Privacy Policy

Home / Privacy Policy

Privacy Policy

Last updated: August 2026

This Privacy Policy explains how ALTAY HAVACILIK VE UZAY TEKNOLOJILERI A.S. ("we", "us", "our") collects, uses, stores, and protects your information when you use Rozetta, our safety and occurrence management platform for aviation crew and personnel. This includes the Rozetta mobile application ("the App"), the Rozetta web application, and the related services we provide (together, "the Services").

The App is provided for use by authorised personnel of the organisation that has licensed it (your "Organisation" or employer). Please read this policy carefully. By using the Services, you acknowledge the practices described here.

Note on roles: In most deployments the airline/Organisation that employs you is the data controller of the safety data you submit, and ALTAY HAVACILIK VE UZAY TEKNOLOJILERI A.S. processes that data on the Organisation's behalf. Where you have questions about how your Organisation uses your data, please also refer to your Organisation's own privacy notice.


1. Scope

This policy applies to personal data processed through the Services, including the Rozetta mobile application, the Rozetta web application, and the related back-end services that support them. Some practices described below apply only to a specific platform (for example, on-device storage, background synchronisation and mobile app permissions relate to the mobile App).

This policy does not cover:

  • third-party websites, products, or services that have their own privacy notice;
  • data your Organisation processes about you outside the Services.

2. Who We Are & How to Contact Us

ALTAY HAVACILIK VE UZAY TEKNOLOJILERI A.S.
RESITPASA MAH. KATAR CAD. ARI2 BINASI A BLOK NO: 4/1/1 SARIYER ISTANBUL TURKIYE
Privacy contact: info@rozetta.ai


3. Information We Collect

We only collect information needed to operate a safety-reporting service. This includes:

3.1 Account & identity information

  • Your email address (used to sign in).
  • Your role, Organisation/company, and department(s), as provided by your Organisation to determine what you can access.

We do not ask you to create an account yourself; accounts are provisioned by your Organisation.

3.2 Authentication data

  • A secure sign-in token issued after you log in. In the mobile App this is stored using the platform's secure storage (iOS Keychain / Android Keystore); in the web application it is held in your browser session.
  • If your Organisation uses Single Sign-On (SSO), sign-in is handled by your Organisation's identity provider (e.g. Microsoft Entra ID); we receive only the authentication result needed to grant access.

We process your password only to authenticate you; it is sent securely to our backend and is not stored on your device.

3.3 Safety / occurrence report content

When you create a report, we collect the information you enter, which may include:

  • report title, description and detailed narrative;
  • occurrence date and time;
  • location (the place of the occurrence, as typed by you, not your device's GPS position);
  • aircraft registration mark and flight number;
  • a confidentiality flag; and
  • other aviation safety fields (e.g. occurrence category and related details).

Important: report content may include personal data about you and, depending on what you write, about other people (e.g. other crew or passengers) and, in some cases, sensitive information (such as details of an injury or a health-related event). Please include only information that is relevant and necessary for the safety report.

3.4 Device & technical information

  • Connectivity status (whether your device is online or offline), used to decide when to send queued reports.
  • Standard technical information necessary to communicate securely with our servers (for example, the network request metadata handled by the backend).

The App does not collect advertising identifiers and does not track you across other apps or websites.

3.5 Information stored locally on your device

To work offline, the mobile App stores your draft and queued reports in a local database on your device until they are successfully sent to our servers, after which they are managed according to the retention rules below.


4. How We Use Your Information

We use the information above to:

  • authenticate you and control access based on your role;
  • create, queue, submit and track safety/occurrence reports;
  • synchronise reports with our servers when connectivity is available, including background synchronisation so reports are not lost;
  • operate, maintain, secure and troubleshoot the Services; and
  • comply with aviation safety and other legal obligations.

We do not use your data for advertising or sell your data.


5. Legal Bases for Processing

Where the UK GDPR / EU GDPR applies, we (or your Organisation as controller) rely on one or more of the following legal bases:

  • Legal obligation: aviation safety and mandatory occurrence-reporting requirements applicable to your Organisation.
  • Performance of a contract: to provide the Services under the agreement with your Organisation, and to give you access as an authorised user.
  • Legitimate interests: to operate a secure, reliable safety-management tool (balanced against your rights and freedoms).
  • Vital interests / public interest, where safety information is necessary to protect health and safety.

Where Turkish law (KVKK) applies, processing is based on the corresponding legal grounds, including compliance with a legal obligation and legitimate interests.

If we ever rely on consent, you may withdraw it at any time.


6. App Permissions

The mobile App uses only the following device capabilities:

  • Network / internet access: to send reports and sign you in.
  • Background app refresh / background processing: to synchronise queued reports when connectivity returns, even if the App is not open.
  • Secure storage (Keychain / Keystore): to protect your sign-in token.

The App does not request access to your device's precise GPS location, camera, contacts, photos, or microphone.


7. Cookies and Similar Technologies

Our web application uses cookies and similar technologies (such as browser local storage) to function and to improve your experience. The mobile App does not use cookies; it stores only the secure sign-in token described above.

We use the following categories:

  • Strictly necessary: required to sign you in, keep your session secure, and operate core features. These cannot be switched off.
  • Functional / preferences: remember choices such as language or display settings.
  • Analytics / performance: help us understand how the web application is used so we can improve it. These are used only where permitted and, where required by law, with your consent.

Where non-essential cookies require consent (for example under UK PECR or EU ePrivacy rules), we ask for it through a cookie banner or settings control, and you can change your choice at any time. You can also manage or delete cookies through your browser settings; blocking strictly necessary cookies may affect how the web application works.


8. How We Share Your Information

We share information only as needed to run the service:

  • Your Organisation: safety reports are made available to your Organisation's authorised safety personnel and systems.
  • Service providers (sub-processors) acting on our behalf under contract, including our cloud hosting provider, Amazon Web Services (AWS) in London (eu-west-2), and, where SSO is used, your Organisation's identity provider.
  • Aviation authorities / regulators, where reporting is required by law.
  • Legal / safety: where required to comply with the law, enforce our terms, or protect the rights, safety, and security of people and property.

We do not sell your personal data or share it for advertising.

Confidential reporting

Where you mark a report as confidential, we apply appropriate measures to limit access to reporter-identifying information, consistent with a "just culture" approach to safety reporting. Disclosure may still be required where the law compels it.


9. International Data Transfers

Your information may be processed on Amazon Web Services (AWS) infrastructure in London (eu-west-2) and other locations where we or our service providers operate. Where personal data is transferred across borders, we rely on appropriate safeguards (such as UK/EU Standard Contractual Clauses or an adequacy decision). Contact us for more detail.


10. Data Retention

We retain safety report data for as long as necessary to fulfil the purposes in this policy and to meet applicable aviation record-keeping and other legal requirements, after which it is deleted or anonymised. Draft/queued reports on your device are removed once successfully submitted.


11. Data Security

We use technical and organisational measures to protect your data, including:

  • encryption in transit (HTTPS/TLS) between the Services and our servers;
  • secure token storage on the device (Keychain / Keystore);
  • role-based access controls on the backend.

No method of transmission or storage is completely secure, but we work to protect your information and to review our safeguards.


12. Your Rights

Subject to applicable law (UK GDPR / EU GDPR / KVKK), you may have the right to:

  • access the personal data we hold about you;
  • request correction of inaccurate data;
  • request erasure of your data;
  • restrict or object to certain processing;
  • request portability of data you provided; and
  • withdraw consent, where processing is based on consent.

Some rights may be limited where we must keep information to comply with aviation safety or other legal obligations. To exercise your rights, contact us at info@rozetta.ai; because your Organisation is typically the controller, you may also contact them directly.

You also have the right to lodge a complaint with a supervisory authority. In the United Kingdom, this is the Information Commissioner's Office (ICO), ico.org.uk; if you are located elsewhere, it is your local data protection authority.


13. Children's Privacy

The Services are professional tools intended for authorised adult personnel. They are not directed to children and we do not knowingly collect data from children.


14. Third-Party Services

The Services rely on the following third parties, which process data only as needed to provide their part of the service:

  • Amazon Web Services (AWS), London (eu-west-2): secure hosting of our backend.
  • Identity provider (e.g. Microsoft Entra ID): only if your Organisation enables Single Sign-On.

These providers have their own privacy notices governing their processing.


15. Changes to This Policy

We may update this policy from time to time. We will change the "Last updated" date above and, where appropriate, notify you or your Organisation of material changes. Continued use of the Services after changes take effect constitutes acknowledgement of the updated policy.


16. Contact Us

If you have questions about this Privacy Policy or how your data is handled, contact:

ALTAY HAVACILIK VE UZAY TEKNOLOJILERI A.S.
RESITPASA MAH. KATAR CAD. ARI2 BINASI A BLOK NO: 4/1/1 SARIYER ISTANBUL TURKIYE
info@rozetta.ai