This English text is provided for convenience. The Italian version is the one that governs the contractual relationship and prevails in the event of any discrepancy.
1. Data controller
The data controller is AIR-GARDA S.R.L., with registered office at Via Giuseppe di Vittorio 121, 20097 San Donato Milanese (MI), Italy, VAT 01169980198, operator of the platform (the “Controller”).
The platform is supplied and operated by APPLICAZI.ONE di Niccolò Busetti, Castello 3593, 30122 Venice, Italy, VAT 04995600279, which acts as a processor under Article 28 of the Regulation and processes data solely on the documented instructions of the Controller.
2. Categories of data processed
For the booking of a catalogue flight, the identification and contact details of the person making the booking, the passengers’ names, the date and route of the flight and any notes entered in free-text fields are processed. The data needed for mandatory invoicing are also processed: address; for private customers resident in Italy, tax code; for private customers resident abroad, country of residence and tax identifier, if available; for businesses and professionals, name, country, VAT number or other tax identifier and, where applicable, recipient code or certified email address.
For bespoke flight requests, the contact details, the number of passengers, the requested date and route, the content of the message and the total weight of passengers and baggage are processed. The latter is a single figure for the entire aircraft, needed to calculate fuel, load and balance as an operational safety requirement, and is deleted within ninety days. If the quote is accepted and completed, the passengers’ names and the mandatory invoicing data described in the previous paragraph are also processed.
To evidence incoming payments, the amount, value date and transaction identifier communicated by the bank are processed. To evidence refunds made, the reason, amount, any amount retained and the outgoing transaction identifier are processed. Only the transaction identifier is retained as the bank reference, not names or payment descriptions.
Some fields on the website are free-text fields. Please do not enter health information in them: any assistance or reduced-mobility needs should be communicated to info@seaplaneinvenice.com before booking. Any such information nevertheless communicated is processed solely to assess the feasibility and safety of the flight, on the basis of the data subject’s explicit consent pursuant to Article 9(2)(a) of the Regulation; it is accessible only to personnel authorised by the Controller, to AELIA as an independent controller and to the pilot in command, and is deleted within thirty days.
During navigation, the systems running the website record the technical data necessary to serve the pages and protect the service: network address, browser type, requested resource, outcome and time of the request.
The cookies used by the website are described in the dedicated notice.
The provision of identification details, contact details, passengers’ names, invoicing data and — for bespoke flights — the total weight is necessary to organise and safely perform the flight and to issue the invoice: failure to provide them makes it impossible to complete the booking. Notes in free-text fields are optional and their absence does not affect the booking.
3. Purposes and legal bases
Booking data are processed by the Controller for the pre-contractual measures requested by the data subject and to enable the performance of the contract of carriage concluded with AELIA, pursuant to Article 6(1)(b) of the Regulation.
Invoicing data are processed and communicated to AELIA by the Controller as necessary for the performance of the requested service, pursuant to Article 6(1)(b) of the Regulation; AELIA processes them as an independent controller to comply with its legal obligations, pursuant to point (c) of the same provision.
The total weight of passengers and baggage is processed for the performance of the contract, in connection with the safety obligations incumbent on the carrier.
Access and security logs, the limitation of repeated access attempts, the verification of message delivery and site performance measurements are processed on the basis of the Controller’s legitimate interest, pursuant to Article 6(1)(f) of the Regulation, in protecting the service against unauthorised access and abuse, ascertaining the actual delivery of communications and maintaining the performance of the website. These are minimal, technical data; data subjects may object at any time pursuant to Article 21 of the Regulation.
Health or mobility information provided spontaneously is processed on the basis of the data subject’s explicit consent, which may be withdrawn at any time.
The Controller does not carry out direct marketing.
No automated decision-making or profiling within the meaning of Article 22 of the Regulation is carried out. The price calculated by the website derives from catalogue parameters identical for all users and does not depend on the identity of the requester.
4. Recipients
Data provided for the booking are communicated to AELIA S.r.l., with registered office at Via Santo Stefano 10, 40125 Bologna, Italy, VAT and tax code 02675111203, REA BO-458109, the recipient and air carrier that operates the flight and issues the invoice, for the performance of the requested service. The communication is necessary for the performance of the contract to which the data subject is party and in order to take steps at the data subject’s request prior to entering into a contract, and is based on Article 6(1)(b) of the Regulation.
AELIA processes the data received as an independent controller for the performance of the contract of carriage, pursuant to Article 6(1)(b) of the Regulation, and to comply with its own obligations concerning safety, invoicing and retention, pursuant to point (c) of the same provision.
The passengers’ names, the contact details of the person who made the booking, the date, time and itinerary are communicated to the pilot assigned to the flight for the sole purposes of preparing and performing the flight.
For the provision of the service, the Controller relies on suppliers processing data on its behalf as processors: Vercel for the running of the website and site performance measurements, Neon for the database, Resend for the dispatch of communications, Cloudflare for the domain and mail routing.
Data may also be communicated to the Controller’s advisers, bound by professional secrecy, and to public authorities in the cases provided for by law.
Except for the communications described in this section, data are not sold or communicated to third parties for purposes other than those stated in this notice.
5. Transfers to third countries
The website, the database and transactional mail run on infrastructure located in the European Union.
Some suppliers are companies established in the United States and may access data from abroad for technical support purposes. In such cases the transfer takes place on the basis of the standard contractual clauses adopted by the European Commission pursuant to Article 46(2)(c) of the Regulation.
6. Retention periods
| Category of data | Retention period |
|---|---|
| Passengers’ names, contact details, itinerary and booking notes | 2 years from the flight, then anonymised |
| Invoicing data | 12 months from the issue of the invoice |
| Accounting records of the booking, containing no identifying data | 10 years from the closure of the financial year |
| Incoming-payment and refund records, containing no identifying data | 10 years from the closure of the financial year |
| Total weight of passengers and baggage | 90 days from the flight, or from the request if the flight does not take place |
| Health or mobility information provided spontaneously | 30 days from the flight, or from the request |
| Quote requests without follow-up | 12 months from the last contact, then anonymised |
| Acceptances and consents | for the retention period of the data to which they relate |
| Security and operations log | 24 months |
| Service messages sent | 12 months, including delivery outcomes |
| Expired sessions | removed within 30 days |
| Vouchers | until expiry, then 12 months |
The criterion adopted is as follows: data capable of identifying the data subject are deleted or anonymised within two years; data retained for ten years contain no identifying elements. The two-year term corresponds to the limitation period for damages actions in air carriage; the ten-year term concerns exclusively the accounting records — amount, date, route and booking code — and incoming-payment and refund records — amount, value date, transaction identifier, reason, any retained amount and case code — subject to the retention obligation of Article 2220 of the Italian Civil Code, for which earlier deletion is not permitted, even at the data subject’s request. The invoice, containing the identification data in full, is retained by the issuing entity and not by this platform.
Where a dispute or a request from an authority is pending, the deletion of the data concerned is suspended until the matter is closed.
7. Security measures
The Controller adopts technical and organisational measures appropriate to the risk, including encryption, pseudonymisation where appropriate, access limitation and backups.
8. Payments
Payments do not pass through the platform. The Customer pays AELIA directly by instant bank transfer or, in the cases stated in the Terms, in cash within the statutory limit. For bank transfers, the platform communicates the account details without processing payment-instrument data.
9. Service communications
Service communications — confirmations, rescheduling notices, reminders, quotes — are sent through the transactional mail provider, which returns the delivery outcome to the Controller: delivered, bounced or reported as unwanted. This information is processed for the sole purpose of detecting the non-delivery of relevant communications.
Neither the opening of messages nor clicks on the links they contain are recorded.
10. Rights of the data subject
Data subjects have the right to obtain access to their data, rectification, erasure, restriction of processing and portability of the data in a structured, commonly used and machine-readable format — including the right to transmit them to another controller and, where technically feasible, to have them transmitted directly — and to object to processing based on legitimate interest, pursuant to Articles 15 to 21 of the Regulation. Where processing is based on consent, consent may be withdrawn at any time, without affecting the lawfulness of processing prior to withdrawal.
Requests relating to processing carried out by the Controller should be addressed to info@seaplaneinvenice.com. A response is provided within one month of receipt; in cases of particular complexity the term may be extended by two months, with reasoned notice to the data subject within the first month. Rights relating to processing carried out by AELIA as an independent controller may be exercised directly against it at the registered office indicated in section 4.
Accounting records and incoming-payment and refund records, containing no identifying data, are retained for the ten-year period prescribed by law and cannot be deleted earlier; in other cases where deletion is not possible, the data are anonymised.
11. Complaints
Data subjects who consider the processing to infringe the Regulation may lodge a complaint with the Italian supervisory authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, protocollo@pec.gpdp.it, www.garanteprivacy.it) or with the supervisory authority of their Member State of residence, without prejudice to the right to bring proceedings before the courts.
12. Version and changes
This notice is version 2026-08-12.2. Compared with version 2026-08-12.1, it makes the information on processing more concise without changing the Controller, recipients, purposes, legal bases, categories of data, retention periods, rights or transfers. The version in force at the time of booking is recorded with it and its text is provided on request. Substantial changes are notified to data subjects with a booking in progress.