1. About this notice
Wingcert provides compliance monitoring, safety management and audit software to aviation organisations. Running that service involves handling personal data — about the people who visit this website, the people who use our platform, and the employees, contractors and reporters whose records our customers keep inside it.
This notice explains what we do with that data. It is written to satisfy Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”), and it should be read alongside our Security & Part-IS overview and, if you are a customer, the data processing agreement we enter into with customers.
Your employer decides what personal data goes into Wingcert and why. For records held inside your organisation's workspace, your employer is the controller and we act on its instructions — so requests about that data should go to your employer first. Section 3 explains the split, and we will always help you reach the right party.
2. Who we are and how to contact us
Wingcert provides compliance monitoring, safety management and audit software to aviation organisations.
Wingcert is in the process of being incorporated in Bulgaria. Until that is complete, the individual operating Wingcert is the controller of the personal data described in this notice. This notice will be updated with the company's registered name, number and address once incorporation is complete, and the company will assume the controller role at that point.
We aim to reply within five working days, and in any event within the one month allowed by Article 12(3) GDPR.
Data Protection Officer
We have not appointed a Data Protection Officer, and are not required to. Article 37 GDPR mandates one only for public authorities, for large-scale systematic monitoring of individuals, or for large-scale processing of special categories of data — none of which describes what Wingcert does. Every privacy question is handled at the address above.
Representative in the Union
Once incorporated in Bulgaria, Wingcert will be established in the European Union. A representative under Article 27 GDPR is therefore not required.
3. When we are a controller and when we are a processor
This distinction determines who you should approach about your data, so it matters more than the terminology suggests.
| Situation | Our role | What that means |
|---|---|---|
| You visit wingcert.com or submit the demo form | Controller | We decide why and how your data is used. This notice governs it in full. |
| You administer a customer account, or we correspond with you about billing and support | Controller | We decide how account, billing and support records are handled. |
| Records your organisation stores in its Wingcert workspace — audits, findings, training records, safety reports, documents | Processor | Your organisation is the controller. We act only on its documented instructions under the data processing agreement. Direct your requests to your organisation. |
| Aggregated, de-identified statistics about how the platform is used | Controller | Used to improve the product. Not attributable to any individual. |
4. Personal data we collect
4.1 Website visitors
- Enquiry details you submit through the demo form: name, work email, organisation, role, approval type, organisation size, area of interest and your message.
- Technical data automatically recorded when the form is submitted: IP address, browser user agent, the page you submitted from and the referring page.
- Server logs generated by our hosting provider, containing IP address, timestamp, requested resource and response status.
4.2 Platform users
- Account data: name, work email, job title, organisational role and post-holder assignment, telephone number where provided, and authentication credentials (passwords are stored only as salted hashes).
- Usage and audit trail data: a record of actions taken in the system — who created, viewed, changed, approved or deleted a record, when, and from which IP address. This is a regulatory feature of the product, not optional analytics, and it cannot be disabled.
- Support correspondence and any information you choose to include in it.
- Device and session data: browser, operating system, and — for the mobile field app — device identifier and, where you enable it, the location attached to evidence you capture.
4.3 Data our customers place in the platform
Our customers use Wingcert to keep the records their approvals require. That content is under their control, and it typically includes personal data about their own personnel:
- Names, roles, employee numbers and post-holder nominations
- Licences, type ratings, certifying-staff authorisations, competency assessments and training records — including expiry dates
- Audit records naming auditors, auditees and responsible persons
- Findings and corrective actions naming the owner and the persons involved
- Hazard reports, occurrence reports and safety investigation records
- Signatures, acknowledgements of controlled documents, and photographic evidence captured during audits
Wingcert is not designed as a repository for special categories of personal data under Article 9 GDPR. Customers should not upload medical certificates, health data or similar material unless it is strictly necessary and they have established a lawful basis and an Article 9 condition for doing so.
5. Aviation safety data and just culture
Safety reporting only works when reporters trust it. Where our customers use Wingcert for occurrence reporting and hazard reporting, the records involved are subject to protections that go beyond ordinary data protection law — principally Regulation (EU) No 376/2014 on the reporting, analysis and follow-up of occurrences in civil aviation, which requires that occurrence reports be de-identified and that information sources be protected.
We have built the product accordingly:
- Confidential and, where the customer enables it, anonymous reporting channels are supported as first-class flows.
- Access to reporter identity can be restricted to a named safety manager role, separately from ordinary administrator permissions.
- Every access to a safety report is written to the audit trail, so misuse is visible after the fact.
- Wingcert personnel do not access the content of safety reports except where strictly necessary to provide support that the customer has requested, and never to identify a reporter.
These are technical capabilities. Whether they are configured correctly, and whether a just-culture policy sits behind them, is the customer's responsibility as controller.
6. Why we process personal data, and our legal bases
Where we act as controller, we rely on the following Article 6 GDPR bases.
| Purpose | Legal basis | Notes |
|---|---|---|
| Responding to a demo request or enquiry | Art. 6(1)(b) — steps prior to entering a contract; and Art. 6(1)(f) — legitimate interests | Our interest is in responding to people who have asked to hear from us. |
| Providing the platform to a customer | Art. 6(1)(b) — performance of the contract | Covers account administration, authentication and support. |
| Maintaining the audit trail | Art. 6(1)(f) — legitimate interests; and Art. 6(1)(c) where the customer has a legal obligation | An unalterable record of who did what is the point of a compliance system. |
| Securing the service, detecting and investigating incidents | Art. 6(1)(f) — legitimate interests; Art. 6(1)(c) where security law applies | Includes obligations arising under Part-IS via our customers. |
| Billing, accounting and tax records | Art. 6(1)(c) — legal obligation | Retention is set by applicable accounting law. |
| Improving the product using aggregated usage statistics | Art. 6(1)(f) — legitimate interests | De-identified so that no individual is distinguishable. |
| Sending marketing about our products to business contacts | Art. 6(1)(f) — legitimate interests, or Art. 6(1)(a) — consent where required | You can opt out at any time, in every message and by emailing us. |
| Establishing, exercising or defending legal claims | Art. 6(1)(f) — legitimate interests |
Where we rely on legitimate interests we have carried out a balancing assessment, and you can ask us for a summary of it using the contact details in section 2.
7. Who we share personal data with
We do not sell personal data, and we do not share it for third-party advertising. We disclose it only as follows.
- Sub-processors that help us run the service — hosting, email delivery, error monitoring and support tooling. Each is bound by a written contract meeting Article 28 GDPR. The current list is maintained in our sub-processor list, which we provide to customers.
- Your own organisation. If you use Wingcert through an employer, that organisation's administrators can see your account and activity within its workspace.
- Competent authorities. Where a customer's regulator or EASA exercises a right of access in respect of contracted activities, we will cooperate as required — see Security, section 11 and our customer agreement.
- Professional advisers — lawyers, auditors, accountants and insurers, under duties of confidentiality.
- Public authorities where we are legally required to disclose. We will notify the affected customer unless legally prohibited from doing so.
- An acquirer, if Wingcert is involved in a merger, acquisition or asset sale. We will give notice before your data becomes subject to a different privacy notice.
8. International transfers
We do not transfer personal data outside the European Economic Area.
All customer data is hosted with Amazon Web Services in the eu-west-3 (Paris) region, and Amazon Web Services is currently our only sub-processor. Nothing described in this notice is transferred to, or routinely accessible from, a country outside the EEA.
Because no transfer to a third country takes place, no transfer mechanism under Chapter V GDPR is engaged — no adequacy decision, no Standard Contractual Clauses, no derogation.
Compliance and safety records are among the most sensitive things an operator holds. Keeping them inside a single EEA region removes an entire category of question from your own supplier assessment, and from your competent authority's.
If this ever changes we will update this notice before any transfer begins, name the destination country and the safeguard relied on, and tell affected customers directly.
9. How long we keep personal data
| Data | Retention |
|---|---|
| Demo requests and enquiries that do not become customers | 24 months from last contact, then deleted |
| Customer account and contact records | For the term of the agreement, then 12 months |
| Customer content (audits, findings, documents, records) | Per the customer's instructions; deleted or returned on termination under the data processing agreement |
| Audit trail entries | Retained for the life of the associated record, reflecting the customer's own regulatory retention obligations |
| Information security records | 5 years, aligned with IS.I.OR.245 record-keeping expectations |
| Billing, invoices and accounting records | 10 years, as required by Bulgarian accounting law |
| Server and security logs | 12 months |
| Backups | 35 days, after which they are overwritten on rotation |
Aviation record-keeping obligations frequently run longer than data protection instinct suggests — continuing airworthiness and personnel records in particular. Where a customer instructs us to retain records to meet such an obligation, we will do so.
Deletion from live systems is immediate on instruction. Deletion from backups follows the 35-day rotation above, during which the data remains encrypted and is not processed for any other purpose.
10. How we protect personal data
Our technical and organisational measures are described in full in the Security & Part-IS overview and are given contractual force in the technical and organisational measures in that agreement. In summary: encryption in transit and at rest, per-tenant isolation, role-based access control with multi-factor authentication, least-privilege administrative access, continuous logging and monitoring, and a documented incident response process with defined notification timelines.
11. Your rights
Subject to the conditions in the GDPR, you have the right to:
- be informed about how your data is used — this notice;
- access a copy of your personal data (Art. 15);
- have inaccurate data rectified (Art. 16);
- have data erased in certain circumstances (Art. 17);
- restrict processing in certain circumstances (Art. 18);
- receive your data in a portable format (Art. 20);
- object to processing based on legitimate interests, and to object to direct marketing at any time (Art. 21); and
- withdraw consent where processing is based on it, without affecting prior processing (Art. 7(3)).
Records in Wingcert frequently exist because a regulation requires them, and the audit trail is deliberately unalterable. Where your employer must retain a record under Part-M, Part-145, Part-ORO or similar, the right to erasure will usually be displaced by Article 17(3)(b) — processing necessary for compliance with a legal obligation. Your employer, as controller, makes that assessment.
To exercise a right, email [email protected]. We respond within one month, extendable by two further months for complex requests, and we will tell you if an extension applies. We may ask for information to verify your identity. There is no charge unless a request is manifestly unfounded or excessive.
If your request concerns data held inside a customer's workspace, we will forward it to that customer and confirm to you that we have done so.
12. Cookies and similar technologies
This website sets no advertising or third-party tracking cookies, loads no external fonts or scripts, and embeds no content from other sites.
The Wingcert platform sets a small number of strictly necessary cookies — a session cookie to keep you signed in, and a CSRF token to protect forms against cross-site request forgery. These are exempt from the consent requirement in Article 5(3) of the ePrivacy Directive because the service cannot function without them.
We use no analytics, advertising or tracking technology of any kind. That is why you were not asked to accept cookies when you arrived: there is nothing to consent to. If we ever introduce analytics, we will list each cookie here with its purpose and lifetime, and ask for your consent before setting any of them.
13. Automated decision-making
We do not make decisions producing legal or similarly significant effects about individuals by automated means within the meaning of Article 22 GDPR.
The platform does generate automated alerts — for instance when a qualification is approaching expiry or a corrective action passes its due date. These prompt a human to act; they do not themselves decide anything about a person.
14. Children
Wingcert is a business tool sold to aviation organisations and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
15. Changes to this notice
We may update this notice as the service or the law changes. The version number and “last updated” date at the top always reflect the current text.
For material changes we will give customers at least 30 days' notice by email or in-product before the change takes effect. Corrections that do not change how we use personal data — a clearer sentence, a corrected typo — take effect immediately.
16. Contact and complaints
Please raise any concern with us first — most are resolved quickly at [email protected].
You also have the right to lodge a complaint with a supervisory authority in the EU or EEA state where you live, where you work, or where you believe an infringement occurred. You do not have to come to us first.
Once Wingcert's incorporation in Bulgaria is complete, our lead supervisory authority will be the Commission for Personal Data Protection (Комисия за защита на личните данни), the Bulgarian data protection authority, at www.cpdp.bg.
Back to top