Privacy Notice

Data Processing Notice (“Privacy Notice”)

AURIGNY AIR SERVICES LIMITED PRIVACY NOTICE FOR CUSTOMERS, SERVICE PROVIDERS, BUSINESS REFERRERS, INTERMEDIARIES AND USERS OF OUR WEBSITE AND MOBILE APPLICATION


WHAT IS THE PURPOSE OF THIS NOTICE?

Aurigny Air Services Limited ("Aurigny", "we", "us") is committed to protecting your personal data.

This Privacy Notice describes how we collect and use personal data about you during and after your relationship with us. It applies to all personal data collected by
Aurigny about its customers, service providers, business referrers, intermediaries and users of our website www.aurigny.com and our mobile application, including
existing, prospective, declined or former customers (collectively referred to as "Contacts", “you”).

This Privacy Notice does not form part of any contract to provide services, and we may update this Privacy Notice at any time.

We have separate Notices for current and ex-employees, contractors and directors ("Employee Privacy Notice") and a further Notice for prospective employees,
contractors and directors ("Recruitment Privacy Notice").

These Notices are available to relevant parties from the [email protected].

Our contact details are as follows:

Aurigny Air Services Ltd
States Airport
La Planque Lane
Forest
GUERNSEY
GY8 0DT
Tel: 01481 266444

Email: [email protected]

Guernsey Company Registration: 62362

Aurigny is primarily a "data controller". This means that we are responsible for deciding how we hold and use personal data about you. We are required under data
protection legislation to notify you of the information contained in this Privacy Notice.

It is important that you read this Privacy Notice, together with any other privacy notices we may provide on specific occasions when we are collecting or processing personal
data about you, so that you are aware of how and why we are using such information.

WHAT PERSONAL DATA WE COLLECT.

Personal data (“personal data”) means any personal details or information details which identify you or could be used to identify you, such as your name and contact details, your travel arrangements and purchase history.

We may collect and process personal data about you, including:

  • Identity and contact details, such as your name, title, date of birth, nationality, contact details and identification documents
  • Travel‑related information, including booking details, travel history, seat numbers, special assistance needs and services booked
  • Payment and financial information, such as payment transaction information
  • Account and profile information, including login credentials and frequent flyer account details
  • Communications and interactions, including correspondence with us by email, telephone, social media or other channels
  • Security and operational information, such as CCTV images, access records and incident reports
  • Customer service and administrative records, including complaints, claims, lost luggage information and related correspondence
  • Technical and usage data, including website and mobile application usage data and location data (where enabled)
Sensitive information is known as Special Category Data.

We may also collect and store Special Category Data, including but not limited to:

  • Health information, such as medical conditions, health or sickness records
  • Special assistance requirements, including mobility, medical or accessibility needs
  • Pregnancy‑related information, where relevant to travel (for example, number of weeks pregnant)
  • Compassionate fare documentation, including death certificates or evidence of death, medical evidence or supporting documentation required to process your request

When using our mobile application and/or Website, we may additionally collect: 
  • Device information (model, OS version, language, network).
  • App or website usage data (session duration, in-app behavior).
  • Location data (if permission is granted).
  • Camera access (for document scanning or uploading images).
  • Records of Push notifications (e.g., travel alerts, promotions).
  • Crash and diagnostic data.

You may manage or disable some of these permissions in your device settings; however, however, limiting all permissions may impact your experience of the mobile application. 

HOW WE COLLECT YOUR PERSONAL DATA We collect personal data from you when you:

  • Book a flight with us (either directly or indirectly through our trusted third-party partners).
  • Create an Aurigny Frequent Flyer Account.
  • Sign up for our newsletter.
  • Use mobile application through permissions you grant (such as camera, location, and notifications) and through analytics tools embedded in the application, use our website (Refer to our Cookies Policy) and other websites accessible through our website.
  • When you fly with us and provide information directly to our employees, ground handlers and other trusted partners.
  • Contact us (either by phone, WhatsApp/LinkedIn/Facebook, Instagram, email, and social media channels)
  • Visit our premises or the Airport site (in the form of CCTV images).
  • Participate in surveys, competitions, or marketing events.
  • Use our services.

We may sometimes collect additional information from third parties including travel agents, tour operators, other airlines, next of kin/guardians/parents, spouse/partner/family member/friends, "trusted" sources including law enforcement agencies, the States of Guernsey, credit reference agencies and public open sources.


LEGAL BASIS FOR COLLECTION OF PERSONAL DATA We will only process your personal data when we have a legal basis to do so.

In most cases our legal basis will be:

  • Performance of a contract
  • Compliance with a legal or regulatory obligation
  • Consent
  • Legitimate interests
  • Vital interests (or someone else's vital interests).
  • Public interest.
  • Law Enforcement Purposes

HOW WE WILL USE YOUR PERSONAL DATA
Performance of a contract
  • Providing services to you, including service notifications through our mobile application, website, e-mail, social media platforms, Whatsapp and text messages, ticketing, check‑in and boarding processes, including issuing tickets and boarding passes, managing check‑in (online, airport, mobile), allocating seats and verifying travel documentation for boarding eligibility.
  • Baggage handling and claims, including baggage check‑in and tracking, matching passengers to baggage and managing delayed, damaged, or lost luggage claims.
  • Disruption management and re‑accommodation, including rebooking passengers during delays, cancellations, or diversions, providing assistance, accommodation, or alternative transport and notifying passengers of operational changes affecting their journey.
  • Payment processing and refunds, including processing payments, managing refunds, credits, vouchers and handling chargebacks and failed payments.
  • Special Assistance requests, including delivering requested special assistance and managing pre‑booked mobility, medical or service needs.
  • Administering the contract/s we have entered with you or where you are a party related to an entity for which we are contracted to provide services.
  • Making arrangements for the termination of our customer relationship.
  • Dealing with disputes or complaints involving you.

Compliance with a legal or regulatory obligation and Law enforcement Purposes
  • Border control and immigration enforcement including immigration control, entry / exit requirements, international border enforcement, passenger security screening, No-fly lists / watchlists and Advanced Passenger Information (“API”) and Passenger Name Record “PNR” data transmission.
  • Aviation safety & regulatory oversight, including aviation safety obligations, mandatory reporting to regulators and compliance audits and inspections
  • Emergency response & incident management including responding to onboard or ground incidents, cooperating with emergency services and providing passenger data where legally required
  • Court orders, statutory requests & investigations including court orders, statutory requests, regulatory investigations
  • Proportionate CCTV, access control & safety monitoring including monitoring premises, incident investigation and protecting staff and passengers.
  • To prevent fraud.
  • International data-sharing obligations (France):
    • In accordance with Article L 232-7 of French Internal Security Code, please be informed that air carriers have to transmit reservation/checking and boarding data collected from their passengers (PNR/API) to the French national public services and competent authorities for the purposes and under conditions as defined in the Decree N° 2014-1095 dated 26/09/2014 and the modifying Decree N° 2018-714 dated 03/08/2018
    • Conformément à l’article L.232-7 du code de la sécurité intérieure, nous vous informons que les transporteurs aériens sont tenus de transmettre les données de réservations, d’enregistrement et d’embarquement de leurs passagers (PNR/API) à l’administration française, selon les modalités de traitement et pour les finalités fixées par le décret n° 2014-1095 du 26/09/2014, modifié par le décret 2018-714 du 03 août 2018.

Consent Marketing activities:

  • For example, where you consent to us collecting data for competitions, post-flight surveys or opt-in to receive direct marketing in the form of emails or direct mail
  • Where you provide consent for filming or photography for marketing campaigns and promotions via a consent form
  • Refunds on behalf of other passengers: for example where you obtain consent to obtain a refund on behalf of another passenger flying

Legitimate Interests
  • Operational efficiency & service delivery optimisation, including route performance analysis, post flight surveys, capacity planning, scheduling optimisation and resource allocation at airports.
  • Disruption analysis and service recovery improvement including analysing delays, cancellations and missed connections, improving processes and reducing repeat disruption impacts.
  • Customer communication quality & service monitoring include monitoring customer communications for quality and training, handling complaints, post flight surveys and related correspondence and escalations and improving response times and consistency.
  • Protection of the airline’s rights and business, including protecting legal rights, managing claims, defending or enforcing contractual terms and insurance purposes.
  • Business management and planning, including accounting and auditing.
  • Education, training and development requirements.
  • For security purposes including, but not limited to, the protection of staff, to assist in the prevention and detection of crime and helping to ensure public safety.
  • Enhancing customer experience and service improvement, including analysing how customers interact with our products and services (such as our flights, website and mobile application), assessing service performance and customer satisfaction, and producing anonymised management information and statistical analysis to support business planning, operational efficiency and service enhancement.
  • To monitor and identify peak workloads and appropriate staffing levels (airport check-in only).
  • To ensure network and information security, including preventing unauthorised access to our computer and electronic communications systems and preventing malicious software distribution
    Where Aurigny relies on legitimate interests as a reason for processing data, it has considered whether or not those interests are overridden by the rights and freedoms or impact the significant interests of Employees or workers and has concluded that they are not.
Vital interests (or someone else's vital interests)
  • Medical emergencies including responding to inflight or ground medical emergencies, contacting emergency services, medical professionals, or hospitals, sharing relevant health information (including special category data) where necessary to protect life and contact emergency contacts or next of kin.
  • Immediate safety incidents, including aircraft incidents or accidents, emergency landings or diversions, dealing with airport or onboard security incidents posing immediate risk and evacuations or emergency response situations.
  • Safeguarding vulnerable passengers, for example unaccompanied minors in emergency situations, disoriented, unconscious, or otherwise vulnerable passengers and situations where there is a genuine risk to life or serious harm.
Public interest and regulatory requirements
  • Aviation and transport security including supporting aviation safety and security measures, identity verification where required for public safety and use of CCTV in controlled airport environments to protect public safety
  • Access control to restricted / airside areas including meeting airport authority requirements, controlling access to restricted zones and protecting passengers, staff, and critical transport infrastructure
  • Statutory cooperation with public bodies including cooperation with regulators, airport operators, or public authorities and supporting inspections, audits, or monitoring carried out in the public interest

Some of the above grounds for processing will overlap and there may be several grounds for our use of your personal information.

Normally, the purposes for which we use your personal data will be made clear at the point where we collect that information. The personal data you provide us is used primarily to provide and pay for the products and services you request; to manage any account you may have with us, and to advise you of any improvements and or changes to those products, services and accounts and to respond to your enquiries, instructions or claims.


CHANGE OF PURPOSE We will only use your personal data for the purposes for which we collect it or for the reasons outlined above how we will use your personal data section above, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal data for unrelated purposes, we will notify you and we will explain the legal basis which allows us to do so.

Please note that we may process your personal information without your knowledge or consent where this is required or permitted by law.


WHEN DO WE ASK FOR YOUR CONSENT

Marketing and Advertising

We aim to give you meaningful choices about how your personal data is used, particularly in relation to marketing and advertising

We may use your personal data to understand what services may be relevant or of interest to you and to tailor our communications accordingly.

You will only receive direct marketing communications from us where you have requested information or purchased services from us and have opted to receive such communications.

We may also use your personal data for direct marketing purposes where you have given your consent at the time your data was collected.

We will obtain your expressed opt‑in consent before sharing your personal data with any third party outside Aurigny for marketing purposes.

You may withdraw this consent at any time by contacting the Data Privacy team. Please email: [email protected]

You can also unsubscribe from marketing emails by selecting the “unsubscribe” button at the footer of our marketing emails


Other uses for consent In addition to marketing, we may, in limited circumstances, ask for your written consent to process special category personal information. If we do, we will explain what information we need and why, so you can decide whether to consent. Providing consent is not a condition of your contract with us, although declining may affect the services we can offer.

Removing consent Where you have given consent for a specific purpose, you may withdraw that consent at any time by contacting [email protected] or writing to us at the address at the end of this Privacy Notice. Once consent is withdrawn, we will stop processing the information for that purpose unless we are permitted or required to do so by law.


AURIGNY FREQUENT FLYER ACCOUNTS If you create an Aurigny Frequent Flyer account, we will process the personal data we collect about you and any additional members nominated by you in line with this Privacy Notice.

Protecting the safety and privacy of children is important to us therefore, as an extra precaution, we will not permit children under 16 to be the Primary Member of an Aurigny Frequent Flyer account. As soon as we become aware of any party under 16 being a Primary Member of an account, we will delete it. You should only add an additional member to your Aurigny Frequent Flyer account if you have their consent to do so and to provide the personal information requested. We will delete any personal data of an additional member collected without that person's consent as soon as we become aware of it.

If you no longer wish to have an Aurigny Frequent Flyer account with us you may request that this is deleted at any time by emailing: [email protected].


USE OF SOCIAL MEDIA FOR CUSTOMER COMMUNICATION: When you contact or interact with us through social media platforms such as Facebook, Instagram, LinkedIn or WhatsApp, we may process the personal data you choose to share with us in order to respond to your enquiry.

Please note that social media platforms operate independently from Aurigny and are subject to their own privacy policies and data practices, which are outside of our control and may involve the transfer of personal data outside jurisdictions covered by data protection laws.
While we take appropriate measures to protect the personal data we receive, the security of information shared via social media platforms cannot be guaranteed. We encourage you to review the relevant platform’s privacy settings and policies before sharing personal data.

Please refrain from sharing any confidential, sensitive or special category information through social media channels. We recommend using secure communication channels or contacting us directly through official communication channels for such purposes.

If you prefer not to engage with us through social media platforms, alternative communication channels are available. Please refer to our website https://www.aurigny.com/contact for other means of communication.


IF YOU FAIL TO PROVIDE PERSONAL DATA If you fail to provide certain personal data when requested, we may not be able to fulfil the contract we have entered into with you, or we may be prevented from complying with our legal obligations


HOW WE USE SPECIAL CATEGORY PERSONAL DATA Special Category Data requires higher levels of protection and is only processed where we have a lawful basis to do so.


We only routinely process special categories of personal data for passengers in the following circumstances:

  • To arrange or deliver special assistance services, including mobility, medical or accessibility support
  • To manage disruption, re‑accommodation or emergency response where health or assistance needs are relevant
  • Responding to medical emergencies during travel and communicating with medical professionals or emergency services where required.
  • To meet aviation safety, security or regulatory requirements, including where health‑related information is necessary.
  • To process insurance, refund or waiver requests where health information is relevant.
  • To safeguard vulnerable passengers, including unaccompanied minors or passengers requiring additional care
  • To facilitate the provision of compassionate fares.
  • Where you choose to provide such information via recorded telephone calls or email communications.
  • Where you choose to provide such information allow us to process compensation claims or complaints.
  • Where you choose to provide pregnancy‑related information by completing and submitting a pregnancy fit‑to‑fly form.
  • To meet the requirements of Guernsey Airport, the Guernsey Border Agency, the United Kingdom Civil Aviation Authority ("CAA") and other regulatory bodies.


Less commonly, we may process special category personal information where it is needed in relation to legal claims or where it is needed to protect your interests (or someone else's interests) and you are not capable of giving your consent, or where you have already made the personal information public.


SHARING YOUR PERSONAL DATA
Third Party Processors


As part of delivering our services and operating our business, we routinely use a range of third‑party service providers, systems and platforms that process personal data on our behalf (“third-party processors”)


Our third-party processors support activities such as flight operations, booking and reservation systems, payment processing, customer support, IT infrastructure, data hosting, analytics, security, and regulatory reporting.
All third‑party processors are required to process personal data only on our instructions and in accordance with applicable data protection law.

We carry out appropriate due diligence and contractual safeguards, including assessing technical and organisational security measures, to ensure your personal data is protected.


We do not allow our service providers to use your personal data for their own purposes.

Our third-party processors include:
  • Booking, reservation, inventory management and airline operational systems
  • Travel agents, booking/inventory system providers or other companies involved in booking flights
  • Suppliers of data warehouse and processing operations.
  • Suppliers provide services to us in order to carry out our business activities.
  • Suppliers assisting us with improving customer experience (including Mindpearl our customer support operations)
  • Marketing, advertising and promotion partners.
  • Mobile application, website hosting and analytics providers
  • IT infrastructure, cloud hosting and data storage providers
  • Payment processing and fraud prevention providers
  • Ground handlers, Flight Operations Partners (i.e. Air Partners) and other operational partners
  • Customer support and communications systems (e.g. email, SMS, call centre platforms)
  • Data protection and compliance consultants
  • Third parties contracted by us (or contracted by you through us) to provide the products and services you have requested
  • Mobile applications and website developers and analytical systems used in these activities.
  • Suppliers of data warehouse and processing operations.


Sharing with other Controllers: In certain circumstances, we may share your personal data with other organisations that act as independent data controllers.

We only share personal data with these parties where required or permitted by law, or as otherwise outlined in this Privacy Notice.

Other data controllers may include:

  • Airports, government authorities, regulators and law enforcement bodies
  • Payment service providers, banks, card issuers and payment processors
  • Credit reference and debt collection agencies
  • Professional advisers, including auditors and legal advisers
  • The Civil Aviation Authority (CAA) and other regulators

Please note that at some of the airports that Aurigny fly to or from, biometric systems may be used as part of the boarding or security process. These systems are operated by the airport or its service providers, not by Aurigny. If you would like to understand more about this processing, please refer to the relevant airport privacy notice for further information.

As part of these processes and our own boarding processes, we may share limited passenger information, either directly or through our third-party processors, to support identity verification, such as CCTV matching, where necessary for security and operational reasons; we do not process biometric data ourselves. Sharing these purposes is limited to either what is required by Law or what is required to ensure the smooth operation of the airline.

Other Personal Data Sharing: We may also share personal data:

  • Within the Aurigny group for business management, reporting, system support and hosting
  • In connection with a corporate transaction, such as a sale, merger, reorganisation or restructuring
  • Where required to comply with legal or regulatory obligations


INTERNATIONAL TRANSFERS We may transfer the personal data we collect about you to countries within the European Union, jurisdictions the European Commission has determined provide an adequate level of protection, and jurisdictions designated by the States of Deliberation as providing appropriate safeguards. For example, as part of our customer support operations, we use Mindpearl Limited, which provides our customer services operations from Fiji.


We also may also use other service providers located outside these jurisdictions.


Where personal data is transferred to countries that are not subject to the UK GDPR, EU GDPR, or an equivalent adequacy decision, we ensure appropriate safeguards are in place, such as standard contractual clauses or other lawful transfer mechanisms, to protect your personal data in accordance with applicable data protection law.

If you have any questions about international transfers of your personal data, please contact our Data Privacy Team at [email protected].


DATA SECURITY We have appropriate technical and organisational measures in place to protect your personal data from unauthorised access, loss, misuse, alteration or disclosure.

Access to personal data is restricted to authorised personnel and third parties who have a legitimate business need and are subject to confidentiality obligations.

Our service providers are not permitted to use your personal data for their own purposes.

We may be required by law to disclose personal data to third parties, such as border control or law enforcement authorities, over whom we may have limited control.

We maintain procedures to manage and report personal data breaches where legally required.

You are encouraged to keep your mobile operating system and the Aurigny mobile application updated to the latest version in the interest of keeping data security protocols up to date.

HOW LONG WILL WE USE YOUR PERSONAL INFORMATION FOR? We will retain your personal data only for as long as necessary for the purposes for which it was collected, including meeting legal, accounting or reporting requirements.

When setting retention periods, we consider the type and sensitivity of the data, the purpose for which it is used, any associated risks, and applicable legal requirements. We may anonymise your data so it can no longer be associated with you. Personal data will then be securely deleted in accordance with our data retention policy and applicable laws.

If you would like more information about how long we retain your personal data, please contact our Data Privacy Team at [email protected].


AUTOMATED DECISION-MAKING We do not make decisions about you solely by automated means.


RIGHTS OF ACCESS, CORRECTION, ERASURE, AND RESTRICTION
Your duty to inform us of changes

It is important that the personal information we hold about you is accurate and current.

Please keep informed if your personal information changes during your working relationship with us.
Your rights in connection with personal data
You have several rights under data protection law. For more information about your rights, please visit the Office of the Data Protection Authority (ODPA) website, which
provides detailed guidance: Individuals' Rights | ODPA.

To exercise any of your data protection rights, please contact our Data Privacy Team at [email protected].

When making Rights requests:
  • We may request information to verify your identity before responding to a rights request

Where a third party is acting on your behalf, we may request written authorisation for security purposes.

Data Protection complaints

If you are unhappy with how we have collected, used, shared, stored, protected, or otherwise handled your personal data, you can raise a data protection complaint with us.

Please contact our Data Privacy Team at [email protected]. You may also raise a data protection complaint through our usual customer contact channels, and we will direct it to the appropriate team.

We will acknowledge receipt of your complaint within 30 days. We will then review and investigate the issues you have raised, make appropriate enquiries, keep you informed where necessary, and tell you the outcome of our investigation without undue delay.

You also have the right to complain directly to the Office of the Data Protection Authority, which can be contacted using the following link: odpa.gg/individuals/make-complaint

CHANGES TO THIS PRIVACY NOTICE We may update this Privacy Notice from time to time. Any changes will be published on our website and mobile application. Last updated June 2026.


QUESTIONS AND QUERIES If you have any questions about this Privacy Notice, please feel free to contact our Data Privacy Team as follows [email protected]