Skip to content

Privacy policy

This policy explains how FlyerOS handles personal data that we control: data about visitors to this website, people who enquire or book a walkthrough, and the contacts at our customer organisations. Personal data held inside the product about a school’s students and staff is handled under our data processing agreement, where the school is the controller and FlyerOS is the processor. That split is set out in section 4.

Last updated: 13 August 2026.

1. The personal data we collect

Depending on how you interact with us, we may hold:

  • Enquiry details: your name, organisation, email, phone, role and the information you give us when you book a walkthrough or get in touch.
  • Customer contact details: the account, administrative and billing contacts at an organisation that uses FlyerOS.
  • Support correspondence: the content of messages you send us and our replies.
  • Website usage: pages viewed, actions taken and approximate location, collected through analytics only after you accept, plus a privacy-preserving traffic count that sets no cookies.
  • Technical data: the logs needed to run and secure the website and service.

We do not collect special-category data through this website, and we ask you not to send it to us in free-text fields.

2. How we collect it

We collect most of this directly from you, when you fill in a form, email us, or use the website. Some technical and usage data is collected automatically by the website, subject to your cookie choice. Where you are a contact at a customer organisation, we may also receive your details from your organisation.

3. Why we process it, and our lawful basis

Under the UK GDPR we process personal data only where we have a lawful basis. Our main purposes and bases are:

PurposeDataLawful basis
Answering an enquiry or running a walkthroughName, organisation, email, phone, role, and what you ask aboutOur legitimate interest in responding to you, and taking steps toward a contract at your request
Providing and billing the service to a customerAccount and billing-contact details, correspondencePerformance of our contract with your organisation
Support and service messagesContact details and the content of your requestPerformance of the contract, and our legitimate interest in supporting the service
Website analyticsUsage events and approximate location, once you acceptYour consent
Security, fraud prevention and keeping recordsTechnical logs, and the minimum needed to meet obligationsLegitimate interest in a secure service, and legal obligation where one applies
Marketing to organisations that ask to hear from usBusiness contact detailsConsent, or legitimate interest with an opt-out, as the rules allow

Where our basis is legitimate interests, we have weighed those interests against your rights, and you can object as set out in section 11.

4. Controller and processor, and our own access

For the personal data a school holds about its students and staff inside the product, the school is the controller and FlyerOS is the processor. We process that data on the school’s documented instructions to provide the service and for nothing else, under our data processing agreement.

For our own data, such as the contacts at a customer organisation, our billing records and this website’s analytics, FlyerOS is the controller, and this policy is our notice for it.

Some product data is special-category data under the UK GDPR, for example the details on a medical certificate. Which lawful basis the school relies on for that data is the school’s decision to make and record; we hold and protect it, but we do not determine that basis for them.

FlyerOS staff may access a school’s data to support and operate the service. Every such access is logged and surfaced in that school’s own audit trail. There is no hidden access.

We do not sell personal data, and we do not use customer or school data to train external AI models.

5. Cookies and analytics

This website uses Google Analytics to understand how it is used, on the lawful basis of your consent. Analytics cookies are set only after you accept them: Google Consent Mode defaults to denied, so nothing analytics-related runs until you choose. You can change or withdraw your choice at any time through “Cookie choices” in the footer. We also use a cookieless, privacy-preserving traffic measure that sets no cookies and needs no consent. Strictly necessary cookies that make the site work are always on and do not need consent.

6. Marketing

If you ask to hear from us, or you are a business contact and the rules allow it, we may send you occasional messages about FlyerOS. Every marketing message has a clear way to opt out, and you can tell us to stop at any time by replying or emailing us. We do not share your details with third parties for their own marketing.

7. Who we share your data with

We share personal data only where we need to, and under appropriate terms. Recipients can include:

  • the service providers who help us run FlyerOS and this website, such as our cloud hosting, email delivery, analytics and payment providers, acting as our processors under contract;
  • our professional advisers, such as accountants and lawyers, where they need it;
  • a buyer or successor if the business is reorganised, sold or transferred; and
  • a regulator, court or authority where we are required by law to disclose, in which case we disclose no more than we must.

Those service providers are our sub-processors. They fall into a small set of categories: cloud hosting, database and file storage, email delivery, error monitoring, and the integrations a school chooses to switch on, such as weather, registry lookups and accounting. We keep an itemised list of the current sub-processors, with each one’s purpose, location and transfer safeguard, and provide it with the data processing agreement. We notify customers before we add or change a sub-processor.

8. International transfers

Your school’s records are held in the UK and the European Economic Area. Some of the service providers above are not UK entities and may process limited data outside the UK. Where that happens, the transfer is covered by an approved safeguard, the UK International Data Transfer Agreement or the UK Addendum to the Standard Contractual Clauses, together with a transfer risk assessment. Data residency options for the service are described on our security page.

9. How long we keep it

We keep personal data only as long as we need it for the purpose we collected it, then delete or anonymise it. Enquiry data is kept while a conversation is live and for a reasonable period after. Customer records are kept for the life of the account and for the period we are required to keep business and tax records afterwards. Product records are retained as the school directs, reconciled with the retention a training organisation is itself required to keep.

Some records must be kept by law and cannot be erased on request while that duty lasts. A training record, for example, is retained for the period a training organisation must keep it, three years after course completion for a DTO under DTO.GEN.220. A distinction follows from this: the expiry date recorded from a medical certificate is a training record kept for that period, while the uploaded scan of the certificate is special-category data and is minimised sooner. The two are deliberately kept for different lengths of time.

10. Children and young people

Flight training reaches young people. A student pilot can be sixteen, and a junior club member can be younger, so a school may hold personal data about under-18s in FlyerOS and give them an account.

In the UK a child can consent to an online service from the age of 13; below that, consent-based processing needs a person with parental responsibility. Where a school enrols a younger member, obtaining that authorisation is the school’s responsibility as the controller. We design for data minimisation, and we do not profile students or use their data for advertising.

11. Your rights

Under the UK GDPR you have the right to:

  • ask what personal data we hold about you and get a copy;
  • have inaccurate data corrected;
  • have data erased, where the law requires;
  • restrict or object to our processing, including profiling;
  • receive data you gave us in a portable form; and
  • withdraw consent at any time, where our basis is consent.

To exercise a right, email info@flyeros.co.uk. We respond within one month and do not charge for a normal request. If you are a student or staff member of a school, your rights over data in the product are exercised through that school as the controller, and we support the school in meeting them.

12. Automated decisions

We do not make decisions about you by solely automated means that produce legal or similarly significant effects. The eligibility checks inside the product are a tool operated by the school under its own procedures, not an automated decision made by us about you.

13. Keeping your data secure

We use technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls, isolation between customers, and logging. Our approach is set out on the security page. If a personal data breach is likely to result in a risk to your rights, we will notify the people and authorities the law requires, without undue delay.

14. How to complain

If you have a concern, please raise it with us first at info@flyeros.co.uk so we can put it right. You also have the right to complain to the Information Commissioner’s Office, the UK regulator, at ico.org.uk or on 0303 123 1113.

15. Changes to this policy

We may update this policy from time to time. The current version is always on this page, with the date it was last updated at the top. Where a change is significant, we will take reasonable steps to bring it to your attention.

16. How to contact us

For anything in this policy, or a data request, email info@flyeros.co.uk.