Last Update: 3 January 2022

Privacy & GDPR

1. Why did Wingie update our Privacy Policy?
As Wingie GmbH, we have released an updated version of our Privacy Policy which came into effect on May 25th, 2018. Our new policy is more user-friendly and addresses new data regulations including GDPR. The most significant changes in the new policy are explained below:

  1. Better navigation and user-friendly language. We reformatted our privacy policy page with related links, so any user can easily find the information. Clear languages and examples with new policy pages make the policy easier to understand.
  2. More control over your information. Wingie has made it easier to control the information our customers provide to us. This policy explains how you make choices about your information.

2. What is GDPR, and what is Wingie doing to comply?
The General Data Protection Regulation (GDPR) is a regulation in EU law on data protection and privacy for all individuals within the European Union, which addresses the export of personal data outside the EU. GDPR is effective as of May 25th, 2018. It replaces national privacy and security law that previously existed within the EU with a single, comprehensive EU-wide law that governs the use sharing, transfer and processing of any personal data that originates from the EU.
Wingie’s policy is to respect all laws that are related to our business, which includes GDPR.

Here are a few things Wingie is committed to doing to ensure our compliance with GDPR:
Where we are transferring data outside of the EU, Wingie commits to having the appropriate data transfer mechanisms in place as required by GDPR.
Wingie commits to follow appropriate security measures and precautions in accordance with GDPR. 
Wingie will assist with notifying regulators of breaches and promptly communicate any breaches to customers and users. 
We will ensure that employees authorized to process personal data have committed to confidentiality. 
We will hold any sub-processors that handle personal data, including our data center partners, to the same data management, security and privacy practices and standards to which we hold ourselves. 
Wingie commits to carrying out data impact assessments and consulting with EU regulators where a data impact assessment indicates a high risk associated with processing without an appropriate mitigating strategy.
Where appropriate, we will offer contractual language documenting our commitments to our customers to support their GDPR obligations.
Wingie will assist our customers, insofar as possible, to respond to data subject requests our customers may receive under the GDPR. 

3. Does Wingie process personal data?
Yes. We process personal data to improve our services as outlined in our Privacy Policy.

4. Where does Wingie store and send my data?
Our goal is to provide our customers with reliable, fast and secure services. We store collected data in Belgium by using Google Cloud Services. We may also allow employees and contractors located around the world to access certain data for product promotion and development, and customer and technical support purposes. For more information, please see the "How we transfer information we collect" section of our Privacy Policy.

5. How does Wingie handle onward transfers of data outside of the EU?
Wingie GmbH is responsible for your personal data, after you use our services. We store your data in Google Cloud servers located in Belgium. Moreover, we may transfer your personal data to other organizations to provide you services. As of May 2018, Enuygun Com Internet Bilgi Hizmetleri AS (“Enuygun”), located in Istanbul, Turkey, is doing the ticketing for Wingie clients, and ticketing data is transferred to their servers in Istanbul. Enuygun uses Flight Company Web Services for booking flights.
For more information on how we transfer and process your data, please see Privacy Policy.

6. Do you offer your customers a Data Processing Addendum ('DPA')?
Yes, we do! We respect all GDPR obligations while processing EU personal data. The Wingie Data Processing Addendum is available upon request for all customers to review and use to meet your onward transfer requirements under GDPR. To obtain a copy of your DPA please reach out to [email protected]

7. Can I make changes to the Wingie DPA?
Wingie DPA is an extension of our Customer Agreement and reflects our compliance with GDPR requirements. We are unable to make any changes to our DPA. For more information, please see the Data Processing Addendum.

8. Can I opt out of having my data collected or shared while booking a flight?
Wingie collects your personal information when you use our services. Your data is collected when you use Wingie including:

  1. When you book or search a flight
  2. When you use any services (check-in etc.)
  3. When you contact our call center
  4. If you complete a customer survey
  5. If you choose to interact with us via social media such as Twitter, Facebook, Instagram

Wingie shares your personal data to provide you services. We have to transfer your personal data for your flights and payments. For instance, we use Web Services with both bank and flight companies. Yet, we DO NOT sell your personal data to third parties.

9. How does Wingie secure my data?
We have implemented our security policy to secure your data, in compliance with GDPR. Your personal data is encrypted while transferring. Moreover, Wingie is compatible with PCI DSS at Level-3, which is a widely accepted standard of policies and procedures intended to optimize security.

10. Are third-party applications covered by Wingie’s Privacy Policy?
Third-party application policies and procedures are not controlled by Wingie, and our Privacy Policy does not cover how third-party applications use your information. We encourage you to review the privacy policies of third parties before connecting to or using their applications or services to learn more about their privacy and information handling practices.

11. Does Wingie use sub-processors to further process customer data?
A list of our sub-processors can be found on our Sub-Processors page.

12. Who can I contact with questions regarding GDPR?
Our services are used by millions around the world. We encourage you to review this page first. Most probably your interest will be addressed in this page. However, we understand there may be some circumstances where you may need to directly contact us. For more information, please use the “Contact” section on Wingie.

Privacy Policy

Wingie is a web based service of Wingie GmbH, Friedrichstr. 171, 10117 Berlin ("Wingie" or "we"), under the address (hereinafter "Website" or "Service"). Wingie GmbH is an Online Travel Agency (OTA). Further contact information can be found at
Wingie takes the protection of your privacy and your personal data very seriously. We act in our customers’ interest and we are transparent about our processing of your personal data. In the following we inform you about the collection, processing and use of your personal data when using our website. Personal data are all data that can be obtained personally from you, e.g. name, telephone number or e-mail address.
We encourage you to read our Privacy Policy each time you visit our website or use our service as it is updated from time to time and by using our website, you are in a position to process your personal information and use the technologies described below agree to the latest version of our Privacy Policy.

1. What information we collect about you
1.1 Information you provide to us
1.1.1 Content you provide through bookings
We use your personal data to complete and administer your online flight reservation. When booking for the first time we need information such as name, surname, phone number, email address, date of birth and gender. In addition, we require your payment details, such as bank details or credit card information, with every booking.
When you visit our website, we also store by default the data that your browser transmits to enable you to visit our website, such as: your IP address, the website from which you visit us, the type of browser, and the date and duration of the visit for statistical purposes (see the web tracking section).

1.1.2 Information you provide through our support channels
We provide international customer service 24 hours a day, 7 days a week. Sharing your relevant details, such as reservation information with our customer service staff allows us to respond when you need us.
When you call our call center, your conversation with call center agent will be recorded for the purposes of better service quality and proof of service. Live listening may be done for quality control and training purposes.
When you use our chat support, your conversation with back office agent will be recorded for the purposes of better service quality and proof of service.
Call and chat recordings are kept for a limited amount of time and automatically deleted, unless Wingie has a legitimate interest to keep such recording for a longer period, including for fraud investigation and legal purposes.

1.2 Information we collect automatically when you use the website and/or mobile applications
1.2.1 Your use of the website and/or mobile applications
We keep track of certain information about you when you visit and interact with our website and/or mobile applications. This information includes the features you use; the links and buttons you click on and frequently used search terms. For example, we might find out from usage data that users cannot find an airport with certain search term and we might add a suggestion for that search term.

1.2.2 Device and Connection Information
1.2.3 Cookies
When using the website, cookies are stored on your computer. Cookies are small text files that are allocated and stored on your hard drive to the browser you use, and that provide certain information to the body that sets the cookie (in this case us). Cookies cannot run programs or transmit viruses to your computer. They serve to make the Internet offer more user-friendly and effective overall.
a) This website uses cookies to the following extent:

  1. Transient cookies (temporary use)
  2. Persistent cookies (temporary use)
  3. Third-party cookies (third-party).

b) Transient cookies are automatically deleted when you close the browser. These include in particular the session cookies. These store a so-called session ID, with which various requests from your browser can be assigned to the common session. This will allow your computer to be recognized when you return to the site. The session cookies are deleted when you log out or when you close the browser.
c)Persistent cookies are automatically deleted after a specified period, which may differ depending on the cookie. You can delete the cookies in the security settings of your browser at any time.
d) You can configure your browser setting according to your wishes, decline the acceptance of third-party cookies or all cookies. We point out, however, that you may not be able to use all features of this website.

1.2.4 Web Tracking Use of Google Analytics
(1) Wingie uses Google Analytics, a web analytics service provided by Google Inc. ("Google"). Google Analytics uses so-called "cookies", text files that are stored on your computer and that allow an analysis of the use of the website by you. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there. However, in the event of activation of IP anonymization on this website, your IP address will be shortened by Google beforehand within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be sent to a Google server in the US and shortened there.
(2) The IP address transmitted by Google Analytics as part of Google Analytics will not be merged with other data provided by Google.
(3) You can prevent the storage of cookies by setting your browser software accordingly; however, please note that if you do this, you may not be able to use all the features of this website to the fullest extent possible.
(4) In addition, you may prevent the collection by Google of the data generated by the cookie and related to your use of the website (including your IP address) as well as the processing of this data by Google using the browser available at the following link Download and install the plug-in:
(5) The use of Google Analytics takes place in accordance with the conditions to which the German data protection authorities agreed with Google. Third-party information: Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001. Terms of Use: .html, Privacy Policy:, and the Privacy Policy: Use of Criteo
On Wingie, Criteo GmbH collects and stores anonymized information about the usage behavior on our website. This data is stored in cookies on your computer. Based on an algorithm, Criteo GmbH analyzes the anonymously recorded surfing behavior and can then display targeted product recommendations as personalized advertising banners on other websites (so-called publishers). In no case can this data be used to personally identify you as a visitor to our websites. The collected data will only be used to improve the offer. Any other use or disclosure of this information to third parties will not take place.
You can object to the completely anonymous analysis of your surfing behavior on our websites by clicking here on Criteo Host. If you have already done so and want to see personalized Criteo banners again, please click on Criteo entry. Further information on the technology used can be found in the privacy policy of Criteo GmbH.

1.3 Information we receive from other source
We might receive information about you from other users.

1.3.1 Other users of the website
When you make a reservation for someone else through Wingie, we will request personal information and travel preferences about that individual. You should obtain the consent of other individuals prior to providing us with their personal information and travel preferences, as any access to view or change their information will be available only through your email address. Other users of our website may provide information about you when they submit content through the website.  For example, you might be added as a passenger to a flight, as a result, your name, surname, age, gender might be shared with us. This information will be stored as passenger information.

2. How we use information we collect
2.1 To provide the services and personalize your experience
We use information about you to provide the services to you, including to process transactions with you, authenticate you when you log in, provide customer support, and operate and maintain the service.

2.2 For research and development
We are always looking for ways to make our website faster, more secure, and more useful to you.  We use collective learnings about how people use our website and feedback provided directly to us to troubleshoot and to identify trends, usage, activity patterns and areas for integration and improvement of the website.

2.3 To communicate with you about the services
We use your contact information to send transactional communications via email and within the website, including confirming your purchases, responding to your questions and requests, and providing customer support.  We might send you email notifications when several online actions become available, for example online check-in.

2.4 To market, promote and drive engagement with the services.
We use your contact information to send promotional communications that may be of specific interest to you, including by email. These communications are aimed at driving engagement and maximizing what you get out of the website. We also communicate with you about new product offers and promotions. You can control whether you receive these communications as described below under "Opt-out of communications."

2.5 Customer support: 
We use your information to resolve technical issues you encounter, to respond to your requests for assistance, to analyze crash information, and to repair and improve the Services.

2.6 For safety and security: 
We use information about you and your Service use to verify accounts and activity, to monitor suspicious or fraudulent activity and to identify violations of our policies. 

2.7 To protect our legitimate business interests and legal rights: 
Where required by law or where we believe it is necessary to protect our legal rights, interests and the interests of others, we use information about you in connection with legal claims, compliance, regulatory, and audit functions, and disclosures in connection with the acquisition, merger or sale of a business.  

2.8 With your consent:
We use information about you where you have given us consent to do so for a specific purpose not listed above.  For example, we may publish testimonials or featured customer stories to promote the Services, with your permission.

3. How we share information we collect
3.1 Sharing with third parties
We share information with third parties that help us operate, provide, improve, integrate, customize, support and market our website.

3.1.1 B2B Ticketing Agency
We are working with a ticketing agency called Enuygun Com Internet Bilgi Hizmetleri Teknoloji ve Ticaret AS (“Enuygun” or “Consolidator”), located in Istanbul, Turkey, for ticketing purposes. Enuygun is Turkey’s leading Online Travel Agency in flights, with more than 10 million visits and 500.000 flight bookings each month, as of spring 2018. Enuygun is also indirectly related to Wingie GmbH via common shareholders.
With Enuygun, we share data that is needed for ticketing purposes. Enuygun may share data with other parties for ticketing purposes, as detailed in the below items.

3.1.2 Airlines:
We work with airlines directly or via Consolidator to provide their flight services. Airlines fulfil your travel reservations. Airlines are required to access and use your personal information including name, surname, date of birth, gender, email address and phone number. We encourage you to review the privacy policies of airlines whose flights you purchase through Wingie. Please note that airlines also may contact you as necessary to obtain additional information about you, facilitate your travel reservation, or respond to a review you may submit.

3.1.3 Global Distribution Systems:
We work with global distribution systems directly or via Consolidators to provide access to flight services from airlines. Global Distribution Systems access and use your personal information including name, surname, date of birth, gender, email address and phone number. Global Distribution Systems share this information with airlines and airlines fulfil your travel reservations.

3.1.4 Payment System Providers:
We or our Consolidators use card information (cardholder name, card number, and expiration date) for the purpose of completing the flight bookings you conduct on website. We work with payment system providers to process payments for your flight bookings. Your card number, card holder name, card expiration date, card CVV are shared with payment system providers which might include banks and other financial systems.

3.2 Links to Third Party Sites:
Our website may include links that direct you to other websites or services whose privacy practices may differ from ours. If you submit information to any of those third-party sites, your information is governed by their privacy policies, not this one. We encourage you to carefully read the privacy policy of any website you visit.

3.3 Social Media Widgets:
Our website may include links that direct you to other websites or services whose privacy practices may differ from ours. Your use of and any information you submit to any of those third-party sites is governed by their privacy policies, not this one. 

3.4 Third-Party Widgets:
Some of our pages contain widgets and social media features, such as the Facebook share button. These widgets and features collect your IP address, which page you are visiting, and may set a cookie to enable the feature to function properly. Widgets and social media features are either hosted by a third party or hosted directly on our website. Your interactions with these features are governed by the privacy policy of the company providing it.

3.5 With your consent:
We share information about you with third parties when you give us consent to do so. websites. For example, with your consent, we may post your name alongside a testimonial. 

3.6 Compliance with Enforcement Requests and Applicable Laws; Enforcement of Our Rights:
In exceptional circumstances, we may share information about you with a third party if we believe that sharing is reasonably necessary to (a) comply with any applicable law, regulation, legal process or governmental request, including to meet national security requirements, (b) enforce our agreements, policies and terms of service, (c) protect the security or integrity of our products and services, (d) protect Wingie, our customers or the public from harm or illegal activities, or (e) respond to an emergency which we believe in good faith requires us to disclose information to assist in preventing the death or serious bodily injury of any person.

4. How we store and secure information we collect
4.1 Information storage and security
We use cloud data hosting service providers in Belgium to host the information we collect, and we use technical measures to secure your data. While we implement safeguards designed to protect your information, no security system is impenetrable and due to the inherent nature of the Internet, we cannot guarantee that data, during transmission through the Internet or while stored on our systems or otherwise in our care, is absolutely safe from intrusion by others.

4.2 How long we keep information
Keeping information time depends on the type of information, as described in further detail below.  After such time, we will either delete or anonymize your information or, if this is not possible (for example, because the information has been stored in backup archives), then we will securely store your information and isolate it from any further use until deletion is possible.

4.2.1 Account information
We retain your account information for as long as your account is active and a reasonable period thereafter in case you decide to reactivate your account.

4.2.2 Information you share on the website for ticketing purposes
We retain your information you share for ticketing purposes for as long as we are legally obliged to.

4.2.3 Marketing information
If you have elected to receive marketing e-mails from us, we retain information about your marketing preferences for a reasonable period of time from the date you last expressed interest in our website.  We retain information derived from cookies and other tracking technologies for a reasonable period of time from the date such information was created.

5. How to access and control your information
You have certain choices available to you when it comes to your information. Below is a summary of those choices, how to exercise them and any limitations.

5.1 Your choices
You have the right to request a copy of your information, to object to our use of your information (including for marketing purposes), to request the deletion or restriction of your information, or to request your information in a structured, electronic format. Below, we describe the tools and processes for making these requests. You can exercise some of the choices by the links available at footer of the website. For all other requests, you may contact us as provided in the Contact Us section below to request assistance.

5.2 Delete your information
We may need to retain certain information for record keeping purposes, to complete transactions or to comply with our legal obligations.

5.3 Opt out of communications
You may opt out of receiving promotional communications from us by using the unsubscribe link within each email, updating your email preferences within your Service account settings menu, or by contacting us as provided below to have your contact information removed from our promotional email list or registration database.  Even after you opt out from receiving promotional messages from us, you will continue to receive transactional messages from us regarding our website.

5.4 Turn off cookie controls
You can read more about our browser-based cookie controls in our Privacy Policy.

5.5 Send “Do Not Track” Signals
Some browsers have incorporated "Do Not Track" (DNT) features that can send a signal to the websites you visit indicating you do not wish to be tracked. Because there is not yet a common understanding of how to interpret the DNT signal, our website does not currently respond to browser DNT signals. You can use the range of other tools we provide to control data collection and use, including the ability to opt out of receiving marketing from us as described above.

5.6 Data Portability
Data portability is the ability to obtain some of your information in a format you can move from one service provider to another (for instance, when you transfer your mobile phone number to another carrier).  Depending on the context, this applies to some of your information, but not to all of your information.  Should you request it, we will provide you with an electronic file of your basic account information and the information. 


This Data Processing Addendum (DPA) forms part of the Agreement between the Customer and Wingie, and applies to the extent that Wingie processes Personal Data on behalf of Customer in the course of providing services. This DPA does not apply where Wingie is the Controller.


1.1. Agreement
The electronic agreement between customer and Wingie for the provision of the services to customer.

1.2. Controller
An entity that determines the purposes and means of the processing of Personal Data.

1.3. Data Protection Law
All data protection and privacy laws applicable to the processing of Personal Data under the Agreement, including, where applicable, EU Data Protection Law.

1.4. EU Data Protection Law
Prior to 25 May 2018, Directive 95/46/EC of the European Parliament and of the Council on the protection of individuals with regard to the processing of Personal Data on the free movement such data; and (ii) on and after 25 May 2018, Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data (General Data Protection Regulation) (“GDPR”).

1.5. Personal Data
Any information related with an identified or identifiable person.

1.6. Personal Data Breach
Accidental or unlawful destruction, loss, alteration, unauthorized disclosure of data, or access to Personal Data.

1.7. Processor
An entity that processes Personal Data on behalf of Controller.

1.8. Services
Any offered service provided by Wingie to Customer pursuant to the Agreement.

1.9. Sub-processor
Any processor engaged by Wingie or any member of its group of companies that processes Personal Data pursuant to the Agreement. Sub-processors include third parties.


2.1. Role of the Parties
As between Wingie and Customer, Wingie will process Personal Data under the Privacy Policy only as a Processor.

2.2. Wingie Processing of Personal Data
Wingie will comply with its processor obligations under Data Protection Law and will process Personal Data in accordance with Customer’s instructions. Customer agrees that the Privacy Policy and Agreement are its complete and final instructions to Wingie in relation to the processing of Personal Data. Processing any Personal Data outside the scope of the Agreement or Privacy Policy will require permission of Customer.

2.3. Processing of Personal Data Details

2.3.1. Duration
Unless customer requests deletion of Personal Data, the maximum duration of processing is 2 years. With customer permission, Wingie may process Personal Data longer.

2.3.2. Purpose
The purpose of the processing is included on Privacy Policy.


3.1. Use of Sub-Processors
Wingie engages Sub-processors to provide certain services on its behalf. Sub-processors are given details on the Wingie. Wingie will be responsible for any acts, errors, or omissions of its Sub-processors that cause Wingie to breach any of Wingie’s obligations under this DPA.

3.2. Obligations
Wingie will enter into an agreement with each Sub-processor that obligates the Sub-processor to protect the Personal Data in a manner substantially similar to the standards set forth in the Privacy Policy and Agreement.


4.1. Security Measures
Wingie will implement and maintain appropriate technical and organizational security measures to protect against Personal Data Breaches and to preserve the security and confidentiality of Personal Data processed by Wingie on behalf of Customer in the provision of the Services. The Security Measures are subject to technical progress and development. Wingie has the right to update of modify the Security Measures which do not result in the degradation of the overall security of the Services purchased by the Customer.

4.2. Personnel
Wingie restricts its personnel from processing Personal Data without authorization, unless required to so by applicable law, and will ensure that any person authorized by Wingie to process Personal Data is subject to an obligation of confidentiality.

Personal data flow is given below:

Upon becoming aware for a Personal Data Breach, Wingie will notify Customer without undue delay and will provide information relating to the Personal Data Breach as reasonably requested by Customer.

Wingie audits its compliance against data protection, information security and PCI DSS standards on a regular basis. Such audits are conducted by Wingie’s internal authorized team or by third party auditors. Upon Customer’s written request, and subject to obligations of confidentiality, Wingie will make available to Customer a summary of its most recent relevant audit report, so that Customer can verify Wingie’s compliance with this DPA.

Wingie may transfer and process Personal Data to provide its services.

Wingie will delete Personal Data by customer request unless it is dependent on any law. Deletion of Data may take 90 days. Personal Data may to be have restored by Sub-Processors of Wingie due to any law regulation.

9.1. Data Protection Requests
If Wingie receives any requests from individuals or applicable data protection authorities relating to the processing of Personal Data under the Privacy Policy and Agreement, including requests from individuals seeking to exercise their rights under EU Data Protection Law, Wingie will redirect the request to the Customer.

9.2. Customer Requests
Wingie will cooperate with Customer, if we receive any request from customers. Wingie will provide Customer’s Personal Data to customer.

9.3. Legal Disclosure Requests
If Wingie receives a legally binding request for the disclosure of Personal Data which is subject to this DPA, such request will be dealt with in accordance with the Privacy Policy and Agreement.

9.4. Data Responsible
Any related question may be asked directly to the Data Responsible. Related information is given below:
Data Responsible:
Name: Nihan Çolak Erol
e-mail: [email protected]
Phone: +49 301 208 5757
Address: Wingie GmbH, Friedrichstr. 171, 10117, Berlin, Deutschland


10.1. Conflicts
Any conflict between this DPA and any privacy-related provisions in the Agreement, the terms of this DPA will prevail.

10.2. Modification and Supplementation
Wingie may modify the terms of this DPA, in circumstances such as,
i. If required to do so by a supervisory authority or other government or regulatory entity,
ii. If necessary to comply with Data Protection Law
iii. To implement or adhere to standard contractual clauses, approved codes of conduct or certifications, binding corporate rules, or other compliance mechanisms
Wingie will provide notice of such changes to Customer, and the modified DPA will become effective.


Current as of October 18, 2023

Third-Party Subprocessors

Thirt Party Service / VendorPurposeEntity CountryWebsite
Euromessagee-Mail Service ProviderTurkey
FirebaseMarketing USA
Google AdwordsMarketingUSA
Google AnalyticsMarketing Analytics & MeasurementUSA
Google Cloud PlatformData HostingUSA‎
Google OptimizeWebsite, AB Testing & Personalization SolutionsUSA
Mailchimpe-Mail Service ProviderUSA
Power BIBusiness Intelligence USA
SegmentifyIdentity ManagementGermany
TurkcellSMS Service ProviderTurkey
TrustpilotGather FeedbackUSA