Policy Center

Privacy Policy

Last updated:Jul 20, 2026
Back

Privacy Policy

Draft GDPR privacy notice for business users, company representatives and platform contacts.

Draft version: 2026-07-20

Important legal note

This is a pre-launch draft intended for platform evaluation and testing. It will be reviewed and updated before Aeroclaim becomes commercially available.

Project owner and status
Aeroclaim is an independently owned, early-stage B2B aviation marketplace project based in Croatia.
Owner: Mario Matošević
Country: Croatia
Contact: info@aeroclaim.aero
The platform is currently under development and is not yet available for production use or live commercial transactions.
Legal operator details and final Terms of Service will be updated before commercial launch.
Clause 1

Controller identity and scope

This pre-launch Privacy Policy describes how personal data may be processed during the evaluation and testing of the independently owned Aeroclaim project in Croatia. Privacy inquiries may be sent to info@aeroclaim.aero. Final controller and legal operator details will be published before commercial launch.

This Policy applies to business contact persons, account holders, admin users, insurance representatives, buyer/MRO representatives, support contacts and other individuals whose personal data is processed through the Platform. It does not apply to purely non-personal company data except where such data identifies an individual.

Clause 2

Controller, processor and joint controller roles

For account administration, user verification, security, audit logs, legal compliance, platform operation and marketplace administration, the Operator generally acts as an independent controller because it determines the purposes and means of processing.

Where the Operator processes personal data solely on documented instructions of an Insurance User or other business customer, the Operator may act as processor under a Data Processing Addendum. Where parties jointly determine purposes and means, a joint controller arrangement may be required under GDPR Article 26.

Clause 3

Personal data processed

The Platform may process full name, business email, phone number, company name, position, company country, VAT/tax identifiers, certification details, uploaded certificates, login metadata, IP address, user agent, roles, verification status, audit logs, document access logs, offer messages, notification events and support communications.

Users must not upload unnecessary personal data in claim, maintenance, damage, aircraft or transaction documents. Insurance Users are responsible for redacting unrelated personal data, passenger data, crew data, insured-party private information and special-category data unless strictly necessary and lawful.

Clause 4

Purposes and legal bases

Personal data may be processed to create and administer accounts, verify companies, provide access controls, host Listings and Documents, manage offers, operate the deal desk, send notifications, maintain security, enforce terms, comply with legal obligations, support export/sanctions checks and establish, exercise or defend legal claims.

Legal bases may include contract performance, legitimate interests in operating a secure B2B platform, compliance with legal obligations, consent where required and legal claims. Legitimate interests include fraud prevention, document access control, auditability, cybersecurity, business continuity, aviation documentation integrity and compliance recordkeeping.

Clause 5

Recipients and disclosures

Personal data may be disclosed to authorised Platform admins, relevant business counterparties, service providers, hosting providers, storage providers, email providers, professional advisers, insurers, buyers, repair organisations, logistics providers, authorities or courts where necessary and lawful.

Private Documents are not intended for public disclosure. Approved buyers and authorised admins may access them subject to Platform controls, confidentiality restrictions and document access logging.

Clause 6

International transfers

The Platform is being developed in Croatia for future B2B use and may eventually involve cross-border access. Appropriate safeguards must be implemented before personal data is transferred to jurisdictions without an adequacy decision.

Where data is transferred to jurisdictions without an adequacy decision, appropriate safeguards such as Standard Contractual Clauses, transfer impact assessments, contractual commitments and technical measures should be implemented before production use.

Clause 7

Retention

Personal data is retained for as long as necessary for Platform operation, account administration, verification, legal compliance, transaction evidence, auditability, dispute resolution, aviation traceability, security and legitimate business purposes.

Document access logs, transaction logs, audit logs, offer records and compliance records may be retained for extended periods because they evidence confidentiality, access, chain of custody, export-control review, deal history and legal responsibility. Final retention periods should be approved in the production retention schedule.

Clause 8

Security and breach response

The Operator should maintain technical and organisational measures including authentication, role-based access, private document controls, audit logging, document access logs, secure transport, backups, least-privilege administration and incident response procedures.

Where a personal data breach occurs, notification obligations will be assessed. GDPR may require supervisory authority notification within 72 hours where legally required.

Clause 9

Individual rights

Individuals may have rights of access, rectification, erasure, restriction, portability, objection and complaint under GDPR, subject to applicable exceptions and competing legal obligations.

Requests may be limited or refused where retention is necessary for legal claims, security, aviation documentation, transaction evidence, regulatory compliance, export-control records or protection of rights of other parties.