Skip to content
Wingcert Wingcert
Platform Modules Product In the field Pricing FAQ
Sign in Request a demo
Platform Modules Product In the field Pricing FAQ Sign in Request a demo
Legal

Privacy Notice

How Wingcert collects, uses, shares and protects personal data — on this website, in the Wingcert platform, and in the records our customers entrust to us.

Version
1.0
Effective from
15 August 2026
Last updated
15 August 2026
Applies to
wingcert.com and all Wingcert workspaces
Privacy Notice Security & Part-IS

Contents

  1. 1. About this notice
  2. 2. Who we are
  3. 3. Controller or processor
  4. 4. Personal data we collect
  5. 5. Aviation safety data & just culture
  6. 6. Purposes and legal bases
  7. 7. Who we share data with
  8. 8. International transfers
  9. 9. How long we keep data
  10. 10. How we protect data
  11. 11. Your rights
  12. 12. Cookies
  13. 13. Automated decision-making
  14. 14. Children
  15. 15. Changes to this notice
  16. 16. Contact and complaints

1. About this notice

Wingcert provides compliance monitoring, safety management and audit software to aviation organisations. Running that service involves handling personal data — about the people who visit this website, the people who use our platform, and the employees, contractors and reporters whose records our customers keep inside it.

This notice explains what we do with that data. It is written to satisfy Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”), and it should be read alongside our Security & Part-IS overview and, if you are a customer, the data processing agreement we enter into with customers.

If you are an employee of a Wingcert customer

Your employer decides what personal data goes into Wingcert and why. For records held inside your organisation's workspace, your employer is the controller and we act on its instructions — so requests about that data should go to your employer first. Section 3 explains the split, and we will always help you reach the right party.

2. Who we are and how to contact us

Wingcert provides compliance monitoring, safety management and audit software to aviation organisations.

Wingcert is in the process of being incorporated in Bulgaria. Until that is complete, the individual operating Wingcert is the controller of the personal data described in this notice. This notice will be updated with the company's registered name, number and address once incorporation is complete, and the company will assume the controller role at that point.

Privacy enquiries Email: [email protected]
We aim to reply within five working days, and in any event within the one month allowed by Article 12(3) GDPR.

Data Protection Officer

We have not appointed a Data Protection Officer, and are not required to. Article 37 GDPR mandates one only for public authorities, for large-scale systematic monitoring of individuals, or for large-scale processing of special categories of data — none of which describes what Wingcert does. Every privacy question is handled at the address above.

Representative in the Union

Once incorporated in Bulgaria, Wingcert will be established in the European Union. A representative under Article 27 GDPR is therefore not required.

3. When we are a controller and when we are a processor

This distinction determines who you should approach about your data, so it matters more than the terminology suggests.

SituationOur roleWhat that means
You visit wingcert.com or submit the demo form Controller We decide why and how your data is used. This notice governs it in full.
You administer a customer account, or we correspond with you about billing and support Controller We decide how account, billing and support records are handled.
Records your organisation stores in its Wingcert workspace — audits, findings, training records, safety reports, documents Processor Your organisation is the controller. We act only on its documented instructions under the data processing agreement. Direct your requests to your organisation.
Aggregated, de-identified statistics about how the platform is used Controller Used to improve the product. Not attributable to any individual.

4. Personal data we collect

4.1 Website visitors

  • Enquiry details you submit through the demo form: name, work email, organisation, role, approval type, organisation size, area of interest and your message.
  • Technical data automatically recorded when the form is submitted: IP address, browser user agent, the page you submitted from and the referring page.
  • Server logs generated by our hosting provider, containing IP address, timestamp, requested resource and response status.

4.2 Platform users

  • Account data: name, work email, job title, organisational role and post-holder assignment, telephone number where provided, and authentication credentials (passwords are stored only as salted hashes).
  • Usage and audit trail data: a record of actions taken in the system — who created, viewed, changed, approved or deleted a record, when, and from which IP address. This is a regulatory feature of the product, not optional analytics, and it cannot be disabled.
  • Support correspondence and any information you choose to include in it.
  • Device and session data: browser, operating system, and — for the mobile field app — device identifier and, where you enable it, the location attached to evidence you capture.

4.3 Data our customers place in the platform

Our customers use Wingcert to keep the records their approvals require. That content is under their control, and it typically includes personal data about their own personnel:

  • Names, roles, employee numbers and post-holder nominations
  • Licences, type ratings, certifying-staff authorisations, competency assessments and training records — including expiry dates
  • Audit records naming auditors, auditees and responsible persons
  • Findings and corrective actions naming the owner and the persons involved
  • Hazard reports, occurrence reports and safety investigation records
  • Signatures, acknowledgements of controlled documents, and photographic evidence captured during audits

Wingcert is not designed as a repository for special categories of personal data under Article 9 GDPR. Customers should not upload medical certificates, health data or similar material unless it is strictly necessary and they have established a lawful basis and an Article 9 condition for doing so.

5. Aviation safety data and just culture

Safety reporting only works when reporters trust it. Where our customers use Wingcert for occurrence reporting and hazard reporting, the records involved are subject to protections that go beyond ordinary data protection law — principally Regulation (EU) No 376/2014 on the reporting, analysis and follow-up of occurrences in civil aviation, which requires that occurrence reports be de-identified and that information sources be protected.

We have built the product accordingly:

  • Confidential and, where the customer enables it, anonymous reporting channels are supported as first-class flows.
  • Access to reporter identity can be restricted to a named safety manager role, separately from ordinary administrator permissions.
  • Every access to a safety report is written to the audit trail, so misuse is visible after the fact.
  • Wingcert personnel do not access the content of safety reports except where strictly necessary to provide support that the customer has requested, and never to identify a reporter.

These are technical capabilities. Whether they are configured correctly, and whether a just-culture policy sits behind them, is the customer's responsibility as controller.

6. Why we process personal data, and our legal bases

Where we act as controller, we rely on the following Article 6 GDPR bases.

PurposeLegal basisNotes
Responding to a demo request or enquiry Art. 6(1)(b) — steps prior to entering a contract; and Art. 6(1)(f) — legitimate interests Our interest is in responding to people who have asked to hear from us.
Providing the platform to a customer Art. 6(1)(b) — performance of the contract Covers account administration, authentication and support.
Maintaining the audit trail Art. 6(1)(f) — legitimate interests; and Art. 6(1)(c) where the customer has a legal obligation An unalterable record of who did what is the point of a compliance system.
Securing the service, detecting and investigating incidents Art. 6(1)(f) — legitimate interests; Art. 6(1)(c) where security law applies Includes obligations arising under Part-IS via our customers.
Billing, accounting and tax records Art. 6(1)(c) — legal obligation Retention is set by applicable accounting law.
Improving the product using aggregated usage statistics Art. 6(1)(f) — legitimate interests De-identified so that no individual is distinguishable.
Sending marketing about our products to business contacts Art. 6(1)(f) — legitimate interests, or Art. 6(1)(a) — consent where required You can opt out at any time, in every message and by emailing us.
Establishing, exercising or defending legal claims Art. 6(1)(f) — legitimate interests

Where we rely on legitimate interests we have carried out a balancing assessment, and you can ask us for a summary of it using the contact details in section 2.

7. Who we share personal data with

We do not sell personal data, and we do not share it for third-party advertising. We disclose it only as follows.

  • Sub-processors that help us run the service — hosting, email delivery, error monitoring and support tooling. Each is bound by a written contract meeting Article 28 GDPR. The current list is maintained in our sub-processor list, which we provide to customers.
  • Your own organisation. If you use Wingcert through an employer, that organisation's administrators can see your account and activity within its workspace.
  • Competent authorities. Where a customer's regulator or EASA exercises a right of access in respect of contracted activities, we will cooperate as required — see Security, section 11 and our customer agreement.
  • Professional advisers — lawyers, auditors, accountants and insurers, under duties of confidentiality.
  • Public authorities where we are legally required to disclose. We will notify the affected customer unless legally prohibited from doing so.
  • An acquirer, if Wingcert is involved in a merger, acquisition or asset sale. We will give notice before your data becomes subject to a different privacy notice.

8. International transfers

We do not transfer personal data outside the European Economic Area.

All customer data is hosted with Amazon Web Services in the eu-west-3 (Paris) region, and Amazon Web Services is currently our only sub-processor. Nothing described in this notice is transferred to, or routinely accessible from, a country outside the EEA.

Because no transfer to a third country takes place, no transfer mechanism under Chapter V GDPR is engaged — no adequacy decision, no Standard Contractual Clauses, no derogation.

Why this matters for an aviation buyer

Compliance and safety records are among the most sensitive things an operator holds. Keeping them inside a single EEA region removes an entire category of question from your own supplier assessment, and from your competent authority's.

If this ever changes we will update this notice before any transfer begins, name the destination country and the safeguard relied on, and tell affected customers directly.

9. How long we keep personal data

DataRetention
Demo requests and enquiries that do not become customers24 months from last contact, then deleted
Customer account and contact recordsFor the term of the agreement, then 12 months
Customer content (audits, findings, documents, records)Per the customer's instructions; deleted or returned on termination under the data processing agreement
Audit trail entriesRetained for the life of the associated record, reflecting the customer's own regulatory retention obligations
Information security records5 years, aligned with IS.I.OR.245 record-keeping expectations
Billing, invoices and accounting records10 years, as required by Bulgarian accounting law
Server and security logs12 months
Backups35 days, after which they are overwritten on rotation

Aviation record-keeping obligations frequently run longer than data protection instinct suggests — continuing airworthiness and personnel records in particular. Where a customer instructs us to retain records to meet such an obligation, we will do so.

Deletion from live systems is immediate on instruction. Deletion from backups follows the 35-day rotation above, during which the data remains encrypted and is not processed for any other purpose.

10. How we protect personal data

Our technical and organisational measures are described in full in the Security & Part-IS overview and are given contractual force in the technical and organisational measures in that agreement. In summary: encryption in transit and at rest, per-tenant isolation, role-based access control with multi-factor authentication, least-privilege administrative access, continuous logging and monitoring, and a documented incident response process with defined notification timelines.

11. Your rights

Subject to the conditions in the GDPR, you have the right to:

  1. be informed about how your data is used — this notice;
  2. access a copy of your personal data (Art. 15);
  3. have inaccurate data rectified (Art. 16);
  4. have data erased in certain circumstances (Art. 17);
  5. restrict processing in certain circumstances (Art. 18);
  6. receive your data in a portable format (Art. 20);
  7. object to processing based on legitimate interests, and to object to direct marketing at any time (Art. 21); and
  8. withdraw consent where processing is based on it, without affecting prior processing (Art. 7(3)).
Erasure has limits in a compliance system

Records in Wingcert frequently exist because a regulation requires them, and the audit trail is deliberately unalterable. Where your employer must retain a record under Part-M, Part-145, Part-ORO or similar, the right to erasure will usually be displaced by Article 17(3)(b) — processing necessary for compliance with a legal obligation. Your employer, as controller, makes that assessment.

To exercise a right, email [email protected]. We respond within one month, extendable by two further months for complex requests, and we will tell you if an extension applies. We may ask for information to verify your identity. There is no charge unless a request is manifestly unfounded or excessive.

If your request concerns data held inside a customer's workspace, we will forward it to that customer and confirm to you that we have done so.

12. Cookies and similar technologies

This website sets no advertising or third-party tracking cookies, loads no external fonts or scripts, and embeds no content from other sites.

The Wingcert platform sets a small number of strictly necessary cookies — a session cookie to keep you signed in, and a CSRF token to protect forms against cross-site request forgery. These are exempt from the consent requirement in Article 5(3) of the ePrivacy Directive because the service cannot function without them.

We use no analytics, advertising or tracking technology of any kind. That is why you were not asked to accept cookies when you arrived: there is nothing to consent to. If we ever introduce analytics, we will list each cookie here with its purpose and lifetime, and ask for your consent before setting any of them.

13. Automated decision-making

We do not make decisions producing legal or similarly significant effects about individuals by automated means within the meaning of Article 22 GDPR.

The platform does generate automated alerts — for instance when a qualification is approaching expiry or a corrective action passes its due date. These prompt a human to act; they do not themselves decide anything about a person.

14. Children

Wingcert is a business tool sold to aviation organisations and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

15. Changes to this notice

We may update this notice as the service or the law changes. The version number and “last updated” date at the top always reflect the current text.

For material changes we will give customers at least 30 days' notice by email or in-product before the change takes effect. Corrections that do not change how we use personal data — a clearer sentence, a corrected typo — take effect immediately.

16. Contact and complaints

Please raise any concern with us first — most are resolved quickly at [email protected].

You also have the right to lodge a complaint with a supervisory authority in the EU or EEA state where you live, where you work, or where you believe an infringement occurred. You do not have to come to us first.

Once Wingcert's incorporation in Bulgaria is complete, our lead supervisory authority will be the Commission for Personal Data Protection (Комисия за защита на личните данни), the Bulgarian data protection authority, at www.cpdp.bg.

Back to top
Back to top
© 2026 Wingcert. All rights reserved.
Home Privacy Notice Security & Part-IS