Privacy, handled discreetly.
Controller and contact
For information submitted through this website and the Private Brief, Oltremare is the controller and contact point until a transaction-specific contracting entity is identified. The contracting entity is named in the proposal or agreement before engagement and may separately control transaction records where it determines how and why those records are used.
Privacy enquiries may be sent to charter@oltremareglobal.com. Post may be sent to 1000 Brickell Avenue, Suite #715 PMB 782, Miami, FL 33131, United States.
What we collect
We may receive your name, email address, telephone or messaging details, the capacity in which you are making an enquiry, journey or asset requirements, preferences, correspondence, and any other information you choose to provide. Booking-stage identity or travel-document information is requested only when an operator, owner, manager or authority requires it.
Do not submit passwords, payment-card details, passport numbers, diagnoses, medical records or other unnecessary sensitive information. Where a request involves medical transport, clinical details should be exchanged directly with the appropriately licensed operator through an appropriate channel.
Why we use it and our lawful bases
We use information to answer a brief, obtain quotations, take steps requested before a contract, arrange and coordinate a mandate, maintain appropriate business records, protect the website, prevent fraud or misuse, and meet legal or regulatory obligations.
- Pre-contract and contract: where processing is necessary to respond to your request, prepare a proposal or perform an engagement.
- Legitimate interests: where necessary for discreet client service, supplier and counterparty management, website security, fraud prevention, recordkeeping and the establishment or defence of legal claims, provided those interests are not overridden by your rights.
- Legal obligation: where records or disclosures are required by applicable accounting, tax, aviation, sanctions, anti-fraud or other law.
- Consent: only where we specifically ask for consent for a purpose that genuinely requires it. Consent may be withdrawn at any time without affecting earlier lawful processing.
The required Privacy Notice acknowledgement on the Private Brief records that you have seen this notice; it is not treated as blanket consent for every use of your information.
Who may receive it
Where necessary for a request, relevant information may be shared on a need-to-know basis with prospective or selected aircraft operators, yacht owners or managers, appropriately licensed brokers, ground or hospitality providers, and independent legal, tax, technical, insurance, financing or registry specialists. Email, hosting, form-processing and document providers may process information as part of ordinary business infrastructure. Information may also be disclosed where law requires it.
We do not sell, rent or trade personal information.
International transfers
Oltremare works across international markets, so information may be processed outside the country in which you are located, including in the United States and in countries relevant to the requested journey or transaction. Where applicable law requires a transfer safeguard, an appropriate safeguard should be used.
Retention
Enquiries that do not become engagements are ordinarily deleted or anonymised within twelve months unless there is a legitimate reason to retain them longer. Transaction and completed-engagement records are retained only for as long as reasonably necessary for contractual, accounting, tax, compliance, limitation-period, security or dispute purposes and are then deleted or anonymised where appropriate.
Your rights
Depending on the law that applies to you, you may have rights to access, correct, delete, restrict or object to processing, receive portable data, and withdraw consent where consent is the basis relied upon. Requests may be sent to charter@oltremareglobal.com. We may need to verify identity before acting on a request.
Complaints
You may raise a concern with us first and may also complain to the data-protection or supervisory authority in the country where you live or work, or where you believe an infringement occurred. In the United Kingdom this is the Information Commissioner’s Office; in the EEA it is the competent national supervisory authority.
Changes
We may update this notice when our services, providers or legal obligations change. The date above identifies the current website version.