Skip to main content
CitadelAero

Legal

Privacy Policy

Version 2.2 · Last updated 28 August 2026

How JLEC Limited, trading as CitadelAero, collects, uses and protects personal data — across our websites, the SMS Platform, Regulatory AI Intelligence, and our consultancy services.

Frameworks: Data Protection (Jersey) Law 2018 · UK GDPR · EU GDPR.

More than one may apply at once. As a Jersey-established company, the Data Protection (Jersey) Law 2018 applies to us in our own right. The UK GDPR applies to processing relating to people in the United Kingdom, and the EU GDPR to people in the European Economic Area. Where they differ, we apply the higher standard. References below to an Article of the UK or EU GDPR should be read as also referring to the corresponding provision of the Jersey Law.

1. Who we are

CitadelAero is the trading name of JLEC Limited, a company incorporated in Jersey, Channel Islands (company number 165488) ("we", "us", "our").

JLEC Limited is registered with the Jersey Office of the Information Commissioner (JOIC) under the Data Protection (Jersey) Law 2018, registration number 103711.

For data protection matters, contact privacy@citadelaero.com.

2. Scope of this policy

This policy applies to personal data we process in connection with:

  • visitors to citadelaero.com and its subdomains, including the demonstration environment;
  • individuals who contact us or make an enquiry;
  • the SMS Platform, at each operator's subdomain;
  • Regulatory AI Intelligence, at ai.citadelaero.com;
  • the billing portal; and
  • Professional Services — our aviation consultancy engagements.

Our products do not share infrastructure. The SMS Platform and Regulatory AI Intelligence run on entirely separate systems, in different countries, with different sub-processors. Where that matters we say which product we mean. Assuming that an answer about one applies to the other will usually be wrong.

3. Our roles: controller and processor

We are a controller in respect of: website visitor data; enquiry and marketing contact data; account administration and billing data; and our own business records. We decide why and how that data is processed, and this policy explains it.

We are a processor in respect of the data our customers put into our products, and the material they give us to carry out consultancy work. The customer is the controller. We act on their instructions under our Data Processing Agreement, and it — not this policy — governs that processing.

If you are an employee or crew member of an operator that uses our products, that operator is the controller of your data. Direct any request about it to them in the first instance. We will assist them, but we cannot act on their data without their instruction.

4. Personal data we process as controller

4.1 Website visitors

What: IP address, browser type and version, operating system, device type, pages viewed, referring source, and approximate location derived from IP address.

Why: to operate and secure the website, and — where you have consented — to understand how it is used.

Lawful basis: legitimate interests (Article 6(1)(f)) for operation and security; consent (Article 6(1)(a)) for analytics.

Retention: raw access logs up to 90 days.

4.2 Enquiries and contact form

What: name, email address, organisation, telephone number where given, and the content of your message.

Why: to respond, and to follow up on a commercial conversation you started.

Lawful basis: steps taken at your request prior to entering a contract (Article 6(1)(b)); legitimate interests.

Retention: up to 2 years from last contact, or longer if a customer relationship develops.

4.3 Account administration and billing

What: names, business email addresses, job titles, organisation details, billing contacts, subscription and invoice records. We do not receive or store payment card details — Paddle acts as merchant of record.

Why: to provide the services, administer accounts, invoice, and keep proper business records.

Lawful basis: performance of a contract (Article 6(1)(b)); legal obligation (Article 6(1)(c)) for financial records.

Retention: for the subscription and 6 years afterwards; financial records 7 years.

4.4 Security and audit logs

What: sign-in events, administrative actions, and security-relevant events.

Why: to detect and investigate unauthorised access and to protect our systems.

Lawful basis: legitimate interests.

Retention: up to 12 months.

5. Personal data we process as processor

Our customers put personal data into our products. Depending on the product and how they use it, this can include employee and crew records, training and competency records, safety reports and investigations, audit findings, and documents they upload.

We process it only to provide, maintain and support the service, on the customer's instructions. We do not sell it, and we do not use it for our own purposes.

We do not use customer data to train, fine-tune or evaluate artificial intelligence or machine learning models, and we do not permit our sub-processors to do so.

6. Protected occurrence data

Where a customer uses our products to record aviation occurrence reports, that data is protected under Regulation (EU) 376/2014 and its UK equivalent. The customer is the controller and is responsible for meeting its own just culture obligations.

We will not access, review, analyse, disclose or use occurrence report data for any purpose other than providing the service — including product development, benchmarking, or the training, fine-tuning or evaluation of AI models — without the customer's express prior written consent. This is an absolute contractual prohibition, and it applies to every product and to our consultancy work.

We will not disclose occurrence report data to any third party, including a regulator, except where required by law or binding court order — in which case we will give the customer prior notice where we lawfully can — or where the customer instructs us in writing.

7. Sub-processors

We engage third parties to help deliver our services. The complete, current list — what each does, where it processes data, and the transfer mechanism that applies — is published on our sub-processors page. In summary, and subject always to that page:

Sub-processorPurposeUsed by
Supabase Inc.Database and file storageSMS Platform
Vercel Inc.Application hosting and deliverySMS Platform
OVHcloudDedicated server hostingRegulatory AI
WorkOS, Inc.Authentication and identityRegulatory AI
Amazon Web ServicesLanguage model inferenceRegulatory AI
Backblaze, Inc.Encrypted off-site backup storageRegulatory AI
Microsoft CorporationTransactional and enquiry emailAll
Paddle.com Market LimitedPayment processing, merchant of recordAll
Google LLC / Google IrelandWebsite analytics (consent only)Website
Microsoft Corporation (Clarity)Website heatmaps and session recordings (consent only)Website

Every sub-processor is bound by a written contract with obligations no less protective than our own. We give customers at least 30 days' notice before adding or replacing one, and they may object on reasonable data protection grounds.

8. Where your data is processed

SMS Platform data is stored at rest in the European Union, in Paris, France.

Regulatory AI Intelligence data is stored at rest in the United Kingdom and the European Union. Uploaded documents, the regulation corpus, the document index and the application database are held on dedicated hosting in the United Kingdom. Encrypted off-site backups of that data are held in the European Union, in Amsterdam, and are encrypted before they leave the hosting server.

Model inference for Regulatory AI is performed in the European Union. When you ask a question, the text of the question and the material retrieved to answer it are sent to our inference provider for the duration of the request, through a geographic inference profile that keeps the request within the EU region set. The provider and the region are named on our sub-processors page.

Jersey and the United Kingdom both hold European Commission adequacy decisions, and the UK treats Jersey as adequate. Movement of data between the EEA, the UK and Jersey therefore needs no additional safeguard. Transfers to the United States are covered by the EU Standard Contractual Clauses and, for UK personal data, the UK International Data Transfer Agreement or Addendum. Copies are available on request.

9. Data security

We take appropriate technical and organisational measures to protect personal data, including:

  • separation of each customer's data at database level;
  • encryption in transit using TLS and at rest at the storage layer;
  • password hashing with bcrypt, with no plain-text storage;
  • session controls with HTTP-only cookies and expiry;
  • role- and capability-based access controls;
  • cross-site request forgery protection on state-changing requests;
  • rate limiting on authentication; and
  • access logging and audit trails.

A fuller description, including our backup position for each product, is in our Security & Trust Overview, available on request from help@citadelaero.com.

No system is completely secure. If you become aware of a security concern or suspected breach, contact us immediately at security@citadelaero.com.

Where a personal data breach is likely to result in a risk to individuals' rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where required, affected individuals. Where we act as processor, we notify the customer.

10. How long we keep data

CategoryRetention
Website access logsUp to 90 days; aggregated anonymised data indefinitely
EnquiriesUp to 2 years from last contact, longer if a relationship develops
Account and commercial recordsDuration of the subscription, plus 6 years
Financial and transactional records7 years
Security and audit logs (as controller)Up to 12 months
Customer data (as processor)30 days after termination, then permanently deleted
Consultancy engagement recordsDuration of the engagement, plus 6 years

11. Professional Services

Where we carry out consultancy work, we may receive personal data from the client — for example in the course of audits, safety management system implementation, incident-investigation support, flight data monitoring work, or personnel selection.

The client is the controller of that data and we act as processor, under the Data Processing Agreement. Where an engagement involves flight data or occurrence data, the additional protections in section 6 apply, together with the client’s own gatekeeper and de-identification arrangements. We agree those in the Statement of Work before the work begins.

We return or delete client material at the end of an engagement, subject to the professional records we are required to retain.

12. Your rights

Where we act as controller of your personal data, you have the right to:

  • be informed about how we use it — this policy;
  • request a copy of it;
  • have inaccurate data corrected;
  • request erasure, in certain circumstances;
  • restrict processing, in certain circumstances;
  • data portability, where processing is by consent or contract and carried out automatically;
  • object to processing based on legitimate interests, and to direct marketing at any time; and
  • withdraw consent at any time, where processing relies on it.

We do not make decisions producing legal or similarly significant effects by automated means alone. Regulatory AI Intelligence generates draft answers and suggestions for a person to review; it does not decide anything about you, and its output is not a determination of compliance.

To exercise a right, contact privacy@citadelaero.com. We may need to verify your identity. We respond within four weeks, which may be extended by up to eight further weeks for complex requests — we will tell you if that applies. Four weeks is the deadline set by Article 28 of the Data Protection (Jersey) Law 2018, and it is shorter than the one month the UK and EU GDPR allow, so it is the one we work to for everyone.

If your data is held by an operator using our products, that operator is the controller — contact them. If you approach us, we will tell you so and, where we can identify the operator, let them know.

13. Complaints

Please raise any concern with us first at privacy@citadelaero.com. You also have the right to complain to a supervisory authority:

  • Jersey — Office of the Information Commissioner (jerseyoic.org)
  • United Kingdom — Information Commissioner's Office (ico.org.uk)
  • EU/EEA — the supervisory authority in your country of residence or work

14. Demonstration environment

Our demonstration environment is populated with fictional data and resets on a recurring cycle. Anything entered into it is destroyed at the next reset. Do not enter real personal data, occurrence data or production data into it.

15. Cookies

Our use of cookies and similar technologies, across all our sites and applications, is described in our Cookie Policy. Analytics cookies are set only with your consent, which you can change at any time.

16. Other sites, and children

Our sites may link to third-party sites. We are not responsible for their privacy practices.

Our services are business tools sold to organisations in the aviation sector. They are not directed at children and we do not knowingly collect children's personal data.

17. Changes to this policy

We may update this policy. Where a change is material we will notify customers by email and update the date at the top. Previous versions are available on request.

18. Contact

JLEC Limited, incorporated in Jersey, Channel Islands. Company number 165488. Our registered office address is available on request.

© JLEC Limited t/a CitadelAero · citadelaero.com · Version 2.2