Legal
Privacy Policy
What personal data we collect, why we collect it, who processes it and what rights you have.
This legal document is published in English, which is the authoritative version.
Version: 3.0 (production-ready)
Effective date: [EFFECTIVE DATE]
Controller: [LEGAL ENTITY NAME], registered at [REGISTERED ADDRESS] under company registration number [COMPANY REGISTRATION NUMBER], trading as [TRADING NAME] ("AeroTech Academy", "we", "us").
Privacy contact: [PRIVACY EMAIL]
Support contact: [SUPPORT EMAIL]
Related documents: Terms and Conditions · Refund Policy · Cookie Policy
This Privacy Policy explains how we collect and use personal data when you use our website and application (the Platform). Capitalised terms not defined here have the meaning given in the Terms and Conditions.
1. How to contact us
| Purpose | Contact |
|---|---|
| Privacy enquiries and rights requests | [PRIVACY EMAIL] |
| General support | [SUPPORT EMAIL] |
| Security incidents | [PRIVACY EMAIL] |
| EU/UK representative (Article 27 GDPR / UK GDPR), where required | [EU/UK REPRESENTATIVE] |
We do not have, and are not required to have, a Data Protection Officer at our current scale. Privacy matters are handled by the contact above.
2. Scope
2.1 This Policy covers personal data we process as controller — that is, where we decide why and how it is processed.
2.2 It does not cover:
- (a) Paddle's processing of your payment, tax and invoicing data. Paddle is the merchant of record and an independent controller for the sale. See section 9.2 and Paddle's privacy policy at https://www.paddle.com/legal/privacy.
- (b) An Enterprise Customer's own use of learning and progress data about its Authorised Users, once we have disclosed it to that Customer. Your employer or training organisation is an independent controller for that use. See section 12.
- (c) Third-party websites we link to.
3. Summary of processing
| What we process | Why | Legal basis | Retention |
|---|---|---|---|
| Account data: name, email, password (hashed) | Create and operate your Account | Contract, Art. 6(1)(b) | Account life; indefinitely thereafter as no deletion mechanism currently exists — see section 11 |
| Authentication data (managed by Supabase) | Sign you in securely | Contract; legitimate interests (security) | Session-based; until sign-out or token expiry |
| Terms-acceptance record (version, timestamp, IP address, 18+ confirmation) | Evidence that you accepted our Terms | Legal obligation; legitimate interests | Indefinitely, as proof of acceptance |
Device identifier (localStorage), user-agent and sign-in country | Enforce the 4-device limit; detect account sharing | Legitimate interests, Art. 6(1)(f) | Indefinitely while the Account is active |
| Learning progress and exam attempts | Deliver the Services; show your progress and results | Contract | Account life; indefinitely thereafter, see section 11 |
| Lesson feedback and support messages | Improve content; answer your queries | Contract; legitimate interests | Indefinitely |
| AI Assistant prompts | Provide the AI Assistant feature | Contract; legitimate interests | Not persisted by us; transient at the AI provider, see section 9.1 |
| Order and entitlement records (from Paddle) | Grant and validate access; accounting | Contract; legal obligation, Art. 6(1)(c) | Typically 7 years for tax/accounting purposes |
| Enterprise seat records (name, work email, seat status) | Administer company licences | Contract; legitimate interests | Term of the licence, then as above |
| First-party aggregate usage data | Understand and improve the Platform | Legitimate interests | Retained in aggregated/internal form; not sold or shared with third parties |
We do not currently operate a data-deletion or self-service export workflow — see section 11 and section 13.
4. Personal data we collect
4.1 Data you give us
- Account data: name, email address and password (stored only as a salted hash by our authentication provider, Supabase).
- AI Assistant prompts: questions and text you submit to the Aviation AI Assistant.
- Lesson feedback and error reports: ratings, comments and content-error reports you submit on lessons.
- Support messages: correspondence you send to [SUPPORT EMAIL] or [PRIVACY EMAIL].
We do not collect a profile photo, a country field, or a target-licence-pathway field. We do not ask for and do not want special category data such as health, biometric or religious data, government identity documents, or aviation employment records such as maintenance logs or licence documents. Please do not submit them.
4.2 Data generated by your use of the Platform
- Learning progress data: courses and lessons started and completed, video/lesson progress, time on task.
- Assessment data: practice and simulation exam attempts, answers given, scores, pass/fail outcomes and attempt history.
- Entitlement data: which products you hold, purchase source, and access status.
- Terms-acceptance record: the version of the Terms you accepted, the timestamp, your IP address and your 18+ confirmation.
- Certificates: where issued, your name, course title, score and a publicly verifiable certificate code.
4.3 Device, technical and security data
- A device identifier that we generate and store in your browser's
localStorageto operate the 4-device limit described in the Terms, together with a coarse device label, your browser's user-agent string, and the country associated with your sign-in IP address (we do not use precise geolocation). - Application and server logs, error reports and diagnostics.
- Security signals such as failed sign-in attempts and the number and diversity of registered devices.
4.4 Purchase data we receive from Paddle
Paddle, our Merchant of Record, processes your payment. We never receive or store your full card number, security code or bank credentials. From Paddle we receive an order/transaction identifier, the product purchased, price, currency, purchase date, the email address used for the purchase, and refund/chargeback status.
4.5 Data from other sources
- Enterprise Customers: where your employer or training organisation buys a Seat for you, we receive your work email address (used to assign the seat) and, once you sign in, your name.
- Google (optional OAuth sign-in): if you choose to sign in with Google, we receive the identifiers and profile fields (such as name and email) that Google shares, subject to your permissions with Google.
5. Cookies and browser storage
5.1 We do not use third-party analytics, advertising or marketing cookies, and we do not run a cookie-consent banner because we do not use any non-essential cookies or trackers.
5.2 The storage we use is limited to strictly necessary, first-party items: an authentication session token, the device identifier described in section 4.3, and your interface preferences (such as language). Paddle sets its own cookies during checkout for fraud prevention and session handling. Full detail is in our Cookie Policy.
6. How we use your data
To provide the Services
- create and administer your Account and authenticate you;
- activate, deliver and validate access to courses, exams and the dictionary, including server-side entitlement checks;
- record and display your progress, scores and history;
- issue certificates of completion where applicable;
- administer Enterprise Seats.
To protect the Services and our content
- enforce the 4-device limit and detect account sharing;
- detect and investigate assessment misuse and unauthorised copying of content;
- maintain security and investigate incidents.
To support and communicate with you
- respond to enquiries, feedback and error reports;
- send essential service messages about your Account, purchases, security or changes to our Terms.
We do not operate a marketing email programme, mailing list, marketing-preference centre or suppression list. We do not send newsletters or promotional emails.
To improve and develop
- understand which content and features are used, using first-party aggregate reporting, to improve course design and the learning experience. We do not use any third-party analytics product.
To provide the AI Assistant and translation
- send your prompts to our AI Assistant so it can answer your questions;
- send lesson and interface text for translation so the Platform can be shown in other languages.
To comply with law
- meet accounting and tax record-keeping obligations;
- respond to lawful requests from authorities;
- establish, exercise or defend legal claims.
7. Legal bases
7.1 Performance of a contract — Article 6(1)(b)
Creating and running your Account, delivering the courses and features you purchased, recording your progress, providing support, and administering Enterprise Seats.
7.2 Legal obligation — Article 6(1)(c)
Retaining transaction records for accounting and tax purposes and responding to lawful requests.
7.3 Consent — Article 6(1)(a)
We do not currently rely on consent for any cookies, since we use no non-essential cookies. Where we ever introduce a feature that requires consent, we will ask for it separately. You may withdraw any consent at any time by emailing [PRIVACY EMAIL], without affecting the lawfulness of processing before withdrawal.
7.4 Vital interests and public interest
We do not rely on these bases.
7.5 Legitimate interests — Article 6(1)(f)
| Purpose | Our interest | Why we consider it balanced |
|---|---|---|
| Device-limit enforcement and anti-sharing | Protecting our licensed content and revenue; fairness to paying users | Limited technical data only (device identifier, user-agent, sign-in country); no precise location; disclosed in the Terms and here; right to object (section 13) |
| Assessment integrity | Preserving the validity of assessments for all learners | Analysis limited to attempts within the assessment feature |
| Fraud and security | Protecting the Platform and users | Minimal data, strictly retained |
| Product improvement using first-party aggregate data | Building a better learning product | No third-party analytics; no individual profiling used for marketing |
| Defending legal claims and enforcing our Terms | Access to justice | Limited to what is necessary for the claim |
8. Automated processing and profiling
8.1 We use automated checks to flag potential breaches of the Terms, such as sharing across too many devices or unusual assessment activity.
8.2 We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Where an automated check flags an Account for review, a member of our staff reviews the evidence manually before any suspension or termination takes effect. You may ask for an explanation and contest the decision by emailing [PRIVACY EMAIL].
9. Who we share data with
We do not sell personal data. We share it only as set out below.
9.1 Service providers acting on our instructions
| Provider | Role | What is shared |
|---|---|---|
| Supabase | Database, authentication and file storage underlying the Platform | All Account, learning, assessment, entitlement and technical data described in section 4 |
| Cloudflare Workers | Application hosting | Request metadata (IP address, user-agent) at the network layer |
| Paddle | Merchant of Record — payment processing, tax calculation and remittance, invoicing, and refund/chargeback handling | Order and transaction data described in section 4.4 (see section 9.2 — Paddle acts as an independent controller for this data) |
| Lovable AI Gateway, using Google Gemini models | Powers the AI Assistant and automatic translation of lesson and interface text | AI Assistant prompts and relevant page context are transmitted to this third-party AI model provider to generate a response. Lesson and interface text is also transmitted to the same provider for translation. This provider does not use your data to train its models on our behalf. |
| Optional OAuth sign-in | If you choose this sign-in method, your Google account identifiers and basic profile fields are exchanged with Google under your permissions |
Each provider is bound by its standard data processing terms. A current list of processors is available on request from [PRIVACY EMAIL].
9.2 Paddle — independent controller
Paddle.com Market Limited is the merchant of record and seller for your transaction. Paddle determines its own purposes for processing payment, tax, fraud-prevention and invoicing data and is an independent controller for that processing. Paddle's privacy policy is at https://www.paddle.com/legal/privacy.
9.3 Enterprise Customers
Where your Seat is purchased by an organisation, we make available to its nominated administrators your name, work email, seat status, course enrolment, progress and completion percentages, and assessment scores.
We do not share your individual answers to specific questions, your AI Assistant prompts, or your support correspondence with us, unless you ask us to or we are required to.
Your employer's own use of that data is governed by its own privacy notice, not this one.
9.4 Others
- Professional advisers — lawyers and accountants, under duties of confidentiality.
- Authorities, regulators and courts where required by law or necessary to establish or defend legal claims.
- A buyer or successor in the event of a merger, acquisition or reorganisation, subject to this Policy continuing to apply.
10. International transfers
10.1 We and our processors may process data in countries other than your own, including the United States (where our AI and hosting infrastructure may run) and other jurisdictions used by Supabase, Cloudflare and Paddle.
10.2 Where a transfer from the EEA or the UK is made to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses under Decision (EU) 2021/914, together with the UK International Data Transfer Addendum, and appropriate technical and organisational safeguards, including encryption in transit and at rest and access restriction.
10.3 You may request a summary of the safeguards applying to a specific transfer by writing to [PRIVACY EMAIL].
11. Retention
11.1 We keep personal data for as long as necessary for the purposes described in this Policy.
11.2 Current reality — please read carefully. We do not currently operate an automatic deletion, anonymisation or retention-expiry process. In practice:
- Account, learning, assessment and technical data is retained for as long as your Account exists, and is not automatically deleted afterwards.
- Transaction records are retained for accounting and tax purposes for at least 7 years.
- Terms-acceptance records (including IP address) are retained indefinitely as evidence of acceptance.
- If you ask us to delete your data (section 13), we will action that request manually, subject to the exceptions below.
- Exceptions we will keep even after a deletion request: transaction and accounting records we are legally required to retain; a minimal enforcement record (identifiers, reason, date) where an Account was terminated for breach or fraud, to prevent re-registration and defend claims; and copies held in encrypted backups until those backups are naturally cycled out.
- Aggregated or anonymised data that no longer identifies you may be retained indefinitely.
12. Enterprise learners: how roles are divided
If your access was bought by an employer or training organisation:
- We are the controller for your Account, authentication, learning activity, assessment results and technical and security data, as described in this Policy.
- Your organisation is an independent controller for the reporting data described in section 9.3 and for the decisions it makes using that data. Questions about why your employer monitors your training should go to your organisation.
- We will not disclose your individual answers or AI Assistant prompts to your organisation.
- You may exercise your rights against either of us by emailing [PRIVACY EMAIL]; we will help route the request to the right party.
13. Your rights
13.1 Under the GDPR, the UK GDPR and comparable laws you have the right to:
- access your personal data and receive a copy;
- rectify inaccurate or incomplete data;
- erase data — the right to be forgotten — in certain circumstances;
- restrict processing in certain circumstances;
- object to processing based on legitimate interests, including the device-limit and integrity monitoring in section 7.5;
- data portability for data you provided to us that we process by automated means on the basis of consent or contract, including your progress and assessment history;
- withdraw consent at any time where processing is based on consent;
- not be subject to solely automated decisions with legal or similarly significant effects — see section 8;
- complain to a supervisory authority — see section 13.5.
13.2 How to exercise your rights — this is a manual process. The Platform does not currently provide self-service account settings, a self-service data export tool, or a self-service account-deletion feature. To exercise any of the rights above, including deleting your Account or requesting a copy of your data, email [PRIVACY EMAIL]. We will verify your identity using information already associated with your Account and action your request manually.
13.3 Timing. We respond within one month of a verified request. Where a request is complex or you have made several requests, we may extend by up to two further months and will tell you why within the first month. Requests are free unless manifestly unfounded or excessive.
13.4 Objecting to device-limit and integrity monitoring. You may object to this processing at any time by emailing [PRIVACY EMAIL]. We will stop unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is necessary for legal claims. Please note that these controls are a condition of the licence under which content is supplied, and we may not be able to continue providing access if we cannot operate them; in that situation we will discuss options with you, including a pro-rata refund.
13.5 Supervisory authorities.
- EEA: you may complain to the data protection authority of your country of residence, your place of work, or the place of the alleged infringement. A list is maintained by the European Data Protection Board.
- United Kingdom: the Information Commissioner's Office, ico.org.uk.
We would appreciate the chance to address your concern first, at [PRIVACY EMAIL].
13.6 Other jurisdictions. If you are in a jurisdiction with its own privacy statute, we will honour the rights that law gives you, on the same manual, email-based basis described above. We do not sell personal data or share it for cross-context behavioural advertising as those terms are defined under United States state privacy laws.
14. Security
14.1 We implement technical and organisational measures appropriate to the risk, including:
- encryption of data in transit and at rest;
- passwords stored only as salted hashes by our authentication provider (Supabase);
- server-side entitlement validation — access rights are checked on our servers and never trusted from the client;
- row-level access controls in our database, so that a user's records are accessible only to that user and to authorised staff;
- least-privilege access for staff, with privileged credentials confined to server-only code;
- signature verification on payment webhooks;
- logging, monitoring and regular backups;
- written terms with our processors, and staff confidentiality obligations.
14.2 No system is completely secure. You are responsible for keeping your credentials confidential and for using a strong, unique password.
14.3 Breach notification. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it where required, and will notify you without undue delay where the breach is likely to result in a high risk to you.
15. Children
15.1 The Platform is intended for individuals aged 18 or over, and for 16- and 17-year-olds only where a parent or guardian has contracted on their behalf under the Terms. It is not directed at children under 16 and we do not knowingly collect their personal data.
15.2 If you believe a child under 16 has provided us with personal data, contact [PRIVACY EMAIL] and we will delete it promptly.
16. Marketing
We do not currently operate any marketing email programme, newsletter, preference centre or suppression list. If this changes in future, we will update this Policy and obtain any consent required by law before sending marketing communications.
17. Changes to this Policy
17.1 We may update this Policy. The current version, with its version number and effective date, is always published on the Platform.
17.2 For material changes we will notify you by an in-Platform notice or by email before they take effect. Where a change requires your consent, we will ask for it.
17.3 Previous versions are available on request from [PRIVACY EMAIL].
18. Contact
[LEGAL ENTITY NAME] trading as [TRADING NAME] [REGISTERED ADDRESS]
Privacy enquiries and rights requests: [PRIVACY EMAIL] General support: [SUPPORT EMAIL] EU/UK representative (where required): [EU/UK REPRESENTATIVE]
This Policy is governed by the laws of [GOVERNING LAW JURISDICTION].
AeroTech Academy — Privacy Policy Version 3.0 (production-ready) · Effective [EFFECTIVE DATE] © [LEGAL ENTITY NAME]. All rights reserved.