Global aviation AOG network
Legal

Privacy Policy

What personal data AOG Hub processes, why, and what rights you have over it. Two systems are involved and they are genuinely different: this website, which is static, and the platform, where accounts and cases live.

This document is in preparation

AOG Hub is being built, and its legal documents are being drafted with counsel rather than assembled from a template. This page sets out what the finished document will cover so that nothing about it is a surprise. For the terms currently in force for your organization - including anything a procurement or data-protection review needs - write to us and we will send them.

Write to us for the current document

This website

The site you are reading is a set of static files. It has no server-side code, makes no call to any API, and loads nothing from another host - no analytics, no tag manager, no embedded fonts or scripts from elsewhere. It therefore collects nothing about you, sets no cookies and builds no profile. Ordinary web-server access logs are kept by the hosting provider, as they are for every website.

The one way this site receives personal data is if you write to the address published on it. That correspondence is read by a person and kept for as long as it takes to answer you and to keep a record of what was agreed.

The platform

Signing in, organization records, members, cases, messages and calls are handled on the AOG HUB platform, which is a different system on a different host. That is where personal data is actually processed - names, business contact details, the organization somebody acts for, and the record of cases they took part in.

Two things about it are worth stating here, because they are load-bearing product decisions and not policy language: routing a message requires knowing that it went from one organization to another and how large it was, and it has never required knowing what the message said. And response times are computed from delivery timestamps alone, with no message content involved.

What the finished document will cover

  • Controller and contact - who is responsible, and how to reach the person who deals with data protection.
  • Categories of data - business contact data, account and authentication data, organization records, case and message metadata, and message content.
  • Purposes and legal bases - operating the network, routing and delivering messages, security, and the legitimate interest in a directory of organizations.
  • Directory listings - why an organization can appear before anybody there has an account, what is published, and how a listing is corrected or challenged.
  • Recipients - the organizations you communicate with, hosting and infrastructure providers, and nobody else.
  • Messages that leave the network - when a message is sent by email to a company that has not joined, email is not private, and the platform says so on every one.
  • Retention - how long case records, messages and account data are kept, and what happens when a member or an organization leaves.
  • International transfers - where data is hosted and the basis for any transfer.
  • Your rights - access, correction, deletion, restriction, objection and portability, and how to exercise them.
  • Complaints - your right to complain to a supervisory authority.

A question about data we hold about you?

Write to us with the subject line for security and data protection, and it reaches the person who deals with it.