LEGAL
Privacy Policy
1. Data Controller
Wayora S.r.l., Via Altinate 125, 35121 Padova, Italy
Email: privacy@wayora.ai
2. Data We Collect
- Account data: name, email, password (hashed)
- Trip data: itineraries, preferences, bookings
- Payment data: processed by our payment provider (we don't store card numbers)
- Usage data: pages visited, features used (via analytics)
- Device data: browser, OS, screen size (for optimization)
- Location: only if you provide it for departure airport
3. How We Use Your Data
- To provide and improve the travel planning service
- To process bookings with third-party providers
- To send booking confirmations and Travel Kit
- To manage your Wayora Miles account
- To improve AI recommendations based on your preferences
- To communicate important updates about your bookings
- To comply with legal obligations
4. Data Sharing
We share your data with:
- Travel providers (airlines, hotels, activity providers) — to make bookings
- Payment processor — for secure payment processing
- Database provider — for data storage (EU servers)
- Hosting provider — for platform infrastructure (edge network)
- AI provider — for AI processing (your messages are processed but not stored for training purposes)
- Email provider — for transactional emails
We NEVER sell your personal data to third parties.
5. Data Retention
- Account data: retained until you delete your account
- Booking data: retained for 5 years (legal/tax requirements)
- AI conversation data: retained for 12 months, then anonymized
- Analytics data: retained for 24 months
6. Your Rights (GDPR)
- Access: request a copy of your data
- Rectification: correct inaccurate data
- Erasure: request deletion ("right to be forgotten")
- Portability: receive your data in machine-readable format
- Objection: object to processing based on legitimate interest
- Restriction: restrict processing in certain circumstances
To exercise your rights: email privacy@wayora.ai
7. Cookies
See our Cookie Policy.
8. International Transfers
Your data may be processed outside the EEA. We ensure appropriate safeguards (Standard Contractual Clauses, adequacy decisions) are in place for all international transfers.
9. Data Security
- Encrypted in transit (HTTPS/TLS)
- Encrypted at rest
- Access controls and authentication
- Regular security reviews
10. Children
Wayora is not intended for users under 18. We do not knowingly collect data from minors.
11. Changes
We may update this policy. Material changes will be communicated via email.
12. Contact
Data Protection: privacy@wayora.ai
© 2026 Wayora. All rights reserved.