Skip to content
SKYALIA

Pre-launch draft

This document is a working draft written to describe how Skyalia is actually built. It has not yet been reviewed by a solicitor and is not legally binding wording. It must be replaced with counsel-approved text before the platform takes a real booking.

Legal

Privacy

Mando Systems Ltd is the data controller for personal data processed through Skyalia.

What we collect

  • Account data — name, email, and a password hash if you did not sign in with Google.
  • Booking data — traveller names, dates of birth and, where a supplier legally requires it, passport details.
  • Search data — the queries you run, so results can be cached and the service improved.
  • Payment metadata — Stripe identifiers and status. Card numbers never reach us.

Why

To arrange and fulfil the bookings you ask for (performance of a contract), to meet legal and supplier obligations, and — only with your consent — to measure how the site is used.

Who we share it with

Only the suppliers needed to fulfil the specific booking, plus our processors: Stripe (payments), our email provider, and our hosting and infrastructure providers. Suppliers outside the UK/EEA receive data under appropriate safeguards.

How it is protected

Passport and date-of-birth fields are encrypted at rest. Secrets and supplier credentials are held server-side only. Personal data is never written to application logs.

How long we keep it

Booking and financial records for six years, as UK tax law requires. Search history for twelve months. Account data until you delete your account.

Your rights

You can access, correct, export or delete your data from your account, or by writing to support@skyalia.com. You can also complain to the Information Commissioner’s Office.