Version dated 11 September 2026.
Data controller
Arawak Aviation operates this website and its associated team area. For any request concerning personal data, use the protected contact form.
Data collected
The website may process the following data: surname, first name, date of birth, email address, telephone number, WhatsApp, trigram, profile photograph, user role, account-creation date, last sign-in date, last sign-in IP address, public contact requests, administrative mailing campaigns and delivery status, training activity, exercise and test results, instructor assignments, programme enrolments, syllabus versions, licences, ratings, certificates, medical validity, formal ground, flight and FSTD training records, instructor assessments, student acknowledgements, oversight approvals, immutable record hashes, amendments and audit events, appointment participants, times, statuses and timezone snapshots, question comments and private question reports, internal instant messages, internal InMail correspondence and their minimum delivery and security metadata, documents uploaded to the libraries, and ArawakBox content, logical folder locations, file names, MIME types, sizes, integrity hashes, owners, access rules, shared-link metadata and server audit events.
Purposes
These data are used to answer legitimate public contact requests, send necessary group communications to defined account categories, manage accounts, control access, deliver and monitor training, request and book one-to-one training appointments, provide authenticated one-to-one messaging, durable internal correspondence and study discussions, process private question reports, produce student progress reports, display the internal directory, upload and consult documents, secure sensitive actions and administer the website.
Legal basis
Processing is based on Arawak Aviation’s legitimate interest in operating a secure website and team area, on responding to contact and access requests made by users, and on consent when a user voluntarily submits an account request or photograph.
Access to data
Registered users may view selected directory information and their own training record. A student may acknowledge only attendance, awareness, a personal declaration or another explicitly personal object; this acknowledgement is never an instructor assessment or pedagogical validation. Appointment identities and details are visible only to the authenticated student and instructor concerned; other students see an occupied slot only as unavailable. Instant-message and InMail content are available only to the authenticated participants through their respective services; the administration interfaces expose operational metrics but no message-reading function. ArawakBox content is available only where a server-side access rule grants the requested action; external shared links provide download only for the explicitly shared file and can be revoked or expire. Instructors may access training records only for students explicitly assigned to them. Administrators may access the data required to manage accounts, roles, security, instructor assignments, training supervision and documents within their authorised scope. Locked training records are retained; later corrections are recorded as traceable amendments rather than silent replacement.
Retention
Instant-message content is automatically deleted after 90 days. InMail correspondence is retained as durable internal correspondence unless a deletion, account-closure or legal-retention instruction applies. Minimum delivery, security and backup metadata may remain for the limited operational lifetime of the corresponding logs and snapshots. Ordinary profile data are retained for the lifetime of the account unless a shorter period is required. Formal training records, signatures, amendments and their audit trail are not automatically erased when an account closes; their retention is governed separately by applicable training and legal obligations. Rejected or deleted requests may be retained temporarily for administrative follow-up. ArawakBox items are first moved to a recoverable trash; permanent purge is restricted to the SUPER ADMIN. File audit events may be retained after an item is purged to preserve security accountability.
Individual rights
Each user may request access to, rectification, deletion, restriction or export of their data. Requests must be sent through the protected contact form.
Security
The website uses named accounts, protected passwords, PIN codes, access roles, confirmations for sensitive actions and access restrictions for internal files. Instant messaging and InMail are protected in transit by the website’s HTTPS connection but are not end-to-end encrypted.
Cookies and sessions
The website uses technical cookies required for sign-in and session continuity. They are not used for advertising.
Changes
This policy may change as the website develops. The applicable version will be displayed on this page.
