eJanet acts on your behalf — booking flights, holding hotel rooms, sending confirmations. That means we see personal details: your name, passport, travel plans, and spend. We want to tell you how we handle all of that. Not because we're required to (we are, under EU GDPR), but because if you can't trust how we handle your data, the rest of the product doesn't matter.

Four principles

1. Your data stays yours.

We process your personal data to do the job you asked us to do. Nothing more. We don't sell it. We don't share it with advertisers. We don't enrich it with data brokers. We don't build advertising profiles.

2. No model training. Ever.

Your conversations with eJanet — what you ask, what we reply — are never used to train AI models. Not ours, not anyone else's. The AI providers we work with (Anthropic) operate under written agreements that prohibit training on your inputs.

3. EU-based storage. Encrypted in motion and at rest.

Everything is stored on EU infrastructure (Frankfurt region). Passports, dates of birth, and other sensitive fields are encrypted at the column level — even our own database administrators don't see them in plain text.

4. Every action is auditable.

Every search, every proposal, every booking, every cancellation is written to an immutable audit log. You can ask to see your audit chain. It's the same record we use internally — full transparency.

What eJanet sees, and why

  • Your name + initials — booking with airlines and hotels; their systems require it.
  • Email address — login, itinerary delivery, booking confirmations.
  • Mobile phone number — login two-factor, account recovery, optional Telegram binding.
  • Date of birth — required by airlines for ticketing. Also used for the occasional birthday note.
  • Passport / national ID number + expiry — required by airlines for international ticketing. Verified once at upload, then encrypted.
  • Nationality — visa eligibility checks before we propose itineraries.
  • Travel preferences (cabin, seat, meal, allergies) — auto-applied on every search so you don't have to repeat yourself.
  • Loyalty programme numbers — credited to your account at booking time. Never shared outside the airline you specified.
  • Spend cap (corporate accounts) — decides which bookings you self-approve and which need a second signature.
  • Trip history — so you can find your past bookings, receipts, and PNRs.

What eJanet does not see:

  • Your payment card number. Flights are paid through Duffel's prepaid balance (your company tops it up); hotels are paid by per-booking virtual cards issued by Stripe at the moment of booking. eJanet never sees a full card number.
  • The content of your inbox. We monitor only a single dedicated mailbox (travel@ejanet.ai) for airline / hotel confirmations relating to your bookings.

Who else touches your data

eJanet uses a small number of carefully-chosen sub-processors. Each operates under a Data Processing Agreement (DPA) that limits what they can do with your data.

  • Anthropic (Claude API) — natural-language understanding + document verification. No training on your data. US infrastructure under EU SCCs.
  • Duffel — flight search + booking + payment to airlines. EU infrastructure.
  • Stripe Issuing — per-booking virtual cards for hotel payment. EU infrastructure.
  • Render — hosting (PWA, dashboard, bot, database). EU (Frankfurt).
  • Microsoft 365 (Graph) — inbound airline confirmation parsing + outbound email. EU.
  • Sentry — error reporting (PII-scrubbed before transmission). EU.
  • Telegram (optional, opt-in) — if you choose to bind your account to a Telegram chat. Global; you opt in individually.

The full sub-processor list is maintained in our Article 30 Record of Processing Activities, available on request.

Your rights

Under EU GDPR, you can ask us at any time to:

  • See what we hold about you — we'll send you a structured export.
  • Correct anything that's wrong — name change, passport renewal, etc.
  • Erase your data — we'll delete it within 30 days, except where we're legally required to retain booking records for tax / audit purposes (typically 7 years; we redact rather than delete in that case).
  • Take your data with you — exported in a machine-readable format you can import elsewhere.
  • Object or restrict — pause specific processing while we sort out a concern.
  • Complain to a supervisory authority — Lametus is based in Cyprus, so the Office of the Commissioner for Personal Data Protection is the supervisory authority.

For any of these, email privacy@ejanet.ai. We aim to respond within 7 working days; the legal deadline is 30 days.

Cookies and tracking

The landing page and product use a minimal set of cookies:

  • Session cookie — keeps you logged in. Strictly necessary.
  • Theme preference (ejanet-theme) — remembers light/dark mode. Functional, no PII.
  • CSRF token — security. Strictly necessary.

We do not use third-party analytics, advertising cookies, cross-site tracking pixels, or heatmap / session-replay tools.

When things change

We'll update this page whenever our approach changes materially. Material changes — new sub-processors, new categories of data, changes to how data is shared — are announced by email to every active user at least 30 days before they take effect.

Questions

If anything on this page is unclear, write to privacy@ejanet.ai and we'll explain. If you'd rather not write, the same address forwards to a human who'll call you back.


Lametus Holdings LTD · Cyprus company registration number HE206074
Registered office: Omonias 141, The Maritime Center Block B, 3045 Limassol, Cyprus
Contact: hello@ejanet.ai · Privacy: privacy@ejanet.ai
Privacy Approach v0.1 · DRAFT pending Cyprus legal review. The formal Terms of Service + DPA are available separately.