Privacy Policy
Overview
Oleksandr Puriha ("FlightDesk AI," "we," "us," or "our") operates FlightDesk AI, a flight school operations platform (the "Service"). This Privacy Policy explains what personal data we collect, why, and what rights you have over it.
Because we are established in the Czech Republic and our customers are flight schools operating in the European Union, the United States, and elsewhere, this policy is built around the EU General Data Protection Regulation (GDPR) as the primary framework, not added as an afterthought. Where a user is located outside the EU, we still apply the same standard as a baseline.
This policy covers two different relationships, which GDPR treats differently:
- Flight schools who sign up for FlightDesk AI are the data controller for the information about their own students, instructors, and operations. We act as their data processor — we process that data on their instructions, under a data processing agreement.
- For account/billing information about the school itself, and for anyone who contacts us directly (e.g. through this website), we are the data controller.
If you are a student or instructor whose data was entered into FlightDesk AI by your flight school, your school is the right first point of contact for exercising your rights — but you can also contact us directly and we will support the request.
Who we are
Oleksandr Puriha, IČO 000111255, se sídlem Zakosteli 188, Zdounky, 76802, Czech Republic (sole trader / OSVČ — not VAT-registered, no DIČ) (This is the standard Czech format for identifying a data controller — company name, IČO/company registration number, DIČ/VAT number, and registered seat address. Confirmed against a real published Czech flight school's privacy policy while drafting this.) Contact: buzjets@gmail.com · +420 733 524 200 (WhatsApp)
No Data Protection Officer is appointed. This is not required under GDPR for a business of this size and processing scope — we're noting the decision explicitly rather than leaving it unaddressed. If FlightDesk AI's scale changes in a way that makes a DPO appropriate, this section will be updated.
What we collect
We only describe below what the product actually stores, based on the built system — not a generic list of "things software companies typically collect."
One principle applies throughout this section: we store structured facts needed to run the school's operations, not documents. We do not collect or store scans, photos, or copies of medical certificates, licences, passports, ID cards, or any other identity or certification document. We also do not collect passport numbers or national ID numbers. Where a record like "licence number" or "medical certificate class" is stored, it is stored as a short data field entered by the school — not as an attached document.
1. Account and organization data
When someone signs up and creates a school's workspace: name, email address, password (stored hashed by our authentication provider, never in plain text), and organization details (school name, contact email/phone, address, country, currency, time zone).
2. Student and instructor records (entered by the flight school)
- Name, email, phone number, date of birth
- Pilot licence type, number, and expiry date
- Ratings held
- Medical certificate class and expiry date
- ICAO English proficiency level and expiry
- Training progress, flight hours, and status (active/waiting/inactive)
Medical certificate data is "special category data" under GDPR Article 9 (it relates to health). We process it because flight schools have a legitimate operational and safety need to know whether a pilot's medical certificate is currently valid — this is directly tied to whether that person may legally fly. Our working legal basis is Article 9(2)(b) — processing necessary for obligations in the field of employment, social security, and safety law, since aviation authorities require operators to verify medical validity before a pilot exercises licence privileges. (This is the one item on this page worth a real lawyer's fifteen minutes before relying on it at scale — Article 9 legal basis is genuinely consequential to get right, and this is a considered starting position, not a substitute for that confirmation.)
Important: we deliberately store the minimum needed, not documents themselves. FlightDesk AI does not store scans, photos, or copies of any document — no medical certificates, no licences, no passports, no ID cards. For medical certification specifically, we store only the certificate class and its expiry date — not clinical findings, test results, diagnoses, or any other detail from the certificate or the examination behind it. We also do not collect passport numbers or ID card numbers at all, which some comparable products do. This is a deliberate data minimization choice (a core GDPR principle), not an accident — but it's worth being precise about what it does and doesn't change: storing only the class and expiry date, instead of a full document scan, is still processing of special category data under Article 9, because that data still reveals health-related information about the person. Not storing the underlying document reduces the amount and sensitivity of what we hold — it doesn't remove the need for a proper legal basis, described above.
3. Flight and operational records
- Bookings: dates, times, aircraft, instructor/student pairing, flight type
- Flight logs: routes, duration, lesson content, instructor grading notes
- Aircraft records: registration, type, engine/propeller hours, maintenance history
- Weather and NOTAM data checked for specific flights (this is airport/route data, not personal data, but it is linked to the flight record)
4. Safety reports
Flight schools can log safety occurrences through the Service. Reports can be submitted anonymously if the reporting person chooses not to identify themselves — in that case we do not know who submitted it and cannot identify them from the report itself. Where a reporter does identify themselves, that identity is visible only to the school's designated safety reviewers, not to the wider organization.
5. Financial records
Invoices and payment records entered by the school (amounts, dates, descriptions). As of this policy, FlightDesk AI does not yet have an integrated payment processor — no card numbers or bank details pass through our systems. This section will be updated with the specific processor and payment-data handling the moment that changes.
6. System and audit data
We log account activity (who changed what, and when) for security and accountability — for example, changes to safety reports, bookings, or licence records. This is standard practice for software handling safety-relevant records, and it also protects everyone using the system: it means actions are attributable and disputes can be resolved by looking at what actually happened.
7. Technical data
Standard web request data (IP address, browser type) is processed by our infrastructure providers as part of operating the Service securely, in line with their own practices. On the marketing website, we also use Google Analytics — but only after you explicitly accept it via the cookie banner; see our Cookie Policy for details on how that consent works.
Legal basis for processing (GDPR)
| What | Legal basis |
|---|---|
| Operating your school's account, bookings, flight logs, maintenance records | Contract (Art. 6(1)(b)) — necessary to provide the Service you signed up for |
| Medical certificate data | Legitimate interest in aviation safety and compliance (Art. 9(2)(b) — obligations in the field of employment/safety law); see note above — worth a lawyer's confirmation before relying on at scale |
| Safety reports | Legitimate interest in aviation safety (Art. 6(1)(f)), balanced against reporter privacy; anonymous reporting is offered specifically to support this |
| Security/audit logging | Legitimate interest in system integrity and accountability (Art. 6(1)(f)) |
| Responding to enquiries sent to us directly | Contract or legitimate interest, depending on context |
| Legal/regulatory obligations (e.g. tax records) | Legal obligation (Art. 6(1)(c)) |
Who we share data with
We do not sell personal data, and we do not share it with advertisers — FlightDesk AI does not run advertising of any kind. Sharing is limited to what is necessary to run the Service:
- Hosting and database (Supabase). All data is stored with Supabase, our infrastructure provider, acting as a sub-processor. Our Supabase project is hosted in the European Union (Frankfurt region) — the same region where our company is established.
- Weather and NOTAM data providers. When a user checks live weather or NOTAM for an airport, we send the airport code to aviationweather.gov and the FAA NOTAM system to retrieve that public data. We do not send any personal data as part of this — only the airport identifier.
- Legal requirements. We may disclose data if required by law, court order, or to protect the rights, safety, or property of FlightDesk AI, our customers, or others.
- Business transfers. If FlightDesk AI is acquired or merged, data may transfer as part of that transaction, under the same protections described here.
Within a school's own account, data is visible according to role: students generally see their own records; instructors see their students; school administrators see everything within their own organization. One school can never see another school's data — this is enforced at the database level (row-level security), not just in the application interface, and was specifically tested during development.
International data transfers
Your core operational data (bookings, flight logs, student/instructor records, aircraft records) is stored on our Supabase project in the European Union (Frankfurt) — this data does not leave the EEA as part of normal operation.
Two supporting tools we use are operated by US-headquartered companies: Cloudflare (hosts the website and application front-end) and Google (our support email runs on Gmail, and the marketing website uses Google Analytics, only after you consent — see our Cookie Policy). Both companies publish their own commitment to the European Commission's Standard Contractual Clauses (SCCs) as the transfer safeguard for any data that reaches infrastructure outside the EEA through their services. We rely on those published commitments rather than negotiating separate terms, which is standard practice for a company of our size.
Data retention
We retain personal data for as long as the flight school's account is active, plus 30 days after account closure to allow for data export requests, after which it is permanently deleted unless a legal retention requirement (below) applies.
Some records cannot be deleted on request even during an active account, because retention is required by law rather than by our own choice. Two different sets of rules apply here, and it's worth being precise about which governs what:
- Our own accounting records (invoices we issue to schools for their subscription) are retained under the Czech Accounting Act (zákon o účetnictví) — a minimum of 5 years after the end of the reporting year for accounting documents, and 10 years for financial statements. This applies to our own billing records, not to the training data a school stores about its students.
- Training, licence, and certification records that a school stores about its own students and instructors are governed by whichever aviation authority that specific school operates under — not uniformly by Czech law, since FlightDesk AI serves schools in multiple jurisdictions. For example, EASA Approved/Declared Training Organisations must keep training records for a minimum of 3 years after completion (Part-ORA / ORA.ATO.120, DTO.GEN.220), while FAA Part 141 schools in the US must retain student records for at least 1 year after graduation, termination, or transfer (14 CFR §141.101/103). Each school, as the data controller for its own students' records, is responsible for configuring retention appropriate to its own regulator — FlightDesk AI supports this by not force-deleting records on a fixed schedule and by making export straightforward.
For everything not covered by a specific legal retention requirement, we define concrete periods rather than leaving this open-ended: enquiry/contact form submissions are retained for 1 year, and account data for the life of the account plus 30 days after closure, as noted above.
Your rights
If you are located in the EEA or UK, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data ("right to be forgotten"), subject to legal retention obligations — see Data Retention above for the specific rules that can limit this (our own accounting records under Czech law, and training/licence records under whichever aviation authority your school operates under)
- Restrict processing in certain circumstances
- Data portability — receive your data in a structured, machine-readable format
- Object to processing based on legitimate interest
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with your national data protection authority — in the Czech Republic, this is the Office for Personal Data Protection (ÚOOÚ)
If your data was entered by your flight school, please contact your school first — they control the record. If you'd rather contact us directly, write to buzjets@gmail.com and we will either action the request (where we control the data) or forward it to the relevant school promptly.
We will acknowledge requests within a reasonable time and respond within one month, as required by GDPR (extendable by two further months for complex requests, with notice to you explaining why).
Children's privacy
FlightDesk AI is a business tool for flight schools, not a service directed at children. That said, we recognize that some flight training students may be minors in some jurisdictions (e.g. glider or ultralight training programs that accept younger students under national aviation rules). Where a school enters a minor's data, the school is responsible for having the appropriate legal basis (typically parental/guardian consent) under its own local law — this is a matter for the school's own compliance, but we note it here rather than pretending the situation doesn't arise.
Security
We take the following measures, among others: row-level data isolation between organizations (verified through testing, not just assumed), encrypted connections (HTTPS) for all traffic, and role-based access control within each school's account. We do not currently hold a formal third-party security certification (e.g. SOC 2, ISO 27001) — if that changes, we will name it here rather than relying on general assurances.
No system is completely immune to risk, and we do not claim otherwise. If we become aware of a data breach affecting your personal data, we will notify affected schools and, where required by law, the relevant supervisory authority, within the timeframes GDPR requires.
Cookies
See our separate Cookie Policy for full detail. In short: we use one non-essential tool, Google Analytics, and only after you actively accept it via the cookie banner on the marketing website — nothing analytics-related loads before that. Session login inside the application uses local browser storage, not a cookie, and is strictly necessary rather than optional.
Changes to this policy
We will post any changes here with an updated "Last updated" date. If a change is material, we will make reasonable efforts to notify active schools directly (e.g. by email) rather than relying on people to check this page on their own.
Contact us
Questions, requests, or concerns about this policy or how we handle personal data: buzjets@gmail.com
For urgent issues (suspected data breach, system down affecting live operations), see our Emergency Contact channel, listed separately from general enquiries because it needs a faster response path.