Privacy Policy

Last updated: 2026-09-30

1. Who we are

RARE AIR (IOM) LTD (“RARE AIR”, “we”, “us”) is an aircraft buyer’s agent and aviation consultancy based in the Isle of Man. This Privacy Policy explains how we collect, use, disclose and protect personal data when you use our website at rare-air.co.uk (the “Site”) or otherwise interact with us.

Our registered address:
34 Hope Street, Third Floor,
Douglas, IM1 1AP,
Isle of Man.

For privacy enquiries: enquiries@rare-aviation.com

2. What data we collect

  • Contact form data: name, email address, and the message you submit when you use the enquiry form on the Site.
  • Authentication data (optional): when you log in via Auth0 (our identity provider), we receive and store your name, email address, profile picture URL, and the stable Auth0 subject identifier (“sub”). A local user profile is created/updated on our systems.
  • Identity and company verification: if you ask us to verify you, we store the legal name and date of birth you submit, and, for a company, the company name, country of incorporation, optional registration number, and the incorporation and good-standing PDFs you upload. The identity document images and liveness check are collected by Didit on their hosted page, not stored by us as scans. We store Didit’s session id, status, and a short decision summary.
  • Technical / log data: IP address, user agent, timestamps, and request details in standard web server and application logs. These logs are used for security, debugging, and abuse prevention.
  • First-party page measurements: for public pages we keep a short operational record of the page path (identifiers such as record ids are replaced with a placeholder), HTTP status, the referring website’s host name, campaign tags on the link you followed (utm_source, utm_medium, utm_campaign, utm_content), country and region codes added by our content-delivery network, whether the browser looked like a desktop, a phone, or an automated visitor, and whether you were signed in. We also store a code that changes every day, derived from the connection and the browser family, so we can count visitors within a single day. That code cannot be joined from one day to the next. These records do not include your IP address, account id, raw user agent, or any other query-string values. Staff use of the Site is not included. We use the records to see which public pages and campaigns are used. They are not used for advertising, and they are not a profile of your account.
  • Bot-protection signals (contact form only): when you use the enquiry form, we apply automated measures to distinguish genuine submissions from spam. This includes a hidden honeypot field (invisible to users) and Cloudflare Turnstile, which may process connection and browser signals such as IP address, user-agent, and site origin to verify that the submission is not automated abuse.
  • Staff / internal data: if you are a staff user, we may store and process additional information related to aircraft models and spec sheets (private documents) for the purpose of serving our clients.
  • Lease marketing appointments: when a principal appoints us to market an aircraft for wet lease (ACMI) or dry lease, we store the principal’s name and email, the appointment terms, and a staff address book of operator legal names, contact names, and email addresses. We email those operators an anonymised aircraft brief. That brief does not include the principal’s name, the registration, or serial numbers. We keep a marketing log. Reports to the principal, and the principal’s own page, show each approach by an anonymous label, the offering, the outcome, and a note written for the principal. They do not include the operator’s legal name, contact name, or email address.
  • Electronic signatures: when we send a document for signature, including a lease-marketing mandate, we send the signer’s name and email address to our e-signature provider with the document.

3. How we use your data and legal basis

We use the data for the following purposes:

  • To respond to your enquiries and provide our buyer’s agent and consultancy services (legitimate interest and/or contract).
  • To market an aircraft for wet lease or dry lease under a written appointment, including anonymised briefs to operators and anonymised activity reports to the principal (contract).
  • To authenticate users and enable secure access to staff features (consent via login + contract).
  • To operate, secure, and improve the Site, including detecting and blocking spam or abusive contact-form submissions (legitimate interest).
  • To measure use of the public Site (pages, campaigns, and countries) with the first-party records described above (legitimate interest).
  • To comply with legal obligations, including identity and company verification where we ask Didit to carry out a check after our staff have reviewed your submission.

The contact form is the primary way members of the public interact with us. By submitting the form you are providing your personal data to us so that we may respond to your enquiry.

4. Sharing and third parties

We do not sell your personal data.

We share data with trusted service providers only where necessary:

  • Auth0 – identity and single sign-on (OIDC). Auth0 processes authentication data on our behalf.
  • Brevo (Sendinblue) – transactional email, including contact-form messages, anonymised aircraft briefs to operators, and lease-marketing reports to principals.
  • SignWell – electronic signatures. We send the signer’s name and email address, and the document, so the hosted signing flow can run. For a lease-marketing mandate that signer is the named principal.
  • AWS (Elastic Beanstalk, RDS Postgres, S3, CloudFront) – hosting, database, and secure file storage. All production data stores for user data and media are private to our VPC or protected by signed URLs; no public buckets expose personal data.
  • Cloudflare Turnstile – bot detection on public contact forms. Turnstile processes connection and browser signals on our behalf to verify submissions and block automated abuse. For enquiries about Turnstile data processed for this purpose, contact us first; see also Cloudflare’s Turnstile Privacy Addendum.
  • Didit – identity verification and business verification after our staff start a check. Didit processes the hosted identity check (including liveness), and for a company the registry lookup, sanctions screening, and related session data. We send Didit the details you submitted so the hosted flow can be pre-filled.

We may also disclose data if required by law, to protect our rights, or in connection with a business transfer.

5. Data retention

We keep personal data only for as long as necessary for the purposes described above, or to meet legal, accounting, or reporting requirements. Contact enquiry records are typically retained for the duration of the business relationship plus a reasonable period thereafter. Authentication profiles are retained while the account is active and for a period after last activity for security and audit purposes. First-party page-measurement records are deleted after 90 days. Operator contact details and lease-marketing logs are kept for the life of the appointment and for as long as we need them to evidence that work afterwards.

6. Your rights

Under the Isle of Man Data Protection Act (and equivalent standards), you have rights including: access to your personal data, rectification, erasure (in certain circumstances), restriction of processing, data portability, and the right to object to certain processing.

To exercise these rights, or to withdraw consent where consent is the legal basis, please contact us at enquiries@rare-aviation.com. We will respond in accordance with applicable law.

7. Cookies and similar technologies

The Site uses essential cookies and similar technologies for session management, CSRF protection, and (via Auth0) authentication and single sign-on across related sites in the same Auth0 tenant. Public contact forms also load Cloudflare Turnstile, which may set strictly necessary third-party cookies or use similar browser storage solely to detect and block bots. These technologies are necessary for the Site to function securely. We do not use advertising or non-essential tracking cookies. The page measurements described above are recorded on our servers. They do not set a tracking cookie, and we do not use Google Analytics, advertising pixels, or other third-party analytics. You can control cookies through your browser settings; disabling essential cookies may prevent login, contact-form submission, and certain other features from working.

8. Security

We implement appropriate technical and organisational measures to protect personal data. Production databases are not publicly accessible. Private media (such as aircraft specification documents) is stored in access-controlled storage and served only via time-limited, cryptographically signed URLs. Nevertheless, no system is 100% secure; please contact us if you have any concerns.

9. International transfers

Some of our service providers (Auth0, Brevo, AWS, Cloudflare, Didit) may process data outside the Isle of Man / UK / EEA. Where this occurs we rely on appropriate safeguards (such as Standard Contractual Clauses or equivalent measures) or the necessity of the transfer for the performance of our services to you.

10. Changes to this policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top indicates the current version. Material changes will be highlighted on the Site or communicated to registered users where appropriate.


This policy is provided for the RARE AIR website and initial contact purposes. Specific engagements for aircraft acquisition services are governed by separate written agreements.