Internal Policy

Data Confidentiality Policy

Last updated: April 2026

Commitment to Confidentiality

Data processed through Every Sky System relates to employee and traveller journeys and is considered sensitive. We are fully committed to maintaining the confidentiality of this data. No party may access it outside the scope of their authorised role.


Confidentiality Principles

Least Privilege Access

Each user is granted access only to the data required to perform their specific duties. No user can view data outside the scope of their assigned role.

No External Disclosure

Transferring any system data to unauthorised external parties is strictly prohibited, whether directly or via electronic or physical media.

Traveller Data Protection

Passport details and personal documents are treated with the highest level of confidentiality and may only be accessed by staff with direct authorisation.

Full Audit Trail

All data access and modification operations are recorded in an immutable audit log, ensuring complete accountability.

Data Lifecycle Management

Data retention periods are defined per organisational policy. Data is anonymised or deleted once its purpose has been fulfilled.


Technical Safeguards


User Obligations

All authorised users are required to:


Reporting a Data Breach

If you suspect a security breach or data leak, you must report it immediately via:

Breach reports will be treated as urgent and addressed within 24 hours of receipt.


Legal Liability

Any violation of this policy may subject the offending party to administrative and legal accountability under applicable laws and regulations. The organisation reserves the right to pursue all necessary legal action in cases of serious breach.