The data controller is "AeroQB" [NTN: 3520282369147] operating AeroQB at aeroqb.com.
Privacy contact: contact@aeroqb.com
We currently do not have any physical establishment in the EU however we offer paid services to EU users while adhering to GDPR Article 27.
| Data | Required? |
|---|---|
| First, middle, last name | First and last required; middle optional |
| Date of birth | Required (minimum age verification) |
| Email address | Required |
| Country of residence | Required |
| Phone number and country dialing code | Required |
| Approved Training Organisation (ATO) | Optional |
| Training stage and target exam window | Required |
| How you heard about us | Optional |
| Marketing consent choice | Recorded either way |
| Terms and privacy acceptance timestamps | Recorded automatically |
Card and payment credentials are collected and processed by Paddle, our payment provider — we never see or store your full card number. We receive transaction confirmations, subscription status, and, from Paddle as merchant of record, limited billing metadata. We also store the raw webhook payloads Paddle sends us (which include the billing metadata above) for idempotency and audit purposes; see Section 7 for how long we keep these.
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Providing the Service — account, quizzes, progress tracking | Registration data, study data | Contract performance (Art. 6(1)(b)) |
| Payment processing and subscription management | Payment metadata, subscription status | Contract performance (Art. 6(1)(b)) |
| Age verification | Date of birth | Legal obligation / legitimate interest (Art. 6(1)(c)/(f)) |
| Preventing account sharing and abuse | Device fingerprints, session data, IP | Legitimate interest (Art. 6(1)(f)) — protecting our service and content |
| Payment routing by region | IP-derived country | Legitimate interest (Art. 6(1)(f)) |
| Marketing emails (study tips, exam reminders, offers) | Email, name, training stage, exam window | Consent (Art. 6(1)(a)) — opt-in only, withdrawable any time |
| Service improvement and aggregate analytics | Study data (aggregated / de-identified where possible) | Legitimate interest (Art. 6(1)(f)) |
| Legal compliance, records, disputes | Acceptance timestamps, transaction records | Legal obligation (Art. 6(1)(c)) |
Paid subscriptions are personal. To enforce this we operate automated measures, which involve a meaningful degree of tracking of your devices and sessions — this is not simple analytics:
These measures can result in automated suspension of an account exhibiting sharing behaviour. If your account is suspended and you believe this is an error, contact us — a human will review the decision (this is your right under GDPR Article 22 in respect of decisions with significant effects). We rely on legitimate interest (Article 6(1)(f)) as the legal basis for this processing, having assessed it as necessary and proportionate to protect the Service from unauthorised sharing.
We do not sell your personal data. We share it only with processors and partners necessary to run the Service:
| Recipient | Role | Data involved |
|---|---|---|
| Supabase Pte. Ltd. | Database and authentication hosting | All account and study data |
| Cloudflare, Inc. | Website hosting, CDN, security, country detection | IP address, technical logs |
| Paddle.com Market Ltd | Merchant of record for all payments | Name, email, country, transaction data |
| DataRep | EU representative under GDPR Article 27 | Correspondence forwarded from EU supervisory authorities or data subjects, where applicable |
| [DECISION-7: email provider — e.g. Resend/SendGrid/Postmark once custom SMTP is configured] | Transactional and marketing email delivery | Email address, name |
| Bunny.net (Bunny Fonts) | Font delivery — chosen specifically for its zero-logging, EU-based service, see Section 10 | None retained; requests are not logged |
We may also disclose data where required by law, court order, or to protect our legal rights.
Our processors store and process data in multiple regions, including the United States, Singapore, and the European Union. Where personal data of EU/EEA/UK residents is transferred outside those areas, we rely on our processors' compliance mechanisms, including Standard Contractual Clauses — the mechanism Supabase Pte. Ltd. (Singapore) relies on — and, where applicable, the EU–US Data Privacy Framework. Details are available in each processor's own privacy documentation.
| Data | Retention |
|---|---|
| Account and profile data | While your account is active, then deleted or anonymised within 30 days of account closure |
| Study/progress data | While your account is active; deleted with the account |
| Transaction and billing records | Retained as required by tax and accounting law (typically 6–7 years) |
| Raw Paddle webhook payloads | Retained on the same 6–7 year basis as transaction and billing records, since they contain the same billing metadata and support the same audit purpose |
| Terms/privacy acceptance timestamps | Duration of account plus limitation period for legal claims |
| Security logs (IP, session events, device fingerprints) | 6 months |
| Marketing consent records | Until consent is withdrawn, plus proof-of-consent retention |
Depending on your location, you have the right to:
To exercise any right, email contact@aeroqb.com. We respond within one month (GDPR) or the period required by your local law. We may need to verify your identity before acting on a request.
We send marketing emails (study tips, exam-window reminders, product news, offers) only if you opted in at registration or later. Every marketing email contains an unsubscribe link. Unsubscribing does not affect transactional emails (receipts, security notices, service announcements), which we send as part of operating the Service.
We use a minimal set of strictly necessary storage mechanisms:
| Item | Type | Purpose | Duration |
|---|---|---|---|
| Supabase auth token | Local storage | Keeping you signed in | Until sign-out / expiry |
| Session token | Local storage | Concurrent-session enforcement | Session |
| Cloudflare security cookies | Cookie | Bot protection and security | Set by Cloudflare |
We do not use advertising or cross-site tracking cookies. Because we use only strictly necessary storage, no consent banner is required; if we ever introduce analytics or marketing cookies, we will implement a consent mechanism first.
Fonts: pages load fonts from Bunny Fonts rather than Google Fonts. Bunny Fonts is EU-based and does not log IP addresses or any other personal data on font requests — we chose it specifically to avoid the data-transfer and consent issues associated with Google Fonts.
No system is perfectly secure. If we become aware of a personal-data breach likely to result in a risk to you, we will notify the relevant supervisory authority and, where required, affected users without undue delay.
The Service is not directed at children under 16, and we do not knowingly collect data from anyone under 16. Date of birth is checked at registration. If you believe a child under 16 has created an account, contact us and we will delete it.
We may update this policy. Material changes will be notified by email or in-Service notice at least 14 days before taking effect. The "last updated" date at the top reflects the current version.
Privacy questions and rights requests: contact@aeroqb.com, or via our contact page
If you are in the EU/EEA or UK and believe our processing infringes data-protection law, you have the right to lodge a complaint with your local supervisory authority, or with DataRep as our EU representative, without prejudice to any other remedy.