JETSFLY

Privacy Policy

This Privacy Policy explains what personal data JetsFly.com Global OÜ collects, why we collect it, how long we keep it, who we share it with, and the rights you have over it. It applies to the jetsfly.com website and to all quotations, bookings, and communications handled by JetsFly.

1. Who We Are (Controller)

The data controller is JetsFly.com Global OÜ, registry code 17206131, registered at Harju maakond, Tallinn, Kesklinna linnaosa, Liivaoja tn 1d-60, 10155, Estonia. For any privacy matter you can reach us at info@jetsfly.com or by WhatsApp at +372 522 5632. As an Estonian company we process personal data under the EU General Data Protection Regulation (GDPR) and Estonian data protection law.

2. Scope

This Policy covers personal data processed through the jetsfly.com website (including quote requests, contact forms, membership applications, and the newsletter), data processed when we arrange charter flights for you, and data exchanged with us over email, phone, WhatsApp, or Telegram. It does not cover the independent aircraft operators' own processing once you contract with them; operators are separate controllers of the passenger data they require by law.

3. Identity and Contact Data

When you request a quote, send a message, or apply for membership, we collect the details you enter: your name (or company name), email address, phone number, preferred contact method, country, and, for corporate membership, company name and registration number. We collect only what the forms ask for; none of our forms require payment card details, and we never ask for passwords or card numbers by email or chat.

4. Trip and Booking Data

Quote requests include your intended route (departure and arrival airports or cities), travel dates and times, passenger count, and any notes you add (for example catering wishes, pets, or luggage). If a charter proceeds to booking, we additionally process the passenger information that aviation, border, and security rules require, which may include full names as per travel documents, dates of birth, nationalities, and passport or ID details. This information is collected at booking stage only, never through the public website forms.

5. Communications

We keep records of correspondence with you, including emails, contact-form messages, and messages exchanged over WhatsApp or Telegram, so that our team can handle your request consistently and evidence what was agreed. If you choose to contact us via WhatsApp or Telegram, those platforms process your data under their own privacy policies as independent controllers; using them is optional and email or phone is always available instead.

6. Technical and Usage Data

Like most websites we process technical data: IP address, browser and device type, pages visited, referring page, and approximate country/city derived from your IP address. We use Google Analytics 4 to understand how visitors use the site (pages viewed, session length, traffic source). Analytics data is pseudonymous, and we do not use it to identify individuals. See our Cookie Policy for details of the cookies involved.

7. Location Convenience Features

To save you typing, the flight search box suggests your nearest airport based on the approximate location of your IP address. This lookup happens when the page loads, uses a third-party IP-location service, is not linked to your name, and is not stored by JetsFly: it only pre-fills the departure field, which you can freely change. Your chosen display currency is stored on your own device (browser local storage), not on our servers.

8. Where Your Data Is Stored

Form submissions (quotes, contact messages, membership applications, newsletter sign-ups) are stored in our secured database hosted by Supabase. The website is served by Vercel through a global content-delivery network. Analytics data is processed by Google. Each provider acts as our processor under a data-processing agreement and may store data outside the European Economic Area; see Section 12 on international transfers.

9. Purposes of Processing

We process personal data to: (a) answer your quote requests and arrange charter options with operators; (b) manage confirmed bookings, including passenger manifests, permits, and border formalities; (c) communicate with you before, during, and after a trip; (d) send the newsletter and empty-leg alerts you have subscribed to; (e) operate, secure, and improve the website; (f) meet legal duties including accounting, aviation security, AML/KYC, and sanctions screening; and (g) establish, exercise, or defend legal claims.

10. Legal Bases

Under the GDPR we rely on: performance of a contract or pre-contractual steps (Article 6(1)(b)) for quotes and bookings; legal obligation (Article 6(1)(c)) for accounting, aviation, AML, and sanctions duties; consent (Article 6(1)(a)) for the newsletter and analytics cookies, which you may withdraw at any time; and legitimate interests (Article 6(1)(f)) for service communications, fraud prevention, website security, and basic business administration, balanced against your rights.

11. Who We Share Data With

To arrange a flight we share the necessary trip and passenger details with the selected aircraft operator and, where relevant, FBOs (private terminals), ground handlers, caterers, and ground transport providers. We share data with authorities where the law requires it, including customs, immigration, and aviation security agencies on international routes. Our service providers (database hosting, website hosting, email delivery, analytics) process data only on our instructions. We never sell personal data, and we do not share your details with advertisers.

12. International Transfers

Private aviation is international by nature, and some of our service providers store data outside the EEA (for example, our database hosting is currently located in Australia and our website infrastructure operates globally). Where personal data leaves the EEA, we rely on European Commission adequacy decisions or the Commission's Standard Contractual Clauses with the receiving provider, together with technical protections such as encryption in transit and at rest. Flight-related data may also be transferred to authorities and operators in the destination country of your trip, as necessary to perform the flight.

13. Retention

We keep quote requests and enquiry correspondence for up to 24 months from last contact, so we can assist with follow-up trips, after which they are deleted or anonymised. Data relating to confirmed bookings and invoices is kept for 7 years, as required by Estonian accounting law. Newsletter data is kept until you unsubscribe. AML/KYC records are kept for the period required by anti-money-laundering law. Analytics data is retained per the Google Analytics settings (currently 14 months).

14. Security

We apply technical and organisational safeguards appropriate to the risk: encrypted connections (TLS) across the entire website, encrypted storage, database access rules that restrict every record to authorised staff accounts, unique staff authentication, and the principle of least privilege for administrative access. Lead data submitted through our forms cannot be read back through the public website. No system is perfectly secure; if a breach ever creates a high risk to you, we will notify you and the supervisory authority as the GDPR requires.

15. Your Rights

You have the right to: access a copy of your personal data; have inaccurate data corrected; have data erased where there is no continuing legal basis; restrict processing while a dispute is resolved; object to processing based on legitimate interests, including direct marketing (objection to marketing is always honoured); receive data you provided in a portable format; and withdraw any consent at any time, without affecting processing already carried out.

16. Exercising Your Rights

Email info@jetsfly.com with your request; to protect your data we may ask you to confirm your identity. We respond within one month, extendable by two further months for complex requests, in which case we will tell you. Exercising your rights is free of charge unless requests are manifestly unfounded or excessive.

17. Complaints

If you believe we have processed your data unlawfully, please contact us first so we can resolve it. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee) or with the supervisory authority of the EU member state where you live or work.

18. Marketing and Newsletter

We send the newsletter and empty-leg alerts only if you subscribe, and we record the time of your consent. Every message includes an unsubscribe option, and you can also unsubscribe by emailing info@jetsfly.com. We do not run third-party advertising on the website and do not share subscriber lists with anyone.

19. Children

Our services are directed at adults, and our forms may only be used by persons aged 18 or over. Children travel on charters only as passengers under a booking made by a responsible adult, and we process their data solely for that trip's operation and legal requirements.

20. Changes to This Policy

We may update this Policy as our services or the law change. The current version is always published on this page, and material changes will be highlighted on the website. Continued use of the website after an update constitutes acceptance of the revised Policy.