1. Data Controller and Scope
This Privacy Policy applies to Erandir, an AI operating system for corporate travel operated by Mitryco, LLC ("Erandir", "we", "our", or "us"). It explains how we collect, use, disclose, and protect personal data when you use our website, product, and related services.
If you use Erandir on behalf of an organization, we process most data as a processor on behalf of that organization. In that case, your organization is the controller of that data, including data about its travelers.
2. Information We Collect
- Account details such as name, work email, organization, and role.
- Traveler profile data submitted by you or your organization, such as names, contact details, dates of birth, passport and other travel document details.
- Trip content such as itineraries, tickets, bookings, accommodation details, statuses, notes, and uploaded documents.
- Usage and technical data such as IP address, browser type, device information, feature usage, and logs.
- Support and communications data when you contact us.
3. Legal Bases for Processing
Where required by applicable law, we rely on one or more of the following legal bases:
- Performance of a contract with you or your organization.
- Legitimate interests, such as securing and improving our services.
- Compliance with legal obligations.
- Consent, where consent is required by law.
4. How We Use Information
- Provide, maintain, and improve the Erandir platform.
- Process travel documents and generate trip data, groupings, and reports, including with the help of AI.
- Authenticate users and secure accounts.
- Notify travelers about their trips, itineraries, and changes.
- Provide customer support and service communications.
- Comply with legal obligations and enforce our terms.
We do not use your organization's data or your travelers' personal data to train AI models.
5. Data Sharing
We do not sell your personal data. We do not share traveler data with other customers or third parties for their own purposes. We may share data in limited cases:
- With vendors and service providers that help us operate Erandir, such as hosting and AI infrastructure providers, bound by confidentiality and data protection obligations.
- With your organization's administrators and authorized team members, according to access controls in the product.
- When required by law, regulation, legal process, or to protect rights.
- In connection with a merger, acquisition, financing, or sale of business assets.
6. International Transfers
We may process and store data in the United States, the European Union, and other jurisdictions where we or our subprocessors operate. Where required, we use appropriate contractual or organizational safeguards for cross-border transfers.
7. Security
Organizations are isolated from each other. Documents and sensitive traveler data are stored encrypted and are visible only to the authorized members of your organization. We use administrative, technical, and organizational safeguards designed to protect data against unauthorized access, loss, misuse, or alteration. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
8. Data Retention
We retain data for as long as needed to provide services, comply with legal obligations, resolve disputes, and enforce agreements. Your organization may request deletion of its workspace data, and travelers may request deletion of their personal data, subject to legal and contractual requirements.
9. Your Rights
Depending on your location (for example, under GDPR, UK GDPR, Ukrainian data protection law, or certain U.S. state privacy laws), you may have rights to:
- Access, correct, or delete personal data.
- Request portability of certain data.
- Object to or restrict certain processing.
- Withdraw consent where processing is based on consent.
- Appeal or lodge complaints with a data protection authority.
To submit a request, contact us using the details below. If your data is managed by your organization, we may direct your request to that organization.
10. Children's Privacy
Erandir is intended for business use and is not directed to children under 13. We do not knowingly collect personal data from children under 13.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The latest version will always be posted on this page with an updated effective date.
12. Contact
Questions about this Privacy Policy may be directed to:
Mitryco, LLC
Representative: Dmytro Loza
1111B S Governors Ave, STE 23705
Dover, DE 19904, United States
Email: dmitry@mitryco.com