Websites and Online Ticketing
Version 3.0 · Last updated: 21.07.2026
Foreword
FLIBTRAVEL International S.A. (hereinafter “Flibco”, “we”, “us” or “our”) operates the Flibco websites and sells tickets for airport shuttle and Door2Gate transfer services. With this Privacy Notice, we inform you transparently about how your personal data is processed when you visit our websites and book or manage transport services online, and about your rights (in particular under Articles 13 and 14 GDPR).
This Privacy Notice is modular in structure. It consists of a general part containing information that applies to all processing of personal data and to every visit to our websites (Part 1), and a special part whose content relates only to the specific processing situation described therein (Part 2).
Part 1 – General Information
1.1 Definition of Terms
This Privacy Notice is based on the following definitions set out in Article 4 GDPR. Where you engage with our UK entity, the equivalent definitions under the UK GDPR apply.
- Personal data means any information relating to an identified or identifiable natural person (the “data subject”), such as a name, an identification number, location data or an online identifier (Art. 4(1) GDPR).
- Processing means any operation performed on personal data, whether or not by automated means, such as collection, storage, use, disclosure or erasure (Art. 4(2) GDPR).
- Controller means the natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data (Art. 4(7) GDPR).
- Processor means a natural or legal person which processes personal data on behalf of the controller (Art. 4(8) GDPR).
- Third party means any person or body other than the data subject, controller, processor and persons authorised to process the data under their direct authority (Art. 4(10) GDPR).
- Consent means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they signify agreement to the processing of their personal data (Art. 4(11) GDPR).
1.2 Name and Address of the Controller
The controller responsible for the processing of your personal data described in this Privacy Notice (Art. 4(7) GDPR) is:
FLIBTRAVEL International S.A.
4, rue Laangwiss, L-4940 Bascharage, Luxembourg
Registration no. B177392
Email: [email protected]
1.3 Contact Details of the Data Protection Officer
Our Data Protection Officer is available to answer your questions and acts as your contact on all matters relating to data protection:
FLIBTRAVEL International S.A., FAO Data Protection Officer
4, rue Laangwiss, L-4940 Bascharage, Luxembourg
Email: [email protected]
1.4 Legal Basis for Data Processing
The processing of personal data is permitted where at least one of the following legal bases applies:
- Art. 6(1)(a) GDPR – the data subject has given consent for one or more specific purposes;
- Art. 6(1)(b) GDPR – processing is necessary for the performance of a contract or to take pre-contractual steps at the data subject’s request;
- Art. 6(1)(c) GDPR – processing is necessary for compliance with a legal obligation (e.g. a statutory retention obligation);
- Art. 6(1)(d) GDPR – processing is necessary to protect the vital interests of the data subject or another natural person;
- Art. 6(1)(f) GDPR – processing is necessary for the purposes of legitimate interests pursued by us or a third party, unless overridden by the data subject’s interests or fundamental rights.
For processing carried out by us, we specify the applicable legal basis in Part 2. Processing may be based on more than one legal basis.
1.5 Categories of Recipients
Under certain conditions, we transmit your personal data to entities of the Flibco group, or receive personal data from them, to the extent permissible. As with any company of our size, we also engage external service providers and partners in Luxembourg and abroad, for example:
carriers performing the booked transport services;
(IT) service providers and hosting providers;
financial institutions and payment service providers;
sales and distribution partners;
customer service providers (internal/external);
other partners engaged for our business operations (e.g. auditors, banks, insurers, lawyers, supervisory authorities).
Service providers acting as data processors on our behalf are bound by a data processing agreement pursuant to Art. 28 GDPR and must implement appropriate technical and organisational measures. We transmit personal data to public authorities and institutions where there is a corresponding legal obligation or authorisation. The categories of recipients for each processing activity are specified in Part 2.
1.6 Transfers of Personal Data to Third Countries
As part of our business relationships, your personal data may be transferred to recipients located outside the European Economic Area (EEA) or, in the case of UK processing, outside the United Kingdom (third countries). Where this is the case, we will provide details in the relevant section of Part 2.
The European Commission has determined that certain third countries provide an adequate level of data protection by means of adequacy decisions. Where personal data is transferred to a third country that is not covered by an adequacy decision, we ensure an adequate level of protection through appropriate safeguards, in particular the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, binding corporate rules, or recognised certifications and codes of conduct. Where necessary for your booking, the transfer of the required data is permitted under Art. 49(1)(b) GDPR.
1.7 Storage Duration and Erasure
The storage period of your personal data depends on the purpose for which we process it; the data is stored only for as long as necessary to achieve that purpose. Where a specific storage period is stated, it is set out in Part 2. If no explicit period is stated, your personal data is erased or blocked as soon as the purpose or legal basis for its storage no longer applies. Storage may extend beyond that period where required by statutory retention obligations or in the event of an actual or imminent legal dispute.
1.8 Automated Decision-Making (Including Profiling)
We do not carry out automated individual decision-making, including profiling, within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you.
1.9 No Obligation to Provide Personal Data
We do not generally make the conclusion of a contract conditional on you providing personal data in advance, and there is in principle no statutory or contractual obligation to provide us with your personal data. However, we may be unable to provide certain services, in whole or in part, if you do not provide the data required for that purpose.
1.10 Statutory Obligation to Transmit Certain Data
In certain circumstances, we may be subject to a specific statutory or legal obligation to provide personal data to third parties, in particular to public authorities.
1.11 Data Security
We use appropriate technical and organisational measures to protect your data against accidental or intentional manipulation, partial or complete loss or destruction, or unauthorised access by third parties (e.g. TLS encryption of our websites), taking into account the state of the art, implementation costs and the nature, scope, context and purposes of processing, as well as the risks involved. Our security measures are continuously improved in line with technological developments.
1.12 Your Rights
You may assert your rights as a data subject at any time, in particular by contacting us using the details in Clause 1.2 or 1.3. You have the following rights under the GDPR / UK GDPR:
- Right of access (Art. 15) – to obtain information about the personal data we process about you and a copy thereof;
- Right to rectification (Art. 16) – to have inaccurate data corrected and incomplete data completed;
- Right to erasure (Art. 17) – to have your personal data erased where the conditions are met;
- Right to restriction of processing (Art. 18);
- Right to data portability (Art. 20) – to receive your data in a structured, commonly used, machine-readable format;
- Right to object (Art. 21) – to object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f); and to object at any time to processing for direct marketing purposes (Art. 21(2));
- Right to withdraw consent (Art. 7(3)) – to withdraw consent at any time with effect for the future, without affecting the lawfulness of processing carried out before withdrawal.
- Right to lodge a complaint. You have the right to lodge a complaint with a data protection supervisory authority.
If your personal data is processed under the EU GDPR (i.e. in connection with our EU/EEA operations), you may lodge a complaint with a supervisory authority. The lead supervisory authority for FLIBTRAVEL International S.A. is:
Luxembourg (lead): Commission nationale pour la protection des données (CNPD), 15, Boulevard du Jazz, L-4370 Belvaux, Luxembourg.
If you are in the United Kingdom (so that your personal data is processed under the UK GDPR), you may instead lodge a complaint with the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
Complaining directly to us (UK only). If you are in the United Kingdom, under Section 164A of the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025) you have the right to make a data protection complaint directly to us before escalating to the ICO. You can do so by email to [email protected] or by post to the address in Clause 1.2. We will acknowledge receipt within 30 days, investigate without undue delay, and inform you of the outcome and of your continuing right to complain to the ICO.
Part 2 – Special Information
2.1 Visiting our Websites
Information about Flibco and our services is available on our websites and the associated sub-pages (the “websites”). When you visit our websites, your personal data is processed as described below.
2.1.1 Provision of the Websites
When you use the websites for information purposes, a log data record (“server log files”) is stored on our web server, consisting of: the requesting (referrer) URL, the name and URL of the requested page, the date and time of the access request, the browser version, the IP address of the requesting device, the volume of data transferred, the operating system, the access status/HTTP status code, and the GMT time-zone difference. This processing serves statistical purposes and the stability and security of our websites. We use IT service providers as processors for hosting and statistical evaluation. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is to make the websites available to you properly and securely.
2.1.2 Contact Forms
When you use a contact form or contact us by email, we process the data you transmit (e.g. title, name, address, company, email address, time of transmission and the subject of your enquiry) in order to handle your enquiry. The legal basis is Art. 6(1)(b) GDPR for contract-related enquiries, and otherwise Art. 6(1)(f) GDPR (our legitimate interest in handling enquiries). We also store the contact data and the relevant IP address to comply with our accountability obligations and to ensure the security of our systems (Art. 6(1)(c) or (f) GDPR). We use customer service providers as processors to answer enquiries.
2.1.3 Booking, Provision and Processing of Transport Services
When you book airport shuttle or Door2Gate transfer services, we collect, store and process the following categories of personal data: email address; first and last name; billing address; the pick-up/drop-off address you provide for the Door2Gate service; itinerary and booking reference; payment data; telephone number (optional, for notifications of delays or changes); and your consent to the applicable terms and conditions. This data is processed for the booking, provision and processing of the transport services, including customer service, and to fulfil legal obligations. The legal basis is Art. 6(1)(b) and (c) GDPR.
Where you require special assistance (e.g. wheelchair support), the related information may constitute a special category of personal data and is processed on the basis of your explicit consent under Art. 9(2)(a) GDPR in conjunction with Art. 6(1)(a) GDPR.
Where the provision of a cross-border transport service requires it, we may be obliged to transmit certain identification data to the competent authorities. The legal basis for such transmission is Art. 6(1)(c) GDPR.
To process payments, we use external payment service providers. They are acting as independent controllers to process the necessary payment data.
2.1.4 Newsletter
If you register for our newsletter, we ask you to consent to the processing of your data (email address, name) in order to send you our newsletter on a regular basis. We use the double opt-in procedure: after registration we send a confirmation email, and if you do not confirm within 24 hours your data is blocked and automatically erased after one month. The legal basis is Art. 6(1)(a) GDPR. We also store the IP addresses used and the times of registration and confirmation to demonstrate consent; the legal basis for this is Art. 6(1)(f) GDPR (our legitimate interest in demonstrating consent). You can withdraw your consent at any time via the unsubscribe link or by emailing the address indicated in the newsletter.
2.1.5 Product Recommendations
To the extent permitted, we may use the email address obtained in connection with your booking to send you offers for our own similar products by email. The legal basis is Art. 6(1)(f) GDPR (in conjunction with the applicable national implementation of Article 13 of the ePrivacy Directive / soft opt-in). You may object to this use of your email address at any time, free of charge, via the unsubscribe link or by contacting us.
2.1.6 Customer Account
You may create a password-protected customer account in which you can manage your bookings and store data for future journeys. To create an account we collect your email address and a self-selected password; the legal basis is Art. 6(1)(a) GDPR. A persistent cookie containing a session ID may be stored on your device so that you do not have to log in again on subsequent visits; the legal basis is Art. 6(1)(f) GDPR. You can delete your account by contacting us at [email protected], or, for a more convenient way to delete your account yourself, please refer to this document.
2.1.7 Cookies and Similar Technologies
Our websites use cookies and similar technologies. In addition to first-party cookies that we set as controller, third-party cookies offered by other providers may be used. Through our consent management platform (consent banner) you can decide which categories of cookies and similar technologies are used and withdraw your consent at any time.
Strictly necessary cookies are used on the basis of Art. 6(1)(f) GDPR (or, where applicable, the relevant national ePrivacy provisions and Regulation 6(4) PECR in the UK). All other categories – in particular performance, functionality and marketing cookies – are used only on the basis of your consent under Art. 6(1)(a) GDPR, which you can withdraw at any time via the cookie banner.
2.2 Customer Service
When you contact our customer service, we process the personal data you provide on your own initiative (e.g. by email, telephone or letter), including communication data such as your email address and telephone number. We use this data to process your request, to fulfil legal obligations where necessary, and for administrative purposes. The legal basis is Art. 6(1)(b), (c) or (f) GDPR. We use external customer service providers as processors.
2.3 Presence on Social Media
We maintain a presence on social media platforms. If you interact with us on our channels, the legal basis for our processing is Art. 6(1)(f) GDPR; our legitimate interest is effective information and communication.
2.4 Whistleblowing
When you contact us via our whistleblowing portal, we collect the personal data you provide on your own initiative (e.g. name and email address).
Your personal data will only be used to process your report and for potential internal investigations conducted after your report.
The legal basis is Art. 6 para. 1(a) GDPR.
Your data is provided voluntarily, and you can make all reports anonymously.
According to the Art. 6 para. 1(c) GDPR, we are legally obliged to transfer your data to public authorities if requested.
Our web portal uses an external service provider as processor.
Version 3.0 · Last updated: 21.07.2026
Mobile Application (App)
Version 3.0 · 21.07.2026
Foreword
FLIBTRAVEL International S.A. (hereinafter “Flibco”, “we”, “us” or “our”) provides the Flibco mobile application (the “App”), through which you can book and manage airport shuttle and Door2Gate transfer services. With this Privacy Notice, we inform you transparently about how your personal data is processed when you install and use the App, and about your rights (in particular under Articles 13 and 14 GDPR).
This Privacy Notice is modular in structure. It consists of a general part containing information that applies to all processing of personal data (Part 1), and a special part whose content relates only to the use of the App (Part 2).
Part 1 – General Information
1.1 Definition of Terms
This Privacy Notice is based on the following definitions set out in Article 4 GDPR. Where you engage with our UK entity, the equivalent definitions under the UK GDPR apply.
- Personal data means any information relating to an identified or identifiable natural person (the “data subject”), such as a name, an identification number, location data or an online identifier (Art. 4(1) GDPR).
- Processing means any operation performed on personal data, whether or not by automated means, such as collection, storage, use, disclosure or erasure (Art. 4(2) GDPR).
- Controller means the natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data (Art. 4(7) GDPR).
- Processor means a natural or legal person which processes personal data on behalf of the controller (Art. 4(8) GDPR).
- Third party means any person or body other than the data subject, controller, processor and persons authorised to process the data under their direct authority (Art. 4(10) GDPR).
- Consent means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they signify agreement to the processing of their personal data (Art. 4(11) GDPR).
1.2 Name and Address of the Controller
The controller responsible for the processing of your personal data described in this Privacy Notice (Art. 4(7) GDPR) is:
FLIBTRAVEL International S.A.
4, rue Laangwiss, L-4940 Bascharage, Luxembourg
Registration no. B177392
Email: [email protected]
1.3 Contact Details of the Data Protection Officer
Our Data Protection Officer is available to answer your questions and acts as your contact on all matters relating to data protection:
FLIBTRAVEL International S.A., FAO Data Protection Officer
4, rue Laangwiss, L-4940 Bascharage, Luxembourg
Email: [email protected]
1.4 Legal Basis for Data Processing
The processing of personal data is permitted where at least one of the following legal bases applies:
- Art. 6(1)(a) GDPR – the data subject has given consent for one or more specific purposes;
- Art. 6(1)(b) GDPR – processing is necessary for the performance of a contract or to take pre-contractual steps at the data subject’s request;
- Art. 6(1)(c) GDPR – processing is necessary for compliance with a legal obligation (e.g. a statutory retention obligation);
- Art. 6(1)(d) GDPR – processing is necessary to protect the vital interests of the data subject or another natural person;
- Art. 6(1)(f) GDPR – processing is necessary for the purposes of legitimate interests pursued by us or a third party, unless overridden by the data subject’s interests or fundamental rights.
For processing carried out by us, we specify the applicable legal basis in Part 2. Processing may be based on more than one legal basis.
1.5 Categories of Recipients
Under certain conditions, we transmit your personal data to entities of the Flibco group, or receive personal data from them, to the extent permissible. As with any company of our size, we also engage external service providers and partners in Luxembourg and abroad, for example:
- carriers performing the booked transport services;
- (IT) service providers and hosting providers;
- financial institutions and payment service providers;
- sales and distribution partners;
- customer service providers (internal/external);
- other partners engaged for our business operations (e.g. auditors, banks, insurers, lawyers, supervisory authorities).
Service providers acting as data processors on our behalf are bound by a data processing agreement pursuant to Art. 28 GDPR and must implement appropriate technical and organisational measures. We transmit personal data to public authorities and institutions where there is a corresponding legal obligation or authorisation. The categories of recipients for each processing activity are specified in Part 2.
1.6 Transfers of Personal Data to Third Countries
As part of our business relationships, your personal data may be transferred to recipients located outside the European Economic Area (EEA) or, in the case of UK processing, outside the United Kingdom (third countries). Where this is the case, we will provide details in the relevant section of Part 2.
The European Commission has determined that certain third countries provide an adequate level of data protection by means of adequacy decisions. Where personal data is transferred to a third country that is not covered by an adequacy decision, we ensure an adequate level of protection through appropriate safeguards, in particular the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, binding corporate rules, or recognised certifications and codes of conduct. Where necessary for your booking, the transfer of the required data is permitted under Art. 49(1)(b) GDPR.
1.7 Storage Duration and Erasure
The storage period of your personal data depends on the purpose for which we process it; the data is stored only for as long as necessary to achieve that purpose. Where a specific storage period is stated, it is set out in Part 2. If no explicit period is stated, your personal data is erased or blocked as soon as the purpose or legal basis for its storage no longer applies. Storage may extend beyond that period where required by statutory retention obligations or in the event of an actual or imminent legal dispute.
1.8 Automated Decision-Making (Including Profiling)
We do not carry out automated individual decision-making, including profiling, within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you.
1.9 No Obligation to Provide Personal Data
We do not generally make the conclusion of a contract conditional on you providing personal data in advance, and there is in principle no statutory or contractual obligation to provide us with your personal data. However, we may be unable to provide certain services, in whole or in part, if you do not provide the data required for that purpose.
1.10 Statutory Obligation to Transmit Certain Data
In certain circumstances, we may be subject to a specific statutory or legal obligation to provide personal data to third parties, in particular to public authorities.
1.11 Data Security
We use appropriate technical and organisational measures to protect your data against accidental or intentional manipulation, partial or complete loss or destruction, or unauthorised access by third parties (e.g. transport encryption), taking into account the state of the art, implementation costs and the nature, scope, context and purposes of processing, as well as the risks involved. Our security measures are continuously improved in line with technological developments.
1.12 Your Rights
You may assert your rights as a data subject at any time, in particular by contacting us using the details in Clause 1.2 or 1.3. You have the following rights under the GDPR / UK GDPR:
- Right of access (Art. 15) – to obtain information about the personal data we process about you and a copy thereof;
- Right to rectification (Art. 16) – to have inaccurate data corrected and incomplete data completed;
- Right to erasure (Art. 17) – to have your personal data erased where the conditions are met;
- Right to restriction of processing (Art. 18);
- Right to data portability (Art. 20) – to receive your data in a structured, commonly used, machine-readable format;
- Right to object (Art. 21) – to object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f); and to object at any time to processing for direct marketing purposes (Art. 21(2));
- Right to withdraw consent (Art. 7(3)) – to withdraw consent at any time with effect for the future, without affecting the lawfulness of processing carried out before withdrawal.
- Right to lodge a complaint. You have the right to lodge a complaint with a data protection supervisory authority.
If your personal data is processed under the EU GDPR (i.e. in connection with our EU/EEA operations), you may lodge a complaint with a supervisory authority. The lead supervisory authority for FLIBTRAVEL International S.A. is:
- Luxembourg (lead): Commission nationale pour la protection des données (CNPD), 15, Boulevard du Jazz, L-4370 Belvaux, Luxembourg.
If you are in the United Kingdom (so that your personal data is processed under the UK GDPR), you may instead lodge a complaint with the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
- Complaining directly to us (UK only). If you are in the United Kingdom, under Section 164A of the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025) you have the right to make a data protection complaint directly to us before escalating to the ICO. You can do so by email to [email protected] or by post to the address in Clause 1.2. We will acknowledge receipt within 30 days, investigate without undue delay, and inform you of the outcome and of your continuing right to complain to the ICO.
Part 2 – Special Information: Use of the App
You can book and manage transport services using the App. We collect, store and process personal data when you install and use the App, as described below.
2.1 Provision of the App
For technical reasons, data is exchanged between the App and our server systems so that we can provide the App and ensure its stability and security. The following access data is processed for this purpose: IP address; date and time of the request; time-zone difference to GMT; content of the request; access status / HTTP status code; volume of data transferred; the originating website; browser; operating system and its interface; language and version of the App; name of your mobile device; language, region and version of the mobile device; and, where applicable, an advertising identifier (optional).
We use IT service providers as processors for hosting the App and for statistical evaluation of the access data. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is to make the App available to you properly and securely.
2.2 Access Authorisations
The App requires access to certain functions and interfaces of your mobile device. You must grant the App the corresponding authorisations; the authorisation system depends on your operating system. Without the requested authorisations, only limited App functions may be available.
All devices. The App requires an internet connection to exchange data with our server systems. The receipt of background notifications must be enabled to keep your booking information up to date.
Location data. If you grant the corresponding authorisation, your location data is processed (optional) to provide you with essential travel information (e.g. arrival times, transfer options) during your trip. The App will, for example, notify you when you are approaching your destination or transfer point. The legal basis is Art. 6(1)(a) GDPR; the storage of and access to information on your device is based on your consent under the applicable national implementation of the ePrivacy Directive (LU/BE/IT) and, in the UK, Regulation 6 PECR. You can withdraw your consent at any time by revoking the location permission in your device settings.
Calendar (Android). On Android devices, you can enable access to your calendar in order to add bookings to your calendar (optional).
Notifications (Apple iOS). On Apple iOS devices, you can enable the receipt of push notifications (optional).
2.3 Contact Forms
When you use a contact form in the App or contact us by email, we process the data you transmit (e.g. name, address, email address, time of transmission and the subject of your enquiry) in order to handle your enquiry. The legal basis is Art. 6(1)(b) GDPR for contract-related enquiries, and otherwise Art. 6(1)(f) GDPR (our legitimate interest in handling enquiries). We also store the contact data and the relevant IP address to comply with our accountability obligations and to ensure the security of our systems (Art. 6(1)(c) or (f) GDPR). We use customer service providers as processors.
2.4 Booking, Provision and Processing of Transport Services
When you book airport shuttle or Door2Gate transfer services through the App, we collect, store and process the following categories of personal data: email address; first and last name; billing address; the pick-up/drop-off address you provide for the Door2Gate service; itinerary and booking reference; payment data; telephone number (optional, for notifications of delays or changes); booking channel (web or App); and your consent to the applicable terms and conditions. This data is processed for the booking, provision and processing of the transport services, including customer service, and to fulfil legal obligations. The legal basis is Art. 6(1)(b) and (c) GDPR.
Where you require special assistance (e.g. wheelchair support), the related information may constitute a special category of personal data and is processed on the basis of your explicit consent under Art. 9(2)(a) GDPR in conjunction with Art. 6(1)(a) GDPR.
Where the provision of a cross-border transport service requires it, we may be obliged to transmit certain identification data to the competent authorities. The legal basis for such transmission is Art. 6(1)(c) GDPR.
To process payments, we use external payment service providers. They are acting as independent controllers to process the necessary payment data.
2.5 Product Recommendations
To the extent permitted, we may use the email address obtained in connection with your booking to send you offers for our own similar products by email. The legal basis is Art. 6(1)(f) GDPR (in conjunction with the applicable national implementation of Article 13 of the ePrivacy Directive / soft opt-in). You may object to this use of your email address at any time, free of charge, via the unsubscribe link or by contacting us.
2.6 Newsletter
If you register for our newsletter, we ask you to consent to the processing of your data (email address, name) in order to send you our newsletter on a regular basis. We use the double opt-in procedure: after registration we send a confirmation email, and if you do not confirm within 24 hours your data is blocked and automatically erased after one month. The legal basis is Art. 6(1)(a) GDPR. We also store the IP addresses used and the times of registration and confirmation to demonstrate consent (Art. 6(1)(f) GDPR). You can withdraw your consent at any time via the unsubscribe link or by emailing the address indicated in the newsletter.
2.7 Push Notifications
If you consent to receive push notifications, we process the data necessary to send you trip-related information and, where you have so consented, promotional messages (e.g. home country, language, booking history and, if enabled, location data). The legal basis is Art. 6(1)(a) GDPR. We also store the IP addresses used and the times of registration and confirmation to demonstrate consent (Art. 6(1)(f) GDPR). You can withdraw your consent to all or specific categories of push notifications at any time via the preference settings in the App or in your device settings.
2.8 Customer Account
You may create a password-protected customer account in which you can manage your bookings and store data for future journeys. To create an account we collect your email address and a self-selected password; the legal basis is Art. 6(1)(a) GDPR. A persistent identifier containing a session ID may be stored on your device so that you do not have to log in again on subsequent visits; the legal basis is Art. 6(1)(f) GDPR. You can delete your account by contacting us at [email protected], or, for a more convenient way to delete your account yourself, please refer to this document.
2.9 Cookies and Similar Technologies in the App
The App uses cookies and similar technologies. In addition to first-party technologies that we set as controller, third-party technologies offered by other providers may be used. Through our consent management platform you can decide which categories are used and withdraw your consent at any time in the App settings. Strictly necessary technologies are used on the basis of Art. 6(1)(f) GDPR (or, where applicable, the relevant national ePrivacy provisions and Regulation 6(4) PECR in the UK); all other categories are used only on the basis of your consent under Art. 6(1)(a) GDPR.
2.10 Customer Service
When you contact our customer service, we process the personal data you provide on your own initiative (e.g. by email, telephone or letter), including communication data such as your email address and telephone number. We use this data to process your request, to fulfil legal obligations where necessary, and for administrative purposes. The legal basis is Art. 6(1)(b), (c) or (f) GDPR. We use external customer service providers as processors.
2.11 Presence on Social Media
We maintain a presence on social media platforms. If you interact with us on our channels, the legal basis for our processing is Art. 6(1)(f) GDPR; our legitimate interest is effective information and communication.
2.12 Whistleblowing
When you contact us via our whistleblowing portal, we collect the personal data you provide on your own initiative (e.g. name and email address).
Your personal data will only be used to process your report and for potential internal investigations conducted after your report.
The legal basis is Art. 6 para. 1(a) GDPR.
Your data is provided voluntarily, and you can make all reports anonymously.
According to the Art. 6 para. 1(c) GDPR, we are legally obliged to transfer your data to public authorities if requested.
Our web portal uses an external service provider as processor.
Version 3.0 · Last updated: 21.07
Job Applicants
Version 1.0 · Last updated: 21.07.2026
Foreword
This Privacy Notice explains how your personal data is processed within the Flibco group (“Flibco”, “we”, “us” or “our”) when you apply for a position advertised by us. Depending on the Flibco entity you apply to, different rules apply: Section A applies to applications to our entities in the EU/EEA (Luxembourg, Belgium, Italy), and Section B applies to applications to our UK entity.
Our general Flibco Privacy Notice (Websites and Online Ticketing) applies in addition to this notice for any processing that is not related to your application (e.g. when you visit our careers website).
Controller and Data Protection Officer
The controller for the processing of your personal data is the Flibco Group entity operating in the jurisdiction where the advertised position is based – i.e. FLIBTRAVEL International S.A. (Luxembourg), SL Belgium S.A. (Belgium), FlibTravel International Italy SRL (Italy), or FlibTravel International UK Ltd (United Kingdom), as identified in the respective job advertisement (“Flibco” or “we”).
Our Data Protection Officer is available for all data protection matters:
FLIBTRAVEL International S.A., FAO Data Protection Officer, 4, rue Laangwiss, L-4940 Bascharage, Luxembourg
Email: [email protected]
For general questions about the application process, please contact [email protected].
Section A – Applicants in the EU/EEA (Luxembourg, Belgium, Italy)
A.1 Categories of Personal Data
As part of the application process, we collect and process the following categories of personal data:
master data and contact details (e.g. first and last name, country, email address, telephone number);
information provided in the application form (e.g. salary expectations, motivation, right to work / work permit, and – only where relevant for the advertised position – information on a disability);
application documents (e.g. CV, cover letter, qualifications, language skills);
results of online assessments and interviews, where applicable;
identification or right-to-work documents required to verify your eligibility to enter into an employment contract, where necessary;
any additional information or references you provide to us.
We may also obtain data relevant to your professional career from public professional networks (e.g. LinkedIn) or job portals, where you have made it available, solely for the purpose of the application process.
A.2 Purposes of Processing
We process your personal data to advertise positions and carry out the selection process, in particular to:
identify you as an applicant and assess your suitability for the position;
initiate and, where applicable, establish an employment relationship;
contact you about your speculative application;
where you consent, contact you about alternative positions, include you in our talent pool, or ask about your satisfaction with the application process.
A.3 Legal Bases
We process your personal data only where permitted by law. The relevant legal bases are:
- Art. 6(1)(b) GDPR – to take steps, at your request, prior to entering into an employment contract and to carry out the selection process;
- Art. 6(1)(c) GDPR – to comply with legal obligations;
- Art. 6(1)(a) GDPR – your consent, in particular for the talent pool, satisfaction surveys, contact about alternative positions, and any voluntary special category data you provide;
- Art. 6(1)(f) GDPR – our legitimate interest, in particular to establish, exercise or defend legal claims arising in the application process (e.g. claims under equal-treatment legislation), and to use information from public professional networks for the purpose of the selection decision (in conjunction with Art. 9(2)(e) GDPR where applicable).
Where you voluntarily provide special categories of personal data (e.g. information on a disability), we process them only on the basis of your explicit consent under Art. 9(2)(a) GDPR. Providing personal data in the application process is voluntary; however, it is necessary in order to process your application or to conclude an employment contract.
A.4 Categories of Recipients
After receipt of your application, your data is made available only to those involved in the selection process. The categories of recipients are:
the recruiting Flibco entity’s own hiring department and Human Resources team
IT and applicant-management service providers acting as processors on our behalf under Art. 28 GDPR;
public authorities or law-enforcement bodies, where we are legally required to disclose data (Art. 6(1)(c) GDPR).
Where a processor is located outside the EEA, we ensure an adequate level of protection through appropriate safeguards, in particular the European Commission’s Standard Contractual Clauses, an adequacy decision, or other safeguards recognised under the GDPR.
A.5 Your Rights
You may assert your rights as a data subject at any time using the contact details above. Under the GDPR, you have the right of access (Art. 15), the right to rectification (Art. 16), the right to erasure (Art. 17), the right to restriction of processing (Art. 18), the right to data portability (Art. 20), the right to object (Art. 21), and the right to withdraw consent at any time with effect for the future (Art. 7(3)). You also have the right to lodge a complaint with a supervisory authority.
A.6 Storage and Retention Periods
We store your personal data for a period of six months after we send you a rejection for the relevant position. This period is necessary in particular to comply with obligations to provide evidence in proceedings under applicable equal-treatment legislation or to defend against claims, Art. 6(1)(f) GDPR. Where you have consented to being included in our talent pool, your application documents are processed for that purpose only. If your application is successful, your data is retained for the duration of the employment relationship in accordance with the applicable employee privacy notice.
Section B – Applicants in the United Kingdom
This Section applies if you apply for a position advertised by FlibTravel International UK Ltd. It supplements Section A and, where it conflicts with Section A, takes precedence for UK applicants.
B.1 Controller and Applicable Law
The controller is FlibTravel International UK Ltd, [Lake House, Market Hill, Royston SG8 9JN, United Kingdom. Our Data Protection Officer can be contacted at [email protected].
The processing of your personal data in connection with your application is governed by the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025. References to the GDPR in Section A should be read as references to the UK GDPR where this Section applies.
B.2 Categories of Data, Purposes and Legal Bases
The categories of personal data, the purposes of processing and the legal bases are the same as set out in Section A, applied under the equivalent provisions of the UK GDPR (in particular Art. 6 and, where applicable, Art. 9 UK GDPR).
B.3 Recipients and Third-Country Transfers
Your personal data may be shared with the recipients described in Section A. Where data is transferred to a country outside the United Kingdom, we ensure an adequate level of protection through UK adequacy regulations, UK International Data Transfer Agreements (IDTAs), the UK Addendum to the EU Standard Contractual Clauses, or other appropriate safeguards recognised under the UK GDPR.
B.4 Your Rights
You have the same rights as set out in Section A under the equivalent provisions of the UK GDPR (Arts. 15–21). You may lodge a complaint with the Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, at any time.
Complaining directly to us. Under Section 164A of the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025), you also have the right to make a data protection complaint directly to us, by email to [email protected] or by post to the registered office above. We will acknowledge receipt within 30 days, investigate without undue delay, and inform you of the outcome and of your continuing right to complain to the ICO.
B.5 Storage and Retention Periods
The retention periods are the same as set out in Section A, subject to applicable UK statutory obligations and limitation periods in place of the references in that Section.
Version 1.0 · Last updated: 21.07.2026