Privacy Policy
Contents
Who we are
This policy explains how PJETS Group Ltd (‘PJETS Group’, ‘we’, ‘us’) collects, uses and protects personal data. It covers this website, our private jet charter service, and our aviation recruitment and executive search services.
We are a company registered in England and Wales, company number 14545518, with our registered office at 19‑20 Bourne Court, Southend Road, Woodford Green, Essex, England, IG8 8HD.
We are the controller of the personal data described here. This means we decide how and why it is used, and we are responsible for it under UK data protection law. That law includes the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003.
We arrange charter flights with aircraft operators, and do not operate aircraft ourselves. The organisations we pass your details to, such as the operator that flies you or an employer you are put forward to, are responsible for their own use of them, under their own privacy policies.
If you have a question about this policy, contact the team that deals with you (see Contact).
What we collect
What we collect depends on how you deal with us. Much of it is what you choose to tell us.
Charter clients and passengers
When you ask about a flight, we collect:
- your name and email address, and whether you would like a reply by email or telephone;
- your telephone number, if you give it;
- the lead passenger’s name, if you are asking for someone else;
- the type of charter and, for a group, the kind of group, such as cargo, a film crew or a government delegation;
- the journey: one way, return or multi-leg, with the airports, dates, preferred times, number of passengers and bags, and any aircraft preference;
- anything you tell us in your message.
If you book, we also collect each passenger’s full name. For international flights, we collect the passport details the operator needs for border, immigration and security rules, such as nationality, date of birth, and passport number and expiry. We keep billing details, a record of payment, and your requests for catering, ground transport and the day itself.
You may also choose to tell us about dietary, medical or accessibility needs, for yourself or another passenger, so that the flight can meet them. We treat these with extra care (see Sensitive information).
Clients who hire through us
We collect your name, company, job title, email address and telephone number. We also collect the details of the role or position you ask us to fill. These include where it is based, the licence and type ratings it needs, whether it is permanent or contract, the start date or timing, and the package.
As we work together, we keep records such as the brief, our correspondence, your feedback on candidates, and invoices.
Shortlist links
We may send you candidates for a role through a private shortlist link. When it is used, we record:
- when the link is opened, and when each CV, licence or reference on it is opened;
- your answers: the candidates you approve and the interview times you offer, with your browser’s time zone so that we read them correctly, your reasons for declining a candidate, your questions, and any note you add;
- the name and email address given with each answer.
We are told by email when the link is opened or answered, so that we can follow up. We do not use cookies for this, and we do not keep your IP address with this record. The page says so too, for any colleague you share it with.
Candidates
We collect your name, contact details, location, role or licence category, type ratings, whether you are open to relocation, your CV, and your licence if you send it (see Recruitment and executive search). We also collect anything else you tell us, such as preferred countries, rotation, notice period or salary expectations. If you use our form, we also keep a record that you ticked the box agreeing to us keeping your details.
As we work with you, we add notes of our conversations, the roles you agreed to be put forward for and how and when you agreed, feedback from clients, references, and the details of any offer and placement. If we put you forward through a shortlist link, this includes when the client opened your details and documents there, and their answer about you (see Shortlist links). We treat references as given in confidence, and pass one to an employer only if you and the referee agree.
Before we introduce you to a client, the law requires us to confirm your identity and that you hold the licences, qualifications and approvals the role needs. So we ask for proof of identity and copies of them. If you work on contract through us, we also keep your timesheets, pay and bank details and, where the law requires, proof of your right to work.
People we identify for a role
For executive search and recruitment, we sometimes identify people who may suit a role but have not contacted us. For them, we collect mainly professional information: name, current and past roles, qualifications, licences and approvals, such as acceptance as a nominated postholder, and professional contact details. If we speak, we also note what you choose to tell us, such as your interest in a move, your notice period and your current package. Where we get it explains where this comes from and when we tell you.
Referees and business contacts
If a candidate names you as a referee, we collect your name, job title, contact details and the reference you give. If you work for an operator, supplier or other business we deal with, we keep your name, role and work contact details, and our correspondence with you.
Visitors to this website
This website uses no analytics or advertising trackers. Everything on it, including the fonts and the airport search, loads from our own server, so your browser does not contact any other company while you look around.
Its public pages set no cookies. The only cookies are on the private pages our own team uses to manage shortlists. Anyone who asks for a sign-in code there gets a cookie that lasts 10 minutes, while the code is checked, and a team member who signs in gets one that keeps them signed in. Both are strictly necessary for signing in. The sign-in page also keeps the email address typed there in that browser, so that it is filled in next time. Private shortlist links we send to clients record when they are opened and answered (see Shortlist links).
Like any website, our server receives your IP address and basic technical details, such as your type of browser, and uses them only to deliver the site and keep it secure. When you send a form, our server also holds your IP address in its memory for up to 20 minutes, to stop anyone sending large numbers of messages. This record is not written to disk.
While you fill in a form, your browser keeps your answers in its session storage, for that tab only, so nothing is lost if the page reloads or you visit another page and come back. Your name, email address and telephone number are kept in the same way, so they are already filled in if you use the same form again in that tab. Your CV and licence files are never kept this way.
When you send a form, the draft of that enquiry is cleared, apart from your name, email address and telephone number. A copy of the confirmation stays with that page in the tab’s history, so a reload or the Back button shows it again. It holds your reference, your first name and email address, and the summary shown on screen. The summary can include your telephone number, the lead passenger’s name, the start of your message, or the names of your CV and licence files, but never the files themselves.
Your browser deletes all of this when the tab’s session ends, normally when you close the tab. If your browser duplicates the tab, reopens closed tabs or restores your last session, it may bring this back with the tab. None of it reaches us until you press send, and it is not used to identify or track you.
You can clear or block this site’s data in your browser settings: the forms still work, they just will not remember your answers. The confirmation is part of the tab’s history rather than site data, so it goes when you close the tab or clear your browsing history.
When you press send, your message and any attachments go to our server. It emails them to our team through our email provider, Google, then sends you a short confirmation email with your reference. Your CV and licence are held in memory only while this happens, and no copy is kept on the website’s server. Google handles the email as our service provider, and it is kept in our team’s mailbox for the periods in How long we keep it.
If the form opens your own email app instead, nothing passes through our server. Your email provider sends the message, you attach any documents yourself, and no confirmation email is sent.
To filter out automated messages, each form also sends a hidden field that people never see, and how long the page had been open. We use these only to spot spam, and they are not passed to our team. A message that fails these checks is discarded, so if you have not heard from us within our usual reply times, please email us.
When you email, call or WhatsApp us
We keep the emails, attachments and WhatsApp messages you send us, with your email address or telephone number and the name you use. We may keep a note of what we discussed on a call. WhatsApp’s own terms and privacy policy apply to your use of it.
Where we get it
We collect personal data:
- From you, when you fill in a form, email, call, message or talk to us.
- From the person booking for you, such as an assistant, an employer or a family member. If you book for others, please tell them you have given us their details, and point them to this policy.
- From our clients, such as their feedback on candidates, including their answers on a shortlist link.
- From referees you name, with your agreement.
- From candidates who name you as a referee.
- From the operator and suppliers of your flight, such as changes to timings.
- From public professional sources and referrals, for executive search and recruitment: professional networking sites such as LinkedIn, company websites, industry publications, public registers such as Companies House, and people in the industry who suggest you for a role.
If we find your details for executive search or recruitment, from a public professional source or through a referral, we will tell you so, as Article 14 of the UK GDPR requires. We will say who we are, where your details came from and whether that source is public, why we have them and how to ask us to stop, and point you to this policy. We will do this within one month of finding your details, or sooner if we contact you or share your details with a client before then.
If a candidate names you as a referee, we tell you who we are and why we have your details when we contact you for the reference. We pass your reference to an employer considering the candidate only if you and the candidate agree. If someone books a flight for you, we ask them to tell you and to point you to this policy.
If we found your details for a role and you would rather not hear from us, tell us. We will stop and delete your details, apart from a note that you asked, so that we do not contact you again. We also keep any record the law requires or that we need for a legal claim, such as a record of an introduction (see How long we keep it).
How we use it
We use personal data only where the law gives us a lawful basis. Here is what we use your details for, and the basis for each.
- To answer your enquiry, by form, email, telephone or WhatsApp, and to confirm that a form has reached us. Basis: our legitimate interests or, if you are asking about a service for yourself, the steps you ask for before a contract.
- To arrange your charter, including the charter agreement with the operator, catering and ground transport. Basis: our contract with you. If you book for a company or for someone else, or you are a passenger who did not book, our legitimate interests, and the booker’s, in the flight going as planned.
- To pass passport and passenger details to the operator, which must give them to the authorities. Basis: our contract, and our legitimate interest in the operator meeting the legal requirements for your flight.
- To run recruitment and executive search for our clients, from the brief to the appointment, including nominated postholder (Form 4) applications. Basis: our contract with the client and, for the people we deal with there, our legitimate interests.
- To match candidates with roles, keep in touch about them and, with your agreement for each role, put you forward. Basis: your consent, given when you register with us by ticking the box on our form or, if you send us your CV another way, when you confirm it after our first reply. Until then, our legitimate interest in replying to you. When you agree to be put forward, also the steps you ask for before a contract.
- To share candidates with a client through a private shortlist link, and to record when it and each document on it are opened, and the client’s answers, so that we can follow up. Basis: for candidates, your agreement for that role, and our legitimate interest in following it up. For the people at our clients who use the link, our legitimate interests.
- To draft the short profile a client sees on a shortlist: an AI service reads your CV and drafts the headline and summary, and one of our team checks and edits every word before anyone else sees it. Basis: your agreement to be put forward for that role, and our legitimate interest in describing you accurately and promptly.
- To confirm your identity and qualifications before an introduction, and to pay contractors. Basis: legal obligation, and our contract with you.
- To identify and approach people about a role, for executive search and recruitment, using professional information. Basis: our legitimate interests, and our client’s, in finding the right person for the role. We approach you in confidence and stop if you ask.
- To take up references and check licences and regulatory history, with the candidate’s agreement. Basis: our legitimate interests, and our client’s, in knowing that a candidate holds what the role needs. For any information about offences, the conditions in Sensitive information.
- To keep the records the law requires, including accounting and tax records, and those the Conduct of Employment Agencies and Employment Businesses Regulations 2003 require. Basis: legal obligation.
- To run and protect our business: invoicing, complaints, legal claims, and keeping our website and systems secure and free from fraud and spam. Basis: our contracts, our legitimate interests, and legal obligation.
- To tell you about our services. Basis: for individuals, your consent. For people at businesses, our legitimate interests, where the law allows us to contact you without consent.
Our legitimate interests
Where we rely on legitimate interests, they are:
- Answering the enquiries we receive.
- Running and developing our charter, recruitment and executive search business.
- Matching the right people with the right roles.
- Knowing when a client has seen and answered a shortlist, so that we can follow up promptly.
- Helping the operator and suppliers of your flight to do their part.
- Keeping proper records, and being able to establish, bring or defend legal claims.
- Keeping our website and systems secure.
We rely on them only where your interests and rights do not outweigh them, and you can object at any time (see Your rights).
Consent
Where we rely on your consent, you can withdraw it at any time, free of charge (see Contact). Withdrawing it does not affect what we did before, and we may still keep the records the law requires.
If you do not give us your details
Some details are needed. We cannot arrange an international flight without the passenger details the authorities require. We cannot put you forward for a role without your CV, or introduce you to a client without confirming your identity and qualifications, which the law requires.
What we do not do
We never sell your personal data, and we do not share it with others for their own marketing. We do not make decisions about you by automated means alone: people, not software, decide how to handle your enquiry and whom to put forward. The AI service that drafts candidates’ shortlist profiles only suggests words; it decides nothing, and our team checks everything it drafts.
Marketing
We send marketing emails to individuals only if you have asked to hear from us. We may contact people at businesses about our services where the law allows. Every message tells you how to opt out. If you do, we keep your address on a list of people not to contact, so that we respect your choice.
Recruitment and executive search
When you send us your CV or contact us about a role, we collect your name, contact details, location, CV, licence details and anything else you choose to tell us.
We use this to match you to roles and to contact you about them. We only send your CV to a client after you’ve agreed to it for that specific role.
We keep your details for 2 years from our last contact with you, then delete them. You can ask us to see, correct or delete your details at any time by emailing louis@pjets.co.uk.
We never sell your details.
PJETS Group Ltd, 19‑20 Bourne Court, Southend Road, Woodford Green, Essex, England, IG8 8HD, is responsible for your data.
Sensitive information
The law gives extra protection to some information, such as information about health, religious beliefs or ethnic origin (‘special category data’), and to information about criminal convictions and offences (‘criminal offence data’). We collect as little of it as we can.
Charter passengers
If you tell us about a medical condition, an accessibility need, or a dietary need that reveals your health or religious beliefs, we use it only with your explicit consent, which we will ask you to confirm in writing. We pass it only to those who need it to meet the need, such as the operator and crew, the handling agent or the caterer.
If it concerns another passenger, we will ask that passenger, or for a child a parent or guardian, to confirm their explicit consent in writing before we pass it on, for example by replying to our email.
In an emergency, where someone’s life or health is at risk and they cannot give consent, we may share what is needed to protect them, as the law allows.
Candidates
For flying roles, we may need to know whether you hold a valid medical certificate of the class the role needs, and when it expires. We record only that, never medical details, and only with your explicit consent, which we ask you to confirm in writing. We do not otherwise ask about your health unless a role legally requires it, and then we tell you what is needed and why.
A role may need a criminal record or background check, or we may review your regulatory history for a senior or nominated postholder role. We handle any information about offences only with your explicit consent, or where the law allows it without consent, for example to help a client or an aviation authority check that someone is fit for a regulated post. Often the employer or the authority carries out the check itself. Where the law requires it, we keep a written policy on how we handle this information.
Please do not send us more information of this kind than we ask for. If you do, we will delete what we do not need. Where we hold sensitive information, we limit who can see it and keep it no longer than we need it for the flight or the role.
Sending data abroad
Some of those we share data with are outside the UK. When we send personal data abroad, we protect it as UK law requires:
- Countries the UK recognises. Our website is hosted on servers in Germany. Under UK adequacy regulations, the UK recognises the countries of the European Economic Area as giving adequate protection, as it does Switzerland, Gibraltar, the Channel Islands and the Isle of Man, among others.
- The United States. Some of our service providers, such as our email provider, Google, and Anthropic, which provides the AI service described above, may process data in the United States. Where the recipient is certified under the UK Extension to the EU-US Data Privacy Framework, the UK recognises it as giving adequate protection.
- Other countries and recipients, such as the UAE, or a US recipient that is not certified. Here we use the ICO’s International Data Transfer Agreement, or its Addendum to the EU standard contractual clauses.
Where none of these applies, we rely on an exception the law allows:
- that the transfer is necessary for a contract with you, or for a contract made in your interest, such as a flight booked for you; or
- for a role abroad, your explicit consent, which we ask for when you agree to be put forward for that role, after telling you that the country may not protect your data as UK law does.
Flying you abroad means your details must go to the operator, handling agents and authorities at your destination. Putting you forward for a role abroad, for example in the UAE, means your CV must go to that employer. Some of those countries may not protect personal data as UK law does, so we send only what is needed.
You can ask us for a copy of the safeguards we use (see Contact).
How long we keep it
We keep personal data only for as long as we need it for the purpose we collected it for, including to meet legal, tax and accounting requirements. Then we delete it or make it anonymous. Our usual periods are set out below.
Charter
- Enquiries that do not lead to a booking: 2 years from our last contact with you.
- Bookings, invoices and client records: 6 years after the end of the financial year they relate to, for tax and accounting, and because that is the usual time limit for legal claims.
- Passport details, and medical, accessibility or dietary needs, for a flight: until the flight has taken place and any questions about it are settled, and in any case no more than 3 months after the flight, unless a complaint or claim needs them.
Recruitment and executive search
- Candidates: 2 years from our last contact with you (see Recruitment and executive search). Shortlists, notes, assessments and client feedback about a candidate are kept with the candidate’s details, for the same period. Shortlist links have their own entry below.
- People we identify or approach about a role who have not registered with us: 2 years from our last contact with you or, if we never contacted you, from when we found your details. Sooner if you ask us to delete them.
- Records of introductions: 6 years after our last engagement with the client. This is a record of whom we introduced, when and for which role, kept with the fee record in case we need to show what we introduced.
- Shortlist links and the documents on them: we close a link when the role is filled or withdrawn, and a link closes by itself after 90 days with no activity. When it closes by itself, its documents are deleted from our server straight away. When we close it, they are deleted within 14 days, in case the role reopens. Everything else the link holds, including when it was opened and the client’s answers, is deleted at the latest 2 years after it closes. We then keep only a short record of each candidate introduced through it: their name, the role, the client, the date of the introduction, and the last answer or outcome and its date. This is part of our records of introductions, and is deleted 6 years after the link closes. The emails we are sent about the link are kept like our other emails.
- Enquiries from employers and executive search clients that do not lead to an engagement: 2 years from our last contact with you.
- Client records, such as briefs, agreements and invoices: 6 years after our last engagement with the client.
- Contractors’ timesheets, pay and bank details: 6 years after the end of the financial year they relate to, for tax and accounting.
- Records the Conduct of Employment Agencies and Employment Businesses Regulations 2003 require, such as proof of identity and qualifications: at least 1 year, as those regulations require, or longer where another period here applies.
Everyone
- Emails, messages and call notes: for the period that applies to the enquiry, booking or candidate they relate to.
- Referees and business contacts: for as long as we keep the candidate or business record they relate to.
- Marketing opt-outs: for as long as we need them to respect your choice.
- Website technical data: our server holds the IP address it uses to limit repeated messages for up to 20 minutes, in memory only. Any server logs, which may include IP addresses, are kept for no longer than 30 days.
- Form drafts, your saved contact details and the confirmation on this website: in your browser only, until the tab’s session ends, normally when you close the tab.
If we place you in a role, your name appears on our invoice to the client, which we keep for the period above. We may keep details longer if we need them for a complaint or a legal claim, or the law requires it, and then only what we need. Backup copies are deleted as backups are replaced in the normal course.
How we protect it
We use appropriate technical and organisational measures to keep personal data secure. In particular:
- Only the people at PJETS Group who need your details to do their work can see them.
- This website uses encrypted connections (HTTPS), so what you send through our forms is encrypted between your browser and our server, and from our server to our email provider.
- CVs and licences sent through our forms are not stored on the website’s server. They are held in memory only while your message is emailed to our team, whose mailbox keeps them for the periods in How long we keep it.
- If we put you forward through a shortlist link, the documents you agreed to share are kept on our server in Germany while the link is open, and deleted within 14 days of it closing (see How long we keep it). Each link is long, random and private to one client and role, is hidden from search engines, and can be closed or replaced at any time. Only our own team can sign in to manage shortlists, with a code sent to their email.
- Our service providers must protect your details and may act only on our instructions.
No website, email system or network can be made completely secure. If a breach puts your personal data at risk, we will act quickly to contain it and, where the law requires, tell you and the Information Commissioner’s Office.
You can help: send passport scans and other sensitive documents only to the address we give you, and check with us, using the details on this page, before acting on any message that asks you to send documents or payment somewhere new.
Your rights and complaints
Under UK data protection law, you have the right to:
- Access the personal data we hold about you, and receive a copy.
- Rectification: have inaccurate details corrected and incomplete ones completed.
- Erasure: have your details deleted, for example when we no longer need them, when you withdraw your consent, or when you object and we have no overriding reason to keep them.
- Restriction: ask us to limit how we use your details, for example while we check that they are accurate.
- Objection: object where we rely on legitimate interests. We will stop unless we have compelling grounds to continue, or need your details for a legal claim. You have an absolute right to object to direct marketing: if you do, we will stop.
- Portability: receive the details you gave us in a common electronic format, or have them sent to another organisation, where we use them on the basis of your consent or a contract.
- Withdraw consent at any time, where we rely on it.
To use any of these rights, contact us (see Contact). It is free of charge. We will reply within one month. If your request is complex, or you make several, we may extend this by up to two further months where the law allows, and we will tell you why within the first month.
We may need to confirm your identity before we act, so that we never give your details to someone else. The month then starts once we have what we need.
Some rights have limits. For example, we may have to keep details the law requires, and we cannot show you other people’s information or a reference given in confidence. If a request is clearly unfounded or excessive, we may charge a reasonable fee or refuse it, as the law allows. If we cannot do what you ask, we will tell you why.
Complaints
If you are unhappy with how we have handled your personal data, please tell us first (see Contact), so that we can put it right. We will acknowledge your complaint within 30 days, look into it without undue delay, keep you informed, and tell you the outcome without undue delay.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK regulator for data protection, at ico.org.uk/make-a-complaint or on its helpline, 0303 123 1113. The ICO usually expects you to raise the matter with us first.
Children
Our website is for adults, and we do not deal directly with children.
When a child travels on a flight we arrange, their details are given to us by a parent, a guardian or the person booking, who should make sure they are entitled to share them. We use them only to arrange the flight and to give the operator what it needs, like any other passenger’s details. If you believe a child has sent us their details in any other way, contact us and we will delete them.
Changes to this policy
We may update this policy from time to time, for example when our services or the law change. We will post the new version on this page, with the date it was last updated at the top.
If we plan to use your details for a new purpose that this policy does not describe, we will tell you before we do so.
Contact
For any question or request about your personal data, contact the team that deals with you. Putting ‘Privacy’ in the subject line, or at the top of your letter, helps it reach the right person quickly.
- Charter: enquiries@pjets.co.uk
- Recruitment and executive search: louis@pjets.co.uk or 020 4571 2638
- By post: PJETS Group Ltd, 19‑20 Bourne Court, Southend Road, Woodford Green, Essex, England, IG8 8HD