eAvioraAviation Safety Intelligence
Home
ExperienceContact
Sign inApply to be a partner
00LEGAL · PRIVACY
LAST UPDATED · 2026-04-15

Privacy policy.
Written in English, not in fear.

We do not sell data. We do not run advertising trackers. We do not replay your sessions. What we do collect, what we do with it, who we share it with, and how you take it back — all below, in plain language.

Contents
  1. 01What this document covers
  2. 02Data controller
  3. 03Data we collect on this website
  4. 04Data we collect in the platform
  5. 05Legal basis (GDPR)
  6. 06How we store and protect data
  7. 07Data retention
  8. 08Your rights
  9. 09Sub-processors
  10. 10International transfers
  11. 11Changes to this policy
01

What this document covers

This policy describes how eAviora Technologies Inc. ("eAviora", "we", "our") handles personal data on our public marketing pages (this site) and in the eAviora platform (the product). It applies to visitors, prospects in early-access conversations, and users of the platform.

eAviora is pre-launch. This policy will be revised when the first production tenant goes live. We version it transparently — the last-updated date above is load-bearing.

02

Data controller

The data controller is eAviora Technologies Inc., headquartered in Montreal, Quebec, Canada. For any privacy question, data-subject request, or complaint, contact us at contact@eaviora.com.

03

Data we collect on this website

We collect the minimum we need to run the site and respond to you:

  • Form submissions. Name, work email, organisation, role, topic, and message you type into our contact form.
  • Server logs. Standard HTTP access logs (IP, user agent, request path, timestamp) from our hosting provider (Vercel), used for security and abuse prevention.
  • Essential cookies. A session token for the authenticated platform. No marketing cookies, no advertising trackers, no session replay.

We do not use Google Analytics, Facebook Pixel, Hotjar, or similar trackers.

04

Data we collect in the platform

When your organisation uses the eAviora platform, the data you enter is your operational data:

  • Account data. Name, email, role, and authentication metadata via Supabase Auth.
  • Operational records. Occurrences, hazards, findings, actions, documents, training records, and all other records your team creates. These are yours, held under Row-Level Security per tenant, and never accessed by eAviora staff without your written authorisation.
  • Audit log. Every mutation in the platform is recorded in an append-only auditLog table scoped to your tenant.
05

Legal basis (GDPR)

We rely on the following legal bases under the EU General Data Protection Regulation:

  • Contract. Processing necessary to provide the platform to your organisation.
  • Legitimate interest. Security logging, fraud prevention, and improving the service. Balanced against your rights.
  • Consent. For any optional marketing email (opt-in only — we have none at present).
  • Legal obligation. When a regulator with lawful authority compels disclosure.
06

How we store and protect data

Platform data is stored in Supabase (Postgres) with Row-Level Security enforced at the database layer. Communications use TLS 1.3. Access to production infrastructure is limited to authorised engineers and logged. We do not ship to your data to third-party analytics processors.

Organisations that require it can request a database-per-tenant deployment. Regulators can audit your tenant directly.

07

Data retention

Marketing-form submissions are kept for up to 24 months to respond to your inquiry and maintain conversation context. Operational records inside the platform are retained for the duration of your organisation's subscription plus any contractually-defined retention period. You can export and delete your data on request.

08

Your rights

You have the right to:

  • Access the personal data we hold about you.
  • Correct inaccuracies.
  • Request deletion (subject to legal obligations to retain).
  • Object to processing on legitimate-interest grounds.
  • Port your data to another provider.
  • Lodge a complaint with your supervisory authority.

Write to contact@eaviora.com and we will respond within 30 days.

09

Sub-processors

We use the following sub-processors to operate eAviora:

  • Supabase — Postgres, Auth, Storage.
  • Vercel — hosting, CDN.
  • Resend — transactional email.
  • Inngest — background job execution.
  • Anthropic — the Claude API for classification and analysis. We send only the data required for a given analysis, with deterministic settings against enumerated outputs (same input gives the same output).
  • Cloudflare — DNS and DDoS protection.

Each sub-processor is bound by a data-processing agreement appropriate to the data it handles.

10

International transfers

Your operational data is stored in the region you select (EU, US, or elsewhere depending on your Supabase project location). Transfers to processors outside the storage region are governed by Standard Contractual Clauses where required.

11

Changes to this policy

We update this policy as the product and our processing practices evolve. Material changes will be announced by email to platform administrators and visible on this page with a new last-updated date. Continued use after the update constitutes acceptance.

Questions? Write to contact@eaviora.com.
Read the Terms
eAvioraAviation Safety Intelligence

Aviation safety, quality and compliance for operators who'd rather see the precursor than write the report.

Operator-built
Auditable by design
Open data, no lock-in
Resources
  • Help center
  • Insights
  • Aviation Safety Glossary
  • Buyer’s Guide
  • ROI
Trust & legal
  • Trust center
  • Security one-pager
  • Platform status
  • Privacy
  • Terms
Company
  • Contact
  • Design Partner Program
  • Documentation
  • What’s new
  • Sign in
© 2026 eAviora Technologies Inc.All rights reserved.
Security disclosure Built in Montréal · QC