1. Data controller
The controller of the personal data processed through this website and through the Wasim platform is:
TODO_FILL_CIF2. Personal data we process
Depending on how you interact with us, we may process the following categories of personal data:
- Identification and contact data: first name, last name, email address, telephone number, professional address.
- Account data: credentials (in hashed form), the organisation membership you belong to, role inside that organisation, language and interface preferences.
- Training data (when you are a student or instructor of an ATO that uses Wasim TMS): programme enrolments, lesson and exercise records, qualifications, expiry dates, training documents you upload, logbook entries, briefing/debriefing records and skill-test results.
- Operational data: simulator agent logs, test-run telemetry and discrepancy records associated with your organisation's devices.
- Commercial data: contact-form submissions, enrolment requests, invoicing and payment records (when applicable).
- Browsing data: IP address, device and browser identifiers, access timestamps and information collected via cookies in the terms set out in our Cookies Policy.
We do not knowingly collect data from minors under the age of 14; if you believe a minor has provided us with personal data without parental authorisation, please contact us so we may delete it.
3. Sources of the data
Most of the personal data we process is provided directly by the data subject (when filling in a form, signing up, uploading a document or interacting with the platform). Where data is provided on a person's behalf — for example by an Approved Training Organisation enrolling its students — we rely on the originating organisation having a valid legal basis to share that data with us as a processor.
4. Purposes and legal bases of processing
We process personal data for the following purposes:
5. Recipients and international transfers
Personal data may be disclosed to:
- The Approved Training Organisation, examiner, instructor or regulator that has a legitimate need to receive it within the scope of the training process.
- Public authorities (tax authorities, social security, the Spanish Aviation Safety and Security Agency — AESA, courts of justice) when there is a legal obligation to do so.
- External providers acting as data processors under written agreements that comply with Article 28 GDPR — for example cloud-hosting providers, e-mail-delivery providers and payment processors. We choose providers offering adequate guarantees of security and confidentiality.
Where a transfer outside the European Economic Area is necessary, we use the legal mechanisms foreseen in the GDPR (adequacy decisions, Standard Contractual Clauses or, exceptionally, the derogations of Article 49). You may request a copy of the guarantees applied by writing to TODO_FILL_PRIVACY_EMAIL.
6. Retention periods
We keep personal data only for as long as it is needed for the purpose for which it was collected and, thereafter, for the periods required by applicable law (in particular tax, accounting, commercial and aviation-training records). Concretely:
- Account data: while the account is active, plus a reasonable period after closure to handle incidents and legal claims.
- Training records: for as long as the originating ATO requires under EASA record-keeping obligations and any longer period imposed by national law.
- Invoicing and accounting records: at least the terms required by Spanish tax and commercial law (typically six years from issue).
- Contact and enquiry data: the time needed to handle the request and a short window thereafter unless the contact converts into a contractual relationship.
- Cookie data: as set out in the Cookies Policy.
7. Your rights
At any time, and free of charge, you may exercise the following rights in relation to your personal data:
- Access — confirm whether we are processing your data and obtain a copy of it.
- Rectification — correct inaccurate or incomplete data.
- Erasure — ask us to delete data when it is no longer needed or when consent is withdrawn, subject to legal-retention obligations.
- Restriction — limit the processing of your data while a question about its accuracy or about the legal basis is resolved.
- Objection — object to processing based on legitimate interest, including profiling.
- Portability — receive in a structured, machine-readable format the data you have provided to us, and ask for it to be transmitted to another controller where technically feasible.
- Withdraw consent — at any time and without retroactive effect on processing already carried out.
- Not be subject to a decision based solely on automated processing that produces legal effects on you, except in the cases foreseen by law.
To exercise these rights, write to TODO_FILL_PRIVACY_EMAIL or to the registered office at Calle Camino de Caicena, 33, casa 1, 18008 Granada, Spain, identifying yourself and indicating clearly which right you wish to exercise. We will respond within the legal deadlines (one month, extendable by two further months for complex requests).
You also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos), www.aepd.es, in particular if you consider that we have not addressed your rights properly.
8. Security measures
We apply the technical and organisational measures required by Article 32 GDPR to ensure a level of security appropriate to the risk of the processing — in particular pseudonymisation and encryption of data in transit, access controls, segregation of production environments, regular backups and a documented incident response process.
9. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in our services, in the legal framework or in the way we process personal data. The version in force at any time is the one published at this URL, with the "Effective" date at the top of the page updated accordingly. Material changes will be notified to active users by reasonable means.