FlyHappy Privacy Policy

Privacy overview and scope

This policy explains how FlyHappy handles personal information when someone searches the website, asks for a fare, contacts the booking team or progresses toward ticketing. The information is intended to reflect the systems, booking processes and supplier relationships used by the business.

The purpose of a privacy notice is transparency. The final wording should describe the data that is actually collected and the tools that are actually used rather than listing generic services that do not form part of the business.

Information you may provide

A visitor can provide a name, email address, telephone number, origin, destination, dates, passenger count, cabin preference and free-text questions. If a booking progresses, additional passenger information can become necessary for reservation and ticketing.

FlyHappy should collect information in stages. A basic fare search does not need passport numbers or payment-card information. More specific information should be requested only when it is genuinely required for the service.

Technical and website information

Servers and security tools may receive IP address, browser, device, referring page and basic log information. Optional analytics or advertising tools may collect additional data when enabled.

The cookie banner and policy should match the technologies deployed on the website. If non-essential analytics or advertising cookies require consent, they should not be activated before the visitor has a meaningful choice.

How enquiry information is used

Information supplied for a fare request can be used to respond, search suitable itineraries, prepare a quote, explain fare conditions and progress a booking when the traveller asks to continue.

The business should avoid using booking enquiries for unrelated marketing unless it has an appropriate lawful basis and has given the individual the information or choice required by law.

Sharing with travel suppliers

When a customer decides to book, relevant passenger and itinerary information may need to be shared with airlines, consolidators, reservation systems, payment providers or other suppliers involved in fulfilling the request.

Only information that is needed for the booking should be shared. This privacy notice describes the main categories of recipients involved in providing flight-booking assistance and should be kept aligned with the booking systems actually used by FlyHappy.

Lawful bases

Processing can rely on different lawful bases depending on the activity. Steps taken at a customer’s request before a contract, performance of a booking contract, legal obligations, legitimate interests and consent can all be relevant in different circumstances.

FlyHappy should keep each major processing activity aligned with an appropriate lawful basis and review this position when business processes materially change.

International transfers

International aviation can involve suppliers outside the United Kingdom. Passenger information needed for an itinerary may therefore be processed in other countries depending on the airline and reservation chain.

Where personal information is transferred internationally, FlyHappy should use any safeguards required by applicable UK data-protection law and keep this policy aligned with the suppliers involved.

Retention and deletion

Data should be kept only for as long as there is a valid booking, legal, accounting, dispute-resolution or service reason. An enquiry that never becomes a booking may justify a shorter retention period than a completed ticket record.

FlyHappy should use documented retention periods rather than keeping enquiries indefinitely. Backups and archived systems should be considered as part of that process.

Security

Reasonable measures can include encrypted connections, strong passwords, role-based access, secure backups, software updates and processes for handling incidents. No website should promise absolute security.

If a breach occurs, the business should follow applicable notification and response requirements. Security claims on the website should describe real controls rather than marketing language.

Your rights

Depending on the circumstances, UK data-protection law can provide rights of access, correction, deletion, restriction, objection, portability and withdrawal of consent. Not every right applies to every processing activity.

The final policy should provide a verified privacy contact and explain that individuals can also raise concerns with the UK Information Commissioner’s Office where applicable.

Other passengers and children

A family or group organiser may provide information about other passengers. The person making the request should have an appropriate reason and authority to supply those details.

Information about children and any sensitive data should be handled with extra care, and the booking process should avoid collecting more than is required for the service.

Policy updates

The privacy notice should be updated when the site adds material new processing such as customer accounts, live GDS integration, payment tools, a CRM or new advertising technology.

FlyHappy should review this policy whenever its company details, processors, retention practices or booking technology change, and the policy should show a current revision date.