Privacy Policy
HIGHFLYR Privacy Policy & Data Protection Notice
This Privacy Policy explains how HighFlyr processes personal data when you use the Platform, apply for membership, or book shared private jet arrangements.
- Effective Date
- August 17, 2026
- Last Updated
- August 17, 2026
HighFlyr Aviation Technologies, Inc. ("HighFlyr," "Company," "we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy informs you about how we process your personal data when you visit our website, utilize our mobile applications, register for membership, or book shared private jet arrangements (collectively, the "Platform"), and informs you of your privacy rights under applicable data protection laws, including the EU General Data Protection Regulation (EU GDPR), the UK Data Protection Act 2018 / UK GDPR, and applicable U.S. state privacy statutes.
1. Important Legal Information & Controller Identity
1.1 Data Controller
HighFlyr acts as the Data Controller for the personal data collected through the Platform and during the provision of our broker and concierge services.
Legal Entity Name: HighFlyr Aviation Technologies, Inc.
Email: privacy@highflyr.com
Data Protection Officer (DPO) / Privacy Lead: dpo@highflyr.com
Postal Address: HighFlyr Aviation Technologies, Inc., United States
1.2 Our Operational Role (14 CFR Part 295 Disclosure)
HighFlyr is an air charter broker and technology platform. HighFlyr is not a direct air carrier and does not operate aircraft. All flights facilitated by HighFlyr are operated by properly licensed and certified direct air carriers holding FAA Part 135 certificates (or equivalent foreign civil aviation authorisations). When you book a seat or charter through HighFlyr, certain passenger data must be transmitted to the licensed direct air carrier, ground handling facilities (Fixed-Base Operators / FBOs), and civil aviation authorities for flight safety and border compliance.
2. Personal Data We Collect
We collect and process personal data categorized as follows:
Identity & Demographic Data: First name, last name, title, date of birth, gender, company name, executive title, nationality, and citizenship.
Contact Data: Primary billing address, business address, email address, and mobile phone number.
Government & Travel Credentials: Passport numbers, national ID/driver’s license details, expiration dates, country of issuance, TSA PreCheck / Known Traveler Numbers (KTN), and visa documents required for flight manifests and border security clearance.
Special Category Data (Article 9 GDPR): Dietary requirements (which may indicate religious beliefs) or mobility/medical assistance needs provided voluntarily to accommodate your travel.
Financial & Transaction Data: Bank wire/ACH details, billing transaction logs, and payment method tokens. All direct payment card processing is handled by PCI-DSS Level 1 compliant processors; HighFlyr never stores raw credit card CVVs or complete PANs.
Technical & Usage Data: Internet Protocol (IP) address, browser type, device identifiers, time zone setting, operating system, platform telemetry, referral URLs, and pages visited.
Marketing & Communication Data: Your communication preferences, chat transcripts, concierge message logs, and feedback submissions.
3. Lawful Bases for Processing (Art. 6 & Art. 9 GDPR)
Under European data protection laws, we only process your personal data when we have a recognized legal basis:
| Processing Activity | Categories of Data | Lawful Basis under GDPR (Art. 6 & 9) |
|---|---|---|
| Membership & Vetting | Identity, Contact, Business Affiliation | Performance of a Contract (Art. 6(1)(b)) & Legitimate Interests (Art. 6(1)(f)) in curating an executive cabin network. |
| Booking & Flight Manifests | Identity, Travel Credentials, Contact | Performance of a Contract (Art. 6(1)(b)) & Legal Obligation (Art. 6(1)(c)) under FAA, TSA Secure Flight, and border security mandates. |
| Payment Processing | Financial, Billing Details | Performance of a Contract (Art. 6(1)(b)). |
| Special Catering / Medical Requests | Special Category Data (Health/Diet) | Explicit Consent (Art. 9(2)(a)) or Substantial Public Interest in air safety/assistance. |
| Shared Cabin Matching Algorithms | Route Preferences, Schedule Times | Performance of a Contract (Art. 6(1)(b)) and Legitimate Interests (Art. 6(1)(f)) in capping cabin occupancy at 60%. |
| FBO & Ramp Security Access | Identity, Vehicle Details | Legal Obligation (Art. 6(1)(c)) & Legitimate Interests (Art. 6(1)(f)). |
| Marketing & Analytics | Technical, Usage, Contact Data | Consent (Art. 6(1)(a)) for non-essential cookies and marketing communications. |
4. How We Share Your Data & Third-Party Disclosures
We do not sell, rent, or monetize your personal data. We disclose personal data only on a strictly need-to-know basis to:
Direct Part 135 Air Carriers: The operating air carrier receives legal flight manifests (full name, date of birth, passport/ID info) strictly to execute the flight under civil aviation laws.
Fixed-Base Operators (FBOs) & Handling Agents: Private jet terminals receive passenger arrival manifests and vehicle details to coordinate gate clearance, VIP lounge reception, and tarmac baggage transfer.
Aviation & Law Enforcement Authorities: Government agencies (TSA, FAA, CBP, civil aviation regulators) when required by statutory safety and border control mandates.
Trusted Service Processors: Cloud infrastructure providers, identity verification/KYC partners, payment gateways, and CRM/customer support tooling bound by strict Data Processing Agreements (DPAs) pursuant to Article 28 GDPR.
5. Curated Peer Network & In-Cabin Privacy
HighFlyr operates a capped 60% occupancy shared private jet platform:
Passenger Confidentiality: We never publish publicly accessible passenger manifests or share personal business profiles with other passengers prior to departure.
Cabin Decorum: All members are bound by platform terms to maintain mutual discretion regarding fellow travelers encountered in private VIP lounges and onboard shared flights.
6. International Data Transfers (Chapter V GDPR)
HighFlyr is headquartered in the United States. Your personal data will be transferred to, stored, and processed in the United States and other jurisdictions outside the European Economic Area (EEA) and the United Kingdom.
To ensure your data receives an essentially equivalent standard of protection, HighFlyr executes transfers in accordance with Chapter V of the GDPR using:
EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF where applicable;
Standard Contractual Clauses (SCCs) approved by the European Commission (under Commission Implementing Decision (EU) 2021/914), alongside the UK International Data Transfer Addendum (IDTA); and
Article 49(1)(b) Derogation: Transfers strictly necessary for the performance of an international air transport contract between you and HighFlyr.
7. Data Retention & Storage Limitation
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
Flight & Manifest Data: Retained for the statutory period mandated by civil aviation authorities, tax agencies, and FAA/DOT safety compliance regulations (typically 5 to 7 years following flight completion).
Account & Membership Profiles: Retained for the active duration of your membership plus statutory limitation periods for breach of contract claims.
Marketing Data: Retained until you withdraw your consent or unsubscribe.
Upon expiration of retention periods, data is permanently erased or irreversibly anonymized.
8. Your Data Protection Rights (EEA & UK Residents)
Under Articles 15-22 of the GDPR / UK GDPR, you hold the following statutory rights:
Right of Access (Art. 15): Request confirmation of processing and obtain a copy of your personal data.
Right to Rectification (Art. 16): Request the correction of inaccurate or incomplete personal data.
Right to Erasure / "Right to be Forgotten" (Art. 17): Request the deletion of your data where no overriding legal or regulatory basis for continued retention exists.
Right to Restriction of Processing (Art. 18): Request that we suspend processing under specific dispute circumstances.
Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, and machine-readable format.
Right to Object (Art. 21): Object at any time to processing based on legitimate interests or direct marketing.
Right to Withdraw Consent (Art. 7(3)): Withdraw consent at any time where processing was based on consent, without affecting the lawfulness of processing prior to withdrawal.
Automated Decision-Making Notice (Art. 22): Our seat-pooling algorithms match flight routes based on logistical criteria; they do not produce legal or similarly significant effects without human oversight.
How to Exercise Your Rights: To exercise any of your rights, contact our Privacy Office at privacy@highflyr.com. We respond to all verified requests within one calendar month (extendable by two additional months for complex requests where permitted by law) without charge.
9. Right to Lodge a Complaint
If you are based in the EEA or the UK and believe that our processing of your personal data infringes data protection laws, you have the right to lodge a complaint with your local Supervisory Authority:
In the UK: The Information Commissioner’s Office (ICO) - ico.org.uk
In the EU: Your national Data Protection Authority (DPA) list accessible via the European Data Protection Board (EDPB) - edpb.europa.eu
10. Security Measures (Art. 32 GDPR)
HighFlyr implements state-of-the-art technical and organizational measures to safeguard data against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure:
End-to-end transport layer encryption (TLS 1.3) for all web and API transmissions.
AES-256 encryption for sensitive databases at rest.
Role-Based Access Controls (RBAC) and mandatory Multi-Factor Authentication (MFA) for all internal systems handling passenger manifests.
Incident response frameworks with mandatory 72-hour regulatory breach notification protocols under Article 33 GDPR.
11. Cookies and Tracking Technologies
We use essential cookies to operate our Platform and non-essential analytics/performance cookies to optimize user experience. In compliance with the ePrivacy Directive and GDPR:
Non-essential cookies and trackers are blocked by default until you provide affirmative, informed consent via our cookie consent banner.
You can manage or revoke cookie preferences at any time via the Cookie Settings footer link.
12. State-Specific U.S. Privacy Rights (CCPA / CPRA)
For residents of California and other U.S. states with comprehensive privacy statutes:
We do not sell personal information or share personal information for cross-context behavioral advertising.
We limit the use of Sensitive Personal Information (government ID numbers) strictly to the provision of aviation services and regulatory security compliance.
13. Updates to this Privacy Policy
We reserve the right to amend this Privacy Policy to reflect changing regulatory, operational, or technical requirements. Material changes will be highlighted on the Platform or communicated via email prior to becoming effective.
14. Contact & Inquiries
For privacy inquiries, DPO communications, or data subject requests:
HighFlyr Privacy Office: privacy@highflyr.com
Concierge Support: support@highflyr.com
HighFlyr Aviation Technologies, Inc., United States
