HAVERIS ("we," "us," or "our") provides airworthiness directive and service bulletin intelligence tools for aircraft owners, mechanics, and maintenance organizations. This Privacy Policy explains how we collect, use, and protect information when you use haverisaero.com and related services (the "Service").
This notice explains data processing; reading it or using the Service does not constitute consent to optional analytics, advertising or unrelated marketing. Where consent is needed, we request it separately. For business records uploaded by an organisation, that organisation generally determines the purposes of processing; HAVERIS processes those records to provide the service. We separately determine the purposes of account administration, security, billing and direct enquiries.
The data controller responsible for processing your personal data is:
For privacy or data protection questions, write to info@haverisaero.com.
To provide applicability matching, we automatically retrieve aircraft registration data from public government registries (e.g., the FAA N-Number registry). We do not cross-reference this with personal data beyond what you have linked to your account.
We use your information to:
We do not sell personal data or use personal browsing histories to set individual subscription prices. The current site does not load advertising tags. AI inference used to answer a request or extract a document is distinct from training a model; the AI section below explains the information involved.
We share limited data with trusted service providers who help us operate the Service, including:
We may also disclose data when required by law, to enforce our Terms, or to protect the rights, property, or safety of our users or the public.
If HAVERIS is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
Retention depends on the record and purpose. Account and organisation records are used while the service is provided; some shared maintenance/audit records and an access-disabled identity record can remain after an account-deletion action. Contact enquiries, feedback, attachments, AI conversations and email copies require separate review when an erasure request is received. We do not represent that closing an account automatically erases every copy within a fixed period. Records needed for legal obligations or claims may be retained with restricted access.
Application backups use a rolling 30-day retention target, with expired files removed after a successful backup run; failures can delay that cleanup. Anti-spam counter windows expire within two days and are cleaned by queue processing. Those counters are separate from the enquiry records. An enquiry is not deleted merely because its email was sent. You can request an explanation of the retention criteria and an export or erasure review at info@haverisaero.com.
Safeguards include encrypted transport, organisation-scoped access controls, restricted server credentials and authentication protections. Support access is limited to people who need it. No system is perfectly secure. We do not claim that every database field is individually encrypted or that a particular security certification has been obtained.
If we become aware of a breach affecting your data, we will notify you without undue delay, as required by applicable law.
Depending on where you live, you may have the following rights:
Contact info@haverisaero.com to exercise rights; we may request proportionate identity verification. Applicable deadlines govern: generally one month under the GDPR (with permitted extensions and notice), and at most 30 days for a KVKK application. Erasure and portability are subject to their legal conditions. You may also request restriction of processing. A shared organisation’s retention duties do not remove your right to contact us directly.
For users in the EU, UK, and Switzerland: the legal bases for processing include performance of a contract, legitimate interests, legal obligations, and consent where applicable. You have the right to lodge a complaint with your local data protection authority.
California: if the CCPA/CPRA applies to our processing, eligible individuals may exercise applicable access, correction, deletion and non-discrimination rights, and rights concerning sale or sharing. We do not sell personal information or load advertising tags in the current site. Applicability depends on statutory criteria, not simply on the presence of a California visitor.
For users in Türkiye: under KVKK Article 11 (Kişisel Verilerin Korunması Kanunu) you have the right to learn whether your personal data is being processed, request information on its purpose, request correction or deletion of incorrect or unlawfully processed data, object to automated decisions producing adverse effects, and seek compensation for damages caused by unlawful processing. The data controller is identified at the top of this policy. Complaints can also be filed with the Turkish Data Protection Authority (KVKK).
Providers can process data outside your country, including in the United States. Applicable transfers require a valid legal mechanism, such as an adequacy decision or appropriate contractual safeguards, and additional measures where needed. An EU contractual clause alone is not a KVKK transfer mechanism. Contact us for the recipient, destination and safeguards applicable to your processing; this notice itself is neither a transfer agreement nor consent to an international transfer.
Necessary storage supports sign-in, security, language and requested interface functions. Optional public-page analytics is off until you accept it. Reject analytics is available alongside Accept analytics with equal prominence. Use Privacy preferences at the bottom of any page to change your choice; withdrawing analytics reloads the page to stop loaded measurement scripts. Blocking optional analytics does not block the service.
Cookie categories we use:
The Service is not directed to individuals under 18. We do not knowingly collect personal data from children. If you believe we have, please contact us and we will delete it.
The date above identifies the latest revision. This revision corrects descriptions of existing processing and restricts optional measurement. We will provide appropriate notice before materially new processing starts and request consent separately where required. A notice update does not itself authorise a new purpose.
If you have questions about this policy or how we handle your data, please reach out:
Where GDPR applies, account/service delivery and requested pre-contract enquiries rely on contractual necessity where the person is a party; business-user administration, support, security and abuse prevention rely on legitimate interests subject to balancing; required accounting/compliance records rely on legal obligations; optional analytics relies on consent. Under KVKK, the corresponding conditions are assessed under Article 5, including contract necessity, legal obligation, establishment/exercise/protection of rights, balanced legitimate interests, or explicit consent where needed. Only necessary form fields are required to process an enquiry. Optional analytics is not a condition of contact or service access.
FLAP is an AI assistant, not a human support agent or certifying aviation authority. Prompts, replies and limited conversation history can be stored. AI document extraction and suggestions can be wrong; an authorised person must verify original records before maintenance, airworthiness or release decisions. Do not submit unrelated sensitive personal data. Cloud-provider retention and processing are governed by the relevant service arrangements; we do not promise zero retention or local-only processing for all features.
Where activity recording is enabled, events include login/activity time, user and organisation identifiers, connection-derived country and approximate device/browser/OS classes. The purpose is service operation, security and support reporting, not employee productivity scoring, advertising profiles or personalised prices. Founder-wide reports are restricted to server credentials. Coverage starts when collection is enabled; a last-seen timestamp cannot reconstruct earlier country/device history. Retention criteria, access restrictions and any new purpose must be reviewed before expanding collection.
A separate founder-only assistant is planned to summarise contact enquiries, bugs and service metrics. It is not the in-app FLAP chat and has not been represented here as deployed. Before activation, recipient access and data flows must be checked. Telegram notifications should default to counts and pseudonymous references, not full messages, attachments, credentials or email addresses. Local AI processing does not make delivery through Telegram local; any such recipient/transfer must be disclosed and assessed before use.
Send privacy requests, suspected unlawful content, copyright concerns or security reports to info@haverisaero.com. Include the affected URL or record reference, the reason for your report and a reply address. Send only the minimum evidence needed; do not include passwords or publish other users’ data. We review reports and can request clarification. Content-report details and review options are also in the Terms.