← Back to home DRAFT — pending legal review

Privacy Policy

Effective date: to be confirmed · Last updated: 26 July 2026

Status: DRAFT — requires legal review before publishing, especially the sections on health data (medical certificates) and international data transfers. This document was researched and structured carefully, but it is not a substitute for review by someone qualified to practice law in your jurisdiction. Placeholders are marked <span class="doc-placeholder">[ ]</span> — fill these in before this goes live.

Effective date: [ ] · Last updated: [ ]


Overview

<span class="doc-placeholder">[Company legal name]</span> ("FlightDesk AI," "we," "us," or "our") operates FlightDesk AI, a flight school operations platform (the "Service"). This Privacy Policy explains what personal data we collect, why, and what rights you have over it.

Because we are established in the Czech Republic and our customers are flight schools operating in the European Union and elsewhere, this policy is built around the EU General Data Protection Regulation (GDPR) as the primary framework, not added as an afterthought. Where a user is located outside the EU, we still apply the same standard as a baseline.

This policy covers two different relationships, which GDPR treats differently:

If you are a student or instructor whose data was entered into FlightDesk AI by your flight school, your school is the right first point of contact for exercising your rights — but you can also contact us directly and we will support the request.


Who we are

<span class="doc-placeholder">[Company legal name]</span> s.r.o., IČO <span class="doc-placeholder">[ ]</span>, DIČ <span class="doc-placeholder">[ ]</span>, se sídlem <span class="doc-placeholder">[registered address, Czech Republic]</span> (This is the standard Czech format for identifying a data controller — company name, IČO/company registration number, DIČ/VAT number, and registered seat address. Confirmed against a real published Czech flight school's privacy policy while drafting this.) Contact: <span class="doc-placeholder">[privacy email]</span>

<span class="doc-placeholder">[If a Data Protection Officer is appointed: name and contact. Not mandatory for most small companies under GDPR, but note this decision explicitly rather than leaving it silently unaddressed.]</span>


What we collect

We only describe below what the product actually stores, based on the built system — not a generic list of "things software companies typically collect."

One principle applies throughout this section: we store structured facts needed to run the school's operations, not documents. We do not collect or store scans, photos, or copies of medical certificates, licences, passports, ID cards, or any other identity or certification document. We also do not collect passport numbers or national ID numbers. Where a record like "licence number" or "medical certificate class" is stored, it is stored as a short data field entered by the school — not as an attached document.

1. Account and organization data

When someone signs up and creates a school's workspace: name, email address, password (stored hashed by our authentication provider, never in plain text), and organization details (school name, contact email/phone, address, country, currency, time zone).

2. Student and instructor records (entered by the flight school)

Medical certificate data is "special category data" under GDPR Article 9 (it relates to health). We process it because flight schools have a legitimate operational and safety need to know whether a pilot's medical certificate is currently valid — this is directly tied to whether that person may legally fly. <span class="doc-placeholder">[Legal basis to confirm with counsel: likely Article 9(2)(b) — obligations in the field of employment/safety law — or explicit consent (Article 9(2)(a)) collected at the point the student/instructor record is created. This needs to be decided deliberately, not left implicit.]</span>

Important: we deliberately store the minimum needed, not documents themselves. FlightDesk AI does not store scans, photos, or copies of any document — no medical certificates, no licences, no passports, no ID cards. For medical certification specifically, we store only the certificate class and its expiry date — not clinical findings, test results, diagnoses, or any other detail from the certificate or the examination behind it. We also do not collect passport numbers or ID card numbers at all, which some comparable products do. This is a deliberate data minimization choice (a core GDPR principle), not an accident — but it's worth being precise about what it does and doesn't change: storing only the class and expiry date, instead of a full document scan, is still processing of special category data under Article 9, because that data still reveals health-related information about the person. Not storing the underlying document reduces the amount and sensitivity of what we hold — it doesn't remove the need for a proper legal basis, described above.

3. Flight and operational records

4. Safety reports

Flight schools can log safety occurrences through the Service. Reports can be submitted anonymously if the reporting person chooses not to identify themselves — in that case we do not know who submitted it and cannot identify them from the report itself. Where a reporter does identify themselves, that identity is visible only to the school's designated safety reviewers, not to the wider organization.

5. Financial records

Invoices and payment records entered by the school (amounts, dates, descriptions). <span class="doc-placeholder">[As of this draft, FlightDesk AI does not integrate a payment processor — no card numbers or bank details pass through our systems. Update this section the moment that changes, since adding a payment processor changes this section materially.]</span>

6. System and audit data

We log account activity (who changed what, and when) for security and accountability — for example, changes to safety reports, bookings, or licence records. This is standard practice for software handling safety-relevant records, and it also protects everyone using the system: it means actions are attributable and disputes can be resolved by looking at what actually happened.

7. Technical data

Standard web request data (IP address, browser type) is processed by our infrastructure providers as part of operating the Service securely, in line with their own practices. <span class="doc-placeholder">[As of this draft, FlightDesk AI does not use third-party analytics or advertising trackers. If that changes, this section and the cookie section below need to be rewritten — do not silently start adding tracking without updating this policy first.]</span>


Legal basis for processing (GDPR)

What Legal basis
Operating your school's account, bookings, flight logs, maintenance records Contract (Art. 6(1)(b)) — necessary to provide the Service you signed up for
Medical certificate data <span class="doc-placeholder">[To be confirmed — see note above]</span>
Safety reports Legitimate interest in aviation safety (Art. 6(1)(f)), balanced against reporter privacy; anonymous reporting is offered specifically to support this
Security/audit logging Legitimate interest in system integrity and accountability (Art. 6(1)(f))
Responding to enquiries sent to us directly Contract or legitimate interest, depending on context
Legal/regulatory obligations (e.g. tax records) Legal obligation (Art. 6(1)(c))

Who we share data with

We do not sell personal data, and we do not share it with advertisers — FlightDesk AI does not run advertising of any kind. Sharing is limited to what is necessary to run the Service:

Within a school's own account, data is visible according to role: students generally see their own records; instructors see their students; school administrators see everything within their own organization. One school can never see another school's data — this is enforced at the database level (row-level security), not just in the application interface, and was specifically tested during development.


International data transfers

<span class="doc-placeholder">[This section needs to be completed once hosting infrastructure is finalized.]</span> If data is transferred outside the European Economic Area, we will rely on an appropriate safeguard recognized under GDPR (such as the European Commission's Standard Contractual Clauses) and will name the specific mechanism here rather than describing it only in the abstract.


Data retention

We retain personal data for as long as the flight school's account is active, plus a reasonable period after account closure to allow for data export requests. Some records cannot be deleted on request even during an active account, because retention is required by law rather than by our own choice — for example, accounting records under the Czech Accounting Act (zákon o účetnictví), and certain training, licence, and certification records under the Czech Civil Aviation Act (zákon o civilním letectví) and its implementing regulations, which may require flight schools to retain training records for a defined period after training ends. <span class="doc-placeholder">[Confirm the exact retention periods required under these specific laws for training/licence records — a real Czech flight school's published policy cites these two acts by name as the basis for retention exceeding a user's deletion request, which is the right model to follow rather than an open-ended "as long as necessary."]</span>

For everything not covered by a specific legal retention requirement, we aim to define concrete periods rather than leaving this open-ended — for example: enquiry/contact form submissions for 1 year, account data for the life of the account plus <span class="doc-placeholder">[ ]</span> after closure. <span class="doc-placeholder">[Fill in real numbers per category before publishing — GDPR's storage limitation principle requires an actual answer, not "as needed."]</span>


Your rights

If you are located in the EEA or UK, you have the right to:

If your data was entered by your flight school, please contact your school first — they control the record. If you'd rather contact us directly, write to <span class="doc-placeholder">[privacy email]</span> and we will either action the request (where we control the data) or forward it to the relevant school promptly.

We will acknowledge requests within a reasonable time and respond within one month, as required by GDPR (extendable by two further months for complex requests, with notice to you explaining why).


Children's privacy

FlightDesk AI is a business tool for flight schools, not a service directed at children. That said, we recognize that some flight training students may be minors in some jurisdictions (e.g. glider or ultralight training programs that accept younger students under national aviation rules). Where a school enters a minor's data, the school is responsible for having the appropriate legal basis (typically parental/guardian consent) under its own local law — this is a matter for the school's own compliance, but we note it here rather than pretending the situation doesn't arise.


Security

We take the following measures, among others: row-level data isolation between organizations (verified through testing, not just assumed), encrypted connections (HTTPS) for all traffic, and role-based access control within each school's account. <span class="doc-placeholder">[If/when a formal security audit or certification is obtained, name it here — general "we take security seriously" language should be backed by something concrete once available.]</span>

No system is completely immune to risk, and we do not claim otherwise. If we become aware of a data breach affecting your personal data, we will notify affected schools and, where required by law, the relevant supervisory authority, within the timeframes GDPR requires.


Cookies

See our separate Cookie Policy for full detail. In short: we do not currently use tracking, analytics, or advertising cookies on the marketing website or inside the application — session login uses local browser storage, not cookies, and is strictly necessary rather than optional.


Changes to this policy

We will post any changes here with an updated "Last updated" date. If a change is material, we will make reasonable efforts to notify active schools directly (e.g. by email) rather than relying on people to check this page on their own.


Contact us

Questions, requests, or concerns about this policy or how we handle personal data: <span class="doc-placeholder">[privacy email]</span>

For urgent issues (suspected data breach, system down affecting live operations), see our Emergency Contact channel, listed separately from general enquiries because it needs a faster response path.


A note on how this document was built

This draft was structured deliberately around GDPR (since the company and its likely first customers are EU-based) rather than adapted from a US-market template, and it only describes what the FlightDesk AI product actually does — no boilerplate about advertising partners, data brokers, or analytics tools that aren't in use. Every <span class="doc-placeholder">[ ]</span> placeholder above is a genuine open question that needs a real decision, not filler text to delete later without reading it.