Privacy Policy

Effective Date: March 22, 2026

Version 1.0

This Privacy Policy explains how Marotino CY LTD ("TUCETO", "we", "us") collects, uses, and protects your personal data. We comply with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), the Virginia Consumer Data Protection Act (VCDPA), and all applicable data protection laws.

1. Data Controller

Marotino CY LTD
Evripidou 9A, 3031 Limassol, Cyprus
EU VAT: CY60017620T
Contact: support@tuceto.com

2. What Data We Collect & Why

2.1 Data You Provide

When you forward your booking email to go@tuceto.com, our parser extracts only the following:

  • Flight number
  • Route (departure and arrival airports)
  • Date and departure time
  • Passenger first name

We do NOT extract or store: passport numbers, ID numbers, payment card details, frequent flyer numbers, seat assignments, baggage info, ticket prices, full booking references, or any other data from your email.

The original email is automatically deleted from our servers immediately after parsing. We do not keep copies, backups, or archives of your booking confirmation.

2.2 Account & Contact Data

To deliver alerts, we store:

  • Your email address (to identify your account)
  • Your phone number (to send SMS/WhatsApp alerts)
  • Your subscription plan and payment status

3. Legal Basis for Processing (GDPR Art. 6)

We process your data based on:

  • Consent (Art. 6(1)(a)) — You actively choose to forward your booking email to us. This is an explicit, voluntary action.
  • Contract performance (Art. 6(1)(b)) — Processing is necessary to deliver the flight alert service you signed up for.
  • Legitimate interest (Art. 6(1)(f)) — Basic analytics to maintain service quality and prevent abuse.

4. Data Minimization & Deletion

This is the core of how we operate: We read only what we need, and we delete everything else.

  • Flight data (flight number, route, time) is automatically purged 48 hours after your flight departs. No exceptions.
  • Your account data (email, phone) is retained as long as you use the Service. Request deletion at any time — see Section 7.
  • We do not maintain long-term backups of flight data. When it's gone, it's gone.

5. Who We Share Data With

We do not sell your data. Period.

We share the minimum necessary data with:

  • SMS/WhatsApp delivery providers — Your phone number and alert content only, required to deliver messages. Bound by Data Processing Agreements (GDPR Art. 28).
  • Cloud hosting provider — EU-based servers only. Data encrypted at rest (AES-256) and in transit (TLS 1.3).
  • Payment processor — For paid plans only. We never see or store your full card number.

All sub-processors are bound by written DPAs and must comply with GDPR standards. A current list of sub-processors is available upon request at support@tuceto.com.

6. International Data Transfers

Your data is processed and stored on servers located in the European Union. If any sub-processor operates outside the EU/EEA, we ensure adequate safeguards through Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by additional technical measures where required under the Schrems II ruling.

7. Your Rights

7.1 Under GDPR (EU/EEA Users)

You have the right to:

  • Access your personal data and receive a copy
  • Rectify inaccurate or incomplete data
  • Erase your data ("right to be forgotten") — we will delete everything within 30 days
  • Restrict or object to processing
  • Data portability — receive your data in a structured, machine-readable format
  • Withdraw consent at any time without affecting prior processing
  • Lodge a complaint with the Cyprus Data Protection Commissioner (dataprotection.gov.cy) or your local supervisory authority

7.2 Under CCPA/CPRA (California Residents)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, and disclose
  • Delete your personal information
  • Opt out of the sale or sharing of personal information — we do not sell or share your data, so this right is automatically fulfilled
  • Non-discrimination — we will not treat you differently for exercising your rights

To exercise these rights, email support@tuceto.com with the subject line "CCPA Request". We will respond within 45 days.

7.3 Under VCDPA (Virginia Residents)

Virginia residents have comparable rights to access, correct, delete, and obtain a copy of their personal data, and to opt out of targeted advertising, sale of data, or profiling. We do not engage in any of these activities. Contact support@tuceto.com to exercise your rights.

8. Security Measures

We implement industry-standard security measures including:

  • AES-256 encryption at rest for all stored data
  • TLS 1.3 encryption for all data in transit
  • Email authentication (SPF, DKIM, DMARC) on tuceto.com domain
  • Strict access controls — only authorized systems process your data; no human reads your emails
  • Automatic data purging — flight data is deleted 48 hours after departure

9. Cookies & Tracking

The TUCETO website (tuceto.com) uses only essential cookies required for site functionality. We do not use advertising cookies, tracking pixels, or third-party analytics that identify individual users.

10. Children's Privacy

TUCETO is not directed at children under 16. We do not knowingly collect data from anyone under 16 years of age. If you believe a child has provided us with personal data, contact us immediately and we will delete it.

11. Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will:

  • Notify the Cyprus Data Protection Commissioner within 72 hours (GDPR Art. 33)
  • Notify affected users without undue delay if the breach poses a high risk (GDPR Art. 34)
  • Notify the California Attorney General if 500+ California residents are affected (CCPA)

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or a notice on tuceto.com at least 14 days before taking effect.

13. Contact Us

For any questions, data requests, or concerns about your privacy:

Marotino CY LTD
Evripidou 9A, 3031 Limassol, Cyprus
Email: support@tuceto.com
EU VAT: CY60017620T