Privacy Policy
Your personal data
Airshoppen Travel Retail A/S, company registration number (CVR) 41391421 (“Airshoppen”, “we”, “our”), respects the privacy of our customers and visitors to our website. The purpose of this policy is to describe clearly and transparently how we collect, display, transfer, and store your information, so you can feel confident that your personal data is stored securely. Airshoppen processes all personal data in accordance with the EU General Data Protection Regulation (GDPR).
When you provide us with personal data, or when we collect personal data from you, the data will be processed in accordance with this Privacy Policy.
It is important to us that you feel secure and that we meet both our customers’ expectations and our own high standards of integrity and data security. If you have any comments regarding our data processing, IT security, or other matters relating to the GDPR or the handling of personal data, we would be very pleased to hear from you using the contact details below. We are always open to improvement and therefore greatly appreciate feedback from our customers, employees, and other stakeholders.
Data controller
This privacy policy applies to services and products offered by ATR, which is also the data controller for the personal data covered by this policy. Personal data collected by Airshoppen is processed for the purposes set out below.
ATR is part of Nordic Leisure Travel Group (NLTG), along with Spies, Ving, Tjäreborg and Sunclass Airlines, among others. NLTG has a controlling interest in ATR, and ATR therefore shares personal data with NLTG for administrative and analytical purposes if you travel with Sunclass Airlines. If you travel with other package tour operators or airlines, your personal data will not be shared with NLTG.
Contact information
If you wish to contact us regarding this privacy policy or have any other questions about how we process your personal data, please contact us at dpo@airshoppen.com. You can also contact Nordic Leisure Travel – the Group's Data Protection Officer – via this form or by post at NLTG, Data Protection Officer, Rålambsvägen 17, 105 20 Stockholm, Sweden. Read more about your rights under the GDPR in section 8 below.
Collection of personal data
What is personal data?
Personal data is any type of information that can be directly or indirectly linked to a living individual. This includes, for example, names, personal identification numbers, addresses, email addresses, and telephone numbers. It also includes, for example, ticket numbers, encrypted data, and various types of electronic identifiers, such as IP addresses, if they can be linked to individuals.
How we collect personal data, the purposes of processing, and what information we collect
ATR collects personal data in several ways, but primarily directly from you.
When you order goods or services on our website, we collect personal data from you in order to process your order. This includes information such as your name and address, contact details, and payment information. We also collect information about your trip. In addition to the information mentioned above, this may include, for example, your ticket number, destination, the duration of your trip, and any other services you have chosen to use during your trip.
We are aware that certain types of personal data are particularly sensitive, such as information about ethnic origin, religion, and health. We never collect such sensitive personal data.
We collect personal data from you when you contact us, for example by email, phone, or in other ways. Primarily, we collect the personal data that is necessary to answer your question or process your case. Depending on how you choose to contact us, we may also collect contact details such as your email address or phone number.
When you call our customer service team, we record your call and retain the recording for 200 days. We do this so that we can document what was said during the call. We also use the recordings for internal training and development. We therefore collect and retain all personal data disclosed during the call. You have the right to request that your call not be recorded. You also have the right to request that a recording be deleted.
If you do not want the call to be recorded, you can inform the customer service representative when your call is answered. The representative will then call you back without recording the conversation. Alternatively, you can email us at airshoppen@airshoppen.dk and request a callback without the conversation being recorded.
When you use one of our websites or other digital services from us, we collect information about your use of the service through the use of cookies (see more information in our cookie policy). Some of this information may be personal data, such as your IP address or ticket number. If you have consented to cookies for statistical and/or marketing purposes, we also collect information about how you navigate the service, which pages you visit, which searches you perform, and which products you are interested in. If you provide us with data that enables us to identify you, we will link data about your usage patterns with other information we have collected about you.
We may also receive your personal data from our partners who collect information about you. These include:
- If you inform a third party that you wish to receive marketing communications from Airshoppen, the third party will securely transfer your contact details, marketing preferences, and consent to us.
- questionnaires or a survey about customer feedback.
Handling and storage of personal data
Fulfilment of an agreement
Airshoppen processes your personal data in accordance with the law. Primarily, we process your data in order to fulfil an agreement to which you are a party and to manage your order, or on the basis of a legitimate interest, such as for marketing purposes. Administration also includes the use of your data for bookkeeping, settlement, auditing, credit or other verification of payment cards. It may occur that the same personal data is processed both in connection with the performance of the agreement or specifically on the basis of consent, and because the data is necessary to fulfil other legal obligations.
In order to provide some of the services you have requested from us, we use suppliers and contractual partners. It may be necessary for us to disclose personal data to them so that the service can be carried out.
In some cases, we share the information with our partners so they can help tailor our offers and marketing to you. We enter into a data processing agreement to ensure that such partners process the information in accordance with the applicable data protection legislation.
We will store personal data for as long as necessary for the purposes mentioned. We have internal deletion procedures, and if you would like to know more about when different types of data are deleted, please send an email to dpo@airshoppen.com or use this form
Customer service and complaints
We use your personal data to provide you with service if you contact us with questions, comments or complaints. We use your name and ticket number to identify you. We may also use any other personal data we have collected about you in order to handle your question or enquiry, depending on what is relevant in each individual case. We have a joint Nordic customer service function within NLTG, and all personal data processed in our customer service system may be shared between the companies in the group to ensure fast and efficient customer service and correct handling of enquiries. If you fly with airlines other than Sunclass Airlines, your data is not shared with NLTG.
Marketing and personalization
The customer information may be used by Airshoppen for marketing purposes in connection with your trip, and we communicate via letter, email, text message, and other online digital marketing channels, such as advertisements on social media.
If you have chosen to receive emails with inspiration and offers from us, we use your personal data to send the email to you and to tailor the content of the email specifically to you. This includes your email address, your travel information, your basic data, information about your possible purchase history, your usage patterns and your preferences. Using this data, we can provide you with the offers that we believe you are most interested in and will benefit the most from.
On our websites, we use information about our users for what is known as personalization. This means that we use the information we have collected about you and your use of our services to influence how the content on the website appears when you visit it. The customization may, for example, consist of us saving and displaying information about things you searched for during a previous visit to our website, language settings, as well as the display of advertisements and offers that we believe match you and your preferences.
We also share information with partners to help us tailor personalized offers and marketing across both our own and external channels, such as social media and web platforms. We enter into agreements to ensure that our partners process personal data in a secure and appropriate manner and in accordance with applicable data protection legislation.
You can unsubscribe from profiling and marketing at any time by using this form, by sending us an email at dpo@airshoppen.com or by contacting the NLTG Group’s Group Data Protection Officer at dpo@nltg.com Rålambsvägen 17, 105 20 Stockholm, Sweden.
Airshoppen’s technical and organizational measures for the secure processing of your personal data
We continuously take measures to comply with the principles of “data protection by design and by default.” We continually assess the risks involved in the processing of personal data and take the necessary precautions to reduce those risks.
We have strict procedures and access restrictions in place to prevent unauthorized access to our information systems, and we continuously train our employees on data protection matters. If you have specific questions about how we work with the EU General Data Protection Regulation (GDPR), you can send an email to dpo@airshoppen.com
Disclosure of personal data
Transfer of personal data
We share personal data with suppliers and contractual partners, for example the systems that handle the actual order as well as all marketing-related aspects.
Within Nordic Leisure Travel Group (NLTG), several functions are shared, including many IT functions. If you are flying with Sunclass Airlines, we may disclose your personal data to any group company for business purposes (these business purposes include storing your data in central/shared systems for administrative and marketing purposes). Our group means our subsidiaries, our ultimate holding company and its subsidiaries. The personal data is shared on the basis that we have a legitimate interest in ensuring a correct and consistent application of our terms and applicable legislation in relation to our customers. We assess that this legitimate interest outweighs the intrusion into our customers’ privacy that the sharing of this information entails. We also assess that the customers’ fundamental interests, rights and freedoms are not unduly affected.
Strict user access rights are implemented in our system, ensuring that only a limited group of employees have access to personal data. Particularly sensitive cases are protected by granting access only to a specially designated, very small group of employees.
NLTG itself has access to personal data as a basis for the analysis of customer data. The use of such data for statistical and analytical purposes takes place exclusively on an aggregated and non-individualized level. If necessary, we may also share other personal data with other companies within the group.
Microsoft
We use Microsoft Office products and system services for our internal work. This means that your personal data will be processed by Microsoft, which we use as our data processor. The personal data is stored by Microsoft in a cloud service within the EU. In the event of a major IT incident, Microsoft may transfer the personal data to a third country (i.e. a country outside the EU/EEA). This transfer only takes place in order to protect the data.
Contract partners and IT suppliers
We use a wide range of IT services and IT systems in our company. Some of these store and manage personal data. We respect your privacy and the security of your data in all handling. Some systems are installed locally with us, and only our staff have access to this information. In these cases, there is no transfer to third parties. However, some systems are cloud solutions or installed by the provider, which means that we disclose personal data to the provider. In these cases, the provider is our data processor and handles the information on our behalf and in accordance with our instructions.
Internal IT systems
Internally, we handle personal data in our ordering and sales systems, our customer service system, and in a system for data management and data enhancement. These systems are designed to deliver the services you have ordered from us and to handle inquiries and customer care in connection with the performance of these services. These systems can process all of the personal data that we collect.
Web analytics companies
We use external providers for personalization and analysis of user behavior, user feedback, and development work on our websites and other digital channels. These companies process personal data as data processors on our behalf. The personal data in question primarily consists of information collected via cookies and is handled on an anonymous or pseudonymous and aggregated level.
Payment solutions
We use external providers to handle payments. These providers have access to personal data such as names, addresses, and payment details. This processing is necessary for us to be able to deliver the services you have ordered from us.
Contact services
We use external providers to send communications before, during and after a trip. These providers have access to personal data in the form of phone numbers and email addresses as well as the booking number.
We use external providers to manage certain contact forms on our websites, such as the form for handling personal data. We also use an external provider to collect feedback about our websites. These providers gain access to the personal data you provided in the respective forms.
Your rights
You have a number of rights when we process your personal data. These rights give you insight into and control over how your data is processed.
You can exercise your rights by contacting us at dpo@airshoppen.com or via this form.
We will respond to your request as quickly as possible and no later than within 30 days, unless the request is particularly complex.
Right of access
You have the right to obtain confirmation as to whether we process personal data about you and to access the data we process.
Right to rectification
You have the right to have inaccurate information about you corrected and incomplete information supplemented.
Right to erasure
In certain cases, you have the right to have your personal data erased. This applies, for example, if the data is no longer necessary for the purpose for which it was collected, or if the processing is based on consent and you withdraw that consent.
The right to erasure does not apply if we still need to process the data to comply with legal requirements, handle a complaint, or establish, exercise, or defend legal claims.
Right to restriction
In certain circumstances, you have the right to restrict the processing of your personal data. This means that, temporarily, we may only process the data for certain limited purposes.
Right to object
You have the right to object to processing based on legitimate interests. If you object, we will assess whether our legitimate grounds override your interests, rights and freedoms.
You always have the right to object to the processing of your personal data for direct marketing purposes, including profiling for this purpose.
Right to withdraw consent
If we process personal data on the basis of your consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of any processing carried out before consent was withdrawn.
Right to data portability
If the processing is based on consent or a contract and is carried out by automated means, you have the right, in certain cases, to receive the personal data you have provided to us in a structured, commonly used and machine-readable format.
Limitations on your rights
In certain cases, we may have the right to refuse or restrict a request, for example if:
- the request is manifestly unfounded or unreasonable, particularly if it is repeated frequently, or
- continued processing is necessary to fulfill an agreement, comply with legal requirements, or establish, exercise, or defend legal claims.
If we are unable to accommodate your request, we will always explain why.
Right to lodge a complaint
If you believe that our processing of your personal data violates data protection rules, you have the right to lodge a complaint with a data protection authority.
You can find more information on the relevant authority’s website:
- Denmark: Danish Data Protection Agency (Datatilsynet)
- Sweden: Swedish Authority for Privacy Protection (IMY)
- Norway: Norwegian Data Protection Authority (Datatilsynet)
- Finland: Office of the Data Protection Ombudsman
Changes to this Privacy Policy
We may update this privacy policy if our processing of personal data changes, if we introduce new services or features, or if there are changes to applicable legislation or regulatory practices.
The latest version of the privacy policy will be available on our website.
