Privacy Policy

Last updated: 30 September 2026

This Privacy Policy explains how Atlenda (“we”, “us”) collects, uses and protects personal data on our website and in our two products: Atlenda Travel, a web application for travel agencies, and Atlenda Shops, a point-of-sale application for Windows. The data a business enters into Atlenda belongs to that business; we process it only to run the service on its behalf.

Data we collect

We collect account details (name, e-mail, business name), what you send us (for example through the demo-request form), and the technical data needed to run and secure the service, such as logs and usage information. The operational data a business enters belongs to that business — in Atlenda Travel: clients, travellers and their passports, opportunities, proposals, bookings, payments and documents; in Atlenda Shops: products, stock, sales, customers and customer credit.

Atlenda Travel: where data is stored

Atlenda Travel is a hosted web application. Each agency's data is kept in its own isolated workspace and encrypted in transit; the most sensitive traveller identity data (such as passport and identity-document details) is additionally encrypted at field level with AES-256-GCM. The database is backed up every day to encrypted off-site storage.

Atlenda Shops: where data is stored

Atlenda Shops runs on the shop's Windows PC, where its data is stored in an encrypted local database. When the shop links the application to the cloud, its data is replicated to a dedicated server operated by Atlenda and hosted in Europe; this is what lets the owner see sales, stock and customer credit from a phone in the Owner space at shops.atlenda.com/m.

Support access to your data

For Atlenda Travel, Atlenda staff can open an agency's workspace only to provide support, only after an administrator of that agency has granted time-limited access, and every access is logged and visible to the agency in Settings → Data access. The administrator can revoke access at any time. For Atlenda Shops, data replicated to our server is used only to provide synchronisation, the Owner space and support.

How we use data

We use account and technical data to provide and secure the service, process payments, send transactional e-mails, provide support and improve the product. We do not sell personal data, and we do not produce market statistics from our customers' data.

Service providers (sub-processors) for Atlenda Travel

Atlenda Travel relies on the following providers, each receiving only the data it needs for its task:

  • Vercel — application hosting, file storage (Vercel Blob) and performance measurement (Speed Insights).
  • Neon — database hosting.
  • Cloudflare R2 — storage of the encrypted daily backups.
  • Resend — sending and receiving e-mail.
  • Stripe and Chargily — online payments.
  • Google (Gemini) and OpenRouter — AI features, including passport reading: passport images uploaded by the agency are processed by these AI providers to extract the traveller's details.
  • Upstash — rate limiting, to protect the service against abuse.
  • Duffel, Hotelbeds and Amadeus — flight and hotel search and booking, when the agency uses them.

Payments

Online payments are handled by our payment processors, Stripe and Chargily. Card and payment details are entered directly with those processors — Atlenda never stores full card numbers.

Data retention

We retain personal data for as long as an account is active and as needed to provide the service, comply with legal obligations, resolve disputes and enforce agreements. You can request deletion at any time.

Your rights and contact

You may request access to, correction of, or deletion of your personal data. For any privacy request, contact us at contact@atlenda.com and we'll respond as required by applicable law.