Privacy Policy
1. DATA CONTROLLER
Trifecta Partners Srl, with registered office in Syracuse, Italy, trading as Syncravia Executive Aviation, is the controller of personal data processed through this website. Contact: [email protected].
2. CATEGORIES OF DATA COLLECTED
Identification and contact data: full name, business email, telephone or WhatsApp number, country of residence, company, job title, LinkedIn profile where voluntarily provided.
Travel data: departure and arrival airports, dates and times, number of passengers, aircraft preferences, flexibility, events attended, willingness to share a charter.
Membership data: industry role, typical annual private aviation usage, preferred airports, referral source.
Technical data: IP address, browser type, pages visited and other data generated by the normal operation of the web server.
Where a booking proceeds, passenger data required by the operating air carrier for the flight manifest may also be processed.
3. PURPOSES AND LEGAL BASES
(a) Responding to charter and contact requests, and taking steps at the request of the data subject prior to entering into a contract — Art. 6(1)(b) GDPR.
(b) Assessing membership applications and managing the Syncravia Club relationship — Art. 6(1)(b) GDPR.
(c) Managing Syncravia Shared alerts and identifying compatible shared charter opportunities — Art. 6(1)(b) GDPR; where the request concerns a person who is not yet a member, Art. 6(1)(f) GDPR, our legitimate interest in evaluating the request.
(d) Transmitting the data strictly necessary for the flight to the selected air operator — Art. 6(1)(b) GDPR and, where applicable, Art. 6(1)(c) GDPR for aviation and security obligations.
(e) Complying with legal, accounting and tax obligations — Art. 6(1)(c) GDPR.
(f) Ensuring the security and correct functioning of the website — Art. 6(1)(f) GDPR.
4. RECIPIENTS
Data may be disclosed to: air operators and handling agents selected for the requested flight; brokers and sourcing partners contacted to obtain quotations; IT, hosting, email and CRM providers acting as processors under Art. 28 GDPR; professional advisers and public authorities where required by law. Data is not sold and is not used for third-party marketing.
5. TRANSFERS OUTSIDE THE EEA
Some flights involve operators or handling agents established outside the European Economic Area, for example in the United Arab Emirates or the United Kingdom. Certain technology providers may also process data outside the EEA. Such transfers take place on the basis of an adequacy decision, of Standard Contractual Clauses adopted by the European Commission, or of Art. 49(1)(b) GDPR where the transfer is necessary to perform the contract requested by the data subject.
6. RETENTION
Charter and contact requests that do not result in a booking: 24 months from the last contact.
Membership applications that are not approved: 12 months from the decision.
Active members: for the duration of the membership and for 10 years thereafter, in line with accounting and tax obligations.
Booking and invoicing records: 10 years, as required by Italian law.
Shared alerts: until the relevant event has taken place and for a further 12 months.
Server logs: a maximum of 12 months.
7. AUTOMATED DECISION-MAKING
Membership applications are reviewed by a person. Syncravia Shared compatibility is currently assessed manually by our team; no decision producing legal or similarly significant effects is taken on a solely automated basis and no profiling is performed for advertising purposes.
8. COOKIES, CONSENT AND ANALYTICS
On your first visit a consent banner is presented, offering accept all, reject all and manage preferences with equal prominence. No non-essential technology is activated before an explicit choice is made: every optional category is set to off by default and refusing does not restrict your use of the site.
There are four categories. Necessary: technical cookies required for the site to work and to store your language, always active, legal basis Art. 6(1)(f) GDPR and Art. 122 of the Italian Privacy Code. Analytics: aggregate audience measurement, activated only with consent. Personalisation: device recognition for continuity of experience, activated only with consent. Marketing: not currently used; should it be introduced, it will remain subject to consent.
Where analytics consent is given we record the page visited, the site language, the referring website, the type of device and browser, and the country inferred from the IP address, which is never stored. A temporary random identifier is attached to the session and is cleared when the browser is closed.
Only where Personalisation consent is given do we issue a random first-party identifier, which contains no information derived from your device or IP address. We do not use fingerprinting or any hashing of IP addresses or browsers. The identifier has a fixed maximum lifetime of twelve months that is not extended by later visits: at expiry it is permanently deleted. It is also deleted immediately if consent is withdrawn or the Personalisation category is turned off, and it is never shared with third parties or used on any other website.
Recognising a returning visitor has no effect whatsoever on the prices, availability or terms offered.
Your choices are recorded together with the date, the version of this notice and the categories accepted, as proof of consent. You can change or withdraw them at any time through the "Cookie preferences" link in the footer of every page; withdrawal takes effect immediately for the future. The data collected stays on our own infrastructure, is used in aggregate form and is never sold or shared with third parties.
9. YOUR RIGHTS
Data subjects have the right of access, rectification, erasure, restriction of processing, data portability and objection to processing carried out on the basis of legitimate interest, under Articles 15 to 22 GDPR. Requests can be sent to [email protected] and receive a response within one month.
10. RIGHT TO LODGE A COMPLAINT
Data subjects may lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it) or with the supervisory authority of their habitual residence.
11. PROVISION OF DATA
Providing the data marked as required is necessary to handle a charter request or a membership application. Without it we cannot process the request. All other data is optional.
This policy may be updated. The version in force is the one published on this page.