Skip to main content
RecoupLane
How it worksSample packPricingAirlinesTrust
Free checklistContact
Navigate
How it worksSample packPricingAirlinesTrustContact
Open the free checklist

Privacy and control

Privacy notice.

What is active now, what remains inactive and how to exercise your rights.

Effective 9 August 2026 · Policy free-beta-2026-08-09-v1 · Approval owner-approved-free-beta-2026-08-09-v2

1. Controller and contact

The controller is NOVOGROUP SYSTEMS S.R.L., Municipiul Zalău, Strada Gheorghe Șincai nr. 38A, județ Sălaj, 450077, România, CUI 39736070, J31/66/2023.

Privacy questions and rights requests go to contact@recouplane.com. No formal data protection officer (DPO) is designated for the current beta. The same monitored address is the privacy contact.

2. Current scope

The public information and browser-only checklist are available globally. Private free-beta activation is limited to adults declaring residence in the European Union, the European Economic Area or the United States. The United Kingdom, Switzerland and other markets are excluded from private activation.

Private intake is currently unavailable while email delivery, Cloudflare Turnstile, production storage and malware scanning are validated. Do not send case documents by email.

3. Data we process

Public site and checklist

  • Technical request and security data, such as IP address, date, route, user agent and response status.
  • A checklist draft stored in your browser session when you choose to use the public checklist. It stays on your device unless you ask the browser to carry it to a later product step; no private case is created while intake is unavailable.
  • Messages and contact details you choose to send to our support or privacy address.

Private workspace, when activated

Account email, authentication and security events; journey and delayed-baggage facts; traveller details; uploaded evidence; expense and prior-reimbursement records; generated packs; user confirmations; support correspondence; and policy-acceptance and audit records. We ask users not to upload unnecessary government identifiers, health data, bank credentials or information about other people.

4. Why and on what basis

  • Contract or steps requested before entering it: provide the checklist and, once activated, the account, private workspace, pack generation and support requested by you (GDPR Article 6(1)(b)).
  • Legitimate interests: keep the public site reliable, secure the service, prevent abuse, investigate failures and defend legal claims, balanced against individual rights (GDPR Article 6(1)(f)).
  • Legal obligation: retain and disclose records where applicable law requires it (GDPR Article 6(1)(c)).
  • Consent: only for a genuinely optional use where refusal and withdrawal are available; no optional analytics processing is active now.

5. Providers and disclosures

Provider Current status Confirmed purpose
Hetzner Active Hosting for the current public site and associated technical and security logs.
Cloudflare proxy and CDN Active Route and protect public-site traffic, terminate HTTPS and process request metadata such as IP address, user agent, requested route and security signals.
Oracle Cloud Active An isolated service performs transient malware scanning in Milan, Italy. Submitted document bytes are streamed to ClamAV and are not retained or stored persistently by the scanner. Scanner failures leave files quarantined and unavailable for use.
Resend Not activated Proposed transactional email; it will be disclosed before activation.
Cloudflare Turnstile Not activated Proposed sign-in abuse prevention; production behavior must first be validated.
AWS S3 Not activated Proposed private object storage in Frankfurt; no case intake uses it now.

We disclose personal data only to validated service providers under appropriate terms, to authorities when legally required, or in connection with a lawful corporate transaction. We do not sell personal data. We do not invent or claim an international-transfer destination or safeguard before it is validated. Any transfer outside the EEA will be identified with its applicable safeguard before the relevant provider is activated.

No Umami or analytics service is active. There is no advertising, profiling, session replay or heatmap tracking.

6. Retention and deletion

  • Authentication sessions expire after 12 hours.
  • An inactive account or case receives a warning after 12 months; absent renewed activity, deletion begins 30 days later.
  • Confirmed deletion blocks normal access immediately and uses a 14-day recoverable-deletion period before active records and files are purged, unless a documented legal hold applies.
  • Copies in backup or object-version storage must expire or become inaccessible no later than 35 days after active-system purge.
  • Identifiable security and access logs are kept for no more than 90 days.
  • Minimal policy acceptance, rights-request and complaint evidence may be kept for three years after account closure or the last relevant event.

Document contents are not part of the three-year legal-record category. Recovery has not been exercised and recoverability remains unverified; this notice makes no disaster-recovery assurance.

7. Your GDPR rights

Where the GDPR applies, you may request access, rectification, erasure, restriction and portability, and object to processing based on legitimate interests. You may withdraw consent without affecting earlier lawful processing. You may also ask about a decision based solely on automated processing; RecoupLane does not make automated airline-eligibility or reimbursement decisions.

Contact us first at contact@recouplane.com. You may lodge a complaint with Romania's ANSPDCP or another supervisory authority competent for your location.

8. Applicable US privacy rights

Where an applicable US state privacy law covers RecoupLane and grants the relevant right, you may request access to or knowledge of personal information, correction, deletion or a portable copy, and may opt out of sale, sharing or targeted advertising or request limits on sensitive-data use. RecoupLane does not sell personal information or use it for cross-context behavioral advertising. We will not discriminate against you for exercising an applicable right. Statutory exceptions may apply.

9. Security and age

The service is designed around private storage, least privilege, short-lived access, audit records and malware quarantine. These controls remain unavailable for real intake until operational validation is complete. The private beta is for adults aged 18 and over; we do not knowingly offer it to children.

10. Changes

We will publish a new effective date and policy version for material changes and request renewed agreement where required.

RecoupLane

Delayed baggage evidence, clearly organised.

PrivacyTermsCookiesContactHow it worksAirlines

Privacy request?

Email the privacy contact

Policy free-beta-2026-08-09-v1.

Privacy contact: contact@recouplane.com.

© RecoupLane