Freedom Travel & Aviata.kz

Privacy Statement

Air tickets Privacy Statement

Privacy Statement

Last updated: 03.07.2026
Website: https://freedom-travel.at/
Contact: [email protected]

1. About This Privacy Statement

This Privacy Statement explains how personal data is collected and used when you visit our website, search for flights, create an account, book flight tickets, manage passengers, contact customer service, request after-sales services such as refunds or rebookings, or otherwise use Freedom Travel's online travel booking services in Europe.

This Privacy Statement should be read together with our Cookie Statement, which explains how we use cookies, pixels, tags, and similar technologies on the website.

When we refer to "Freedom Travel," "we," "us," or "our," we mean the joint controllers named below, unless the context clearly indicates that only one of them is meant.

If you provide personal data about another passenger, for example when booking a ticket for a family member, colleague, or other traveler, you should make this Privacy Statement available to that passenger wherever possible.

2. Who Is Responsible for Your Personal Data?

For the processing described in this Privacy Statement, the following entities act as joint controllers:

OTA&A GmbH manages the website https://freedom-travel.at/ and acts as the main point of contact for users in the European Economic Area.

Aviata LLP participates in the operation, development, configuration, security, and maintenance of the online travel booking platform and related systems.

3. Core of the Joint Controllership Arrangement

Freedom Travel and Aviata LLP have entered into a joint controllership arrangement pursuant to Article 26 GDPR.

Under this arrangement:

You may exercise your GDPR rights against either of the joint controllers. For your convenience, you may contact us at: [email protected]

4. Personal Data That We Process

We process various types of personal data, depending on how you use our services.

4.1. Website and Technical Data

Website and Technical Data

When you visit the website, we may process the following data:

4.2. Data on Flight Search Queries

When you search for flights, we process search parameters such as:

In the initial search phase, this information may not directly identify you. However, it may be linked to your account, browser, device, or booking session if you continue with a booking or are logged in.

4.3. Account Data

When you create or use an account, we may process the following data:

4.4. Passenger and Booking Data

When you book a ticket or add passenger information, we may process the following data:

Providing information about passenger identity, travel documents, and contact details is a contractual requirement and, in some cases, is required under airline rules, border control, or aviation security regulations (for example, Advance Passenger Information requirements). If you do not provide this data, we may be unable to complete the booking, issue the ticket, or provide the requested travel service.

4.5. Payment and Transaction Data

When you pay for a booking, we may process the following data:

Full payment card details are normally processed by payment service providers and banks. We do not intend to store full card numbers, unless this is expressly stated during the payment stage and is legally permitted.

4.6. Data on Customer Service and After-Sales Services

When you contact us or request after-sales services, such as refunds, rebookings, name corrections, ticket status checks, cancellations, or adding a child passenger, we may process the following data:

For some transactions, such as refunds and rebookings, it may only be necessary to pass on ticket numbers, booking references, and operational information to the booking system. For other transactions, such as adding a child passenger or a name correction, additional data on passenger identity and documents may be required.

4.7. Marketing, Analytics, and Preference Data

Where applicable, and subject to your consent where required, we may process the following data:

5. Special Categories of Personal Data

We do not intentionally request special categories of personal data, such as health data, biometric data, religious beliefs, or other sensitive information, unless this is necessary for a specific travel-related request or legally required.

In limited cases, special categories of data may become apparent from information you provide, for example, if you request assistance in connection with a health condition or provide information that reveals sensitive data.

When special categories of data are processed, we rely on an appropriate condition under Article 9 GDPR, such as your explicit consent (Article 9(2)(a) GDPR), necessity for the establishment, exercise, or defense of legal claims (Article 9(2)(f) GDPR), or, in exceptional cases where you are physically or legally incapable of giving consent, the protection of vital interests (Article 9(2)(c) GDPR).

6. Sources of Personal Data

We may receive personal data from:

7. Why We Process Personal Data and the Legal Bases

We process personal data only when we have a legal basis to do so under the GDPR. The table below sets out the main purposes for which we process personal data and the primary legal basis for each purpose.

Where we rely on legitimate interests, we do so only for the specific purposes listed below, and only where we have assessed that our interests do not override your interests, rights, and freedoms. We keep documented Legitimate Interests Assessments as evidence of compliance.

PurposeExamplesPrimary Legal Basis
Providing access to the websiteWebsite access, page loading, basic website functioning, session managementLegitimate interests, Article 6(1)(f) GDPR: operating and making the website available
Creating and managing your accountAccount registration, login, account settings, language preferences, account managementPerformance of a contract or steps prior to entering into a contract, Article 6(1)(b) GDPR
Managing passenger profiles stored in your accountStoring, updating, or deleting passenger profiles and travel document data at your requestPerformance of a contract, Article 6(1)(b) GDPR
Securing accounts and preventing unauthorized accessAuthentication, access control, login security, account security logsLegitimate interests, Article 6(1)(f) GDPR: protecting accounts, users, and the platform
Providing flight search functionalityRoute, travel dates, number of passengers, passenger type, and selected flight optionsPerformance of a contract or steps prior to entering into a contract, Article 6(1)(b) GDPR
Creating and issuing bookings for the clientCollection of passenger data, creation of bookings, issuance of tickets, management of travel itinerariesPerformance of a contract, Article 6(1)(b) GDPR
Processing passenger data when the booking is made by another personPassenger identity data, travel documents, and travel itinerary entered by the client for another travelerLegitimate interests, Article 6(1)(f) GDPR: arranging the travel requested by the client for the passenger
Managing travel documents required for the booking or tripPassport data, identity data, nationality, document expiry date, visa information where required for the selected tripPerformance of a contract, Article 6(1)(b) GDPR
Complying with travel, aviation, border control, or regulatory requirementsData required by airlines, travel providers, competent authorities, or applicable travel rulesLegal obligation, Article 6(1)(c) GDPR, where such processing is legally required
Processing payments for bookingsPayment confirmation, payment status, transaction reference, limited information about the payment methodPerformance of a contract, Article 6(1)(b) GDPR
Retaining payment, invoice, tax, and accounting dataTransaction data, invoices, accounting records, tax documentationLegal obligation, Article 6(1)(c) GDPR
Preventing payment fraud and abuseFraud checks, payment verification data, chargeback indicators, abuse signalsLegitimate interests, Article 6(1)(f) GDPR: protecting users, transactions, and the platform against fraud
Providing customer service for bookingsBooking-related inquiries, issue resolution, correspondence, customer service notesPerformance of a contract, Article 6(1)(b) GDPR
Answering general inquiriesNon-booking-related inquiries, general correspondence, service questionsLegitimate interests, Article 6(1)(f) GDPR: responding to inquiries and managing customer communications
Handling refunds, rebookings, and cancellationsRefund requests, ticket rebookings, cancellations, ticket status checksPerformance of a contract, Article 6(1)(b) GDPR
Handling after-sales changes requested by the clientName corrections, adding child passengers, updating passenger data, after-sales service provisionPerformance of a contract, Article 6(1)(b) GDPR
Sending service communicationsBooking confirmations, ticket updates, refund updates, information about schedule changes, security notificationsPerformance of a contract, Article 6(1)(b) GDPR
Protecting the platform and preventing fraudBot protection, abuse prevention, security monitoring, technical logs, incident investigationLegitimate interests, Article 6(1)(f) GDPR: ensuring platform security, preventing fraud, and protecting users
Complying with legal and regulatory obligationsData relating to tax, accounting, regulatory matters, aviation, consumer protection, payments, and legal complianceLegal obligation, Article 6(1)(c) GDPR
Using strictly necessary cookies and similar technologiesCookies required for login, security, session management, the booking process, and storing cookie preferencesPerformance of a contract, Article 6(1)(b) GDPR, where necessary to provide the requested service; or legitimate interests, Article 6(1)(f) GDPR, where necessary to operate and secure the website
Using non-essential analytics, performance, functional, or advertising cookiesPerformance analysis, campaign measurement, personalization cookies, advertising pixels, retargeting technologiesConsent, Article 6(1)(a) GDPR
Sending marketing communicationsNewsletters, promotional offers, travel offers, and campaign communicationsConsent, Article 6(1)(a) GDPR, unless applicable law permits communication without consent
Measuring and personalizing marketing campaignsCampaign identifiers, advertising identifiers, retargeting, email interaction data, marketing analyticsConsent, Article 6(1)(a) GDPR, where required by applicable law
Improving the platform without using non-essential cookiesDebugging, error analysis, service optimization, performance improvement, non-intrusive technical analysisLegitimate interests, Article 6(1)(f) GDPR: improving the reliability, usability, and performance of the service
Handling complaints and disputesComplaints, chargebacks, dispute correspondence, internal investigation dataLegitimate interests, Article 6(1)(f) GDPR: handling disputes and protecting our rights and interests
Establishing, exercising, or defending legal claimsLitigation files, legal correspondence, evidence, communications with lawyers, courts, or insurersLegitimate interests, Article 6(1)(f) GDPR: establishing, exercising, or defending legal claims
Responding to lawful requests from authoritiesRequests from supervisory authorities, court orders, requests from law enforcement authorities, legally binding communications from authoritiesLegal obligation, Article 6(1)(c) GDPR, where the request is legally binding

Where processing is based on consent, you may withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Where processing is based on legitimate interests, you have the right to object at any time to that processing on grounds relating to your particular situation. You also have the right to object at any time to the processing of your personal data for direct marketing purposes.

8. How Booking Data Flows Through the Platform

When you search for flights, the initial search step may relate only to route, dates, and number of passengers.

When you proceed to checkout, passenger data, documents, and contact details enter the booking process. This data is used to create a booking, issue tickets, save the order, create or update your account, and support customer service.

Operationally, data may be processed through systems used for:

Some systems only pass data through during the request and do not store it. Other systems store information about orders, accounts, passengers, documents, customer service, or consent.

9. Recipients of Personal Data

We may share personal data with the following categories of recipients.

9.1. Travel and Booking Providers

We share booking and passenger data with Amadeus, airlines, global distribution systems, ticket providers, and other travel-related providers, to the extent necessary to search for, book, issue, manage, refund, rebook, or cancel tickets.

During the creation of a booking, Amadeus may receive passenger identity data, document data, visa data where applicable, contact details, and loyalty card information. During after-sales services, Amadeus may receive ticket numbers, booking references, passenger type, and, to the extent necessary for a specific service, additional passenger data.

Amadeus, airlines, and other travel providers may process personal data as independent controllers, processors, or providers with a mixed role, depending on the relevant service, agreement, and legal requirements.

9.2. Payment Service Providers

We share payment and transaction data with payment service providers, acquiring banks, card schemes, fraud prevention providers, and other financial institutions, to the extent necessary to handle payments, refunds, fraud checks, chargebacks, and legal or regulatory obligations.

These providers generally process personal data as independent controllers for regulated purposes relating to payments, fraud prevention, and compliance.

9.3. Hosting and Infrastructure Providers

Our platform is hosted within the European Economic Area, including on the infrastructure of Amazon Web Services in the Netherlands.

Amazon Web Services acts as a service provider for hosting and infrastructure services. Where support, management, sub-processing, or access by the provider involves personal data being accessed from outside the EEA, we apply appropriate GDPR safeguards where required.

9.4. Cookie and Consent Management Providers

We use a consent management platform, including CookieYes, to record and manage cookie choices.

More information about cookies and similar technologies is available in our Cookie Statement.

9.5. Partners for Analytics, Functionality, and Advertising

Subject to your consent where required, we may use partners for analytics, functionality, and advertising. These may be providers affiliated with Cloudflare, Google, Meta, TikTok, Bloomreach, and other technology partners.

Depending on the service, these providers may act as processors, independent controllers, or joint controllers. Where a provider determines its own purposes and means of processing, its own privacy documentation may also apply.

9.6. Professional Advisors, Authorities, and Legal Recipients

We may share personal data with:

10. International Transfers

Our website is hosted within the European Economic Area, including on the infrastructure of Amazon Web Services in the Netherlands.

Some personal data may be accessed from, or transferred to, countries outside the European Economic Area where this is necessary for the operation, support, security, and maintenance of the platform, or for travel bookings, ticketing, aviation operations, payment processing, customer service, analytics, advertising, or legal compliance.

Where personal data is transferred outside the European Economic Area and no adequacy decision applies, we use appropriate GDPR safeguards, such as the European Commission's Standard Contractual Clauses, transfer impact assessments, and additional technical and organizational measures where required. In particular, because our joint controller Aviata LLP is established in Kazakhstan, personal data processed on the platform may be accessed from, and transferred to, Kazakhstan, a country not covered by an adequacy decision of the European Commission. These transfers take place on the basis of the Standard Contractual Clauses concluded between the joint controllers, supported by a transfer impact assessment and additional technical and organizational measures.

You may contact us at [email protected] for more information about the safeguards used for international transfers. Upon request, we will provide you with a copy of the relevant safeguards or information about where they have been made available.

11. How Long We Retain Personal Data

We retain personal data only for as long as necessary for the purposes described in this Privacy Statement, unless a longer period is required or permitted by law.

Our retention approach is based on the following criteria:

Data CategoryTypical Retention Approach
Account DataRetained for as long as your account is active and for a reasonable period after closure or inactivity, unless longer retention is required for bookings, legal obligations, or claims
Passenger Profiles Stored in the AccountRetained until you delete the passenger profile or close the account, unless the data is linked to a booking, legal obligation, or claim
Booking, Order, Invoice, and Transaction DataRetained for the period required under tax, accounting, travel, aviation, and legal obligations, typically up to 7 years where Austrian accounting/tax retention rules apply, and longer if required for ongoing proceedings or claims
Customer Service and After-Sales RequestsRetained for as long as necessary to handle the request and for a reasonable period thereafter for purposes of evidence, quality, legal claims, and compliance
Data on Refunds, Rebookings, and CancellationsRetained for as long as necessary to complete the service and to comply with tax, accounting, payment, and legal obligations
Consent and Privacy DataRetained for as long as necessary to demonstrate compliance and to manage your preferences
Marketing PreferencesRetained until you withdraw your consent or object, whereby suppression data is retained to respect your choice
Cookie DataRetained in accordance with the duration described in the Cookie Statement and your consent settings
Security LogsRetained for a limited period based on security needs, unless required for investigating incidents, fraud, abuse, or legal claims

When data is no longer needed, we delete it, anonymize it, or restrict access to it.

12. Marketing Communications

We may send you marketing communications where we have your consent or where this is otherwise permitted by applicable law.

You may withdraw your consent or unsubscribe at any time by using the unsubscribe link in the message or by contacting us at: [email protected]. Withdrawal of marketing consent does not affect service communications, such as booking confirmations, ticket updates, payment information, refund information, or security notifications.

13. Profiling and Automated Decision-Making

We may use limited profiling for analytics, advertising, personalization, fraud prevention, security, service improvement, and campaign measurement.

We do not currently make decisions based solely on automated processing (except with payment and fraud prevention providers, where transactions may be automatically declined without human review) that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. Where profiling for advertising or analytics relies on cookies or similar technologies, we ask for consent where required.

14. Beveiligingsmaatregelen

We use technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

These measures may be implemented directly by the joint controllers or through our technology, hosting, security, and infrastructure service providers.

Our measures include, where applicable:

No system is completely secure. If we become aware of a personal data breach, we assess it and notify the competent supervisory authority and the affected individuals where this is legally required.

15. Your Rights Under the GDPR

Subject to the conditions and limitations set out in the GDPR, you have the following rights:

To exercise your rights, you may contact us at: [email protected]

We may need to verify your identity before responding. We will respond without undue delay and in any event within one month of receipt of your request. Where your request is complex or we have received a large number of requests, we may extend this period by up to two further months; in that case, we will inform you of the extension and the reasons for it within one month of receipt of your request.

16. Complaints

We recommend that you first contact us at: [email protected]

You also have the right to lodge a complaint with a supervisory authority.

For Austria, the supervisory authority is:

Austrian Data Protection Authority

Österreichische Datenschutzbehörde

Barichgasse 40-42

1030 Vienna

Austria

Email: [email protected]

Phone: +43 1 52 152-0

You may also contact the supervisory authority in the EU member state where you reside, work, or where you believe an infringement has taken place.

17. Links to Third-Party Websites and Services

Our website may contain links to third-party websites, airline services, payment services, or other external platforms. This Privacy Statement does not apply to third-party websites or services that are not managed by us. Their own privacy statements and terms and conditions apply.

18. Changes to This Privacy Statement

We may update this Privacy Statement from time to time to reflect changes to our services, systems, legal requirements, providers, data flows, or business activities. Where changes are significant, we will take appropriate steps to inform you, for example by publishing a notice on the website or, where required, by requesting renewed consent.

If you have any questions about this Privacy Statement or about how we process personal data, you may contact:

[email protected]