Privacy Policy
At AXPA Systems S.L.U. we are committed to protecting the privacy and security of your personal data, in accordance with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD).
1. Data Controller
AXPA Systems S.L.U. (NIF B26941039), registered at CR. Baños de Arteixo, 33, 15008, La Coruña, Spain. Data Protection Officer: Pablo Menéndez-Ponte Alonso — admin@axpa.app.
2. Purpose of Processing
We process the information you provide for the following purposes: (a) Management of your user account and platform access; (b) Provision of contracted services, including flight planning, fleet management, and operational viability analysis; (c) Billing and subscription management; (d) Service-related communications (updates, plan changes, security notifications); (e) Platform improvement through usage analysis (using tools that do not collect personal data); (f) Sending marketing communications about AXPA Systems products, training and offers by email, phone or instant messaging (WhatsApp), only if you have given your express consent.
3. Legal Basis
The legal basis for processing your data is: (a) Contract execution: necessary to provide the requested services; (b) Consent: given upon registration and acceptance of the Terms and Conditions. For marketing communications by phone or instant messaging we request specific, separate consent, which you may refuse without this preventing registration or use of the platform, and which you may withdraw at any time; (c) Legitimate interest: for service improvement and platform security.
4. Data Processed
We collect the following data: registration data (first and last name, email, contact phone number, country of residence and encrypted password); a record of your consents (date of acceptance of the Terms and date of your decision on marketing communications); organization and membership data; fleet data (models, registrations, technical characteristics); flight operation data (geometries, trajectories, operational parameters); technical session data (IP address, browser type, necessary for service security).
5. Recipients
Your data may be communicated to: (a) Cloud infrastructure providers (Vercel, databases) for service hosting; (b) Payment providers (Stripe) for subscription management; (c) Our CRM and marketing automation provider (GoHighLevel, with servers in the United States), to which we send your name, email, phone number, subscription plan, amount paid and the indicator of whether you have consented to marketing communications. This provider acts as a data processor, solely on our instructions, and your phone number is only used for marketing purposes if you have consented to it. This international transfer relies on the Standard Contractual Clauses approved by the European Commission; (d) Competent authorities when legally required; (e) The distributor or reseller organisation (partner) that gave you a promotional code or a licence, at the moment you redeem it: we disclose the plan activated, the redemption date, the validity granted and your email domain, together with your organisation name ONLY where that organisation is a company. If you operate as an individual or sole trader, the partner does not receive your name: you are identified as “an individual customer”. Under no circumstances do we disclose your full email address or your phone number. Where the licence was delivered by a reseller that in turn received its inventory from a distributor, that distributor receives the same minimum information —the plan, the start and expiry dates and your organisation name only where it is a company— in order to manage its channel; that disclosure includes NO email address whatsoever, not even a partially masked one. That partner acts as an independent controller and solely for the purpose of managing its distribution channel (support, commission settlement and tracking of the codes it has handed out), and is contractually forbidden from using that data for its own commercial prospecting or disclosing it to third parties. We do not sell your data, nor do we share it with third parties for their own commercial prospecting.
6. Data Retention
Your data will be retained as long as your user account remains active. After account cancellation, data will be kept blocked for the legally required period to address potential liabilities.
7. Data Subject Rights
You have the right to access, rectify, delete, port, restrict, and object to the processing of your personal data. You may exercise these rights by contacting our DPO at admin@axpa.app. You may also withdraw your consent to marketing communications at any time — from the 'Account Settings' section of the platform or by writing to the DPO — without affecting the lawfulness of processing carried out beforehand. You may also file a complaint with the Spanish Data Protection Agency (www.aepd.es).
8. Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or destruction. Passwords are stored encrypted, communications use secure protocols (HTTPS/TLS), and we apply robust session controls.
9. Account and Data Deletion
You can permanently delete your account and all associated data at any time from the 'Account Settings' section on the platform, using the automated deletion button. Alternatively, you can request the deletion of your account by sending an email to admin@axpa.app. Data will be permanently deleted, except for those that must be retained due to legal obligations.
10. Advertising Measurement and Campaign Attribution
If you consent to the advertising measurement purpose, we process usage data (device and advertising identifiers, IP address, sign-up and purchase events) in order to attribute those events to the campaign that produced them and assess its performance. The legal basis is your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time from the "Privacy preferences" link in the footer or from the application settings. Recipients: Meta Platforms Ireland Limited, as joint controller for the data collected by its pixel; and AppsFlyer Ltd., as data processor for campaign attribution both on the website and within the mobile application, including linking an ad seen on the website to the subsequent app download, which in turn reports aggregated results to the contracted advertising platforms. These processing activities may involve international transfers to the United States, covered by the European Union–United States adequacy framework and, failing that, by standard contractual clauses. On iOS, attribution is performed through Apple's SKAdNetwork, which returns aggregated results and does not allow specific individuals to be identified. If you do not consent, the pixel is not loaded and the application's attribution system is not activated.