Effective Date: May 7, 2025
This GDPR Privacy Notice (“Notice”) forms part of the Air1network Privacy Policy and applies to the processing of personal data of individuals located in the European Economic Area (EEA) and the United Kingdom (UK) by Air1network LLC, operating as Air1network.us (“Air1network,” “we,” “us,” or “our”).
If there is any conflict between this Notice and our general Privacy Policy, this Notice governs for EEA/UK residents.
If you are located outside the EEA or UK, please refer to our general Privacy Policy.
Controller Details
Air1network LLC is the data controller for personal data collected through Air1network.us and related booking channels.
Contact Information:
Email: support@Air1network.us
Phone: +1-844-414-9223
Lawful Bases for Processing
We process personal data only where a lawful basis applies, including:
Contract (Art. 6(1)(b)) – to complete bookings, issue tickets, manage reservations.
Legal Obligation (Art. 6(1)(c)) – tax compliance, fraud reporting, accounting rules.
Legitimate Interests (Art. 6(1)(f)) – platform security, fraud prevention, service improvements.
Consent (Art. 6(1)(a)) – marketing subscriptions or optional services.
We do not use automated decision-making that produces legal or significant effects.
International Transfers
Your personal data may be stored or processed in the United States and other jurisdictions.
We use the following safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- UK International Data Transfer Addendum
- Additional technical and contractual protections
Data Privacy Framework (DPF) Notice:
Air1network may pursue DPF certification in the future.
If certified, our listing will appear at:
https://www.dataprivacyframework.gov/
Until certification occurs, we rely on SCCs and equivalent measures.
Transfers to airlines, hotels, and suppliers outside the EEA/UK are permitted under GDPR Art. 49(1)(b)–(c), as they are necessary for performing your travel contract or fulfilling your request.
Data Retention
We retain personal data only for as long as necessary for the purposes described.
Typical retention periods include:
- Booking and transaction records: 6 years (required for tax and audit laws)
- Customer service communications: Up to 3 years
- Marketing preferences: Until consent is withdrawn
- Fraud prevention records: As required by security obligations
When retention is no longer required, data is securely deleted or anonymized.
Information Security
Air1network implements technical and organizational measures including:
- SSL/TLS encryption
- PCI-DSS-compliant payment processing
- Access controls and authentication
- Secure server environments and monitoring
- Logging of IP addresses and system activity for security purposes
While no system is completely secure, we take reasonable steps to protect personal data.
Government Access Requests
We may disclose personal data when legally required to comply with:
- Court orders
- Law enforcement requests
- Regulatory inquiries
- National security requirements
Such disclosures are limited to what the law strictly requires.
Corporate Restructuring
If Air1network undergoes a merger, acquisition, restructuring, or sale of assets, personal data may be transferred to the successor organization under equivalent privacy protections.
Your GDPR / UK GDPR Rights
EEA and UK individuals may exercise the following rights:
- Access - request a copy of your data
- Rectification - correct inaccurate information
- Erasure - request deletion when legally permitted
- Restriction - limit processing under certain conditions
- Portability - receive data in machine-readable format
- Objection - stop processing based on legitimate interest
- Withdraw Consent - stop processing where consent was the lawful basis
To exercise your rights:
Email: support@Air1network.us (Subject: “GDPR Notice”)
We may request identity verification.
Direct Marketing & Legitimate Interest Objections
You may object to direct marketing at any time.
Marketing emails include an “unsubscribe” link.
Administrative communications (booking confirmations, itinerary updates) cannot be opted out of, as they are required to provide the service.
Right to Lodge a Complaint
You may submit a complaint to your local Data Protection Authority.
EU authority list:
https://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm
UK ICO: https://ico.org.uk/
Minors
Air1network does not knowingly collect personal data from individuals under 18 years of age.
Onward Transfers to Third Parties
We may share personal data with:
- Service providers acting as processors
- Travel suppliers (airlines, hotels, rental car companies)
- Analytics or IT infrastructure vendors
Processors are bound by contracts requiring GDPR-equivalent protections.
We do not share sensitive personal data without explicit opt-in consent.
Updates to This Notice
We may update this Notice periodically.
The “Effective Date” above reflects the latest revision.
Continued use of the website after updates constitutes acceptance.
Contact Us
For GDPR inquiries:
Email: support@Air1network.us (Subject: “GDPR Notice”)
Phone: +1-844-414-9223
Disclosure: Air1network is an independent online travel agency and is not affiliated with or endorsed by any airline. We may charge our own service fees in addition to airline or supplier fees. Prices, rules, and availability are subject to airline terms and conditions.