1. Scope and accountability
This Policy applies to AeroOps websites, applications, support, subscriptions, and services that link to it. AeroOps is accountable for personal information under its control and designates a Privacy Officer who can be contacted at support@aeroops.ca.
For account, billing, website, security, and direct support information, AeroOps determines the processing purposes. For records entered into an organization workspace, the organization generally determines why the information is collected and who may use it, while AeroOps processes it to provide the service. Requests concerning organization-controlled records may be referred to that organization.
2. Information we collect
- Identity and account data, including name, email, profile image, authentication identifiers, age or date of birth where relevant, organization, role, qualifications, licences, ratings, and permissions.
- Aviation and professional records, including flights, routes, OOOI times, aircraft, crew, passengers, training, exams, flight tests, recommendations, authorizations, recency, medical-expiry details, schedules, duty, maintenance, safety, quality, licensing, and operational records.
- Documents and content, including written-examination results, flight-test reports, logbook pages, uploads, signatures, comments, messages, social posts, support requests, invoices, receipts, accounting records, calendar data, OCR text, AI-extracted fields, generated forms, and backup metadata.
- Location and sensor-derived data when enabled, including device location, map selections, aircraft positions, routes, weather proximity, and safety-report locations.
- Transaction data, including plan, subscription, referral, invoice, payment status, tax jurisdiction, and limited payment metadata. Complete card numbers are handled by the payment processor and are not stored by AeroOps.
- Technical and usage data, including IP address, device and browser information, timestamps, pages and features used, API activity, diagnostics, audit history, security events, cookies, and similar technologies.
- Integration data received from services you connect or ask us to query, such as calendars, cloud storage, identity providers, maps, weather, aviation-data providers, and government or public sources.
3. Sources of information
We receive information directly from you; from your employer, instructor, school, club, operator, administrator, or another authorized User; from imported files and connected services; from payment and identity providers; from public or licensed aviation sources; and automatically when the service is used.
Organizations must provide required notices and obtain required authority before adding another person’s information. If you believe an organization entered your information without authority, contact that organization and AeroOps.
4. Purposes for collection and use
- Create accounts, authenticate Users, administer tenants and permissions, provide requested platforms, and personalize settings.
- Maintain aviation records, generate reports and forms, perform calculations and analytics, provide SmartImport document extraction, synchronize schedules, and operate enabled workflows.
- Process subscriptions, invoices, payments, referrals, trials, taxes, account recovery, service notices, and Customer support.
- Monitor reliability, measure usage, enforce plan and API limits, troubleshoot, prevent fraud and abuse, investigate incidents, protect people and systems, and maintain audit trails.
- Improve and develop the service using aggregated, de-identified, or appropriately authorized information. We do not use Customer confidential records to train a general-purpose public AI model without express permission.
- Comply with legal obligations, lawful process, regulatory requests, safety requirements, and the establishment, exercise, or defence of legal claims.
- Send product and marketing communications where consent or another lawful basis exists. Operational and account messages may still be sent when necessary to provide the service.
5. Consent and choices
Consent may be express or implied depending on the sensitivity of the information and the circumstances. You may withdraw consent to optional processing, subject to legal or contractual restrictions and reasonable notice. Withdrawal may prevent a feature or the service from functioning.
Before using SmartImport, the User must choose a protection option and provide the acknowledgement shown at upload. The User confirms that they own the document or are otherwise authorized to process it and permits the selected processing.
You can configure profile visibility, social sharing, location access, notifications, integrations, calendar links, and backups where those controls are offered. Marketing messages include an unsubscribe method. Browser and device controls can restrict cookies or location, although some functionality may be affected.
6. Disclosure and service providers
We disclose information to authorized Users in the applicable workspace and to providers that perform hosting, databases, authentication, payments, email, monitoring, support, mapping, weather, aviation data, OCR, artificial-intelligence processing, analytics, storage, calendar, and security functions. Providers receive only information reasonably required for their function and are subject to contractual or other safeguards where appropriate.
OpenAI provides the artificial-intelligence processing used by SmartImport. The protection option presented at upload determines which AeroOps OpenAI project receives the document and whether that project permits OpenAI data sharing. AeroOps does not send a document through SmartImport until the User makes the required acknowledgement.
We may disclose information with your direction or consent; to complete a transaction; during a corporate financing, reorganization, merger, acquisition, or sale subject to appropriate protections; to investigate fraud, abuse, or a safety or security threat; or where required or permitted by law. We do not sell personal information for money.
Information shared through a public or friends-only social feature is visible according to the privacy setting selected by the User. Users should not publish sensitive operational, passenger, employment, or safety information in social features.
7. International and cross-border processing
AeroOps and its providers may process or store information outside your province or Canada. While information is in another jurisdiction, it may be accessible to courts, law enforcement, national-security authorities, or regulators under that jurisdiction’s laws.
AeroOps remains accountable for personal information under its control and assesses providers and safeguards in light of the information’s sensitivity. An organization may configure or contract for additional requirements where available.
8. SmartImport
SmartImport offers Advanced Document Protection and Standard Protection. Advanced Document Protection uses a separately credentialed OpenAI project configured by AeroOps for no input/output sharing and an approved zero-data-retention control. AeroOps sends document-page images for extraction with API response storage disabled. A configuration failure causes this option to stop rather than fall back to Standard Protection.
Standard Protection uses the standard AeroOps OpenAI project. If that project is enrolled in OpenAI input-and-output sharing, the submitted document and generated output may be retained and used by OpenAI as described in OpenAI’s applicable data-sharing terms. The User must expressly acknowledge the selected protection option before upload.
Manual Import does not send the document to OpenAI. When a User attaches an original document to an AeroOps record, AeroOps may still store that attachment in its application storage until it is deleted or reaches the applicable retention period.
AeroOps records a minimal authorization audit for SmartImport, including the User, selected protection option, policy version, time, page count, and a one-way document hash. The audit record does not contain the document image or extracted text.
9. Accuracy, automated processing, and OCR
Users and organizations are responsible for keeping submitted information accurate. AeroOps may normalize, calculate, infer, cache, transcribe, or extract information to provide features. Automated matching, OCR, risk scoring, weather interpretation, projections, and generated documents may be incorrect and must be reviewed by an authorized person.
AeroOps does not make final licensing, employment, training, medical, safety, credit, or regulatory decisions about individuals. Organizations are responsible for human review, lawful decision-making, and providing any required explanation or appeal process.
10. Retention
We retain information only as long as reasonably required for the identified purposes, Customer instructions, account administration, safety and regulatory records, billing and tax obligations, security, fraud prevention, backups, dispute resolution, and legal requirements. Different record categories have different retention periods.
When information is no longer required, it is deleted, securely disposed of, or de-identified, subject to technical backup cycles and legal holds. AI-provider retention depends on the SmartImport protection option selected at upload and the provider controls described in section 8. Closing an account does not necessarily delete records controlled by an organization or records that must be retained. Users should export records they are legally required to keep before access ends.
11. Safeguards and incidents
AeroOps uses administrative, technical, and physical safeguards appropriate to the sensitivity of information, including access controls, tenant boundaries, encryption in transit, restricted administrative access, logging, backups, and security monitoring. No system, transmission, or storage method is completely secure, and AeroOps cannot guarantee absolute security.
Users must protect credentials, devices, exports, calendar links, API keys, and shared files and promptly report suspected misuse. Where required, AeroOps will assess security incidents, keep required records, notify affected individuals or organizations, and report qualifying breaches to the appropriate authority.
12. Individual rights and requests
Subject to applicable law, you may request information about our handling practices and seek access to or correction of personal information under AeroOps’s control. You may also request export, deletion, consent withdrawal, or restriction where available. We may verify identity, refer organization-controlled requests to the organization, charge a lawful minimal fee, or refuse a request where permitted by law, with an explanation.
If a concern is not resolved, you may contact the Office of the Privacy Commissioner of Canada or the applicable provincial privacy authority. Contact support@aeroops.ca with “Privacy” in the subject line to reach the Privacy Officer.
13. Children and student accounts
AeroOps is not directed to children for independent consumer use. An organization may create or manage a student account for a minor only where it has appropriate authority and provides the supervision, notices, and consent required by law. We may request confirmation of age or authority and may restrict or remove an account where those requirements are not met.
14. Changes to this Policy
We may update this Policy as the service, providers, or legal requirements change. The effective date and version identify the current revision. Material changes will be communicated through the service, email, or another reasonable method, and fresh consent will be requested where required by law.