FlyMate software
FlyMate — privacy policy
This policy describes how personal data is processed in the FlyMate software — web application and iOS application — published by MSDP, in accordance with Regulation (EU) 2016/679 (GDPR). It is separate from the policy covering the www.msdp.eu website.
Who does what
FlyMate is software provided as a hosted service to aviation training organisations, operators and flying clubs. Each organisation has a partitioned space in which it records its own data.
For the data an organisation records in its space — students, pilots, instructors, staff, aircraft, training, accounting — the organisation is the data controller: it decides the purposes and the means. MSDP acts as a processor within the meaning of Article 28 GDPR: it processes that data solely on the organisation’s documented instructions, under a data processing agreement concluded with it.
For a limited number of processing operations of its own — creating and securing platform-level accounts, technical logs, assistance and support — MSDP acts as controller.
In practice: if you are a student, pilot or member of staff at an organisation using FlyMate, your first point of contact for exercising your rights is that organisation. MSDP assists it and can be contacted directly at denis@msdp.eu.
Data processed
Identity and contact details: surname, first name, date of birth, national registration number, postal address, email address, telephone numbers, profile photograph, signature image, VAT number and bank details where the person is invoiced.
Aviation credentials: licences, class and type ratings, instructor and examiner certificates, language proficiency, with their issue and expiry dates, together with the corresponding scanned documents.
Medical certificates: aeromedical class, examination date, expiry, limitations and restrictions, and a scan of the certificate. This data falls within the special categories referred to in Article 9 GDPR (data concerning health) — see the next section.
Travel documents: type, number, nationality, validity dates and scan, where the organisation requires them for its operations.
Operational activity: bookings, flights performed, flight time, crew, instruction sessions, graded exercises, debriefings, progress within a syllabus, examinations, attendance at ground courses.
Signatures and attestations: electronic signature by PIN applied to flight records, training documents and read receipts, with their timestamps.
Accounting data: account balance, movements, invoices, credit notes, shop purchases.
Technical data: login identifiers, session tokens, access and audit logs (author and date of creations and changes), IP address, device and browser type, push notification token for the iOS application.
Health data
Medical fitness certificates are processed because European aviation regulation makes the exercise of licence privileges conditional on their validity. The organisation, as controller, must verify that validity before each flight.
The processing relies on Article 9(2)(b) GDPR — obligations in the field of employment and social security law — combined, where applicable, with Article 9(2)(g), substantial public interest relating to aviation safety. It is strictly limited to what the regulation requires: class, expiry dates and limitations. FlyMate records no diagnosis, no medical examination result and no clinical data.
Scans of medical certificates are subject to reinforced protection: access restricted to the roles authorised by the organisation, encryption at rest, time-limited download links, and reinforced local storage protection in the iOS application.
Purposes and legal bases
Delivery of training and flight operations — scheduling, instruction, progress tracking, issuing of certificates. Legal basis: performance of the contract between the organisation and the individual (Art. 6(1)(b)), and the organisation’s legal obligation under aviation regulation (Art. 6(1)(c)).
Regulatory compliance and safety — pre-flight validity checks, signature traceability, keeping records producible at audit, occurrence reporting. Legal basis: legal obligation (Art. 6(1)(c)) and legitimate interest in operational safety (Art. 6(1)(f)).
Invoicing and accounting — valuing flights, keeping accounts, issuing documents. Legal basis: performance of the contract (Art. 6(1)(b)) and statutory accounting obligation (Art. 6(1)(c)).
Service security and support — technical logs, authentication, assistance. Legal basis: legitimate interest in securing and operating the service correctly (Art. 6(1)(f)).
FlyMate carries out no marketing outreach, no advertising profiling and no resale of data.
No automated decision-making
FlyMate applies deterministic blocking rules — for example refusing a booking when a medical certificate has expired or a rating is not valid. Those rules express explicit regulatory requirements, are configured by the organisation, and can be overridden by an authorised person, with every override logged.
No decision producing legal effects concerning an individual is taken solely on the basis of automated processing within the meaning of Article 22 GDPR, and no profiling is carried out.
Recipients and sub-processors
An organisation’s data is accessible only to the users to whom that organisation has granted the corresponding rights. Partitioning between organisations is enforced at every layer of the software: a person registered with several organisations exposes to each only what concerns it.
MSDP uses the following sub-processors, bound by contract and by confidentiality obligations: Amazon Web Services (storage of files and scanned documents), the hosting provider for the application infrastructure and database, Brevo (transactional email delivery) and Apple (APNs push notification service for the iOS application).
No data is sold, rented or passed to third parties for commercial purposes. Data may be disclosed to the competent aviation authority or to an appointed auditor, at the request and under the responsibility of the organisation.
Data location and transfers
Data is hosted in the European Union. No transfer to a third country is made at MSDP’s initiative. Where a sub-processor may carry out a transfer, it is covered by the appropriate safeguards set out in Chapter V of the GDPR, in particular the European Commission’s standard contractual clauses.
Retention periods
Retention periods are determined by the organisation acting as controller, within the limits imposed by the applicable aviation and accounting regulation. As an indication: training records and regulatory records are kept for the period that regulation prescribes; accounting documents follow Belgian statutory periods; technical logs are kept for no more than twelve months.
At the end of the service contract, the organisation’s data is returned in a usable format and then deleted from MSDP’s systems, save where a legal retention obligation applies, within the period agreed in the data processing agreement.
Security
Exchanges between the applications and the server are encrypted in transit (TLS). Authentication relies on time-limited encrypted tokens. Regulatory signatures require a PIN distinct from the login password. Files are stored in a space dedicated to each organisation and reachable only through short-lived signed links.
In the iOS application: tokens are held in the system keychain, the local database is encrypted through Apple’s data protection mechanisms, with a reinforced level for licence and medical certificate scans. A PIN protects local access, the offline usage window is limited, and all local data is purged on sign-out or when the account is deactivated server-side.
What the iOS application does not do
The application displays no advertising, embeds no advertising network and performs no tracking for targeting purposes. It does not request access to location, contacts, the microphone or the photo library. Camera access is requested only when the user chooses to scan a document, and the result is sent only to their organisation’s server.
No data is sent to any third-party analytics service.
Your rights
You have the rights of access, rectification, erasure, restriction, objection and portability set out in Articles 15 to 22 GDPR.
Those rights are exercised with the organisation that registered you in FlyMate, in its capacity as controller. If you cannot identify or reach it, write to denis@msdp.eu: MSDP will pass on your request and assist the organisation in handling it.
Some data cannot be erased while a regulatory retention obligation subsists — this is notably the case for training records and accounting documents. Where that applies, the reason is given to you and restriction of processing may be applied instead.
You also have the right to lodge a complaint with the Belgian Data Protection Authority (Rue de la Presse 35, 1000 Brussels — www.dataprotectionauthority.be) or with the supervisory authority of your country of residence.
Account deletion
A FlyMate account is created on invitation from an organisation. To be removed from an organisation, address the request to it: removal revokes access without deleting your global account or your access to other organisations.
To request full deletion of your account from the platform, write to denis@msdp.eu from the email address associated with the account. The request is handled within one month. Records that aviation or accounting regulation requires to be kept remain archived with the organisation concerned, under its responsibility, for the prescribed period.
Minors
FlyMate is not intended for consumer use and is not open to self-registration. Where an organisation registers a student who is a minor, it is for that organisation to obtain the consents required by the applicable national law and to keep evidence of them.
Changes
This policy may be amended to reflect changes to the software or to applicable regulation. Client organisations are informed of substantial changes. The date of the last update appears below.
Contact
Publisher of the FlyMate software: MSDP SRL, Rue Antoine Glume 11, 1367 Ramillies, Belgium — denis@msdp.eu. Full details appear in the legal notice.
Given the nature and volume of the processing carried out, MSDP is not required to appoint a data protection officer (Art. 37 GDPR) and has not appointed one. Client organisations may have appointed one of their own.
Last updated :