Travel ID Privacy Notice
October 2024
The purpose of this Travel ID Privacy Notice (referred to below as “Privacy Notice”) is for us to inform you about the processing of your personal data in connection with your use of Travel ID.
We, the airlines of the Lufthansa Group and Miles & More GmbH, as the operators of Travel ID, would like to offer you our services within the Lufthansa Group in the most convenient way possible and provide you with a travel experience that is tailored to you and your particular wishes and expectations, from your first visit to our website and other touchpoints through to the end of your trip and beyond. Travel ID gives you the option of creating a free customer profile that is valid for all Travel ID operators and allows you access to a wide range of services.
The creation of a Travel ID profile and provision of the data needed for this is voluntary. However, some of our services are available exclusively to our Travel ID customers. This applies, for example, to the option of receiving personalised flight offers and additional services on the booking platforms of the Lufthansa Group Airlines.
This privacy statement is aligned with the applicable data protection regulations; depending on the scope of application, these include the GDPR as well as any other legally provided national data protection laws and regulations.
The operators of Travel ID are Austrian Airlines AG, Brussels Airlines SA/NV, Deutsche Lufthansa AG, Eurowings GmbH, EW Discover GmbH and Swiss International Air Lines AG as the “Lufthansa Group airlines” and Miles & More GmbH.
Unless otherwise stated in this Privacy Notice, “we” or “us” or “Travel ID operators” refers to the Lufthansa Group airlines and Miles & More GmbH as the controllers with joint responsibility (“Joint Controllers”) for the processing of your personal data as defined in Article 26 GDPR.
More information and contact addresses for the Lufthansa Group airlines and Miles & More GmbH can be found in the respective privacy policies of the Travel ID operators.
If you have any data protection-related queries in connection with Travel ID, please contact the following offices:
The data protection officer of Deutsche Lufthansa AG, Miles & More GmbH, Eurowings GmbH and EW Discover GmbH:
Lufthansa Aviation Centre
Airportring
60546 Frankfurt am Main
Germany
Data protection officer of Austrian Airlines AG:
PO Box 100
1300 Vienna Airport
Austria
Data protection officer of Swiss International Air Lines AG:
Postfach
8058 Zurich Airport
Switzerland
Data protection officer of Brussels Airlines SA/NV
1831 Machelen
Belgium
When you register for Travel ID, we ask for your email address, your title, your first and last names, your date of birth and a password as mandatory information. Your country and preferred language settings will be automatically transferred, where technically feasible, using the country and language settings you entered on the respective websites or other touchpoints of the Travel ID operators. This information is required in order to create a Travel ID profile and to use the services described in detail in the Travel ID Terms and Conditions of Use. You have the option of adding further information to your Travel ID profile on a voluntary basis. These can be, for example, your address, mobile phone number, payment data or your preferences (such as preferred departure airport).
Based on your activities linked to your Travel ID profile, we will show you anonymous statistics (e.g. your position in the ranking of kilometres flown) and/or “badges” (e.g. a badge for certain achievements).
If you want to create a Travel ID profile for your child or your child would like to create their own profile and is under the age of 18, the consent of a parent or legal guardian is required. After sending the completed registration form, the parent or legal guardian will receive an email requesting them to consent to the creation of the Travel ID profile by clicking on the link provided in the email. If the parent or legal guardian does not consent within the specified timeframe, all personal data entered will be deleted.
The legal basis for processing your data is the performance of the contract in accordance with Art. 6(1)(b) GDPR.
You also have the option of storing other personal data in your Travel ID profile based on your consent. You can find details about this in the relevant sections of this Privacy Notice.
If necessary to fulfil the contract, we will send you messages about status changes in your Travel ID profile. This includes, among other things, the expiry of the validity of your travel documents, payment methods or password uploaded via your Travel ID profile.
If you have not logged into your Travel ID profile for three years, we will ask you to log in again. If we do not see any activity in your Travel ID profile within another six months, we will delete it (see paragraph “Deletion of your Travel ID profile”).
The legal basis for processing your data is the performance of the contract in accordance with Art. 6(1)(b) GDPR.
When you visit our websites, use our mobile apps and other touchpoints on the ground and on board, our aim is to make it easier and quicker for you to find and use the information that is relevant to you. You therefore have the option of registering there with your Travel ID and being contacted personally, as well as receiving information that matches your current flight booking or your Miles & More membership, for example.
If you do not wish to use the login service, you are, of course, free to use the website/touchpoints without logging in. In this case, the respective content will be displayed to you in a non-personalised manner.
The legal basis for processing your data is the performance of the contract in accordance with Art. 6(1)(b) GDPR.
We use the data you enter in your Travel ID profile to make the booking process easier for you through pre-filled forms. This can be data you actively provided during registration or added at some later point, or data you gave as part of a previous booking in relation to your Travel ID and which we automatically take into account for another booking. We also use the data you gave during the booking process to provide you with pre-filled forms, for example for online check-in and at self-service check-in machines. If you fill out other forms, such as during your participation in a lucky draw or when you send customer feedback using one of our electronic feedback forms on the website, the necessary contact details required are also pre-populated from your Travel ID profile.
The legal basis for processing your data is the performance of the contract in accordance with Art. 6(1)(b) GDPR.
Flight bookings are automatically stored and shown in your Travel ID profile if you made them while logged in. If you subsequently want to add a flight booking to your Travel ID profile, we will check the booking for completeness and if needed, we will add further information that you have stored in your profile. No data will be overwritten without your consent.
Amongst other things, the overview of your flight bookings is limited to 10 years and includes the creation and display of flight statistics.
If you change your previous customer profile from one of the Lufthansa Group airlines to a Travel ID profile, your past flight bookings from your previous customer profile will also be displayed in your Travel ID profile.
The legal basis for processing your data is the performance of the contract in accordance with Art. 6(1)(b) GDPR.
We use the data you have entered in your Travel ID profile to be able to offer you personalised services. We process data that you entered in your Travel ID profile during registration or at a later date, as well as data that we have recorded, for example, as part of the flight bookings made via Travel ID. This also includes flight delays or cancellations and baggage problems. We also process your data from enquiries to our Service Centre and other interactions, for example with the crew on board our aircraft.
Based on this processing, we can improve our complaints management system and offer you a bespoke service as a Travel ID customer at all our touchpoints. Your enquiries to our Service Centres will be displayed in your Travel ID profile and can be managed by you.
The legal basis for processing your data is the performance of the contract in accordance with Art. 6(1)(b) GDPR.
If you have used products and services from Travel ID operators using your Travel ID profile, we may wish to contact you regarding these services, for example, if we have repeatedly been unable to offer you the promised service. For this purpose, we use data pertaining to irregularities and customer concerns, the number and severity of the incidents, travel and service preferences and issues relating to your Miles & More membership, for example.
The legal basis for processing your data is our justified interest in accordance with Art. 6(1)(1)(f) GDPR.
If you belong to one or more customer groups (e.g. students), you can have your membership of such customer groups verified and the confirmation stored in your Travel ID profile. If you book a trip later while logged in for example, we can use the customer group status stored in your Travel ID profile to check whether you are entitled to claim specific customer group benefits.
The legal basis for processing your data is provided by the consent granted by you in accordance with Art. 6(1)(a) GDPR.
You have the right to withdraw your consent to the confirmation of your customer group at any time, without affecting the lawfulness of any processing performed on the basis of this consent until it was withdrawn. You can delete the confirmation(s) in your Travel ID profile under "Customer groups" to do so.
Your entitlement to special conditions and reductions will be deleted automatically once they are no longer valid.
You have option of storing travel documents such as your passport or visa in your Travel ID profile. We keep this data for you in a separate secure database. If you book a trip while logged in that requires the availability of specific travel documents, we will automatically add the data stored in your Travel ID profile to your flight booking. This process is not carried out if your flight booking already contains your travel documents details.
The legal basis for processing your data is provided by the consent granted by you in accordance with Art. 6(1)(a) GDPR.
You have the right to withdraw your consent to the use of data from your travel documents at any time without affecting the lawfulness of any processing performed on the basis of this consent until such consent is withdrawn. To do this, you can delete your travel documents in your Travel ID profile under “Personal documents”.
Your travel documents will be deleted automatically once they are no longer valid.
We offer you the option of storing your preferred payment methods in your Travel ID profile. You can do this yourself at any time within your Travel ID profile. You also have the option during the booking process of deciding to store in your Travel ID the payment methods you entered for the booking for future purchases.
If you have stored a payment method in your Travel ID profile and make a booking with your Travel ID profile while logged in, we will pre-fill your preferred payment methods or offer you a selection.
You can edit or delete your payment methods at any time.
The legal basis for processing your data is provided by the consent granted by you in accordance with Art. 6(1)(a) GDPR.
You have the right to withdraw your consent to the storage of your payment methods at any time without affecting the lawfulness of any storage on the basis of this consent before such consent is withdrawn. You can delete your payment methods in your Travel ID profile under “Payment methods”.
If you have booked a flight, the Lufthansa Group airlines would like to contact you about possible additional services relating to your flight. These additional services may include flight-related services of the Lufthansa Group airlines, such as premium meals or upgrades, but also additional services of partner companies of the Lufthansa Group airlines (information about partner companies of the Lufthansa Group airlines: Austrian Airlines, Brussels Airlines, Eurowings, Discover Airlines, Lufthansa, Swiss International Air Lines, as well as rental cars or insurance companies. Data stored about you in your Travel ID profile and at Lufthansa Group airlines (e.g. flight data and preferences) is processed for this purpose.
The legal basis for processing your data is provided by the consent granted by you in accordance with Art. 6(1)(a) GDPR.
This consent is given by you during the registration process or later in your Travel ID profile and can be managed by you at any time in your Travel ID profile.
Advertising contact by Travel ID operators
As described in the section “Settings for personalising our offers” in this Privacy Notice, you have the option of giving your consent to our determining your main areas of interest, as well as sending information and personalised offers based on this regarding the services of Lufthansa Group airlines and their respective partner companies (information about partner companies of the Lufthansa Group airlines: Austrian Airlines, Brussels Airlines, Eurowings, Discover Airlines, Lufthansa, Swiss International Air Lines), via digital communication channels (e.g. by email, SMS/MMS, messenger services, search engines, videos, banners) and by telephone or the websites of LHG airlines.
In addition, you can give Miles & More GmbH consent to send you offers relating to your possible membership of the Miles & More programme if you are not yet a member of the Miles & More programme.
Since we only want to provide you with information and offers that really interest you, with your consent, we thus process the booking information stored with the Lufthansa Group airlines, such as travel route, travel period and booking class, as well as preferences stored in your Travel ID profile. For example, by analysing information regarding your forthcoming trip, we may send you special offers or vouchers for additional services for your trip or for services available at your travel destination.
Personalised advertising through customer data matching (CRM Datamatch)
One way to provide you with personalised information and offers tailored to you is to identify you on websites of partners or advertisers.
For this purpose, we transmit your email address and/or telephone number stored in your Travel ID profile, previously encrypted with the SHA 256 hash algorithm recommended by the Federal Office for Security as “cryptographically strong”, to a so-called data clean room. A data clean room is a secure environment isolated from external technical influences for the processing of personal data. Its purpose is to facilitate the exchange of data between advertising companies, in this case the Travel ID operators, and partners or providers of advertising spaces, while protecting the privacy of the respective customers as far as possible. For this purpose, the partners or advertising companies also supply data of their customers to the data clean room using the same encryption method. As part of a data comparison, hits (data matches) are sent to so-called audiences (person groups), which in turn can be analysed by the Travel ID operators and addressed for advertising purposes. Access to the data we provide to a data clean room is only granted by us to selected partners and advertising space providers, and after the conclusion of corresponding data processing contracts.
Depending on technological development and marketer support technology, we ensure that stronger and more secure encryptions and/or extensions are used.
CRM Datamatch with Google Customer Match
In the case of CRM Datamatch with Google Customer Match, we provide encrypted data to a data clean room operated by Google in accordance with a process described in the section “Personalised advertising through customer data matching (CRM Datamatch)”. In this data clean room, Google compares the data we provide with those of Google Account customers who are encrypted using the same SHA 256 hash algorithm. Matches are summarised by Google in a list to what are referred to as audiences. As soon as this process is completed (max. 48 hours), the encrypted data is deleted. If you belong to such an audience, Google can identify you when you are surfing using Google platforms and show you our personalised advertising.
A prerequisite for the processing of your personal data in Google Customer Match is that you have a Google account in which you have given Google permission to display personalised advertising. You can amend this setting to suit your preferences under the data protection tab in your Google user account.
The controller for the processing of personal data within the framework of Google Ads/Google Customer Match within the meaning of the EU GDPR is Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland. Google Ireland Ltd is a subsidiary of Google LLC, which has its head office registered in California, USA, and is subject to the laws of that location, and may therefore also be obliged to provide access to data processed outside the USA.
You can find further information about the processing of your personal data by Google in the Google Privacy Notice.
Personalised advertising through customer data matching via Meta
In order to display personalised advertising to potential new customers or interested persons on Meta platforms such as Facebook and Instagram, and to measure the success of our advertising measures, we use Meta Pixel technology in conjunction with the Meta Conversion API of the company Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (hereinafter “Facebook”). For this purpose, we register the visits to our websites and your flight searches and bookings and transmit these in encrypted form to Facebook using the SHA 256 hash algorithm. On the basis of this data, Facebook identifies its own customer groups with similar interests and enables us to show advertisements to these customer groups on Facebook and Instagram. We are also able to make offers to people thinking about booking flights.
Meta Platforms Ireland Limited is a subsidiary of Meta Platforms Inc., which has its head office registered in California, USA, and is subject to the laws of that location, and may therefore also be obliged to provide access to data processed outside the EU.
We are joint controllers with Meta for the collection and transfer of data in this process. We have a corresponding agreement with Meta governing our responsibility as joint controllers.
You can find further information about the processing of your personal data by Facebook in the Facebook Privacy Notice.
You can contact the Data Protection Officer of Facebook via the online contact form provided by Facebook.
The legal basis for all processing of your data listed in the section “Personalised advertising communication” is provided by the consent you have given for this in accordance with Art. 6(1)(a) GDPR.
This consent is given by you during the registration process or later in your Travel ID profile and can be managed by you at any time in your Travel ID profile.
You can decide for yourself the extent to which you wish to receive information and individual offers from us by adjusting your communication settings. You may withdraw your consent to marketing communications also for individual areas (such as for the email newsletter only) in your Travel ID profile.
If you have a Travel ID profile and your Travel ID profile is not linked to a Miles & More member account, Lufthansa Group airlines will exchange your data with one another in order to offer you the services specified in the Travel ID Terms and conditions of use. Miles & More GmbH will only receive data from you that is required to manage your Travel ID profile (e.g. contact details, date of birth and your voluntarily stored profile data) and will not process this data for its own purposes.
If you have linked your Travel ID profile to your Miles & More member account, the Travel ID operators will exchange your data with one another in order to offer you the services specified in the Travel ID Terms and conditions of use. You decide for yourself whether to make the connection. If you make such a connection, data synchronisation is performed between your Travel ID profile and your Miles & More account. Specifically, the data stored by you in both accounts is carried over as follows:
All master data (such as name, date of birth, postal address, telephone) and preferences (such as preferred departure airport) is automatically transferred from your Miles & More account. The email address will be taken from your Travel ID profile.
The legal basis for the transfer of your data is the performance of the contract in accordance with Art. 6(1)(b) GDPR.
If you have given Miles & More GmbH your consent to receive personalised advertising communication (see the section “Personalised advertising communication”, Miles & More GmbH will also process your flight data (such as your route, travel class, departure airport, destination airport) for this purpose.
Your customer group status is checked by our commissioned data processor SheerID, Inc. with its registered office in the USA. Data is transferred based on the EU-US Data Privacy Framework under which SheerID, Inc. is certified with the U.S. Department of Commerce.
Furthermore, your personal data is processed in principle within the EU.
When you log into a website or other touchpoint of a Travel ID operator for the first time, you are prompted to enter your access details. In order to recognise you during your session, we set a “log-in” cookie. This cookie allows you to be automatically logged in when visiting websites of other Travel ID operators without having to enter your login credentials again.
You also have the option of actively selecting a “stay logged-in” feature on the websites of the Travel ID operators on which you have logged in, so that after finishing your session, you will not be required to log in again when re-visiting the website.
For this purpose, we also use a cookie that automatically recognises you when you visit the website/touch point again.
When the “stay logged-in” feature expires, you will be asked to log in again. In addition, you will always be prompted to log in again if you are in the process of carrying out activities which require an enhanced level of security.
The legal basis for processing your data is provided by the consent granted by you in accordance with Art. 6(1)(a) GDPR.
We process your data to the extent and as long as necessary for the processing purposes described in this Privacy Notice.
If the purpose for which your data was processed no longer applies, this data will be deleted, unless its retention is required for the following purposes:
- compliance with statutory retention periods that may derive from obligations under commercial or tax law. These periods may be for up to ten years; and
- enforcement, exercise or defence of legal claims.
In these cases, the processing of your data will be restricted (“blocked”) so that it can no longer be processed for other purposes.
If you no longer wish to use the Travel ID services, you may delete your Travel ID profile at any time. The personal data collected in connection with your use of Travel ID will then be deleted immediately, notwithstanding any conflicting statutory retention requirements and obligations.
You can delete your Travel ID profile, as well as any specific items of data you have provided in your Travel ID profile, yourself by logging into your Travel ID profile and deleting it there.
We also delete your provisional Travel ID profile if you do not confirm your registration within the period stated in the confirmation email, or if you have had a confirmation email with an activation link sent to you more than three times without using it.
We also delete your profile after a specific period of inactivity (see the section “Notifications about your Travel ID profile”).
Your rights
As a data subject, you can exercise the following rights where the respective statutory requirement is met:
- Right of access, Art. 15 GDPR
- Right to rectification, Art. 16 GDPR
- Right to erasure (“right to be forgotten”), Art. 17 GDPR (see also the section “Deleting your Travel ID profile” in this Travel ID Privacy Notice)
- Right of restriction of processing, Art. 18 GDPR
- Right of data portability, Art. 20 GDPR
- Right to object, Art. 21 GDPR (see also the section “Right to object under Art. 21 GDPR” of this Travel ID Privacy Notice)
Insofar as we process your data on the basis of consent, you have the right to withdraw this consent at any time without affecting the lawfulness of any processing performed on the basis of this consent before such consent is withdrawn.
To exercise your rights, you can contact the respective Travel ID operators from the section “Who can you contact” of this Privacy Notice. In order to process your application and identify you, we will process your personal data in accordance with Art. 6(1)(c) GDPR.
In your Travel ID profile, you can also check the current status of most of your master data yourself at any time. Please update your personal data immediately after any changes occur (for example your postal address, email address or telephone number). To delete your Travel ID profile, you can also proceed as described in the section “Deleting your Travel ID profile”.
You also have the right to lodge a complaint with a supervisory authority, Art. 77 GDPR.
Competent supervisory authorities
You will find a list of all data protection authorities responsible for the Travel ID operators below.
The relevant supervisory authority for Deutsche Lufthansa AG, EW Discover GmbH and Miles & More GmbH is:
The Officer for Data Protection and Freedom of Information of the State of Hesse
Postfach 3163
65021 Wiesbaden
Germany
Telephone: +49 - 611 - 14 08 - 0
Fax: +49 - 611 - 14 08 - 900 or - 901
Email: poststelle@datenschutz.hessen.de
The competent supervisory authority for Eurowings GmbH is:
Regional Officer for Data Protection and Freedom of Information
State of North Rhine-Westphalia
Postfach 20 04 44
40102 Dusseldorf
Germany
Tel.: +49 - 211 - 38 424 - 0
Fax: +49 - 211 - 38 424 - 999
Email: poststelle@ldi.nrw.de
The competent supervisory authority for Austrian Airlines AG is:
Austrian Data Protection Authority
Barichgasse 40-42
1030 Vienna
Austria
Telephone: +43 - 52 -152 - 0
Email: dsb@dsb.gv.at
The competent supervisory authority for Swiss International Air Lines AG is:
Federal Data Protection and Information Commissioner
Feldeggweg 1
3003 Bern
Switzerland
Telephone: +41 - 58 - 46 24 395
Fax: +41 - 58 - 46 59 996
For data processing that is subject to the GDPR:
The Officer for Data Protection and Freedom of Information of the State of Hesse
Postfach 3163
65021 Wiesbaden
Germany
Telephone: +49 - 611 - 14 08 - 0
Fax: +49 - 611 - 14 08 - 900 or - 901
Email: poststelle@datenschutz.hessen.de
The competent supervisory authority for Brussels Airlines SA/NV is:
Autorité de protection des données
Gegevensbeschermingsautoriteit
Data Protection Authority
Rue de la presse 35, 1000 Brussels
Belgium
Telephone: +32 - 2 - 27 44 800
Email: contact@apd-gba.be
You have the right to object to the processing of your personal data based on Article 6(1)(f) GDPR at any time on grounds relating to your particular situation.
In the event of an objection, we will no longer process the personal data concerning you, unless we can prove that there are compelling legitimate reasons for the processing that outweigh your interests, rights and freedoms, or if the processing is used to enforce, exercise or defend legal claims.
If the personal data concerning you is processed by us for the purpose of direct marketing and you object to this processing, the personal data concerning you will no longer be processed for these purposes.
You can object to the processing of your personal data at any time, for example via the contacts specified in the section “Who can you contact”.
We use technical and organisational security measures to protect your data against accidental or deliberate manipulation, loss, deletion or access by unauthorised persons. Our security measures are being continuously improved in line with technological progress.
In connection with the processing operations described in this Travel ID Privacy Notice, we may disclose your data to the following categories of recipients:
- service providers with which we cooperate on the basis of a commissioned processing agreement in accordance with Art. 28(3) GDPR; and
- government agencies and authorities, e.g. due to police and investigative activities.
In such cases, personal data may be transferred to third countries or international organisations worldwide. For your protection and the protection of your personal data, appropriate security measures will be taken for such data transfers in compliance with and in accordance with the law.
We use EU standard contractual clauses if these transfers are made to a third country for which the EU Commission or the relevant authorities have not issued an adequacy decision. You will find information about EU standard contractual clauses on the European Union website.
In exceptional cases, the transfer to countries without adequate protection may also be permissible in other cases, e.g. based on consent, in connection with legal proceedings or if the transfer is necessary for the execution of a contract.
We review this Travel ID Privacy Notice regularly and will update it as required. We will inform you if there are significant changes to this Travel ID Privacy Notice (for example on our websites).