1. Data Controller
A.I.R.Space Technologies Pty Ltd (operating as OverSite) is the data controller for the personal and operational data described in this policy.
Registered address: 294 Ocean Keys Boulevard, Clarkson WA 6030, Australia.
Contact: For any privacy enquiry, data access request, or deletion request, contact your organisation's OverSite administrator, email info@airspacetech.com.au, or submit an enquiry via the Contact Us form on our landing page.
2. Data We Collect
We collect the following categories of data:
2.1 Account data (Personal Information)
- •Full name, email address, and phone number — provided during onboarding or invitation.
- •Google account identifier — if you choose to log in with Google.
- •Assigned role(s) and worksite assignments — set by your organisation's admin.
2.2 Operational data
- •Drone operation plans: pilot name, contact details, zones, times, altitudes, aircraft type, mission notes, takeoff/landing positions.
- •Manned aircraft airspace blocks: aircraft registration, operation type, scheduled times, buffer windows.
- •Manual tactical deconfliction records: participating pilot names, messages, approvals, and CRP adjudication notes.
- •Emergency response records: pilot name, contact details, capability notes, and whether the pilot operates remotely.
- •Emergency dispatch records: dispatched pilot name, dispatching officer, and assignment details.
- •Flight extension requests: requesting pilot name, requested end times, and CRP adjudication notes.
2.3 Pilot live location data
- •Real-time GPS position — only when a pilot has explicitly opted in to location sharing in Settings. This data is captured only while the app is open, updates at most once per minute, and only when the pilot has moved. It is cleared when sharing is turned off.
2.4 Messaging data
- •Message thread content, participant lists, timestamps, and read/unread state — for general, tactical deconfliction, and direct threads.
2.5 Notification data
- •UNOTAP broadcasts and targeted alerts, including delivery metadata, read status, and expiry state.
2.6 Billing data
- •Subscription plan, billing type (card or invoice), billing status, quoted price, and billing interval.
- •Stripe customer ID and subscription ID — when paying by card. Card details never touch OverSite servers; they are entered directly on Stripe's secure checkout page.
2.7 Enquiry data
- •Name, email, phone, organisation, interest type, and message — submitted via the public Contact Us form on the landing page.
2.8 Audit log data
- •Timestamp, actor name and role, action type, entity type and ID, and detail — for every significant action taken in the system. The audit log is immutable and retained indefinitely as a compliance record.
2.9 Technical and usage data
- •Device type, browser, and approximate location (derived from IP) for security and service operation. We do not use this for advertising.
3. How We Use Your Data
We use your data to:
- •Operate the safety system — coordinate operation plans, detect airspace conflicts, broadcast UNOTAP notifications, and manage emergencies.
- •Maintain safety records — retain operation plans, audit logs, and tactical deconfliction histories for regulatory compliance and incident investigation.
- •Process payments — manage subscriptions and billing via Stripe.
- •Communicate with you — send notifications, messages, and operational alerts.
- •Respond to enquiries — follow up with prospective customers who submit the Contact Us form.
- •Improve the service — analyse usage patterns to improve features and reliability.
We do not sell your personal data to third parties. We do not use your data for advertising.
4. Legal Basis for Processing
We process your data under the following legal bases:
- •Contractual necessity — to provide the OverSite service you or your organisation has subscribed to.
- •Legal obligation — to comply with aviation safety regulations (including CASA requirements) that mandate the retention of flight and operational records.
- •Legitimate interests — to maintain safety-critical audit trails, prevent airspace conflicts, and protect the safety of personnel and aircraft.
- •Vital interests — to broadcast emergency notifications and Return-to-Home instructions during site emergencies.
- •Consent — for pilot location sharing, which is strictly opt-in and can be withdrawn at any time.
5. Data Retention
Different data types are retained for different periods based on operational, regulatory, and safety requirements:
| Data type | Retention period | Reason |
|---|---|---|
| Account data | While your account is active; deleted or anonymised on account deletion (see Data Deletion Policy) | Operational necessity |
| Operation plans | Retained as safety/regulatory records; anonymised on account deletion | CASA compliance, incident investigation |
| Audit logs | Retained indefinitely | Immutable compliance record; legal obligation |
| Notifications | Most active notices expire within 24 hours; some safety-critical types persist longer; archived notifications retained indefinitely | Delivery proof; compliance |
| Messages | Retained indefinitely as audit and safety records; anonymised on account deletion | Safety coordination, incident investigation, audit |
| Pilot live location | Cleared immediately when sharing is off or app is closed; not retained | Data minimisation |
| Billing data | Retained for the duration of the subscription and as required for tax/accounting law | Legal obligation |
| Enquiry data | Retained until the enquiry is closed and for a reasonable period thereafter | Business records |
| Archived site data | Held for 3 months after site archive, then permanently deleted (audit logs and message conversations retained indefinitely) | Data minimisation with safety buffer |
When a worksite is archived, a full data snapshot is generated automatically and made available for download before the 3-month retention window expires and the live data is permanently deleted.
6. Third-Party Processors
We use the following third-party services to operate OverSite:
6.1 Google (Authentication)
- •Used for Google single sign-on. Google provides your name and email to OverSite for account linking. Google's privacy policy applies to your Google account data.
6.2 Stripe (Payment Processing)
- •Used for card-based subscription payments. Stripe processes your card details on its secure checkout page — OverSite never receives or stores card numbers. Stripe's privacy policy applies to payment data. We store only the Stripe customer ID and subscription ID.
6.3 Flightradar24 (Aircraft Tracking)
- •Used for OverSite Traffic live aircraft data on OverSite 24 and above plans. FR24 provides aircraft position data; we do not share your personal data with FR24.
6.4 Cloud Infrastructure
- •OverSite is hosted on cloud infrastructure providers that process data on our behalf under data processing agreements. Your data is stored in compliance with applicable data protection laws.
We do not share your personal data with any other third parties except where required by law, or where necessary to provide the safety-critical service you have subscribed to.
7. Data Security
We take reasonable technical and organisational measures to protect your data:
- •Access control — OverSite uses an invite-only access model. Every user must be invited by an existing admin; there is no public self-signup. Access is role-based and scoped to assigned worksites.
- •Encryption — data is transmitted over encrypted connections (HTTPS/TLS).
- •Audit logging — every significant action is recorded in an immutable audit log for traceability.
- •Row-level security — data access is enforced at the database level, not just the application level, to prevent unauthorised access.
No system is perfectly secure. If a data breach occurs that is likely to result in a risk to your rights, we will notify affected users and relevant authorities as required by law.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- •Access — request a copy of the personal data we hold about you.
- •Rectification — request correction of inaccurate personal data.
- •Deletion — request deletion of your account and associated personal data. See our Data Deletion Policy for the specific rules that apply to OverSite, including the active-site restriction.
- •Restriction — request that we limit the processing of your data in certain circumstances.
- •Objection — object to the processing of your data for specific purposes.
- •Portability — request an export of your data in a machine-readable format. OverSite provides on-demand full-site data export for admins.
Important — limited deletion right: Because OverSite is a safety-critical aviation system subject to regulatory retention requirements, your right to deletion is not absolute. Certain records (operation plans, audit logs, notifications) are retained as safety and regulatory records. Personal identifiers in these records are anonymised rather than fully deleted. See the Data Deletion Policy for full details.
To exercise any of these rights, contact your organisation's OverSite administrator or submit a request via the Contact Us form.
9. International Data Transfers
OverSite is designed for use in Australia. Your data is stored on cloud infrastructure that may process data outside Australia. Where this occurs, we rely on appropriate safeguards (such as standard contractual clauses) to ensure your data is protected to a standard consistent with Australian privacy law.
If you are accessing OverSite from outside Australia, your data will be transferred to and processed in Australia and any applicable cloud infrastructure regions.
10. Children's Data
OverSite is a professional aviation safety system and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a minor has been inadvertently given access, contact your organisation's admin immediately so the account can be removed.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify active users of material changes via in-app notification or email. The "last updated" date at the top of this page indicates when the policy was last revised. Continued use of OverSite after changes take effect constitutes acceptance of the updated policy.
12. Contact
For any privacy-related enquiry, data access request, deletion request, or complaint:
- •Contact your organisation's OverSite administrator, or
- •Submit an enquiry via the Contact Us form on our landing page, selecting "General" as the interest type.
We will respond to all legitimate privacy requests within a reasonable timeframe.
