Set the missing operator details before launch: legal entity name, entity type and jurisdiction, registered or trading address, legal contact email, privacy contact email.
Account, pilot, organisation, logbook, training, document, billing and security information.
No advertising profiles, sale of personal information or solely automated legal or regulatory decisions.
Correct records, export your account, manage sessions and request deletion from Settings.
1Who we are and how to contact us
FlightHours operator, operator details to be configured before production, operates FlightHours and is the controller for personal information used to provide accounts, billing, product security and personal pilot workspaces.
- Registered or trading address
- Address to be configured before production
- General and legal enquiries
- Legal contact to be configured before production
- Privacy requests and complaints
- Privacy contact to be configured before production
2Scope and controller roles
This notice covers the FlightHours website, pilot application, organisation workspaces, branded organisation portals and related support and billing communications.
For a personal pilot workspace, FlightHours normally decides why and how personal information is used. For an organisation workspace, the club, ATO or DTO may be the controller for member, student, staff and organisation records it chooses to enter. FlightHours remains an independent controller for account identity, security, fraud prevention, billing and service administration. Where FlightHours processes organisation data only on the organisation’s instructions, the parties must put an appropriate data-processing agreement in place.
Joining an organisation does not, by itself, give that organisation access to a pilot’s private logbook, medical, documents or other personal workspace records. Access requires a specific product feature and an explicit authorised grant.
3Personal information we collect
Account and profile
- Name, email address and authentication identifiers
- Password hash, verification state, MFA state and recovery data
- Country, timezone, preferences, home airport and onboarding answers
- Terms, privacy and health-data consent records
Pilot records
- Flights, aircraft, routes, crew, approaches, landings, remarks and revisions
- Opening balances, qualifications, ratings and theory attempts
- Training records, goals, evidence, recommendations and progress snapshots
- Costs, budgets, uploaded documents and file metadata
- Medical class, issue/expiry dates and evidence status; we do not ask for diagnoses or medical history
Organisation information
- Organisation identity, type, CAA approval reference and locations
- Membership, role, invitation, training, aircraft-register, document and compliance records
- Branding, portal configuration and organisation billing information
Technical and service information
- Session, device, browser, IP-derived security and request information
- Audit events, error codes, rate-limit and security events
- Subscription, entitlement, invoice and payment-status information
- Support correspondence and privacy or deletion requests
Sources
Most information comes directly from you. We also receive information from an organisation owner or administrator, records you import, payment and subscription events from Stripe when enabled, and technical events generated when the service is used. We do not obtain official licensing or medical decisions from a regulator unless a future integration is clearly disclosed.
4How we use information and our lawful bases
| Purpose | Information | UK GDPR basis |
|---|---|---|
| Create accounts, authenticate users and deliver requested workspaces | Account, profile, pilot and organisation records | Contract; steps at your request before contract |
| Store records, calculate totals, build journey snapshots and provide requested exports | Logbook, training, documents, goals and preferences | Contract |
| Process plans, trials and billing | Identity, plan, subscription and payment status | Contract; legal obligation for tax and accounting records |
| Protect accounts, investigate abuse, prevent fraud and preserve audit history | Sessions, security events, limited account and audit data | Legitimate interests in operating a secure and accountable service; legal obligation where applicable |
| Send verification, security, expiry and service messages | Email, preferences, account and relevant expiry state | Contract; legitimate interests for important service and security notices; consent where required for marketing |
| Respond to rights requests, disputes and authorities | Account, request, audit and correspondence data | Legal obligation; establishment, exercise or defence of legal claims |
| Improve reliability and understand feature performance | Minimised technical and aggregated usage information | Legitimate interests, after balancing necessity against your rights |
Where we rely on legitimate interests, you may ask for information about the balancing assessment. We do not use consent where the processing is necessary to provide the service or comply with law.
5Medical and other special-category information
Medical class and medical certificate dates may reveal health information and are treated as special-category data. We process these fields only when you choose to add them and give explicit consent for the stated record-keeping and expiry-tracking purposes (UK GDPR Article 9(2)(a)), alongside the Article 6 basis described above.
- Entry is optional and the product asks you not to enter diagnoses, treatment or medical history.
- Sensitive revision payloads are encrypted and are not returned through ordinary list APIs.
- You may withdraw consent by contacting us and may archive or request deletion of the record. Withdrawal does not make earlier lawful processing unlawful and some limited data may be retained where law permits or requires.
- FlightHours does not provide medical advice or determine medical fitness.
5AAutomated analysis and recommendations
FlightHours uses deterministic software rules to calculate totals, compare records with a selected rule-pack fixture, classify possible evidence and rank suggested next actions. The system can show the contributing records, exclusions, rule version and confidence state. These outputs are advisory planning information only. They do not produce a legal, licensing, employment or medical decision and are not a substitute for an instructor, ATO or DTO, examiner, medical professional or regulator.
7International transfers
Production providers may process information outside the United Kingdom. Before making a restricted transfer, we will use a lawful mechanism such as UK adequacy regulations or appropriate safeguards, which may include the UK International Data Transfer Agreement or the UK Addendum, and complete the required data-protection test. You may contact the privacy address for information about the mechanism applying to a particular transfer.
8How long we keep information
| Record | Typical retention approach |
|---|---|
| Account and pilot content | While the account is active, then deleted or de-identified following an accepted deletion request unless an exception applies. |
| Uploaded private files | While the related active or archived record is retained; file bytes are removed through account deletion where applicable. |
| Sessions and security events | For the active security lifecycle and then for a limited period needed to investigate incidents and protect the service. |
| Billing, tax and transaction records | For the period required by tax, accounting, anti-fraud and legal-claims obligations. |
| Consent and legal acceptance records | For as long as needed to demonstrate the version, decision and context of consent or contract acceptance. |
| De-identified audit events | Where necessary to preserve system integrity and accountability without retaining the user’s identity or record contents. |
| Backups | Until overwritten or expired under the approved backup schedule; deleted data is not restored into the live service except for disaster recovery and is removed again when practicable. |
FlightHours uses an approved retention-policy register rather than inventing automatic periods. We may retain information longer where required for law, a dispute, fraud prevention or the establishment, exercise or defence of legal claims. Account deletion has a 14-day cooling-off period and can be cancelled before execution.
9Security
Measures include scoped authorisation, password hashing, optional multi-factor authentication, encrypted sensitive revision data, private file storage, request forgery protection, rate limiting, session controls, audit history, security-focused logging and recoverable backups. No service can guarantee absolute security. If we identify a personal-data breach, we will assess it and notify affected people and the ICO when required by law.
11Your data-protection rights
Depending on the circumstances, you may ask us to:
- provide access to your personal information and supplementary information;
- correct inaccurate or incomplete information;
- erase information, or restrict how it is used;
- provide information you supplied in a portable format;
- stop processing based on consent by withdrawing that consent;
- object to processing based on legitimate interests or to direct marketing; and
- review a qualifying decision made solely by automated means.
Rights are not absolute and lawful exemptions may apply. We may need to verify your identity. You can correct many records, prepare a full account export, manage sessions and schedule account deletion from Settings. Otherwise contact Privacy contact to be configured before production. We normally respond within the period required by law and do not charge unless a request is manifestly unfounded, excessive or repeated where the law permits a fee.
12Privacy complaints
Send a complaint to Privacy contact to be configured before production with enough information for us to investigate. We will acknowledge it, investigate fairly and provide an outcome. If you remain unhappy, you may complain to the UK Information Commissioner’s Office through the ICO complaint service or call 0303 123 1113. You may also have the right to seek a judicial remedy.
12AChildren
FlightHours is not designed for children to open paid accounts independently. If a user is under 18, their parent or guardian and, where relevant, their training organisation should ensure they have the legal capacity and appropriate permission to use the service. Do not enter information about a child unless you are authorised and have provided the required privacy information.
13Changes to this notice
We may update this notice to reflect changes in law, providers or product features. Material changes will be presented in the service or sent to the account email where appropriate. The version and effective date at the top identify the notice that applies. Earlier acceptances remain recorded against the version shown at the time.