Draft for legal review - not yet in force. These documents were prepared as a working draft and have not been reviewed by a qualified solicitor. They are not legal advice. Fields marked [add] must be completed, and the whole text should be reviewed by a UK data protection practitioner before publication or customer use.

Privacy notice

Version 0.1 - draftLast updated 11/09/2026Controller AeroParts Network Limited

This notice explains what personal data AeroParts Network Limited collects when you visit this website, contact us, or use AeroParts Network, why we collect it, and what rights you have.

1Who we are

AeroParts Network Limited operates AeroParts Network, a platform that helps UK Part-145 maintenance organisations source components and verify airworthiness documentation.

Registered nameAeroParts Network Limited
Registered inEngland and Wales
Company number[add]
Registered office[add]
ICO registration number[add - registration is required where you process personal data electronically]
Contact for privacy mattersfounder@aeropartsnetwork.com

We have not appointed a Data Protection Officer. Given our size and the nature of our processing we do not believe one is required under Article 37 of the UK GDPR, and this position will be reviewed as we grow.

2When we are the controller, and when we are not

We are the controller for personal data about website visitors, people who contact us, and individual users who hold accounts on the platform. We are a processor for personal data that a customer organisation puts into the platform, including names and authorisation references of certifying staff that appear on release certificates uploaded by that customer.

3What we collect

When you visit this website

Nothing that identifies you, by design. This site sets no cookies, runs no analytics, and loads no third-party trackers or advertising pixels. Our hosting provider keeps standard server logs for security and fault diagnosis.

When you contact us

Your name, work email address, organisation, job role if you give it, and whatever you choose to put in your message.

When you use the platform

  • Account data - name, work email, organisation, role and permissions, and authentication records.
  • Activity records - requirements viewed, proposed, approved or rejected, and when. These form the audit trail.
  • Content you upload - including release certificates. A UK CAA Form 1, EASA Form 1 or FAA 8130-3 may contain the name and authorisation number of an authorised signatory in Block 14. We process it on your instruction as your processor.

We do not knowingly collect special category data as defined in Article 9 of the UK GDPR, and the platform is not designed to hold it.

4Why we process it, and our lawful basis

PurposeLawful basisNote
Replying to your enquiryLegitimate interestsOur interest in responding to someone who contacted us about our product.
Providing the platformContractNecessary to perform the agreement with your organisation.
Maintaining the audit trailLegitimate interestsTraceability of maintenance-related decisions and customer record keeping.
Security, fraud and abuse preventionLegitimate interestsProtecting the platform and the organisations on it.
Product updates to existing customersLegitimate interests (soft opt-in)Unsubscribe in one click, in every message.
Marketing to new prospectsConsentWe ask first. We do not buy contact lists.
Keeping records for accountingLegal obligationCompanies Act and HMRC requirements.

Where we rely on legitimate interests we have considered whether our interest is overridden by your rights. You can ask us for that assessment and you can object at any time.

5Who we share it with

We do not sell personal data, share it with advertising networks, or disclose one customer's data to another customer. We use a small number of service providers who process data on our behalf and are listed in Annex 3.

We may disclose data where legally required, for example to the UK Civil Aviation Authority, a court, or a regulator acting within its powers.

6Where your data is held

Platform data is intended to be hosted in the United Kingdom, London region. If a provider outside the UK is ever needed, an appropriate transfer mechanism will be put in place first and Annex 3 will be updated.

7How long we keep it

Server logs90 days
Enquiries that do not become customers24 months from last contact
Account and user dataDuration of the agreement, then 12 months
Audit trail and transaction records[confirm - 6 years is proposed, to align with the Limitation Act and customer record-keeping]
Accounting records6 years after the end of the financial year

8Automated decision-making

AeroParts Network ranks and routes candidate components using a scoring process applied to components and organisations, not individuals. No decision producing legal or similarly significant effects concerning an individual is taken solely by automated means. A human remains in the loop for acceptance of any component for fitment.

9Your rights

Under the UK GDPR you have the right to be informed; obtain a copy of your data; have inaccurate data corrected; have data erased in certain circumstances; restrict processing; data portability; object to processing based on legitimate interests; and withdraw consent where consent is the basis.

To exercise any of these rights, email founder@aeropartsnetwork.com. We will respond within one month.

10Complaints

Please raise any concern with us first. You also have the right to complain to the Information Commissioner's Office at any time.

Information Commissioner's OfficeWycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Helpline 0303 123 1113. ico.org.uk

11Changes to this notice

If we make a material change we will update the version and date at the top and, for changes affecting platform users, tell customers by email at least 30 days before the change takes effect.

Data processing agreement

Version 0.1 - draftLast updated 11/09/2026Forms part of the Customer Agreement

This agreement governs personal data that we process on your instruction when you use AeroParts Network. It is written to satisfy Article 28 of the UK GDPR.

Before sending this to a customer: a solicitor should review the liability position, the audit clause and the sub-processor list.

1Definitions

Controller, Processor, Data Subject, Personal Data, Processing and Personal Data Breach have the meanings given in the UK GDPR. Customer Personal Data means Personal Data that we process on your behalf under the Customer Agreement. Data Protection Law means the UK GDPR and the Data Protection Act 2018 as amended.

2Roles of the parties

You are the Controller of Customer Personal Data. We are the Processor. Each party will comply with its own obligations under Data Protection Law.

3Processing on your instructions

We will process Customer Personal Data only on your documented instructions, including as to transfers, unless required to do otherwise by law. The Customer Agreement, this agreement and your use of the platform features constitute your complete instructions.

4Confidentiality

We will ensure that anyone authorised to process Customer Personal Data is subject to a binding duty of confidentiality and has access only to the data needed for their role.

5Security

We will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking account of Article 32 of the UK GDPR. Annex 2 describes the measures currently planned or in force.

6Sub-processors

You give us general written authorisation to engage the sub-processors listed in Annex 3. We will give at least 30 days' notice before adding or replacing a sub-processor.

7Assisting with data subject rights

The platform provides features allowing you to access, correct, export and delete Customer Personal Data yourself. Where you cannot fulfil a request using those features, we will provide reasonable assistance.

8Personal data breach

We will notify you without undue delay and in any event within 48 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data.

9Deletion and return

On termination, and at your choice, we will delete or return Customer Personal Data. You may export your records at any time during the term and for 30 days afterwards.

10Audit

We will make available the information necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits conducted by you or an auditor you appoint, subject to reasonable notice and confidentiality.

11International transfers

Customer Personal Data is intended to be processed in the United Kingdom. We will not transfer it outside the UK without first putting in place a transfer mechanism recognised under Data Protection Law.

12General

Where this agreement conflicts with the Customer Agreement on data protection matters, this agreement prevails. This agreement is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

A1Annex 1 - Description of processing

Subject matterProvision of the AeroParts Network platform for component sourcing and airworthiness documentation verification.
DurationThe term of the Customer Agreement, plus the deletion periods in clause 9.
Nature and purposeHosting, storage, indexing, retrieval, structuring and display of records; scoring components; maintaining an audit trail of decisions; providing access to authorised users.
Types of Personal DataNames, work email addresses, job roles and organisation; authentication and access records; activity and audit records; names and authorisation references of certifying staff appearing on release certificates; any personal data contained in free-text fields or uploaded documents.
Categories of Data SubjectYour employees, contractors and authorised users; certifying staff named on documentation you upload; individuals named in correspondence attached to a requirement.
Special category dataNone. The platform is not designed to process it and it should not be uploaded.

A2Annex 2 - Technical and organisational security measures

MeasureStatusDetail
Encryption in transitIn placeTLS for all connections to the platform.
Encryption at restIn placeProvided by the hosting platform at the storage layer.
Tenant isolationIn placeRow-level security so one organisation cannot read another organisation records.
Access controlIn placeRole-based permissions; least-privilege administrative access.
Audit loggingIn placeDecisions and record access are logged and retained.
BackupsIn placeAutomated backups with point-in-time recovery. Confirm retention window before launch.
Multi-factor authentication[confirm]State plainly whether this is enforced for all users, optional, or not yet available.
Penetration testingNot yetPlanned. We will not claim it before it has happened.
ISO 27001 certificationIn progressNot yet certified. We will say so until we are.
Staff trainingIn placeData protection briefing for anyone with access to customer data.
Business continuity[add]Document recovery objectives before a customer asks.

Overstating this annex creates legal risk. If a measure is not in place, the correct entry is "not yet".

A3Annex 3 - Authorised sub-processors

Sub-processorPurposeLocation
SupabaseApplication database, authentication and file storageUnited Kingdom / EU - London region [confirm contracting entity and region]
Hosting / deployment providerApplication hosting and content delivery[add provider and region]
Email providerTransactional and notification email[add provider and region]

The current list is maintained here. We will give 30 days' notice before adding to it, as set out in clause 6.

These are drafts. They are intended as a substantial starting point for review by a UK data protection practitioner and are not legal advice.

AeroParts Network Limited - founder@aeropartsnetwork.com