Privacy Policy
Status: DRAFT — requires legal review before publishing, especially the sections on health data (medical certificates) and international data transfers. This document was researched and structured carefully, but it is not a substitute for review by someone qualified to practice law in your jurisdiction. Placeholders are marked <span class="doc-placeholder">[ ]</span> — fill these in before this goes live.
Effective date: [ ] · Last updated: [ ]
Overview
<span class="doc-placeholder">[Company legal name]</span> ("FlightDesk AI," "we," "us," or "our") operates FlightDesk AI, a flight school operations platform (the "Service"). This Privacy Policy explains what personal data we collect, why, and what rights you have over it.
Because we are established in the Czech Republic and our customers are flight schools operating in the European Union and elsewhere, this policy is built around the EU General Data Protection Regulation (GDPR) as the primary framework, not added as an afterthought. Where a user is located outside the EU, we still apply the same standard as a baseline.
This policy covers two different relationships, which GDPR treats differently:
- Flight schools who sign up for FlightDesk AI are the data controller for the information about their own students, instructors, and operations. We act as their data processor — we process that data on their instructions, under a data processing agreement.
- For account/billing information about the school itself, and for anyone who contacts us directly (e.g. through this website), we are the data controller.
If you are a student or instructor whose data was entered into FlightDesk AI by your flight school, your school is the right first point of contact for exercising your rights — but you can also contact us directly and we will support the request.
Who we are
<span class="doc-placeholder">[Company legal name]</span> s.r.o., IČO <span class="doc-placeholder">[ ]</span>, DIČ <span class="doc-placeholder">[ ]</span>, se sídlem <span class="doc-placeholder">[registered address, Czech Republic]</span>
(This is the standard Czech format for identifying a data controller — company name, IČO/company registration number, DIČ/VAT number, and registered seat address. Confirmed against a real published Czech flight school's privacy policy while drafting this.)
Contact: <span class="doc-placeholder">[privacy email]</span>
<span class="doc-placeholder">[If a Data Protection Officer is appointed: name and contact. Not mandatory for most small companies under GDPR, but note this decision explicitly rather than leaving it silently unaddressed.]</span>
What we collect
We only describe below what the product actually stores, based on the built system — not a generic list of "things software companies typically collect."
One principle applies throughout this section: we store structured facts needed to run the school's operations, not documents. We do not collect or store scans, photos, or copies of medical certificates, licences, passports, ID cards, or any other identity or certification document. We also do not collect passport numbers or national ID numbers. Where a record like "licence number" or "medical certificate class" is stored, it is stored as a short data field entered by the school — not as an attached document.
1. Account and organization data
When someone signs up and creates a school's workspace: name, email address, password (stored hashed by our authentication provider, never in plain text), and organization details (school name, contact email/phone, address, country, currency, time zone).
2. Student and instructor records (entered by the flight school)
- Name, email, phone number, date of birth
- Pilot licence type, number, and expiry date
- Ratings held
- Medical certificate class and expiry date
- ICAO English proficiency level and expiry
- Training progress, flight hours, and status (active/waiting/inactive)
Medical certificate data is "special category data" under GDPR Article 9 (it relates to health). We process it because flight schools have a legitimate operational and safety need to know whether a pilot's medical certificate is currently valid — this is directly tied to whether that person may legally fly. <span class="doc-placeholder">[Legal basis to confirm with counsel: likely Article 9(2)(b) — obligations in the field of employment/safety law — or explicit consent (Article 9(2)(a)) collected at the point the student/instructor record is created. This needs to be decided deliberately, not left implicit.]</span>
Important: we deliberately store the minimum needed, not documents themselves. FlightDesk AI does not store scans, photos, or copies of any document — no medical certificates, no licences, no passports, no ID cards. For medical certification specifically, we store only the certificate class and its expiry date — not clinical findings, test results, diagnoses, or any other detail from the certificate or the examination behind it. We also do not collect passport numbers or ID card numbers at all, which some comparable products do. This is a deliberate data minimization choice (a core GDPR principle), not an accident — but it's worth being precise about what it does and doesn't change: storing only the class and expiry date, instead of a full document scan, is still processing of special category data under Article 9, because that data still reveals health-related information about the person. Not storing the underlying document reduces the amount and sensitivity of what we hold — it doesn't remove the need for a proper legal basis, described above.
3. Flight and operational records
- Bookings: dates, times, aircraft, instructor/student pairing, flight type
- Flight logs: routes, duration, lesson content, instructor grading notes
- Aircraft records: registration, type, engine/propeller hours, maintenance history
- Weather and NOTAM data checked for specific flights (this is airport/route data, not personal data, but it is linked to the flight record)
4. Safety reports
Flight schools can log safety occurrences through the Service. Reports can be submitted anonymously if the reporting person chooses not to identify themselves — in that case we do not know who submitted it and cannot identify them from the report itself. Where a reporter does identify themselves, that identity is visible only to the school's designated safety reviewers, not to the wider organization.
5. Financial records
Invoices and payment records entered by the school (amounts, dates, descriptions). <span class="doc-placeholder">[As of this draft, FlightDesk AI does not integrate a payment processor — no card numbers or bank details pass through our systems. Update this section the moment that changes, since adding a payment processor changes this section materially.]</span>
6. System and audit data
We log account activity (who changed what, and when) for security and accountability — for example, changes to safety reports, bookings, or licence records. This is standard practice for software handling safety-relevant records, and it also protects everyone using the system: it means actions are attributable and disputes can be resolved by looking at what actually happened.
7. Technical data
Standard web request data (IP address, browser type) is processed by our infrastructure providers as part of operating the Service securely, in line with their own practices. <span class="doc-placeholder">[As of this draft, FlightDesk AI does not use third-party analytics or advertising trackers. If that changes, this section and the cookie section below need to be rewritten — do not silently start adding tracking without updating this policy first.]</span>
Legal basis for processing (GDPR)
| What | Legal basis |
|---|---|
| Operating your school's account, bookings, flight logs, maintenance records | Contract (Art. 6(1)(b)) — necessary to provide the Service you signed up for |
| Medical certificate data | <span class="doc-placeholder">[To be confirmed — see note above]</span> |
| Safety reports | Legitimate interest in aviation safety (Art. 6(1)(f)), balanced against reporter privacy; anonymous reporting is offered specifically to support this |
| Security/audit logging | Legitimate interest in system integrity and accountability (Art. 6(1)(f)) |
| Responding to enquiries sent to us directly | Contract or legitimate interest, depending on context |
| Legal/regulatory obligations (e.g. tax records) | Legal obligation (Art. 6(1)(c)) |
Who we share data with
We do not sell personal data, and we do not share it with advertisers — FlightDesk AI does not run advertising of any kind. Sharing is limited to what is necessary to run the Service:
- Hosting and database (Supabase). All data is stored with Supabase, our infrastructure provider, acting as a sub-processor.
<span class="doc-placeholder">[Confirm and state the exact hosting region here — this matters for the international transfer section below and needs a real answer, not a placeholder, before this goes live.]</span> - Weather and NOTAM data providers. When a user checks live weather or NOTAM for an airport, we send the airport code to aviationweather.gov and the FAA NOTAM system to retrieve that public data. We do not send any personal data as part of this — only the airport identifier.
- Legal requirements. We may disclose data if required by law, court order, or to protect the rights, safety, or property of FlightDesk AI, our customers, or others.
- Business transfers. If FlightDesk AI is acquired or merged, data may transfer as part of that transaction, under the same protections described here.
Within a school's own account, data is visible according to role: students generally see their own records; instructors see their students; school administrators see everything within their own organization. One school can never see another school's data — this is enforced at the database level (row-level security), not just in the application interface, and was specifically tested during development.
International data transfers
<span class="doc-placeholder">[This section needs to be completed once hosting infrastructure is finalized.]</span> If data is transferred outside the European Economic Area, we will rely on an appropriate safeguard recognized under GDPR (such as the European Commission's Standard Contractual Clauses) and will name the specific mechanism here rather than describing it only in the abstract.
Data retention
We retain personal data for as long as the flight school's account is active, plus a reasonable period after account closure to allow for data export requests. Some records cannot be deleted on request even during an active account, because retention is required by law rather than by our own choice — for example, accounting records under the Czech Accounting Act (zákon o účetnictví), and certain training, licence, and certification records under the Czech Civil Aviation Act (zákon o civilním letectví) and its implementing regulations, which may require flight schools to retain training records for a defined period after training ends. <span class="doc-placeholder">[Confirm the exact retention periods required under these specific laws for training/licence records — a real Czech flight school's published policy cites these two acts by name as the basis for retention exceeding a user's deletion request, which is the right model to follow rather than an open-ended "as long as necessary."]</span>
For everything not covered by a specific legal retention requirement, we aim to define concrete periods rather than leaving this open-ended — for example: enquiry/contact form submissions for 1 year, account data for the life of the account plus <span class="doc-placeholder">[ ]</span> after closure. <span class="doc-placeholder">[Fill in real numbers per category before publishing — GDPR's storage limitation principle requires an actual answer, not "as needed."]</span>
Your rights
If you are located in the EEA or UK, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data ("right to be forgotten"), subject to legal retention obligations — see Data Retention above for the specific Czech laws that can limit this (accounting and civil aviation record-keeping requirements)
- Restrict processing in certain circumstances
- Data portability — receive your data in a structured, machine-readable format
- Object to processing based on legitimate interest
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with your national data protection authority — in the Czech Republic, this is the Office for Personal Data Protection (ÚOOÚ)
If your data was entered by your flight school, please contact your school first — they control the record. If you'd rather contact us directly, write to <span class="doc-placeholder">[privacy email]</span> and we will either action the request (where we control the data) or forward it to the relevant school promptly.
We will acknowledge requests within a reasonable time and respond within one month, as required by GDPR (extendable by two further months for complex requests, with notice to you explaining why).
Children's privacy
FlightDesk AI is a business tool for flight schools, not a service directed at children. That said, we recognize that some flight training students may be minors in some jurisdictions (e.g. glider or ultralight training programs that accept younger students under national aviation rules). Where a school enters a minor's data, the school is responsible for having the appropriate legal basis (typically parental/guardian consent) under its own local law — this is a matter for the school's own compliance, but we note it here rather than pretending the situation doesn't arise.
Security
We take the following measures, among others: row-level data isolation between organizations (verified through testing, not just assumed), encrypted connections (HTTPS) for all traffic, and role-based access control within each school's account. <span class="doc-placeholder">[If/when a formal security audit or certification is obtained, name it here — general "we take security seriously" language should be backed by something concrete once available.]</span>
No system is completely immune to risk, and we do not claim otherwise. If we become aware of a data breach affecting your personal data, we will notify affected schools and, where required by law, the relevant supervisory authority, within the timeframes GDPR requires.
Cookies
See our separate Cookie Policy for full detail. In short: we do not currently use tracking, analytics, or advertising cookies on the marketing website or inside the application — session login uses local browser storage, not cookies, and is strictly necessary rather than optional.
Changes to this policy
We will post any changes here with an updated "Last updated" date. If a change is material, we will make reasonable efforts to notify active schools directly (e.g. by email) rather than relying on people to check this page on their own.
Contact us
Questions, requests, or concerns about this policy or how we handle personal data: <span class="doc-placeholder">[privacy email]</span>
For urgent issues (suspected data breach, system down affecting live operations), see our Emergency Contact channel, listed separately from general enquiries because it needs a faster response path.
A note on how this document was built
This draft was structured deliberately around GDPR (since the company and its likely first customers are EU-based) rather than adapted from a US-market template, and it only describes what the FlightDesk AI product actually does — no boilerplate about advertising partners, data brokers, or analytics tools that aren't in use. Every <span class="doc-placeholder">[ ]</span> placeholder above is a genuine open question that needs a real decision, not filler text to delete later without reading it.