Privacy policy
FSP, d.o.o. · version 1.0 · valid from 6. 9. 2026
This policy explains which personal data we collect on the website www.ifly.si, why we process it, who we share it with, how long we keep it and what rights you have. It is written for users, not lawyers; where necessary, it refers to the General Data Protection Regulation (GDPR) and the Personal Data Protection Act (ZVOP-2).
Controller
The controller of personal data is FSP, d.o.o., Vesca 6a, 1217 Vodice, registration number 3381137000. Contact for privacy questions: info@ifly.si, phone 031 305 048. We are not required to appoint a data protection officer; questions are handled by the company's management.
What data we process and why
| Purpose | Data | Legal basis |
|---|---|---|
| Booking a tandem flight, enrolling in a course, buying goods or a gift voucher, payment, notifications about the date, issuing the invoice and ticket | full name, email, phone, for tandem flights the passenger's weight and preferred date, for courses the date of birth and weight (equipment selection), for minors the name and contact of a parent or guardian, delivery address, order and payment details (without card details), organisational notes | contract or steps prior to entering into a contract (Article 6(1)(b) GDPR) |
| Keeping invoices and accounting records, records of tandem flights and tickets sold | details of the order, invoice, payment, ticket and completed flight | legal obligation (Article 6(1)(c) GDPR; tax, accounting and aviation regulations) |
| User account (My Course): overview of enrolments and dates, flight log, notification settings | email, password (stored only as a hash), name, phone, town, address, date of birth, skill level | contract (use of the account at your request) |
| SMS and email notifications about scheduled course dates | phone, email, selected categories | contract for notifications about dates you are enrolled in; consent for notifications about newly scheduled courses, which you can withdraw at any time in the settings |
| Newsletter | consent (Article 6(1)(a) GDPR), withdrawal at any time | |
| Showing your name, town and chosen contact to other participants of the same date for arranging carpooling | name, town, phone and/or email – at your choice | separate consent, off by default; refusal does not affect the enrolment |
| Website visitor statistics (Matomo, installed on our server) | pseudonymised identifier, pages viewed, device type | consent via the cookie settings; without consent the analytics is not loaded |
| Website security: preventing abuse, lockout after failed logins, server logs, verifying staff logins with an SMS code | IP address, access time, browser, email at login, staff phone | legitimate interest (Article 6(1)(f) GDPR): protecting the system and data |
| Proof of acceptance of the terms and conditions at the time of the order | version and hash of the accepted terms, time of acceptance, order identifier, IP address | legitimate interest: proving the content of the concluded contract |
The "I confirm that I have read the Privacy Policy" checkbox at booking or ordering is not consent to processing. Data required to conclude and perform the contract is processed on the basis of the contract; without it we cannot provide the service. We request consent only for genuinely optional purposes (newsletter, analytics, sharing your contact with other participants).
Health and other sensitive data
We do not collect health data. Do not enter medical diagnoses or other sensitive personal data in the organisational notes field; the field is intended only for information related to organising the date.
Who we share data with
Subcontractors who actually deliver the service
Tandem flights are carried out by independent actual operators and their pilots, and courses by FSP or subcontractors (instructors). We pass on to the selected operator, pilot or course provider only the data needed to deliver the specific service: name, contact details, date, weight, age information or guardian consent for minors, and essential organisational information. The subcontractor may not use this data for its own marketing.
FSP determines each partner's role under the GDPR (processor, independent controller or another role) in the contract with the partner, in line with how the data is actually processed. In the administration we keep a record of this role and a link to the partner's privacy notice, where it has one. You will receive the details of the actual operator of your flight in the ticket.
Service providers we use
- Stripe — processing of online payments (cards, Apple Pay, Google Pay, PayPal). You enter card details directly in Stripe's form; FSP never receives them. Stripe Payments Europe Ltd. (Ireland) may transfer data to the USA; the transfer is based on standard contractual clauses and Stripe's commitments. More at stripe.com/privacy.
- PayPal — when you choose to pay with PayPal, the payment is processed via Stripe and PayPal under their privacy rules.
- Matomo — visitor analytics installed on our server; data is not sent to third parties. Loaded only with your consent.
- Email server — we send confirmations, tickets and notifications via our hosting provider's email server (SMTP).
- SMS — we send SMS messages via our own GSM modem and the mobile operator's network; message content does not pass through third-party intermediaries.
- Country detection by IP address — for the default site language we use a local GeoIP database on our server; the IP address is not sent to third parties.
- Hosting — the website and database run on a server under FSP's control.
- Public authorities — where required by law (tax, inspection and aviation authorities, courts).
With providers that process data on our behalf, the relationship is governed by a data processing agreement or by their terms where these contain appropriate commitments; the actual position for each partner is kept in an internal register. We do not sell data and do not pass it on for third-party marketing.
Sharing contacts between course participants
Your name, town and contact details are not automatically visible to other participants. If you wish, you can give separate consent at enrolment or in your profile settings:
You choose whether to allow your phone, email or both to be shown. Refusal does not affect the enrolment. We stop sharing the data immediately after consent is withdrawn and no later than 30 days after the end of the date.
Minor participants
Minors may fly in tandem or attend a course with the written consent of a parent or guardian. When enrolling a minor, we require the name and contact details of a parent or guardian; the consent must be provided before the service takes place (secure file upload or confirmation of receipt in the administration). The consent is not publicly accessible and is kept only until the expiry of the period for any legal claims. Without confirmed consent, the flight or participation is not marked as ready to go ahead. A user account may be created independently by a person aged at least 16; younger persons use it with the consent of a parent or guardian.
Retention periods
- accounting and tax records (invoices): in line with statutory periods (as a rule 10 years);
- contract and order data, proof of acceptance of the terms: for as long as necessary to perform the contract and to establish or defend legal claims (as a rule 5 years after performance);
- records of tandem flights and tickets sold: at least two years, or longer where required by another regulation, an open dispute or an incident;
- course and training data: in line with the applicable training programme, statutory requirements and the period for legal claims;
- data a participant voluntarily shares for carpooling: until consent is withdrawn or no later than 30 days after the date;
- newsletter: until consent is withdrawn;
- user account: until deleted at your request or 3 years after the last activity, of which we notify you before deletion;
- guardian consent for minors: until the expiry of the period for legal claims relating to the service;
- server logs and security records: no more than one year;
- health details: we do not collect them; if we were to lawfully receive them in an individual case, we delete them immediately after the service has been provided.
Cookies
Which cookies we use, which are essential and how to change or withdraw your consent to analytics is described on the page Cookies.
Your rights
- access to your data (Article 15 GDPR);
- rectification of inaccurate data (Article 16);
- erasure, where we no longer need the data or there is no other legal basis (Article 17);
- restriction of processing (Article 18);
- portability of data you have given us on the basis of a contract or consent (Article 20);
- objection to processing based on legitimate interest (Article 21);
- withdrawal of consent at any time, without affecting the lawfulness of processing before the withdrawal.
Send your request to info@ifly.si or by post to FSP, d.o.o., Vesca 6a, 1217 Vodice, marked "personal data". We respond within one month at the latest; for more complex requests we may extend the period by up to two months, of which we will inform you.
Supervisory authority
If you believe we are processing your data in breach of the regulations, you can lodge a complaint with the Information Commissioner of the Republic of Slovenia, Dunajska cesta 22, 1000 Ljubljana, phone 01 230 97 30, email gp.ip@ip-rs.si, www.ip-rs.si.
Changes to the policy
We may update the policy when our services, providers or regulations change. The current version is always published on this page with its effective date; we notify registered users of material changes by email.
Related documents: General terms and conditions · Cookies · Company info