Privacy notice
Version 0.1 - draftLast updated 11/09/2026Controller AeroParts Network Limited
This notice explains what personal data AeroParts Network Limited collects when you visit this website, contact us, or use AeroParts Network, why we collect it, and what rights you have.
1Who we are
AeroParts Network Limited operates AeroParts Network, a platform that helps UK Part-145 maintenance organisations source components and verify airworthiness documentation.
| Registered name | AeroParts Network Limited |
| Registered in | England and Wales |
| Company number | [add] |
| Registered office | [add] |
| ICO registration number | [add - registration is required where you process personal data electronically] |
| Contact for privacy matters | founder@aeropartsnetwork.com |
We have not appointed a Data Protection Officer. Given our size and the nature of our processing we do not believe one is required under Article 37 of the UK GDPR, and this position will be reviewed as we grow.
2When we are the controller, and when we are not
We are the controller for personal data about website visitors, people who contact us, and individual users who hold accounts on the platform. We are a processor for personal data that a customer organisation puts into the platform, including names and authorisation references of certifying staff that appear on release certificates uploaded by that customer.
3What we collect
When you visit this website
Nothing that identifies you, by design. This site sets no cookies, runs no analytics, and loads no third-party trackers or advertising pixels. Our hosting provider keeps standard server logs for security and fault diagnosis.
When you contact us
Your name, work email address, organisation, job role if you give it, and whatever you choose to put in your message.
When you use the platform
- Account data - name, work email, organisation, role and permissions, and authentication records.
- Activity records - requirements viewed, proposed, approved or rejected, and when. These form the audit trail.
- Content you upload - including release certificates. A UK CAA Form 1, EASA Form 1 or FAA 8130-3 may contain the name and authorisation number of an authorised signatory in Block 14. We process it on your instruction as your processor.
We do not knowingly collect special category data as defined in Article 9 of the UK GDPR, and the platform is not designed to hold it.
4Why we process it, and our lawful basis
| Purpose | Lawful basis | Note |
|---|
| Replying to your enquiry | Legitimate interests | Our interest in responding to someone who contacted us about our product. |
| Providing the platform | Contract | Necessary to perform the agreement with your organisation. |
| Maintaining the audit trail | Legitimate interests | Traceability of maintenance-related decisions and customer record keeping. |
| Security, fraud and abuse prevention | Legitimate interests | Protecting the platform and the organisations on it. |
| Product updates to existing customers | Legitimate interests (soft opt-in) | Unsubscribe in one click, in every message. |
| Marketing to new prospects | Consent | We ask first. We do not buy contact lists. |
| Keeping records for accounting | Legal obligation | Companies Act and HMRC requirements. |
Where we rely on legitimate interests we have considered whether our interest is overridden by your rights. You can ask us for that assessment and you can object at any time.
5Who we share it with
We do not sell personal data, share it with advertising networks, or disclose one customer's data to another customer. We use a small number of service providers who process data on our behalf and are listed in Annex 3.
We may disclose data where legally required, for example to the UK Civil Aviation Authority, a court, or a regulator acting within its powers.
6Where your data is held
Platform data is intended to be hosted in the United Kingdom, London region. If a provider outside the UK is ever needed, an appropriate transfer mechanism will be put in place first and Annex 3 will be updated.
7How long we keep it
| Server logs | 90 days |
| Enquiries that do not become customers | 24 months from last contact |
| Account and user data | Duration of the agreement, then 12 months |
| Audit trail and transaction records | [confirm - 6 years is proposed, to align with the Limitation Act and customer record-keeping] |
| Accounting records | 6 years after the end of the financial year |
8Automated decision-making
AeroParts Network ranks and routes candidate components using a scoring process applied to components and organisations, not individuals. No decision producing legal or similarly significant effects concerning an individual is taken solely by automated means. A human remains in the loop for acceptance of any component for fitment.
9Your rights
Under the UK GDPR you have the right to be informed; obtain a copy of your data; have inaccurate data corrected; have data erased in certain circumstances; restrict processing; data portability; object to processing based on legitimate interests; and withdraw consent where consent is the basis.
To exercise any of these rights, email founder@aeropartsnetwork.com. We will respond within one month.
10Complaints
Please raise any concern with us first. You also have the right to complain to the Information Commissioner's Office at any time.
| Information Commissioner's Office | Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Helpline 0303 123 1113. ico.org.uk |
11Changes to this notice
If we make a material change we will update the version and date at the top and, for changes affecting platform users, tell customers by email at least 30 days before the change takes effect.
Data processing agreement
Version 0.1 - draftLast updated 11/09/2026Forms part of the Customer Agreement
This agreement governs personal data that we process on your instruction when you use AeroParts Network. It is written to satisfy Article 28 of the UK GDPR.
Before sending this to a customer: a solicitor should review the liability position, the audit clause and the sub-processor list.
1Definitions
Controller, Processor, Data Subject, Personal Data, Processing and Personal Data Breach have the meanings given in the UK GDPR. Customer Personal Data means Personal Data that we process on your behalf under the Customer Agreement. Data Protection Law means the UK GDPR and the Data Protection Act 2018 as amended.
2Roles of the parties
You are the Controller of Customer Personal Data. We are the Processor. Each party will comply with its own obligations under Data Protection Law.
3Processing on your instructions
We will process Customer Personal Data only on your documented instructions, including as to transfers, unless required to do otherwise by law. The Customer Agreement, this agreement and your use of the platform features constitute your complete instructions.
4Confidentiality
We will ensure that anyone authorised to process Customer Personal Data is subject to a binding duty of confidentiality and has access only to the data needed for their role.
5Security
We will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking account of Article 32 of the UK GDPR. Annex 2 describes the measures currently planned or in force.
6Sub-processors
You give us general written authorisation to engage the sub-processors listed in Annex 3. We will give at least 30 days' notice before adding or replacing a sub-processor.
7Assisting with data subject rights
The platform provides features allowing you to access, correct, export and delete Customer Personal Data yourself. Where you cannot fulfil a request using those features, we will provide reasonable assistance.
8Personal data breach
We will notify you without undue delay and in any event within 48 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data.
9Deletion and return
On termination, and at your choice, we will delete or return Customer Personal Data. You may export your records at any time during the term and for 30 days afterwards.
10Audit
We will make available the information necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits conducted by you or an auditor you appoint, subject to reasonable notice and confidentiality.
11International transfers
Customer Personal Data is intended to be processed in the United Kingdom. We will not transfer it outside the UK without first putting in place a transfer mechanism recognised under Data Protection Law.
12General
Where this agreement conflicts with the Customer Agreement on data protection matters, this agreement prevails. This agreement is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
A1Annex 1 - Description of processing
| Subject matter | Provision of the AeroParts Network platform for component sourcing and airworthiness documentation verification. |
| Duration | The term of the Customer Agreement, plus the deletion periods in clause 9. |
| Nature and purpose | Hosting, storage, indexing, retrieval, structuring and display of records; scoring components; maintaining an audit trail of decisions; providing access to authorised users. |
| Types of Personal Data | Names, work email addresses, job roles and organisation; authentication and access records; activity and audit records; names and authorisation references of certifying staff appearing on release certificates; any personal data contained in free-text fields or uploaded documents. |
| Categories of Data Subject | Your employees, contractors and authorised users; certifying staff named on documentation you upload; individuals named in correspondence attached to a requirement. |
| Special category data | None. The platform is not designed to process it and it should not be uploaded. |
A2Annex 2 - Technical and organisational security measures
| Measure | Status | Detail |
|---|
| Encryption in transit | In place | TLS for all connections to the platform. |
| Encryption at rest | In place | Provided by the hosting platform at the storage layer. |
| Tenant isolation | In place | Row-level security so one organisation cannot read another organisation records. |
| Access control | In place | Role-based permissions; least-privilege administrative access. |
| Audit logging | In place | Decisions and record access are logged and retained. |
| Backups | In place | Automated backups with point-in-time recovery. Confirm retention window before launch. |
| Multi-factor authentication | [confirm] | State plainly whether this is enforced for all users, optional, or not yet available. |
| Penetration testing | Not yet | Planned. We will not claim it before it has happened. |
| ISO 27001 certification | In progress | Not yet certified. We will say so until we are. |
| Staff training | In place | Data protection briefing for anyone with access to customer data. |
| Business continuity | [add] | Document recovery objectives before a customer asks. |
Overstating this annex creates legal risk. If a measure is not in place, the correct entry is "not yet".
A3Annex 3 - Authorised sub-processors
| Sub-processor | Purpose | Location |
|---|
| Supabase | Application database, authentication and file storage | United Kingdom / EU - London region [confirm contracting entity and region] |
| Hosting / deployment provider | Application hosting and content delivery | [add provider and region] |
| Email provider | Transactional and notification email | [add provider and region] |
The current list is maintained here. We will give 30 days' notice before adding to it, as set out in clause 6.