Legal
Privacy Policy
Controller: AURELIS EXECUTIVE (“we”, “us”). Contact: info@aurelisexecutive.com · +31 6 28 24 62 19 · www.aurelisexecutive.com
Last updated: 24 August 2026
1. Scope
This policy explains how we process personal data when you use our website, submit an enquiry, or engage our private aviation, transfer, charter and hospitality services. We process data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Dutch law.
2. Data we collect
- Enquiry data: full name, email address, request type, message content, and any travel preferences you voluntarily provide.
- Service data: passenger details, itineraries, payment references, hotel and transport preferences necessary to fulfil a confirmed engagement.
- Technical data: basic server logs (IP address, browser type, timestamp) for security and abuse prevention. We do not operate advertising trackers or sell data to ad networks.
3. Purposes and legal bases
- Responding to enquiries — legitimate interests (Art. 6(1)(f) GDPR) and, where you request a service, steps prior to a contract (Art. 6(1)(b)).
- Delivering services — performance of a contract (Art. 6(1)(b)).
- Legal and accounting obligations — legal obligation (Art. 6(1)(c)).
- Security of our systems — legitimate interests (Art. 6(1)(f)).
We do not use your data for automated profiling that produces legal effects, and we do not send marketing without a lawful basis.
4. Recipients
Data is accessed only by personnel and trusted operational partners strictly required to fulfil your request (for example, aviation operators, ground handlers, hotels or yacht operators in the relevant destination). Partners are bound by confidentiality and data-processing terms appropriate to the engagement. We do not sell personal data.
5. International transfers
Where a service requires coordination outside the EEA (for example Dubai, Miami or Tokyo), data may be transferred to partners in those jurisdictions solely to execute your itinerary. We use appropriate safeguards (including contractual clauses) where required by GDPR.
6. Retention
- Unconverted enquiries: up to 24 months after last contact, unless a longer period is needed for legal claims.
- Client files and invoices: as required by Dutch tax and commercial law (typically 7 years for financial records).
- Server logs: retained for a limited security window, then deleted or anonymised.
7. Security
We apply organisational and technical measures appropriate to the sensitivity of executive travel data, including access control, encrypted transport (HTTPS), and the principle of least privilege. No method of transmission is completely secure; we continuously review our controls.
8. Your rights
Subject to GDPR conditions, you may request access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interests. You may lodge a complaint with the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). To exercise rights, email info@aurelisexecutive.com.
9. Cookies
This site uses only strictly necessary storage (for example language preference in local storage). We do not deploy third-party advertising cookies.
10. Children
Our services are directed at adults. We do not knowingly collect data from children under 16.
11. Changes
We may update this policy to reflect legal or operational changes. The “Last updated” date will be revised accordingly. Material changes will be indicated on this page.