Privacy notice
Global Concierge Solutions Ltd · company 516135407 · reviewed 10 August 2026
01Who holds your data
Global Concierge Solutions Ltd (company number 516135407), trading as GCS, registered in Israel, is the controller of the personal data described here. There is one desk and one route to it: +972 50-666-6444 by telephone, Eran.globalcs@gmail.com by email. Privacy questions, access requests and complaints go to the same place and are handled by Eran, who is also the named accessibility coordinator. We have not appointed a statutory data protection officer: the appointment duty under the Protection of Privacy Law applies to data brokers, to large-scale monitoring operations, and to businesses whose core activity is high-volume processing of specially sensitive data. This desk is none of those. The privacy contact above answers in the same role.
02What this website collects
Nothing is asked for on this website. There is no form, no newsletter signup, no account, no chat widget, no analytics, no advertising pixel and no third-party script. The site makes no requests to any domain other than its own - fonts and client marks are served from this site, not from a font host or a logo service. There is no profiling and no automated decision-making anywhere on it.
03Cookies and local storage
This site sets no cookies - not one, not even a so-called necessary one, and no analytics or advertising tag of any kind. You are still asked: on a first visit a consent panel offers Accept all, Reject all and Manage preferences, with refusal exactly as easy as acceptance and nothing pre-ticked. Closing it without choosing counts as a refusal, Global Privacy Control and Do Not Track are read as a refusal, and “Cookie settings” in the footer reopens the panel so consent can be withdrawn as easily as it was given. Your decision is recorded on your own device and never sent to us. Anything non-essential added in future can only load through that consent gate. The full table, category by category, is on the cookies and storage page; in summary, the site can write:
- gcs.a11y-text
- Your chosen text size. Written when you pick a size in the accessibility panel. Kept until you reset the panel or clear site data.
- gcs.a11y-contrast
- Whether high contrast is on. The site ships with it on; this records a choice to change that. Written when you use the switch, kept until reset or site data is cleared.
- gcs.a11y-underline
- Whether links are underlined. Written when you use the switch, kept until reset or site data is cleared.
- gcs.motion-paused
- Whether motion is paused. Written when you use the switch, kept until reset or site data is cleared.
- gcs.consent
- Your decision on the consent panel, with the date and the version of the notice it answered. Strictly necessary: it is what stops you being asked again and what the gate reads. Kept until you clear site data.
- tsr-scroll-restoration (session)
- Where you had scrolled to, so the back button returns you to the same place. Held in per-tab session storage and discarded when you close the tab.
- How to remove them
- Press “Withdraw and delete” in the cookie settings panel, “Reset all” in the accessibility panel, or clear site data for this domain in your browser. Nothing breaks: the site returns to its defaults.
04What the desk collects when you engage it
Data reaches us when you call, message or email - never through this website. What a file holds depends on what the work requires:
- Identity and contact
- Name, telephone number, email address, and the company or mission you are travelling for.
- Movement
- Flight numbers, dates, arrival and departure times, addresses, vehicle and route details, hotel and restaurant bookings.
- Travel identity
- Passport number, date of birth and nationality, where a border, charter operator, hotel or permit demands them. Requested on a secure channel, used for that booking, and removed once it closes.
- Preferences
- Seat, room, dietary and language notes that a booking cannot be made without.
- Health and accessibility
- Mobility requirements, medical escort or oxygen needs, medication cold-chain, service animal and interpreter requirements - only where you have asked us to arrange them.
- Third parties on your file
- Names and contact details of the people travelling with you, or the staff a company is sending. Where a company gives us its people's details, that company is responsible for having told them; we will provide this notice to anyone who asks.
- Billing
- Invoicing details and payment references. Card numbers are not held by us; payment is taken by the provider or the supplier.
05Specially sensitive data
Health, medical logistics, and travel identity documents fall into the category the Protection of Privacy Law treats as specially sensitive. They are collected only when the arrangement cannot be made without them, held only for as long as the movement is open, shared only with the specific operator performing that leg, and deleted on closure unless a law requires the record to stand. Because ordinary email passes through a mail provider, we ask for these details by telephone, or we give you the operator's own secure channel and you send them there. If a detail does arrive by email we act on it, take it out of the thread, and tell you which route to use next time. You may also keep a document yourself and hand it to the operator at the door: say so and we route it that way.
06Why we hold it, and on what basis
Two legal frames apply. In Israel, the Protection of Privacy Law, 5741-1981, as amended. Where you are in the EU or the UK, the GDPR and UK GDPR apply to the same processing, and the basis is stated alongside it.
- Arranging what you asked for
- Performance of the engagement between us - GDPR Art. 6(1)(b). Given knowingly and voluntarily under Israeli law.
- Health, medical and accessibility arrangements
- Your explicit consent - GDPR Art. 9(2)(a). Asked for in words, in the message where you request the arrangement.
- Crisis and safety work
- Performance of the engagement, and where a life or physical safety is at stake, vital interests - GDPR Art. 6(1)(d).
- Invoices and accounting records
- Legal obligation under Israeli tax law - GDPR Art. 6(1)(c).
- Keeping a returning client's file
- Our legitimate interest in not making you repeat yourself - GDPR Art. 6(1)(f). Objectable at any time, with no effect on service.
07Whether you have to give it
Giving us any of this is voluntary. There is no legal duty to hand it over and no consequence beyond the practical one: a detail withheld is an arrangement we cannot make. Without a flight number we cannot meet an aircraft; without a passport number a border unit will not clear a fast-track; without a medical requirement stated we cannot brief an escort. We will tell you plainly at the time which part of a request is blocked and offer whatever can still be done. Nothing is refused because you declined marketing, and we hold no data whose only purpose is marketing.
08Who else sees it
Only the people performing the work, and the infrastructure the message travels on:
- The GCS staff assigned to your file, and nobody else on the desk.
- The specific supplier a booking requires - a driver, a hotel, an airline, a charter operator, a border or terminal unit, a medical escort, an interpreter - and only the fields that supplier needs to perform.
- The providers that carry our own communications, acting as processors of whatever you send through them: our mail provider (Google) holds the content of email threads, and our telephone carrier holds call and message metadata. We choose which channel a sensitive detail travels on for exactly this reason, and a request made by telephone reaches no messaging provider at all.
- Our accountants and, where a dispute arises, our lawyers, both under professional confidentiality.
- A public authority where a law, a court order or a border requirement compels it. We will tell you when this happens unless we are forbidden to.
09What we never do with it
It is not sold, rented, brokered or traded. It is not used to build a marketing list, and we run no direct-marketing database. We send no promotional email or SMS messages, which is why you have never been asked to opt in to any; if that ever changes it will start with an unticked box and a request in writing, as Israeli communications law requires. We publish no client names without written permission. Nothing about your movements is discussed outside the file.
10Where it goes
The desk is in Israel and the file sits in Israel. Two things leave it. An arrangement abroad necessarily involves the operator in that country: a booking in Paris is transmitted to a supplier in France, one in Singapore to a supplier in Singapore, limited to what that leg requires. And the communication providers named above store message content and metadata on infrastructure outside Israel, including in the United States, under their own terms. Both transfers are made in order to perform the engagement you asked for - GDPR Art. 49(1)(b), reading with the adequacy framework applicable to Israel. We do not publish a claim about the current standing of any adequacy decision. If you need a contractual assurance on transfers, ask and we will sign the appropriate clauses; if you would rather nothing about your file crossed a mail provider, the desk works by telephone.
11How long it stays
- Movement details
- Deleted once the movement is closed and any dispute window has passed.
- Travel identity documents and numbers
- Deleted on closure of the booking that required them, at the latest.
- Health and accessibility notes
- Held only while the arrangement is live, unless you ask us to keep them so a returning trip does not start from nothing.
- Client file and preferences
- Duration of travel plus 24 months, then deleted.
- Accounting records
- The period Israeli tax law requires, and no longer.
12Your rights, and what we do with them
You may ask for a copy of what we hold, where it came from and who has received it; ask for a correction; ask for deletion; ask us to stop relying on legitimate interest; and withdraw a consent you gave. Write or call the desk. The statutory window is 30 days, and in practice we answer inside a week; if we refuse any part of a request we say which part and why, in writing. Asking costs nothing in the ordinary case. If some of the data has to stay - an invoice, for instance - we tell you which record and under which obligation.
13Security, and what happens if it fails
Access is limited to the staff on your file. Sensitive fields are taken on a secure channel rather than in an open email thread and are removed when the booking closes. Devices are locked and encrypted. This website is served over HTTPS only, with a content security policy that allows nothing to load from another domain, framing of the site blocked, and camera, microphone, location and payment access denied at the browser level. If a security incident affects your data we investigate immediately, notify the Privacy Protection Authority within the statutory timeframe - late reporting is itself an offence the Authority now fines - and tell you directly what was involved, what we have done and what you should do. We will not wait to be asked.
14Reporting a vulnerability
If you find a security or privacy weakness in this site, tell us rather than anyone else: Eran.globalcs@gmail.com, or +972 50-666-6444. The same contact is published in machine-readable form at /.well-known/security.txt. We answer within two working days, we do not threaten researchers who act in good faith and do not access other people's data, and we will tell you what we fixed.
15If you are in the EU or the UK
GCS is established in Israel and has no branch, office or agent in the EU or the UK. Where we arrange a movement for someone in those territories, the GDPR or UK GDPR applies to that processing alongside Israeli law, and the bases above are stated for it. We have not appointed an Art. 27 representative in the Union or the UK: the desk does not monitor behaviour and does not offer this service to the public of any member state at scale - work comes to it by referral. We keep that assessment under review and will appoint a representative, and say so here, if the pattern of work changes. Nothing in this paragraph limits the rights below or where you can bring a complaint.
16Complaints
Start with the desk: +972 50-666-6444 or Eran.globalcs@gmail.com. If our answer does not satisfy you, you may complain to the Privacy Protection Authority at the Israeli Ministry of Justice. If you are in the EU or the UK, you may instead complain to the supervisory authority of your country of residence, and, where the claim concerns a breach of data-protection duties, Israeli law now allows a claim for statutory damages without proof of harm. Complaining to a regulator does not stop us continuing to work on your arrangement.
17Changes
This notice was last reviewed on 10 August 2026. If it changes materially we date the new version here and, where we hold your contact details and the change affects you, we write to tell you before it takes effect.