Privacy notice for the MCP server

This notice covers mcp.easygroupflights.com, the server that lets AI assistants such as Claude request group flight quotes and look up fares. It explains what the server receives, where that goes and how long it is kept. The website, bookings and cookies are covered by the operator's full privacy policy.

Last updated 1 October 2026

At a glance

The server receives only what an assistant sends to one of its tools. It never reads your conversation, your assistant's memory or your files.

egf_get_service_info
What it receivesWhich market to describe. No personal data
Where it goesAnswered by the server itself
How longNot kept
egf_search_flights, egf_get_offer
What it receivesAirports, dates and the number of travellers. No personal data
Where it goesThe operator's fare service, to find live fares
How longSearch results are held for 30 minutes
egf_prepare_group_quote, egf_prepare_flight_offer
What it receivesThe details you want to send, so the server can check them
Where it goesBack to your assistant only, inside a confirmation token valid for 15 minutes
How longNot kept by the server
egf_request_group_quote
What it receivesYour name, email address, phone number, trip details and any note
Where it goesThe operator's group desk, where a specialist prepares your quote
How longSix years from when the enquiry is handled
egf_send_flight_offer
What it receivesYour name, email address and the fare you chose
Where it goesThe operator's fare service, which emails you the offer
How longSix years from when the request is handled
  1. What this covers

    You talk to an AI assistant, and the assistant decides when to call this server. The assistant's provider handles your conversation under its own privacy terms. This server receives only the arguments of the tools it calls.

    Nothing is sent to the group desk or emailed until you have seen a summary and confirmed it. The prepare tools check the details and send nothing. Only the confirmed request goes on.

  2. Why we process it

    To prepare the quote or offer you asked for. That is a step taken at your request before a contract, under Article 6(1)(b) of the GDPR. To keep the service available, the server also counts requests per IP address for one minute, under its legitimate interest in preventing abuse (Article 6(1)(f)).

  3. Who receives it

    Only the operator's own group desk and fare service, and the companies that host and run them. The server runs on Cloudflare, which processes requests, including IP addresses, as a processor. Where that happens outside the European Economic Area, transfers rely on the European Commission's standard contractual clauses or other safeguards the GDPR allows.

    If you go on to book, the airline and other suppliers receive what the booking needs, as the operator's full policy describes. If you reach this server through another platform, that platform's own policy covers what it handles.

  4. How long it is kept

    Quote requests and offer emails are kept for six years from when the request is handled, the period the operator's policy sets for customer communication. The server itself keeps nothing longer than a day:

    • Search results: 30 minutes, so the next page and the chosen fare match what you saw. They hold no personal data.
    • Confirmation tokens: 15 minutes. They are returned to your assistant, not stored by the server.
    • The result of a sent request: up to 24 hours, including the email address it went to, so that a retried request is not sent twice.
    • Request counts per IP address: one minute.
  5. What the server does not do

    • No account, login or API key is needed, and the server sets no cookies.
    • It does not log tool arguments or results.
    • It takes no payments and stores no payment details.
    • It never asks for, or reads, your conversation, chat history, memory or files.
  6. Your rights

    You can ask for access to your data, and have it corrected, erased, restricted or transferred, and you can object to processing based on legitimate interest. Write to dpo@pelikan.sk. If you think your data is being handled wrongly, you can complain to the Slovak data protection authority, Úrad na ochranu osobných údajov (dataprotection.gov.sk), or to the authority in the country where you live.