SVS Northstar Enterprises, London
+44 7936 862815Send a requirement
Menu

PRIVACY NOTICE

Use what is needed. Protect what is entrusted.

Cross-border work moves information as well as people and instructions. This notice explains the boundaries around that movement.

Effective 13 September 2026

01

Who is responsible

SVS Northstar Enterprises Ltd is responsible for personal information it controls. We are registered in England and Wales under company number 17451167. Our registered office is 128 City Road, London, EC1V 2NX, United Kingdom. Privacy questions and electronic complaints can be sent to operations@svsnorthstar.com.

Where a business client decides why and how traveller or employee information is used, that client may be the controller and Northstar may act on its instructions. The assignment documents should clarify the relationship where material.

SVS Northstar Enterprises Ltd is incorporated in England and Wales. Its London registered office is a statutory address and is not a staffed operating office. Authorised day-to-day operational access may occur from Bangladesh. The UK company remains the contracting entity unless the Service Confirmation expressly states otherwise.

02

Information we may collect

We do not ask for passwords, one-time codes or complete card details through our website, ordinary email or messaging channels. Passport, medical or other sensitive information is collected only where genuinely necessary and with an appropriate basis.

  • Identity and contact details for buyers, travellers, visitors and operational contacts.
  • Itinerary, location, timing, baggage, language, accessibility and service requirements.
  • Company, quotation, approval, confirmation, payment-status and billing records.
  • Messages, call attempts, instructions, provider responses, incident evidence and completion records.
  • Technical security information generated when the website or our systems are used.

03

Why we use information

We use information to answer enquiries, prepare and perform contracts, coordinate providers, protect safety, manage payments, prevent fraud, keep evidence, resolve incidents, meet legal duties and improve controlled operations.

The applicable legal basis may be contract, steps requested before a contract, legitimate interests, legal obligation, vital interests or consent. We do not use consent where another basis is the correct one.

04

Where information comes from

Information may come from you, the person booking, an employer or corporate client, a traveller or representative, an approved provider, a public flight or company source, a payment provider or a lawful fraud and compliance source.

05

Who receives information

We share only what is reasonably needed with relevant local providers, professional advisers, technology and communications providers, payment providers, insurers where applicable, and public authorities where lawfully required.

We do not sell personal information. A provider must not use a partner’s client or traveller information for its own marketing without a lawful basis and authority.

06

International access and transfers

Before personal information is made accessible to a separate overseas recipient, Northstar identifies the recipient, country, purpose, legal role and minimum information required. Where UK restricted-transfer rules apply, the transfer will not proceed until an applicable lawful mechanism and risk assessment are in place.

Depending on the recipient and country, this may involve UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum or another lawful route. Northstar does not claim that one mechanism covers every provider or assignment. Tell us before booking if your organisation has specific transfer restrictions.

07

Website and contact channels

The website brief builder prepares text in the visitor’s browser. It does not send information to Northstar or save it to a Northstar database. Information reaches Northstar only if the visitor chooses to send it through an email application or WhatsApp. Those services apply their own privacy terms.

Email and WhatsApp are discovery channels for non-sensitive information. Do not use them to send passports, identity documents, medical records, complete payment-card details, passwords, one-time codes or other sensitive documents. Before a confirmed assignment needs higher-risk information, Northstar and the client must agree an appropriate secure route.

Passenger names, telephone numbers and itineraries are personal information. Supply them only after the requester’s authority, purpose, recipients and required scope have been recorded.

08

Retention and deletion

We keep information only as long as needed for the relevant purpose, legal duty, accounting record, incident or claim. Routine operational details are reviewed for deletion or de-identification after the assignment; identity documents and sensitive accessibility or health details are not retained as routine marketing or general account data.

Financial and tax records may need to be kept for six years or longer where law or an active claim requires it. A minimal suppression record may be retained to respect a marketing opt-out.

09

Your rights and marketing choices

Depending on the circumstances, you may ask for access, correction, deletion, restriction, portability or human review, object to certain processing, or withdraw consent. Rights can be subject to lawful limits. We normally respond to a valid rights request within one calendar month.

You may object to direct marketing at any time. Service and safety messages about an active assignment are not marketing.

10

Security, incidents and complaints

We use proportionate safeguards, including access control, device and account protection, recipient checks and operational record controls. No system is completely secure.

Send a data-protection complaint electronically to operations@svsnorthstar.com. We will acknowledge it within 30 days, make appropriate enquiries, keep you informed and provide an outcome without undue delay. You may also complain to the UK Information Commissioner at ico.org.uk/make-a-complaint.

11

Website cookies and changes

The current Northstar website does not intentionally use advertising cookies. Essential technical storage may be used where required for security or functionality. If analytics, advertising or new embedded services are introduced, this notice and any required consent controls will be updated before use.

We may update this notice when our services, systems or legal duties change. The current effective date will remain visible on this page.

BEFORE ANY PAID WORK

Let us define the scope, decision points and evidence together.

Start a controlled brief