Privacy Policy - FlyInPoland
Legal

Privacy Policy

Version 1.2 · Effective 25 September 2026 · Operated by Dutch Aviation Services Sp. z o.o. (90-369 Łódź, Poland)

This Privacy Policy explains how Dutch Aviation Services Sp. z o.o. ("we", "us", "the Controller") collects, uses, and protects personal data of users of the flyinpoland.com website and recipients of FlyInPoland services.

This Policy is issued in compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 ("GDPR") and, in Polish jurisdiction, the Polish Personal Data Protection Act of 10 May 2018 ("RODO", Dz.U. 2018 poz. 1000).

Data Controller: Dutch Aviation Services Sp. z o.o.

KRS 0000838546 · NIP 7252299781 · REGON 386179729

ul. Piotrkowska 222/3, 90-369 Łódź, Poland

Email: [email protected] · Phone: +48 887 888 978

1. What data we collect

We collect personal data in three contexts:

(a) When you visit our website

  • Standard server-log data (IP address, browser type, pages visited, referring URL, timestamp) for the purpose of security, fraud prevention, and aggregate analytics. Retained for up to 12 months.
  • Cookies, as described in our Cookie Policy.

The website stores a versioned record of separate analytics, advertising and chat choices. Analytics and advertising identifiers are not currently configured. Chat loads only after specific chat consent and may then store a persistent visitor identifier for up to 12 months plus browser-local session and history entries, including pages visited and unsent chat text, until site data is cleared. Use the persistent Cookie settings control to change or withdraw any optional choice.

(b) When you submit a contact form or place an order

  • Identification data: name, email, phone number, nationality;
  • Service-specific data: the service you have selected, your stated goals or timeline, any information you choose to add to the message field;
  • Consent records: the consents you ticked + timestamp + IP address (kept as proof of valid consent).

(c) When you receive a service

This varies by service. The training records and operational pilot data category applies to FlyInPoland. Detail follows below.

2. Why we process your data (legal bases)

PurposeLegal basis (GDPR)Retention
Respond to your enquiry; provide pre-contractual informationArt. 6(1)(b) - pre-contractual measures12 months from last contact
Deliver the service you have purchasedArt. 6(1)(b) - performance of contractDuration of contract + 6 years (statute of limitations)
Issue invoices and fulfil tax obligationsArt. 6(1)(c) - legal obligation (Polish Accounting Act, VAT Act)5 years from end of tax year
Marketing communications (where you opted in)Art. 6(1)(a) - consentUntil consent is withdrawn, max 36 months from last engagement
Defend legal claims; respond to regulatory inquiryArt. 6(1)(f) - legitimate interest; Art. 9(2)(f) for special categoryUntil limitation period expires (typically 6 years)
Aviation regulatory record-keeping (where applicable)Art. 6(1)(c); aviation sectoral law (EASA Part-FCL, applicable national law)As required by the regulation (typically 5–10 years)

3. Who has access to your data

Inside our organisation, access is limited to those individuals who need the data to perform their role.

Outside our organisation, we share data with the following categories of recipient, each operating either as a processor under Art. 28 GDPR or as an independent controller where they determine their own purposes:

  • Hosting and IT infrastructure providers (web hosting, email, document storage) - processors, EU-based or under adequacy decisions;
  • Customer relationship management platform (CRM) - processor, with sub-processors outside the EEA as described under international transfers;
  • Payment service providers (bank, future online-payment integration) - independent controllers for payment data, processors for transaction metadata;
  • Accountancy and tax advisors - processors;
  • Aviation regulatory authorities (EASA, national CAA) - independent controllers, where statutory disclosure applies;
  • Legal advisors and dispute-resolution bodies - only as required.

We do not sell your personal data and we do not share it for the purpose of cross-context behavioural advertising.

The providers behind those categories are: Avantwerk, operated by Bennovate sp. z o.o., which supplies and administers our website, CRM, forms, consent-gated chat and email sending, and engages its own infrastructure providers as sub-processors, some of which are outside the EEA; Zoom, where a call or online meeting is arranged; Stripe, if a payment is taken online, in which case we never receive or store a full card number; and Google and Meta for analytics and advertising, which load only after the corresponding choice or Accept all. This list is kept current; a provider may be replaced by another of the same kind.

The providers behind those categories are:

  • Avantwerk, operated by Bennovate sp. z o.o. — Supplies and administers the website, CRM, forms, consent-gated chat and email sending, and engages its own infrastructure providers as sub-processors, some of which are outside the EEA. Established in Poland, with sub-processors outside the EEA. Transfers are made under Standard Contractual Clauses in the platform's data-processing terms.
  • Zoom — Where a video call or online meeting is arranged: assessment interviews, consultations and online meetings. Established in the United States. Transfers are made under the EU-US Data Privacy Framework, with Standard Contractual Clauses as fallback.
  • Stripe — If a payment is ever taken online: card payments. A full card number is never received or stored by the controller. Established in the United States / Ireland. Transfers are made under the EU-US Data Privacy Framework, with Standard Contractual Clauses as fallback.
  • Google Ireland Limited — When analytics or advertising is enabled on this website: analytics and advertising. Established in Ireland, with transfers to the United States. Transfers are made under the EU-US Data Privacy Framework, with Standard Contractual Clauses as fallback. Loads only after the corresponding analytics or advertising choice, or after “Accept all”.
  • Meta Platforms Ireland Limited — When analytics or advertising is enabled on this website: advertising measurement and audiences on Facebook and Instagram. Established in Ireland, with transfers to the United States. Transfers are made under the EU-US Data Privacy Framework, with Standard Contractual Clauses as fallback. Loads only after the corresponding analytics or advertising choice, or after “Accept all”.

This list is kept current; a provider may be replaced by another of the same kind.

4. International transfers

Where data is transferred outside the European Economic Area, we rely on the following safeguards:

  • Adequacy decisions (Art. 45 GDPR) - applies to transfers to the UK, Switzerland, Israel, and other adequacy-listed countries;
  • Standard Contractual Clauses (Art. 46(2)(c)) - for transfers to other third countries where applicable;
  • Your explicit consent (Art. 49(1)(a) GDPR) - only for transfers that are not repetitive and are necessary for a specific situation you have agreed to. This basis is not used for systematic or regular transfers.

5. Your rights

Under GDPR / RODO you have the following rights:

  • Access (Art. 15) - request a copy of your data;
  • Rectification (Art. 16) - correct inaccurate or incomplete data;
  • Erasure (Art. 17) - "right to be forgotten", subject to legal retention obligations;
  • Restriction of processing (Art. 18) - limit how we use your data while a dispute is resolved;
  • Data portability (Art. 20) - receive your data in a structured machine-readable format;
  • Object (Art. 21) - to processing based on legitimate interests or direct marketing;
  • Withdraw consent at any time, for any processing based on consent - without affecting prior lawful processing;
  • Lodge a complaint with the Polish supervisory authority (Prezes Urzędu Ochrony Danych Osobowych (UODO)) or your local EU data protection authority.

Detailed information about your rights and how to exercise them is on our GDPR Rights page.

6. Automated decision-making and profiling

We do not make decisions about you that are based solely on automated processing and that produce legal or similarly significant effects on you. Where psychometric assessments are involved, results are interpreted by a qualified human professional before any recommendation is communicated.

7. Security

We implement technical and organisational measures appropriate to the risk: TLS encryption for data in transit, encryption at rest where supported by the platform, role-based access controls, regular access reviews, incident-response procedures, and personnel-confidentiality undertakings. Breach notification follows Art. 33–34 GDPR - within 72 hours to the supervisory authority where required, and without undue delay to you where the breach is likely to result in a high risk to your rights.

8. Contact us about this Privacy Policy

Email: [email protected] (subject: "Privacy request")

Post: Dutch Aviation Services Sp. z o.o., ul. Piotrkowska 222/3, 90-369 Łódź, Poland

We respond to data-subject requests within one calendar month, extendable by a further two months for complex requests (in which case we will tell you within the first month).

9. Supervisory authority

Prezes Urzędu Ochrony Danych Osobowych (UODO)

ul. Stawki 2, 00-193 Warszawa, Poland

https://uodo.gov.pl

10. Changes to this Policy

This Policy is Version 1.2, effective 25 September 2026. Material changes are notified by email to active customers; the current version and effective date are always shown at the top of this page.