you.aero Privacy Notice
Controller: JETSONIC TRADING - FZCO
Version: 1.1
Effective date: 2 September 2026
Last updated: 1 September 2026
Privacy contact: team@you.aero
Covered services: you.aero, app.you.aero and the closed
B2B pilot
1. Who we are
you.aero is a B2B aviation marketplace product operated by JETSONIC TRADING - FZCO, referred to as Jetsonic, you.aero, we, us or our. Jetsonic is the controller of the personal data described in this Notice unless another organisation is clearly identified as acting independently.
For privacy questions or requests, email team@you.aero with the subject Privacy Request. We have designated an internal privacy owner for the pilot. This contact does not state that a statutory Data Protection Officer has been appointed.
2. Scope
This Notice covers:
- the public website at you.aero;
- the closed business workspace at app.you.aero;
- supplier registration, invitation, email verification and onboarding;
- company profiles, private draft listings and restricted demo or internal test RFQs;
- support and service communications;
- approved marketing invitations and preferences; and
- security, audit and compliance activities needed to operate the pilot; and
- the limited workspace activity telemetry described below when that feature is enabled.
The pilot is intended for people acting for a business or other organisation. Company information can be personal data where it identifies or relates to an individual, such as a named contact, sole trader, account user or message author.
Payments, escrow, live orders, public supplier verification and autonomous high impact decisions are not active pilot purposes.
3. Data we process
Depending on how you use the service, we may process:
Account and contact data
Name, business email, telephone number, language, role, company affiliation, account status and password hash. We do not store readable passwords.
Company and supplier data linked to people
Company name, legal name, country, city, business address, website, business contacts, job role, authority to represent the company, capabilities, certifications and identifiers.
Marketplace and communication data
Private draft listings, part numbers, quantities, condition, product descriptions, demo or internal test RFQs, test offers, messages, comments, attachments and supporting documents.
Verification and compliance data
Invitation status, email verification, company records, reviewer notes, KYB status, sanctions or export review records, risk flags and decision history where an approved manual review is enabled.
Marketing and preference data
Consent source, wording and version, date and time, campaign identifier, referral and UTM fields, delivery, bounce, complaint, unsubscribe and suppression status. Open pixel tracking is disabled for the closed pilot. Campaign level links may use disclosed UTM parameters without embedding an email address or other directly identifying data in the URL.
Technical, security and audit data
IP address, request identifier, date and time, browser and user agent, login and verification events, failed login counters, lockouts, session and revocation events, security alerts and material audit records.
Workspace activity telemetry
When the workspace activity telemetry feature is enabled, we process the account and company identifiers, a random per-tab activity session identifier, session start, end and last-seen times, a controlled page or screen key, bounded engaged seconds, online status derived from recent activity, and selected allowlisted action names. For an approved form event, the record may identify only changed field groups, such as company profile, contact or listing details.
This telemetry does not record field values, passwords, message or email text, attachment content, keystrokes, pointer movements, full URLs, query strings or unrestricted object identifiers. A feature flag can disable collection. Authorised platform administrators with the required permission may use the resulting reports to understand service adoption, response and workflow timing, investigate faults and protect the Platform.
Public website analytics
After affirmative analytics consent, page path and title, locale, page views, button and outbound link interactions, scroll milestones, active engagement and performance metrics may be sent to Google Analytics. Advertising storage, advertising user data, personalised advertising, Google Signals and user provided data collection are disabled for the pilot.
AI feature data
If a clearly identified AI feature is enabled, prompts, selected business context, attachments, generated output and feedback may be processed to provide that feature. During the pilot, personal, confidential and user content is not used for model training, fine tuning or secondary product improvement.
Do not send passwords, payment card data, bank credentials, medical data, passports or national identity documents through ordinary email or free text fields. Upload identity or compliance documents only through an approved secure workflow that explains why they are required.
4. Sources of data
We receive data:
- directly from you when you register, complete a profile, create or upload content, change a preference or contact us;
- from an authorised colleague or company administrator;
- from the organisation you represent or an authorised business referral;
- from an approved campaign record where recipient level permission and source evidence are recorded;
- automatically from your browser, device and interaction with the service; and
- from service providers that report email delivery, security, support or consented analytics events.
Publicly available contact information is not treated by itself as permission to send marketing.
5. Purposes and legal grounds
We process personal data only where an applicable legal ground is available. Depending on the activity and applicable law, this may include your consent, steps requested before entering into the Marketplace Terms, performance and administration of those Terms, compliance with legal obligations, protection of rights and systems, prevention of fraud, or establishment, exercise or defence of legal claims.
We use data to:
- create and administer accounts and company workspaces;
- verify email addresses and protect accounts;
- provide supplier profiles, private draft listings and restricted demo or internal test RFQs;
- confirm authority and perform approved manual KYB or compliance reviews;
- send security, verification, workflow and support communications;
- respond to questions and rights requests;
- prevent misuse, fraud and security incidents;
- measure service adoption, response and workflow timing through the limited workspace activity telemetry described in section 3;
- maintain legally significant acceptance and audit records;
- comply with law and respond to competent authorities; and
- send marketing or use optional analytics only after the required affirmative choice.
Where consent is the legal ground, you may withdraw it at any time through the relevant preference control or by contacting us. Withdrawal does not affect processing lawfully completed before withdrawal and does not stop processing required or permitted on another ground.
6. Registration choices and legal evidence
Registration uses separate controls:
- an unchecked required agreement to the current Marketplace Terms;
- an unchecked required acknowledgement that the current Privacy Notice was displayed;
- an optional unchecked marketing subscription.
Privacy acknowledgement is evidence that the Notice was shown. It is not a contract and is not treated as consent to all processing. A marketing refusal does not block registration or essential service messages.
For the Terms agreement and Privacy acknowledgement, we record the document key, version, cryptographic hash, server time, account and company identifiers, action type, request identifier, IP address and user agent. A materially changed Terms version may require renewed agreement.
7. Visibility and sharing between users
During the closed pilot, listings, RFQs, offers, messages and uploaded documents are private or restricted to the user, authorised members of the same company and specifically selected internal reviewers. They are not public by default.
If a future feature allows sharing with another participant or the public, the interface will identify the intended audience before submission and this Notice will be updated where the processing materially changes.
Do not place personal home addresses, private telephone numbers, unrelated identity documents or unnecessary personal data in a company profile, listing, RFQ or message.
8. Marketing communications
We send marketing only where recipient level permission has been recorded and the recipient is eligible under the law applying to the communication. Consent evidence includes the recipient, date and time, wording and version, collection source, scope and current status.
Every marketing email identifies the sender and includes a working unsubscribe method. A withdrawal or objection is applied without delay. We keep a minimal suppression record so that an address is not added back without new valid permission.
Service communications, such as verification codes, account security notices and direct support responses, are not marketing and may continue while necessary to provide or protect an account.
Email providers may report delivery, bounce, unsubscribe and abuse complaints. Open pixel tracking is disabled for the closed pilot. Link measurement is limited to disclosed campaign parameters and registration attribution necessary to evaluate the pilot.
9. Cookies and analytics
Strictly necessary cookies and browser technologies support requested functions and security. Optional analytics remains disabled until the visitor gives a clear affirmative choice.
Google Analytics is used only on the public website after consent. Before consent or after rejection, the Google Analytics script is not loaded, analytics cookies are not set and analytics requests are not sent. The closed workspace does not use Google Analytics during the pilot.
You may reject optional cookies or later change or withdraw the choice through Cookie Preferences. On withdrawal, future analytics stops and existing first party Google Analytics cookies are deleted where technically available. The Cookie Notice provides the current inventory and durations.
10. AI assisted functions
An enabled AI function may process a prompt, message, selected business context or uploaded material to produce a draft, search aid or suggestion. AI output may be incomplete or inaccurate and must be reviewed by an authorised person.
AI does not make final airworthiness, sanctions, export, supplier verification, payment or other legally significant decisions. External actions require explicit human approval. The provider, data fields, region, retention, no training settings and contractual controls must be approved before real personal or confidential data is sent.
11. Recipients
We disclose personal data only as reasonably necessary to:
- authorised Jetsonic personnel and contractors;
- authorised users within your company;
- selected participants where you use an approved sharing workflow;
- providers of hosting, databases, object storage, transactional email, campaign email, malware scanning, monitoring, analytics, security and support;
- legal, tax, audit, insurance and other professional advisers under confidentiality duties;
- courts, regulators, law enforcement or other competent authorities where legally required; and
- a genuine purchaser, investor or successor in a corporate transaction under appropriate controls.
Active pilot providers may include Sender.net for approved campaign email and Google Analytics for consented public website measurement. A current processor and subprocessor register is maintained internally and information about relevant recipients is available on request, subject to security and confidentiality limits.
We do not sell personal data for money. We do not disclose personal data to another organisation for that organisation's independent direct marketing without the required permission.
12. International transfers
Jetsonic is based in the United Arab Emirates. Users and providers may be located in other countries. Personal data may therefore be accessed, stored or processed outside the country where it was collected.
Before a production transfer, we identify the destination, recipient, purpose and applicable transfer requirement. Where required, we use a mechanism permitted by applicable law, such as processing in an approved jurisdiction, contractual and organisational safeguards, or a legally recognised exception. You may request information about the safeguard applying to your data, subject to lawful confidentiality and security restrictions.
13. Retention
We retain personal data only for as long as necessary for its purpose and approved legal, security, audit and dispute needs. The following schedule applies to the closed pilot:
| Record category | Retention period |
|---|---|
| Active account and current profile | While active. Access ends immediately on closure. Operational profile fields are deleted or anonymised within 30 days unless a record below must be preserved. |
| Registration, invitation outcome, email verification fact, Terms agreement, Privacy acknowledgement and related material audit evidence | Up to five years after account closure, application rejection or the last relevant event. |
| Private draft listings, demo or internal test RFQs, messages, support correspondence and uploaded business records | Up to five years after account closure or the last relevant interaction where necessary for contractual, legal, audit or dispute purposes. Unnecessary personal fields are removed or anonymised earlier. |
| Marketing consent and cookie consent evidence | Five years after withdrawal, the last related communication or the last recorded choice, whichever is later. |
| Suppression record | A minimal keyed or cryptographic marker for as long as necessary to honour the opt out or until new valid permission is recorded. |
| Unverified registration | Deleted or anonymised after 30 days. |
| Invitation token | One use and no more than seven days. Only a cryptographic hash is stored. The raw token is not retained. |
| Email verification code | Valid for 10 minutes and deleted or irreversibly invalidated after use or expiry. Non secret evidence of verification may be kept for five years. |
| Password reset secret | Valid for 15 minutes and deleted or irreversibly invalidated after use or expiry. |
| Authentication session | No more than 24 hours from successful authentication. The server rejects a cookie session after two hours of inactivity. Reissue during active use does not extend the absolute lifetime. Sessions are revoked on logout, password change and material account changes. |
| Ordinary access and technical logs, including raw IP and user agent | Normally up to 12 months. Incident specific evidence may be retained up to five years after the incident closes where reasonably necessary. |
| Workspace activity sessions, page timing and allowlisted action or changed-field-group records | Activity sessions and related records are scheduled for bounded deletion 90 days after the session starts. Because related page, action and timing records are created during the session and deletion runs in bounded operational batches, an individual record may be kept for slightly less or slightly more than 90 days. Backlog is monitored. A documented legal hold may preserve relevant records longer. |
| UTM, referral and user linked attribution | Up to 12 months, then deleted or irreversibly aggregated unless the field forms part of a five year legal consent or acceptance record. |
| Google Analytics user and event level data | 14 months in the Google Analytics property. First party analytics cookies may last up to two years unless rejected, withdrawn or deleted earlier. |
| Privacy requests, complaints and closed investigations | Up to five years after completion. |
| Contracts, orders, invoices, payment and corporate tax records, if a future approved feature creates them | At least seven years after the end of the relevant tax period where required by UAE tax law. |
| Deleted data in protected backups | Up to 90 days before ageing out, unless a legal hold applies. |
Data may be retained longer where required by law, a regulator, fraud prevention, dispute resolution or a documented legal hold. At the end of the applicable period, data is deleted or irreversibly anonymised.
14. Security
We use technical and organisational measures proportionate to the nature and risk of the pilot. These include password hashing, email verification, access control, rate limiting, session revocation, security monitoring, audit records and protected storage workflows.
Authenticated sessions use server controlled Secure and HttpOnly cookies with SameSite protection, CSRF protection, session rotation and server side revocation. Authentication bearer tokens are not stored in browser local storage.
No internet or storage system is completely secure. Users must protect credentials, use authorised business accounts, enable available security controls and contact us promptly about suspected misuse.
15. Your rights
Subject to applicable law and lawful exceptions, you may have the right to:
- receive information about processing;
- access and obtain a copy of personal data;
- correct inaccurate data;
- request deletion or restriction;
- object to certain processing;
- withdraw consent;
- request transfer of data where applicable;
- request human review of certain automated processing; and
- complain to the competent authority.
To make a request, email team@you.aero with the subject Privacy Request. You do not need an account to contact us. We may request information reasonably necessary to verify identity and authority, but we will never ask for your password.
We will respond within the period required by applicable law and will explain any lawful restriction. A request may not require deletion of a minimal suppression marker, another person's data, legally required tax records, security evidence or records needed for legal claims.
16. Account closure and preferences
You may update available account fields and preferences in the workspace. You may unsubscribe from marketing through the email link or by contacting us. You may request account closure or deletion by emailing team@you.aero.
Closure does not erase another company's records, shared business records, security evidence, suppression records, tax records or legally required audit information where retention is permitted or required.
17. Children
you.aero is a business service and is not intended for children. Users must be at least 18 years old. If you believe a child has provided personal data, contact us so that we can assess and take appropriate action.
18. Other organisations
The Platform may link to third party websites or permit approved sharing with another business. An independent organisation processes data under its own notice and responsibilities. Each participating company is responsible for having authority to provide information about its personnel and for using information received through the Platform only for lawful business purposes.
19. Changes
We may update this Notice when the pilot, technology, providers or law changes. The current version and effective date will be displayed. If a change materially affects existing data, we will provide additional notice or seek a new choice where required.
20. Contact
JETSONIC TRADING - FZCO / you.aero
Email: team@you.aero
Subject: Privacy Request
Website: https://you.aero/