Retail inMotion – Privacy Policy – Inflight Retail Payment Services
1. Controller
Retail inMotion Limited has entered into an agreement with your airline to provide it with certain services including inflight point of sale and offline payment card processing. Pursuant to Art. 4 paragraph 7 General Data Protection Regulations (“GDPR”), the Controller for the provision of the offline inflight payment services on behalf of your airline is:
Retail inMotion Limited
Building 11, Cherrywood Business Park
Loughlinstown
Dublin 18
Ireland
Phone: +353 1445 1212
E-Mail: dpc@retailinmotion.com
2. Data Protection Commission
In addition to contacting Retail inMotion Limited, you have the option of contacting the relevant supervisory authority, which for Retail inMotion Limited is:
Data Protection Commission
21 Fitzwilliam Square
South Dublin 2
D02 RD28
Ireland
Phone
+353 (0)761 104 800
+353 (0)57 868 4800
Contact Online: https://www.dataprotection.ie/
If you reside outside of Ireland, you will find your local relevant Data Protection authorities’ details here: https://edpb.europa.eu/about-edpb/about-edpb/members_en
3. What personal data is collected?
The data collected includes:
- First Name, last name
- Credit card details (Primary account number, expiry date, date and time of retail transaction(s))
- Seat number onboard the flight
- Flight number
4. How will we use your data?
Retail inMotion collects your data so that we can:
- Provide onboard retail services to you on behalf of the airline.
- Provide a receipt of transactions for goods and services purchased by you during your journey on board the airline’s aircraft.
- Provide a refund on goods and services procured during the flight, where appropriate.
5. How do we store your data?
In order to prevent unauthorised access or disclosure we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect. If you have any questions regarding this, you can contact us.
6. What is the purpose and legal basis of processing your personal data?
In addition to the purposes mentioned section 4, the processing of your personal data is required to provide you onboard retail services on behalf of your airline.
The legal basis for processing your personal data is:
- GDPR Art. 6 para. 1 lit. b) – which states that processing is necessary for the performance of a contract to which the data subject is party or to take steps at the request of the data subject prior to entering into a contract.
- GDPR Art. 6 para. 1 lit. f) – Legitimate interest
- Regarding individual processing operations, several legal bases may apply. Insofar as individual legal bases are mentioned for the respective processing activities, this does not exclude that further legal bases may be applicable in addition.
7. Is there data used by Third Parties?
We utilise third parties, who handle your data to offer the service to you, such as banks, credit and charge card providers, who will use the data for payment processing and antifraud operations. If you need more information on our third party and their privacy policy, please contact us at dpc@retailinmotion.com.
8. How long does RiM store the data?
Retail inMotion keeps your personal information for no longer than necessary for the purposes for which it is processed. Your personal information is retained for one year for the purposes for which it is collected and use it and/or as required to comply with applicable laws. Where there are technical limitations that prevent deletion or anonymization, we safeguard personal information and limit active use of it.
9. Is data transferred outside of EEA?
Retail inMotion does not transfer your data outside of EEA.
10. How do we keep your data secure?
Retail inMotion protects your data using stringent policies, procedures, and processes, such as:
- Data encryption (end to end) protects your data both at rest and in transit.
- Access to personal data is restricted by strong access and authentication methods and policies.
- Technical measures are in place to monitor intrusion detection and prevention systems (IDS/IPS).
- Anti-virus software provides virus protection from the internet and other devices.
- Our infrastructure is secured by a Distributed Denial of Solution (DDoS) protection service. This offers detection and automated mitigations, therefore reducing security risks.
- Organisational measures, such as data security and privacy awareness and training for all staff, are put in place to ensure that your data is treated with the highest care.
- Business continuity strategies have been developed and outlined in terms of how to safeguard and retrieve any personal data.
- In the case of a data breach, please inform us immediately at dpc@retailinmotion.com.
11. Rights of the data subject and the right to lodge a complaint with a supervisory authority
According to Art. 12 – 23 GDPR, you have the following rights in relation to the personal data processed:
- The right to access – You have the right to request Retail inMotion for copies of your personal data. We may charge you a small fee for this service.
- The right to rectification – You have the right to request that Retail inMotion correct any
information you believe is inaccurate. You also have the right to request Retail inMotion to complete information you believe is incomplete. - The right to erasure – You have the right to request that Retail inMotion erase your personal data, under certain conditions.
- The right to restrict processing – You have the right to request that Retail inMotion restrict the processing of your personal data, under certain conditions.
- The right to object to processing – You have the right to object to Retail inMotion ‘s processing of your personal data, under certain conditions.
- The right to data portability – You have the right to request that Retail inMotion transfer the data that we have collected to another organisation, or directly to you, under certain conditions.
If you make a data subject request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us at our email: dpc@retailinmotion.com
12. Changes to our privacy policy
Retail inMotion maintains a frequent review of its privacy policy and makes any necessary changes as required.
13. How to contact us
If you have any questions about Retail inMotion’s privacy policy, the data we hold on you, or you would like to exercise one of your data protections rights, please do not hesitate to contact us at dpc@retailinmotion.com.