Legal

Privacy Policy

What personal data we collect, why we collect it, who processes it and what rights you have.

This legal document is published in English, which is the authoritative version.

Version: 3.0 (production-ready)

Effective date: [EFFECTIVE DATE]

Controller: [LEGAL ENTITY NAME], registered at [REGISTERED ADDRESS] under company registration number [COMPANY REGISTRATION NUMBER], trading as [TRADING NAME] ("AeroTech Academy", "we", "us").

Privacy contact: [PRIVACY EMAIL]

Support contact: [SUPPORT EMAIL]

Related documents: Terms and Conditions · Refund Policy · Cookie Policy

This Privacy Policy explains how we collect and use personal data when you use our website and application (the Platform). Capitalised terms not defined here have the meaning given in the Terms and Conditions.


1. How to contact us

PurposeContact
Privacy enquiries and rights requests[PRIVACY EMAIL]
General support[SUPPORT EMAIL]
Security incidents[PRIVACY EMAIL]
EU/UK representative (Article 27 GDPR / UK GDPR), where required[EU/UK REPRESENTATIVE]

We do not have, and are not required to have, a Data Protection Officer at our current scale. Privacy matters are handled by the contact above.


2. Scope

2.1 This Policy covers personal data we process as controller — that is, where we decide why and how it is processed.

2.2 It does not cover:

  • (a) Paddle's processing of your payment, tax and invoicing data. Paddle is the merchant of record and an independent controller for the sale. See section 9.2 and Paddle's privacy policy at https://www.paddle.com/legal/privacy.
  • (b) An Enterprise Customer's own use of learning and progress data about its Authorised Users, once we have disclosed it to that Customer. Your employer or training organisation is an independent controller for that use. See section 12.
  • (c) Third-party websites we link to.

3. Summary of processing

What we processWhyLegal basisRetention
Account data: name, email, password (hashed)Create and operate your AccountContract, Art. 6(1)(b)Account life; indefinitely thereafter as no deletion mechanism currently exists — see section 11
Authentication data (managed by Supabase)Sign you in securelyContract; legitimate interests (security)Session-based; until sign-out or token expiry
Terms-acceptance record (version, timestamp, IP address, 18+ confirmation)Evidence that you accepted our TermsLegal obligation; legitimate interestsIndefinitely, as proof of acceptance
Device identifier (localStorage), user-agent and sign-in countryEnforce the 4-device limit; detect account sharingLegitimate interests, Art. 6(1)(f)Indefinitely while the Account is active
Learning progress and exam attemptsDeliver the Services; show your progress and resultsContractAccount life; indefinitely thereafter, see section 11
Lesson feedback and support messagesImprove content; answer your queriesContract; legitimate interestsIndefinitely
AI Assistant promptsProvide the AI Assistant featureContract; legitimate interestsNot persisted by us; transient at the AI provider, see section 9.1
Order and entitlement records (from Paddle)Grant and validate access; accountingContract; legal obligation, Art. 6(1)(c)Typically 7 years for tax/accounting purposes
Enterprise seat records (name, work email, seat status)Administer company licencesContract; legitimate interestsTerm of the licence, then as above
First-party aggregate usage dataUnderstand and improve the PlatformLegitimate interestsRetained in aggregated/internal form; not sold or shared with third parties

We do not currently operate a data-deletion or self-service export workflow — see section 11 and section 13.


4. Personal data we collect

4.1 Data you give us

  • Account data: name, email address and password (stored only as a salted hash by our authentication provider, Supabase).
  • AI Assistant prompts: questions and text you submit to the Aviation AI Assistant.
  • Lesson feedback and error reports: ratings, comments and content-error reports you submit on lessons.
  • Support messages: correspondence you send to [SUPPORT EMAIL] or [PRIVACY EMAIL].

We do not collect a profile photo, a country field, or a target-licence-pathway field. We do not ask for and do not want special category data such as health, biometric or religious data, government identity documents, or aviation employment records such as maintenance logs or licence documents. Please do not submit them.

4.2 Data generated by your use of the Platform

  • Learning progress data: courses and lessons started and completed, video/lesson progress, time on task.
  • Assessment data: practice and simulation exam attempts, answers given, scores, pass/fail outcomes and attempt history.
  • Entitlement data: which products you hold, purchase source, and access status.
  • Terms-acceptance record: the version of the Terms you accepted, the timestamp, your IP address and your 18+ confirmation.
  • Certificates: where issued, your name, course title, score and a publicly verifiable certificate code.

4.3 Device, technical and security data

  • A device identifier that we generate and store in your browser's localStorage to operate the 4-device limit described in the Terms, together with a coarse device label, your browser's user-agent string, and the country associated with your sign-in IP address (we do not use precise geolocation).
  • Application and server logs, error reports and diagnostics.
  • Security signals such as failed sign-in attempts and the number and diversity of registered devices.

4.4 Purchase data we receive from Paddle

Paddle, our Merchant of Record, processes your payment. We never receive or store your full card number, security code or bank credentials. From Paddle we receive an order/transaction identifier, the product purchased, price, currency, purchase date, the email address used for the purchase, and refund/chargeback status.

4.5 Data from other sources

  • Enterprise Customers: where your employer or training organisation buys a Seat for you, we receive your work email address (used to assign the seat) and, once you sign in, your name.
  • Google (optional OAuth sign-in): if you choose to sign in with Google, we receive the identifiers and profile fields (such as name and email) that Google shares, subject to your permissions with Google.

5. Cookies and browser storage

5.1 We do not use third-party analytics, advertising or marketing cookies, and we do not run a cookie-consent banner because we do not use any non-essential cookies or trackers.

5.2 The storage we use is limited to strictly necessary, first-party items: an authentication session token, the device identifier described in section 4.3, and your interface preferences (such as language). Paddle sets its own cookies during checkout for fraud prevention and session handling. Full detail is in our Cookie Policy.


6. How we use your data

To provide the Services

  • create and administer your Account and authenticate you;
  • activate, deliver and validate access to courses, exams and the dictionary, including server-side entitlement checks;
  • record and display your progress, scores and history;
  • issue certificates of completion where applicable;
  • administer Enterprise Seats.

To protect the Services and our content

  • enforce the 4-device limit and detect account sharing;
  • detect and investigate assessment misuse and unauthorised copying of content;
  • maintain security and investigate incidents.

To support and communicate with you

  • respond to enquiries, feedback and error reports;
  • send essential service messages about your Account, purchases, security or changes to our Terms.

We do not operate a marketing email programme, mailing list, marketing-preference centre or suppression list. We do not send newsletters or promotional emails.

To improve and develop

  • understand which content and features are used, using first-party aggregate reporting, to improve course design and the learning experience. We do not use any third-party analytics product.

To provide the AI Assistant and translation

  • send your prompts to our AI Assistant so it can answer your questions;
  • send lesson and interface text for translation so the Platform can be shown in other languages.

To comply with law

  • meet accounting and tax record-keeping obligations;
  • respond to lawful requests from authorities;
  • establish, exercise or defend legal claims.

7. Legal bases

7.1 Performance of a contract — Article 6(1)(b)

Creating and running your Account, delivering the courses and features you purchased, recording your progress, providing support, and administering Enterprise Seats.

7.2 Legal obligation — Article 6(1)(c)

Retaining transaction records for accounting and tax purposes and responding to lawful requests.

7.3 Consent — Article 6(1)(a)

We do not currently rely on consent for any cookies, since we use no non-essential cookies. Where we ever introduce a feature that requires consent, we will ask for it separately. You may withdraw any consent at any time by emailing [PRIVACY EMAIL], without affecting the lawfulness of processing before withdrawal.

7.4 Vital interests and public interest

We do not rely on these bases.

7.5 Legitimate interests — Article 6(1)(f)

PurposeOur interestWhy we consider it balanced
Device-limit enforcement and anti-sharingProtecting our licensed content and revenue; fairness to paying usersLimited technical data only (device identifier, user-agent, sign-in country); no precise location; disclosed in the Terms and here; right to object (section 13)
Assessment integrityPreserving the validity of assessments for all learnersAnalysis limited to attempts within the assessment feature
Fraud and securityProtecting the Platform and usersMinimal data, strictly retained
Product improvement using first-party aggregate dataBuilding a better learning productNo third-party analytics; no individual profiling used for marketing
Defending legal claims and enforcing our TermsAccess to justiceLimited to what is necessary for the claim

8. Automated processing and profiling

8.1 We use automated checks to flag potential breaches of the Terms, such as sharing across too many devices or unusual assessment activity.

8.2 We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Where an automated check flags an Account for review, a member of our staff reviews the evidence manually before any suspension or termination takes effect. You may ask for an explanation and contest the decision by emailing [PRIVACY EMAIL].


9. Who we share data with

We do not sell personal data. We share it only as set out below.

9.1 Service providers acting on our instructions

ProviderRoleWhat is shared
SupabaseDatabase, authentication and file storage underlying the PlatformAll Account, learning, assessment, entitlement and technical data described in section 4
Cloudflare WorkersApplication hostingRequest metadata (IP address, user-agent) at the network layer
PaddleMerchant of Record — payment processing, tax calculation and remittance, invoicing, and refund/chargeback handlingOrder and transaction data described in section 4.4 (see section 9.2 — Paddle acts as an independent controller for this data)
Lovable AI Gateway, using Google Gemini modelsPowers the AI Assistant and automatic translation of lesson and interface textAI Assistant prompts and relevant page context are transmitted to this third-party AI model provider to generate a response. Lesson and interface text is also transmitted to the same provider for translation. This provider does not use your data to train its models on our behalf.
GoogleOptional OAuth sign-inIf you choose this sign-in method, your Google account identifiers and basic profile fields are exchanged with Google under your permissions

Each provider is bound by its standard data processing terms. A current list of processors is available on request from [PRIVACY EMAIL].

9.2 Paddle — independent controller

Paddle.com Market Limited is the merchant of record and seller for your transaction. Paddle determines its own purposes for processing payment, tax, fraud-prevention and invoicing data and is an independent controller for that processing. Paddle's privacy policy is at https://www.paddle.com/legal/privacy.

9.3 Enterprise Customers

Where your Seat is purchased by an organisation, we make available to its nominated administrators your name, work email, seat status, course enrolment, progress and completion percentages, and assessment scores.

We do not share your individual answers to specific questions, your AI Assistant prompts, or your support correspondence with us, unless you ask us to or we are required to.

Your employer's own use of that data is governed by its own privacy notice, not this one.

9.4 Others

  • Professional advisers — lawyers and accountants, under duties of confidentiality.
  • Authorities, regulators and courts where required by law or necessary to establish or defend legal claims.
  • A buyer or successor in the event of a merger, acquisition or reorganisation, subject to this Policy continuing to apply.

10. International transfers

10.1 We and our processors may process data in countries other than your own, including the United States (where our AI and hosting infrastructure may run) and other jurisdictions used by Supabase, Cloudflare and Paddle.

10.2 Where a transfer from the EEA or the UK is made to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses under Decision (EU) 2021/914, together with the UK International Data Transfer Addendum, and appropriate technical and organisational safeguards, including encryption in transit and at rest and access restriction.

10.3 You may request a summary of the safeguards applying to a specific transfer by writing to [PRIVACY EMAIL].


11. Retention

11.1 We keep personal data for as long as necessary for the purposes described in this Policy.

11.2 Current reality — please read carefully. We do not currently operate an automatic deletion, anonymisation or retention-expiry process. In practice:

  • Account, learning, assessment and technical data is retained for as long as your Account exists, and is not automatically deleted afterwards.
  • Transaction records are retained for accounting and tax purposes for at least 7 years.
  • Terms-acceptance records (including IP address) are retained indefinitely as evidence of acceptance.
  • If you ask us to delete your data (section 13), we will action that request manually, subject to the exceptions below.
  • Exceptions we will keep even after a deletion request: transaction and accounting records we are legally required to retain; a minimal enforcement record (identifiers, reason, date) where an Account was terminated for breach or fraud, to prevent re-registration and defend claims; and copies held in encrypted backups until those backups are naturally cycled out.
  • Aggregated or anonymised data that no longer identifies you may be retained indefinitely.

12. Enterprise learners: how roles are divided

If your access was bought by an employer or training organisation:

  • We are the controller for your Account, authentication, learning activity, assessment results and technical and security data, as described in this Policy.
  • Your organisation is an independent controller for the reporting data described in section 9.3 and for the decisions it makes using that data. Questions about why your employer monitors your training should go to your organisation.
  • We will not disclose your individual answers or AI Assistant prompts to your organisation.
  • You may exercise your rights against either of us by emailing [PRIVACY EMAIL]; we will help route the request to the right party.

13. Your rights

13.1 Under the GDPR, the UK GDPR and comparable laws you have the right to:

  • access your personal data and receive a copy;
  • rectify inaccurate or incomplete data;
  • erase data — the right to be forgotten — in certain circumstances;
  • restrict processing in certain circumstances;
  • object to processing based on legitimate interests, including the device-limit and integrity monitoring in section 7.5;
  • data portability for data you provided to us that we process by automated means on the basis of consent or contract, including your progress and assessment history;
  • withdraw consent at any time where processing is based on consent;
  • not be subject to solely automated decisions with legal or similarly significant effects — see section 8;
  • complain to a supervisory authority — see section 13.5.

13.2 How to exercise your rights — this is a manual process. The Platform does not currently provide self-service account settings, a self-service data export tool, or a self-service account-deletion feature. To exercise any of the rights above, including deleting your Account or requesting a copy of your data, email [PRIVACY EMAIL]. We will verify your identity using information already associated with your Account and action your request manually.

13.3 Timing. We respond within one month of a verified request. Where a request is complex or you have made several requests, we may extend by up to two further months and will tell you why within the first month. Requests are free unless manifestly unfounded or excessive.

13.4 Objecting to device-limit and integrity monitoring. You may object to this processing at any time by emailing [PRIVACY EMAIL]. We will stop unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is necessary for legal claims. Please note that these controls are a condition of the licence under which content is supplied, and we may not be able to continue providing access if we cannot operate them; in that situation we will discuss options with you, including a pro-rata refund.

13.5 Supervisory authorities.

  • EEA: you may complain to the data protection authority of your country of residence, your place of work, or the place of the alleged infringement. A list is maintained by the European Data Protection Board.
  • United Kingdom: the Information Commissioner's Office, ico.org.uk.

We would appreciate the chance to address your concern first, at [PRIVACY EMAIL].

13.6 Other jurisdictions. If you are in a jurisdiction with its own privacy statute, we will honour the rights that law gives you, on the same manual, email-based basis described above. We do not sell personal data or share it for cross-context behavioural advertising as those terms are defined under United States state privacy laws.


14. Security

14.1 We implement technical and organisational measures appropriate to the risk, including:

  • encryption of data in transit and at rest;
  • passwords stored only as salted hashes by our authentication provider (Supabase);
  • server-side entitlement validation — access rights are checked on our servers and never trusted from the client;
  • row-level access controls in our database, so that a user's records are accessible only to that user and to authorised staff;
  • least-privilege access for staff, with privileged credentials confined to server-only code;
  • signature verification on payment webhooks;
  • logging, monitoring and regular backups;
  • written terms with our processors, and staff confidentiality obligations.

14.2 No system is completely secure. You are responsible for keeping your credentials confidential and for using a strong, unique password.

14.3 Breach notification. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it where required, and will notify you without undue delay where the breach is likely to result in a high risk to you.


15. Children

15.1 The Platform is intended for individuals aged 18 or over, and for 16- and 17-year-olds only where a parent or guardian has contracted on their behalf under the Terms. It is not directed at children under 16 and we do not knowingly collect their personal data.

15.2 If you believe a child under 16 has provided us with personal data, contact [PRIVACY EMAIL] and we will delete it promptly.


16. Marketing

We do not currently operate any marketing email programme, newsletter, preference centre or suppression list. If this changes in future, we will update this Policy and obtain any consent required by law before sending marketing communications.


17. Changes to this Policy

17.1 We may update this Policy. The current version, with its version number and effective date, is always published on the Platform.

17.2 For material changes we will notify you by an in-Platform notice or by email before they take effect. Where a change requires your consent, we will ask for it.

17.3 Previous versions are available on request from [PRIVACY EMAIL].


18. Contact

[LEGAL ENTITY NAME] trading as [TRADING NAME] [REGISTERED ADDRESS]

Privacy enquiries and rights requests: [PRIVACY EMAIL] General support: [SUPPORT EMAIL] EU/UK representative (where required): [EU/UK REPRESENTATIVE]

This Policy is governed by the laws of [GOVERNING LAW JURISDICTION].


AeroTech Academy — Privacy Policy Version 3.0 (production-ready) · Effective [EFFECTIVE DATE] © [LEGAL ENTITY NAME]. All rights reserved.