PRIVACY POLICY

(Version 1.3, 8 May 2025)

1 Who we are

Accessairbility Ltd (we, us, our)

Registered office: 6 Bexley Square, Salford, Greater Manchester, M3 6BZ, UK

Email: info@access-air-bility.com

Privacy Lead: James William Boyce

For details on cookies and tracking, see our Cookie Policy. By using this site you also agree to our Terms and Conditions.

2 What data we collect, why, and on what legal basis

Category

Examples

Purpose

Legal basis

Identity and contact

Name, email (optional)

Follow-up research; newsletter

Legitimate interests

Travel details

Flight number, travel dates, airports, cabin

Correlating assistance experience

Legitimate interests

Accessibility and health

Impairment type, mobility aid, assistance requested

Benchmarking accessibility and equality of service

Explicit consent under Article 9(2)(a) UK GDPR, fallback: substantial public interest under UK DPA 2018 Schedule 1 paragraph 16

Staff details

Role, employer, tenure

Analysing operational bottlenecks

Legitimate interests

Payment data

Card token, billing email (Stripe/WooCommerce)

Delivering paid reports

Contract

Technical and cookies

IP address, device data, Google Analytics 4 (IP-anonymised), LinkedIn Insight Tag, Google reCAPTCHA v2 (free tier), Stripe cookies

Analytics, fraud detection, site security, B2B remarketing, spam prevention

Legitimate interests for analytics, reCAPTCHA, Insight Tag; consent for non-essential cookies

Survey responses

Journey facts, ratings, free-text feedback

Building anonymised research database

Explicit consent

See our Appropriate Policy Document for full Article 6 and 9 bases and fallback conditions.

3 How we process your data

We decide the why and how of processing and are therefore the data controller.

Our processors (WordPress/Elementor, AWS, Stripe, Google reCAPTCHA, etc.) act under Article 28 GDPR addenda.

We do not make automated decisions with legal or similarly significant effects.

4 Sharing and safeguards against re-identification

We never disclose raw, identifiable survey responses.

We share only aggregated, anonymised statistics.

Client contracts forbid any re-identification attempt; downstream controllers must manage their own compliance.

5 International transfers

Primary storage is in the UK (London) or EU (Dublin). Any transfers outside the UK/EEA use the UK International Data Transfer Agreement or EU Standard Contractual Clauses, plus a Schrems II–compliant Transfer Risk Assessment.

6 Retention schedule

Dataset

Maximum retention

Raw identifiable survey submissions

Deleted or redacted within 14 days

Anonymised/pseudonymised dataset

Kept indefinitely

7 Security measures and redaction

AES-256 at rest and TLS 1.2+ in transit

Least-privilege access controls plus multi-factor authentication for all staff and dashboard users

Google reCAPTCHA v2 for spam prevention (visitor IPs transmitted to Google; see Google’s DPA and Privacy Notice)

Annual external penetration testing; AWS GuardDuty monitoring

Automated PII-scrub and 14-day purge via cron job

8 Your rights and how to exercise them

You may request access, rectification, erasure, restriction, portability, or object to processing at any time by emailing info@access-air-bility.com with “Data Request” in the subject. We respond within one calendar month via encrypted link.

9 Cookies and tracking

Our cookie banner lets you consent to or refuse each category. We link to this Cookie Policy in the footer.

Cookie or Tag

Purpose

Lifespan

Category

Consent toggle

_ga (GA4)

Usage analytics (IP anonymised)

2 years

Statistics

yes

li_fat_id (LinkedIn Insight Tag)

B2B remarketing

30 days

Marketing

yes

_GRECAPTCHA

Bot and spam prevention

Session

Essential¹

no

_stripe_mid / _stripe_sid

Payment fraud detection

1 year

Essential

no

Other essential cookies

WordPress, Elementor, etc.

Session

Essential

no

¹ Although marked Essential, reCAPTCHA processes personal data under legitimate interests.

See Google’s data processing terms at https://policies.google.com/privacy/frameworks and Google’s privacy notice at https://policies.google.com/privacy

10 Children

We do not knowingly collect data from anyone under 18. Any such submissions are deleted immediately.

11 EU representative

Before collecting data from EU residents, we will appoint an EU representative.

12 Changes to this policy

The latest version is always published here with its revision date. This is version 1.3, last revised 8th May 2025