Privacy Policy
What personal data is processed, why, on what legal basis and with what rights.
- Version
- 1.0
- Effective date
- 17 August 2026
- Last updated
- 17 August 2026
- Document owner
- the Groundmaster project, with responsibility assigned to its legal and compliance function
- Applicable jurisdiction
- Portugal, European Union
- Permanent URL
- https://www.groundmaster.pt/legal/privacy
1.Who we are and our role
Groundmaster AI is operated by the Groundmaster project, based in Portugal, European Union. Privacy enquiries can be sent to groundmaster.web@gmail.com.
We act as controller for data we process for our own purposes: account administration, authentication, billing, security monitoring, abuse prevention, support, service communications, and website analytics where used. We act as processor for Content that a Customer or its Users place in an Organisation workspace, including operational and technical records.
2.Categories of data processed
| Category | Typical examples | Role |
|---|---|---|
| Identity and contact data | Name, work email, phone number, postal address, personnel identifiers and codes used inside an organisation | Processor (workspace) / Controller (account) |
| Credential and authentication data | Hashed credentials, session and token metadata, multi-factor status | Controller |
| Role and permission data | Assigned roles, functional categories, page-level access levels, approval and delegation attributes | Processor |
| Personnel and qualification documents | Certificates, authorisations and similar documents uploaded by an organisation, and official identification or tax reference numbers where an organisation chooses to record them | Processor |
| Operational and technical records | Records describing aircraft, components, planned and corrected work, findings, materials, tooling, inspections, forecasts and traceability documents | Processor |
| Activity and audit data | Sign-in events, record creation and modification events, sign-off and time-recording entries, permission changes | Processor / Controller |
| Technical and device data | IP address, browser and device characteristics, timestamps, request metadata, error diagnostics | Controller |
| Support and communications data | Messages, attachments and correspondence relating to support requests | Controller |
| Billing and commercial data | Subscription, invoicing and payment status information | Controller |
| AI interaction data | Prompts, retrieved context references and generated output associated with AI-assisted features | Processor |
3.Special categories and sensitive data
The Platform is not designed for special categories of personal data as defined by data protection law, and organisations should not upload such data unless there is a lawful basis and an appropriate safeguard. Certain identifiers that organisations may record for personnel administration are treated as sensitive by us and are subject to restricted access controls.
4.Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the Platform under an agreement with a Customer | Performance of a contract; or legitimate interests where the individual is not the contracting party |
| Authentication, access control and tenancy separation | Legitimate interests; legal obligation for security of processing |
| Security monitoring, abuse and fraud prevention, rate limiting | Legitimate interests; legal obligation |
| Support, incident handling and service communications | Performance of a contract; legitimate interests |
| Product reliability, error diagnosis and capacity planning | Legitimate interests |
| Billing, accounting and tax records | Contract; legal obligation |
| Compliance with legal, regulatory and lawful requests | Legal obligation |
| Optional analytics and non-essential cookies | Consent |
| Processing of workspace Content | On the Customer's documented instructions as controller |
5.Model training and AI
Customer Data is not used to train generative or foundation models for our own purposes or for the general benefit of other customers. Where AI features are used, prompts and the necessary context are transmitted to a model provider only to generate a response for that request. Contractual controls require providers not to use that content to train their models. Further detail is in the AI Policy & AI Transparency Notice.
7.International transfers
Hosting and processing take place in the European Economic Area (EEA), where technically available; any processing by third-party subprocessors outside the EEA is subject to appropriate GDPR safeguards, including Standard Contractual Clauses where applicable. Where personal data is transferred outside the European Economic Area, transfers rely on an adequacy decision or on appropriate safeguards such as the European Commission's standard contractual clauses, together with supplementary technical and organisational measures where required.
8.Retention
Retention is governed by the Data Retention & Deletion Policy. In summary, workspace Content is retained for as long as the Organisation's subscription requires it and for the periods the Customer configures or is legally required to observe; account, security and billing records are retained for the periods necessary for security, statutory and accounting purposes; and backups follow their own rolling cycle.
9.Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, encryption at rest, row-level access enforcement, role-based and page-level permissions, logical tenancy separation, least-privilege administration, audit logging, secret management, dependency and configuration monitoring, and backup and recovery procedures. The Security Overview describes these measures in more detail. No system can be guaranteed absolutely secure.
10.Your rights
Subject to applicable law you may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests. Where processing relies on consent you may withdraw it at any time. You may also lodge a complaint with your supervisory authority.
Where the data sits inside an Organisation workspace, we will normally refer the request to that Organisation as controller and assist it in responding. Requests can be submitted through the legal requests page. Some records — in particular records maintained for aviation traceability, audit and statutory purposes — may lawfully be retained despite an erasure request.
11.Automated decision-making
The Platform does not take decisions producing legal effects concerning individuals solely by automated means. Automated features generate suggestions, forecasts and alerts that require human review before use.
12.Children
The Platform is intended for professional use and is not directed at children.
13.Changes to this notice
We may update this notice. The version and dates at the top of this page indicate the current release, and material changes are communicated in advance where required.
Change history
| Version | Date | Change |
|---|---|---|
| 1.0 | 17 August 2026 | Rewritten to cover platform-wide processing, roles, legal bases, international transfers and rights. |
Questions about this document can be sent to groundmaster.web@gmail.com. Formal legal, privacy, security and regulatory requests should follow the routes described in the legal requests page. Fields shown as bracketed placeholders are pending confirmation by the operating legal entity and do not constitute a statement of fact.