Privacy built around the journey.
Fly Me Now SRL is intended to be the Romanian controller for marketplace account and inquiry data. Its registered office, company/VAT registration and any appointed DPO details must be inserted and counsel-approved before commercial activation.
1. Contact and scope
This notice covers public website accounts, charter inquiries, membership applications, operator onboarding, support, security and legal-acceptance records. Privacy contact: privacy@nawaeurope.com.
2. Data we collect
- Identity and contact details, country and account credentials in one-way hashed form.
- Corporate/operator entity, registration, tax, AOC and operating-authority declarations.
- Itinerary, passenger count, preferences and communications. Do not submit passports or payment cards through public forms.
- Versioned legal acceptances, timestamps, session tokens stored only as hashes, login-attempt controls and recovery-request hashes.
- Later transaction phases may require contracts, passenger documents, payments and flight updates only through approved providers and access controls.
3. Purposes and legal bases
- Account and requested-service delivery: steps before a contract and performance of marketplace terms.
- Operator/corporate verification, platform security, fraud prevention and service improvement: legitimate interests, balanced against user rights.
- Compliance, sanctions, finance and record keeping: legal obligations where applicable.
- Optional marketing: consent, separately requested and withdrawable without affecting service.
GDPR transparency requirements include the information listed in Article 13 of Regulation (EU) 2016/679.
4. Recipients and international transfers
Data may be disclosed on a need-to-know basis to eligible licensed operators for a requested itinerary, hosting/security providers, professional advisers, e-signature vendors and licensed payment providers. Operator identity and applicable privacy role must be disclosed before passenger information is supplied. Transfers outside the EEA require an approved GDPR transfer mechanism and documented assessment.
5. Retention
Current engineering defaults are: public inquiries and applications up to 24 months; account data for the account lifetime plus up to 24 months; login/security controls up to 12 months; and acceptance, contract and financial evidence for the applicable statutory period. The definitive schedule requires Romanian counsel, tax and aviation-record review before paid activation. Data is deleted or irreversibly anonymised when no longer required.
6. Security
Controls include PBKDF2-SHA-256 salted password hashing, HttpOnly SameSite session cookies, hashed session tokens, login throttling, role-bound access, prepared database statements, restricted public APIs and versioned acceptance evidence. No system is risk-free; report suspected compromise to security@nawaeurope.com.
7. Your rights
Subject to law, you may request access, correction, deletion, restriction, portability or objection, withdraw consent, and complain to the competent supervisory authority. Romanian users may contact the National Supervisory Authority for Personal Data Processing (ANSPDCP). Identity verification may be required before fulfilling a request.
8. Automated decisions and children
Public intake uses validation and search ranking but does not make a solely automated decision with legal or similarly significant effect. The service is not intended for persons under 18.
9. Changes
Material changes receive a new version. Re-acknowledgement is requested when the processing or user relationship materially changes.
Published 22 July 2026 · controller-detail and counsel approval gate remains open
Return to account creation →