Skip to content

Legal information

Privacy Policy

Last updated: 23 September 2026

1. Controller

SKY SOCIETY – FZCO IFZA Business Park, DDP Dubai Silicon Oasis, Dubai United Arab Emirates Licence No. 49170

E-mail: hello@skysocietyjet.com

For any question about data protection, or to exercise your rights, an e-mail to this address is sufficient.

2. Scope and applicable law

This policy covers the website skysocietyjet.com including the customer area "My Sky Society", as well as our communication with you and the handling of enquiries and bookings.

Sky Society is established in the United Arab Emirates. Because the service is directed at individuals in Germany, Austria and Switzerland and flights are offered from European departure points, the General Data Protection Regulation (GDPR) applies to the processing of their data under Article 3(2) GDPR. German rules on digital services and on privacy in telecommunications and digital services (TDDDG) apply in addition. For users resident in the United Arab Emirates, UAE data protection rules may apply alongside.

3. Processing activities in detail

3.1 Visiting the website

When you open the website, your browser transmits technical data to our hosting provider: IP address, date and time of the request, the address requested, volume of data transferred, status code, referrer, and browser and operating system identifiers. We need this data to deliver the site, keep it stable and detect attacks.

The legal basis is our legitimate interest in the secure and uninterrupted operation of the website (Art. 6(1)(f) GDPR). Log data is deleted or truncated after no more than 30 days and is not combined with other data.

3.2 Language preference

We store your language choice in a cookie so the site appears in that language on your next visit. This storage is necessary to provide the service you expressly requested (Sec. 25(2) no. 2 TDDDG); the subsequent processing is based on Art. 6(1)(f) GDPR. Details are set out in our Cookie Policy.

3.3 Audience measurement

We measure use of the website with Vercel Web Analytics and Speed Insights. These services work without cookies and do not recognise individuals across sessions. They record the pages opened, the referring source, an approximate region, device type and loading times. The IP address is used to derive this information and is not stored.

The legal basis is our legitimate interest in understanding which content is used and how quickly the site loads (Art. 6(1)(f) GDPR). In our assessment no personal identification arises; you may object to this processing under section 8.

3.4 Route and charter enquiries

When you request a route or a charter, we process the details from the form: departure and destination, travel window, number of travellers, number and type of accompanying animals, and any notes you choose to add. To reply we also need your name and contact details.

The legal basis is taking steps at your request prior to entering into a contract (Art. 6(1)(b) GDPR). If the enquiry does not lead to a booking, we delete it after twelve months unless a statutory retention obligation applies.

3.5 "My Sky Society" account

For the customer account we process your e-mail address and password as well as the details you store about travellers and animals. The password is stored only as a cryptographic hash. You may instead sign in using a link sent to you by e-mail, in which case no password is stored.

You can store your own documents in the account. This storage serves your own overview only: we do not check the documents for completeness or validity and we do not pass them to third parties. Sky Society administrators can view the stored files where this is necessary to support your enquiry.

The legal basis is performance of the contract covering the customer area (Art. 6(1)(b) GDPR). You can have your account deleted at any time by e-mailing hello@skysocietyjet.com. After deletion we retain only the data we need to meet statutory retention obligations or to carry out existing bookings.

3.6 E-mail communication

We send sign-in links, password resets, enquiry confirmations and correspondence about your journey through Resend, Inc., 2261 Market Street, San Francisco, CA 94114, USA. Processing takes place on servers in Ireland. This involves the recipient address, the content and the delivery status.

The legal basis is performance of the contract or pre-contractual steps (Art. 6(1)(b) GDPR) together with our legitimate interest in reliable delivery (Art. 6(1)(f) GDPR). Delivery logs are deleted after 30 days.

3.7 Booking and carrying out the journey

For a booking we process your account details, the details of all travellers, passport and identity data including nationality, date of birth and validity, information on visas and entry documents, flight and baggage data, and your invoicing address.

The legal basis is performance of the carriage contract (Art. 6(1)(b) GDPR). Where operators and border or customs authorities require this information in advance, we process it to comply with legal obligations (Art. 6(1)(c) GDPR) and in the legitimate interests of the operators involved in meeting entry requirements (Art. 6(1)(f) GDPR).

If you tell us health-related information — for example about reduced mobility, a pregnancy, or food intolerances and allergies to be taken into account for the on-board catering — we process it only so far as it is necessary to carry out the journey. We pass it to the operating air carrier and its ground handlers so far as they need it; that carrier may be established outside the European Union, including in a country not covered by an adequacy decision.

The legal basis is your explicit consent (Art. 9(2)(a) GDPR), which also covers that transfer (Art. 49(1)(a) GDPR). Providing the information is voluntary and you may withdraw your consent at any time with effect for the future. Without it the on-board catering cannot be adapted, and the journey may not be possible as planned. We delete this information once the flight has taken place, unless you choose to keep it in your customer account.

3.8 Travelling with animals

To assess whether your animal can travel in the cabin on the route you want, and to operate the journey, we process details about the animal: species, breed, age, weight and size. We pass these details to the operating carrier so far as it needs them for carriage.

You obtain the required travel and animal documents yourself and carry the originals on the day of travel. Sky Society does not check these documents, does not monitor deadlines and does not transfer the documents to third parties.

On request we will put you in touch with an agency specialising in pet travel. For that purpose we pass your name and contact details to that agency; any contract is concluded directly between you and them. The legal basis is your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time with effect for the future.

The legal basis for processing the animal details is performance of the carriage contract (Art. 6(1)(b) GDPR).

3.9 Payment

Payment is made exclusively by bank transfer to the company's account. We process the information our bank passes on with the incoming payment: the payer's name, bank details, amount, payment reference and value date. We do not collect payment card details and we currently use no payment service provider.

The legal basis is performance of the contract (Art. 6(1)(b) GDPR); the subsequent booking and retention of the records follows section 3.10. Our bank and, where applicable, intermediary correspondent banks are involved in the payment and process the data under their own responsibility.

3.10 Invoicing and retention

We retain invoices, payment records and the related correspondence for as long as the tax and commercial law of the United Arab Emirates requires. That period is generally five years after the end of the relevant tax period, and longer for matters involving real property. The legal basis is Art. 6(1)(c) GDPR in conjunction with those rules; for the duration of the retention period the data is restricted from further processing.

3.11 Information about fellow travellers

If you book for other people, we receive their data from you rather than from them. We process their name, date of birth, nationality and passport or document data so far as this is needed for carriage and border control. The legal basis is performance of the carriage contract concluded with you (Art. 6(1)(b) GDPR) together with our legitimate interest in handling a booking as a single case (Art. 6(1)(f) GDPR). Please inform your fellow travellers about this processing and about this privacy policy. They have the same rights as you (section 7).

3.12 Map display

On the shared flights page we show a map. It is rendered with the open-source library MapLibre GL; map tiles, fonts and icons are loaded from OpenFreeMap, a service of Hyperknot Software Kft., Hungary. The underlying map data comes from OpenStreetMap.

When you open that page, your browser sends its IP address to OpenFreeMap so that the tiles can be delivered. According to the provider, IP addresses are not logged; in the event of a security incident, logging may be enabled temporarily for no more than 30 days. The service sets no cookies and does not recognise individuals. OpenFreeMap processes the data under its own responsibility; there is no processor relationship.

The legal basis is our legitimate interest in presenting the routes we offer in an understandable way (Art. 6(1)(f) GDPR). The provider is established in the European Union; no transfer to a third country takes place. You may object to this processing under section 8.

4. Recipients

We share personal data with the following categories of recipients:

RecipientPurposeRole
Vercel Inc., USAhosting, delivery of the website, audience measurementprocessor
Supabase Inc., USA (data stored in the EU)database, authentication, file storageprocessor
Resend, Inc., USA (data stored in Ireland)sending system and service e-mailsprocessor
IT service provider for development and maintenanceoperating and developing the platformprocessor
Aircraft operators and their ground handlers, including outside the EUoperating the flight, handlingindependent controller
Hyperknot Software Kft., Hungary (OpenFreeMap)delivering the map tilesindependent controller
Pet travel agencyputting you in touch at your request (name, contact details)independent controller
Banks, correspondent banksprocessing the paymentindependent controller
Border, customs and veterinary authoritieslegally required notificationsindependent controller
Tax advisers and bookkeepingaccounting, tax obligationsprocessor

Data processing agreements under Art. 28 GDPR are in place with all processors. We do not share data for advertising purposes and we do not sell data.

5. Transfers to third countries

The database, authentication, uploaded files and e-mail delivery are held on servers within the European Union. Access from third countries may nevertheless occur in the course of support and maintenance.

Vercel Inc., Supabase Inc. and Resend, Inc. are established in the United States and are certified under the EU-U.S. Data Privacy Framework, for which an adequacy decision of the European Commission exists. In addition, we have agreed the European Commission's Standard Contractual Clauses with these providers.

The United Arab Emirates is not covered by an adequacy decision. Transfers of your data to our administration there, and to operators, authorities and service providers outside the EU, take place on the basis of Art. 49(1)(b) GDPR where they are necessary to perform the contract with you or to take pre-contractual steps, and otherwise on the basis of the Standard Contractual Clauses. Operating air carriers may be established outside the European Union. Health-related information under section 3.7 is transferred to recipients outside the European Union solely on the basis of your explicit consent (Art. 49(1)(a) GDPR).

You can obtain a copy of the safeguards in place by writing to hello@skysocietyjet.com.

6. Retention periods

We keep personal data only as long as it is needed for the relevant purpose:

  • Server logs: no longer than 30 days
  • E-mail delivery logs: 30 days
  • Enquiries that do not lead to a booking: 12 months
  • Customer account: until you ask us to delete it
  • Booking and travel records, invoices: until the statutory retention periods expire, generally five years
  • Health-related information under section 3.7: until the flight has taken place, unless you keep it in your customer account
  • Documents you store in your customer account: until you delete them or the account is deleted

7. Your rights

You have the right to obtain access to the data we hold about you (Art. 15 GDPR), to have inaccurate data corrected (Art. 16 GDPR), to erasure (Art. 17 GDPR), to restriction of processing (Art. 18 GDPR) and to receive the data you provided in a commonly used format (Art. 20 GDPR).

You may withdraw any consent at any time with effect for the future (Art. 7(3) GDPR). This does not affect the lawfulness of processing carried out before the withdrawal.

An e-mail to hello@skysocietyjet.com is sufficient to exercise these rights. We reply within one month; for complex requests that period may be extended by a further two months, and we will tell you if it is.

You may also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular the authority where you live or work.

8. Right to object

Where we process data on the basis of a legitimate interest (Art. 6(1)(f) GDPR) — this concerns sections 3.1, 3.2, 3.3, 3.6 and 3.12 — you may object at any time on grounds relating to your particular situation. We will then stop processing the data concerned unless we can demonstrate compelling legitimate grounds which override your interests, or the processing serves to establish, exercise or defend legal claims.

An informal e-mail to hello@skysocietyjet.com is enough.

9. No automated decision-making

We do not carry out automated decision-making, including profiling, within the meaning of Art. 22 GDPR. Your enquiries are reviewed and answered by people.

10. Whether you have to provide data

You are not legally required to provide your data. Without the information described in sections 3.4 to 3.8, however, we cannot answer an enquiry, maintain an account, or book and operate a journey; passport and document data are mandatory for carriage and border control.

11. Data security

The website is delivered exclusively over an encrypted TLS connection. Access to customer data is limited to the people who need it for their work. Passwords are stored only as hashes. Complete protection against unauthorised access cannot be technically guaranteed for transmission over the internet.

12. Minors

The customer area is intended for adults. We do not knowingly collect data from children for the purpose of maintaining their own account. Where minors travel with you, we process their travel data on the basis of the contract concluded with the person making the booking.

13. Changes to this policy

We update this policy when the processing described here or the legal position changes. The version published on this page, bearing the date given above, is the one that applies.