Skip to content
Seaplanein Venice
  • The experience
  • The aircraft
  • Bespoke
  • FAQ
  • Private area
English▾
Check availability
English▾
Menu
  • The experience
  • The aircraft
  • Bespoke
  • FAQ
  • Private area
Check availability

Privacy

Privacy notice

This English text is provided for convenience. The Italian version is the one that governs the contractual relationship and prevails in the event of any discrepancy.

1. Data controller

The data controller is AIR-GARDA S.R.L., with registered office at Via Giuseppe di Vittorio 121, 20097 San Donato Milanese (MI), Italy, VAT 01169980198, operator of the platform (the “Controller”).

The platform is supplied and operated by APPLICAZI.ONE di Niccolò Busetti, Castello 3593, 30122 Venice, Italy, VAT 04995600279, which acts as a processor under Article 28 of the Regulation and processes data solely on the documented instructions of the Controller.

2. Categories of data processed

For the booking of a catalogue flight, the identification and contact details of the person making the booking, the passengers’ names, the date and route of the flight and any notes entered in free-text fields are processed. The number of minors on board and the total weight of passengers and baggage are also processed; the latter is a single figure for the entire aircraft. Both are required, as operational safety requirements, to calculate fuel, load and balance and to prepare the flight. They are communicated to the pilot in command assigned to the flight and deleted within ninety days. No further identifying data relating to minors are processed beyond the name already required for each passenger. The data needed for mandatory invoicing are also processed: address; for private customers resident in Italy, tax code; for private customers resident abroad, country of residence and tax identifier, if available; for businesses and professionals, name, country, VAT number or other tax identifier and, where applicable, recipient code or certified email address.

For bespoke flight requests, the contact details, the number of passengers, the requested date and route, the content of the message, the number of minors on board and the total weight of passengers and baggage are processed. The latter is a single figure for the entire aircraft. Both are required, as operational safety requirements, to calculate fuel, load and balance and to prepare the flight. They are communicated to the pilot in command assigned to the flight and deleted within ninety days. No further identifying data relating to minors are processed beyond the name already required for each passenger. If the quote is accepted and completed, the passengers’ names and the mandatory invoicing data described in the previous paragraph are also processed.

To evidence incoming payments, the amount, value date and transaction identifier communicated by the bank are processed, together with documentary evidence and verified links to the relevant tax documents. Multiple evidence items and documents are supported, including advance invoices, balances and variation notes, together with their revisions. To evidence refunds made, the reason, amount, any amount retained and the outgoing transaction identifier are processed. Only the transaction identifier is retained as the bank reference, not names or payment descriptions.

Some fields on the website are free-text fields. Please do not enter health information in them: any assistance or reduced-mobility needs should be communicated to info@seaplaneinvenice.com before booking. Any such information nevertheless communicated is processed solely to assess the feasibility and safety of the flight, on the basis of the data subject’s explicit consent pursuant to Article 9(2)(a) of the Regulation; it is accessible only to personnel authorised by the Controller, to AELIA as an independent controller and to the pilot in command, and is deleted within thirty days.

During navigation, the systems running the website record the technical data necessary to serve the pages and protect the service: network address, browser type, requested resource, outcome and time of the request.

The cookies used by the website are described in the dedicated notice.

The provision of identification details, contact details, passengers’ names, invoicing data, the number of minors on board and the total weight of passengers and baggage is necessary to organise and safely perform the flight and to issue the invoice: failure to provide them makes it impossible to complete the booking. Notes in free-text fields are optional and their absence does not affect the booking.

In the broker portal, the organisation’s legal name and code are processed and, for each authorised user, the display name, email address, role, credential stored as a non-reversible cryptographic hash, sessions and access records. For requests and purchases of credits, minutes and flight days, the product, quantity, status, dates, price, documented taxes, commercial reference, receipts and linked tax documents, requesting user, and movements of available, reserved, consumed or released units are processed. For flight days, we also process Nicelli closing times and revisions, multi-flight programmes, manifests received from the broker, assignments, actual-flight reports and durations, cancellations with receipt time, start time and derived notice, the administrative per-organisation count of cancellations with less than 48 hours’ notice, weather decisions and annotations of voucher agreements, together with their revisions. When a broker books for one of its customers, we receive indirectly from the organisation and the relevant user the contact person’s first name, surname, email address and telephone number, the passengers’ names, selected experience, date and time, number of minors and total weight of passengers and baggage; we also record the organisation and account from which the booking originated. The broker declares that it is authorised to transmit these data and must make this notice available to the data subjects. The broker form does not collect the customer’s invoicing data.

3. Purposes and legal bases

Booking data are processed by the Controller for the pre-contractual measures requested by the data subject and to enable the performance of the contract of carriage concluded with AELIA, pursuant to Article 6(1)(b) of the Regulation.

Invoicing data are processed and communicated to AELIA by the Controller as necessary for the performance of the requested service, pursuant to Article 6(1)(b) of the Regulation; AELIA processes them as an independent controller to comply with its legal obligations, pursuant to point (c) of the same provision.

The number of minors on board and the total weight of passengers and baggage are processed for the performance of the contract, in connection with the safety obligations incumbent on the carrier.

Access and security logs, the limitation of repeated access attempts, the verification of message delivery and site performance measurements are processed on the basis of the Controller’s legitimate interest, pursuant to Article 6(1)(f) of the Regulation, in protecting the service against unauthorised access and abuse, ascertaining the actual delivery of communications and maintaining the performance of the website. These are minimal, technical data; data subjects may object at any time pursuant to Article 21 of the Regulation.

Health or mobility information provided spontaneously is processed on the basis of the data subject’s explicit consent, which may be withdrawn at any time.

The Controller does not carry out direct marketing.

No automated decision-making or profiling within the meaning of Article 22 of the Regulation is carried out. The price calculated by the website derives from catalogue parameters identical for all users and does not depend on the identity of the requester.

4. Recipients

Data provided for the booking are communicated to AELIA S.r.l., with registered office at Via Santo Stefano 10, 40125 Bologna, Italy, VAT and tax code 02675111203, REA BO-458109, the recipient and air carrier that operates the flight and issues the invoice, for the performance of the requested service. The communication is necessary for the performance of the contract to which the data subject is party and in order to take steps at the data subject’s request prior to entering into a contract, and is based on Article 6(1)(b) of the Regulation.

AELIA processes the data received as an independent controller for the performance of the contract of carriage, pursuant to Article 6(1)(b) of the Regulation, and to comply with its own obligations concerning safety, invoicing and retention, pursuant to point (c) of the same provision.

The passengers’ names, the contact details of the person who made the booking, the date, time and itinerary are communicated to the pilot assigned to the flight for the sole purposes of preparing and performing the flight.

For the provision of the service, the Controller relies on suppliers processing data on its behalf as processors: Vercel for the running of the website and site performance measurements, Neon for the database, Resend for the dispatch of communications, Cloudflare for the domain and mail routing.

Data may also be communicated to the Controller’s advisers, bound by professional secrecy, and to public authorities in the cases provided for by law.

Except for the communications described in this section, data are not sold or communicated to third parties for purposes other than those stated in this notice.

5. Where data is processed, and transfers to third countries

The application functions of the website run in Frankfurt, Germany. The production database is hosted in the Frankfurt region of the European Union. Transactional mail is sent from Ireland.

Some suppliers are companies established in the United States and process part of the data there beyond technical support activities. In particular, the transactional mail provider processes message content, recipient addresses, the related metadata and delivery logs in the United States; the application infrastructure provider stores technical logs and backups there, which may be replicated across several regions.

Those transfers take place on the basis of the standard contractual clauses adopted by the European Commission pursuant to Article 46(2)(c) of the Regulation, as included in the data processing agreements entered into with the suppliers; where a supplier adheres to the Data Privacy Framework, the corresponding adequacy decision also applies, limited to the services covered by that certification.

An up-to-date list of suppliers, with the service provided and the place of processing, is available on request at the contact details given in section 1.

6. Retention periods

6. Retention periods
Category of dataRetention period
Passengers’ names, contact details, itinerary and booking notes2 years from the flight or, for cancelled bookings, from cancellation, then anonymised
Invoicing data12 months from the issue of the invoice
Accounting records of the booking, containing no identifying data10 years from the closure of the financial year
Incoming-payment and refund records, containing no identifying data10 years from the closure of the financial year
Number of minors on board and total weight of passengers and baggage90 days from the flight, or from the request if the flight does not take place
Health or mobility information provided spontaneously30 days from the flight, or from the request
Quote requests without follow-up12 months from the last contact, then anonymised
Acceptances and consentsfor the retention period of the data to which they relate
Security and operations log24 months
Service messages sent12 months, including delivery outcomes
Expired sessionsremoved within 30 days
Vouchersuntil expiry, then 12 months
Broker purchases, incoming-payment evidence, document links and tax revisions10 years from the closure of the financial year; after redaction, only evidence containing no identifying data is retained
Flight-day programmes, manifests, actual-flight reports and revisions2 years from completion of the day or case, subject to obligations and disputes
Flight-day cancellations, receipts, timestamps and derived notice2 years from termination of the session; structural links and the non-identifying count remain with the ledger
Weather voucher agreements and revisions2 years from the later of the weather closure and the agreement’s latest registration or revision; longer if disputed

The criterion adopted is as follows: data capable of identifying the data subject are deleted or anonymised within two years; data retained for ten years contain no identifying elements. The two-year term corresponds to the limitation period for damages actions in air carriage; the ten-year term concerns exclusively the accounting records — amount, date, route and booking code — and incoming-payment and refund records — amount, value date, transaction identifier, reason, any retained amount and case code — subject to the retention obligation of Article 2220 of the Italian Civil Code, for which earlier deletion is not permitted, even at the data subject’s request. The invoice, containing the identification data in full, is retained by the issuing entity and not by this platform.

Where a dispute or a request from an authority is pending, the deletion of the data concerned is suspended until the matter is closed.

7. Security measures

The Controller adopts technical and organisational measures appropriate to the risk, including encryption, pseudonymisation where appropriate, access limitation and backups.

8. Payments

Payments do not pass through the platform. The Customer pays AELIA directly by instant bank transfer or, in the cases stated in the Terms, in cash within the statutory limit. For bank transfers, the platform communicates the account details without processing payment-instrument data.

9. Service communications

Service communications — confirmations, rescheduling notices, reminders, quotes — are sent through the transactional mail provider, which returns the delivery outcome to the Controller: delivered, bounced or reported as unwanted. This information is processed for the sole purpose of detecting the non-delivery of relevant communications.

Neither the opening of messages nor clicks on the links they contain are recorded.

10. People who access the platform for professional reasons

This section concerns people who sign in to the reserved area for professional reasons: crew assigned to flights, members of the referral programme, people who administer the platform and people authorised by a broker organisation. For customer and passenger data transmitted by the broker, this notice is also provided pursuant to Article 14 of the Regulation: the source and categories of data are stated in section 2. The other sections apply so far as they are relevant.

The data processed are first name and surname or display name, email address and telephone number; personal credentials, of which the password is stored only as a non-reversible cryptographic hash; the second-factor authentication secret, where enabled; open sessions and the related access records; and acceptance of the applicable terms, with the version and time of acceptance. For crew, declared availability, flight assignments, programmes and actual-flight reports are also processed; for members of the referral programme, the assigned code, bookings attributed to it and bank details needed to settle the fee; for brokers, the organisation’s legal name and code, the role of each individual account, requests and purchases of credits, minutes and days, incoming-payment evidence and document links, unit movements, programmes and manifests transmitted, bookings, cancellations and rescheduling made for customers, and annotations of weather agreements.

Data are processed to provide access to the reserved area and to perform the relationship or take requested pre-contractual steps, pursuant to Article 6(1)(b) of the Regulation, where the data subject is party to that relationship; where the person acts for their organisation, the processing of their contact and role data is based on the legitimate interests of the Controller and the organisation in managing the B2B relationship, pursuant to point (f). Access security and reconstruction of operations are based on the same legitimate interest; commercial management of packages is based on performance of the relationship, and the related accounting and tax obligations on point (c). Customer and passenger data transmitted by the broker are processed to arrange and perform the service pursuant to point (b), or, where the data subject is not party to the relationship, for the legitimate interests of the Controller, the broker and the recipient of the service in fulfilling the booking, pursuant to point (f); the legal bases relating to flight safety stated in sections 3 and 4 continue to apply.

Within a broker organisation, commercial and booking data are visible only to authorised individual accounts of that same organisation, within the limits of their role, and not to other brokers. Operational data relating to customers and passengers are accessible to the administration and are communicated to AELIA and the assigned pilot to the extent necessary to prepare and perform the flight. The other recipients and suppliers indicated in sections 4 and 5 continue to apply.

Profile data are retained for the duration of the relationship or authorisation and for ninety days after the relevant relationship or authorisation ends. The same rule applies to the broker organisation’s legal name and code after its deactivation; redaction is deferred for as long as there are active users, open commercial requests, available or reserved units, disputes or requests from an authority. Crew availability not linked to a booking is retained for twelve months from the end of the interval. For bookings made by a broker, identification and contact data follow the two-year period, while the number of minors and total weight follow the ninety-day period stated in section 6. Package requests and purchases and unit movements remain available for the duration of the relationship and the related obligations; once profiles have been redacted, only commercial or accounting evidence containing no identifying elements is retained for ten years from the closure of the relevant financial year. Expired sessions are removed within thirty days and the security and operations log is retained for twenty-four months.

The rights and complaint procedure set out in sections 11 and 12 apply.

11. Rights of the data subject

Data subjects have the right to obtain access to their data, rectification, erasure, restriction of processing and portability of the data in a structured, commonly used and machine-readable format — including the right to transmit them to another controller and, where technically feasible, to have them transmitted directly — and to object to processing based on legitimate interest, pursuant to Articles 15 to 21 of the Regulation. Where processing is based on consent, consent may be withdrawn at any time, without affecting the lawfulness of processing prior to withdrawal.

Requests relating to processing carried out by the Controller should be addressed to info@seaplaneinvenice.com. A response is provided within one month of receipt; in cases of particular complexity the term may be extended by two months, with reasoned notice to the data subject within the first month. Rights relating to processing carried out by AELIA as an independent controller may be exercised directly against it at the registered office indicated in section 4.

Accounting records and incoming-payment and refund records, containing no identifying data, are retained for the ten-year period prescribed by law and cannot be deleted earlier; in other cases where deletion is not possible, the data are anonymised.

12. Complaints

Data subjects who consider the processing to infringe the Regulation may lodge a complaint with the Italian supervisory authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, protocollo@pec.gpdp.it, www.garanteprivacy.it) or with the supervisory authority of their Member State of residence, without prejudice to the right to bring proceedings before the courts.

13. Version and changes

This notice is version 2026-09-26.1 and has been prepared for publication. Compared with version 2026-09-01, it describes incoming-payment evidence and document links, purchases and uses of broker flight days, multi-flight programmes and received manifests, actual-flight reports, cancellations with receipt time and derived notice, the administrative per-organisation count and annotations of weather agreements, together with the relevant revisions and retention. It does not change the Controller or the rights of data subjects. Version 2026-09-01 retains its effective date until this notice is published; the new version’s actual effective time will be recorded on release. The version in force at the time of booking is recorded with it and its text is provided on request. Substantial changes are notified to data subjects with a booking in progress.

Seaplanein Venice
  • The experience
  • Bespoke flights
  • Empty legs
  • Book
  • Manage your booking
  • Private area
  • Privacy
  • Cookies
  • Terms and conditions
  • Contact

Flights are sold and operated by AELIA s.r.l. · Via Santo Stefano 10, 40125 Bologna, Italy · VAT 02675111203 · REA BO-458109

Website operated by AIR-GARDA S.R.L. · VAT 01169980198 · Information and assistance: info@seaplaneinvenice.com

Images and animations are for illustrative purposes.

© Seaplane in Venice

Experience in Italian and English