Privacy Policy
Effective date: 27 August 2026
Oryx Global Aviation, a trading name of Oryx Global Limited, a company registered in England and Wales under company number 13778790 (“we”, “our”, “us”) is the data controller for personal data collected through this website. We are committed to handling personal data lawfully, fairly and transparently under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are and how to contact us
We operate internationally from a main European head office with a West African presence, providing private jet charter, aircraft sales, commercial charter, cargo charter and specialist aviation support.
Questions about this policy or your personal data should be sent to MB@ORYX.GLOBAL, marked for the attention of the Data & Compliance Lead.
2. Personal data we collect
- Enquiry and quotation data — name, title, email address, telephone number, country, service of interest and the content of your message.
- Document request data — the details you provide when requesting a service brochure or capability document.
- Flight and travel data — where you proceed to a charter enquiry, the routing, dates, passenger numbers and any requirements you disclose to us.
- Business contact data — the professional contact details of operator, broker and supplier representatives we deal with.
- Internal account data — for staff using our internal tools, the email address and authentication records associated with the account.
- Technical data — limited server log information such as IP address and browser type, generated automatically when you visit the site.
We do not seek special category data. Where a passenger requirement makes it necessary to handle health or accessibility information, we process only what you volunteer and only to fulfil the charter.
3. How and why we use your data
- To respond to enquiries and prepare quotations.
- To arrange, broker and administer charter and aircraft transactions.
- To send requested documents and service information.
- To maintain business records and meet accounting and regulatory obligations.
- To secure, operate and improve the website and our internal tools.
- To detect and prevent fraud, sanctions breaches and other unlawful activity.
4. Lawful bases for processing
- Contract — to take steps at your request before entering into a contract, and to perform a contract with you.
- Legitimate interests — to operate and grow our business, respond to business enquiries and keep our systems secure, balanced against your rights.
- Legal obligation — to comply with tax, accounting, aviation, anti-money laundering and sanctions requirements.
- Consent — for optional marketing communications and any non-essential cookies. You may withdraw consent at any time.
5. Who we share data with
We share personal data only where necessary, with: aircraft operators, handling agents and suppliers engaged to deliver your flight or transaction; professional advisers such as lawyers, accountants and insurers; IT and communications providers who host our website and process our email; and regulators, law enforcement or other authorities where we are legally required to do so. We do not sell personal data.
Our website is hosted on Google Firebase, and enquiry emails are transmitted using EmailJS. These providers act as our processors under written terms.
6. International transfers
Because charter is inherently international, your data may be transferred outside the United Kingdom or European Economic Area — for example to an operator or handling agent in the country of departure or arrival. Where we transfer personal data to a country without an adequacy decision, we rely on appropriate safeguards, ordinarily the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum. You may request a copy of the relevant safeguard.
7. How long we keep data
- Enquiries that do not proceed: up to 24 months from last contact.
- Charter and transaction records: 7 years from the end of the relevant financial year, to meet accounting and tax obligations.
- Marketing consents and objections: for as long as we operate, so we can honour them.
- Internal account records: for the duration of the account and 12 months thereafter.
8. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, authenticated access to internal tools, least-privilege access controls and regular review of who holds access. No transmission over the internet is entirely secure, and we cannot guarantee absolute security of data sent to us.
9. Your rights
Subject to conditions and exemptions, you have the right to be informed, to request access to your personal data, to have inaccurate data rectified, to request erasure, to restrict or object to processing, to data portability, and to withdraw consent. You also have the right not to be subject to a decision based solely on automated processing — we do not carry out automated decision-making or profiling that produces legal effects.
We will respond to a valid request within one month. There is no fee unless the request is manifestly unfounded or excessive.
10. Complaints
If you are unhappy with how we have handled your personal data, please contact us first so we can try to resolve it. You may also complain to the Information Commissioner’s Office, the UK supervisory authority, at ico.org.uk, or to the supervisory authority in your country of residence.
11. Cookies
Information about the storage this site uses is set out in our Cookie Policy.
12. Changes to this policy
We may update this policy from time to time. The effective date above shows when it was last revised, and material changes will be highlighted on this page.
Return to Home