SkyDynamics
Privacy Policy
How SkyDynamics collects, uses, and safeguards your information when you use our website and services.
Privacy Policy
Last updated: 2 October 2026
This Privacy Policy ("Policy") explains how SkyDynamics ("Company," "we," "us," or "our") collects, uses, processes, discloses, and safeguards your information when you use our website located at https://skydynamics.aero and all associated services, platforms, and applications (collectively, the "Services"). This Policy applies to all visitors, users, Authorised Users, and representatives of Authorised Organisations.
This Policy is designed to comply with the EU General Data Protection Regulation 2016/679 ("GDPR"), the Swiss Federal Act on Data Protection ("FADP"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and other applicable US state privacy laws. Where specific provisions apply to particular jurisdictions, they are identified accordingly.
1. Data Controller
1.1. SkyDynamics, with its principal office at N. Plastira 100, Step-C Technology Park, Foundation for Research & Technology Hellas, 70013 Heraklion, Crete, Greece, is the data controller responsible for your personal data processed through the Services.
1.2. For data protection inquiries, you may contact us at info@skydynamics.aero.
1.3. EU Representative: For purposes of Article 27 GDPR, SkyDynamics' representative in the European Union is SkyDynamics, located at the above Greek address.
1.4. Swiss Representative: For purposes of the Swiss FADP, SkyDynamics' representative in Switzerland may be designated upon written request.
2. Information We Collect
We collect the following categories of information:
2.1. Information You Provide Directly:
- Account registration data (name, email address, telephone number, organisation name, job title)
- Aircraft and operational data entered by Authorised Users (aircraft types, tail numbers, flight data, maintenance records)
- Training and competency records (pilot qualifications, instructor certifications, grading data, scenario records)
- Communication records (emails, support tickets, contact form submissions)
- Billing and payment information processed through our payment providers
2.2. Information Collected Automatically:
- Technical data (IP address, browser type and version, operating system, device identifiers)
- Usage data (pages visited, features used, session duration, click patterns)
- Cookies and similar tracking technologies (see Section 7)
- Log data (access timestamps, error logs, referring/exit URLs)
2.3. Information from Third Parties:
- Single sign-on (SSO) providers (e.g., Microsoft 365 Azure AD, Google Workspace) when you choose to authenticate via these services
- Integration partners when you connect third-party systems to the Services
2.4. Sensitive Data: We do not intentionally collect special categories of personal data (as defined in Article 9 GDPR) such as racial or ethnic origin, political opinions, religious beliefs, or biometric data. However, certain training records may indirectly reveal health-related information (e.g., medical fitness to fly). Such data is processed only where necessary for regulatory compliance and with appropriate safeguards.
3. Legal Basis for Processing (GDPR / FADP)
We process your personal data under the following legal bases:
3.1. Contract performance (Art. 6(1)(b) GDPR): Processing necessary for the performance of our contract with you or your Authorised Organisation.
3.2. Legitimate interests (Art. 6(1)(f) GDPR): Processing necessary for our legitimate interests, including operating and improving the Services, ensuring security, preventing fraud, and conducting analytics that do not rely on cookies or similar technologies, provided that your interests and fundamental rights do not override our interests. Analytics on our website that uses cookies relies on your consent (see 3.4 and Section 7).
3.3. Legal obligation (Art. 6(1)(c) GDPR): Processing necessary to comply with applicable legal obligations, including Aviation Regulations, tax laws, and anti-money laundering requirements.
3.4. Consent (Art. 6(1)(a) GDPR): Where we process data based on your consent (e.g., marketing communications, non-essential cookies), you may withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
4. How We Use Your Information
We use the information we collect to:
- Provide, maintain, administer, and improve the Services
- Process transactions and manage your account
- Authenticate your identity and verify access permissions
- Generate training reports, compliance documentation, and analytics
- Send technical notices, security alerts, and support messages
- Respond to your inquiries, comments, and requests
- Conduct research and development to enhance the Services
- Protect against fraudulent, unauthorised, or illegal activity
- Comply with legal and regulatory obligations, including aviation safety regulations
- Enforce our Terms of Use and other agreements
5. Data Sharing and Disclosure
5.1. We do not sell your personal data to any third party.
5.2. We may share your personal data in the following circumstances:
- Service providers: With third-party processors who perform services on our behalf (cloud hosting providers, payment processors, email delivery services, analytics providers), under contractual data processing agreements that comply with Article 28 GDPR.
- Authorised Organisations: With your employer or Authorised Organisation, where the data relates to your use of the Services on their behalf.
- Regulatory authorities: With aviation regulatory authorities (EASA, HCAA, FAA, FOCA, ICAO) when required by law or when necessary to demonstrate regulatory compliance on behalf of an Authorised Organisation.
- Legal compliance: When required by law, regulation, legal process, or governmental request.
- Protection of rights: To protect the rights, property, or safety of SkyDynamics, its users, or the public.
- Business transfers: In connection with a merger, acquisition, reorganisation, or sale of assets, subject to confidentiality obligations.
5.3. Third-party integrations: When you use integrations with third-party services (e.g., Microsoft 365, Google Workspace, Dropbox), data may be shared with those third-party providers under their own privacy policies. SkyDynamics is not responsible for the privacy practices of third-party services. For more information, see our Legal Disclaimer regarding third-party services.
6. International Data Transfers
6.1. SkyDynamics is headquartered in Greece (EU/EEA). Your personal data may be transferred to and processed in countries outside the EU/EEA, including the United States and Switzerland.
6.2. EU-to-US transfers: When transferring personal data to the United States, we rely on:
- The EU-US Data Privacy Framework (where the recipient is certified), or
- Standard Contractual Clauses (SCCs) approved by the European Commission under Article 46(2)(c) GDPR, supplemented by a transfer impact assessment, or
- Your explicit consent under Article 49(1)(a) GDPR where no other safeguard applies.
6.3. Swiss transfers: Transfers from Switzerland to countries without an adequacy decision under the Swiss FADP are protected by the same Standard Contractual Clauses, adapted for Swiss law.
6.4. Data residency: Where the Services offer configurable data residency (e.g., sovereign data centres, jurisdictional clustering), your data will not be transferred across jurisdictional boundaries without your explicit instruction.
7. Cookies and Tracking Technologies
7.1. Our Cookie Policy lists every cookie and storage item the website uses, with its purpose and how long it is kept, and lets you change your choice at any time. It forms part of this Policy.
7.2. What the website stores on your device:
- Necessary storage: Remembers your cookie choice and interface state, such as the light or dark theme. It holds no identifier, stays in your browser and is never sent to us. It needs no consent under Article 4(5) of Greek Law 3471/2006 and Article 5(3) of Directive 2002/58/EC.
- Analytics cookies: Set by Google Analytics 4 to help us understand how visitors use the website (page views, scroll depth, use of buttons and links, loading performance). They are set only with your consent.
The website uses no advertising cookies, no social media trackers and no embedded third-party content.
7.3. Consent: On your first visit we ask whether you accept analytics cookies. Rejecting is as easy as accepting, and using the website never depends on accepting. Until you accept, no analytics script is loaded and no connection to Google is opened. We keep your choice for 180 days and then ask again, or sooner if the Cookie Policy changes in a way that matters to you.
7.4. Withdrawing consent: You can change your choice at any time with "Cookie settings" in the footer of every page. When you switch analytics off, we stop Google Analytics and delete its cookies from your browser. You can also delete or block cookies in your browser settings; the website keeps working if you do.
7.5. Google Analytics: Google Analytics 4 is provided by Google Ireland Limited, which acts as our processor. Google signals and advertising personalisation are switched off. Google may process analytics data in the United States under the safeguards described in Section 6.
7.6. Global Privacy Control and Do Not Track: If your browser sends a Global Privacy Control signal, we treat it as a refusal of analytics cookies. We do not respond to other "Do Not Track" (DNT) signals, as no industry-wide DNT standard has been adopted.
7.7. Applications: The SkyDynamics applications use strictly necessary cookies and similar technologies for authentication, session management and security.
8. Data Security
8.1. We implement appropriate technical and organisational measures to protect the security of your personal information, including:
- Encryption of data in transit (TLS 1.3) and at rest (AES-256)
- Role-based access controls and multi-factor authentication
- Regular security assessments, penetration testing, and vulnerability scanning
- Information security management aligned with ISO 27001
- Alignment with EASA Part-IS (Implementing Regulation (EU) 2023/203) requirements
8.2. While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data.
9. Data Retention
9.1. We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including:
- For the duration of your account or your Authorised Organisation's subscription
- As required to comply with legal obligations (including aviation record-keeping requirements, which may require retention for periods of up to 10 years or longer)
- To resolve disputes and enforce our agreements
9.2. Upon account termination, personal data will be deleted or anonymised within ninety (90) days, unless longer retention is required by law.
10. Your Data Protection Rights
10.1. GDPR Rights (EU/EEA and Switzerland): Subject to applicable legal exceptions, you have the right to:
- Access (Art. 15): Obtain a copy of your personal data
- Rectification (Art. 16): Correct inaccurate or incomplete personal data
- Erasure (Art. 17): Request deletion of your personal data ("right to be forgotten")
- Restriction (Art. 18): Request restriction of processing
- Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format
- Object (Art. 21): Object to processing based on legitimate interests
- Withdraw consent (Art. 7(3)): Where processing is based on consent, withdraw it at any time
10.2. Swiss FADP Rights: In addition to the above, under the revised Swiss FADP (effective 1 September 2023), you have the right to obtain information about the logic involved in automated decision-making that produces legal effects or similarly significantly affects you.
10.3. US State Privacy Law Rights (California, Colorado, Connecticut, Virginia, Utah, and others): Depending on your state of residence, you may have the right to:
- Know what personal information is collected, used, and disclosed
- Delete personal information
- Correct inaccurate personal information
- Opt out of the sale or sharing of personal information (SkyDynamics does not sell personal information)
- Non-discrimination for exercising your privacy rights
- Limit the use of sensitive personal information
10.4. Exercising your rights: To exercise any of the above rights, please contact us at info@skydynamics.aero. We will respond within the timeframes required by applicable law (30 days under GDPR, 45 days under CCPA/CPRA).
10.5. Right to lodge a complaint:
- EU/EEA: You have the right to lodge a complaint with your local supervisory authority. For Greece, the Hellenic Data Protection Authority (HDPA), www.dpa.gr.
- Switzerland: You may lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC).
- United States: You may contact your state's Attorney General.
11. Children's Privacy
The Services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you believe we have collected personal information from a child under 16, please contact us immediately and we will take steps to delete such information.
12. Automated Decision-Making and Profiling
12.1. The Services may use automated processing, including AI-powered analytics (AeroBrain), to identify training patterns, competency trends, and operational insights. Such processing is designed to assist Authorised Organisations in their training and operational decision-making.
12.2. No automated decisions produce legal effects or similarly significant effects on individual data subjects without human review. All regulatory compliance decisions, disciplinary actions, and certification determinations require human oversight by qualified personnel of the Authorised Organisation.
13. Changes to This Policy
13.1. We may update this Policy from time to time. Material changes will be notified by email to the address associated with your account or by prominent notice on the Services at least thirty (30) days before the effective date.
13.2. Your continued use of the Services after the effective date of any modification constitutes acceptance of the updated Policy.
14. Contact
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
- Email: info@skydynamics.aero
- Subject line: "Data Protection Inquiry"
Registered offices:
- N. Plastira 100, Step-C Technology Park, Foundation for Research & Technology Hellas, 70013 Heraklion, Crete, Greece
- 8 The Green, Ste. B, Dover, DE 19901, USA

