How personal information may be handled when people use this website, make an enquiry or arrange chauffeur travel.
Who We Are
CIA Chauffeurs is the service name used on this website. The verified legal entity acting as data controller and its official privacy contact must be configured and legally approved before this page is published.
Information We May Collect
Depending on the enquiry or booking channel actually used, information may include names, contact details, booking routes, pickup and destination information, flight details, passenger requirements, correspondence, payment records, device information and cookie choices. Only information genuinely required for the service should be collected.
How Information Is Collected
Information may be received through website forms, a configured booking system, telephone, WhatsApp, email, a corporate booker, executive assistant, travel agency, hotel or concierge, and the website consent controls. The final policy must match the channels actually in use.
Purposes for Processing
Possible purposes include responding to enquiries, reviewing availability, managing confirmed bookings, delivering journeys, communicating with passengers and bookers, administering payments or approved accounts, preventing fraud, meeting legal obligations, improving the service and sending marketing only where legally permitted.
Lawful Bases
Each purpose must be mapped to an appropriate UK GDPR lawful basis after professional review. A basis may include steps requested before a contract, performance of a contract, legal obligation, legitimate interests or consent, but no basis applies automatically to every activity.
Passenger Information Provided by Others
A company, assistant, agency, hotel or concierge may provide information for another passenger. The booker should share only what is necessary, have authority to do so and direct the passenger to this policy where appropriate.
Sharing Personal Data
Personal data should be shared only with actual recipient categories needed to operate the service, comply with law or support the website. The final policy must identify real providers and roles without suggesting unverified partnerships.
International Data Transfers
The approved policy must explain any transfer outside the United Kingdom only if one actually occurs, together with the safeguards relied upon. No international transfer mechanism is asserted in this draft.
Retention
Personal information should be kept only for justified business and legal purposes. Verified retention periods must be documented before publication; no period is invented here.
Security
Reasonable technical and organisational safeguards should be selected for the real systems and working practices. No certification or guarantee of absolute security is claimed.
Your Rights
Depending on the circumstances, UK data protection law may provide rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent. Some rights are conditional and identity may need to be verified.
Marketing
Marketing should be sent only where there is a lawful basis. Every applicable message should provide a practical way to unsubscribe or change preferences.
Cookies
The website stores necessary consent preferences locally. Optional analytics and marketing remain disabled unless selected. See the Cookie Policy and use Cookie Settings in the footer.
Complaints
Privacy questions should use the verified privacy contact once configured. The final wording about regulatory complaints must be checked against current UK requirements before publication.
Updates
The approved page must display an accurate last-reviewed date. Material changes should be reflected in the policy and, where required, communicated to affected people.