Privacy Notice

This page contains information relating to the processing of personal data by Corsair. It is separate from the Cookie Policy. 

1. Who is responsible for processing your personal data?

Corsair, acting as the data controller, processes your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable French data protection laws.

2. What data do we collect?

Contact details, booking information, payment data, browsing data, travel preferences, communications with customer service, and information necessary for the performance of the transport service. The provision of certain data (in particular data required for issuing your travel ticket and complying with obligations to transmit information to the competent authorities, such as API/PNR data) is necessary for the performance of the transport contract and compliance with our legal obligations. Failure to provide such data may prevent boarding or the provision of the requested service.

3. Why do we use your data?

We process your data for the following purposes, each based on a legal basis indicated in parentheses: performance of the transport contract (performance of a contract); customer relationship management (performance of a contract and legitimate interest); compliance with our legal obligations, including the transmission of data to competent authorities where required by law, such as API/PNR obligations (legal obligation); flight safety and fraud prevention (legal obligation and legitimate interest); service personalization (legitimate interest, or consent where cookies or similar tracking technologies are used for this purpose); and marketing communications (consent, except where otherwise permitted under applicable regulations governing so-called "soft opt-in" marketing).

4. What are the legal bases for processing?

The relationship between each processing purpose and its legal basis is detailed in Section 3 above. In general, depending on the purpose concerned, Corsair relies on the performance of a contract, compliance with a legal obligation, its legitimate interests, your consent, or, in exceptional circumstances, the protection of your vital interests or those of another person (e.g. in the event of a medical emergency).

5. With whom do we share your data?

With service providers necessary for the performance of your journey, competent authorities where required by law (API/PNR), and certain partners acting on behalf of Corsair.

5 bis. Is your data transferred outside the European Union?

Some of your data may be transferred outside the European Union, particularly to technical or marketing service providers established in third countries or to competent foreign authorities (for example, in connection with API/PNR obligations). Where such a transfer is made to a country that has not been recognized by the European Commission as providing an adequate level of protection, it is subject to appropriate safeguards.

6. How long do we keep your data?

Retention periods vary depending on the nature of the data processed, the purposes pursued, and the applicable legal obligations. Personal data is retained for as long as necessary to achieve the purposes for which it was collected, and is then archived or deleted in accordance with applicable regulations. Where data is collected through cookies or similar technologies, the applicable retention periods are set out in our Cookie Policy . For guidance: booking and transport data is retained for the duration of the contract, plus the applicable statutory limitation periods (particularly for commercial and tax purposes); personal data used for marketing purposes is retained for a maximum period of one year from the last meaningful contact unless you object, after which the data is anonymized and archived; data required to comply with legal obligations (flight safety, fraud prevention, API/PNR obligations) is retained for the periods specified by the laws applicable to each obligation.

7. Your rights

You have the right to access, rectify, erase, restrict the processing of, object to the processing of, and request the portability of your personal data, as well as the right to withdraw your consent where consent is the legal basis for processing.

8. Contact the Data Protection Officer (DPO)

Data Protection Officer     
Corsair     
2 place de l'Equerre – 94150 Rungis, France     
E-mail: dpo@corsair.fr     
You may also lodge a complaint with the French Data Protection Authority (CNIL): https://www.cnil.fr