1230 Vunne forsinkelser til utbetaling

DelayMoney

Privacy Policy

Controller: Herakles Analytics AB, reg. no. 559448-3629, Sibyllegatan 69 II, 114 43 Stockholm, Sweden (“DelayMoney”, “we”, “us”). Service: delaymoney.com and the DelayMoney application.

Version 1.0 - effective from 30 August 2026. Contact: support@delaymoney.com.

This privacy policy is available in English only.

1. Summary - what you need to know

This section is a plain-language overview. It does not replace the full text below.

  • You connect your email account to DelayMoney. We use read-only access. We cannot send, delete or alter anything in your mailbox.
  • We scan your mailbox to find flight bookings, delay, cancellation and denied-boarding notices that may give you a right to compensation or a refund.
  • Email that is not flight-related is processed only momentarily in order to classify it, and is then discarded. It is not stored, not indexed, not used for advertising and never sold.
  • We use automated analysis, including AI/machine-learning models, to identify flights and assess claims. Detailed processing is described in section 4.
  • You decide which claims we pursue. We do nothing against an airline until you approve that specific claim.
  • If a claim succeeds we deduct a 20% commission including VAT and pay the remainder to you.
  • You can disconnect your mailbox at any time, which immediately revokes our access.
  • We are the controller for this processing. Our supervisory authority is the Swedish Authority for Privacy Protection (IMY).

2. Who we are and how to reach us

Herakles Analytics AB is a Swedish limited liability company, registered in Stockholm under company registration number 559448-3629. We are the controller for the personal data described in this policy.

Postal addressSibyllegatan 69 II, 114 43 Stockholm, Sweden
Privacy enquiriessupport@delaymoney.com
Data Protection OfficerNo DPO appointed, see section 16. Privacy requests go to the address above.
EU/EEA representativeNot applicable (we are established in Sweden)

3. Categories of personal data we process

3.1 Account and identity data

Name, email address, telephone number (optional), country of residence, language, password hash or third-party login identifier, account creation and login timestamps.

3.2 Mailbox access data

The OAuth access and refresh tokens issued by your email provider, the identifier of the connected mailbox, the scopes granted, and the date and time of connection and disconnection. We never receive, ask for or store your email password.

3.3 Email content processed during scanning

In order to identify flight-related messages we must process the content and metadata of messages in the connected mailbox. This includes sender, recipient, subject line, date, and message body and attachments. See section 4 for exactly what is retained and what is discarded.

3.4 Flight and booking data

Passenger name(s), booking reference / PNR, ticket number, e-ticket details, airline, flight number, route, scheduled and actual departure and arrival times, class of travel, fare and taxes paid, reason for disruption as communicated by the airline, and any rebooking, refund or voucher already provided.

3.5 Claim and case data

Which claims you approved and when, the power of attorney or authorisation you signed, correspondence with the airline, submissions to national enforcement bodies, alternative dispute resolution bodies or courts, the outcome of each claim, and the amounts awarded.

3.6 Identity verification and payout data

Where an airline, bank or authority requires it: a copy of your passport or ID document, your date of birth, your signature, and your bank account details (IBAN/BIC) or other payout details. Payment data may be processed by our payment service provider rather than by us.

3.7 Financial and accounting data

Commission invoices, VAT records, payout records and other data we are required to retain under the Swedish Accounting Act (bokföringslagen 1999:1078).

3.8 Technical and usage data

IP address, device and browser type, operating system, app version, language settings, timestamps, pages and screens viewed, error and crash logs, and cookie or similar identifiers. See section 14 on cookies.

3.9 Communications

Emails, chat messages, support tickets and, where applicable, call notes exchanged between you and us.

3.10 Personal data relating to third parties

Your mailbox will contain personal data about people other than you, co-passengers on a booking, travel agents, colleagues, family members and the senders of unrelated messages. We do not seek out this data. Section 8 explains how we handle it.

4. How the mailbox scan actually works

This section is the core of this policy. Read it carefully before connecting your mailbox.

4.1 Access is read-only and granted by you

We connect to your mailbox through the official interface of your email provider (Google Gmail API, Microsoft Graph, or another provider you select) using OAuth 2.0. You authenticate directly with your provider. We request the narrowest read-only scope that allows us to read messages. We cannot compose, send, modify, label or delete messages, and we cannot access other services in your provider account (for example Drive, Calendar or Contacts) unless separately and explicitly authorised by you.

4.2 What we scan

We scan messages in the connected mailbox, including archived and, where technically applicable, historical messages, in order to identify travel-related correspondence. Where the provider’s interface allows meaningful pre-filtering (for example by sender domain or keyword), we apply that filtering so that fewer messages are retrieved.

4.3 What happens to non-relevant messages

Messages that our classification determines are not flight-related are processed transiently, in volatile memory only, for the sole purpose of that classification. They are not written to persistent storage, not indexed, not profiled, not used to build any interest profile about you, not used for advertising, and not disclosed to anyone. They are discarded immediately after classification. Only a non-identifying processing counter (for example “number of messages scanned”) may be retained for operational and audit purposes.

4.4 What we retain

Where a message is identified as flight-related, we retain:

  • the structured data extracted from it (section 3.4); and
  • a copy of the message itself, including relevant attachments, where it constitutes evidence for a potential or ongoing claim, an airline, an enforcement body or a court will normally require the booking confirmation and the disruption notice as documentary proof.

Where a message is flight-related but relates to a flight for which no claim is possible or for which you have declined to claim, we retain only the minimum structured data needed to avoid re-presenting the same flight to you, or we delete it, in accordance with section 11.

4.5 Automated and AI-assisted analysis

Identification of flights, extraction of booking details and the initial assessment of whether a disruption may give rise to compensation are performed by automated systems, including machine-learning and large language models. These models are operated by us and/or by contracted processors listed in section 9. We contractually require that:

  • your data is used solely to deliver the DelayMoney service to you;
  • your data is not used to train, develop or improve any general-purpose or generalised AI or machine-learning model; and
  • your data is not retained by the model provider beyond what is necessary to return the result (zero or minimal retention).

4.6 Human access

Our staff and contracted case handlers do not browse your mailbox. Human access to retained email content is limited to:

  • handling a specific claim you have approved;
  • responding to a support request from you;
  • investigating a suspected security incident, fraud or abuse;
  • where required by law or by a competent authority; and
  • limited, controlled review necessary to fix a defect in, or verify the accuracy of, our extraction systems, where feasible on de-identified or aggregated data, and always subject to access logging and confidentiality obligations.

4.7 Google and Microsoft platform requirements

DelayMoney’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not transfer Google user data to third parties except as necessary to provide or improve the DelayMoney service, to comply with applicable law, or as part of a merger, acquisition or sale of assets with your consent; we do not use Google user data for serving advertising; we do not allow humans to read Google user data except as set out in section 4.6; and we do not use Google user data to develop, improve or train generalised AI and/or ML models.

Where you connect a Microsoft account, equivalent restrictions apply under the Microsoft APIs Terms of Use and the permissions you have granted.

4.8 Disconnecting

You can disconnect your mailbox at any time in your DelayMoney account settings, and independently in your email provider’s security settings. On disconnection we revoke and delete the stored tokens and stop all scanning. Data already retained in connection with an approved or ongoing claim is kept in accordance with section 11, because we and you may need it to pursue, defend or account for that claim.

5. Purposes and legal bases

#PurposeCategories of dataLegal basis (GDPR)
1Creating and administering your account, authenticating you3.1, 3.8Art. 6(1)(b) - performance of a contract
2Connecting your mailbox and scanning it to identify potential claims3.2, 3.3, 3.4Art. 6(1)(a) - your explicit consent, which you may withdraw at any time
3Presenting identified claims to you and obtaining your approval3.4, 3.5Art. 6(1)(b)
4Pursuing an approved claim against an airline as your authorised representative, including correspondence, enforcement body proceedings, ADR and litigation3.1, 3.3, 3.4, 3.5, 3.6Art. 6(1)(b); and Art. 6(1)(f) - our legitimate interest and the interest of third parties in establishing, exercising and defending legal claims
5Verifying your identity where an airline, bank or authority requires it3.6Art. 6(1)(c) - legal obligation, where applicable; otherwise Art. 6(1)(b)
6Paying out the amount recovered and invoicing our commission3.6, 3.7Art. 6(1)(b) and Art. 6(1)(c)
7Bookkeeping, tax and statutory record-keeping3.7Art. 6(1)(c) - Accounting Act, VAT Act
8Security, fraud prevention, abuse detection and logging3.1, 3.2, 3.8Art. 6(1)(f) - legitimate interest in a secure service
9Service improvement, debugging, statistics and analytics3.8, aggregated/de-identified 3.4Art. 6(1)(f) - legitimate interest in a functioning service
10Service messages about your account and your claims3.1, 3.5Art. 6(1)(b)
11Marketing to existing users about similar services3.1Art. 6(1)(f), and the Swedish Marketing Act; you may object at any time
12Marketing where consent is required3.1Art. 6(1)(a)
13Establishing, exercising or defending our own legal claimsany relevantArt. 6(1)(f)

Withdrawal of consent. Where we rely on consent (purposes 2 and 12) you may withdraw it at any time, without giving reasons. Withdrawal does not affect the lawfulness of processing carried out before withdrawal and does not affect claims you have already approved, which we continue to process under purposes 3–7.

Alternative to mailbox scanning. Connecting a mailbox is optional. If you prefer not to, you can send us your flight details directly at support@delaymoney.com and we will assess the claim from those details instead. This is why we can treat your consent to mailbox scanning as freely given.

Balancing tests. Where we rely on legitimate interests, we have carried out a balancing test and concluded that our interest is not overridden by your interests or fundamental rights. You may request a summary of that assessment at support@delaymoney.com.

6. Automated decision-making and profiling

Our systems automatically classify messages and produce an initial assessment of whether a flight may qualify for compensation, and of the likely amount. This assessment is a proposal to you, not a decision about you. No claim is submitted, withdrawn or settled without your specific approval, and every case that proceeds is reviewed by a human case handler before substantive steps are taken against an airline.

We therefore do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. If we introduce such a decision in future, we will inform you in advance and provide the safeguards required by Article 22(3), including the right to obtain human intervention, to express your point of view and to contest the decision.

The automated assessment may be incomplete or wrong. It is not legal advice and does not guarantee any outcome.

7. Special categories of personal data

We do not seek to process special categories of personal data (Article 9 GDPR) such as health data, religious or philosophical beliefs, trade union membership or data concerning your sex life or sexual orientation.

However, such data may incidentally appear in a mailbox or in a claim file, for example, a medical certificate submitted to justify a missed flight, a request for special assistance, or a meal preference that reveals a religious belief. Where such data is encountered:

  • during scanning, in a message that is not relevant to a claim: it is discarded with the rest of the message under section 4.3 and never stored;
  • where it is necessary in order to establish, exercise or defend a legal claim: we may process it on the basis of Article 9(2)(f) GDPR;
  • where it is necessary for the claim and Article 9(2)(f) does not apply: we will ask for your explicit consent under Article 9(2)(a) before processing it.

We apply technical filtering intended to reduce the likelihood that irrelevant special-category data is retained, but we cannot guarantee that such data will never be captured in a retained message.

8. Personal data about other people

Your mailbox and your claim file contain personal data about individuals other than you, most obviously co-passengers on the same booking, but also travel agents, employers and the senders of the messages we scan.

  • Data about senders of non-relevant messages is discarded under section 4.3 and is never stored.
  • Data about co-passengers is processed on the basis of Article 6(1)(f) (establishing and exercising legal claims) and, where you pursue a claim on their behalf, on the basis of the authority you confirm you hold from them.
  • You are responsible for ensuring that you are entitled to submit a claim on behalf of any other passenger and, where required, that they are informed. DelayMoney may ask you to provide a signed authorisation from each additional passenger before pursuing their claim.
  • We rely on Article 14(5)(b) GDPR (disproportionate effort) in respect of individuals whose data we obtain from your mailbox and whom we cannot practicably contact; this policy, publicly available at delaymoney.com/en/privacy, serves as the information required by Article 14.

9. Recipients and processors

We disclose personal data only as set out below. We do not sell personal data, and we do not share it for advertising purposes.

9.1 Recipients acting as independent controllers

  • Airlines and their agents - the passenger and flight data necessary to assert your claim, together with the supporting documents and your authorisation.
  • National enforcement bodies (for example the Swedish Transport Agency, Transportstyrelsen) and equivalent bodies in other Member States.
  • Alternative dispute resolution bodies, including the Swedish National Board for Consumer Disputes (ARN), and their counterparts in other Member States.
  • Courts, bailiffs and enforcement authorities (including Kronofogdemyndigheten), and external law firms instructed in a specific case.
  • Banks and payment service providers processing your payout.
  • Public authorities where we are legally obliged to disclose, including the Swedish Tax Agency and, where applicable, law enforcement.
  • Insurers and professional advisers where necessary for the defence of a legal claim.
  • An acquirer in a merger, acquisition, restructuring or sale of assets, subject to section 4.7 in respect of data received from Google APIs.

9.2 Processors acting on our documented instructions

We use the following categories of processor. Each is bound by a data processing agreement under Article 28 GDPR.

CategoryPurposeLocationProvider
Cloud hosting and databaseOperating the service, storing case filesEU/EEANamed on request
Email provider APIsRetrieving messages you authorisedEU/EEA or as determined by your providerGoogle / Microsoft / Apple
AI/ML inferenceExtracting flight data and classifying messagesEU/EEAOpenAI
Email and notification deliveryService messagesEU/EEANamed on request
Customer support platformHandling your enquiriesEU/EEANamed on request
Payment and payout servicesPaying out recovered amountsEU/EEANamed on request
Identity verificationWhere required by an airline or bankEU/EEANamed on request
Analytics and error monitoringStability and improvementEU/EEANamed on request
Accounting and invoicingStatutory bookkeepingEU/EEANamed on request

An up-to-date list of our processors is available on request at support@delaymoney.com.

10. International transfers

Our primary infrastructure is located within the EU/EEA and we design the service so that personal data is stored in the EU/EEA.

Some processing may nonetheless involve a transfer to a country outside the EU/EEA, for example where a claim is directed against a non-EU airline, where a support provider offers follow-the-sun coverage, or where a subcontractor of one of our processors is established outside the EU/EEA.

Where such a transfer takes place we rely on one of the following:

  • an adequacy decision of the European Commission for the country concerned;
  • the European Commission’s Standard Contractual Clauses, supplemented where necessary by additional technical and organisational measures identified in a transfer impact assessment; or
  • for transfers to an airline or authority outside the EU/EEA that are necessary in order to pursue your claim, the derogation in Article 49(1)(e) GDPR (establishment, exercise or defence of legal claims), or Article 49(1)(b) where the transfer is necessary for the performance of our contract with you.

You may request a copy of the relevant safeguards at support@delaymoney.com.

11. Retention

We keep personal data only as long as necessary for the purpose for which it was collected, and thereafter only where a legal obligation requires it.

DataRetention period
Non-relevant email contentNot stored. Processed transiently and discarded immediately after classification
OAuth tokens and mailbox connection dataUntil you disconnect, delete your account, or after 12 months of account inactivity, whichever is earliest
Account dataFor the life of the account, then 90 days, after which it is deleted or anonymised
Flight and booking data where no claim was pursued24 months from identification, unless you delete it earlier
Claim files, retained evidence emails, correspondence and outcomesUntil the claim is finally resolved, and thereafter for the applicable limitation period, normally up to 10 years under the Swedish Limitations Act (preskriptionslagen 1981:130) where a Swedish limitation period applies, or the shorter period applicable to the claim
Powers of attorney and authorisations10 years from the end of the mandate
Identity documentsDeleted as soon as verification is complete, and in any event within 90 days
Accounting and payout records7 years from the end of the calendar year in which the financial year ended (Accounting Act, ch. 7 s. 2)
Support communications24 months from closure of the matter
Security and access logs12 months
Technical and analytics data14 months
Marketing consents and objectionsUntil withdrawal, plus a suppression record kept indefinitely so that we can honour your objection

Where deletion is not immediately possible for technical reasons (for example in encrypted backups), we isolate the data from active processing and delete it when the backup cycle expires, normally within 30 days.

12. Security

We apply technical and organisational measures appropriate to the risk, including:

  • encryption in transit (TLS 1.2 or higher) and at rest;
  • encryption of OAuth tokens and other secrets using a dedicated key-management service, with keys separated from the application database;
  • least-privilege access control, individual named accounts, multi-factor authentication for administrative access, and logging of access to case files;
  • a documented deletion and retention routine, including deletion on account closure;
  • segregation of production and development environments, with no use of real mailbox content in development or testing;
  • vulnerability management, patching and periodic penetration testing;
  • written confidentiality undertakings and training for all personnel and contractors;
  • Article 28 data processing agreements with all processors, with sub-processor controls; and
  • a documented incident response procedure.

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we notify IMY within 72 hours of becoming aware of it, and we notify you without undue delay where the breach is likely to result in a high risk to you.

No system is completely secure. Connecting a mailbox to any third-party service increases your exposure, and you should weigh that before connecting.

13. Your rights

Under the GDPR you have the right to:

  • Access - obtain confirmation of whether we process your personal data and a copy of it;
  • Rectification - have inaccurate data corrected and incomplete data completed;
  • Erasure - have your data deleted where one of the grounds in Article 17 applies;
  • Restriction - have processing restricted in the circumstances set out in Article 18;
  • Data portability - receive the data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
  • Object - object at any time, on grounds relating to your particular situation, to processing based on legitimate interests; and to object at any time and without reason to processing for direct marketing;
  • Withdraw consent - at any time, with effect for the future;
  • Not be subject to a decision based solely on automated processing producing legal or similarly significant effects (see section 6); and
  • Lodge a complaint with a supervisory authority.

These rights are not absolute. In particular, we may refuse erasure or restriction where the data is necessary for the establishment, exercise or defence of legal claims (Articles 17(3)(e) and 18(2)), for example, while a claim you approved is pending, or during the limitation period afterwards, or where we are legally required to retain it.

How to exercise your rights. Contact support@delaymoney.com or use the tools in your account. We respond within one month; where a request is complex or you have made several requests, we may extend this by two further months and will tell you if we do. Requests are free of charge, unless manifestly unfounded or excessive. We may need to verify your identity before acting.

Complaints. Our supervisory authority is Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, Sweden - imy@imy.se, www.imy.se. If you live or work in another EU/EEA state, or the alleged infringement occurred there, you may instead complain to your local supervisory authority. You also have the right to an effective judicial remedy.

14. Cookies and similar technologies

We use cookies and similar technologies on delaymoney.com and in the app. Strictly necessary cookies are set on the basis of chapter 6, section 18 of the Swedish Electronic Communications Act (lag 2022:482). All other cookies, including analytics and marketing cookies, are set only with your consent, which you can withdraw at any time through the "Cookie settings" link in the footer.

We use three categories:

CategoryPurposeConsent
Strictly necessaryKeeping you signed in, security, load balancing and remembering your cookie choiceNo consent required
AnalyticsAnonymous statistics on how the site is used, so we can improve itOnly with your consent
MarketingMeasuring and targeting our advertisingOnly with your consent

No analytics or marketing cookies are set unless you accept them in the cookie banner. You can change or withdraw your choice at any time via "Cookie settings" in the footer, or by clearing cookies in your browser.

15. Children

DelayMoney is not directed at children. You must be at least 18 years old and legally capable of entering into a binding contract to create an account and to instruct us to pursue a claim. We do not knowingly process personal data of persons under 18 as users. Personal data of a minor may appear in a claim file where the minor is a co-passenger; in that case it is processed under section 8, on the authority of the parent or guardian.

16. Data protection officer and impact assessments

We have assessed our processing under Article 37 GDPR and have not appointed a Data Protection Officer. Privacy questions and data subject requests are handled by our privacy team and should be sent to support@delaymoney.com. We will appoint a DPO and update this policy if the scale or nature of our processing makes one mandatory.

We have carried out a data protection impact assessment under Article 35 GDPR in respect of mailbox scanning and AI-assisted analysis, and we review it whenever the processing changes materially. A summary is available on request.

17. Changes to this policy

We may update this policy. The current version, its version number and its effective date are always published at delaymoney.com/en/privacy. Where a change materially affects you, in particular a change to the purposes of processing, to the categories of recipients, or to the scope of mailbox access, we will notify you by email at least 30 days before it takes effect and, where the change requires it, ask for your renewed consent. Continuing to use the service after the effective date constitutes acceptance of the updated policy, except where consent is legally required.

18. Governing law

This policy and any dispute arising from it are governed by Swedish law and by directly applicable EU law, without prejudice to any mandatory consumer protection rules of the country in which you are habitually resident.

Herakles Analytics AB, reg. no. 559448-3629, Stockholm, Sweden.