Privacy Policy
Last Updated: October 12, 2024
1. Introduction
Aviamatic LLC ("Aviamatic," "we," "us," or "our") is committed to protecting the privacy and security of the personal data we process. This Privacy Policy explains how we collect, use, and disclose information when you use our aviation maintenance tool control software (the "Service") and our website.
2. Our Role: Data Processor vs. Data Controller
In the context of providing the Service to our B2B customers (aviation maintenance organizations), Aviamatic acts as a Data Processor. Our customers are the Data Controllers. This means we process personal data (such as employee names, badge IDs, and tool custody records) solely on behalf of our customers and in accordance with their instructions, as defined in our Data Processing Agreements (DPA).
3. Information We Collect
We may collect and process the following categories of data:
- Customer Account Data: Names, email addresses, billing information, and contact details of our customers' authorized administrators.
- End-User Data: Names, employee IDs, badge numbers, and system activity logs (e.g., tool checkout events, locations, and timestamps) of mechanics and staff using the Service.
- Usage Data: Information about how the Service is accessed and used, including IP addresses, browser types, and diagnostic telemetry to ensure platform stability.
4. How We Use Information
As a Data Processor, we use the collected information strictly to:
- Provide, operate, and maintain the Service.
- Authenticate users and enforce security policies (e.g., role-based access).
- Generate audit trails and evidence required for aviation compliance (e.g., EASA Part-145).
- Provide technical support and improve the reliability of the platform.
5. Data Sharing and Sub-processors
We do not sell personal data. We may share information with trusted third-party service providers (Sub-processors) who assist us in operating our platform (e.g., cloud hosting providers like AWS or GCP). All Sub-processors are bound by strict confidentiality and data protection obligations compatible with GDPR and applicable US privacy laws.
6. Data Security and Retention
We implement robust technical and organizational measures designed to secure personal data against unauthorized access, loss, or alteration. Data is retained only as long as necessary to provide the Service to our customers or to comply with legal obligations. Upon termination of a customer contract, we will delete or return all personal data as directed by the Data Controller.
7. Your Privacy Rights
Depending on your location (e.g., under the GDPR, CCPA, or Delaware Personal Data Privacy Act), you may have rights to access, correct, delete, or restrict the processing of your personal data. Because we process end-user data on behalf of our customers, individuals seeking to exercise these rights should direct their requests to their employer (the Data Controller). We will assist our customers in responding to such requests.
8. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us at:
Aviamatic LLC
Email: privacy@aviamatic.com