Privacy Policy
Effective from 21 August 2026
Cuppa Pte Ltd (“Cuppa”, “Aviato”, “we”, “us”, “our”) provides a flight tracking and roster companion, which includes Aviato's website www.aviato.so, mobile apps, web dashboard at dash.aviato.so, service features and integrations (“Services”) that help airline crew, their friends and family, customers, prospective customers, partners, vendors, job applicants, visitors and others connected to or interested in Aviato (“Users”) import rosters, follow flights in real time, receive disruption alerts, and keep a logbook.
In the course of providing the Services, Aviato collects personal information relating to you and your preferences, being information that identifies you, or that could reasonably be used to identify you, whether directly or indirectly (“Personal Data”). Such information may include your roster, your schedule and your professional flying record. This Privacy Policy sets out how and why we collect, use, process, store, disclose and protect your Personal Data, and the choices available to you in respect of it. The following provisions are summarised at the outset for convenience:
- We do not sell your Personal Data, and we do not share your roster or flight records with your airline, your employer, or any other third party for their own purposes.
- We do not permit third parties to use your Personal Data to train artificial intelligence models.
- Roster files uploaded by you are encrypted at rest. We retain such files in order to re-process your roster, to recover flights that failed to import and to restore your schedule in the event of data loss.
- Flight sharing operates on an opt-in basis and may be revoked at any time. Persons you invite may view only those flights you have elected to share, and may not access your logbook, your complete roster history or your account details.
- Device location is collected only where you grant permission, and is used to improve the accuracy of flight matching, delay detection and flight tracking. You may withdraw that permission at any time through your device settings.
- Your Personal Data is stored on infrastructure operated by Supabase and DigitalOcean located in Singapore, and is encrypted in transit and at rest.
Each section of this Privacy Policy is preceded by a short summary. The summaries are provided for convenience only, do not form part of this Privacy Policy and do not limit the provisions that follow. This Privacy Policy should be read together with our Terms of Service, which govern your use of the Services. Capitalised terms used but not defined in this Privacy Policy have the meaning given to them in the Terms of Service. Any questions may be directed to us using the details in the Contact Us section.
Scope of This Privacy Policy
By using Aviato or giving us your Personal Data, you accept the practices described here.
This Privacy Policy applies whenever you access or use any part of our Services, wherever you are located. It covers the Aviato iOS and Android apps, the web dashboard, our website, and our email communications.
This Privacy Policy applies whether you use the Services as a pilot, as cabin crew, or as a friend or family member following another User's flights. Where you have been invited to the Services by a crew member, this Privacy Policy governs the Personal Data we hold in respect of you.
Where you submit to us the contact details of any other person, including for the purpose of issuing an invitation to follow your flights, you represent and warrant that you are entitled to disclose those details to us for that purpose and that the person concerned would reasonably expect such disclosure.
Your Rights and Preferences
You can exercise your privacy rights and control how we use your information.
Data protection laws differ by region and grant individuals different rights over their Personal Data. Cuppa Pte Ltd is incorporated in Singapore and operates its Services from Singapore, using cloud infrastructure and service providers located in Singapore, the United States and the European Union.
Where permitted by applicable law, we may transfer, process or store your Personal Data in any region where we have operations or where we engage service providers and business partners (together, “Service Providers”). If you access our Services from outside Singapore, you agree to the collection, transfer, use and storage of your Personal Data in line with applicable data protection laws and the safeguards described in this policy.
If this policy does not answer your question, please Contact Us.
Information We Collect
We collect information about you, your schedule, your flights, and how you use Aviato.
Categories of Personal Data
The table below lists the categories of Personal Data we may collect, including information we may have collected in the past 12 months.
| Category of Personal Data | Examples of Personal Data We Collect | Categories of Third Parties with Whom We Share this Personal Data |
|---|---|---|
| Profile or Contact Data |
|
|
| Professional or Employment-Related Data |
|
|
| Roster and Schedule Data |
|
|
| Flight Log Data |
|
|
| Sharing and Connection Data |
|
|
| Payment Data |
|
|
| Device/IP Data |
|
|
| Location Data |
|
|
| Web and Product Analytics |
|
|
| Marketing and Communication Data |
|
|
| Other Identifying Information that you Voluntarily Choose to Provide |
|
|
Information That You Provide to Aviato
We collect Personal Data you give us when you register for and use the Services: your name, email address, professional details, the roster files you upload, the flights you log, and the people you choose to share flights with. We also keep correspondence, feedback and notes you send us privately or post in public forums.
The provision of certain Personal Data is a prerequisite to use of the Services. We are unable to construct your schedule without your roster, or to issue flight alerts without the means to identify your flights. Other information is optional and serves to improve the utility of the Services; the provision of your rank and seat, for example, enables the correct calculation of time in seat and applicable regulatory limits.
If you apply to work with Cuppa as an employee or contractor, Personal Data will be required in order for you to be considered for and to maintain that relationship.
Roster Files
This section applies to roster files and to the data contained within them, which constitute a distinct category of Personal Data warranting specific provision. It applies only where you upload a roster. Users who record or follow individual flights without uploading a roster provide only the flight details they enter, and no part of this section applies to them.
Roster files uploaded by you are stored encrypted at rest. We retain such files in order to re-parse your roster following improvements to our import logic, to recover flights that failed to import, to correct import errors and to restore your schedule in the event of data loss. Roster files are processed automatically by our systems and are accessed by authorised personnel only to the extent necessary to investigate an import failure or a support request submitted by you.
Roster files may contain the Personal Data of third parties. Airline rosters may identify the names, staff numbers or duty details of other crew members rostered alongside you. We process such information solely for the purpose of reconstructing your own duties and flights. We do not create profiles of, contact, or direct marketing to, any other crew member identified in your roster, and we do not disclose their details to your connections. You may redact such details prior to upload, or record your flights manually, if you do not wish to disclose them to us.
Licence and Certificate Data
Where you elect to record licence, rating, qualification or certificate details, including the validity or expiry date of a medical certificate, we store those details solely in order to display them to you and to issue expiry reminders. We do not request, and you should not submit, any information concerning the content of a medical assessment, any medical condition, diagnosis, treatment or restriction, or any other special category of personal data within the meaning of Article 9 of the EU General Data Protection Regulation. We do not knowingly process special category data, and where such data is submitted to us we may delete it without notice.
Automatic Information Collection
When you access or use our Services we automatically collect certain information. We use cookies and similar tracking technologies on our website and dashboard, and analytics SDKs in our mobile apps, to collect technical information such as URL, cookie data, IP address, device type, unique device identifiers, device attributes, network connection type and provider, browser type, language, operating system, app version and other functional information.
Location Data
The Services request permission to access your device location. Depending on your device and the permissions you grant, this may include access while you are using the app and, where you have granted background permission, while the app is not in use. Where you grant that permission, we process device location data in order to improve the accuracy of flight matching, departure and arrival detection, delay detection and flight tracking, and to determine the local time and time zone applicable to your duties. Background location, where granted, is used solely for those purposes.
Where the EU or UK General Data Protection Regulation applies, we process device location data on the basis of your consent. You may withdraw that permission at any time through your device settings. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal, and does not prevent you from using the remainder of the Services, although the accuracy of flight matching and tracking may be reduced.
We separately derive an approximate location from your IP address for security, fraud prevention and regional formatting purposes.
Analytics and Functional Information
We use analytics tools to understand how the Services are used and how we can improve them. This information may include log entries, diagnostics, crash reports, performance data and other analytics associated with devices tied to you, and may be collected to facilitate the provision of our Services. We also gather non-personally identifiable data about download and usage patterns. We use this information to maintain and improve the User experience.
Derived Information
We calculate new information from the data you give us. From your roster and flight records we derive block time, flight time, night time, day and night landings, time in seat, cumulative totals against regulatory limits, experience by aircraft type, and the statistics shown in Insights. From your usage we may draw inferences about which features are valuable to you so that we can prioritise development and tailor what we show you. Derived information may also include variations of the technical and usage information described above.
Personal Data from Third Parties
If you interact with Aviato through a third party — an app store, a calendar integration, or a connection who invites you — we may receive Personal Data from that third party where you provided it to them and consented to it being shared, or where the connection is otherwise authorised. For example, when a crew member invites you to follow their flights, we receive the contact detail they used to invite you.
We transmit flight identifiers, such as flight number, date and airport codes, to aviation data providers in order to obtain live status, aircraft and timing information. We do not transmit your name, email address or account details to such providers. The data returned in respect of the flight is thereafter associated with your records.
Where a third party has disclosed your Personal Data to us, or you have authorised us to connect to a third party, that third party remains the controller of the data it holds. You are advised to review the policies and privacy settings of any such third party.
Children's Data
Aviato does not knowingly collect or solicit Personal Data from children under 16 years of age. Persons under the age of 16 must not register for or otherwise use the Services, or submit any Personal Data to us. If we become aware that we have collected Personal Data from a child under the age of 16, we will delete such data as promptly as reasonably practicable. If you believe that a child under the age of 16 may have provided Personal Data to us, please contact us at hello@aviato.so.
How Aviato Uses Your Personal Data
We use your Personal Data to run the Services, to keep them working, and to improve and promote them.
Unless we specifically say otherwise, and as permitted by applicable law, we may use any of your Personal Data for the purposes described below.
For Account Registration, Access and Servicing
We may use your Personal Data:
- to create, provide access to, maintain, service, change or delete your account;
- to verify and authenticate your access for security purposes;
- to determine your subscription entitlements and apply the correct free or Pro feature set; and
- to resolve support questions and follow up with you about your experience.
To Provide the Core Services
We may use your Personal Data:
- to parse your roster files and build your upcoming schedule;
- to identify the specific flights on your schedule and subscribe them to live tracking;
- to enrich flights with real-world data such as departure and arrival times, gates, delays, aircraft type and registration;
- to promote completed flights into your logbook and calculate derived figures such as block time, night time and time in seat;
- to send the push notifications and alerts you have enabled, including delay, gate change, takeoff and landing alerts; and
- to operate flight sharing, including delivering invites and showing shared flights to the connections you have approved.
To Communicate with You
We may use your Personal Data:
- to send you service messages about your account, your subscription, security and changes to the Services;
- to send you marketing emails, product announcements and onboarding sequences, where you have consented or where permitted by law; and
- to respond to you when you contact us.
All marketing emails include an unsubscribe facility. Service messages are not optional for so long as you hold an account.
To Improve and Develop New Services
We may use your Personal Data:
- to understand which features are used and which are not, and to prioritise accordingly;
- to diagnose and remedy faults, including in roster parsing and flight tracking;
- to personalise your experience and recommend features that may be useful to you; and
- in combination with data from other Users, in aggregated form, to understand overall usage of the Services.
To Operate our Business
We may use your Personal Data to:
- fulfil your requests, provide technical and customer support, and protect the Services, including combating fraud and abuse;
- conduct research, alone or in combination with data from other Users — where we share such research outside Aviato we do so in aggregated or de-identified form, with safeguards designed to prevent re-identification; and
- maintain legal, tax and regulatory compliance.
Automated Processing
Certain features of the Services operate automatically. Our systems determine when a flight has departed, when it has landed, when an alert is to be issued, and what data is recorded in your logbook. Such features are assistive in nature. They do not produce legal effects concerning you, nor do they similarly significantly affect you, and we do not employ automated processing to make binding decisions in respect of you.
Automatically generated flight records are derived from third-party data and telemetry and may be incomplete or inaccurate. You remain solely responsible for the accuracy of your logbook. You may review, correct and override any automatically generated entry, and should do so before relying upon any such entry for any regulatory, licensing or employment purpose.
No Sale of your Personal Data
We do not sell your Personal Data, and we do not permit our Service Providers to use Personal Data we disclose to them for their own independent marketing purposes.
We do use advertising measurement technologies, including the Meta Pixel and Google Analytics, on our website. Under some laws — notably the California Privacy Rights Act — this may qualify as “sharing” Personal Data for cross-context behavioural advertising. You can opt out through our , through the controls described in the Cookies section below, or by contacting us.
How Aviato Shares Your Personal Data
We share your Personal Data only as described in this policy.
We may disclose or share your Personal Data:
- With Service Providers — vendors and contractors who need access to carry out work on our behalf, including cloud hosting, database, email delivery, push notification, analytics and payment providers. They are bound by contract to process the data only on our instructions.
- With connections you authorise — the people you invite to follow your flights see the flight information you have chosen to share with them. They do not see your logbook, your roster history or your account details.
- With flight data providers — we send flight identifiers only, never your identity, in order to retrieve status and aircraft information.
- To enforce our terms, or to protect the rights, property or safety of Aviato, our Users or the public.
- In connection with a merger, acquisition, financing, bankruptcy proceeding or sale of assets, or in anticipation of one, in which case the receiving party will be bound by this policy.
- To law enforcement, governmental entities or regulatory bodies in response to a valid legal request or judicial or regulatory process.
We will not disclose your roster or logbook to your airline, your employer, a regulator or a training department, save where we are compelled to do so by law, in which case we will notify you to the extent we are permitted to do so.
We may use and disclose de-identified or aggregated data that cannot reasonably be attributed to any individual for lawful business purposes, including analytics, benchmarking and industry insight. We will not attempt to re-identify such data.
Our principal Service Providers are:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | Singapore |
| DigitalOcean | Application and backend hosting | Singapore |
| Amplitude | Product analytics | United States |
| Google (Analytics) | Website and dashboard analytics | United States / EU |
| Meta Platforms | Advertising measurement and audiences | United States / EU |
| Mailchimp (Intuit) | Marketing email delivery | United States |
| Resend | Transactional email delivery | United States |
| OneSignal | Push notification delivery | United States |
| Apple, Google | App distribution and in-app subscription billing | United States |
| Stripe | Payment processing | United States / Singapore |
| Sentry | Error monitoring and crash reporting | United States / EU |
| Cloudflare | Content delivery, DNS and network security | Global edge network |
| Our aviation data providers | Flight status, position and aircraft data (flight identifiers only; no personal identifiers transmitted) | EU / United States |
Data Transfers
We use appropriate transfer mechanisms and protection measures.
Cuppa Pte Ltd is incorporated in Singapore. Your account data, roster files, flight records and logbook are stored on infrastructure located in Singapore. Certain ancillary Service Providers, being those engaged for analytics, advertising measurement, email delivery, push notification delivery, error monitoring, content delivery and payment processing, operate in the United States, the European Union and, in the case of our content delivery network, from edge locations worldwide, and limited categories of Personal Data are transferred to them for those purposes as described in this Privacy Policy. Some countries have data protection laws that differ from those of your country of residence.
Where we transfer Personal Data out of Singapore, we take steps to satisfy ourselves that the recipient is bound to provide a standard of protection comparable to that under the Personal Data Protection Act 2012 (“PDPA”), through contractual commitments.
For individuals in the European Union, the European Economic Area, the United Kingdom or Switzerland, transfers to countries outside your region are conducted under appropriate legal mechanisms, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, or under an adequacy decision covering the destination. You can request a copy of the relevant safeguards by contacting us.
Managing Your Data and Privacy
You can review and change your information, control marketing, and manage cookies.
Managing Your Account Data
You may view and amend your profile, correct or delete individual flight records, export your logbook, revoke a connection and delete your account through the Services. Deletion of your account is permanent and irreversible. You are advised to export your logbook prior to requesting deletion, as we will be unable to restore it thereafter.
Managing Marketing Communications From Us
If you no longer wish to receive marketing communications:
- click the unsubscribe link in any marketing email you have received from us;
- adjust your notification and communication preferences in your account settings; or
- Contact Us and we will action it.
You may disable push notifications within the Services or at device level. Disabling push notifications will prevent the delivery of flight alerts, which form a core function of the Services.
Notwithstanding any opt-out from marketing communications, we will continue to send mandatory service and transactional communications, including those relating to billing, security and material changes to the Services.
Cookies and Similar Tracking Technologies
We and certain authorised third parties use cookies, web beacons, pixels, device identifiers, tags, scripts, advertising identifiers and similar technologies (“Cookies”) to collect information when you use our Services. Cookies are small data files stored on your browser or device.
We use both session cookies, which expire when you close your browser, and persistent cookies, which remain until deleted. The types we use are:
- Essential Cookies — required to provide the Services you have requested, such as logging into the dashboard. Disabling these will make parts of the Services unavailable.
- Functional Cookies — record your settings and preferences, recognise you on return, and remember choices such as your Local/UTC display preference.
- Performance and Analytical Cookies — help us understand how the Services are accessed and used, how many people visit, which pages they view, and how our advertising performs.
- Advertising Cookies — set by the Meta Pixel and by Google, allowing us to measure whether visitors who arrive from our ads go on to sign up, and to build advertising audiences.
We use Cookies for the following purposes:
| Purpose | Reasoning |
|---|---|
| Processes | To make the Services function correctly. |
| Authentication, Security and Compliance | To recognise and authenticate you, prevent fraud, protect your data from unauthorised access, and meet legal requirements. |
| Preferences | To remember how you prefer to use the Services and to customise your experience. |
| Notifications | To let us surface options and messages relating to your use of the Services. |
| Advertising and Marketing | To make our marketing more relevant and to measure the effectiveness of our campaigns. |
| Analytics | To understand how our Services are used and how they are performing. |
Where required by law, we ask for your consent before setting analytics or advertising Cookies, and you can change your choice at any time using the on our site. You can also control Cookies through your browser or device settings, though some features may not work correctly if you block essential Cookies. On mobile, you can limit ad tracking through App Tracking Transparency on iOS or Ads settings on Android.
You can opt out of Google Analytics across all websites using Google's browser add-on at https://tools.google.com/dlpage/gaoptout. You can control how Meta uses your data through the Ad Preferences settings in your Meta account.
To learn more about Cookies generally, including how to manage and delete them, visit allaboutcookies.org.
Do Not Track
Aviato does not currently respond to browser “Do Not Track” signals, no uniform standard for such signals having been adopted.
Social Media and Third-Party Features
Our website and Services may include features delivered by social media platforms or other third parties. These features may collect your IP address, log which pages you visit and set a Cookie in order to function. Your interactions with them are governed by the privacy practices of the company providing them, not by Aviato.
Data Retention and Your Access Rights
You have rights over your Personal Data, and we will not discriminate against you for exercising them.
Data Retention
We retain your Personal Data in accordance with applicable law, based on the nature and sensitivity of the information, the purposes for which we process it, the length of our relationship with you, and our legal and contractual obligations.
| Data | Retention |
|---|---|
| Account and profile data | While your account is active |
| Roster files | While your account is active, so that we may reprocess and recover flights. Deleted within 90 days of account deletion or on request |
| Flight logs and flight records | While your account is active. Retained as a professional record and not deleted save at your request |
| Sharing and connection data | While the connection is active, plus 12 months following revocation for audit purposes |
| Analytics event data | Up to 14 months against a pseudonymous identifier |
| Marketing contact data | Until you unsubscribe, plus a suppression record so that we do not email you again |
| Billing, accounting and tax records | Up to 5 years, as required under Singapore law |
| Support correspondence | 2 years |
Upon deletion of your account, we will remove or anonymise your Personal Data within 30 days, save as otherwise specified in the table above, save where we are required to retain it for legal, tax or accounting purposes, and save in respect of backups, which are overwritten on a rolling 90-day cycle.
Aggregated and de-identified data that cannot reasonably be attributed to you may be retained indefinitely.
Your Rights
We respond to requests to exercise data protection rights in accordance with applicable law. Depending on where you live, your rights generally include:
- accessing, correcting, updating or requesting deletion of your Personal Data;
- objecting to or asking us to restrict our processing;
- requesting a portable copy of your data;
- choosing whether to receive marketing communications; and
- withdrawing your consent at any time, noting that withdrawal does not affect the lawfulness of processing carried out beforehand, and that it may mean we can no longer provide parts of the Services.
Requests may be submitted to hello@aviato.so and must contain sufficient information to enable us to verify your identity and your relationship with Aviato; confirmation of control of the email address registered to your account will ordinarily suffice. In certain circumstances we may be unable to comply with a request in full, including where we are unable to verify your identity, where compliance would prejudice the rights of others, or where we are required by law to retain the data. In such circumstances we will state our reasons and will comply to the fullest extent lawfully and practicably possible.
Your Obligations and Reliance on the Services
You are responsible for the accuracy of your records, and the Services are not a substitute for official sources.
Accuracy of records. The Services generate flight records automatically from roster files supplied by you and from data supplied by third-party aviation data providers. Such data may be incomplete, delayed or inaccurate, and the Services may fail to detect, or may incorrectly detect, the occurrence or timing of a flight. You are solely responsible for reviewing, verifying and correcting your logbook and flight records, and for retaining such independent records as may be required by your licensing authority, your employer or applicable law. We do not warrant that any record generated by the Services is accurate, complete or fit for submission to any regulatory, licensing or employment body.
Operational reliance. The Services are provided for informational and record-keeping purposes only. They are not an operational, dispatch, air traffic, flight-planning or safety-of-life system, and must not be relied upon for any operational decision, for compliance with flight time limitations, or for the purpose of determining fitness for duty. Notifications and alerts are delivered on a best-efforts basis through third-party networks and may be delayed, duplicated or not delivered at all.
Data you submit. You are responsible for the content of any file you upload to the Services and for ensuring that you are entitled to disclose it to us, including where it contains the Personal Data of other crew members or third parties. You must not upload material that you are prohibited from disclosing by your employer, by contract, or by applicable law.
Account security. You are responsible for maintaining the confidentiality of your account credentials and for all activity conducted through your account. You must notify us promptly at hello@aviato.so if you become aware of any unauthorised use of your account.
Nothing in this section limits any right you have under applicable data protection law, or any liability that cannot lawfully be excluded.
Information Security
We apply reasonable and appropriate measures to protect your Personal Data.
We use physical, administrative and technical measures to protect your Personal Data from unauthorised use or access, including:
- encryption in transit using TLS for all traffic between the apps and our servers;
- encryption at rest for uploaded roster files and stored data;
- password hashing — we never store your password in readable form;
- access controls restricting internal access to personnel who need it;
- logging and monitoring of access to production systems; and
- regular dependency and infrastructure updates.
The security of your Personal Data is also dependent upon you. You are responsible for maintaining the confidentiality of your password and must not disclose it to any person.
Transmission of information over the internet is not wholly secure, and we cannot guarantee the security of data transmitted to us; any such transmission is at your own risk. In the event of a data breach that is likely to result in significant harm to affected individuals, we will notify you, the Personal Data Protection Commission of Singapore and any other competent regulator, within the periods prescribed by applicable law. Where the EU or UK General Data Protection Regulation applies, we will notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach, and will notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
Controlling Country and Regional Data Privacy Considerations
Aviato is based in Singapore. Additional rights may apply depending on where you live.
Singapore Data Subject Rights (PDPA)
Cuppa Pte Ltd is subject to the Personal Data Protection Act 2012. We collect, use and disclose Personal Data with your consent, or where the PDPA permits us to do so without consent, and only for purposes that a reasonable person would consider appropriate in the circumstances.
You have the right to:
- request access to the Personal Data we hold about you and to information about how it has been used or disclosed in the year before your request;
- request correction of Personal Data that is inaccurate or incomplete; and
- withdraw consent to our collection, use or disclosure of your Personal Data, on reasonable notice. We will inform you of the likely consequences of withdrawal; in most cases, withdrawal will result in our being unable to continue to provide the Services.
We will respond to access and correction requests within 30 days or, where we are unable to do so, will notify you of the time within which a response will be provided. A reasonable fee may be charged in respect of access requests, and we will notify you of any such fee before proceeding.
Our Data Protection Officer can be reached at hello@aviato.so or at the postal address below. If you are not satisfied with our response, you may contact the Personal Data Protection Commission of Singapore at www.pdpc.gov.sg.
EU, UK and Swiss Data Subject Rights
If you are in the EU, EEA, UK or Switzerland, you have additional rights under the EU or UK General Data Protection Regulation (“GDPR”). We process your Personal Data only where we have a lawful basis:
Contractual necessity. We process the following categories because we need to in order to provide the Services under our agreement with you. Without them, you will not be able to use some or all of the Services:
- Profile or Contact Data
- Professional or Employment-Related Data
- Roster and Schedule Data
- Flight Log Data
- Sharing and Connection Data
- Payment Data
Legitimate interests. We process the following categories where we believe it furthers our legitimate interests or those of others:
- Device/IP Data
- Web and Product Analytics
- Marketing and Communication Data
- Other Identifying Information that you Voluntarily Choose to Provide
Examples of these legitimate interests include providing, securing and improving the Services; diagnosing faults; marketing the Services; corresponding with you; meeting legal requirements and enforcing our terms; and completing corporate transactions.
Consent. We rely on consent in respect of device Location Data, analytics and advertising Cookies, push notifications, and marketing emails in those jurisdictions that require it. Reliance on consent will be made clear at the point of collection, and consent may be withdrawn at any time.
Other grounds. We may also process Personal Data to comply with a legal obligation, to protect vital interests, or for a task carried out in the public interest.
Where we rely on legitimate interests, we have carried out an assessment balancing those interests against your rights and freedoms. You may request further information regarding that assessment by contacting us.
Your rights include access, rectification, erasure, restriction, objection (including to direct marketing), portability, and withdrawal of consent. To submit a request, email hello@aviato.so with the subject line “GDPR Request: [nature of request]”.
You also have the right to lodge a complaint with a supervisory authority. In the UK this is the Information Commissioner's Office. In the EEA, it is the supervisory authority in your country of residence, your place of work, or where the alleged infringement occurred.
Data processing agreement. Where you use the Services in a capacity in which we act as processor on your behalf, or where you require contractual data protection commitments, our data processing agreement, incorporating the applicable Standard Contractual Clauses, is available on request.
United States Data Subject Rights
We have modelled the following on the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), although other state laws may apply. Terms defined in the CCPA carry the same meaning here, and “Personal Data” and “personal information” are used interchangeably in this section.
In the preceding twelve months, we have disclosed the following categories of personal information for a business purpose: identifiers including name and email address; professional or employment-related information; commercial information relating to your subscription; internet or other network activity, including usage of the Services and interaction with our emails and advertising; geolocation data, being device location where permission has been granted and approximate location derived from IP address; and inferences drawn from the above.
You have the right to:
- know what personal information we collect, the sources it comes from, our purpose for collecting it, and the categories of third parties with whom we share it;
- request the specific pieces of personal information we hold about you, in a portable format;
- request correction or deletion of your personal information, unless we are legally required to retain it;
- opt out of the “sale” or “sharing” of personal information, including for cross-context behavioural advertising; and
- appeal a decision we make about your request, where applicable law provides for this.
We will respond to verified requests within 45 days. We do not sell personal information. As noted above, our use of advertising measurement technologies may constitute “sharing” under California law, and you can opt out through our .
We do not knowingly collect or process “sensitive personal information” as defined by the CPRA. To the extent any is inadvertently collected, we do not use or disclose it except as permitted by law.
We will not discriminate against you for exercising any of these rights.
Changes to This Privacy Policy
We may amend this Privacy Policy, and will give notice of material changes.
We may amend or update this Privacy Policy at any time. Amendments take effect upon publication to our website bearing the revised effective date, or upon being otherwise notified to you through the Services. Where we consider the amendments to be material, we will endeavour to give notice not less than thirty (30) days before they take effect.
Contact Us
If you have questions or concerns about this Privacy Policy, our privacy practices, or your choices regarding your Personal Data:
Email hello@aviato.so. This is the correct address for any data protection or privacy request and will result in the fastest response. Requests should be marked for the attention of the Data Protection Officer.
Direct mail to:
Cuppa Pte Ltd133 New Bridge Road
#19-09/10 Chinatown Point
Singapore 059413
Attn: Data Protection Officer
Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of the Republic of Singapore, without prejudice to any mandatory right or protection available to you under the laws of your country of residence. If any provision of this Privacy Policy is held to be invalid or unenforceable, that provision shall be severed and the remaining provisions shall continue in full force and effect.