GDPR & Data Protection
Last updated: 28 September 2026
For users in the EU, EEA and UK. This notice supplements our Privacy Policy. It explains the lawful bases we rely on, your rights, international transfers, and how we protect your data.
1. Controller and UK representative
The controller of your personal data is paxID OÜ, a private limited company registered in Estonia (registry code 17608154), Juhkentali 8, Tallinn, 10132, Estonia. Contact: privacy@paxid.com.
paxID OÜ is established in the EU, so it has no separate EU/EEA representative. Before paxID serves users in the UK, it will appoint a UK representative and publish that representative's contact details here.
2. Data protection by design
paxID holds a traveller profile so you do not have to re-enter the same details for every trip, form and booking. It can include surnames, passport and identity-document numbers, issue and expiry dates, nationalities, date of birth, country of birth, addresses, phone numbers, additional email addresses and emergency contacts.
These details are stored on paxID's systems, encrypted in transit and at rest, with access limited to the parts of the service that need them and restricted, logged and reviewed for sensitive fields. Sensitive values are kept out of ordinary application logs, error reports and analytics. We apply data minimisation to each processing purpose: requirement checks receive only eligibility facts such as nationality, document type, issuing country, expiry and route, and never your name, passport number or document images. We assess the risks of this processing, keep a record of our processing activities, and apply retention limits and deletion routines to the data we hold.
Beyond the traveller profile, paxID stores the data needed to operate the account, search and check travel requirements, support trips, provide bookings, process payments, offer mobile data when it launches, and meet legal obligations.
3. Lawful bases
- Contract: account creation, authentication, traveller-profile storage and sync, flight search, trip planning, entry-requirement checks, bookings, mobile data (when it launches), payment processing, support and service messages.
- Legitimate interests: security, fraud prevention, debugging, service improvement, abuse prevention, basic analytics, dispute handling, and protecting paxID, users and partners.
- Consent: optional marketing, waitlist communications where required, optional document scanning where consent is the chosen basis, optional analytics where required, and other optional processing clearly presented in the app.
- Legal obligation: tax, accounting, sanctions screening, consumer-protection duties, payment disputes, regulatory requests and legally required records.
- Vital or public-interest grounds: only if an emergency or law requires processing for that purpose.
4. Special category and sensitive-context data
paxID is a travel-readiness product and may process identity documents, nationality, country of birth, date of birth, travel routes, family travel details and documents you upload or forward. Some of this may be sensitive by context even when it is not a special category under the GDPR. We minimise what we collect for each purpose, restrict and log access to identity-document fields, delete scanned document images after extraction unless you choose to save a copy, and run higher-risk processing such as document scanning only when you choose to use it.
5. Your rights
Subject to legal limits, you may have the right to access, rectify, erase, restrict, port and object to processing of your personal data. You may withdraw consent where processing is based on consent. You also have the right to object to processing based on legitimate interests. You can view, correct and delete traveller profiles, documents, trips and your account directly in paxID, on the website or in the apps. For anything you cannot resolve there, contact privacy@paxid.com. We respond within the statutory time limits.
6. Required data
Some data is required to provide the service. For example, we need your email to create an account, limited travel and document metadata to check requirements, trip details to prepare readiness results, and payment data to complete purchases. If you do not provide required data, some features may not work. Optional features, such as document scanning or marketing emails, can be skipped.
7. International transfers
paxID OÜ is registered in Estonia and may use providers in other countries, including the United States. We do not have to store EU/EEA or UK user data only in Europe, but transfers outside the EU/EEA or UK require safeguards. Depending on the transfer, paxID relies on adequacy decisions, EU Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, processor agreements, transfer risk assessments, and technical safeguards. Personal data is encrypted in transit and at rest wherever it is transferred or stored.
8. Processors and recipients
We use processors and recipients for hosting, storage, databases, payment processing, fraud prevention, airline ticketing and booking, travel insurance (when offered, through an insurance partner that is responsible for its own processing), mobile-network services (when mobile data launches), document reading and parsing, email, support, monitoring and push notifications. We require processors to protect personal data, use it only for agreed purposes, and support deletion, security and transfer obligations where applicable. Final launch notices may identify key processors by name once the launch vendor set is locked.
9. Retention and deletion
We keep data only for as long as needed for the service, legal duties, disputes, security and accounting. You can delete traveller-profile items, trips, uploaded documents and your account. Account deletion deletes or anonymises your account data and traveller profiles, subject to records we must retain for legal, tax, fraud, payment, dispute or security reasons.
10. Automated decisions
Entry-requirement and readiness results are generated by applying data sources and rules to trip and document details you provide. paxID does not make solely automated decisions that produce legal or similarly significant effects on you within the meaning of GDPR Article 22. Border, immigration, airline and payment decisions are made by the relevant authority, airline, supplier or payment provider, not by paxID.
11. Personal data breaches
We maintain a procedure to detect, assess and record personal data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within the statutory time limit, and we notify affected users directly where the risk is high.
12. Complaints
Please contact us first at privacy@paxid.com. You also have the right to complain to your local data protection supervisory authority. In the UK, this is the Information Commissioner's Office. In the EU/EEA, this is usually the authority in the country where you live, work, or where the issue occurred.