Privacy Policy
PRIVACY AND PERSONAL DATA PROTECTION REGULATION
AZURE TRAVEL
Version: 23 August 2026
This Regulation sets out the principles and rules applied by AZURE TRAVEL entities in relation to the collection, use, disclosure, transfer, storage, safeguarding, retention and deletion of personal data relating to clients, prospective clients, passengers, users of AZURE TRAVEL platforms and other data subjects.
This Regulation has been prepared having regard to the applicable legislation of the Republic of Moldova, Greece and the European Union.
1. AZURE TRAVEL ENTITIES AND APPLICABLE LEGISLATION
1.1. AZURE TRAVEL P.C. — Greece
AZURE TRAVEL P.C.
Registered address: 15 Frixou Street, GR 54627, Thessaloniki, Greece
Registration No.: 172898806000
Greek Ministry of Tourism Registration No.: 0933E60000818001
In respect of personal data processing activities carried out by AZURE TRAVEL P.C., the following legislation shall apply, as appropriate:
- Regulation (EU) 2016/679 — the General Data Protection Regulation (“GDPR”);
- Greek Law No. 4624/2019 implementing and supplementing the GDPR;
- Greek Law No. 3471/2006, insofar as applicable to electronic communications and privacy;
- any other applicable provisions of European Union and Greek law.
The competent supervisory authority is the Hellenic Data Protection Authority (“HDPA”).
1.2. AZURETRAVEL SOLUTIONS SRL — Republic of Moldova
AZURETRAVEL SOLUTIONS SRL
IDNO: 1026023029283
Authorisation: P-72573/2026
Registered address: 10 I. Gagarin Blvd., MD-2001, Chișinău Municipality, Republic of Moldova
In respect of personal data processing activities carried out by AZURETRAVEL SOLUTIONS SRL, the following legislation shall apply:
- Law No. 195/2024 on Personal Data Protection;
- secondary legislation and regulatory acts adopted for the implementation thereof;
- any other applicable provisions of the laws of the Republic of Moldova.
Law No. 195/2024 establishes the current legal framework governing personal data protection in the Republic of Moldova and transposes the principles and requirements of Regulation (EU) 2016/679 into Moldovan law.
The competent supervisory authority is the National Centre for Personal Data Protection of the Republic of Moldova (“NCPDP”).
1.3. Allocation of Responsibilities Between the Entities
AZURE TRAVEL P.C. and AZURETRAVEL SOLUTIONS SRL are separate and independent legal entities, incorporated in different jurisdictions.
The entity acting as controller in respect of a specific processing activity shall be determined by reference to, inter alia, the entity with which the data subject enters into a contractual relationship, the entity from which the data subject requests a service, or the entity that determines the purposes and means of the relevant processing.
Where both entities jointly determine the purposes and means of a particular processing activity, they may, where the applicable legal requirements are satisfied, act as joint controllers.
This Regulation establishes the common personal data protection principles applicable to both AZURE TRAVEL entities.
Where mandatory requirements under Moldovan law and Greek and/or European Union law differ, the mandatory provisions applicable to the relevant controller and specific processing activity shall prevail.
2. PRINCIPLES GOVERNING THE PROCESSING OF PERSONAL DATA
AZURE TRAVEL shall process personal data in accordance with the principles of lawfulness, fairness and transparency.
Personal data shall be collected for specified, explicit and legitimate purposes and shall not be further processed in a manner incompatible with those purposes.
AZURE TRAVEL shall seek to ensure that the personal data collected are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
Personal data shall be retained only for as long as necessary for the relevant processing purposes and for compliance with applicable legal obligations.
AZURE TRAVEL shall implement appropriate technical and organisational measures designed to ensure the security, integrity and confidentiality of personal data.
3. CATEGORIES OF DATA SUBJECTS
This Regulation shall apply, as appropriate, to:
- clients and prospective clients;
- persons requesting quotations, advice or information;
- persons making bookings;
- passengers and travellers included in a booking;
- family members and other persons included in a booking;
- minors;
- participants in group travel arrangements;
- representatives and employees of corporate clients;
- persons for whom employers or other organisations purchase travel services;
- persons communicating with AZURE TRAVEL by telephone, e-mail, website, messaging applications, social media or other communication channels;
- visitors to AZURE TRAVEL online platforms;
- any other persons whose personal data are lawfully provided to AZURE TRAVEL in connection with the provision of travel services.
4. CATEGORIES OF PERSONAL DATA PROCESSED
Depending on the service requested, AZURE TRAVEL may process the following categories of personal data.
4.1. Identification Data
First name, surname, date of birth, sex or gender where required for booking purposes, nationality and any other information necessary to identify the individual.
4.2. Contact Data
Telephone number, e-mail address, postal address and any other contact information provided to AZURE TRAVEL.
4.3. Travel Document Data
Depending on the nature of the service, AZURE TRAVEL may process:
- type of document;
- passport or other travel document series and number;
- date of issue;
- expiry date;
- issuing authority or issuing country;
- nationality;
- any other information lawfully required by a carrier, travel supplier or competent public authority.
4.4. Travel-Related Data
AZURE TRAVEL may process information regarding travel destination, travel dates, airports, flights, accommodation, room category and type, transfers, excursions, ancillary services, travel preferences and any other information necessary for the organisation and performance of the travel arrangements.
4.5. Booking and Contractual Data
AZURE TRAVEL may retain booking references, information regarding requested or purchased services, prices, amendments, cancellations, refunds, complaints and correspondence relating to the relevant services.
5. PAYMENTS AND BANK CARD DATA
AZURE TRAVEL does not collect, view, store or use clients’ full bank card details.
Where an online payment is made by bank card, the transaction is processed directly through the secure payment page of the relevant bank or payment service provider.
The information required to complete the payment is entered by the client directly into the secure infrastructure of the institution processing the transaction.
Accordingly, the full card number, card expiry date and CVV/CVC security code are not disclosed to AZURE TRAVEL and are not stored within AZURE TRAVEL systems.
In connection with a transaction, AZURE TRAVEL may receive and process only such administrative information as is necessary for booking management and financial or accounting purposes, including:
- confirmation that payment has succeeded or failed;
- payment amount;
- currency;
- transaction date;
- transaction reference or identifier;
- payment status;
- information necessary for refunds or payment reconciliation.
The bank or payment service provider processing the transaction shall process the payment information entered on its platform in accordance with its own legal obligations, security requirements and privacy policy.
6. HEALTH DATA AND SPECIAL TRAVEL REQUIREMENTS
In certain circumstances, the provision of a requested service may require the processing of information concerning:
- reduced mobility;
- special assistance requirements;
- allergies or food intolerances;
- special dietary requirements;
- other medical or special needs relevant to the journey.
To the extent that such information constitutes special categories of personal data, AZURE TRAVEL shall process it only where an appropriate lawful basis exists under the applicable legislation.
Such data shall be limited to what is necessary for the requested service.
Where necessary, such information may be disclosed to the relevant service provider solely to the extent required to fulfil the client’s request.
7. SOURCES OF PERSONAL DATA
AZURE TRAVEL may obtain personal data:
- directly from the data subject, including when requesting a quotation, making a booking, entering into a contract, completing forms, communicating by e-mail or telephone, or using other communication channels;
- from the person making the booking, where that person books services on behalf of other passengers;
- from employers, companies, representatives or group organisers, where travel is arranged through such persons or entities;
- from service providers involved in fulfilling the booking, including in connection with amendments, cancellations, refunds, confirmations or the resolution of booking-related issues;
- from booking systems and travel platforms lawfully used for the performance of the relevant service.
8. BOOKINGS MADE ON BEHALF OF OTHER PERSONS
A client may make a booking on behalf of other persons where the client is lawfully entitled to provide their personal data.
Any person providing AZURE TRAVEL with personal data relating to other passengers must ensure that those individuals are informed of the disclosure and processing of their personal data and, where required by applicable law, that there is an appropriate lawful basis for such disclosure.
The person making the booking must provide only accurate personal data that are necessary for the provision of the relevant services.
Such person is encouraged to make this Regulation available to all other passengers included in the booking.
9. PERSONAL DATA RELATING TO MINORS
AZURE TRAVEL may process personal data relating to minors where a minor is included in a booking or where such processing is otherwise necessary for the provision of travel services.
Depending on the circumstances, such data may include the minor’s name, surname, date of birth, nationality, travel document details, itinerary and other information necessary for the journey.
Personal data relating to minors shall be processed with particular care and only to the extent necessary for the relevant purpose.
Where applicable law requires authorisation or consent from a parent or legal guardian, AZURE TRAVEL may request such information as is reasonably necessary to comply with that requirement.
10. PURPOSES AND LAWFUL BASES FOR PROCESSING
AZURE TRAVEL may process personal data on one or more lawful bases applicable to the specific processing activity.
10.1. Pre-Contractual Measures and Performance of a Contract
Personal data may be processed for the purposes of:
- preparing quotations requested by the client;
- checking availability;
- creating and administering bookings;
- issuing travel documents, vouchers and itineraries;
- arranging flights, accommodation, transfers and other travel services;
- amending or cancelling services;
- processing refunds;
- providing customer support;
- sending operational information;
- responding to requests relating to the contracted service.
10.2. Compliance with Legal Obligations
Personal data may be processed where necessary to comply with tax, accounting, administrative, judicial, travel-related and other legal obligations imposed by applicable law.
10.3. Legitimate Interests
Where permitted by applicable law and provided that the rights and freedoms of the data subject do not override such interests, AZURE TRAVEL may process personal data for purposes including:
- ensuring the security of its systems and services;
- preventing fraud and misuse;
- handling complaints;
- protecting the rights and interests of AZURE TRAVEL;
- establishing, exercising or defending legal claims;
- improving the quality of its services.
10.4. Consent
Where applicable law requires the data subject’s consent, such consent shall be requested for the specific processing purpose concerned.
Consent may be withdrawn in accordance with applicable law. Withdrawal shall not affect the lawfulness of processing carried out prior to the withdrawal of consent.
11. SERVICE QUALITY IMPROVEMENT. RECORDING AND RETENTION OF COMMUNICATIONS
For the purposes of monitoring and improving service quality, training and evaluating personnel, handling enquiries and complaints, clarifying possible disputes or misunderstandings, and safeguarding the lawful rights and interests of AZURE TRAVEL and its clients, AZURE TRAVEL may record telephone conversations and retain written communications with clients and other data subjects, subject to applicable law.
Where a telephone conversation is recorded, the processing may include the caller’s voice, telephone number and information disclosed during the conversation.
Written communications may include e-mails, online forms, messages, correspondence exchanged through communication platforms used by AZURE TRAVEL and other communications connected with the relationship between the client and AZURE TRAVEL.
Where a telephone call is recorded, the individual shall be informed of the recording and its purpose in accordance with applicable legal requirements.
Where applicable law requires consent for the relevant recording or other processing activity, AZURE TRAVEL shall obtain such consent in the form required by law.
By contacting AZURE TRAVEL, requesting a quotation, initiating a booking or using AZURE TRAVEL services, the individual is deemed to have been informed that relevant communications may be processed in accordance with this Regulation.
However, the mere fact of making a booking shall not replace separate consent where such consent is expressly required by applicable law.
Recordings and written communications shall be accessible only to authorised persons.
They shall be retained for the period necessary to achieve the relevant purpose or for such longer period as may be required or permitted by applicable law.
Upon expiry of the applicable retention period, recordings and communications shall be deleted, securely destroyed or anonymised, unless continued retention is necessary for compliance with a legal obligation, the handling of a complaint or dispute, or the establishment, exercise or defence of legal rights.
12. MARKETING, PROMOTIONAL ACTIVITIES AND COMMERCIAL COMMUNICATIONS
AZURE TRAVEL may process certain personal data for the purposes of promoting its services, conducting marketing activities and sending commercial or promotional communications, subject to the requirements of applicable law.
Depending on the applicable lawful basis, the following data may be used for such purposes:
- first name and surname;
- e-mail address;
- telephone number;
- history of the client’s relationship with AZURE TRAVEL;
- travel services requested or purchased;
- travel destinations and preferences.
Marketing activities may include the communication of travel offers, promotions, special offers, destination information, AZURE TRAVEL products and services, newsletters, seasonal campaigns and, where legally permitted, offers tailored to the client’s interests and preferences.
Commercial communications may be sent by e-mail, telephone, SMS, messaging applications or other communication channels permitted by applicable law.
The mere fact that a booking has been made through AZURE TRAVEL shall not constitute a general or unrestricted consent to all marketing activities.
Where applicable law permits a particular marketing activity on another lawful basis, AZURE TRAVEL may carry out such activity within the limits and subject to the conditions of that lawful basis.
Where consent is required for a particular marketing activity, such consent shall be obtained separately and in accordance with applicable law.
Consent to marketing is voluntary and shall not constitute a condition for making a booking or purchasing a travel service.
The data subject may at any time withdraw consent or, depending on the relevant lawful basis, object to direct marketing.
This may be done by using the unsubscribe mechanism provided in the communication or by submitting a request to:
info@azure-travel.com
Withdrawal of consent shall not affect the lawfulness of processing carried out prior to withdrawal.
AZURE TRAVEL may retain the minimum information necessary to record an opt-out or objection in order to ensure that the individual’s marketing preferences are respected in the future.
Operational Communications Are Not Marketing Communications
Booking confirmations, tickets, vouchers, invoices, payment information, flight or schedule changes, cancellations, refunds, hotel and transfer information, safety notifications and other communications necessary for the performance of the requested service may be sent irrespective of the client’s marketing preferences.
13. RECIPIENTS OF PERSONAL DATA
For the purposes of arranging and performing travel services, AZURE TRAVEL may disclose necessary personal data, depending on the specific service, to:
- airlines and other carriers;
- hotels and other accommodation providers;
- tour operators;
- destination management companies (DMCs) and local partners;
- transfer service providers;
- car rental companies;
- cruise operators;
- excursion and activity providers;
- global distribution systems (GDS), booking systems and technology platforms;
- insurance companies;
- banks and payment service providers;
- IT, hosting, cloud, e-mail and communications service providers;
- legal advisers, accountants and auditors, where necessary;
- public, judicial, tax, border, immigration and other competent authorities;
- other persons or entities where disclosure is necessary for the requested service or is required or permitted by law.
AZURE TRAVEL shall seek to limit the personal data disclosed to that which is necessary for the relevant purpose.
14. PASSENGER INFORMATION AND REQUIREMENTS OF PUBLIC AUTHORITIES
For certain international journeys, airlines, other carriers and/or competent public authorities may require passenger information.
Such information may include Advance Passenger Information (“API”) and other information relating to the passenger or booking as required under the laws of the country of departure, transit or destination.
Where such disclosure is necessary for the performance of the journey or compliance with a legal obligation, AZURE TRAVEL may provide the necessary information to the carrier, relevant service provider or competent authority.
15. INTERNATIONAL TRANSFERS OF PERSONAL DATA
Travel services are, by their nature, international.
Where a client books accommodation, air travel, transfers, cruises, excursions or other services in another country, the personal data required for the relevant service may be transferred to service providers located in that country.
Accordingly, personal data may be transferred to and processed in countries outside the Republic of Moldova and/or outside the European Economic Area.
International transfers shall be carried out in accordance with the legislation applicable to the relevant controller.
For processing subject to the GDPR, AZURE TRAVEL may rely, as appropriate, on the mechanisms permitted under the GDPR, including adequacy decisions, appropriate safeguards, Standard Contractual Clauses or applicable statutory derogations.
AZURETRAVEL SOLUTIONS SRL shall carry out international transfers in accordance with the mechanisms and requirements established by Law No. 195/2024 and any other applicable Moldovan legislation.
16. COOKIES AND SIMILAR TECHNOLOGIES
AZURE TRAVEL platforms may use cookies and similar technologies necessary for website functionality, security, storage of user preferences and, where and to the extent permitted by applicable law, analytics and marketing.
Where consent is required for the use of specific cookies or similar technologies, such technologies shall be used in accordance with the preferences expressed by the user.
The specific categories of cookies, their purposes, providers and retention periods shall be described in the AZURE TRAVEL Cookie Policy and/or through the preference-management tool made available on the website.
17. RETENTION OF PERSONAL DATA
AZURE TRAVEL shall retain personal data only for as long as necessary for the purposes for which the data were collected and for compliance with applicable legal obligations.
When determining the applicable retention period, AZURE TRAVEL may take into account:
- the duration of the contractual relationship;
- the period necessary to arrange and complete the journey;
- booking amendments and cancellations;
- refunds;
- tax and accounting obligations;
- statutory record-keeping requirements;
- limitation periods;
- complaints or litigation;
- the need to protect or defend legal rights;
- the duration of consent where processing is based on consent.
Upon expiry of the applicable retention period, personal data shall be deleted, securely destroyed or anonymised, unless continued retention is permitted or required by law.
18. SECURITY AND CONFIDENTIALITY
AZURE TRAVEL shall implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, loss, destruction or unlawful use.
Depending on the nature and risks of the processing, such measures may include:
- secure communications;
- access controls;
- user authentication;
- restriction of employee access rights;
- backup procedures;
- information security measures;
- confidentiality obligations;
- contractual and organisational measures applicable to service providers;
- staff training.
Access to personal data shall be granted only to persons who require such access for the proper performance of their duties.
19. RIGHTS OF DATA SUBJECTS
Subject to the conditions and limitations imposed by applicable law, a data subject may have:
- the right to be informed;
- the right of access to personal data;
- the right to rectification of inaccurate or incomplete data;
- the right to erasure where the applicable legal conditions are met;
- the right to restriction of processing;
- the right to object to processing;
- the right to data portability;
- the right to withdraw consent where processing is based on consent;
- rights relating to decisions based solely on automated processing, where applicable;
- the right to lodge a complaint with the competent supervisory authority;
- the right to seek judicial remedies available under applicable law.
These rights are subject to the exceptions and limitations provided by law.
In particular, a request for erasure shall not require AZURE TRAVEL to delete information which it is legally required or otherwise lawfully entitled to retain.
20. EXERCISE OF DATA SUBJECT RIGHTS AND PRIVACY CONTACT
To exercise any rights relating to personal data or to obtain information regarding AZURE TRAVEL’s processing activities, the data subject may contact AZURE TRAVEL at:
E-mail: info@azure-travel.com
The request should contain sufficient information to enable AZURE TRAVEL to identify the individual and the booking, contract or other interaction to which the request relates.
In order to safeguard personal data, AZURE TRAVEL may request reasonably necessary additional information to verify the identity of the applicant before granting access to personal data or acting upon the request.
Requests shall be handled within the periods and in accordance with the conditions prescribed by applicable law.
21. RIGHT TO LODGE A COMPLAINT
21.1. AZURE TRAVEL P.C. — Greece
Where AZURE TRAVEL P.C. is the relevant controller, the data subject has the right to lodge a complaint with the competent supervisory authority, including the Hellenic Data Protection Authority (HDPA), in accordance with the GDPR and applicable Greek law.
21.2. AZURETRAVEL SOLUTIONS SRL — Republic of Moldova
Where AZURETRAVEL SOLUTIONS SRL is the relevant controller, the data subject has the right to lodge a complaint with the National Centre for Personal Data Protection of the Republic of Moldova (NCPDP) in accordance with Law No. 195/2024.
The right to lodge a complaint shall be without prejudice to any judicial remedies available under applicable law.
22. AMENDMENTS AND UPDATES TO THIS REGULATION
AZURE TRAVEL may amend or update this Regulation where necessary as a result of:
- changes in applicable legislation;
- changes to the services provided;
- implementation of new technologies or systems;
- changes to service providers or processing operations;
- requirements imposed by competent authorities;
- the need to improve personal data protection measures.
The current version of this Regulation shall state the date of the most recent update.
Where amendments are material and applicable law requires additional notice to data subjects, AZURE TRAVEL shall use reasonable means to provide such notice.
23. CONTACT DETAILS OF THE CONTROLLERS
AZURE TRAVEL P.C. — Greece
15 Frixou Street GR 54627, Thessaloniki
Greece
Registration No.: 172898806000
Greek Ministry of Tourism Registration No.: 0933E60000818001
E-mail for personal data and privacy matters:
info@azure-travel.com
AZURETRAVEL SOLUTIONS SRL — Republic of Moldova
IDNO: 1026023029283
Authorisation: P-72573/2026
10 I. Gagarin Blvd.
MD-2001, Chișinău Municipality
Republic of Moldova
E-mail for personal data and privacy matters:
info@azure-travel.com
24. FINAL PROVISIONS
This Regulation constitutes AZURE TRAVEL’s general framework governing the processing and protection of personal data.
It shall be read together with the applicable contracts, booking terms and conditions, Cookie Policy, consent forms and other AZURE TRAVEL documents through which data subjects may receive additional information regarding specific processing activities.
In the event of any inconsistency between this Regulation and a mandatory provision of applicable law, the applicable mandatory provision of law shall prevail.
Where a specific processing activity requires additional information to be provided to the data subject or requires separate consent under applicable law, AZURE TRAVEL shall provide such information and/or obtain such consent in accordance with the applicable legal requirements.
This Regulation shall enter into force on the date of its approval by AZURE TRAVEL.
Document version: 23 August 2026.