1. Our Commitment
This statement describes how Turbsol Management, LLC, the company that makes and operates the AvTools platform ("AvTools", "we", "us", or "our"), approaches the obligations of the European Union General Data Protection Regulation ("GDPR") for users of the AvTools platform and its web and mobile applications (the "Services") who are located in the European Economic Area (EEA), the United Kingdom, or Switzerland ("Data Subjects"). References to the GDPR include the UK GDPR and, where applicable, equivalent Swiss data-protection law.
It supplements (and should be read together with) our Privacy Policy, which is the complete description of what we collect and how we use it, and our Terms of Service. Where this statement and the Privacy Policy describe the same processing, the Privacy Policy controls.
The Services are business tools for aviation parts and maintenance organizations. We collect the minimum personal information needed to operate them: work identities for the people your organization invites, the operational records your organization chooses to store, and the billing and support data needed to run the relationship.
2. Controller and Processor Roles
The GDPR assigns responsibilities by role, and we act in two distinct ones:
2.1 AvTools as Processor
Most data in the Services is Customer Data: the photos, inspection records, documents, quotes, and ERP-connected records that a customer organization and its users put into the platform. For Customer Data, the customer organization is the controller and AvTools is a processor: we process it only to provide, secure, and support the Services and on the organization's instructions, as set out in our Terms of Service and any Data Processing Agreement in place (Section 11). Personal data of third parties that appears inside Customer Data (for example a counterparty contact on a quote, or an inspector's name on a report) is processed under the same instructions.
2.2 AvTools as Controller
For a narrower set of data, AvTools is the controller: account registration and authentication data, billing and subscription records, support and sales communications (including demo-request leads from our website), and the device, usage, and diagnostic data described in our Privacy Policy.
3. What Personal Data We Process
The categories are described in full in Section 3 of our Privacy Policy. In summary:
- Work identity data: name, work email, role/permissions, and (for password sign-in) a hashed password, or a single-sign-on identity.
- Operational content: QC photos and capture metadata, part and work-order data, generated documents, quotes and RFQ emails, and signature/certification records, to the extent your organization stores them.
- Billing data: subscription and invoice records. We never see or store card details; payment is processed by Stripe. The Services do not currently offer Apple in-app purchases; if that changes, Apple will process those payments and this statement will be updated.
- Device and usage data: device identifiers, IP address, session and diagnostic logs.
The Services are not designed to collect special categories of personal data (Article 9), and we do not knowingly process data of children.
4. Lawful Bases for Processing
Where we act as controller, we rely on the following Article 6 lawful bases. Where we act as processor, identifying the lawful basis is the customer organization's responsibility as controller, and we support it with the commitments described in this statement.
| Processing | Lawful basis |
|---|---|
| Providing the Services: accounts, authentication, storage, sync, support | Performance of a contract (Art. 6(1)(b)) |
| Billing, subscription management, and financial record-keeping | Performance of a contract; legal obligation (Art. 6(1)(b), (c)) |
| Security, fraud prevention, audit logging, error monitoring, service improvement | Legitimate interests (Art. 6(1)(f)): operating a secure, reliable service |
| Responding to demo requests and sales inquiries you send us | Legitimate interests; consent where required (Art. 6(1)(f), (a)) |
| Optional features you enable, such as GPS location tagging on photos | Consent (Art. 6(1)(a)): controlled by you and revocable in settings |
| Retention required by aviation, tax, or financial regulation | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we balance them against your data-protection interests and fundamental rights, and we do not proceed where those override ours.
5. Your Rights as a Data Subject
If you are a Data Subject, the GDPR gives you the right to:
- Access the personal data we hold about you (Art. 15)
- Rectify inaccurate or incomplete data (Art. 16)
- Erase your data in the circumstances Article 17 provides
- Restrict processing while a dispute or verification is resolved (Art. 18)
- Receive a portable copy of data you provided, in a machine-readable format (Art. 20)
- Object to processing based on legitimate interests, and to direct marketing (Art. 21)
- Withdraw consent at any time where processing is based on consent, without affecting processing before withdrawal
- Lodge a complaint with a supervisory authority in your EEA member state, or with the UK Information Commissioner's Office
We do not make solely automated decisions about individuals that produce legal or similarly significant effects (Art. 22). AI-assisted features in the Services produce drafts, summaries, and suggestions for human review, and they do not decide anything about you.
How to Exercise Your Rights
- If your account is managed by your organization (the usual case), contact your administrator first: for Customer Data, your organization is the controller and we act on its instructions. We will assist the organization in fulfilling your request.
- For data AvTools controls, or if you cannot reach your administrator, email legal@avtools.aero. We may need to verify your identity before acting.
- Response time: within one month (30 days) of the request, as Article 12 requires. If a request is complex we may extend as the GDPR permits, and we will tell you why.
Erasure and rectification are subject to the aviation, tax, and financial record-keeping obligations described in Section 7 of our Privacy Policy. Where a record must be kept by law, we will tell you so and restrict it instead.
6. International Data Transfers
AvTools is located in the United States and the Services' primary infrastructure runs in the United States. If you use the Services from the EEA, the UK, or Switzerland, your personal data will be transferred to and processed in the United States and in other jurisdictions where our sub-processors operate. Data protection laws there may differ from those of your country. The United States has not received a general finding of adequacy from the European Commission under Article 45 of the GDPR, and AvTools does not currently participate in the EU–U.S. Data Privacy Framework.
Where the GDPR applies to a transfer, we rely on Standard Contractual Clauses approved by the European Commission (and the UK equivalent safeguards), entered into with our sub-processors, together with supplementary measures including encryption in transit and at rest and the access controls described in Section 8.
7. Sub-Processors
We use a limited set of service providers to operate the Services: hosting, database and storage, payments, AI features, email, error monitoring, and identity. Every sub-processor that can touch Customer Data is named publicly in Section 5 of our Privacy Policy rather than buried in a contract, and that list is kept current: when it changes, the Privacy Policy and its Last Updated date change with it.
Sub-processors are bound by data-protection obligations consistent with ours, process data only to provide their service to us, and are engaged under agreements incorporating Standard Contractual Clauses where they involve a restricted transfer. We remain responsible to our customers for our sub-processors' performance.
8. Security of Processing
We maintain technical and organizational measures consistent with Article 32, scaled to the sensitivity of aviation quality records:
- Encryption in transit (TLS) and at rest
- Per-organization row-level isolation enforced at the database, so one company's account cannot reach another company's records
- Role-based access control, with single sign-on and MFA available
- Private storage for photos and documents, served through authorization checks and short-lived links
- Server-side-only handling of integration credentials
- Append-only audit logs for signing events, plus best-effort append-only logging of AI reads. An AI logging failure does not block operational work.
A plain-language description of these controls is on our Security page.
9. Data Retention and Deletion
We retain personal data for as long as the account it belongs to is active, then delete it on the schedule described in Section 7 of our Privacy Policy: deletion is initiated within 30 days of account deletion, backups clear within 90 days, and records subject to aviation, tax, or financial retention mandates are kept for the legally required period only.
When a customer organization ends its subscription, it may export its Customer Data first. Our Terms of Service commit to data portability and to never withholding data in a commercial dispute. We then delete or return Customer Data in accordance with those Terms and any Data Processing Agreement in place.
10. Personal Data Breach Notification
If we become aware of a personal data breach affecting Customer Data, we will notify the affected customer organizations without undue delay, and will provide the information reasonably available to us about the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken, so that each organization can meet its own notification obligations under Articles 33 and 34. Where AvTools is the controller of the affected data, we will notify the competent supervisory authority and affected individuals as those Articles require.
11. Data Processing Agreements
Organizational customers that need a Data Processing Agreement: a contract governing our processing of Customer Data on the organization's behalf, including processing instructions, the sub-processor list, breach notification, and return or deletion of data at the end of the relationship, incorporating Standard Contractual Clauses where required, can request one at legal@avtools.aero.
12. Contact
For questions about this statement, or to exercise any of the rights in Section 5, contact us:
If you believe we have not adequately resolved a concern, you may lodge a complaint with the supervisory authority of your EEA member state, the UK Information Commissioner's Office, or the Swiss Federal Data Protection and Information Commissioner.