Limassol Airport
Express

Privacy Policy

Effective Date: 25 August 2026

Website: https://limassolairportexpress.online/

1. Introduction and Data Controller

Welcome to Limassol Airport Express. We respect your privacy and process your personal data in strict accordance with the European General Data Protection Regulation (GDPR) and applicable Cypriot laws.

For the purposes of the GDPR, The Urban Limassol Bus Company (EAL Ltd) acts as the Data Controller. This policy explains our minimal-data approach: we collect only what is necessary to issue your ticket and retain only the transactional logs required for financial compliance.

2. Personal Data We Collect

To issue your ticket, we collect only three pieces of information during the checkout process:

  • Identity Data: Your name.

  • Contact Data: Your email address and phone number.

Payment Information: We do not collect, process, or store your credit card or financial details on our servers. All payments are processed entirely by our secure, third-party payment gateway, Stripe.

3. Lawful Basis and Purpose of Processing

Under the GDPR, we process your data based on the following lawful bases:

  • Performance of a Contract: We use your name, email, and phone number exclusively to generate and deliver your electronic bus ticket in real-time. Your phone number serves solely as a backup contact method in the event of an email delivery failure.

  • Legal Obligation: We retain basic transactional email logs (which include the name and email address to which the ticket was sent) to comply with corporate, tax, and financial reporting requirements under the laws of the Republic of Cyprus.

4. Data Storage and Retention

We operate a strict data minimization policy. We do not maintain a marketing database or create user profiles.

  • Active Processing: Once your payment is authorized via Stripe, our system uses your provided details to automatically generate and email your ticket.

  • Log Retention: Following ticket dispatch, we retain only the automated email logs of the transaction. These logs are stored securely and are kept strictly for the statutory period required by Cypriot financial and tax authorities (typically up to 7 years). Once this legal retention period expires, these logs are securely deleted.

Note: Our payment processor (Stripe) separately retains transaction records to comply with international financial regulations. You may review Stripe’s privacy policy directly on their website.

5. Data Sharing

We do not sell, rent, or trade your information. Your data is only shared with essential, GDPR-compliant service providers:

  • Stripe: To securely authorize and finalize your ticket purchase.

  • Our Hosting and Email Providers: The secure server infrastructure used to route your electronic ticket to your inbox and store the required financial logs.

6. Your Data Protection Rights

As a resident of the European Economic Area (EEA), you possess fundamental rights under the GDPR, including:

  • Right of Access: You may request a copy of the transactional data we hold about you in our email logs.

  • Right to Erasure (“Right to be Forgotten”): You may request the deletion of your data. Please note that this right is not absolute; we are legally required to decline deletion requests for data contained within our financial and tax logs until the statutory retention period has expired.

  • Right to Lodge a Complaint: You have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection in Cyprus if you believe your data has been mishandled.

7. Contact Information

For any legal or privacy inquiries, or to exercise your GDPR rights, please contact the Data Controller: