1. About this notice
Wingcert provides compliance monitoring, safety management and audit software to aviation organisations. Running that service involves handling personal data — about the people who visit this website, the people who use our platform, and the employees, contractors and reporters whose records our customers keep inside it.
This notice explains what we do with that data. It is written to satisfy Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”), and it should be read alongside our Security & Part-IS overview and, if you are a customer, the Data Processing Agreement.
Your employer decides what personal data goes into Wingcert and why. For records held inside your organisation's workspace, your employer is the controller and we act on its instructions — so requests about that data should go to your employer first. Section 3 explains the split, and we will always help you reach the right party.
2. Who we are and how to contact us
[Legal entity name], a company registered in [country] under company number [registration number], with its registered office at [registered address], trading as Wingcert (“Wingcert”, “we”, “us”).
Email: [email protected]
3. When we are a controller and when we are a processor
This distinction determines who you should approach about your data, so it matters more than the terminology suggests.
| Situation | Our role | What that means |
|---|---|---|
| You visit wingcert.com or submit the demo form | Controller | We decide why and how your data is used. This notice governs it in full. |
| You administer a customer account, or we correspond with you about billing and support | Controller | We decide how account, billing and support records are handled. |
| Records your organisation stores in its Wingcert workspace — audits, findings, training records, safety reports, documents | Processor | Your organisation is the controller. We act only on its documented instructions under the DPA. Direct your requests to your organisation. |
| Aggregated, de-identified statistics about how the platform is used | Controller | Used to improve the product. Not attributable to any individual. |
4. Personal data we collect
4.1 Website visitors
- Enquiry details you submit through the demo form: name, work email, organisation, role, approval type, organisation size, area of interest and your message.
- Technical data automatically recorded when the form is submitted: IP address, browser user agent, the page you submitted from and the referring page.
- Server logs generated by our hosting provider, containing IP address, timestamp, requested resource and response status.
4.2 Platform users
- Account data: name, work email, job title, organisational role and post-holder assignment, telephone number where provided, and authentication credentials (passwords are stored only as salted hashes).
- Usage and audit trail data: a record of actions taken in the system — who created, viewed, changed, approved or deleted a record, when, and from which IP address. This is a regulatory feature of the product, not optional analytics, and it cannot be disabled.
- Support correspondence and any information you choose to include in it.
- Device and session data: browser, operating system, and — for the mobile field app — device identifier and, where you enable it, the location attached to evidence you capture.
4.3 Data our customers place in the platform
Our customers use Wingcert to keep the records their approvals require. That content is under their control, and it typically includes personal data about their own personnel:
- Names, roles, employee numbers and post-holder nominations
- Licences, type ratings, certifying-staff authorisations, competency assessments and training records — including expiry dates
- Audit records naming auditors, auditees and responsible persons
- Findings and corrective actions naming the owner and the persons involved
- Hazard reports, occurrence reports and safety investigation records
- Signatures, acknowledgements of controlled documents, and photographic evidence captured during audits
Wingcert is not designed as a repository for special categories of personal data under Article 9 GDPR. Customers should not upload medical certificates, health data or similar material unless it is strictly necessary and they have established a lawful basis and an Article 9 condition for doing so.
5. Aviation safety data and just culture
Safety reporting only works when reporters trust it. Where our customers use Wingcert for occurrence reporting and hazard reporting, the records involved are subject to protections that go beyond ordinary data protection law — principally Regulation (EU) No 376/2014 on the reporting, analysis and follow-up of occurrences in civil aviation, which requires that occurrence reports be de-identified and that information sources be protected.
We have built the product accordingly:
- Confidential and, where the customer enables it, anonymous reporting channels are supported as first-class flows.
- Access to reporter identity can be restricted to a named safety manager role, separately from ordinary administrator permissions.
- Every access to a safety report is written to the audit trail, so misuse is visible after the fact.
- Wingcert personnel do not access the content of safety reports except where strictly necessary to provide support that the customer has requested, and never to identify a reporter.
These are technical capabilities. Whether they are configured correctly, and whether a just-culture policy sits behind them, is the customer's responsibility as controller.
6. Why we process personal data, and our legal bases
Where we act as controller, we rely on the following Article 6 GDPR bases.
| Purpose | Legal basis | Notes |
|---|---|---|
| Responding to a demo request or enquiry | Art. 6(1)(b) — steps prior to entering a contract; and Art. 6(1)(f) — legitimate interests | Our interest is in responding to people who have asked to hear from us. |
| Providing the platform to a customer | Art. 6(1)(b) — performance of the contract | Covers account administration, authentication and support. |
| Maintaining the audit trail | Art. 6(1)(f) — legitimate interests; and Art. 6(1)(c) where the customer has a legal obligation | An unalterable record of who did what is the point of a compliance system. |
| Securing the service, detecting and investigating incidents | Art. 6(1)(f) — legitimate interests; Art. 6(1)(c) where security law applies | Includes obligations arising under Part-IS via our customers. |
| Billing, accounting and tax records | Art. 6(1)(c) — legal obligation | Retention is set by applicable accounting law. |
| Improving the product using aggregated usage statistics | Art. 6(1)(f) — legitimate interests | De-identified so that no individual is distinguishable. |
| Sending marketing about our products to business contacts | Art. 6(1)(f) — legitimate interests, or Art. 6(1)(a) — consent where required | You can opt out at any time, in every message and by emailing us. |
| Establishing, exercising or defending legal claims | Art. 6(1)(f) — legitimate interests |
Where we rely on legitimate interests we have carried out a balancing assessment, and you can ask us for a summary of it using the contact details in section 2.
7. Who we share personal data with
We do not sell personal data, and we do not share it for third-party advertising. We disclose it only as follows.
- Sub-processors that help us run the service — hosting, email delivery, error monitoring and support tooling. Each is bound by a written contract meeting Article 28 GDPR. The current list is maintained in Annex III of the DPA.
- Your own organisation. If you use Wingcert through an employer, that organisation's administrators can see your account and activity within its workspace.
- Competent authorities. Where a customer's regulator or EASA exercises a right of access in respect of contracted activities, we will cooperate as required — see Security, section 11 and Terms, clause 11.
- Professional advisers — lawyers, auditors, accountants and insurers, under duties of confidentiality.
- Public authorities where we are legally required to disclose. We will notify the affected customer unless legally prohibited from doing so.
- An acquirer, if Wingcert is involved in a merger, acquisition or asset sale. We will give notice before your data becomes subject to a different privacy notice.
8. International transfers
Customer data is hosted in the European Union by default. Where personal data is transferred outside the EEA — for example to a support or monitoring provider — we rely on one of the following:
- an adequacy decision by the European Commission under Article 45 GDPR;
- the Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), supported by a transfer impact assessment and, where required, supplementary technical measures; or
- another lawful transfer mechanism under Chapter V GDPR.
You can request a copy of the relevant safeguards from [email protected]. Enterprise customers may require that no processing take place outside a named region; see clause [x] of the Terms.
9. How long we keep personal data
| Data | Retention |
|---|---|
| Demo requests and enquiries that do not become customers | [24] months from last contact, then deleted |
| Customer account and contact records | For the term of the agreement, then [12] months |
| Customer content (audits, findings, documents, records) | Per the customer's instructions; deleted or returned on termination per the DPA |
| Audit trail entries | Retained for the life of the associated record, reflecting the customer's regulatory retention obligations |
| Information security records | [5] years, aligned with IS.I.OR.245 record-keeping expectations |
| Billing, invoices and accounting records | As required by applicable tax law — typically [7] years |
| Server and security logs | [12] months |
| Backups | [35] days, after which they are overwritten on rotation |
Aviation record-keeping obligations frequently run longer than data protection instinct suggests — continuing airworthiness and personnel records in particular. Where a customer instructs us to retain records to meet such an obligation, we will do so.
Deletion from live systems is immediate on instruction; deletion from backups follows the rotation cycle above, during which the data remains encrypted and is not accessible for ordinary processing.
10. How we protect personal data
Our technical and organisational measures are described in full in the Security & Part-IS overview and are given contractual force in Annex II of the DPA. In summary: encryption in transit and at rest, per-tenant isolation, role-based access control with multi-factor authentication, least-privilege administrative access, continuous logging and monitoring, and a documented incident response process with defined notification timelines.
11. Your rights
Subject to the conditions in the GDPR, you have the right to:
- be informed about how your data is used — this notice;
- access a copy of your personal data (Art. 15);
- have inaccurate data rectified (Art. 16);
- have data erased in certain circumstances (Art. 17);
- restrict processing in certain circumstances (Art. 18);
- receive your data in a portable format (Art. 20);
- object to processing based on legitimate interests, and to object to direct marketing at any time (Art. 21); and
- withdraw consent where processing is based on it, without affecting prior processing (Art. 7(3)).
Records in Wingcert frequently exist because a regulation requires them, and the audit trail is deliberately unalterable. Where your employer must retain a record under Part-M, Part-145, Part-ORO or similar, the right to erasure will usually be displaced by Article 17(3)(b) — processing necessary for compliance with a legal obligation. Your employer, as controller, makes that assessment.
To exercise a right, email [email protected]. We respond within one month, extendable by two further months for complex requests, and we will tell you if an extension applies. We may ask for information to verify your identity. There is no charge unless a request is manifestly unfounded or excessive.
If your request concerns data held inside a customer's workspace, we will forward it to that customer and confirm to you that we have done so.
12. Cookies and similar technologies
This website sets no advertising or third-party tracking cookies, loads no external fonts or scripts, and does not embed content from other sites.
The Wingcert platform sets a small number of strictly necessary cookies — a session cookie to keep you signed in, and a CSRF token to protect forms against cross-site request forgery. These are exempt from the consent requirement in Article 5(3) of the ePrivacy Directive because the service cannot function without them.
[If analytics are added later, list each cookie here with its purpose and lifetime, and implement a consent banner before setting any non-essential cookie. Delete this bracketed paragraph once resolved.]
13. Automated decision-making
We do not make decisions producing legal or similarly significant effects about individuals by automated means within the meaning of Article 22 GDPR.
The platform does generate automated alerts — for instance when a qualification is approaching expiry or a corrective action passes its due date. These prompt a human to act; they do not themselves decide anything about a person.
14. Children
Wingcert is a business tool sold to aviation organisations and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
15. Changes to this notice
We may update this notice as the service or the law changes. The version number and “last updated” date at the top always reflect the current text. For material changes we will give customers at least [30] days' notice by email or in-product before the change takes effect.
16. Contact and complaints
Please raise any concern with us first — most issues are resolved quickly at [email protected].
You also have the right to lodge a complaint with a supervisory authority in the EU or EEA state where you live, work, or where you believe an infringement occurred. Our lead supervisory authority is [name of supervisory authority and its website].
Back to top