Privacy Notice
Â
PRIVACY NOTICE
Peak Aviation Academy OOD | Peak Aviation OOD | Peak Aviation FZC LLC Effective Date: 13 June 2026Â | Version 1.2
This Privacy Notice explains what personal data we collect, why, how we use it, who we share it with, and your rights. We have written it in plain language. Questions: [email protected].
1. Who We Are
Peak Aviation operates through three legal entities, each a data controller for the personal data it processes for its own products:
| Entity | Registration | Country | Products / Services |
|---|---|---|---|
| Peak Aviation Academy OOD | Reg. No. 207786682 | Bulgaria | Private Pilot Pathway, Certification Module (EASA DTO) |
| Peak Aviation OOD | Reg. No. 205855051 / VAT BG205855051 | Bulgaria | ELP Tests, ATPL Programme, B2B Training |
| Peak Aviation FZC LLC | UAE free zone company | UAE | Single Subject Modules |
Registered address (Bulgarian entities): Puzl CoWorking, Business Centre Vitosha, Cherni Vrah 47A Blvd., Sofia 1407, Bulgaria. Contact: [email protected].
Peak Aviation FZC LLC (UAE) has appointed Peak Aviation OOD (Sofia) as its representative in the EU under Article 27 GDPR. EU/EEA data subjects may exercise all rights through [email protected].
This Notice covers personal data collected through our website (www.peakaviation.eu), our mobile application ("the App"), and communications between you and us.
2. What Personal Data We Collect
2.1 Data you give us directly: identity data (name, date of birth, nationality); contact data (email, phone); account credentials (username, hashed password); payment data (billing name and address — we do not store card numbers or bank details, which are handled by our payment processors); pilot licence data (licence or student licence number, if submitted for ELP or ATPL); course submissions (quiz answers, module progress, written content); communications.
2.2 Data we collect automatically: technical data (IP address, browser type, operating system, referring URL, pages visited, session duration, via server logs and cookies); usage data (modules opened, progress milestones, time on content); transaction records (amount, currency, payment method type, invoice data).
2.3 Data from third parties: payment confirmation from our payment processors; in-person ELP examination result and assessment data from our in-person ELP partner; online ELP examination result, session audio recording, and scoring and timing logs from our remote ELP partner.
2.4 Special categories of data: we do not intentionally collect special-category data. If you share an accessibility requirement for an in-person ELP exam, we use it only to accommodate you and retain it no longer than necessary.
2.5 Community and Blog data: if you post in our community area or comment on our blog, we collect your display name, profile information, and the content you submit. Community posts and blog comments are visible to other users unless set private. Please do not post personal data about yourself or others in public areas.
2.6 Mobile app data: device identifiers (device type, OS version, unique device identifier, mobile network info); push-notification token (if enabled); app usage data (screens, features, session duration, crash reports); camera and microphone (only with consent and only during online ELP sessions, for identity verification and recording — you are asked explicitly). Manage permissions in device settings; revoking camera or microphone prevents sitting online ELP exams via the app.
2.7 Minimum age and young learners: we accept students from age 15. Students aged 15–17 are minors under EU law and we apply these protections: verifiable parental or guardian consent is required before creating an account for a student aged 15 or 16 (under GDPR Art. 8 and the Bulgarian PDPA Art. 25a, Bulgaria's digital-consent age is 14; for students aged 14 and under, parental consent is also required — we collect the consenting guardian's name and email); no marketing to under-16s and no use of their data for advertising or ad targeting; a guardian may exercise any GDPR right on a minor's behalf (contact [email protected] with proof of relationship); we verify date of birth at registration and may suspend an account pending consent if age is misrepresented. If you believe a student under 15 created an account without parental consent, contact [email protected] and we will investigate and delete if appropriate.
3. How and Why We Use Your Data
| Purpose | Lawful Basis | Data Involved | Retention |
|---|---|---|---|
| Providing and managing your course access | Contract performance | Identity, contact, credentials, course progress | Duration of subscription + 2 years |
| Provisioning ebooks and learning materials with our content partner | Contract performance | Name, email | Duration of enrolment + as required by the partner agreement |
| Processing payments and issuing VAT invoices | Contract performance + Legal obligation (Bulgarian Accountancy Act, VAT law) | Identity, contact, billing address, transaction records | 10 years from invoice date |
| Delivering online ELP examinations | Contract performance | Identity, licence data, examination audio recordings, scoring and timing logs | Recordings: 12 months. Results: 5 years (EASA regulatory requirement) |
| Delivering in-person ELP examinations (Sofia) | Contract performance | Identity, photo ID verification, result data | 5 years (EASA regulatory requirement) |
| Customer support and complaints | Contract performance + Legitimate interests | Identity, contact, communications | 3 years from last contact |
| Fraud prevention and security | Legitimate interests | Technical data, transaction records | 12 months for logs; fraud flags reviewed annually |
| Website analytics and improvement | Legitimate interests | Technical data, usage data (aggregated) | 26 months |
| Operating the community area and blog comments | Legitimate interests | Display name, profile, posts, comments | Until account deletion or post removal; inactive accounts reviewed after 3 years |
| Sending push notifications via the app | Consent | Push token, device identifier | Until you disable notifications or delete the app |
| Collecting parental/guardian consent for minors | Legal obligation (GDPR Art. 8; Bulgarian PDPA Art. 25a) | Guardian name, email, relationship | Student's account duration + 2 years |
| Sending marketing emails (with consent) | Consent (not available to under-16s) | Name, email | Until you unsubscribe or withdraw consent |
| Complying with legal obligations | Legal obligation | As required by law | As required by law |
You can withdraw marketing consent at any time via the unsubscribe link or [email protected]. Withdrawal does not affect prior processing.
4. Who We Share Your Data With
We do not sell your personal data, and we do not share it for any third party's own marketing. We share it only with the service providers below, each acting under our instruction and a data processing agreement, and with authorities where legally required. To protect the security and integrity of our service, we identify providers by function; we will name a specific provider on request to a verified data subject.
| Provider (by function) | Location | Purpose | Transfer Safeguard |
|---|---|---|---|
| Learning management platform | USA | Hosts course content, manages accounts and progress, sends transactional emails | EU Standard Contractual Clauses |
| Course content / ebook partner | United Kingdom | Provisions your ebooks and learning materials (name and email shared to issue your books) | UK adequacy decision |
| Card payment processor | USA | Card payment processing, invoice generation | EU SCCs + EU–US Data Privacy Framework |
| Cryptocurrency payment processor | USA | Crypto payment processing | EU Standard Contractual Clauses |
| Analytics and advertising provider | USA | Website analytics; advertising and conversion tracking | EU SCCs + EU–US Data Privacy Framework |
| Content delivery and security provider | USA | CDN, DDoS protection, web security | EU SCCs + EU–US Data Privacy Framework |
| Banking / payments provider | Belgium (EU) | Banking and international payments for invoices and refunds | Within the EU/EEA — none required |
| Remote ELP examination partner | Estonia (EU) | Administers and rates online exams; processes session recordings and results | Within the EU/EEA — none required |
| In-person ELP examination partner | United Kingdom | Conducts in-person exams (TEAC), shares results | UK adequacy decision |
We may also disclose data to: (a) competent courts, regulators, or law enforcement when legally required; (b) professional advisors (lawyers, accountants, auditors) under confidentiality; and (c) an acquirer or prospective acquirer of our business, in connection with a merger, sale, financing, restructuring, or acquisition of all or part of our business — in which case we will notify you in advance and the acquirer will be bound to protect your data consistently with this Notice.
5. International Transfers
Some providers are based outside the EEA. Where personal data is transferred outside the EEA, we ensure protection by one or more of: Standard Contractual Clauses (European Commission-approved terms binding the recipient to GDPR-equivalent protection); the EU–US Data Privacy Framework (used only with certified recipients — verify at www.dataprivacyframework.gov); or an adequacy decision, including the European Commission's adequacy decision for the United Kingdom, which recognises it as providing an adequate level of protection. You can request a copy of the specific safeguard applicable to your data by emailing [email protected].
6. Cookies, Tracking Technologies, and Mobile App Permissions
Our website uses cookies and similar technologies; our app uses equivalent SDK-level tracking and device permissions you grant explicitly.
| Cookie Type | Example | Purpose | Lawful Basis |
|---|---|---|---|
| Strictly necessary | Session, CSRF token | Log you in, keep your cart, protect against fraud. Cannot be turned off. | Necessary for contract performance — no consent required |
| Functional | Language preference | Remember settings between visits | Legitimate interests |
| Analytics | Analytics cookies | Count visits and measure page use, aggregated | Consent (opt out via cookie banner) |
| Marketing | Advertising and conversion cookies | Show relevant ads and track conversions | Consent (opt out via cookie banner) |
Manage preferences via our cookie banner or browser settings; blocking strictly necessary cookies affects site use. Full detail in our Cookie Policy at www.peakaviation.eu/cookie-policy.
Mobile app permissions: camera and microphone (optional, only when you start an online ELP exam — you may decline and use the website); push notifications (optional, off at any time in device settings); internet access (required). We do not access your contacts, location, photos, or other device data.
7. Your Rights Under the GDPR
If you are in the EU, EEA, or UK, you have the rights below; we respond within 30 days (extendable to 3 months for complex requests, with notice).
| Right | What it means |
|---|---|
| Access | A copy of the data we hold about you and how we use it |
| Rectification | Correct inaccurate or incomplete data |
| Erasure | Delete data no longer necessary, or where you withdraw consent and there is no other basis |
| Restriction | Pause processing in certain circumstances |
| Data portability | Receive your data in a structured, machine-readable format (consent or contract data) |
| Object | Object to processing based on legitimate interests; we stop unless we show compelling grounds |
| Withdraw consent | Withdraw consent at any time, without affecting prior processing |
| Automated decisions | We do not make solely automated decisions producing legal or similarly significant effects about you |
Exercising your rights is free. We may verify your identity first to protect your data.
8. How to Exercise Your Rights
Email [email protected] (subject "Privacy Request"); post: Puzl CoWorking, Cherni Vrah 47A Blvd., Sofia 1407, Bulgaria. Response within 30 days.
9. Data Security
TLS (HTTPS) encryption in transit; passwords stored hashed; card data never stored by us (handled by a PCI DSS Level 1 certified processor); access restricted to authorised personnel; web protection via a security and CDN provider; the app communicates over encrypted connections only and stores no sensitive data locally beyond session tokens invalidated on sign-out. No transmission or storage is 100% secure; if you believe your interaction is no longer secure, contact [email protected].
10. Data Retention
We keep data only as long as needed for its purpose or as required by law (key periods in Article 3). On expiry we securely delete or anonymise. You may request earlier deletion (Article 7), subject to legal obligations (e.g. 10-year VAT invoice retention under Bulgarian law).
11. Links to Other Websites and Social Media
Our site links to third-party sites and social platforms not governed by this Notice; review their policies before sharing data. Direct messages you send us via social media are handled under this Notice.
12. Complaints
Raise concerns with us first. If unsatisfied, you may complain to a supervisory authority: Bulgaria (primary) — Commission for Personal Data Protection (КЗЛД), www.cpdp.bg, +359 (02) 91-53-518, 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592; UK residents — Information Commissioner's Office, www.ico.org.uk; other EU/EEA residents — your local supervisory authority.
13. Changes to This Privacy Notice
We review this Notice periodically and update it as practices or law change; the current version is always at www.peakaviation.eu/privacy-policy. For material changes we give at least 30 days' email notice; for minor changes we update the version date.
End of Privacy Notice — Peak Aviation | Version 1.2 | Effective 13 June 2026

