Legal & Trust Center

Privacy Policy

What personal data is processed, why, on what legal basis and with what rights.

Version
1.0
Effective date
17 August 2026
Last updated
17 August 2026
Document owner
the Groundmaster project, with responsibility assigned to its legal and compliance function
Applicable jurisdiction
Portugal, European Union
Permanent URL
https://www.groundmaster.pt/legal/privacy
This notice explains how personal data is handled in connection with the Platform. For most data held inside an Organisation's workspace, the Customer organisation acts as controller and we act as processor on its instructions; the Data Processing Terms describe that relationship. For account, billing, security and website data we act as controller.

1.Who we are and our role

Groundmaster AI is operated by the Groundmaster project, based in Portugal, European Union. Privacy enquiries can be sent to groundmaster.web@gmail.com.

We act as controller for data we process for our own purposes: account administration, authentication, billing, security monitoring, abuse prevention, support, service communications, and website analytics where used. We act as processor for Content that a Customer or its Users place in an Organisation workspace, including operational and technical records.

2.Categories of data processed

CategoryTypical examplesRole
Identity and contact dataName, work email, phone number, postal address, personnel identifiers and codes used inside an organisationProcessor (workspace) / Controller (account)
Credential and authentication dataHashed credentials, session and token metadata, multi-factor statusController
Role and permission dataAssigned roles, functional categories, page-level access levels, approval and delegation attributesProcessor
Personnel and qualification documentsCertificates, authorisations and similar documents uploaded by an organisation, and official identification or tax reference numbers where an organisation chooses to record themProcessor
Operational and technical recordsRecords describing aircraft, components, planned and corrected work, findings, materials, tooling, inspections, forecasts and traceability documentsProcessor
Activity and audit dataSign-in events, record creation and modification events, sign-off and time-recording entries, permission changesProcessor / Controller
Technical and device dataIP address, browser and device characteristics, timestamps, request metadata, error diagnosticsController
Support and communications dataMessages, attachments and correspondence relating to support requestsController
Billing and commercial dataSubscription, invoicing and payment status informationController
AI interaction dataPrompts, retrieved context references and generated output associated with AI-assisted featuresProcessor

3.Special categories and sensitive data

The Platform is not designed for special categories of personal data as defined by data protection law, and organisations should not upload such data unless there is a lawful basis and an appropriate safeguard. Certain identifiers that organisations may record for personnel administration are treated as sensitive by us and are subject to restricted access controls.

5.Model training and AI

Customer Data is not used to train generative or foundation models for our own purposes or for the general benefit of other customers. Where AI features are used, prompts and the necessary context are transmitted to a model provider only to generate a response for that request. Contractual controls require providers not to use that content to train their models. Further detail is in the AI Policy & AI Transparency Notice.

6.Sharing and disclosure

Personal data may be shared with:

  • service providers acting as subprocessors, by category, as listed in the Subprocessors document;
  • other Users of the same Organisation, according to the permissions configured by that Organisation;
  • professional advisers, auditors and insurers where necessary and under confidentiality;
  • competent authorities and courts where legally required, following the process described in the Legal, Privacy & Authority Requests page;
  • a successor entity in the context of a reorganisation, merger or acquisition, subject to equivalent protection.

We do not sell personal data and do not share it for cross-context behavioural advertising.

7.International transfers

Hosting and processing take place in the European Economic Area (EEA), where technically available; any processing by third-party subprocessors outside the EEA is subject to appropriate GDPR safeguards, including Standard Contractual Clauses where applicable. Where personal data is transferred outside the European Economic Area, transfers rely on an adequacy decision or on appropriate safeguards such as the European Commission's standard contractual clauses, together with supplementary technical and organisational measures where required.

8.Retention

Retention is governed by the Data Retention & Deletion Policy. In summary, workspace Content is retained for as long as the Organisation's subscription requires it and for the periods the Customer configures or is legally required to observe; account, security and billing records are retained for the periods necessary for security, statutory and accounting purposes; and backups follow their own rolling cycle.

9.Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit, encryption at rest, row-level access enforcement, role-based and page-level permissions, logical tenancy separation, least-privilege administration, audit logging, secret management, dependency and configuration monitoring, and backup and recovery procedures. The Security Overview describes these measures in more detail. No system can be guaranteed absolutely secure.

10.Your rights

Subject to applicable law you may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests. Where processing relies on consent you may withdraw it at any time. You may also lodge a complaint with your supervisory authority.

Where the data sits inside an Organisation workspace, we will normally refer the request to that Organisation as controller and assist it in responding. Requests can be submitted through the legal requests page. Some records — in particular records maintained for aviation traceability, audit and statutory purposes — may lawfully be retained despite an erasure request.

11.Automated decision-making

The Platform does not take decisions producing legal effects concerning individuals solely by automated means. Automated features generate suggestions, forecasts and alerts that require human review before use.

12.Children

The Platform is intended for professional use and is not directed at children.

13.Changes to this notice

We may update this notice. The version and dates at the top of this page indicate the current release, and material changes are communicated in advance where required.

Change history

VersionDateChange
1.017 August 2026Rewritten to cover platform-wide processing, roles, legal bases, international transfers and rights.
Contact

Questions about this document can be sent to groundmaster.web@gmail.com. Formal legal, privacy, security and regulatory requests should follow the routes described in the legal requests page. Fields shown as bracketed placeholders are pending confirmation by the operating legal entity and do not constitute a statement of fact.

Related documents