top of page

AeroAccess Privacy Policy

Effective date: 4 September 2026

1. Who we are

AeroAccess.io is an online aviation-access platform that connects pilots, aircraft operators, drone operators and other requesters with airfields, airports, landing sites, landowners and aviation service providers.

AeroAccess enables users to find locations, submit and manage operational requests, purchase relevant services and communicate with providers.

For the personal information described in this Privacy Policy, the data controller is AeroAccess (“AeroAccess”, “we”, “us” or “our”).

Privacy contact: info@aeroaccess.io

An airfield, airport, landing site, landowner or other service provider that receives a request through AeroAccess may also act as a separate data controller for the personal information it receives and uses for its own operational, safety, regulatory, accounting or customer-service purposes. Its own privacy policy may therefore also apply.

2. Scope of this Privacy Policy

This Privacy Policy explains how we collect, use, store and share personal information when you:

​

  • visit AeroAccess.io;

  • create or administer an AeroAccess account;

  • claim or manage a provider or location listing;

  • submit, manage or respond to an aviation-access request;

  • arrange or pay for services;

  • communicate with another user or provider through the platform;

  • contact AeroAccess; or

  • otherwise use our website, services or platform.


This Privacy Policy does not govern third-party websites or services linked from AeroAccess.io.

3. Personal information we collect

Depending on how you use AeroAccess, we may collect the following categories of personal information.

Account and identity information

This may include:

​

  • your name;

  • email address;

  • telephone number;

  • password or authentication identifiers;

  • account type;

  • organisation;

  • job title;

  • profile details;

  • account permissions; and

  • communication preferences.


Aviation and operational information

This may include:

​

  • aircraft or drone type;

  • aircraft registration or callsign;

  • maximum take-off weight or weight band;

  • pilot or operator details;

  • point of origin and destination;

  • planned arrival and departure dates and times;

  • flight or operational purpose;

  • passenger numbers;

  • requested aviation services;

  • parking requirements;

  • fuel type and quantity;

  • repair or maintenance requirements;

  • international-arrival information;

  • operational notes;

  • request status;

  • approval, referral or rejection information;

  • supporting documentation; and

  • messages exchanged in connection with a request.


Provider and location information

This may include:

​

  • provider contact information;

  • airfield, airport or landing-site details;

  • location addresses and coordinates;

  • opening hours;

  • available facilities and services;

  • prices and charges;

  • company or location logos;

  • website details;

  • payment and payout information;

  • authorised team members;

  • assigned permissions;

  • provider claim evidence; and

  • information used to verify or administer a provider listing.


Transaction information

This may include:

​

  • payment amounts;

  • currency;

  • provider charges;

  • AeroAccess platform fees;

  • refunds;

  • remittances;

  • invoices;

  • payment status; and

  • transaction references.


Payment-card and digital-wallet information is normally collected and processed directly by our payment provider. AeroAccess does not intend to store complete card numbers or card security codes.

Communications and support information

This may include:

​

  • messages;

  • enquiries;

  • feedback;

  • complaints;

  • support requests; and

  • records of our responses.


Technical and usage information

This may include:

​

  • IP address;

  • device details;

  • browser type;

  • operating system;

  • login and security events;

  • pages and features used;

  • referring pages;

  • approximate location derived from an IP address;

  • cookie preferences;

  • transaction and request audit trails; and

  • technical, diagnostic or security logs.


Marketing information

This may include your marketing preferences and information about how you interact with service messages or marketing communications.

Please do not enter health information, criminal-offence information or other sensitive personal information into free-text fields or uploads unless we specifically request that information and explain why it is required.

4. How we obtain personal information

We may obtain personal information:

​

  • directly from you;

  • from another user or organisation that creates an account for you;

  • from someone who includes you in an aviation-access request;

  • from providers that administer listings or respond to requests;

  • automatically from your device and use of the platform;

  • from payment, authentication, communications, hosting and security suppliers;

  • from public aviation and regulatory information;

  • from mapping and address services;

  • from publicly available business information; and

  • from licensed aviation databases used to populate or verify listings.


If you provide personal information about another person, you must be authorised to do so and, where required, bring this Privacy Policy to their attention.

5. Why we use personal information

We use personal information for the following purposes.

Providing accounts and platform functions

We use personal information to:

​

  • create and administer accounts;

  • authenticate users;

  • provide dashboards;

  • save preferences;

  • assign permissions; and

  • enable users to create and manage requests.


Our lawful bases are the performance of a contract and our legitimate interests in operating the AeroAccess platform.

Processing aviation-access and service requests

We use relevant information to:

​

  • submit requests to selected providers;

  • allow providers to assess requests;

  • enable requests to be approved, referred, amended or rejected;

  • arrange requested services;

  • communicate request updates; and

  • maintain an operational record of each request.


Our lawful bases are the performance of a contract and our legitimate interests in enabling aviation-access requests and services.

Taking payments and administering payouts

We use personal information to:

​

  • calculate charges;

  • process payments;

  • issue refunds;

  • administer provider payouts;

  • generate invoices and remittance records;

  • prevent payment fraud; and

  • maintain accounting records.


Our lawful bases are the performance of a contract, compliance with legal obligations and our legitimate interests in administering payments and preventing fraud.

Verifying and administering provider listings

We may use provider information and claim evidence to:

​

  • verify that a person is authorised to manage a listing;

  • prevent unauthorised control of a listing;

  • maintain accurate provider information;

  • assign administrative permissions; and

  • manage the provider relationship.


Our lawful bases are the performance of a contract and our legitimate interests in maintaining accurate and trustworthy listings.

Safety, security and prevention of misuse

We may use personal information to:

​

  • protect users and providers;

  • protect our systems;

  • detect suspicious activity;

  • prevent fraud and misuse;

  • investigate security incidents;

  • maintain audit trails;

  • enforce our Terms and Conditions; and

  • support safety or incident investigations.


Our lawful bases are our legitimate interests, compliance with legal obligations and, where applicable, recognised legitimate interests permitted by data-protection law.

Legal, regulatory and records-management purposes

We may use and retain information to:

​

  • comply with tax and accounting requirements;

  • respond to court orders;

  • respond to lawful requests from regulators, public authorities or law-enforcement bodies;

  • comply with applicable aviation or financial requirements; and

  • establish, exercise or defend legal claims.


Our lawful bases are compliance with legal obligations and our legitimate interests in protecting our legal rights.

Customer support and service communications

We use personal information to:

​

  • answer enquiries;

  • provide support;

  • send request confirmations;

  • notify users of status changes;

  • provide payment and refund updates;

  • send security alerts; and

  • communicate information necessary to operate the service.


Our lawful bases are the performance of a contract and our legitimate interests in supporting users and operating the service.

Improving and analysing AeroAccess

We may use information to:

​

  • understand how the platform is used;

  • monitor performance;

  • diagnose technical problems;

  • develop new features;

  • improve the user experience; and

  • produce aggregated statistics.


Our lawful bases are our legitimate interests and, where non-essential cookies or similar technologies are used, your consent.

Marketing

We may use your information to send news, offers or product updates and to measure the effectiveness of our communications.

We rely on consent where required. In other circumstances, we may rely on our legitimate interests, subject to your right to object to direct marketing at any time.

Where we rely on legitimate interests, those interests include:

​

  • operating a safe and reliable commercial platform;

  • enabling users and providers to manage aviation access;

  • keeping provider and location listings accurate;

  • protecting the platform and its users;

  • preventing fraud and misuse;

  • improving AeroAccess; and

  • managing our business.


We consider and balance those interests against your rights, interests and reasonable expectations.

Where information is required to enter into or perform a contract, failing to provide it may mean that we cannot create your account, submit or process a request, take payment or provide the relevant service.

6. Who we share personal information with

We may share personal information with the following recipients where reasonably necessary.

Providers

We may share request information with the airfield, airport, landing site, landowner or service provider selected by the requester.

Information may be made available to the provider’s authorised:

​

  • administrators;

  • operational staff;

  • air traffic personnel;

  • finance staff;

  • customer-service staff; and

  • contractors.


Providers should only receive the information reasonably necessary to assess, administer and fulfil the relevant request.

Other authorised users

Information may be available to authorised members of your organisation or account team according to their assigned permissions.

Service providers

We may use suppliers that provide:

​

  • website hosting;

  • content-management services;

  • cloud storage;

  • authentication;

  • email and messaging;

  • customer support;

  • analytics;

  • mapping;

  • document generation;

  • payment processing;

  • fraud prevention; and

  • cybersecurity services.


These suppliers may process personal information on our behalf and must protect it in accordance with their contracts and applicable law.

Payment providers

We may share transaction information with payment processors, banks and payout providers, including Stripe where Stripe is used to process a transaction.

Professional and commercial advisers

We may disclose information to professional advisers, auditors, insurers, investors or prospective buyers or sellers in connection with professional advice, insurance or a proposed business transaction.

Authorities and legal recipients

We may disclose personal information to regulators, courts, law-enforcement bodies, public authorities or other appropriate parties where disclosure is:

​

  • required by law;

  • necessary to respond to a lawful request;

  • necessary to protect legal rights;

  • necessary to protect the safety of a person; or

  • reasonably necessary to protect the integrity of aviation operations or the AeroAccess platform.


We do not sell personal information.

Providers must not use information obtained from an AeroAccess request for unrelated marketing unless they have their own valid lawful basis and have provided any privacy information required by law.

7. Payments

Payments may be processed by Stripe or another payment provider.

The payment provider may receive the payment, identity, transaction and device information needed to:

​

  • authorise a payment;

  • prevent fraud;

  • comply with financial regulation;

  • issue refunds; and

  • administer provider payouts.


The payment provider’s own privacy policy will apply to personal information it processes as an independent controller.

AeroAccess will generally receive information such as:

​

  • a transaction reference;

  • the amount paid;

  • payment status;

  • the payment-card brand;

  • limited card details, such as the final four digits;

  • refund information; and

  • payout or remittance information.


AeroAccess does not intend to receive or store complete payment-card numbers or security codes.

8. Cookies and similar technologies

We use strictly necessary cookies and similar technologies to:

* operate the website;
* authenticate users;
* maintain security;
* remember essential preferences;
* maintain user sessions; and
* process transactions.

With your consent, we may also use functional, analytics or advertising technologies.

Non-essential cookies and similar technologies will not be activated until any consent required by law has been obtained.

You can manage or change your cookie choices through **[COOKIE SETTINGS LINK]**.

Withdrawing consent does not affect processing that occurred before consent was withdrawn.

Further information about the cookies and similar technologies used by AeroAccess is available in our Cookie Policy.

9. International transfers

Some of our suppliers or recipients may process personal information outside the United Kingdom.

Where UK data-protection law requires safeguards, we will use an appropriate transfer mechanism, such as:

​

  • a UK adequacy regulation;

  • the UK International Data Transfer Agreement;

  • the UK Addendum to the European Commission’s Standard Contractual Clauses; or

  • another lawful transfer safeguard.


Where required, we will assess relevant transfer risks and apply supplementary technical or organisational protections.

You can contact us for further information about the safeguard relevant to your personal information.

10. How long we keep personal information

We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including legal, accounting, safety, dispute-resolution and fraud-prevention requirements.

Our intended baseline retention periods are:

​

  • Account and profile information:  while the account remains active and normally for up to 24 months after the account is closed.

  • Requests, approvals, operational messages and audit trails:  normally for six years after the request is completed, cancelled or finally resolved.

  • Transaction, invoice, refund and payout records:  normally for six years after the end of the relevant financial year, or longer where required by law.

  • Provider claim and verification evidence:  while required to verify or administer the listing and normally for up to 24 months after the claim or provider relationship ends.

  • Support enquiries and complaints:  normally for three years after closure, or up to six years where a contractual or legal dispute may arise.

  • Security and technical logs:  normally for up to 12 months unless a security incident, fraud investigation or legal matter requires longer retention.

  • Marketing records: until you opt out or the information is no longer required. We may retain minimal suppression information to ensure that an opt-out continues to be respected.


We may retain information for longer where required by law or because of an active legal claim, investigation, safety matter, fraud concern or regulatory request.

We may retain irreversibly anonymised information indefinitely because it no longer identifies an individual.

11. Security

We use proportionate technical and organisational measures designed to protect personal information.

These measures may include:

​

  • access controls;

  • role-based permissions;

  • user authentication;

  • encryption where appropriate;

  • system and activity logging;

  • supplier security controls;

  • backups;

  • data-minimisation measures; and

  • security incident-management procedures.


No website or online service can be guaranteed to be completely secure.

You should use a strong and unique password, keep your account credentials confidential and promptly notify us if you suspect unauthorised access to your account.

12. Your data-protection rights

Depending on the circumstances, UK data-protection law may give you the right to:

​

  • request access to your personal information;

  • receive a copy of your personal information;

  • ask us to correct inaccurate or incomplete information;

  • ask us to erase personal information;

  • ask us to restrict how personal information is used;

  • receive certain information in a portable format;

  • ask us to transfer certain information to another organisation;

  • object to processing based on legitimate interests;

  • object at any time to the use of your information for direct marketing;

  • withdraw consent where consent is our lawful basis; and

  • raise a concern about a decision made solely through automated processing that produces legal or similarly significant effects.


These rights are not absolute, and legal exemptions may apply.

To exercise a data-protection right, contact us at info@aeroaccess.io

We may need to verify your identity before completing a request. We normally respond within one month, although the law permits extensions in certain circumstances.

You may also complain to the UK Information Commissioner’s Office.

We would appreciate the opportunity to address your concerns first, but you are not required to contact us before approaching the Information Commissioner’s Office.

Information about making a complaint is available at:

https://ico.org.uk/make-a-complaint/data-protection-complaints/

13. Marketing choices

You can opt out of AeroAccess marketing at any time by:

​

  • selecting the unsubscribe link in a marketing message;

  • changing your account preferences, where available; or

  • contacting us at info@aeroaccess.io


Opting out of marketing will not prevent you from receiving service communications needed to:

​

  • operate your account;

  • process a request;

  • provide a payment or refund update;

  • send security information; or

  • fulfil a contract.


14. Children

AeroAccess is intended for people aged 18 or over and for authorised business or operational users.

We do not knowingly offer AeroAccess accounts directly to children.

If you believe that a child has provided personal information to AeroAccess, please contact us at info@aeroaccess.io

15. Automated decision-making

AeroAccess may apply configurable rules to help assess or route requests.

These rules may relate to:

​

  • operating hours;

  • minimum notice periods;

  • aircraft or drone limitations;

  • weight restrictions;

  • required documents;

  • service availability; or

  • other provider-configured requirements.


These rules may flag, route, refer or automatically determine a request.

Where a decision is based solely on automated processing and produces legal or similarly significant effects, we will provide the information and protections required by law. These may include the right to:

​

  • request human intervention;

  • express your point of view; and

  • challenge the decision.


Provider personnel may also make independent operational decisions under their own procedures and responsibilities.

16. Third-party links and services

AeroAccess may contain links to:

​

  • provider websites;

  • government websites and forms;

  • mapping services;

  • aviation-information services;

  • payment services; and

  • other third-party resources.


Those organisations control their own websites, services and privacy practices. You should review their privacy information before providing personal information to them.

17. Public and licensed data sources

AeroAccess may use information from public or licensed aviation, mapping, regulatory and business sources to populate and maintain provider or location listings.

Although we take reasonable steps to maintain accurate information, public or licensed information may be incomplete, inaccurate or out of date.

Providers and individuals can contact us to request the correction of relevant personal information or listing details.

18. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes to:

​

  • AeroAccess services and features;

  • the personal information we process;

  • our suppliers;

  • applicable law; or

  • our business operations.


We will publish the updated Privacy Policy with a revised effective date.


Where a change is significant, we may also notify account holders or request fresh consent where required by law.

19. Contact us

For questions, requests or complaints relating to privacy or personal information, contact:  info@aeroaccess.io
 

bottom of page