Privacy notice
Effective 20 July 2026 · Version 2026-07-20.3
AERLYO uses the information needed to create accounts, process aviation requests, verify marketplace roles, operate the live workflow and protect the service. Passenger accounts are free. We do not sell personal data or use it for cross-context behavioral advertising. Public ADS-B positions are informational and are not proof that an aircraft is available.
1. Who controls your data
Thoth Group LLC, a Delaware limited liability company, operates AERLYO and is the controller of personal data processed through aerlyo.com and the AERLYO applications, except where an identified licensed operator or other participant acts as an independent controller for its own legal, safety, crew, passenger or transportation records.
Privacy requests may be sent to privacy@nawaeurope.com. Commercial agreements may identify additional contact and registered-office details. Where EU, UK or other local law requires a representative, the applicable representative will be identified before AERLYO actively offers commercial service in that territory.
1A. Controller, processor and participant roles
Thoth generally acts as an independent controller for account identity, marketplace matching, memberships, security, fraud prevention, audit, support, service-fee and legal-compliance records. A licensed operator generally acts as an independent controller for passenger acceptance, manifests, carriage, safety, crew, permits, border, operational and incident records. An aircraft owner, travel agent, ground-transfer provider, insurer, payment provider or identity provider may be an independent controller for its own regulated service and legal duties.
Where a signed agreement expressly appoints Thoth to process personal data only on a business customer’s documented instructions, the parties’ data-processing addendum controls that processing. Nothing in this notice transfers an operator’s operational control or its independent aviation duties to Thoth. Participants must give their own required notices and may not use marketplace data for unrelated marketing, profiling, resale or circumvention.
2. Scope
This notice applies to visitors, passengers, travel agents and their authorized client contacts, aircraft owners, licensed operators, pilots, operations workers, administrators and business contacts using AERLYO. It does not replace an air operator’s passenger privacy notice, government border or security notices, airport notices, or the terms of independent payment, transfer, insurance, identity-verification, mapping and aviation-data providers.
3. Personal data we process
Sources
We receive data from you; your authorized travel agent or organization; authorized marketplace participants; transfer and insurance partners when selected; hosted payment, security, sanctions, communications and identity providers; document issuers or registries where verification is permitted; licensed aviation-data providers; public airport directories; ADS-B contributors; and authorities or partners where permitted by law. An agent must have lawful authority to provide client data and must give the client the required notices.
4. Live airspace and aircraft location
The public radar displays fresh ADS-B observations provided by adsb.lol contributors under the Open Data Commons Open Database License 1.0. The public AERLYO response is minimized to a daily rotating aircraft identifier, broadcast callsign, aircraft type, position, altitude, speed, track, observation age and distance. Public responses do not include registration. Provider responses are normally cached for ten seconds; a prior response may be used for up to 120 seconds during a temporary upstream interruption and is labeled as reconnecting.
For verified aircraft that an owner or operator has explicitly opted into AERLYO matching, a contracted provider such as Flightradar24 may later provide position data under a separate commercial license. Location data only ranks candidates. It does not prove commercial availability, airworthiness, crew readiness, price or authority to operate.
5. Purposes and legal bases
AERLYO does not make a solely automated decision that legally confirms a flight, rejects a professional license or otherwise produces a similarly significant effect. Matching is a recommendation; authorized humans make commercial and operational decisions.
5A. Matching, document screening and automated assistance
AERLYO uses rules and scoring to find eligible supply, order time-limited offers, detect duplicate transactions, protect accounts and prescreen professional documents. Relevant matching factors may include airport or fresh opted-in aircraft position, distance, capacity, aircraft/operator relationship, approval status, availability and current trip commitment. Sponsorship is labeled and is not permitted to bypass eligibility, distance, safety, crew or release controls.
Document screening may inspect file integrity, readability, metadata, expiry, internal consistency, duplicate patterns and configured sanctions or issuer signals. A screening result is an administrative aid—not authentication by the issuer and not an aviation approval. A human administrator reviews required evidence and can approve, reject or request more information. An adverse professional decision must not be based solely on generative AI or a document score.
Where applicable law grants a right concerning a solely automated decision with legal or similarly significant effect, AERLYO provides meaningful information about the principal factors, a way to express the individual’s view and a route to human review. At present, aircraft dispatch, professional activation and operational flight release require authorized human actions.
8. International transfers
AERLYO is operated by a U.S. company and may process data in the United States and other countries where participants or processors are located. Those countries may provide different data-protection rules. Where required, Thoth Group LLC will use an adequacy decision, the European Commission’s standard contractual clauses, the UK addendum or international data-transfer agreement, contractual safeguards, transfer-risk assessments and supplementary technical or organizational measures, or another lawful mechanism. A copy or summary of the applicable safeguard may be requested where law provides. Mandatory rights in your home jurisdiction remain available.
9. Retention
We keep personal data only as long as reasonably necessary for the stated purpose and applicable law. The default schedule is: public ADS-B cache, normally 10 seconds and no more than 120 seconds as a resilience fallback; abandoned registration or incomplete request data, up to 90 days; routine security and access logs, up to 12 months unless an incident requires longer; account data, while active and generally up to 24 months after closure; trip, agreement, quote, payment, invoice, commission and audit records, generally seven years after the relevant transaction; professional verification evidence, for the relationship and generally up to five years afterward where legally justified; and privacy, complaint or legal-request records, generally three years after closure. A shorter local limit controls where required. Data may be isolated and preserved longer for a legal hold, chargeback, accident, safety report, fraud, tax, sanctions, aviation or regulatory obligation, then securely deleted, anonymized or rendered inaccessible.
10. Security and incident response
Controls include HTTPS, one-way password hashing, secure HttpOnly session cookies, CSRF protection, least-privilege role authorization, rate limiting, encrypted professional-document storage, integrity hashes, audit and domain events, private server-side storage, credential separation and data minimization. Payment credentials are write-only in administration and secret material is encrypted at rest. No system is perfectly secure, and this description is not a warranty against every incident. Users must maintain unique passwords, restrict organizational access and report suspected unauthorized access promptly.
We investigate suspected personal-data breaches, contain and remediate them, preserve appropriate evidence and notify affected people or authorities within the time required by applicable law where the notification threshold is met. Security reports should be sent to security@nawaeurope.com without accessing, downloading or disclosing more data than necessary.
11. Your choices and rights
Depending on your location and subject to lawful exceptions, you may ask to access or know, correct, delete, restrict or receive a portable copy of personal data; object to or opt out of certain processing; withdraw consent; appeal a refusal; and receive equal service without unlawful discrimination. You may also opt out of targeted advertising, sale, certain profiling or use of sensitive data where those practices exist. AERLYO currently does not sell personal data, run targeted advertising or make a qualifying solely automated decision.
An authenticated user can start permanent account deletion inside an AERLYO service from Account → Privacy and legal → Request account deletion. The request closes sign-in access and enters a controlled deletion review. Eligible account data is erased or anonymized; trip, safety, tax, fraud, sanctions, professional-qualification, claim and audit records remain protected only where and for as long as applicable law requires. If a travel agent or organization supplied your information and you do not have an account, contact us with the relevant agent, trip or agency reference.
You may send a request to privacy@nawaeurope.com from the account email and state your jurisdiction and request. An authorized agent may submit a request where law permits. We verify identity and authority proportionately, may limit information that would expose another person or security control, and may retain information required by law. We respond within the locally required period; Delaware requests are generally answered within 45 days. A denial will explain the reason and any appeal route. We do not require sensitive identity evidence unless reasonably necessary, and verification evidence is used only for the request.
12. Regional disclosures
European Economic Area and United Kingdom
GDPR or UK GDPR may apply when services are offered to people in those territories even though Thoth is a U.S. company. You may exercise rights to access, rectify, erase, restrict, port and object; withdraw consent; and complain to the supervisory authority where you live, work or believe an infringement occurred. Contract, legitimate interests, legal obligation, consent and vital interests are used as described above. You may object to legitimate-interest processing based on your circumstances. Matching does not replace human commercial or aviation decision-making. Any required EU or UK representative and data-protection contact must be appointed and published before active launch into that territory.
California
California residents may request to know/access, correct or delete covered personal information and may opt out of sale, sharing for cross-context behavioral advertising, or certain uses of sensitive personal information, subject to the CCPA’s scope and exceptions. The categories described in section 3 are collected for the business purposes in section 5 and disclosed to the participant and service-provider categories in section 7. AERLYO does not sell or share personal information for cross-context behavioral advertising and offers no financial incentive for personal data. We do not knowingly sell or share data of consumers under 16.
Delaware and other U.S. states
Where the Delaware Personal Data Privacy Act or a similar state law applies, residents may access, correct, delete and obtain portable data and opt out of sale, targeted advertising and qualifying profiling. A denied request may be appealed by replying to the decision. After a Delaware internal appeal, a complaint may be sent to the Delaware Department of Justice. State-specific exceptions, authentication and response periods apply.
Brazil, Canada and other jurisdictions
Where Brazil’s LGPD, Canadian private-sector privacy law or another local regime applies, we honor the applicable access, correction, deletion, portability, consent-withdrawal, information and complaint rights and use the locally recognized legal basis or accountability mechanism. A local representative, officer or regulator contact will be published where required before active market launch. Mandatory rights cannot be waived by contract.
13. Children
AERLYO accounts and trip requests are intended for adults aged 18 or older. The service is not directed to children under 13 and we do not knowingly collect their personal data. A parent or guardian who believes a child submitted data should contact us for review and deletion. Passenger details for minors may be processed later only through an adult account and the responsible licensed operator’s controlled travel process.
14. Changes
We may update this notice as the service, providers or law changes. The effective date and version will change, and material changes will be presented in the service or by another appropriate notice before they take effect where required.
15. Contact
Thoth Group LLC
Delaware, United States
Operator of AERLYO
privacy@nawaeurope.com
Security reports: security@nawaeurope.com. General legal notices: legal@nawaeurope.com.