Who We Are & Scope
Aircora is a trading name operated by Festus Kumi, a sole trader established in England, with a business and service address at 10 Minster Road, Coventry, CV1 3AF ("Aircora", "we", "us", or "our").
Festus Kumi, trading as Aircora, is the data controller for the personal data described in this policy. This means we decide why and how that personal data is processed.
This policy applies when you visit the Aircora website, view the public map, create or use an account, register a drone, publish or manage flight notices, use flight logs, maintenance or planning features, interact with the blog, upload documents, contact us, or use Premium and billing services.
We process personal data under the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 ("PECR"), and relevant amendments made by the Data (Use and Access) Act 2025.
Privacy enquiries and requests can be sent to Festuskumi8@gmail.com.
Privacy at a Glance
- Published flight notices are public. The operating area, location, time window, altitude, operation details, status, display name, and relevant badge may be visible to anyone.
- Your private records stay private. Flight logs, maintenance records, flight plans, evidence files, billing details, email address, and account-security information are not displayed on the public map.
- Share links require care. Anyone who receives a valid share link may be able to view the information made available through that link.
- We do not sell personal data. We disclose it only as needed to run, secure, support, and lawfully administer Aircora.
- We currently use strictly necessary first-party cookies. We do not currently use Aircora advertising or cross-site behavioural tracking cookies.
- You have data protection rights. These can include access, correction, deletion, restriction, portability, objection, withdrawal of consent, and the right to complain.
Personal Data We Collect
| Category | Examples |
|---|---|
| Identity and account data | Full name, display name, email address, user ID, account role and status, email verification status, pilot-verification status, Premium entitlement, and account timestamps. |
| Authentication data | Password hash, refresh-token hash, hashed verification and password-reset codes, login and logout events, and session-security information. We do not store your password in readable form. |
| Operator and drone data | Operator or flyer identifiers you provide, drone nickname, manufacturer, model, serial or registration number, weight, class marking, battery records, status, and associated maintenance information. |
| Flight and geospatial data | Flight notices, routes, areas, coordinates, location names, altitudes, dates, times, duration, operation type, mission category, status, restrictions, conflicts, live or simulated state, and related operational notes. |
| Operational records | Flight logs and sorties, flight plans, risk assessments, site-survey content, briefings, declarations, signatures, maintenance events, pre-flight inspections, incidents, evidence references, exports, and audit stamps. |
| Files and uploaded evidence | Permissions, risk assessments, method statements, screenshots, photographs, PDFs, maintenance evidence, flight-plan attachments, file names, content type, size, storage path, upload time, and malware-scan outcome. |
| Communications and content | Notice comments and read states, blog comments, likes and shares, contact-form submissions, support correspondence, review notes, and other information you send to us or other users. |
| Subscription and billing data | Subscription plan, status, billing interval, Stripe customer and subscription identifiers, payment-event records, renewal and cancellation dates, reminder history, invoices, refunds, and limited payment-method metadata. Stripe processes full card details; Aircora does not store your full card number. |
| Technical, usage, and security data | IP address, user agent, browser and device information, request time, route accessed, error and application logs, rate-limit records, cookie and session activity, security events, and audit records of important user and administrator actions. |
| Search and map interaction data | Location-search text, selected search result, map viewport requests, and technical information sent to map, tile, and geocoding providers when those services are used. |
3.1 Information we do not seek
Aircora does not intentionally request special-category data, such as information about health, ethnicity, religion, political views, sexuality, or biometric identity. It also does not intentionally request criminal-offence data. Do not include such information in notices, comments, plans, incident descriptions, support messages, or uploads unless it is strictly necessary and you have a lawful reason to provide it.
3.2 Other people's information
If you enter personal data about another person, you are responsible for ensuring you have a lawful basis and authority to do so, and for giving that person any privacy information the law requires. Avoid naming third parties unless necessary.
How We Obtain Personal Data
- Directly from you when you register, complete your profile, add a drone, create or update records, upload a file, publish content, contact us, or purchase Premium.
- Automatically from your use of Aircora through application, security, session, audit, and server logs and through records generated by platform workflows.
- From other Aircora users where they mention you, communicate with you, add you to a relevant record, or submit information relating to a shared operational matter.
- From service providers, including Stripe subscription events, email-delivery results, hosting and security logs, storage metadata, and map or geocoding responses.
- From public or official sources where official airspace, restriction, aviation, or geographic information contains identifiers or metadata relevant to platform operation.
We do not buy personal-data lists and do not sell or rent user profiles.
Purposes & Lawful Bases
We identify a lawful basis before using personal data. The applicable basis may depend on the context and your relationship with Aircora.
| Purpose | Main data | Lawful basis |
|---|---|---|
| Create and administer your account | Identity, contact, authentication, profile, and account data | Contract |
| Provide drone, notice, map, coordination, logging, planning, and maintenance features | Drone, flight, geospatial, operational, file, and communication data | Contract |
| Publish flight notices and other content you choose to make public | Display name, badges, notice details, blog content, and share-link content | Contract and, where appropriate, legitimate interests in providing shared coordination |
| Run restriction, conflict, validation, and review workflows | Flight, geospatial, evidence, account, and audit data | Contract and legitimate interests in platform integrity and safety |
| Manage Premium, payments, VAT, invoices, cancellations, reminders, and refunds | Identity, contact, subscription, billing, and payment-event data | Contract and legal obligation |
| Verify accounts, prevent abuse, investigate incidents, and secure the Service | Authentication, technical, usage, file, communication, and audit data | Legitimate interests in security, fraud prevention, accountability, and defending legal rights |
| Moderate content and administer support or complaints | Account, content, communications, evidence, and audit data | Contract, legitimate interests, and where applicable legal obligation |
| Send essential account, billing, safety, security, and legal messages | Email, account state, subscription state, and relevant service data | Contract, legal obligation, and legitimate interests |
| Maintain financial, operational, security, and audit records | Billing, flight, operational, technical, and audit data | Legal obligation and legitimate interests in record integrity and legal claims |
| Improve reliability, diagnose faults, and understand feature performance | Technical, usage, error, and aggregated operational data | Legitimate interests in operating and improving Aircora |
| Send optional marketing or product-news messages | Name, email, preferences, and engagement | Consent, or the PECR soft opt-in where lawfully available |
| Comply with law, court orders, regulators, and lawful authority requests | Any relevant category | Legal obligation or legitimate interests |
Where we rely on legitimate interests, you may object to that processing. We will stop unless we have compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is needed for legal claims. We will always stop direct marketing when you object.
Public Map, Blog & Share Links
6.1 Public flight notices
The core purpose of Aircora is shared drone-activity awareness. When you publish a Flight Notice, information intended for coordination may be visible to registered users and unregistered visitors.
This may include your display name, Premium or verified badge, planned operating area, route or coordinates, location description, date and time window, maximum altitude, operation type, flight rules, notice status, and other fields deliberately included in the public notice view.
Your login email, password or authentication data, private account details, uploaded evidence, private messages, flight logs, maintenance records, full flight plans, billing data, and administrator-only records are not intended to appear on the public map.
A notice describes an operational location, but repeated publication from a home, workplace, or other private site may reveal an association with that location. Review each notice before publishing and do not include personal or confidential information that is unnecessary for coordination.
6.2 Blog and coordination content
Blog comments, display names, publication times, and related interactions may be visible publicly. Notice comments or coordination threads are visible to authorised participants and, where the feature design permits, other eligible users associated with the notice.
6.3 Share links
Some Premium features can create token-based share links for records such as flight plans. A valid link may allow a person to view the shared content without signing into your account. Treat share links as confidential, send them only to intended recipients, and revoke or regenerate them if they are disclosed accidentally.
6.4 Search-engine visibility
Public web pages, including blog posts and other indexable content, may be discovered and cached by search engines or third-party archives. Removal from Aircora does not guarantee immediate removal from external caches.
Cookies & Similar Technologies
Aircora currently uses first-party cookies that are strictly necessary to provide secure authentication and maintain your session. PECR generally permits strictly necessary cookies without consent.
| Technology | Purpose | Typical duration |
|---|---|---|
| Access-token cookie | Authenticates requests during an active session. It is configured as httpOnly and Secure in production. | Short-lived |
| Refresh-token cookie | Allows secure session renewal without repeatedly entering your password. It is rotated and protected. | Limited duration |
| Temporary security or state storage | Supports fraud prevention, request integrity, interface state, or other functions necessary to deliver a feature. | Session or short-lived |
Aircora does not currently place first-party advertising cookies or use cross-site behavioural advertising. If we introduce non-essential analytics, personalisation, or advertising technologies, we will update this policy and implement consent controls before using them where required.
Stripe and other external services may use their own cookies when you visit their hosted pages. Their use is governed by their own notices and controls.
Who Receives Personal Data
We do not sell personal data and do not share it with third-party advertisers. We disclose personal data only where reasonably necessary for the purposes in this policy.
8.1 Service providers and platforms
| Recipient | Purpose | Relevant data |
|---|---|---|
| Render | Backend application and managed data infrastructure | Platform, account, operational, technical, and log data |
| Vercel | Frontend hosting and delivery | IP address, user agent, request and technical data |
| Cloudflare | Domain, network/security services, and R2 object storage | Request metadata, security data, uploaded evidence, and media |
| Stripe | Checkout, payment processing, billing portal, invoices, VAT, and refunds | Identity, contact, billing, payment, and subscription data |
| Resend and email-delivery infrastructure | Verification, password reset, billing, reminder, and service emails | Email address, name where used, message content, and delivery events |
| OpenStreetMap Nominatim and configured map/tile providers | Location search and map display | Search terms, requested map area, IP address, and technical request data |
Providers may change as Aircora develops. We assess material providers and update this policy when a change materially affects how personal data is handled.
8.2 Other users and the public
Public notice and blog data is disclosed as described in Section 06. Communications are disclosed to their intended participants. Share-link content is disclosed to anyone able to use the valid link.
8.3 Aircora administrators and support access
Authorised administrators may access account, notice, evidence, maintenance, flight-plan, subscription, support, and audit data where necessary for moderation, platform administration, troubleshooting, security, or support. Access must be tied to a legitimate operational need, and important administrator actions are audit-logged.
8.4 Professional advisers and authorities
We may disclose relevant data to legal, accounting, insurance, cybersecurity, or other professional advisers under duties of confidentiality. We may also disclose data where required by law, a court, a regulator, law enforcement, or another body with lawful authority, or where necessary to establish, exercise, or defend legal claims.
8.5 Business transfer
If Aircora or its assets are sold, reorganised, or transferred, personal data may be disclosed to prospective and actual buyers or successors subject to appropriate safeguards. We will notify you where the law requires.
International Data Transfers
Some providers are headquartered outside the United Kingdom or operate international infrastructure. Personal data may therefore be accessed or stored outside the UK.
Where UK data protection law requires a transfer safeguard, we use an appropriate mechanism, which may include:
- a UK adequacy regulation;
- the UK Extension to the EU-US Data Privacy Framework where the recipient is validly certified and the transfer is covered;
- the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses; or
- another lawful transfer mechanism, together with supplementary safeguards.
Contact Festuskumi8@gmail.com to ask about the safeguard used for a particular transfer.
Retention & Account Deletion
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including providing the Service, maintaining record integrity, meeting legal duties, resolving disputes, and defending claims. We then delete, anonymise, or securely restrict it.
| Data | Normal retention approach |
|---|---|
| Account and profile data | While the account is active, followed by a limited closure period, except where information must be retained for another purpose below. |
| Verification and password-reset codes | Short-lived and removed or rendered unusable after expiry or successful use. |
| Flight notices, logs, plans, maintenance records, inspections, incidents, and associated evidence | Generally while the account is active and, where needed to support aviation record-keeping, audit integrity, or claims, for at least three years from the relevant record or operation. Some records may be kept longer where the user keeps them in an active account or another lawful need applies. |
| Subscription, invoice, tax, and payment records | Normally six years after the relevant financial period or transaction, where required for tax, accounting, and legal purposes. |
| Contact, support, and complaint records | Normally up to 24 months after resolution, or longer where needed for an active complaint, safeguarding issue, dispute, or legal claim. |
| Blog comments and public interactions | While the content remains published or until removed, followed by any limited moderation, backup, or claims-retention period. |
| Security, access, and audit logs | Normally up to 24 months, with longer retention for an investigation, legal claim, regulatory matter, or serious security event. |
| Stripe webhook and payment-event records | For the period needed for payment idempotency, reconciliation, fraud prevention, accounting, and legal obligations. |
| Backups | Retained on a rolling disaster-recovery schedule. Deleted data may remain in a protected backup until that backup expires and is overwritten. |
10.1 Account deletion
You may use an account-deletion function where available or email Festuskumi8@gmail.com. Closing an account does not automatically erase every record immediately. We delete or anonymise data that is no longer needed, but may retain restricted operational, financial, security, or legal records for the periods above.
Where practical, retained operational records are tombstoned or separated from ordinary account access so only the identifiers necessary for the lawful retention purpose remain.
10.2 Cancellation is not deletion
Cancelling Premium changes your subscription access but does not delete your Aircora account or operational records.
Security & Data Breaches
We use technical and organisational measures designed to provide security appropriate to the risks, including:
- HTTPS/TLS encryption for data in transit;
- strong one-way password hashing;
- hashed verification and password-reset codes;
- httpOnly and Secure authentication cookies in production;
- short-lived access tokens and refresh-token rotation;
- role-based access controls and record-ownership checks;
- server-side validation and entitlement checks;
- rate limiting and request hardening on sensitive endpoints;
- file-type, size, and content validation for uploads;
- malware-scanning controls where enabled;
- audit logging for important user and administrator actions;
- restricted administrator access and secrets management;
- dependency, security, and production-readiness reviews; and
- backup and recovery arrangements appropriate to the service stage.
No internet service can guarantee absolute security. You must keep your password and devices secure, avoid sharing authentication details, protect share links, and notify us promptly if you suspect unauthorised access.
If a personal-data breach occurs, we will assess the likely risk. Where required, we will notify the Information Commissioner within the applicable time limit and notify affected individuals where the breach is likely to create a high risk to their rights and freedoms.
Your Data Protection Rights
Depending on the circumstances and the lawful basis used, you may have the following rights:
| Right | What it means |
|---|---|
| Be informed | Receive clear information about how we process personal data. |
| Access | Request a copy of personal data we hold about you. |
| Rectification | Ask us to correct incomplete or inaccurate personal data. |
| Erasure | Ask us to delete personal data where there is no overriding lawful reason to retain it. |
| Restriction | Ask us to restrict processing in specified circumstances. |
| Data portability | Receive eligible data you provided in a structured, commonly used, machine-readable format or ask us to transmit it where technically feasible. |
| Object | Object to processing based on legitimate interests and object at any time to direct marketing. |
| Withdraw consent | Withdraw consent at any time where consent is the basis, without affecting earlier lawful processing. |
| Automated decisions | Receive safeguards where a solely automated decision has legal or similarly significant effects, where applicable. |
| Complain | Raise a data protection complaint with us and with the ICO. |
12.1 How to make a request
Email Festuskumi8@gmail.com with the right you wish to exercise and enough information for us to identify the relevant account or data. You may also use the contact form.
We may ask for proportionate proof of identity, particularly if the request comes from an email address that is not linked to the account. Do not send unnecessary identity documents unless requested.
We normally respond without undue delay and within one month. Where legally permitted, a complex or numerous request may be extended by up to two further months; we will explain the extension within the first month. Requests are normally free, although the law permits a reasonable fee or refusal in limited cases involving manifestly unfounded or excessive requests.
Some rights are not absolute. We will explain any lawful reason why a request cannot be fulfilled in full.
Data Protection Complaints
You may complain if you believe Aircora has infringed data protection law or handled your personal data unfairly, inaccurately, insecurely, or without sufficient transparency.
13.1 How to complain to Aircora
Email Festuskumi8@gmail.comwith the subject "Data protection complaint", or use the contact form. Include:
- your name and account email, where relevant;
- what you believe happened;
- when it happened;
- the personal data or feature involved;
- the outcome you are seeking; and
- any supporting information that is necessary and proportionate.
We will provide a clear way to complain, acknowledge receipt within 30 days, make appropriate enquiries, keep you informed where necessary, and tell you the outcome without undue delay, in line with the Data (Use and Access) Act 2025.
13.2 Complaining to the ICO
You may complain to the Information Commissioner's Office ("ICO"), the UK supervisory authority for data protection. You are not required to complain to Aircora first, although giving us an opportunity to investigate may allow the matter to be resolved more quickly.
Children
Aircora accounts and paid subscriptions are intended for people aged 18 or over. We do not knowingly permit children to create accounts or intentionally design the Service to collect children's personal data.
A child may view genuinely public pages in the same way as any internet user, but must not register or submit personal data. If you believe a child has created an account or provided personal data, contact Festuskumi8@gmail.com. We will investigate and take appropriate action.
Automated Processing
Aircora uses automated processing to support functions such as geometry validation, restriction detection, conflict detection, risk prompts, entitlement checks, spam or abuse controls, rate limiting, and generation of operational records.
These processes support platform operation and advisory outputs. Aircora does not currently use solely automated processing to make decisions about you that produce legal or similarly significant effects. A restriction or conflict result does not determine whether you have legal permission to fly. Where platform publication requires administrator review, the relevant moderation decision includes human involvement.
If Aircora introduces significant automated decision-making, we will assess the legal basis, provide required information and safeguards, and update this policy before the processing begins.
Email & Marketing
16.1 Essential communications
We may send messages necessary to operate your account or comply with law, including verification and reset codes, security alerts, service changes, billing receipts, payment-failure notices, cancellation confirmations, renewal reminders, privacy notices, complaint updates, and other important operational messages. These are not optional marketing messages.
16.2 Optional marketing
We will send optional marketing or general product-news emails only where permitted by PECR and data protection law, such as with your consent or a valid soft opt-in for similar services. Every marketing message will provide a simple way to unsubscribe.
You can withdraw consent or object to direct marketing at any time by using the unsubscribe control or emailing Festuskumi8@gmail.com. We may retain a minimal suppression record so we can respect your choice.
Changes to This Policy
We may update this policy when Aircora's features, providers, security controls, legal obligations, or processing practices change. The current version and effective date appear at the top of this page.
Where a change is material, we will take reasonable steps to bring it to your attention, such as an email, in-app notice, or prominent website notice before or when it takes effect. We will request consent again where a new use legally requires it.
You should review this policy periodically, particularly before submitting new types of information or using a newly launched feature.
Contact Details
Contact us about this policy, your personal data, a rights request, or a data protection complaint using the details below.