Privacy Policy
PlannAir application and website · Version 1.0 · Effective from: 1
August 2026
This policy describes what personal data AeroTech Services Kft.
processes in the course of operating the PlannAir application and
the plannair.hu website, for what purpose and for how long, to whom
it is disclosed, and what rights you have in relation to all of
this.
1. The controller
- Name
- AeroTech Services Kft. (limited liability company)
- Registered seat
- 2621 Verőce, Tábor út 11., Hungary
- Company registration number
-
13-09-235634 (Company Court of the Pest County Regional Court)
- VAT number
- 32622726-2-13
- Represented by
- Adorján Balázs Péter, managing director
- Data protection contact
-
privacy@plannair.hu
- Customer support
-
support@plannair.hu
We have not appointed a data protection officer, because under
Article 37 GDPR we are not required to do so: we are not a public
authority, we do not carry out large-scale, regular and systematic
monitoring, and we do not process special categories of data on a
large scale. You can contact us with your data protection questions
at the e-mail address above.
2. Our two distinct roles
PlannAir is used within organizations (companies). Because of this
we process data in two different roles, and the two differ from each
other legally:
-
We act as controller in respect of the data
relating to the user account: registration, login, profile, error
reports, customer support. We are the ones who decide that these
are necessary — this policy is about that.
-
We act as processor in respect of everything that
users put into the application: projects, groups, duct pieces,
exports, as well as permissions within the organization. These are
controlled by the given organization: it is the
controller, and we store and process them on its instructions,
within the framework of the data processing agreement concluded
with it. If you use PlannAir as an employee, the notice provided
by your employer is primarily what governs in respect of these.
3. What data we process and for what purpose
Creating an account, logging in
- Data processed
-
e-mail address, the encrypted hash of the password or the
identifier of the Google account, the name and the profile
picture link received from the Google account, time of last
login
- Legal basis
- performance of a contract (Article 6(1)(b))
- Retention
- until the account is deleted, plus a further 30 days
Profile and identifiability within the organization
- Data processed
-
display name, profile picture, and personal settings visible
solely to you
- Legal basis
- performance of a contract (Article 6(1)(b))
- Retention
- until the account is deleted, plus a further 30 days
Login security log
- Data processed
- IP address, time, type of the event
- Legal basis
-
legitimate interests (Article 6(1)(f)): detecting abuse, account
security
- Retention
- 90 days
Providing the service, synchronization across devices
- Data processed
-
projects, groups, duct pieces, exports, and the record of who
created or modified these and when
- Legal basis
-
the instruction of the organization as controller (we act as
processor)
- Retention
- as decided by the organization
Troubleshooting, crash reporting
- Data processed
-
the user’s identifier (a random identifier, without name
and e-mail address), the organization’s identifier,
application and system version, the screen concerned, the
technical data of the error; depending on the error, the content
of the affected data as well
- Legal basis
-
legitimate interests (Article 6(1)(f)): the operability of the
service
- Retention
- at most 90 days
Error report sent by the user
- Data processed
- the text of the report and the user’s identifier
- Legal basis
-
legitimate interests (Article 6(1)(f)): investigating the report
- Retention
- at most 90 days
Customer support, keeping in contact
- Data processed
- e-mail address, name, the content of the correspondence
- Legal basis
-
performance of a contract, and legitimate interests (Article
6(1)(b) and (f))
- Retention
- 1 year from the closure of the matter
Serving the website and the application
- Data processed
-
IP address, browser identifier, the address of the requested
page, time
- Legal basis
-
legitimate interests (Article 6(1)(f)): operational security
- Retention
- 15 days
Statistical analysis, development of the service
- Data processed
-
aggregated metrics calculated from the data above (see section
7)
- Legal basis
-
further use for statistical purposes (Article 5(1)(b) and
Article 89)
- Retention
- the aggregated, anonymous result for an unlimited period
We receive the data from you, or — in the case of logging in with a
Google account — from Google. If you were invited to PlannAir by an
organization, the permission data relating to you is provided by a
member of the organization authorized to do so.
4. Who has access to the data
We do not sell the data and we do not disclose it to third parties
for marketing purposes. We use the following processors to operate
the service:
Supabase, Inc. (USA)
- What it does
- database, authentication, real-time synchronization
- Where the data is stored
- Frankfurt, Germany (AWS eu-central-1)
DigitalOcean, LLC (USA)
- What it does
- web server, internal reporting system
- Where the data is stored
- Frankfurt, Germany (FRA1)
Functional Software, Inc. (Sentry, USA)
- What it does
- receiving and storing error reports
- Where the data is stored
- European Union (Frankfurt)
Google Ireland Ltd. (Ireland)
- What it does
-
logging in with a Google account, distribution of the
application through the Google Play store
- Where the data is stored
- European Union / United States
Apple Distribution International Ltd. (Ireland)
- What it does
-
distribution of the application through the App Store and
TestFlight
- Where the data is stored
- European Union / United States
OpenRouter, Inc. (USA) and the model provider routed through it
- What it does
- operating our internal reporting system (see section 6)
- Where the data is stored
- receives no personal data
Leaning Technologies Ltd. (United Kingdom)
- What it does
-
serving the runtime environment of the Excel export in the web
version — sees technical data only (IP address, browser)
- Where the data is stored
-
United Kingdom — the transfer is covered by the European
Commission’s adequacy decision or, failing that, by
standard contractual clauses
Transfers outside the European Union
We store your data within the European Union: the
database, the servers and the error reports are all in data centres
in Frankfurt. Some of the providers above belong to a US parent
company, and therefore have a theoretical possibility of accessing
the data in the course of technical support. This is safeguarded by
the standard contractual clauses (SCC) adopted by the European
Commission, and — where the provider is certified — by the EU–US
Data Privacy Framework. No personal data reaches the model provider
used by our internal reporting system (see section 6).
5. How long we keep the data
The retention period belonging to each purpose is set out in the
table in section 3. In addition:
-
Backups: a backup of the database is made daily
and stored by our provider for 7 days. In
addition, we make a weekly encrypted copy which we keep for
30 days.
-
Operational logs: the platform logs of the
database provider are available for 7 days.
-
Deleting the account: upon receipt of the
deletion request we immediately close the account and make the
data inaccessible, and then delete it permanently after
30 days. These 30 days serve to allow a deletion
started by mistake to be revoked. Permanently deleted data
disappears from the backups within a further 30 days at the
latest. Error reports are not deleted together with the account;
they expire at the end of their own retention period — after 90
days at the latest.
The content of the organization (projects, duct pieces, exports) is
not your personal data but the organization's: it remains with the
organization even after your account is deleted. Your name is
removed from the items created by you.
6. Automated internal reporting
We use a system based on artificial intelligence to follow how the
service is running and to produce internal statistics. This system
has no access to personal data: it reads the
database solely through a view layer that discloses no names and no
contact details, and none of the organisations’ content either
— no project, group or idom names, no dimensions, no comments. What
it sees is identifiers, types, counts and timestamps.
The system does not read customer correspondence,
nor does it have access to the error reports, and it takes no part
in answering enquiries. Since no personal data reaches it, no such
data reaches the model provider operating it either.
The system
does not take decisions based solely on automated processing that
produce legal effects concerning you
within the meaning of Article 22 GDPR: every substantive decision —
closing an account, modifying a permission, deciding on a request —
is taken by a human.
7. Statistical use
For the development of the service, the measurement of its
performance and for our business decisions we produce aggregated,
averaged and calculated statistics from the data processed. The GDPR
expressly permits this as use compatible with the original purpose
(Article 5(1)(b) and Article 89), with the following safeguards:
-
the result is anonymous: it contains no name,
e-mail address or individual identifier, and is not capable of
identifying any single person;
-
we do not produce any breakdown from which the
activity of a single person or of a group of
fewer than five people could be reconstructed;
-
we do not use the statistics to take decisions affecting an
individual user or organization.
8. Data security
-
all data transmission takes place over an encrypted channel (TLS),
and passwords are stored exclusively as a one-way hash;
-
the database applies
row-level access control: the database itself
decides which row a user may see — not just the application;
-
nobody apart from us and you has access to the private part of the
profile (personal settings), and there is technically no query
path to it; the other members of the organization see only your
name and profile picture;
-
internal access to the service is limited to the necessary
minimum, and is restricted to support purposes.
9. Cookies and local storage
PlannAir
does not use analytics, profiling or advertising cookies, and does not run any third-party tracking code. We store on your
device only the data strictly necessary for operation, for which no
consent is required under the electronic communications rules:
- the identifier token that keeps you logged in;
-
a local copy of your projects, so that the application can be used
without an internet connection as well;
- the application's settings (for example theme, language).
This data remains on your device. On logout the login token is
deleted; the local copy ceases to exist when the application's data
is cleared or the application is uninstalled.
10. Your rights
You may at any time request from us:
-
information about and a copy of the data
processed about you (Article 15);
-
rectification, if any of your data is inaccurate
(Article 16);
-
erasure (Article 17), within the framework of
retention obligations based on law;
- restriction of processing (Article 18);
-
data portability: the release of your data in a
machine-readable format (Article 20);
-
to object to processing based on legitimate
interests (Article 21) — in which case we cease the processing,
unless we can demonstrate compelling legitimate grounds.
Please send your request to
privacy@plannair.hu. We
reply within one month at the latest; in the case
of a complex request this deadline may be extended by two months, of
which we will inform you. The reply is free of charge.
If the data was put into the system by your organization (projects,
duct pieces), then in that respect you must turn to the
organization — we forward any such request received
by us to it, and assist in fulfilling it.
Deleting your account
You can delete your account yourself from inside the app, on the
Account page — the
deleting your account page
describes it step by step. If you cannot sign in, you can also
request the deletion at
privacy@plannair.hu, in a
message sent from the e-mail address belonging to your account. The
deletion procedure is described in section 5.
11. Remedies
If you feel that your data is not being processed properly, please
contact us first at
privacy@plannair.hu — most
questions are resolved fastest this way. Independently of this, you
may lodge a complaint with the supervisory authority at any time:
Hungarian National Authority for Data Protection and Freedom of
Information (NAIH)
1055 Budapest, Falk Miksa utca 9–11., Hungary
Phone: +36 (1) 391-1400
E-mail:
ugyfelszolgalat@naih.hu
Website: naih.hu
In the event of an infringement of your rights you may also turn to
the courts. The proceedings may — at your choice — also be brought
before the regional court of your place of residence or place of
stay.
12. Age limit
PlannAir is made for professional, business use; it is not aimed at
children. We do not provide the service to users under the age of
16, and we do not knowingly process data originating from them.
13. Changes to this policy
We update this policy from time to time — for example if a new
feature or a new provider is introduced. The version in force at any
given time is available on this page, with the version number and
date indicated at the top. We notify you of material changes in
advance within the service or by e-mail.