Below is an overview of how your personal data is processed when you visit AirPlus’ website.
Who is the controller?
With this Privacy Statement, Lufthansa AirPlus Servicekarten GmbH (Dornhofstraße 10, 63263 Neu-Isenburg, Germany) (hereinafter, “AirPlus,”) would like to inform you about how your personal data is processed as part of AirPlus’ online offerings. You can access AirPlus’ online offerings directly at airplus.com (hereinafter, “this Website”).
In the context of this Privacy Statement, the term AirPlus Group refers to Lufthansa AirPlus Servicekarten GmbH (Germany), AirPlus International Srl (Italy), AirPlus International Ltd (UK), AirPlus International SA/NV (Belgium), AirPlus International Inc (U.S.A.)., AirPlus Payment Management Co., Ltd (China), AirPlus Int. Soluções de Pagamento (Brazil) and AirPlus International AG (Switzerland).
What is the purpose and legal basis of AirPlus’ processing of your data?
AirPlus processes personal data in compliance with the provisions of the EU’s General Data Protection Regulation (hereinafter, “GDPR”).
AirPlus processes personal data to meet its contractual obligations under Article 6 1 p. 1 b) of the GDPR. These obligations include, but are not limited to,
- entering into agreements regarding specific AirPlus products;
- dispatching agreement confirmations; and
- providing you with the information you need to use your AirPlus products.
AirPlus processes your data to comply with its legitimate interests under Article 6 1 p. 1 f) of the GDPR. These legitimate interests include, but are not limited to,
- providing you with the information you need to use your AirPlus products;
- preventing fraud, for example, credit card abuse, identity fraud, or the fraudulent obtainment of special conditions or rates;
- ensuring IT security and operation;
- preparing statistics to enhance AirPlus’ online offerings including using web tracking that enable limited profiling (find more information on objecting to this type of data processing in the section titled Data processing when you use this Website); and
- processing requests AirPlus received, for example, through contact forms or social media.
AirPlus processes your data based on your consent under Article 6 1 p.1 a) of the GDPR. This processing includes, but is not limited to,
- dispatching newsletters detailing the AirPlus Group’s offerings and information; and
- dispatching special information regarding the AirPlus Group’s market research and customer surveys.
AirPlus also processes your data to meet its legal obligation under Article 6 1 p. 1 c) of the GDPR. These obligations include, but are not limited to,
- combatting money laundering and preventing terrorism including collecting data concerning the beneficial owners of companies and identifying credit card applicants; and
- transmitting data to authorities in compliance with its legal obligations.
Which data is being processed when you use this website?
This Website uses small text files, referred to as cookies, which web portals save on visitors’ computer systems (computer, tablet or smartphone). Cookies can be used to store personal data. You can set your browser to prevent your activities from being traced through cookies (do-not-track, tracking protection list) or to prohibit third-party cookies from being stored in general. To object to the use of some web tracking solutions, you also will be required to set cookies. Because deleting all the cookies (automatically or manually) means deleting opt-out cookies as well, you may need to re-execute the opt-out functions you executed in the past.
AirPlus wants to offer you the opportunity to make informed decisions regarding cookies that are not mandatory for using the technical functions of this Website.
AirPlus differentiates between cookies that are mandatory for using the technical functions of this Website, and optional cookies.
To enable you to adjust your data protection settings for your visit to this Website in an individualised manner, AirPlus offers you the opportunity to define your preferences in these four categories: Operational Necessity, Statistics, Convenience and Personalization. The full scope of this Website will be available to you even if you object to the setting of cookies.
1. Operational Necessity category
Cookies in this category are mandatory for operating this Website and providing the functions thereof, for example, language selection and Portal login.
2. Statistics category
To continue enhancing its offerings and Website, AirPlus captures data to prepare statistics and conduct analyses. AirPlus uses the cookies in this category, for example, to determine the number of visitors to and the user-friendliness of specific pages of this Website and to optimise AirPlus-related content.
3. Personalization category
Cookies in this category are used to provide you with personalized content that matches your interests so that AirPlus’ offerings are particularly relevant to you.
To be able to adjust its advertising so that it is relevant to you and matches your current interests, AirPlus wants to draw conclusions concerning your current interests based on your visit to AirPlus pages and on your browsing behaviour. AirPlus uses third-party cookies and creates pseudonym usage profiles to address visitors returning to this Website (retargeting, remarketing) and to measure conversion rates. These third-party cookies and usage profiles then are analysed for advertising and monitoring purposes; they cannot be used to identify individual visitors.
AirPlus uses advertising cookies, for example, to
- store your visits to this Website to ascertain your interests;
- determine whether you clicked an advertisement;
- monitor the number of visitors who click specific advertisements;
- use third-party services to display advertisements tailored to your needs, interests or preferences;
- determine which advertisements and means of advertising prove efficient for AirPlus;
- display advertisements for products which you previously clicked or searched for;
- measure the number of advertisements displayed to avoid showing the same advertisements repeatedly; and
- display other interesting advertisements based on your use of this Website.
AirPlus uses the following cookies including third-party cookies:
|_gat_UA||This Google Analytics cookie is used by Google Analytics to monitor the number of requests in connection with its servers.||1 minute|
|_ga||This Google Analytics cookie facilitates user identification.||2 years|
|_gid||This Google Analytics cookie facilitates user identification.||1 day|
|AL_SESS-S||This cookie is used to allocate a unique ID to every visitor to this Website. The ID then is used to identify the user session so that existing sessions can be continued, if applicable.||End of session|
|aplus_country||This cookie is used to save the user’s country selection.||1 year|
|aplus_language||This cookie is used to save the language settings selected by the user.||1 year |
|apluscountryflag||This cookie is used to save the flag of the country selected by the user.||1 year|
|apluscountryname||This cookie is used to save the name of the country selected by the user.||1 year|
|aplus_language||This cookie is used to store the language selected by the user.||1|
|cb-enabled||This cookie is used to determine whether the user confirmed the data protection notice.||1 year|
|alertId||This cookie is used to determine whether the user closed a notification in the top menu on this Website.||1 year|
|pactive||This cookie is used to determine whether the user opened or closed the login menu for the AirPlus Business Travel Portal.||1 year|
|aplus_fold||This cookie is used to determine whether the user opened or closed the contact menu in the mobile view.||1 year|
|_hs_do_not_track||This cookie can be set to prevent the tracking code from sending any information to HubSpot. Setting this cookie is different from opting out of cookies, as it still allows anonymised information to be sent to HubSpot.||13 months|
|hs_ab_test||This cookie is used to consistently serve visitors the same version of an A/B test page they’ve seen before.||End of session|
|<id>_key||When visiting a password-protected page, this cookie is set so future visits to the page from the same browser do not require login again. The cookie name is unique for each password-protected page.||6 months|
|hs-messages-is-open||This cookie is used to determine and save whether the chat widget is open for future visits. It resets to re-close the widget after 30 minutes of inactivity.||30 minutes|
|hs-messages-hide-welcome-message||This cookie is used to prevent the welcome message from appearing again for one day after it is dismissed.||1 day|
|__hsmem||This cookie is set when visitors log in to a HubSpot-hosted site.||1 year|
|__hstc||The main cookie for tracking visitors. It contains the domain, utk, initial timestamp (first visit), last timestamp (last visit), current timestamp (this visit), and session number (increments for each subsequent session).||13 months|
|hubspotutk||This cookie is used to keep track of a visitor's identity. This cookie is passed to HubSpot on form submission and used when de-duplicating contacts.||13 months|
|__hssc||This cookie keeps track of sessions. This is used to determine if HubSpot should increment the session number and timestamps in the __hstc cookie. It contains the domain, viewCount (increments each pageView in a session), and session start timestamp.||30 minutes|
|__hssrc||Whenever HubSpot changes the session cookie, this cookie is also set to determine if the visitor has restarted their browser. If this cookie does not exist when HubSpot manages cookies, it is considered a new session.||End of session|
|messagesUtk||This cookie is used to recognize visitors who chat with you via the messages tool. If the visitor leaves your site before they're added as a contact, they will have this cookie associated with their browser. If you chat with a visitor who later returns to your site in the same cookied browser, the messages tool will load their conversation history.||13 months|
|AUTH_SESSION_ID||Used to connect to the same server via a load balancer (sticky session)||End of session|
|KEYCLOAK_LOCALE||Sets language information||End of session|
|KEYCLOAK_IDENTITY||Contains a token (JWT) with the user IDs||End of session|
|KEYCLOAK_SESSION||Session ID for the corresponding area (realm)||End of session|
|.AspNet.KeycloakOwinAuthenticationSample_cookie_auth||Serialised authentication cookie to validate the authenticated user in subsequent requests.||End of session|
|ASP.NET_SessionId||Generated unique session ID from .net to track the user session.||End of session|
|XSRF-TOKEN||Generated token to protect the portal from XSRF attacks by validating the request with this cookie.||End of session|
|_RequestVerificationToken||Generated verification cookie from VC to validate user requests.||End of session|
|_hjClosedSurveyInvites||This cookie is set once a visitor interacts with a Survey invitation modal pop-up. It is used to ensure that the same invite does not re-appear if it has already been shown.||365 days|
|_hjDonePolls||This cookie is set once a visitor completes a Poll using the Feedback Poll widget. It is used to ensure that the same Poll does not re-appear if it has already been filled in.||365 days|
|_hjMinimizedPolls||This cookie is set once a visitor minimises a Feedback Poll widget. It is used to ensure that the widget stays minimized when the visitor navigates through your site.||365 days|
|_hjDoneTestersWidgets||This cookie is set once a visitor submits their information in the Recruit User Testers widget. It is used to ensure that the same form does not re-appear if it has already been filled in.||365 days|
|_hjMinimizedTestersWidgets||This cookie is set once a visitor minimises a Recruit User Testers widget. It is used to ensure that the widget stays minimised when the visitor navigates through your site.||365 days|
|_hjDoneSurveys||This cookie is set once a visitor completes a survey. It is used to only load the survey content if the visitor hasn't completed the survey yet.||365 days|
|_hjIncludedInSample||This cookie is set to let Hotjar know whether that visitor is included in the sample which is used to generate heat maps, funnels, recordings, etc.||365 days|
|_hjShownFeedbackMessage||This cookie is set when a visitor minimises or completes Incoming Feedback. This is done so that the Incoming Feedback will load as minimized immediately if they navigate to another page where it is set to show.||365 days|
Description of third-party cookies used for usage-based online advertising
AirPlus uses the following companies to collect data for the provision of usage-based online advertising. The tools used for tracking and remarketing are categorised as follows:
- Google AdWords Remarketing – Personalisation category
- Google Analytics – Personalisation category
- DoubleClick (HubSpot) – Personalisation category
- DoubleClick Search – Statistics category
- Hotjar – Statistics category
Google AdWords Remarketing
This Website uses the remarketing function offered by Google Inc. (hereinafter, “Google”). This function is implemented through a cookie and is used to present interest-related advertisements to visitors of this Website as part of Google’s advertising network. On this Website, visitors may be shown advertisements relating to content they previously accessed on other websites. According to Google, Google does not collect any personal data during this process. If you do not want Google’s remarketing function, you can deactivate it by adjusting the setting at http://www.google.com/settings/ads. For more information on Google’s remarketing activities and privacy statement, please go to http://www.google.com/privacy/ads/.
This Website uses Google Analytics, a web analysis service offered by Google Ireland Limited, (Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland). The use includes the Universal Analytics operation which facilitates the association of data, sessions and interactions across devices with a pseudonym user ID to analyse users’ activities across devices.
You may refuse the storage of cookies by adjusting your browser settings accordingly. In addition, you can object to Google’s collection and processing of data generated by cookies relating to your use of this website (including your IP address). To do so, please download and install the browser add-on. Opt-out cookies are used to prevent your data from being collected when you visit this Website in the future. To prevent Universal Analytics from collecting your data across devices, please set the opt-out cookie in all the systems you are using. Click the link to set the opt-out cookie: Deactivate Google Analytics.
AirPlus uses Hotjar to gain a better understanding of its customers’ needs and to optimize its services continuously. Hotjar is a technology service that helps AirPlus to better understand its users’ experiences, for example, the time they spend on which pages or the links they click. This user feedback helps AirPlus improve this Website continuously. AirPlus uses Hotjar’s services including heat maps, visitor recordings, funnels and form analysis. Hotjar uses a tracking code and a cookie to receive data concerning the behaviour of AirPlus’ users and their devices. The following information is captured through Hotjar’s tracking code: the device’s IP address (captured and stored in an anonymized form only), size of the device’s screen, type of device (unique device codes), browser information, geographical location (country only) and the language preferences for displaying this Website. Hotjar saves this information in a pseudonym user profile. Hotjar does not associate this information with visitors to this Website. Instead, Hotjar shows the behaviour of visitors to this Website. Hotjar or AirPlus will not use this information to identify individual users or match it with other data concerning individual users. For details, please go to Hotjar’s privacy statement available at https://www.hotjar.com/legal/policies/privacy.
You can object to Hotjar’s creating a user profile, saving data concerning your use of this Website and using tracking cookies on other websites by clicking https://www.hotjar.com/legal/compliance/opt-out.
b. Customer Portal
If you want to use additional functions, you can register for AirPlus’ Customer Portal. AirPlus will use the data you provide at registration for authentication purposes only. Please ensure the mandatory information requested during the registration process is complete; otherwise, AirPlus will reject your registration.
AirPlus will notify you about important adjustments to its offerings, for example, or necessary technical adjustments by sending you an e-mail to the address you provide at registration.
c. Identification Portal
When you use AirPlus’ Identification Portal, AirPlus processes only the data you enter into the Identification Portal to meet its obligations under anti-money laundering laws, namely to identify the person acting on behalf of AirPlus’ contracting partner when entering into an agreement or to prevent money laundering and terrorism financing.
After you have entered your data and verified your e-mail address, a personal identifier (hereinafter, “PID”) will be created. The personal data provided by you will be stored in connection with the PID together with the additional data collected during identification by the entity you selected. If you enter into additional agreements with AirPlus in the future, entering your PID will suffice; you will not need to undergo the identification process again.
d. Contact form
On this Website you have the opportunity to communicate with AirPlus through a contact form. To be able to respond to your requests, AirPlus will collect the information you provided concerning the form of address, your last name, first name and e-mail address. If you provide your telephone number and check the Call-back box, AirPlus will be happy to call you in response to your requests. You are free to provide additional data to facilitate the allocation and processing of your requests by AirPlus.
All data collected in contact forms will be used exclusively to respond to your requests. To this end, your requests along with your data may have to be forwarded to the AirPlus company in charge of supporting you as a customer.
If you submit a request via a contact form, AirPlus will save the information you provide in the form, including your contact information, to process your requests and, if applicable, to answer any follow-up questions you may have. AirPlus will not disclose this data.
How long will your data be stored?
Your personal data will be erased once it is no longer needed for the purpose intended. Subject to legal regulations, AirPlus will store your data until the legal retention period expires. Depending on the legal basis, retention periods typically are between six and 10 years. In addition, your data will be stored until the legal statute of limitations expires (typically, three years) provided storing your data is required for asserting, exercising or defending legal claims. After this date, the respective data will be erased routinely.
Which recipients will your data be shared with?
Your personal data may be shared with persons in the categories specified below for the purposes described in this Privacy Statement and for the respective legal reasons (fulfilment of agreements, legitimate interests, consent, or legal obligations):
1. Data processors
Carefully selected partners that deliver services on behalf of AirPlus will be involved in the processing of your data. These service providers will treat your personal data only as data processors on behalf of AirPlus and according to AirPlus’ instructions.
AirPlus uses service providers in the following categories:
- IT services providers (hosting and web infrastructure services) in Europe;
- service providers for customer relationships (call center services) in Europe; and
- service providers for compliance with anti-money laundering regulations (anti-money laundering audits) in Europe.
For details regarding the transmission of data to service providers located in countries outside the European Union or the European Economic Area (hereinafter, “Third Countries”), please refer to the section titled Transmission of your data to Third Countries.
2. Third parties
AirPlus also may share your personal data with reliable third parties that support AirPlus with the provision of this Website, the Customer Portal, the Identification Portal and contract documents provided these third parties undertake to treat your personal data confidentially and to comply with the GDPR.
In addition, AirPlus may share your personal data with third parties in the following categories:
- external auditors in the case of audits or investigations due to legal obligations or legitimate business interests;
- external attorneys or courts as part of the assertion of legal claims;
- authorities (e.g., Federal Financial Supervisory Authority and/or other national financial market supervisory authorities, financial authorities, the Bundeszentralamt für Steuern (Federal Central Tax Office) and/or other national tax authorities) to comply with the applicable laws; and
- all of the AirPlus Group and the Lufthansa Group.
3. Transmission of your data to Third Countries
Your personal data will be transmitted to Third Countries only within the scope required to meet the respective purposes (e.g., reporting obligations under tax laws). Before personal data is transmitted to a processor or a third party in a Third Country, AirPlus will ensure that a GDPR-compliant transmission mechanism is in place (e.g., the sample clauses regarding the transmission of personal data to Third Countries provided by the European Commission). To obtain a copy of the applicable guarantees, please contact AirPlus at the information available under Contact at the end of this Privacy Statement.
What are your rights regarding data protection?
1. Data subjects’ rights
Every data subject has the right to information under Article 15 of the GDPR, the right to correction under Article 16 of the GDPR, the right to erasure under Article 17 of the GDPR, the right to restrict the processing of data under Article 18 of the GDPR, the right to object under Article 21 of the GDPR (find more information in the section titled Your right to object under Article 21 of the GDPR), the right to portability of data under Article 20 of the GDPR, and the right to lodge a complaint with a supervisory authority under Article 77 of the GDPR, in particular, the supervisory authority responsible for your habitual residence or your country or the supervisory authority responsible for AirPlus named below:
Data Protection Officer of the State of Hesse
Telephone: +49 611 1408 – 0
If you wish to exercise your rights, please contact us at:
Lufthansa AirPlus Servicekarten GmbH
Data Protection Officer, JX JDO
How can you revoke your consent?
You can revoke your consent to AirPlus processing your personal data at any time. Please note that your revocation will apply to the future only and will not concern any past activities or processing.
To revoke your consent to receiving AirPlus’ newsletter, please click on the Unsubscribe link included in each newsletter. In addition, you can contact AirPlus at the information indicated below under Contact.
Your right to object under Article 21 of the GDPR
You have the right to object, on grounds relating to your particular situation, at any time to processing of your personal data which is based on Article 6 1 f) of the GDPR, including profiling based on those provisions. Your objection notice does not need to be in a specific form. Please contact AirPlus at the information indicated below under Contact.
Social media functions
This Website includes several social media functions including, but not limited to,
- functions you can use to forward or recommend AirPlus-related content (e.g., Share and Like buttons); and
- links from AirPlus’ offerings to social media, for example, when you log into your personalised section on this Website (hereinafter, “Social Login”).
As part of its online offerings, AirPlus offers you the opportunity to distribute and recommend content in social media. When you visit this Website and use the recommendation functions, AirPlus will share the URL with the social media you selected.
This Website includes the following social media plug-ins equipped with the two-click solution:
With the two-click solution, your data will not be transmitted to the respective social media network company until after the respective plug-in button has been activated (consent).
To this end, this Website uses the social sharing button developed as part of c’t magazine’s Shariff project to protect visitors’ privacy against prying social media such as Facebook, Twitter, YouTube, Xing or LinkedIn. To share pages with friends, visitors only need to click on the Shariff button.
Thanks to the Shariff button you can use social media without unnecessarily compromising your privacy. Shariff replaces the conventional share buttons offered by social media and protects your browsing behaviour from prying eyes. Nonetheless, you only have to click the button if you want to share information.
Conventional social media buttons transmit your user data to the social media every time you access their pages and provide precise information regarding your browsing behaviour (user tracking) even if you are not logged in or have joined the respective social medium. In contrast, the Shariff button only establishes direct contact between the social medium and you, the visitor, when you actively click the button. In this way, Shariff prevents you from leaving a digital trace on every page you visit.
Please note that AirPlus has no knowledge of or influence on how social media handle information you shared and whether this information is provided to other websites. AirPlus suggests that you read the respective data protection notices carefully.
Data protection in connection with AirPlus’ newsletter
Please note that if while in the Newsletter section of this Website you register to receive AirPlus’ newsletter, until you revoke your subscription or the AirPlus Group discontinues the newsletter the following shall apply:
AirPlus uses the double opt-in procedure to register for our newsletter. This means that AirPlus will send an e-mail to the address you provided asking you to confirm your registration to receive the newsletter. If you fail to confirm within 14 days, your information will be blocked and then deleted automatically after one month. AirPlus will save information regarding the time of your registration and, respectively, your confirmation. This is required to evidence your registration and to prevent, or resolve, abuse of your personal data.
Your consent to the processing of your personal data applies to the following information:
- your e-mail address;
- your last name, first name, title, salutation/form of address;
- your preference for the newsletter language; and
- your usage behavior.
Your consent applies to AirPlus’ dispatching its newsletter to the e-mail address you provided and to its collection of information on your use of the newsletter so the content you receive can be tailored to meet your interests. You may revoke your consent at any time, effective immediately. To do so, please use the Unsubscribe link at the bottom of each newsletter or contact AirPlus as indicated below under Contact.
AirPlus’ newsletters provide you with information about AirPlus’ current services and products and offer updates on news and trends in the travel and payment services industry. The newsletters also offer AirPlus-related facts and invitations to attend selected events (e.g., trade fairs, customer events, training sessions) supported by AirPlus.
Please note that AirPlus will analyze your user behavior in connection with the newsletter based on the information you provide in the consent form. To this end, the one-pixel image files represented by the tracking pixels contained in e-mails sent by AirPlus are saved on AirPlus’ website. AirPlus’ analyses are based on your personal data and the tracking pixel in connection with your e-mail address and an individual ID.
The individual ID also is integrated into the links included in AirPlus’ newsletters. AirPlus uses the data so collected to create a user profile based on which the newsletter will be tailored to meet your individual interests. For indications regarding your personal interests, AirPlus will collect information regarding the time when you read the newsletters and the links you click on in the newsletters. The data then will be linked to your actions on AirPlus’ website and social media pages.
Who can you contact?
If you have any questions regarding data protection in connection with this Website or the services offered through this Website, please contact AirPlus’ Data Protection Officer at
Lufthansa AirPlus Servicekarten GmbH
Data Protection Officer, JX JDO
If you contact us by e-mail, your communications will not be encoded.
In addition, you can contact AirPlus via the contact form or AirPlus’ social media pages.