Privacy Policy
Last updated: 2 August 2026 · Effective from: 1 January 2025
AerQio is committed to protecting your personal data. This policy explains what data we collect, why we collect it, how we use it, and the rights you have over it. We process data in accordance with the General Data Protection Regulation (GDPR) and applicable national data protection law.
Data controller
The data controller for personal data collected through the AerQio platform and website is AerQio ("we", "us" or "AerQio"). You can contact us at any time regarding your personal data:
Data we collect
Depending on how you interact with AerQio, we may collect the following categories of personal data:
Account data
First name, last name, email address, password (hashed), role within your agency.
Agency data
Agency trading name, legal name, tax/VAT number, registered address, IATA code (if applicable), logo.
Booking and client data
Passenger names, contact details, passport numbers, travel dates, routes, booking references — entered by your agency into the platform.
Payment data
Billing address, subscription plan. Card details are processed directly by our payment provider (Redsys/PayGold); we do not store full card numbers.
Usage and technical data
IP address, browser type, device information, pages visited, features used, session duration, error logs.
Communications data
Messages sent through our contact form or to our support email.
How we collect data
We collect personal data through the following means:
- Directly from you when you register, complete forms, or contact us.
- Automatically via cookies and similar technologies when you browse our website or use the platform (see Section 11).
- From your use of the platform — booking records, client profiles and invoices you create.
- From payment providers when a transaction is processed.
Purpose and legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the SaaS service and managing your account | Art. 6(1)(b) — performance of contract |
| Processing payments and managing subscriptions | Art. 6(1)(b) — performance of contract |
| Sending service communications (updates, incidents, invoices) | Art. 6(1)(b) — performance of contract |
| Complying with legal and tax obligations | Art. 6(1)(c) — legal obligation |
| Improving the platform via anonymised analytics | Art. 6(1)(f) — legitimate interests |
| Sending marketing communications | Art. 6(1)(a) — consent |
| Preventing fraud and abuse | Art. 6(1)(f) — legitimate interests |
Data sharing and processors
We do not sell or rent your personal data. We may share it with carefully selected third-party processors solely to deliver the contracted service:
- Cloud infrastructure and database hosting providers.
- Payment gateway: Redsys / PayGold for card transaction processing.
- Email delivery providers for transactional and notification emails.
- Analytics tools (anonymised usage data only).
- Amadeus GDS for flight search and ticket issuance (booking-specific data).
All processors are bound by data processing agreements and are prohibited from using your data for any purpose other than delivering their respective services to us. Client data entered by one agency account is never accessible to or shared with any other AerQio customer.
WhatsApp Business integration
AerQio optionally integrates with the WhatsApp Business Platform (provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland) to allow travel agencies to communicate with their clients via WhatsApp directly from the AerQio dashboard.
When your agency connects a WhatsApp Business account through AerQio, the following data is processed:
WhatsApp account credentials
Your WhatsApp Business Account ID (WABA ID), phone number ID, and access token — used solely to send and receive messages on your agency's behalf. Access tokens are encrypted at rest.
Message content
Text messages sent and received through your connected WhatsApp Business number. Messages are stored within AerQio's database and are accessible only to authorised users of your agency account.
Contact phone numbers
Phone numbers of the clients who message your agency. We store these to maintain conversation threads. We do not use them for any purpose other than displaying your inbox.
What we do not do: We do not read, analyse, or use WhatsApp message content for advertising or any purpose beyond displaying it in your agency's inbox. We do not share WhatsApp message content with any third party other than Meta as the infrastructure provider.
Meta's role: Meta acts as a data processor for message delivery. Message transmission is subject to WhatsApp Business Policy and WhatsApp Business Privacy Policy. Your end-clients who message your agency are subject to WhatsApp's standard consumer privacy policy.
Disconnecting: You can disconnect your WhatsApp Business account from AerQio at any time from the CRM → WhatsApp settings. Upon disconnection, your access token is invalidated in our system. Stored message history can be deleted on request.
Legal basis: Processing of WhatsApp data is based on Art. 6(1)(b) GDPR (performance of the service contract) for the agency user, and Art. 6(1)(f) GDPR (legitimate interests of the agency in communicating with their clients).
International transfers
Where we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent mechanisms recognised under applicable law. You may request details of the specific safeguards by contacting us.
Data retention
We retain personal data only for as long as necessary for the purposes described in this policy, or as required by law:
- Account and agency data: retained for the duration of the subscription plus 30 days after termination, then permanently deleted.
- Booking and client data: retained according to your subscription period and any applicable legal retention requirements for financial records (typically 5–7 years).
- Payment transaction records: retained for the period required by tax and accounting law.
- Technical and usage logs: retained for up to 12 months.
- Marketing consent records: retained until consent is withdrawn.
Your rights
Under GDPR you have the following rights regarding your personal data. To exercise any of them, contact us at support@aerqio.com. We will respond within 30 days.
Access
Request a copy of the personal data we hold about you.
Rectification
Ask us to correct inaccurate or incomplete data.
Erasure
Request deletion of your data where there is no overriding legal basis for us to retain it.
Portability
Receive your data in a structured, machine-readable format or ask us to transfer it to another controller.
Restriction
Ask us to restrict processing of your data in certain circumstances.
Objection
Object to processing based on legitimate interests or for direct marketing purposes.
Withdraw consent
Where processing is based on consent, withdraw it at any time without affecting prior processing.
Complaint
Lodge a complaint with your national data protection authority (e.g. ICO in the UK, AEPD in Spain).
Security measures
We apply appropriate technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration or destruction. These include:
- All data transmitted between your browser and our servers is encrypted using HTTPS/TLS.
- Passwords are stored using strong one-way cryptographic hashing.
- Two-factor authentication (2FA/TOTP) is available for all user accounts.
- Database access is restricted to authorised personnel and services only.
- Regular automated backups with tested restore procedures.
- Automated monitoring and alerting for suspicious activity.
Children's privacy
AerQio is a business platform intended for professional use by travel agencies. It is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
Cookies
Our website and platform use cookies and similar technologies. For full details of the cookies we use, their purpose and how to manage your preferences, please see our Cookie Policy.
Marketing communications
We may send you marketing emails about new features, product updates and offers if you have given us your consent. You can withdraw consent and unsubscribe from marketing communications at any time by clicking the unsubscribe link in any marketing email or by emailing us.
Unsubscribing from marketing emails does not affect service-related communications (invoices, incident notifications, account alerts), which we send under our contractual basis.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will notify you of any material changes by email and by updating the "Last updated" date at the top of this page. We encourage you to review this policy periodically.
Contact and complaints
For any questions, requests or complaints relating to your personal data or this Privacy Policy, please contact us:
If you are not satisfied with our response, you have the right to lodge a complaint with your national supervisory authority — for example the ICO (UK) at ico.org.uk or the AEPD (Spain) at aepd.es.