Regulatory & Legal Notice: This Privacy Protocol outlines the data processing activities of Elite Luxury Bookings in compliance with the General Data Protection Regulation (Regulation (EU) 2016/679 - "EU GDPR"), the UK Data Protection Act 2018 / UK GDPR, and the California Consumer Privacy Act (CCPA/CPRA). Highlighted entries marked with LEGAL REVIEW NEEDED designate jurisdiction-specific corporate identifiers, statutory numbers, or retention windows requiring confirmation by qualified legal counsel prior to formal publication.
1. Commitment to Discretion & Scope
At Elite Luxury Bookings, discretion is the cornerstone of our enterprise. As a premier luxury concierge brokerage coordinating bespoke private aviation charter, superyacht charter, and luxury villa leases across the European Union, the United Kingdom, and internationally, we treat the safeguarding of client personal data with uncompromising rigor.
This Privacy Protocol ("Policy") sets out transparently, intelligibly, and unambiguously how we collect, process, store, disclose, and protect personal data when you engage with our concierge desk, communicate with our brokers, visit our website (eliteluxurybookings.com), or contract our charter and estate services.
In accordance with GDPR Article 12, this Policy ensures that while our high standards of discretion are preserved, all legal rights, obligations, and processing operations are set forth in clear, accessible language.
2. Identity of the Data Controller
The legal entity responsible as the Data Controller for the personal data processed under this Policy is:
- Legal Entity Name: Elite Luxury Bookings Ltd. LEGAL REVIEW NEEDED: Confirm exact incorporated name, e.g. Elite Luxury Bookings SARL / Ltd / LLC
- Company Registration / Identifier: LEGAL REVIEW NEEDED: Insert official registered company/SIREN/Companies House number
- Registered Corporate Address: LEGAL REVIEW NEEDED: Insert physical registered business address, e.g., 27 Avenue Georges Gallice, 06160 Juan-les-Pins / Antibes, France OR London, UK
- Jurisdiction of Incorporation: LEGAL REVIEW NEEDED: France / England & Wales / Monaco
- Data Protection Contact: contact@eliteluxurybookings.com (Alt: contactshaikk@gmail.com)
- Physical Response Channel: Data Privacy Desk, Elite Luxury Bookings, LEGAL REVIEW NEEDED: Insert physical postal response address
3. Personal Data We Collect
We collect only the personal information strictly necessary to coordinate high-value private charter and hospitality missions:
- Identity & Manifest Data: Full legal name, date of birth, nationality, passport copy/number, expiration date, issuing country, national identity card details, visa documentation, and emergency contact details. This data is statutory for aviation General Declarations (GenDec) and maritime IMO passenger lists.
- Contact & Encrypted Communication Records: Email address, mobile telephone number, corporate address, messaging handles (including WhatsApp and Signal accounts), and historical communication logs with our concierge team.
- Mission Logistics & Travel Preferences: Flight routes, maritime itineraries, embarkation/disembarkation ports, villa reservation dates, passenger manifests, luggage specifications, bespoke in-flight/on-board catering requests, ground transfer arrangements, and close protection/security details.
- Special Category Data (Health & Dietary): Medical mobility assistance requirements and dietary preferences that may infer religious beliefs or physiological conditions. This information is processed strictly upon your explicit consent or in emergency vital interests.
- Financial & Transaction Information: Bank account identifiers (IBAN/BIC/SWIFT), wire transfer receipts, billing addresses, VAT/tax identifiers, and corporate escrow settlement records. Elite Luxury Bookings does not store unencrypted credit card primary account numbers (PANs).
- Technical & Browsing Intelligence: IP address, browser type, operating system, geolocation indicators, referrer URLs, and behavioral interaction data collected automatically via secure digital cookies.
4. Lawful Bases for Processing (GDPR Article 6 & Article 9)
In accordance with GDPR Article 6, every processing activity conducted by Elite Luxury Bookings is anchored to a specific lawful basis:
| Data Category | Purpose of Processing | Lawful Basis (GDPR Art. 6) | Special Category Basis (Art. 9) |
|---|---|---|---|
| Identity & Manifest Data (Passports, IDs, Passenger Manifests) | Arranging flight clearances, FBO handling, customs & border security filing, port authority clearances, maritime safety compliance. | Performance of a Contract (Art. 6(1)(b)) & Legal Obligation (Art. 6(1)(c)) under civil aviation and maritime safety statutes. | N/A |
| Contact Data (Email, Phone, WhatsApp, Signal) | Managing inquiries, delivering mission quotes, 24/7 flight/yacht operational updates, contract administration. | Performance of a Contract (Art. 6(1)(b)) & Legitimate Interests (Art. 6(1)(f)) in providing premium client communication. | N/A |
| Mission Logistics & Specifications | Aircraft selection, yacht berth allocation, villa lease execution, VIP catering, ground transfers. | Performance of a Contract (Art. 6(1)(b)). | N/A |
| Dietary & Medical Assistance Data | Customized catering, wheelchair or physical accessibility, on-board emergency preparedness. | Performance of a Contract (Art. 6(1)(b)). | Explicit Consent (Art. 9(2)(a)) or Vital Interests (Art. 9(2)(c)) in medical emergencies. |
| Financial & Transaction Records | Invoicing, fiscal accounting, Anti-Money Laundering (AML) verifications, fraud prevention. | Legal Obligation (Art. 6(1)(c)) & Contract Performance (Art. 6(1)(b)). | N/A |
| Website Analytics & Cookies | Digital infrastructure security, site performance monitoring, user experience optimization. | Consent (Art. 6(1)(a)) via cookie consent management banner. | N/A |
5. Third-Party Sharing & Operational Partners
Elite Luxury Bookings acts as an intermediary luxury broker. To execute contracted travel and hospitality missions, essential client data must be disclosed to verified third-party partners:
- Licensed Air Carriers & Vessel Operators: Commercial aircraft operators (AOC holders), superyacht owners, and management companies who require official passenger manifests for flight clearances, maritime navigation permits, and insurance coverage.
- Fixed Base Operators (FBOs) & Port Authorities: Private airport terminal handlers, customs and border control agencies, harbor masters, and civil aviation security officials under international ICAO and IMO/SOLAS mandates.
- Estate Managers & Villa Hosts: Property owners and luxury estate management companies for guest registration, security clearance, arrival logistics, and tenancy documentation.
- VIP Ground Transportation & Close Protection: Vetted executive chauffeur companies, licensed private security details, helicopter transfer providers, and bespoke provisioning suppliers.
- Technology & Cloud Infrastructure Hosts: Encrypted communications platforms (WhatsApp/Meta, Signal), secure cloud storage facilities, and accounting software vendors.
Confidentiality Safeguards: All external commercial partners and aviation/maritime operators are bound by strict non-disclosure agreements (NDAs) and Data Processing Agreements (DPAs) requiring enterprise-grade security standards and restricting processing strictly to the designated mission scope.
6. International Data Transfers (Cross-Border Data Flows)
Given the international nature of private charter, personal data may be transferred to and stored in jurisdictions outside the European Economic Area (EEA) and the United Kingdom (e.g., when organizing private flights or yacht charters operating in or through the United States, the Caribbean, the UAE, or Asia-Pacific).
Where personal data is transferred to a country that has not received a formal Adequacy Decision from the European Commission or UK Government, Elite Luxury Bookings implements rigorous contractual safeguards:
- Standard Contractual Clauses (SCCs): We incorporate the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914) and the UK International Data Transfer Addendum into our agreements with international processors.
- U.S. Data Processing & Communication Tools: Communications routed via WhatsApp are operated by WhatsApp LLC / Meta Platforms, Inc. Transfers to Meta’s U.S. data infrastructure are governed by Meta’s Data Privacy Framework certification and Standard Contractual Clauses LEGAL REVIEW NEEDED: Confirm formal reliance on EU-US Data Privacy Framework vs. SCCs. Clients seeking zero-knowledge communication may request Signal or PGP-encrypted channels.
- Specific Derogations (GDPR Art. 49(1)(b)): Transfers strictly necessary for the performance of a contract concluded in your interest (e.g., filing flight manifests directly with destination civil aviation authorities).
7. Data Retention Schedule
In accordance with the GDPR principle of storage limitation (Article 5(1)(e)), personal data is retained only for the duration necessary to fulfill the operational, legal, and regulatory purposes for which it was gathered:
| Record Type | Retention Period | Statutory / Operational Justification |
|---|---|---|
| Flight Manifests & FBO Filings | 5 Years post-flight completion | Civil aviation security compliance, air accident investigation readiness, and border control audits. LEGAL REVIEW NEEDED: Confirm DGAC / CAA statutory requirement |
| Maritime Manifests & Crew Lists | 3 Years post-charter completion | Port state control requirements, flag state maritime safety logs, and SOLAS conventions. LEGAL REVIEW NEEDED: Confirm flag state / Port Authority requirement |
| Invoices, Contracts & Tax Records | 7 to 10 Years post-financial year end | Statutory commercial code, tax audit, and Anti-Money Laundering (AML) retention rules (e.g., 10 years under French Commercial Code Art. L123-22; 7 years under UK HMRC rules). LEGAL REVIEW NEEDED |
| Inquiries & Uncompleted Quotes | 12 Months from quote date | Legitimate commercial interest in revisiting past quotes upon client return; permanently purged thereafter. |
| Encrypted Chat Transcripts (WhatsApp/Signal) | 6 Months post-charter completion | Operational dispute resolution and concierge continuity, followed by irreversible deletion. |
| Web Analytics & Session Logs | 14 Months | Standard Google Analytics / telemetry retention window for traffic evaluation and cybersecurity monitoring. LEGAL REVIEW NEEDED |
Upon expiration of the applicable retention schedule, records are securely destroyed or permanently anonymized using cryptographic data sanitization standards.
8. Cookies, Tracking Technologies & Analytics
Our website uses first-party and third-party cookies and tracking scripts to ensure digital security, facilitate page navigation, and analyze visitor interactions:
- Strictly Necessary Cookies: Essential for website routing, session security, and mobile navigation. These cookies cannot be deactivated.
- Google Analytics 4 (GA4): Measurement ID
G-J56D1LJLFM. Evaluates aggregate visitor traffic, session duration, and route conversion events. IP anonymization protocols are enforced. - Microsoft Clarity: Tracking ID
sia395rirl. Generates anonymized behavioral heatmaps and session interaction diagnostics to improve interface performance. - Yandex.Metrika: Tag ID
103558768. Provides web analytics, click maps, and traffic source validation.
Managing Cookies: When visiting our website, you may manage your tracking preferences via our consent banner. You may also block or delete cookies via your browser settings; however, disabling certain cookies may affect website functionality.
9. Your Data Subject Rights (GDPR & UK GDPR)
Under Chapter III of the GDPR (Articles 15 through 22), you hold enforceable legal rights regarding your personal information:
- Right of Access (Art. 15): Obtain confirmation as to whether your personal data is being processed, along with a structured copy of that data and detailed processing information.
- Right to Rectification (Art. 16): Request the immediate correction of inaccurate or incomplete personal data.
- Right to Erasure ("Right to be Forgotten", Art. 17): Request the permanent deletion of your personal records where data is no longer necessary, or where processing was based on withdrawn consent, subject to mandatory civil aviation, maritime, or fiscal retention laws.
- Right to Restriction of Processing (Art. 18): Restrict the processing of your data while its accuracy or the lawfulness of processing is being verified.
- Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, and machine-readable format (e.g., CSV/JSON), or request transmission to another controller where technically feasible.
- Right to Object (Art. 21): Object at any time to data processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent (Art. 7(3)): Withdraw consent at any time where processing was grounded in consent, without affecting the lawfulness of prior processing.
How to Exercise Your Rights: Submit your request by email to contact@eliteluxurybookings.com with the subject line "Data Subject Rights Request". We verify identity and respond within one calendar month (30 days) without fee, unless requests are manifestly unfounded or excessive.
10. California Privacy Rights (CCPA / CPRA Notice)
This section applies solely to residents of the State of California under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA).
- Categories of Personal Information Collected: Real names, passport numbers, email addresses, telephone numbers, financial details, travel itinerary details, and browsing telemetry.
- Commercial Purposes: Delivering luxury charter brokerage, verifying passenger identity for flight manifests, and processing contract settlements.
- No Sale or Sharing of Personal Data: Elite Luxury Bookings does not sell personal information, nor do we "share" personal information for cross-context behavioral advertising as defined under the CCPA/CPRA.
- California Consumer Rights: California residents have the right to request disclosure of personal data collected, request deletion, request correction of inaccurate data, and limit the use of sensitive personal information. We do not discriminate against any client for exercising these rights.
11. Security Standards & Breach Notification Protocol
Elite Luxury Bookings implements rigorous technical, organizational, and physical safeguards:
- Cryptographic Security: AES-256 encryption at rest and TLS 1.3 protocol encryption in transit across all digital communication and administrative channels.
- Access Governance: Role-based access control (RBAC) and the Principle of Least Privilege (PoLP); access to sensitive passport and manifest files is restricted solely to assigned mission coordinators.
- Binding Confidentiality: All staff, brokers, and operational contractors are bound by comprehensive confidentiality deeds containing strict non-disclosure obligations.
Personal Data Breach Protocol (GDPR Art. 33 & 34):
- In the event of a personal data breach, we will notify the competent supervisory authority within 72 hours of becoming aware of the incident, in accordance with GDPR Article 33.
- Where the breach is likely to result in a high risk to your personal rights and freedoms, we will notify you directly and without undue delay, outlining the nature of the breach, likely consequences, and remediation measures undertaken.
12. Supervisory Authority & Right to Lodge a Complaint
If you consider that our processing of your personal data infringes the GDPR or applicable data privacy laws, you have the right to lodge a complaint with a competent supervisory authority:
- Lead Authority in France:
Commission Nationale de l'Informatique et des Libertés (CNIL)
3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
Website: www.cnil.fr LEGAL REVIEW NEEDED: Confirm lead EU authority - Supervisory Authority in the United Kingdom:
Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom
Website: www.ico.org.uk - Other Jurisdictions: You may lodge a complaint with the supervisory authority of the EU Member State of your habitual residence, place of work, or place of the alleged infringement.
13. Governing Law & Dispute Resolution
This Policy and any disputes or claims arising out of or in connection with it shall be governed by and construed in accordance with the laws of France LEGAL REVIEW NEEDED: Confirm governing law, e.g. France / England & Wales. Any dispute relating to data privacy that cannot be resolved amicably shall be submitted to the exclusive jurisdiction of the competent courts of Grasse / Nice, France LEGAL REVIEW NEEDED: Confirm judicial venue.
14. Contact & Data Privacy Desk
For questions regarding this Privacy Protocol, to exercise your data subject rights, or to discuss custom non-disclosure agreements (NDAs) for high-profile missions, please contact our compliance desk:
- Direct Privacy Desk Email: contact@eliteluxurybookings.com
- Alternate Administrative Email: contactshaikk@gmail.com
- Dedicated WhatsApp Concierge Line: +91 88010 79030 LEGAL REVIEW NEEDED: Confirm corporate desk line
- Physical Response Channel:
Attn: Data Privacy & Protocol Desk
Elite Luxury Bookings Ltd.
LEGAL REVIEW NEEDED: Insert complete physical corporate mailing address