Roles and instructions
The transfer company is the controller and PaxWhere is the processor for passenger and booking data entered into the service. PaxWhere processes data only to provide, secure, support and maintain the service and on the company’s documented in-product instructions, unless law requires otherwise.
Subject matter and duration
Processing covers airport-arrival coordination, secure passenger-link delivery, passenger-declared status collection and the timestamped Operations record for the duration of the company account and the retention period described in the Data Retention notice.
People and data
Data subjects are passengers and company users. Data may include names, business emails, booking references, flight details, scheduled times, meeting instructions, contact settings, passenger-declared stages, help/contact actions and event timestamps.
Security and confidentiality
PaxWhere limits Operations access to authenticated company users, separates records by company, uses unguessable passenger tokens and preserves append-only event history. People authorized to handle the service must keep information confidential.
Subprocessors
Current core subprocessors include Supabase for authentication and OpenAI Sites and its hosting infrastructure for application delivery and storage. Google acts as an optional identity provider when a user chooses Google sign-in. PaxWhere will use subprocessors only as needed to provide the service and will require appropriate data-protection commitments.
Assistance, incidents and deletion
PaxWhere will reasonably assist the company with data-subject requests, security incidents and compliance information. Requests can be sent to info@paxwhere.com. At account closure, the company may request deletion or return of personal data, subject to legal, security and backup-retention requirements.