Privacy Notice
Last updated: 22 July 2026
This Privacy Notice explains how Pelops AI AB (“we”, “us”) processes personal data when you use Olympus, our travel planning and booking service at app.olympus-ai.techand related domains (the “Service”). We process personal data under the EU General Data Protection Regulation (GDPR) and applicable Swedish law.
Related documents: Terms of Service and Payment terms.
1. Data controller
The controller of your personal data is:
Pelops AI AB
Org. nr 559579-1574
Söralidsvägen 32, 184 60 Åkersberga, Sweden
Email: hello@pelops.ai
Olympus is our product brand. Pelops AI AB is the legal entity responsible for the Service.
2. Soft-live scope
Olympus may be offered with limited capacity or invite-based access while we operate Soft-live in Sweden and the EU. Soft-live does not reduce our obligations under the GDPR. When you use the Service, we process real account, planning, booking, and payment-related data as described below.
3. What data we collect
Depending on how you use Olympus, we may process:
- Account and identity: name, email address, login identifiers, and profile details you provide.
- Travel planning inputs: destinations, dates, traveller counts, budget, preferences, and natural-language prompts you provide for AI-assisted planning.
- Booking and travel details: passenger names and details required by suppliers, selected flights and hotels, booking references, and related confirmation data.
- Payment data: amount, currency, status, and transaction references. Card and payment-instrument data are handled by Stripe. We do not store full card numbers or CVV on our systems; we may retain limited metadata such as last four digits, brand, and a Stripe customer or payment identifier.
- Communications: emails and messages you send us (for example support or booking questions).
- Technical and usage data: IP address, browser or device information, logs, timestamps, and similar data used to run and secure the Service.
Please avoid submitting unnecessary sensitive information in free-text fields. Special-category data is processed only if you choose to provide it and only as needed for your trip or legal requirements.
4. Why we use your data and legal bases
- Provide the Service (account, trip planning, search results, Soft-live access): contract performance and/or legitimate interests in operating a reliable service (GDPR Art. 6(1)(b) and 6(1)(f)).
- Bookings and fulfilment (search and complete packages via suppliers): contract (Art. 6(1)(b)).
- Payments and refunds (via Stripe): contract (Art. 6(1)(b)); legal obligation where applicable (Art. 6(1)(c)).
- Customer support and service messages: contract and/or legitimate interests (Art. 6(1)(b), 6(1)(f)).
- Security, abuse prevention, and diagnostics: legitimate interests (Art. 6(1)(f)).
- Legal and accounting compliance: legal obligation and/or legitimate interests (Art. 6(1)(c), 6(1)(f)).
- Optional features that require consent (for example non-essential cookies, if used): consent (Art. 6(1)(a)), which you may withdraw at any time.
Where we rely on legitimate interests, we balance those interests against your rights and expectations. You may object where the GDPR allows.
5. Who we share data with
We share personal data only as needed to run Olympus. Categories include:
- Stripe for payment processing and related fraud tools.
- Duffel Technology Ltd and related Duffel entities, to search, price, book, and ticket flights and related travel inventory.
- Airlines, hotels, and other travel suppliers named in your offer, to issue tickets or reservations and operate the journey. Once they receive passenger data for carriage or stay, they typically process it as independent controllers under their own privacy notices (for example schedules, disruptions, and legal duties).
- Hosting and infrastructure (for example cloud and edge hosting used to run the web app and API).
- AI / language-model providers used to generate trip planning suggestions from the inputs you provide.
- Email and communications providers for transactional messages.
- Professional advisers and authorities when required by law or to protect rights.
For flight bookings we may share, as needed to ticket and travel: passenger full name, date of birth, gender, contact email and phone, nationality and travel document details where required (passport or ID number, expiry, issuing country), frequent-flyer numbers if you provide them, itinerary and booking or ticket references, and special service requests you submit. Payment card numbers are handled by Stripe, not sent as full card data to airlines.
Without the data required for ticketing and advance passenger information, we cannot complete a flight booking. We do not sell your personal data.
6. International transfers
Some providers may process data outside the EU/EEA. Where we transfer personal data internationally, we use appropriate safeguards under the GDPR, such as the European Commission's Standard Contractual Clauses and additional measures where required, or other lawful transfer mechanisms. Contact us for more information.
7. Retention
- Account and planning data: for the life of your account and a reasonable period after closure.
- Booking and payment records: for the booking lifecycle and as required for accounting, tax, consumer, package travel, and dispute purposes under Swedish law.
- Logs and security data: typically shorter operational periods unless needed for investigation or security.
- Support correspondence: as long as needed to resolve the matter and for a limited archive period.
When data is no longer needed, we delete or anonymise it where feasible, unless a longer period is required by law.
8. Your rights
Under the GDPR you may have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase data in certain cases
- Restrict processing in certain cases
- Data portability in certain cases
- Object to processing based on legitimate interests
- Withdraw consent where processing is based on consent (without affecting prior lawful processing)
To exercise rights, email hello@pelops.ai. We may need to verify your identity. We respond within the time limits required by law. Some rights may be limited where we must keep data for legal reasons, complete a contract, or establish, exercise, or defend legal claims.
You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se, or with another EU supervisory authority where you live or work.
9. Cookies and similar technologies
We use cookies and similar technologies that are necessary to run the Service (for example session and security). If we use non-essential analytics or similar technologies, we will inform you and obtain consent where required. You can control cookies through your browser settings; blocking some cookies may affect functionality. See also our Cookies page.
10. Security
We apply technical and organisational measures appropriate to the risk, including access controls, encryption in transit where standard, and logging. No method of transmission or storage is perfectly secure; we work to reduce risk and respond to incidents as required by law.
11. Children
The Service is directed at adults who can enter a booking contract. We do not knowingly create accounts for children under 16. Bookings may include minors as travellers when an adult books on their behalf; we then process only what is needed for the booking.
12. Changes
We may update this Privacy Notice when our processing or the Service changes. The “Last updated” date at the top reflects the latest revision. Where appropriate, we will notify Soft-live users by email or in-product notice of material changes.
13. Contact
Pelops AI AB · org. nr 559579-1574
Söralidsvägen 32, 184 60 Åkersberga, Sweden
Privacy and data protection: hello@pelops.ai
Integritet (kort svensk version)
Olympus drivs av Pelops AI AB (559579-1574), Söralidsvägen 32, 184 60 Åkersberga. Vi behandlar personuppgifter för konto, reseplanering (inklusive AI-förslag), bokning, betalning via Stripe, support och drift. Rättslig grund är främst avtal, rättslig förpliktelse och berättigat intresse enligt GDPR. Mottagare kan vara Stripe, reseleverantörer (t.ex. via Duffel), hosting och AI-leverantörer. Du har rätt till information, rättelse, radering m.m. Kontakt: hello@pelops.ai. Tillsynsmyndighet: IMY (imy.se). Fullständig information finns i den engelska texten ovan.