details is a contractual requirement and, in some cases, is required under airline rules, border control, or aviation security regulations (for example, Advance Passenger Information requirements). If you do not provide this data, we may be unable to complete the booking, issue the ticket, or provide the requested travel service.
When you pay for a booking, we may process the following data:
Full payment card details are normally processed by payment service providers and banks. We do not intend to store full card numbers, unless this is expressly stated during the payment stage and is legally permitted.
When you contact us or request after-sales services, such as refunds, rebookings, name corrections, ticket status checks, cancellations, or adding a child passenger, we may process the following data:
For some transactions, such as refunds and rebookings, it may only be necessary to pass on ticket numbers, booking references, and operational information to the booking system. For other transactions, such as adding a child passenger or a name correction, additional data on passenger identity and documents may be required.
Where applicable, and subject to your consent where required, we may process the following data:
We do not intentionally request special categories of personal data, such as health data, biometric data, religious beliefs, or other sensitive information, unless this is necessary for a specific travel-related request or legally required.
In limited cases, special categories of data may become apparent from information you provide, for example, if you request assistance in connection with a health condition or provide information that reveals sensitive data.
When special categories of data are processed, we rely on an appropriate condition under Article 9 GDPR, such as your explicit consent (Article 9(2)(a) GDPR), necessity for the establishment, exercise, or defense of legal claims (Article 9(2)(f) GDPR), or, in exceptional cases where you are physically or legally incapable of giving consent, the protection of vital interests (Article 9(2)(c) GDPR).
We may receive personal data from:
We process personal data only when we have a legal basis to do so under the GDPR. The table below sets out the main purposes for which we process personal data and the primary legal basis for each purpose.
Where we rely on legitimate interests, we do so only for the specific purposes listed below, and only where we have assessed that our interests do not override your interests, rights, and freedoms. We keep documented Legitimate Interests Assessments as evidence of compliance.
| Purpose | Examples | Primary Legal Basis |
|---|---|---|
| Providing access to the website | Website access, page loading, basic website functioning, session management | Legitimate interests, Article 6(1)(f) GDPR: operating and making the website available |
| Creating and managing your account | Account registration, login, account settings, language preferences, account management | Performance of a contract or steps prior to entering into a contract, Article 6(1)(b) GDPR |
| Managing passenger profiles stored in your account | Storing, updating, or deleting passenger profiles and travel document data at your request | Performance of a contract, Article 6(1)(b) GDPR |
| Securing accounts and preventing unauthorized access | Authentication, access control, login security, account security logs | Legitimate interests, Article 6(1)(f) GDPR: protecting accounts, users, and the platform |
| Providing flight search functionality | Route, travel dates, number of passengers, passenger type, and selected flight options | Performance of a contract or steps prior to entering into a contract, Article 6(1)(b) GDPR |
| Creating and issuing bookings for the client | Collection of passenger data, creation of bookings, issuance of tickets, management of travel itineraries | Performance of a contract, Article 6(1)(b) GDPR |
| Processing passenger data when the booking is made by another person | Passenger identity data, travel documents, and travel itinerary entered by the client for another traveler | Legitimate interests, Article 6(1)(f) GDPR: arranging the travel requested by the client for the passenger |
| Managing travel documents required for the booking or trip | Passport data, identity data, nationality, document expiry date, visa information where required for the selected trip | Performance of a contract, Article 6(1)(b) GDPR |
| Complying with travel, aviation, border control, or regulatory requirements | Data required by airlines, travel providers, competent authorities, or applicable travel rules | Legal obligation, Article 6(1)(c) GDPR, where such processing is legally required |
| Processing payments for bookings | Payment confirmation, payment status, transaction reference, limited information about the payment method | Performance of a contract, Article 6(1)(b) GDPR |
| Retaining payment, invoice, tax, and accounting data | Transaction data, invoices, accounting records, tax documentation | Legal obligation, Article 6(1)(c) GDPR |
| Preventing payment fraud and abuse | Fraud checks, payment verification data, chargeback indicators, abuse signals | Legitimate interests, Article 6(1)(f) GDPR: protecting users, transactions, and the platform against fraud |
| Providing customer service for bookings | Booking-related inquiries, issue resolution, correspondence, customer service notes | Performance of a contract, Article 6(1)(b) GDPR |
| Answering general inquiries | Non-booking-related inquiries, general correspondence, service questions | Legitimate interests, Article 6(1)(f) GDPR: responding to inquiries and managing customer communications |
| Handling refunds, rebookings, and cancellations | Refund requests, ticket rebookings, cancellations, ticket status checks | Performance of a contract, Article 6(1)(b) GDPR |
| Handling after-sales changes requested by the client | Name corrections, adding child passengers, updating passenger data, after-sales service provision | Performance of a contract, Article 6(1)(b) GDPR |
| Sending service communications | Booking confirmations, ticket updates, refund updates, information about schedule changes, security notifications | Performance of a contract, Article 6(1)(b) GDPR |
| Protecting the platform and preventing fraud | Bot protection, abuse prevention, security monitoring, technical logs, incident investigation | Legitimate interests, Article 6(1)(f) GDPR: ensuring platform security, preventing fraud, and protecting users |
| Complying with legal and regulatory obligations | Data relating to tax, accounting, regulatory matters, aviation, consumer protection, payments, and legal compliance | Legal obligation, Article 6(1)(c) GDPR |
| Using strictly necessary cookies and similar technologies | Cookies required for login, security, session management, the booking process, and storing cookie preferences | Performance of a contract, Article 6(1)(b) GDPR, where necessary to provide the requested service; or legitimate interests, Article 6(1)(f) GDPR, where necessary to operate and secure the website |
| Using non-essential analytics, performance, functional, or advertising cookies | Performance analysis, campaign measurement, personalization cookies, advertising pixels, retargeting technologies | Consent, Article 6(1)(a) GDPR |
| Sending marketing communications | Newsletters, promotional offers, travel offers, and campaign communications | Consent, Article 6(1)(a) GDPR, unless applicable law permits communication without consent |
| Measuring and personalizing marketing campaigns | Campaign identifiers, advertising identifiers, retargeting, email interaction data, marketing analytics | Consent, Article 6(1)(a) GDPR, where required by applicable law |
| Improving the platform without using non-essential cookies | Debugging, error analysis, service optimization, performance improvement, non-intrusive technical analysis | Legitimate interests, Article 6(1)(f) GDPR: improving the reliability, usability, and performance of the service |
| Handling complaints and disputes | Complaints, chargebacks, dispute correspondence, internal investigation data | Legitimate interests, Article 6(1)(f) GDPR: handling disputes and protecting our rights and interests |
| Establishing, exercising, or defending legal claims | Litigation files, legal correspondence, evidence, communications with lawyers, courts, or insurers | Legitimate interests, Article 6(1)(f) GDPR: establishing, exercising, or defending legal claims |
| Responding to lawful requests from authorities | Requests from supervisory authorities, court orders, requests from law enforcement authorities, legally binding communications from authorities | Legal obligation, Article 6(1)(c) GDPR, where the request is legally binding |
Where processing is based on consent, you may withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Where processing is based on legitimate interests, you have the right to object at any time to that processing on grounds relating to your particular situation. You also have the right to object at any time to the processing of your personal data for direct marketing purposes.
When you search for flights, the initial search step may relate only to route, dates, and number of passengers.
When you proceed to checkout, passenger data, documents, and contact details enter the booking process. This data is used to create a booking, issue tickets, save the order, create or update your account, and support customer service.
Operationally, data may be processed through systems used for:
Some systems only pass data through during the request and do not store it. Other systems store information about orders, accounts, passengers, documents, customer service, or consent.
We may share personal data with the following categories of recipients.
We share booking and passenger data with Amadeus, airlines, global distribution systems, ticket providers, and other travel-related providers, to the extent necessary to search for, book, issue, manage, refund, rebook, or cancel tickets.
During the creation of a booking, Amadeus may receive passenger identity data, document data, visa data where applicable, contact details, and loyalty card information. During after-sales services, Amadeus may receive ticket numbers, booking references, passenger type, and, to the extent necessary for a specific service, additional passenger data.
Amadeus, airlines, and other travel providers may process personal data as independent controllers, processors, or providers with a mixed role, depending on the relevant service, agreement, and legal requirements.
We share payment and transaction data with payment service providers, acquiring banks, card schemes, fraud prevention providers, and other financial institutions, to the extent necessary to handle payments, refunds, fraud checks, chargebacks, and legal or regulatory obligations.
These providers generally process personal data as independent controllers for regulated purposes relating to payments, fraud prevention, and compliance.
Our platform is hosted within the European Economic Area, including on the infrastructure of Amazon Web Services in the Netherlands.
Amazon Web Services acts as a service provider for hosting and infrastructure services. Where support, management, sub-processing, or access by the provider involves personal data being accessed from outside the EEA, we apply appropriate GDPR safeguards where required.
We use a consent management platform, including CookieYes, to record and manage cookie choices.
More information about cookies and similar technologies is available in our Cookie Statement.
Subject to your consent where required, we may use partners for analytics, functionality, and advertising. These may be providers affiliated with Cloudflare, Google, Meta, TikTok, Bloomreach, and other technology partners.
Depending on the service, these providers may act as processors, independent controllers, or joint controllers. Where a provider determines its own purposes and means of processing, its own privacy documentation may also apply.
We may share personal data with:
Our website is hosted within the European Economic Area, including on the infrastructure of Amazon Web Services in the Netherlands.
Some personal data may be accessed from, or transferred to, countries outside the European Economic Area where this is necessary for the operation, support, security, and maintenance of the platform, or for travel bookings, ticketing, aviation operations, payment processing, customer service, analytics, advertising, or legal compliance.
Where personal data is transferred outside the European Economic Area and no adequacy decision applies, we use appropriate GDPR safeguards, such as the European Commission's Standard Contractual Clauses, transfer impact assessments, and additional technical and organizational measures where required. In particular, because our joint controller Aviata LLP is established in Kazakhstan, personal data processed on the platform may be accessed from, and transferred to, Kazakhstan, a country not covered by an adequacy decision of the European Commission. These transfers take place on the basis of the Standard Contractual Clauses concluded between the joint controllers, supported by a transfer impact assessment and additional technical and organizational measures.
You may contact us at [email protected] for more information about the safeguards used for international transfers. Upon request, we will provide you with a copy of the relevant safeguards or information about where they have been made available.
We retain personal data only for as long as necessary for the purposes described in this Privacy Statement, unless a longer period is required or permitted by law.
Our retention approach is based on the following criteria:
| Data Category | Typical Retention Approach |
|---|---|
| Account Data | Retained for as long as your account is active and for a reasonable period after closure or inactivity, unless longer retention is required for bookings, legal obligations, or claims |
| Passenger Profiles Stored in the Account | Retained until you delete the passenger profile or close the account, unless the data is linked to a booking, legal obligation, or claim |
| Booking, Order, Invoice, and Transaction Data | Retained for the period required under tax, accounting, travel, aviation, and legal obligations, typically up to 7 years where Austrian accounting/tax retention rules apply, and longer if required for ongoing proceedings or claims |
| Customer Service and After-Sales Requests | Retained for as long as necessary to handle the request and for a reasonable period thereafter for purposes of evidence, quality, legal claims, and compliance |
| Data on Refunds, Rebookings, and Cancellations | Retained for as long as necessary to complete the service and to comply with tax, accounting, payment, and legal obligations |
| Consent and Privacy Data | Retained for as long as necessary to demonstrate compliance and to manage your preferences |
| Marketing Preferences | Retained until you withdraw your consent or object, whereby suppression data is retained to respect your choice |
| Cookie Data | Retained in accordance with the duration described in the Cookie Statement and your consent settings |
| Security Logs | Retained for a limited period based on security needs, unless required for investigating incidents, fraud, abuse, or legal claims |
When data is no longer needed, we delete it, anonymize it, or restrict access to it.
We may send you marketing communications where we have your consent or where this is otherwise permitted by applicable law.
You may withdraw your consent or unsubscribe at any time by using the unsubscribe link in the message or by contacting us at: [email protected]. Withdrawal of marketing consent does not affect service communications, such as booking confirmations, ticket updates, payment information, refund information, or security notifications.
We may use limited profiling for analytics, advertising, personalization, fraud prevention, security, service improvement, and campaign measurement.
We do not currently make decisions based solely on automated processing (except with payment and fraud prevention providers, where transactions may be automatically declined without human review) that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. Where profiling for advertising or analytics relies on cookies or similar technologies, we ask for consent where required.
We use technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
These measures may be implemented directly by the joint controllers or through our technology, hosting, security, and infrastructure service providers.
Our measures include, where applicable:
No system is completely secure. If we become aware of a personal data breach, we assess it and notify the competent supervisory authority and the affected individuals where this is legally required.
Subject to the conditions and limitations set out in the GDPR, you have the following rights:
To exercise your rights, you may contact us at: [email protected]
We may need to verify your identity before responding. We will respond without undue delay and in any event within one month of receipt of your request. Where your request is complex or we have received a large number of requests, we may extend this period by up to two further months; in that case, we will inform you of the extension and the reasons for it within one month of receipt of your request.
We recommend that you first contact us at: [email protected]
You also have the right to lodge a complaint with a supervisory authority.
For Austria, the supervisory authority is:
Austrian Data Protection Authority
Österreichische Datenschutzbehörde
Barichgasse 40-42
1030 Vienna
Austria
Email: [email protected]
Phone: +43 1 52 152-0
You may also contact the supervisory authority in the EU member state where you reside, work, or where you believe an infringement has taken place.
Our website may contain links to third-party websites, airline services, payment services, or other external platforms. This Privacy Statement does not apply to third-party websites or services that are not managed by us. Their own privacy statements and terms and conditions apply.
We may update this Privacy Statement from time to time to reflect changes to our services, systems, legal requirements, providers, data flows, or business activities. Where changes are significant, we will take appropriate steps to inform you, for example by publishing a notice on the website or, where required, by requesting renewed consent.
If you have any questions about this Privacy Statement or about how we process personal data, you may contact: