Flying Blue+ Payment Method Privacy Notice

This is the privacy notice (“Notice”) of Pointspay Management FZCO ("Pointspay Management", “we”, “us”, “our”) in relation to the provision of our consumer services and our websites flyingblueplus-shopping@flyingblue.com and plus-secure@flyingblue.com (the “Site(s)”) in connection with the Flying Blue+ Payment Method (together “the Services”). This Notice sets out how we process personal information that you give to us, or that we may collect or otherwise process in the course of providing the Services to you.

1. Information About Us

1.1

Pointspay Management FZCO whose registered address is Dubai Airport Freezone Authority, PO Box 293805, Dubai United Arab Emirates is the controller with respect to processing pursuant to this Notice and the Site is owned and operated by it. For any questions you may have in relation with the processing of your personal data or when executing your data protection rights, you can contact us by email at: privacy@pointspay.com.

1.2

Our EU representative for data related queries is Loylogic AG Latvia branch, registration number: 40103284489, legal address: Ernesta Birznieka-Upīša iela 21, Rīga, LV-1011. If you have any questions about how we handle data with respect to this Notice you can contact us by email at: privacy@pointspay.com.

2. What this Notice covers

This Privacy Notice applies to our data processing in relation with your use of our Services. The Site may contain links to other Sites. Please note that we have no control over how your data is collected, stored, or used by other Sites and we advise you to check the privacy policies of any such Site before providing any data to them.

3. What Data do we collect?

3.1

Depending upon your use of our Services, we may collect some or all of the following personal and non-personal data (please also see section 6 on our use of Cookies and similar technologies):

  • personal details (e.g., name);
  • contact information (e.g., country of residence, e-mail address);
  • information on your use of Flying Blue+’s Payment Method (e.g., your shopping behaviour, your payment behaviour and your use of points or cash portion, invoicing and reporting details);
  • Flying Blue loyalty program account information (inc. user program profile details, Flying Blue Miles);
  • general payment information such as credit / debit card details;
  • technical information (e.g., IP address, web browser type and version, operating system; list of URLs starting with a referring Site, your activity on our Site, and the Site you exit to).

3.2

Such data may also include sensitive data, i.e., data that requests higher protection. We will usually not process such information unless you give your prior explicit consent thereto.

3.3

You are at no time obliged to provide us with your personal data. However, should you not wish to provide the information we ask you for you may not be able to use all our Services.

4. How We Use your Data and legal basis of processing

4.1

When provisioning our Services, we may use your data in order to:

  • provide you with our Services (incl. payment card transactions using the Flying Blue+ Payment Method);
  • co-ordinate with Flying Blue and merchants who are affiliated with the Flying Blue+ Payment Method (“Merchants”);
  • process transactions you have requested;
  • allow us to improve our services to you or to develop new services;
  • personalising and tailoring your experience on our Site;
  • reply to communications you send to us;
  • provide you with personalised marketing materials by email, telephone, SMS and/or by post, but only where you have given us your permission to do so.
  • analyse your use of our Site and gather feedback to enable us to continually improve our Site and personalise user experience;

4.2

Our use of your personal data will only be processed on a lawful basis, either because it is necessary for entering into or the performance of a contract with you, because you have consented to our use of your personal data, or because it reflects a legal requirement or is necessary for legitimate interests.

4.3

When we base processing of your personal data on legitimate interest, this primarily refers to our interest to (i) provide you with our Services, (ii) to run, monitor and improve our business activities (incl. cooperating with business partners and our holding company, Pointspay Holding AG, and its affiliates and subsidiaries), (iii) generating statistics and anonymous data about your use of the Services and (iv) facilitate business transactions and reorganizations impacting the structure of our business.

5. Automated decision making (incl. profiling)

5.1

"Automated individual decision making" relates to decisions which are based solely on automated means and which result in negative legal effects or other similarly negative effects on you. We will inform you separately if we make automated individual decisions and provided that such information is required by law.

5.2

"Profiling" means a process by which personal data is processed automatically to evaluate, analyse or predict personal aspects, e.g., personal preferences, interests, online shopping behaviour, location or movements. We carry out profiling, for example., when analysing purchasing behaviour.

We will process your personal data based on such processes, in particular in the context of our marketing activities or customer relationship management.

5.3

You have the right to object to the processing of your personal data. Please refer to section 9 below. Please note that we may be unable to provide the Services to you in case of such objection.

6.  Information about our use of cookies

6.1

A cookie is a small file of letters and numbers that we store on your browser or the hard drive of your computer if you agree. Cookies contain information that is transferred to your computer's hard drive. Our Site use cookies to distinguish you from other users of our Site. This helps us to provide you with a good experience when you browse our Site and also allows us to improve our Site.

6.2

Before cookies are placed on your computer or device, you will be shown a pop-up requesting your consent to set those cookies. By continuing to browse our Site or where you provide consent separately (for example for delivering targeted ads on other Sites you may visit), you are agreeing to our use of cookies.

6.3

We use the following cookies:

  • Strictly necessary cookies: These cookies are necessary for the Site to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.
  • Performance cookies: These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site and will not be able to monitor its performance.
  • Targeting cookies: These cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

6.4

Cookies are destroyed once they are no longer necessary for their purpose. You do not have to allow us to use cookies, and you can block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, whilst our use of them does not pose any risk to your privacy or your safe use of Flying Blue+’s Payment Method, it does enable us to continually improve Flying Blue+’s Payment Method, making it a better and more useful experience for you, and if you block all cookies you may not be able to access all or parts of our Site.

6.5

We may also use other technologies to collect information about the use of our Site, such as Local Storage, and similar technologies.

6.6

Our Site may contain links to third party Site some of which may also use cookies and other technologies. This Notice does not cover third party Site which will be subject to their own privacy and cookies policies. We do not have access to or control over cookies or other features used by such Site. Please contact them directly for more information about their privacy practices.

7. Google Analytics

7.1

This Site uses Google Analytics, a web analysis service of Google Inc. and Google LLC ("Google"). Google uses cookies and other technologies to collect and analyze information about the use of this Site and in order to provide services to us. Google may collect data about your browser, your provider, visited pages and duration of visits, your IP address, device identifiers (e.g., Android Advertising Identifier or Advertising Identifier for iOS) etc. The information generated about your use of this Site is usually transferred to a Google server in the USA and stored there. However, as IP anonymisation is activated on this Site, Google will shorten your IP address within the European Union or European Economic Area beforehand. In exceptional cases the full IP address will be transmitted to a Google server in the USA and shortened there. For these cases Google relies on the European Commission’s model contract clauses. On behalf of the operator of this Site, Google will use this information to evaluate your use of the Site, to compile reports on Site activities and to provide the Site operator with further services associated with Site and Internet use.

7.2

You may refuse the use of cookies by selecting the appropriate settings on your browser (see sec 6.4). You can also prevent Google from collecting the data generated by the cookie and relating to your use of the Site (including your IP address) and from processing this data by downloading and installing the browser plug-in available under the following link: https://tools.google.com/dlpage/gaoptout?hl=en.

7.3

We use Google Analytics to analyse and regularly improve the use of our Site. Through the obtained statistics we can improve our offer and make it more interesting for you as a user. For the exceptional cases in which personal data is transferred to the USA, Google relies on the European Commission’s model contract clauses.

7.4

Third Party Information: Google Dublin, Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001.

8. How we share your data

8.1

We may co-ordinate with third parties in the provision of your selected Services to you (e.g., your loyalty program provider(s), payment service providers, financial institutions, and suppliers). These parties may process your personal data to supply services to you on our behalf as well as for their own purposes. In that case, these parties act as separate controllers, and you are invited to review their privacy notices to learn more about their processing.

8.2

We may also share your data with other companies in our group for the provision of some of the Services, for example, payment processing as well as for their own purposes. This includes our holding company, Pointspay Holding AG, and its affiliates and subsidiaries.

8.3

In some cases, the third parties may require access to some or all of your data. Where any of your data is shared for such a purpose, we will take all reasonable steps to ensure that your data will be handled safely, securely, and in accordance with your rights, our obligations, and the obligations of the third party under the law.

8.4

We may share your personal data with third parties based on your separate consent.

8.5

We may, from time to time, expand or reduce our business and this may involve the sale and/or the transfer of control of all or part of our business. Any personal data that you have provided, where it is relevant to any part of our business that is being transferred, will be transferred along with that part and the new owner or newly controlling party will, under the terms of this Notice, be permitted to use that data only for the same purposes for which it was originally collected by us.

8.6

We may compile statistics about the use of our Site including data on traffic, usage patterns, user numbers, sales, and other information. We may from time to time share such data with third parties such as prospective investors, affiliates, partners, analytics service providers and advertisers. Data will only be shared and used within the bounds of the law.

8.7

In certain circumstances, we may be legally required to share certain data held by us, which may include your personal data, for example, where we are involved in legal proceedings, where we are complying with legal requirements, a court order, or a governmental authority.

8.8

In case that we share and transfer your personal data with third parties (incl. other group-companies) that are located outside of Switzerland and/or of the European Economic Area (“the EEA”) (e.g., United Arab Emirates or India but potentially world-wide ) we will take all reasonable steps to ensure that your data is treated as safely and securely as it would be under the data protection law applicable to respective processing in Switzerland or within the EEA. In such cases, we will ensure data protection with standard contractual clauses for data transfers to third countries issued and approved by the EU Commission and/or the Federal Data Protection and Information Commissioner (FDPIC), as accordingly amended and adapted to local circumstances. If you wish to receive a copy of these clauses, please contact us (cf. section 1 above). We may transfer personal data to such countries without standard contractual clauses where we are expressly authorized by applicable law, for example with your separate consent, where disclosure is directly connected with the conclusion or performance of certain contracts, for important reasons of public interest or to establish, exercise or defend legal claims.

9. Data protection rights

9.1

According to applicable law, you may have the right to:

  • request access to your personal information.
  • request correction of the personal information that we hold about you if it is inaccurate.
  • request erasure of your personal information if there is no good reason for us continuing to process it.
  • ask us to stop processing personal information (where we are relying on a legitimate interest) if you wish to object to processing on this ground.
  • withdraw your consent to processing of your personal data.
  • request the restriction of processing of your personal information.
  • request the transfer of your personal information to another party.
  • lodge a complaint with the competent data protection supervisory authority, the Data State Inspectorate, Latvia (Latvian Supervisory Authority).

9.2

If you wish to use one of your rights, you can e-mail us at: privacy@pointspay.com.

9.3

Servicing emails sent to you are triggered automatically when you use the Site, for example, when you make a purchase. If you do not wish to receive service triggered emails, you must stop using the Site.

10. Security

10.1

Securing your personal and non-personal information is very important to us and we take the necessary technical and organizational measures to ensure an adequate level of data protection appropriate to the risk that is related to a respective processing. In particular, all customer databases are held in a secure environment and (except for law enforcement authorities in limited circumstances), only our employees or other persons who need access to your information in order to perform their duties are allowed such access.t's U.S. Patent No. 7,698,185 and U.S. Patent No. 8,533,083.

10.2

Where you are using our Site, we attempt to provide for the secure transmission of your information from your computer to our servers by utilising encryption software. However, due to the inherent open nature of the Internet, we cannot guarantee that communications between you and us will be free from unauthorised access by third parties, such as hackers.

10.3

Our Site utilises SSL certificate-based encryption on pages where secure information is transmitted over the Internet. All critical information is encrypted using AES 256 algorithm and stored.

11. How long we store your personal data

We do not normally keep your personal data for any longer than three (3) months after you complete a transaction via the Services. We will however retain personal data for as long as we have a legitimate interest in the storage, e.g. if we need personal data to handle a customer servicing issue, for the enforcement of or the defence against claims, for archiving purposes and for guaranteeing IT security. We will retain your personal data as long as you do not withdraw your consent and it is subject to a legal retention obligation.

12. Privacy Notice Updates

We may change this Privacy Notice from time to time as we add new products and apps, as we improve our current offerings, and as technologies and laws change. Any changes will become effective upon our posting of the revised Privacy Notice on our affected Site. We will provide notice to you if these changes are material and, where required by applicable law, we will obtain your consent. Moreover, this notice will be provided by email or by posting notice of the changes consistent with applicable laws.

13. Site Owner

The entire contents of Site are owned by Pointspay Management FZCO and are protected by copyright (all rights reserved). The downloading or printing of individual pages or passages from the Site is only permitted if neither a copyright notice nor any other legally protected titles are removed. If you download data from the Site or reproduce it in any other way, all proprietary rights remain with Pointspay Management FZCO. The (complete or partial) reproduction, transmission (electronically or by other means), modification, linking or usage of the Site for public or commercial purposes is forbidden without the prior written agreement of Pointspay Management FZCO.

Last updated: 31st July, 2023