Privacy Policy

Last updated: January 1, 2025

Important Notice

This Privacy Policy is a comprehensive legal document. While we strive to ensure accuracy and compliance with applicable laws, this document should be reviewed by qualified legal counsel before publication. This policy is designed to comply with the General Data Protection Regulation (GDPR), Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Hungary), and other applicable Hungarian data protection laws.

1. Introduction

Welcome to Tixace Travel ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, process, store, and protect your personal information when you use our AI-powered travel planning service, including our Iris travel companion feature.

By using our service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our service.

This Privacy Policy complies with:

  • Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR)
  • Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Hungary)
  • Act V of 2013 on the Civil Code (Hungary)
  • Other applicable Hungarian and European data protection laws

2. Data Controller Information

The data controller responsible for your personal data is:

Tixace Travel

Service operated by an individual entrepreneur (egyéni vállalkozó) under Hungarian law

Website: travel.tixace.com

General inquiries: hello@tixace.com

AI-related inquiries: iris@tixace.com

Specific registration details (legal name, tax identification number, registered address) are available upon request. Please contact us at hello@tixace.com to request this information.

If you have questions about this Privacy Policy or our data processing practices, please contact us using the information provided in Section 14.

4. Data We Collect

We collect the following categories of personal data:

4.1. Travel Planning Data

  • Travel Plans: Trip titles, descriptions, travel preferences, destinations, dates, budgets, and travel requirements
  • Filters and Preferences: Selected filters (flights, stays, food, hiking, beach, rail, photo spots, city walks, etc.)
  • Itinerary Information: Generated travel itineraries, activities, accommodations, transportation details
  • Pricing Information: Travel costs, currency, payment modes, pricing breakdowns

4.2. Organizer and Traveler Information

  • Primary Organizer Data: Name, email address, contact information, and other details provided during finalization
  • Secondary Organizers: Names, email addresses, and contact information of additional organizers
  • Traveler Emails: Email addresses of travelers included in the travel plan
  • Payment Information: Payment mode preferences (pay-as-you-go, etc.)

4.3. Technical Data

  • IP Address: Your Internet Protocol address when accessing our service
  • Browser Information: Browser type, version, and settings
  • Device Information: Device type, operating system, screen resolution
  • Usage Data: Pages visited, time spent, actions taken, features used
  • Log Data: Server logs, error logs, access timestamps

4.4. Communication Data

  • Email Addresses: Provided for newsletter subscriptions, travel notifications, and service communications
  • AI Communication Emails: Email addresses used for AI-generated travel notifications and updates sent from iris@tixace.com
  • Contact Information: Any contact details you provide when reaching out to us
  • Correspondence: Messages, inquiries, feedback, and support requests sent to hello@tixace.com or iris@tixace.com

4.5. Preferences and Settings

  • Theme Preferences: Light/dark mode selections stored in local storage
  • User Preferences: Customized settings and preferences for the service

4.6. Additional Trip Data

  • Trip Names: Names of additional trips created
  • Trip Details: Additional trip information, itineraries, and pricing

Special Categories of Data

We do not intentionally collect special categories of personal data (sensitive data) as defined in GDPR Article 9, such as information about race, ethnicity, political opinions, religious beliefs, health, or sexual orientation. If you provide such information in your travel descriptions, we process it only as necessary to provide our services and in accordance with applicable law.

5. Purposes of Data Processing

We process your personal data for the following purposes:

5.1. Service Provision

  • Creating and managing your travel plans
  • Generating personalized travel itineraries using AI technology (Iris)
  • Processing travel requests and preferences
  • Managing travel finalizations and organizer information
  • Providing additional trip options and recommendations
  • Calculating and displaying travel pricing information

5.2. Communication

  • Sending travel notifications and updates from our AI assistant (Iris) via iris@tixace.com
  • Responding to your inquiries and support requests sent to hello@tixace.com
  • Handling AI-related inquiries and communications via iris@tixace.com
  • Sending newsletter content (with your consent)
  • Providing important service announcements

5.3. Service Improvement

  • Analyzing usage patterns to improve our AI travel planning capabilities
  • Enhancing user experience and service features
  • Conducting research and development
  • Testing and optimizing service performance

5.4. Legal Compliance

  • Complying with applicable laws and regulations
  • Responding to lawful requests from authorities
  • Protecting our legal rights and interests
  • Enforcing our terms and conditions

5.5. Security and Fraud Prevention

  • Detecting and preventing fraud, abuse, and security threats
  • Ensuring service security and integrity
  • Monitoring for suspicious activities

We will not use your personal data for purposes incompatible with those described above without your consent or as required by law.

6. Data Storage and Retention

6.1. Storage Location

Your personal data is stored using MongoDB Atlas, a cloud-based database service. MongoDB Atlas may store data in data centers located within the European Economic Area (EEA) or in other locations as configured. We ensure that appropriate safeguards are in place for any international transfers (see Section 11).

We implement appropriate technical and organizational measures to protect your data during storage and transmission.

6.2. Data Retention Periods

We retain your personal data for the following periods:

  • Active Travel Plans: Retained while the travel plan is active and for a period of 3 years after the last activity or finalization
  • Newsletter Subscriptions: Retained until you unsubscribe or request deletion
  • Communication Records: Retained for 3 years from the date of last communication
  • Technical Logs: Retained for 12 months for security and debugging purposes
  • Legal Compliance Data: Retained as required by applicable laws (e.g., accounting records may be retained for 8 years under Hungarian law)

After the retention period expires, we will securely delete or anonymize your personal data, unless we are required to retain it for legal compliance purposes.

6.3. Data Deletion

You may request deletion of your personal data at any time by contacting us. We will delete your data within 30 days of your request, unless we are required to retain it for legal compliance or legitimate business purposes.

7. Data Sharing and Disclosure

We do not sell your personal data. We may share your data only in the following circumstances:

7.1. Service Providers

We may share data with trusted third-party service providers who assist us in operating our service:

  • MongoDB Atlas: Cloud database hosting service
  • Hosting Providers: Cloud infrastructure and hosting services
  • Barion Payment Services: Payment processing service (see Section 7.5 for details)
  • Email Service Providers: Services for sending emails and newsletters, including AI-generated emails from iris@tixace.com
  • Analytics Providers: Services for analyzing usage patterns (if applicable)

All service providers are contractually obligated to protect your data and use it only for the purposes we specify.

Note on AI Services: Our AI travel planning assistant (Iris) is developed and operated by Tixace. It is not a third-party service. All AI-generated communications are sent from iris@tixace.com.

7.2. Legal Requirements

We may disclose your data if required by law, court order, or governmental authority, or to protect our rights, property, or safety, or that of our users or others.

7.3. Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity. We will notify you of any such transfer and ensure your rights are protected.

7.4. With Your Consent

We may share your data with other parties when you have explicitly consented to such sharing.

7.5. Payment Processing - Barion

When you make payments through our Service, we use Barion Payment Services ("Barion") to process payments. Barion is a Hungarian payment service provider authorized by the Magyar Nemzeti Bank (Central Bank of Hungary).

We share the following data with Barion for payment processing:

  • Payment amount and currency
  • Transaction identifiers
  • Email address (for payment confirmations)
  • Payment method information (credit card, bank transfer, etc.)
  • Billing information necessary for transaction processing

Important: We do not store or have access to your full payment card details. All payment card information is handled directly by Barion and is subject to Barion's privacy policy and security measures. Payment card data is processed in accordance with PCI DSS standards.

Barion may share certain transaction data with banks, card networks, and other financial institutions as necessary to process payments. Barion's processing of your payment data is governed by:

  • Barion's Terms and Conditions and Privacy Policy
  • Hungarian financial services regulations
  • European Union payment services regulations (PSD2)
  • PCI DSS security standards

For more information about how Barion processes your payment data, please review Barion's privacy policy available at www.barion.com.

Data Sharing with Travel Organizers

When you participate in a travel plan as an organizer or traveler, your information (email address, name, etc.) may be visible to other organizers and travelers within that travel plan. This is necessary for the travel planning functionality.

8. Your Rights

Under GDPR and Act CXII of 2011, you have the following rights regarding your personal data:

8.1. Right of Access (Article 15 GDPR)

You have the right to obtain confirmation as to whether we process your personal data and to access your personal data, including copies of the data we hold about you.

8.2. Right to Rectification (Article 16 GDPR)

You have the right to have inaccurate or incomplete personal data corrected or completed.

8.3. Right to Erasure ("Right to be Forgotten") (Article 17 GDPR)

You have the right to request deletion of your personal data when:

  • The data is no longer necessary for the purposes for which it was collected
  • You withdraw consent and there is no other legal basis for processing
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed
  • Deletion is required for legal compliance

8.4. Right to Restrict Processing (Article 18 GDPR)

You have the right to restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.

8.5. Right to Data Portability (Article 20 GDPR)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

8.6. Right to Object (Article 21 GDPR)

You have the right to object to processing of your personal data based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.

8.7. Right to Withdraw Consent

When processing is based on consent, you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

8.8. Right to Lodge a Complaint

You have the right to lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) or your local supervisory authority if you believe your data protection rights have been violated (see Section 15).

Exercising Your Rights

To exercise any of these rights, please contact us at hello@tixace.com. We will respond to your request within 30 days. We may request verification of your identity before processing certain requests to ensure data security.

9. Cookies and Local Storage

9.1. Local Storage

We use browser local storage to store your preferences, such as:

  • Theme Preferences: Your light/dark mode selection (stored as "tixace-theme")
  • User Preferences: Other settings and preferences for service functionality

Local storage data is stored only on your device and is not transmitted to our servers except as part of normal service functionality. You can clear local storage through your browser settings.

9.2. Cookies

Currently, we use minimal cookies. If we implement cookies in the future, we will update this policy and provide appropriate cookie consent mechanisms in accordance with GDPR and EU ePrivacy Directive requirements.

9.3. Tracking and Analytics

We may use analytics tools to understand how our service is used. Any tracking will be disclosed in this section and will comply with applicable privacy laws. We do not currently use third-party tracking or advertising cookies.

10. Security Measures

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:

  • Encryption: Data transmitted over the internet is encrypted using secure protocols (HTTPS/TLS)
  • Access Controls: Strict access controls and authentication mechanisms for our systems
  • Secure Storage: Data stored in secure, encrypted databases with restricted access
  • Regular Updates: Regular security updates and patches for our systems and dependencies
  • Monitoring: Continuous monitoring for security threats and vulnerabilities
  • Staff Training: Regular training for staff on data protection and security best practices
  • Incident Response: Procedures for responding to security incidents and data breaches

While we strive to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we commit to promptly addressing any security issues that arise.

Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours, as required by GDPR Article 33 and 34.

11. International Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including:

11.1. MongoDB Atlas

MongoDB Atlas may store data in data centers located outside the EEA. We ensure that appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • MongoDB Atlas compliance with GDPR and other applicable data protection laws
  • Data processing agreements that protect your rights

11.2. Adequacy Decisions

We may transfer data to countries that have been deemed adequate by the European Commission, where no additional safeguards are required.

11.3. Your Rights

When we transfer your data internationally, you retain all the rights described in Section 8, and we ensure that your data receives an adequate level of protection.

12. Children's Privacy

Our service is not intended for children under the age of 16. We do not knowingly collect personal data from children under 16 without parental consent.

In accordance with GDPR Article 8, if we become aware that we have collected personal data from a child under 16 without appropriate parental consent, we will take steps to delete that information promptly.

If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately so we can take appropriate action.

13. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service features. We will notify you of any material changes by:

  • Posting the updated policy on our website with a new "Last updated" date
  • Sending email notifications for significant changes (if you have provided your email)
  • Displaying a prominent notice on our website when you next visit

Your continued use of our service after changes become effective constitutes acceptance of the updated policy. We encourage you to review this policy periodically.

14. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:

Data Protection Inquiries

Website: travel.tixace.com

General inquiries: hello@tixace.com

AI-related inquiries: iris@tixace.com

For data protection inquiries, please contact us at hello@tixace.com. For questions about AI-generated communications or the Iris travel assistant, please contact iris@tixace.com.

We will respond to your inquiries within 30 days as required by GDPR. For complex requests, we may extend this period by an additional 60 days, and we will inform you of the extension.

15. Supervisory Authority

If you believe that we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)

Address: 1055 Budapest, Falk Miksa utca 9-11, Hungary

Phone: +36 1 391 1400

Email: ugyfelszolgalat@naih.hu

Website: https://naih.hu

You also have the right to lodge a complaint with the supervisory authority in your country of residence, place of work, or the place of the alleged infringement, if you are located in the European Union.

This Privacy Policy is effective as of the "Last updated" date shown above. By using our service, you acknowledge that you have read and understood this policy.