Privacy policy

Version: 0.2 — Last updated: 14 September 2026

Translation. This English version is provided for information. The French version is the binding text and prevails in the event of any discrepancy.
Working version. Working draft — legal review required before publication. The postal address of the controller's registered office and the exact details of the subprocessors are still to be filled in. The text is published as it stands so that it can be read.

1. Who are we?

CHAINIT, a société par actions simplifiée unipersonnelle (SASU) registered under SIRET 83154416800022, is the controller of the personal data collected through the Farygo application (the "Application").

Contact: privacy@farygo.com

2. What data do we collect?

CategoryData concernedPurpose
Account dataEmail, password (encrypted) or Google/Apple identifier, display name (optional)Creating and managing the user account
PreferencesLanguage, currency, notification preferences, followed routes, discount thresholdsProviding the service (personalised alerts)
Consent dataAcceptance of the Terms (date, version), marketing consentProof of consent, honouring the user's choice
Usage dataSearch history, clicks through to airlines (RG-26)Improving the service, aggregate statistics
Technical dataIP address, device type, push notification identifierSecurity, technical operation of the Application

We collect no sensitive data within the meaning of Article 9 GDPR (health, origin, opinions, etc.) and no banking data (no payment is processed inside the Application).

3. On what legal basis do we process your data?

  • Performance of a contract — for the operation of the account and the service (followed routes, alerts)
  • Consent — for marketing communications and, where applicable, non-essential analytics cookies
  • Legitimate interest — for improving the service from aggregated, anonymised usage statistics
  • Legal obligation — for retaining certain data under accounting or tax obligations (paid account)

4. Who has access to your data?

Your data is accessible to:

  • CHAINIT's technical teams, within the limits of their duties
  • Our technical subprocessors, listed below, bound by data processing agreements compliant with the GDPR
SubprocessorRoleData concerned
Amazon Web Services (AWS)Hosting, infrastructure (us-east-1 region, United States — see section 5)All Application data
[Duffel / the flight data provider selected]Flight searchNo personal data transmitted (anonymised searches: origin, destination, dates)
[Travelpayouts or equivalent, if enabled]Affiliate redirection to airlinesRedirection click (no identifying personal data transmitted beyond what is necessary)
Email delivery provider (Amazon SES or equivalent)Sending alerts and notificationsEmail address

We never sell your data to third parties for advertising purposes.

5. Where is your data hosted?

Data is hosted on AWS infrastructure, in the `us-east-1` region (Northern Virginia, United States). It is therefore transferred outside the European Union.

That transfer is framed by the Standard Contractual Clauses adopted by the European Commission, which Amazon Web Services incorporates into its AWS GDPR Data Processing Addendum, applicable as of right to all AWS customers. AWS is also certified under the EU-U.S. Data Privacy Framework, an adequacy framework recognised by the European Commission's adequacy decision of 10 July 2023.

The data transferred is limited to what is described in section 2: no sensitive data within the meaning of Article 9 GDPR, no banking data.

> ⚠️ To be verified by legal counsel before publication. This section describes the hosting actually in place at the time of writing. Two points call for validation: (1) whether AWS's Data Processing Addendum alone is sufficient in light of the Transfer Impact Assessment that post-Schrems II case law recommends documenting; (2) whether to migrate to an EU region (eu-west-1 Ireland or eu-west-3 Paris), which would remove the transfer question entirely. A migration was considered and set aside — see the note below.

6. How long do we keep your data?

DataRetention period
Active accountFor the whole time the service is used
Inactive accountAutomatic deletion after 3 years and 6 months of inactivity (with a prior warning email)
Search/click history24 rolling months
Data subject to a legal obligation (invoicing)The applicable statutory period (generally 10 years for accounting records)

7. What are your rights?

Under the GDPR, you have the following rights:

  • Right of access — obtain a copy of the data concerning you
  • Right to rectification — correct inaccurate data
  • Right to erasure — request deletion of your account and your data (see section 8)
  • Right to portability — receive your data in a structured, machine-readable format
  • Right to object — object to processing based on legitimate interest
  • Right to withdraw consent — at any time, for processing based on consent (e.g. marketing), without affecting the lawfulness of processing carried out beforehand
  • Right to lodge a complaint — with the CNIL (www.cnil.fr) if you consider your rights are not being respected

You can exercise these rights directly from the Application's settings (data export, account deletion) or by contacting us at privacy@farygo.com.

8. How do you delete your account?

From the Application's settings, you can request deletion of your account. Deletion takes effect within 30 days at most. Data strictly necessary to comply with a legal obligation may be kept beyond that, within the limits provided by law; everything else is deleted or anonymised.

9. Cookies (web version)

The Application's website shows a consent banner on the first visit, before anything non-essential is stored. Two purposes are presented separately — audience measurement and campaign measurement — and are consented to separately: you may accept one and refuse the other. Nothing is pre-ticked, refusing is as easy as accepting, and your choice can be changed at any time from the "Manage my cookies" link present on every page. Cookies strictly necessary to the operation of the service require no prior consent. The details are in the [cookie policy](/en/cookies).

10. Security

We implement appropriate technical and organisational measures (password hashing, encryption of data at rest and in transit, access control) to protect your data against unauthorised access, loss or disclosure.

11. Data breach

In the event of a breach likely to result in a risk to your rights and freedoms, we undertake to notify the CNIL within 72 hours and to inform you as soon as possible, in accordance with Article 34 GDPR.

12. Changes to this policy

This policy may be updated. Any substantial change will be notified to you by email or by a notification in the Application.

13. Contact

For any question about this policy or about exercising your rights: privacy@farygo.com


This English version is a translation provided for information. The French version — [Politique de confidentialité](/confidentialite) — is the text that binds, and prevails in the event of any discrepancy.

[Still to be completed before publication: the postal address of CHAINIT's registered office, the exact details of the subprocessors once the providers are definitively selected (Duffel/Travelpayouts confirmed), appointment of a DPO if user volume warrants it, mention of the competent supervisory authority if activity extends outside France.]