Privacy Policy
Information on how we collect, use, protect, and retain personal data within airport transfer bookings and services.
Last updated: August 25, 20261. Data Operator
The operator of personal data collected through the transferaeroport24.ro website and in connection with the booked services is:
Name: LISTRA COM S.R.L.
Tax ID: RO 5895314
Trade Registry: J05/2333/1994
Headquarters: Str. Oașului nr. 16, Oradea, Bihor, România
Phone: +40 741 170 881
Email: office@transferaeroport24.ro
Throughout this policy, LISTRA COM S.R.L. is referred to as "the Operator", "TransferAeroport24", "we", or "the company".
2. Scope of the policy
This policy applies to individuals who:
- visit or use the transferaeroport24.ro website;
- search, configure, or make an Economy or Private Transfer booking;
- pay for a service online or request its cancellation or refund;
- contact us via form, email, phone, WhatsApp, or other channels displayed on the website;
- are indicated as passengers or beneficiaries of a booking made by another person.
This policy must be read together with the Terms and Conditions, the Cookie Policy, and the Cancellation and Refund Policy.
3. Categories of Personal Data We Collect
Depending on the service used and the information provided, we may process:
- identification and contact data: first name, last name, phone number, and email address;
- booking and travel data: route, airport, location, pickup or destination address, date and time, travel direction, and vehicle type;
- passenger data: the number of passengers and, when required for the booking, the names of the transported individuals;
- luggage and operational requirements data: information required for vehicle allocation and transfer execution;
- billing data: name or company name, address, country, county, locality, postal code, VAT/fiscal code (CUI), and other legally required information;
- order and payment data: order number, booked services, amount, currency, payment method and status, transaction identifier;
- communications: messages, comments, requests, complaints, and responses sent;
- technical data: IP address, device and browser type, security information, technical logs, and cookie preferences;
- proof of consent: acceptance of the Terms, policies, and cookie preferences expressed.
4. Data Sources
The data is collected:
- directly from you when you complete a booking, place an order, or contact us;
- from the person making the booking on behalf of you or the group you are part of;
- automatically, through the technical systems and cookies necessary for the operation and security of the website;
- from the payment processor, regarding the confirmation, status, and transaction identifier;
- from authorities or partners, when necessary and permitted by law.
5. Purposes and Legal Bases for Processing
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Creation, confirmation, and administration of the booking | Contact details, route, passengers, vehicle, date, time, and address | Pre-contractual steps and contract performance |
| Performing the transfer and communicating with the passenger | Contact details and operational ride information | Contract performance |
| Collection and verification of payment | Order data, amount, status, and transaction identifier | Contract performance and legal obligations |
| Billing, accounting, and tax reporting | Identification, billing, order, and payment data | Fulfillment of legal obligations |
| Cancellations, refunds, complaints, and disputes | Reservation, payment, and communication data | Contract performance, legal obligations, and legitimate interest |
| Website security, prevention of fraud and abuse | Technical data, logs, IP address, and transaction information | Legitimate interest and legal obligations |
| Website usage analysis | Online identifiers and statistical data | Consent, when analytics cookies are enabled |
| Commercial communications, if offered | Name, email, or phone number | Consent, which can be withdrawn at any time |
When data is necessary for reservation, payment, or invoicing, refusal to provide it may make it impossible to conclude or execute the contract and provide the requested service.
6. Online payments via NETOPIA Payments
For online payment, you will be redirected or connected to the secure infrastructure of NETOPIA Payments. LISTRA COM S.R.L. transmits to the processor the information necessary to identify the order and payment, such as the order number, amount, currency, and requested contact details.
TransferAeroport24 does not store the full card number, expiration date, and security code. The card data is entered and processed in the secure environment of the payment processor and the involved financial institutions. We receive information such as payment status and the transaction identifier.
NETOPIA FINANCIAL SERVICES S.A. processes the payer's data in accordance with its own obligations and policies. Check out the NETOPIA GDPR Privacy Notice for Payers.
7. To whom we may transmit data
Data may be accessed or transmitted, strictly within the necessary limits, to:
- authorized employees and collaborators of LISTRA COM S.R.L.;
- drivers, dispatchers, and, where applicable, carriers or subcontractors involved in performing the trip;
- hosting, maintenance, security, email, and IT service providers;
- the booking and e-commerce platform providers used for order management;
- NETOPIA Payments, the banks and payment organizations involved in processing the transaction;
- accounting, tax, legal, or audit service providers;
- public authorities, courts, or other entities, when disclosure is required or permitted by law.
Providers acting on our behalf are selected based on the service rendered and must process data only in accordance with the instructions and applicable contractual obligations.
8. How long we keep data
We keep data only as long as necessary for the purpose for which it was collected:
| Category of data | Retention period or criterion |
|---|---|
| Reservations, orders, and contractual communications | For the duration of the service provision and subsequently, generally for the applicable legal limitation period |
| Invoices and financial and accounting documents | For the period required by tax, accounting, and archiving legislation |
| Requests, complaints, and GDPR requests | As long as necessary for resolution and the defense of rights, generally up to 3 years from the closure of the request |
| Technical and security logs | Generally up to 12 months, except in situations where they are necessary for investigating an incident |
| Cookie preferences and proof of consent | Until the expiration or withdrawal of the option; preferences are renewed periodically |
| Data for commercial communications | Until the withdrawal of consent or the termination of the communication purpose |
The period may be extended if there is a dispute, an investigation, a legal obligation of preservation, or the necessity to establish, exercise, or defend a right in court. Upon the expiration of the applicable period, the data are deleted, anonymized, or archived with restricted access, as the case may be.
9. Cookies and external services
The website uses strictly necessary cookies for operation, security, reservations, cart, and checkout. Optional cookies, such as analytical ones, are activated only according to the preferences expressed through the cookie settings panel.
You can change your options at any time from the "Cookie Settings" floating button. Complete information is available in the Cookie Policy.
If you choose to contact us via WhatsApp or access external services through website links, the respective provider may process data in accordance with its own privacy policy.
10. International data transfers
We aim to use providers that process data within the European Economic Area. However, certain technical services or external channels may involve accessing or transferring data to countries outside the European Economic Area.
In such situations, the transfer is carried out solely on the basis of a mechanism permitted by the GDPR, such as an adequacy decision, standard contractual clauses, or another applicable legal safeguard. You can request information regarding the relevant safeguards using the contact details at the end of the policy.
11. Data security
We apply appropriate technical and organizational measures to risks, including secure HTTPS connection, access control, security updates and monitoring, backups, and limiting access to persons who need the data to fulfill their duties.
No electronic transmission or storage can be guaranteed to be completely risk-free. If we identify a data security breach, we will apply the legal procedures for evaluation, remediation, notification of the authority, and information of the affected persons, when necessary.
12. Your rights
Under the conditions provided by the GDPR, you have the following rights:
Poți afla dacă îți prelucrăm datele și poți solicita o copie a acestora.
Poți cere corectarea sau completarea datelor inexacte ori incomplete.
Poți cere ștergerea datelor atunci când condițiile legale sunt îndeplinite.
Poți solicita limitarea temporară a utilizării datelor în anumite situații.
Poți primi datele furnizate într-un format structurat, când dreptul este aplicabil.
Te poți opune prelucrărilor bazate pe interes legitim și marketingului direct.
Îți poți retrage acordul oricând, fără a afecta prelucrarea anterioară retragerii.
Poți sesiza ANSPDCP dacă apreciezi că datele tale sunt prelucrate nelegal.
Some rights are not absolute. For example, certain data cannot be deleted if there are legal retention obligations or if it is necessary for the establishment, exercise, or defense of a legal claim.
13. How to exercise your rights
Send your request to office@transferaeroport24.ro with the subject "GDPR Request", or by post to the headquarters of LISTRA COM S.R.L. Indicate the right you wish to exercise and the information necessary to identify your booking or request.
To protect data, we may request additional information to verify your identity. We will respond without undue delay and, as a rule, within a month at the latest, in accordance with GDPR deadlines. This period may be extended in cases permitted by law, in which case you will be informed.
You can also file a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP).
14. Data of minors and other passengers
The services may be used for the transport of minors only under applicable legal and operational conditions. The person making the booking must have the right to provide the data of other passengers and is responsible for informing them about this policy.
We only request information necessary to organize and perform the ride. If additional information is required for the safety of a minor or for special assistance, please contact us directly before booking.
15. Changes to the policy
We may update this policy when services, technical tools, providers, or legal requirements change. The applicable version is the one published on the website, and the date of the last update is displayed at the top of the page.
Important changes will be communicated through appropriate means when required by law.