/
SkyRay Travel
Travel›
Destinations
About us
Contact

Privacy policy

Last updated: 28 September 2026

This policy explains what personal data we collect when you use skyraytravel.com, send us an enquiry, book a trip or subscribe to our newsletter; why we use it; who we share it with; and what your rights are. It is written for travellers in the United Kingdom, Spain and the rest of Europe, and covers both the UK GDPR and the EU General Data Protection Regulation (GDPR), together with Spain's Organic Law 3/2018 (LOPDGDD).

1. Who is responsible for your data

Two companies work together under the SkyRay Travel name. Each one is responsible — the "controller" — for its own part of the work. They are separate controllers, not joint controllers:

SKYRAY TRAVEL S.L. is responsible for everything to do with your trip: enquiries and quotes, bookings, assistance before and during travel, complaints, and the messages we exchange with you by email, phone or WhatsApp. This includes trade enquiries from travel companies.

  • CIF B22670764 — Calle Laureà Miró 230, 08950 Esplugues de Llobregat (Barcelona), Spain

SKY RAY LTD is responsible for running the website: delivering and securing the site, visitor statistics, what the site stores in your browser, and the newsletter.

  • Registered in England and Wales, company number 16196679 — 51 Shropshire Street, Market Drayton, England, TF9 3DA, United Kingdom

When you send an enquiry through a form on the website, the website (run by SKY RAY LTD) receives and stores it on behalf of SKYRAY TRAVEL S.L., which decides how it is used. For that data SKY RAY LTD acts only as a service provider (processor) to SKYRAY TRAVEL S.L.

Contact for both companies on any privacy matter: privacy@skyraytravel.com. Neither company has appointed a data protection officer; your message will be handled by the person responsible for data protection at the relevant company.

2. What we collect and why

2.1 Enquiries (holidays, hotels, tours, activities, packages, boats, car hire)

Controller: SKYRAY TRAVEL S.L.

What: your name, email address, phone number and message; the trip details you enter (the product you are asking about, dates, number of adults and children, departure airport, boat duration, number of passengers, whether you need a skipper, extras); the price and currency shown to you when you sent the form; and the language you used.

Why: to answer your enquiry, check availability with our suppliers and send you a quote.

Legal basis: steps taken at your request before entering into a contract (UK GDPR / GDPR art. 6(1)(b)).

How long: 2 years after our last contact if no booking is made.

2.2 Trade enquiries (travel agencies, tour operators, suppliers)

Controller: SKYRAY TRAVEL S.L.

What: your name, email, phone, company name and type, country, website and message.

Why: to reply to you and, if we agree to work together, to manage the business relationship.

Legal basis: our legitimate interest in developing business relationships (art. 6(1)(f)), or steps before a contract (art. 6(1)(b)).

How long: 2 years after our last contact, or for the length of the business relationship plus the periods required by law.

2.3 Bookings

Controller: SKYRAY TRAVEL S.L.

What: the details of everyone travelling that we need to book the services (full names, dates of birth, nationality, passport or ID details where a supplier or authority requires them, contact details), payment records, and any special requests you give us — for example dietary needs, reduced mobility or medical information.

Why: to make and manage your booking, send your travel documents, assist you before and during the trip, and handle changes, cancellations, complaints and claims.

Legal basis: performance of our contract with you (art. 6(1)(b)); compliance with legal obligations such as accounting, tax and travel-industry rules (art. 6(1)(c)). If you give us health information or other special-category data so that a supplier can meet your needs, we use it only with your explicit consent (art. 9(2)(a)) and pass it only to the suppliers who need it.

How long: for the duration of the booking and then 6 years after the end of the trip, to meet accounting and tax obligations and to deal with possible claims.

If you book for other people, please make sure they know about this policy.

2.4 Flight bookings on vuelos.skyraytravel.com

Controller: SKYRAY TRAVEL S.L.

The flight search and booking pages are run for us by our technology provider, Nexit, which processes the data you enter there to make your flight booking. Passenger details are shared with the airlines and with the global distribution systems (GDS) used to issue tickets, and airlines may pass passenger data to border authorities as the law requires. Airlines process your data under their own privacy policies. The flight engine also uses its own cookies — see our Cookie policy.

2.5 Newsletter

Controller: SKY RAY LTD

What: your email address, language, where you signed up, the consent wording you agreed to and the date and time you gave and confirmed it.

Why: to send you travel offers and news from SkyRay Travel by email.

Legal basis: your consent (art. 6(1)(a); UK Privacy and Electronic Communications Regulations; Spanish LSSI art. 21). We use double opt-in: you are only added after you click the link in our confirmation email. You can unsubscribe at any time with the link in every email or by writing to privacy@skyraytravel.com. Withdrawing consent does not affect emails already sent.

How long: until you unsubscribe. After that we keep only your email address and the unsubscribe date, so that we never email you again and can show that we had your consent. Sign-ups that are never confirmed are not used and are deleted within 3 months.

2.6 Emails, phone calls and WhatsApp

Controller: SKYRAY TRAVEL S.L.

If you contact us directly, we use your contact details and the content of your message to reply. Legal basis: steps before a contract or the contract itself (art. 6(1)(b)), or our legitimate interest in answering your questions (art. 6(1)(f)). Kept as for enquiries (2.1) or bookings (2.3). If you contact us on WhatsApp, WhatsApp (Meta) also processes your data under its own terms and privacy policy.

2.7 Using the website

Controller: SKY RAY LTD

What: when you visit the site, our hosting provider and Cloudflare (our network and security provider) process technical data such as your IP address, browser type, the pages requested and the time of the request.

Why: to deliver the website, keep it secure, prevent abuse and fix errors. Cloudflare also tells the website which country your connection comes from; we use that only to pre-select a currency (GBP or EUR) and do not store it.

Legal basis: our legitimate interest in running a secure, working website (art. 6(1)(f)).

How long: technical logs are kept only as long as needed for security and troubleshooting, and then deleted.

Statistics: we use Cloudflare Web Analytics to count visits and measure page speed. It does not use cookies or store anything on your device, and gives us aggregated figures only.

What the site stores in your browser is explained in our Cookie policy.

3. Who we share your data with

We share only what each recipient needs:

  • Travel suppliers who provide the services you book: hotels and other accommodation, tour and activity operators, boat operators, car-hire companies, airlines, and local agents. Many are outside the UK and the European Economic Area — see section 4.
  • Between our two companies: SKY RAY LTD passes website enquiries to SKYRAY TRAVEL S.L. and stores them for it (section 1).
  • Service providers who act on our instructions (processors), under a contract:
    • our website and database hosting provider;
    • Cloudflare, Inc. — domain name service, content delivery, security, web statistics and image storage;
    • Resend — sending our emails (enquiry confirmations and the newsletter);
    • our email (mailbox) provider;
    • Nexit — the flight booking engine;
    • our bank and accounting advisers, for payments and bookkeeping.
  • The ATOL partner that provides flight-inclusive trips for UK customers (see our Booking terms), for those bookings.
  • Public authorities, courts and professional advisers, when the law requires it or to establish, exercise or defend legal claims.

We do not sell your personal data.

4. International transfers

To book services abroad we must send traveller data to suppliers in the destination country, which may be outside the UK and the EEA. These transfers are necessary to perform your contract (UK GDPR / GDPR art. 49(1)(b)).

Data also moves between the UK and Spain, because our two companies are in those countries; the UK and the EU recognise each other's data protection as adequate.

Some of our service providers are based in, or may access data from, other countries (for example the United States). Where that happens we rely on adequacy regulations and decisions (including the EU–US Data Privacy Framework and its UK Extension, where the provider is certified) or on standard contractual clauses with the UK International Data Transfer Addendum. You can ask for a copy of the relevant safeguards at privacy@skyraytravel.com.

5. Your rights

You have the right to:

  • access the personal data we hold about you;
  • rectify inaccurate data;
  • erase your data in certain circumstances;
  • restrict how we use your data in certain circumstances;
  • object to our use of your data where we rely on legitimate interests, and at any time to direct marketing;
  • data portability — receive the data you gave us in a common electronic format;
  • withdraw your consent at any time, where we rely on consent.

To exercise any of these rights, write to privacy@skyraytravel.com — you do not need to know which company holds the data; we will deal with it. We may ask you to confirm your identity. We reply within one month (this can be extended in complex cases, and we will tell you if so).

We do not make decisions about you based solely on automated processing.

6. Complaints to a data protection authority

If you are unhappy with how we handle your data, please tell us first. You also have the right to complain to a supervisory authority:

  • United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk/make-a-complaint — 0303 123 1113 — Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
  • Spain: Agencia Española de Protección de Datos (AEPD) — www.aepd.es — C/ Jorge Juan 6, 28001 Madrid.
  • If you live in another EU country, you can also complain to the authority there.

7. Children

Our website and bookings are intended for adults. We only process children's data when an adult booking a trip gives it to us for a child who is travelling.

8. Security

We use appropriate technical and organisational measures to protect your data, including encrypted connections (HTTPS), access controls on our systems and contracts with our service providers.

9. Changes

We may update this policy. The date at the top shows when it last changed. If we make important changes, we will tell newsletter subscribers and customers with current bookings.

Your travel journey starts here

Sign up and we'll send you our best trips and offers