Privacy Policy
Heliplan — Flightcode Ltd  ·  Last updated: March 2026

1. About This Policy

This Privacy Policy explains how Flightcode Ltd ("we", "us", "our") collects, uses, stores and protects personal data when you use the Heliplan platform and website ("the Service"). Flightcode Ltd is registered in England and Wales (Company No. 13788994), 67 Falsgrave Road, Scarborough, North Yorkshire, YO12 5EA.

We are committed to protecting your privacy and handling your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy applies to all users of the Heliplan platform and visitors to https://heliplan.co.uk.

We may update this policy from time to time. The current version is always available at https://heliplan.co.uk/privacy.

2. What Personal Data We Collect

2.1 Data provided by your organisation

Where Heliplan is used by an organisation (the data controller), that organisation may enter the following categories of personal data about their personnel into the system:

Identity data: e.g. names of crew members and operational staff
Contact data: e.g. email addresses and telephone numbers
Professional data: e.g. job titles, employee or staff identifiers, role qualifications

2.2 Data generated by your use of the Service

When you access and use Heliplan, we automatically collect certain technical data:

IP address and approximate location
User account identifier and login credentials (passwords are stored in hashed form and never in plain text)
Login timestamps, session data, and authentication events
System-generated audit logs recording authentication and access activity
Browser type and operating system

2.3 Data we do not collect

Heliplan does not collect or process special category (sensitive) personal data, including health data, biometric data, racial or ethnic origin, religious beliefs, criminal records, or financial data. Heliplan does not process credit card or payment information — any payments are processed directly by third-party payment providers integrated with the platform, and no payment card data passes through or is stored by Heliplan.

3. How We Use Your Personal Data

We process personal data for the following purposes:

To provide and operate the Heliplan service, including managing user accounts and enabling operational flight planning and scheduling functionality
To maintain accurate operational records and audit trails as required for safe helicopter operations
To send transactional communications, including account notifications, system alerts, and password reset emails
To maintain the security of the platform, including detecting and preventing unauthorised access
To comply with our legal obligations

We do not use personal data for marketing purposes, profiling, automated decision-making, or any purpose incompatible with the operational purposes for which it was collected. We do not sell personal data to third parties.

4. Legal Basis for Processing

We process personal data on the following legal bases under UK GDPR:

Contractual necessity: processing is necessary to perform the service agreement with your organisation
Legitimate interests: processing is necessary for the legitimate operational interests of your organisation in managing helicopter flight operations safely and compliantly
Legal obligation: where processing is required to comply with applicable law

5. Third-Party Services and Sub-Processors

We use the following sub-processors to deliver the Heliplan service. All sub-processors are contractually bound to process personal data only as directed by us and in accordance with applicable data protection law:

Akamai Technologies (Linode) — cloud hosting infrastructure, London UK. Certified to ISO 27001, SOC 2 Type II, PCI DSS
Amazon Web Services (AWS) — encrypted backup storage, London UK region. Certified to ISO 27001, SOC 2 Type II, PCI DSS
Cloudflare Inc — web application firewall, DDoS protection, and access security
Google LLC — Google Maps APIs used within the platform for mapping and location functionality. Google's use of data is governed by the Google Privacy Policy
Postmark (ActiveCampaign) — transactional email delivery
Sentry Inc — error monitoring and performance tracking. Sentry processes data under standard contractual clauses and is certified to ISO 27001, SOC 2 Type II

We do not transfer personal data outside the United Kingdom. With the exception of error monitoring data processed by Sentry (USA), all primary data storage and backup infrastructure is located in UK-based data centres.

6. Data Retention

Backup archives are retained for a maximum of 365 days, after which they are permanently and irrecoverably deleted.

7. Security

We implement appropriate technical and organisational measures including encryption in transit and at rest, access controls, and security monitoring.

8. Cookies

Heliplan uses the following types of cookies:

Essential cookies: required for the platform to function, including session authentication cookies. These cannot be disabled
Security cookies: used to protect against cross-site request forgery (CSRF) attacks

We do not use advertising cookies, tracking cookies, or third-party analytics cookies within the authenticated platform. The Heliplan marketing website may use analytics cookies to understand how visitors use the site. You can control cookies through your browser settings.

9. Your Rights

Under UK GDPR, you have the following rights in relation to your personal data:

Right of access: you can request a copy of the personal data we hold about you
Right to rectification: you can request correction of inaccurate or incomplete personal data
Right to erasure: you can request deletion of your personal data, subject to our legal obligations and backup retention timescales described in Section 6
Right to restriction: you can request that we restrict processing of your personal data in certain circumstances
Right to data portability: you can request a copy of your personal data in a structured, machine-readable format
Right to object: you can object to processing based on legitimate interests

To exercise any of these rights, please contact us at [email protected]. Where Heliplan is used by your organisation, requests should in the first instance be directed to your organisation as the data controller, who may then engage Flightcode Ltd on your behalf. We will respond to all requests within 30 days.

10. Third-Party Links

The Heliplan platform may contain links to third-party websites. We are not responsible for the privacy practices of those websites and recommend you review their privacy policies before providing any personal data.

11. Changes to This Policy

We may update this Privacy Policy from time to time. The current version is always available at https://heliplan.co.uk/privacy. Material changes will be notified to users via email or in-platform notification.

12. Contact Us

If you have any questions about this Privacy Policy or how we handle your personal data, please contact us:

Post: Flightcode Ltd, 67 Falsgrave Road, Scarborough, North Yorkshire, YO12 5EA

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at https://ico.org.uk.

Flightcode Ltd  ·  Company No. 13788994  ·  Registered in England and Wales  ·  Last updated March 2026