Privacy Policy

Effective 1 October 2026 · All legal documents

Draft. This document is awaiting legal review, and details in [square brackets] are still to be confirmed.

1. Who we are

GHSLink is provided by [COMPANY LEGAL NAME], [REGISTERED ADDRESS] (company number [COMPANY NUMBER]). Contact us about privacy at privacy@ghslink.com.

2. Our two roles

GHSLink handles personal data in two different capacities, and who you should contact depends on which applies:

  • As a controller, for our own purposes: people who sign up and use GHSLink accounts, visitors to our websites, our customers' billing contacts, and people who contact us. This policy explains that processing.
  • As a processor, on behalf of our customers: the information a customer puts into its GHSLink workspace, such as details of its own clients, passengers, crew, drivers and staff, and messages from a mailbox it connects. The customer (for example the FBO, operator or transport company you dealt with) decides why and how that data is used, and its privacy notice applies. We process it only on its instructions, under our Data Processing Agreement. If you ask us about such data, we will pass your request to the customer.

3. What we collect

  • Account data: name, work email, password (stored only as a secure hash), organisation, role and the workspaces you can use.
  • Usage and device data: IP address, browser and device type, pages visited, sign-in times and security events. Our website analytics are cookie-free and aggregate.
  • Billing data: company name, billing contact names and emails, VAT number, invoices and payment records. Card details, if any, are handled by the payment provider, not stored by us.
  • Communications: messages you send us and our replies.
  • Approximate location: if a driver allows it on a phone, the device location is used once to show local road weather. It is not stored.
  • Customer Data: whatever a customer puts into its workspace, processed as described in section 2.

We do not ask for special category data (such as health information) and ask customers not to put it into GHSLink.

4. Why we use it, and our legal basis

PurposeDataLegal basis (GDPR art. 6)
Create and run your account; provide the ServicesAccount, usageContract (6(1)(b)), or our legitimate interest in providing the Services to your employer (6(1)(f))
Keep GHSLink secure; detect and prevent fraud and misuseAccount, usage, security logsLegitimate interests (6(1)(f))
Send service messages (sign-up, password reset, invoices, changes to terms)Account, billingContract (6(1)(b)); legitimate interests (6(1)(f))
Bill customers and keep accounting recordsBillingContract (6(1)(b)); legal obligation (6(1)(c))
Record acceptance of our TermsAccountLegitimate interests (6(1)(f)); legal claims
Improve GHSLink using aggregated usage statisticsUsage (aggregated)Legitimate interests (6(1)(f))
Answer questions and privacy requestsCommunicationsLegitimate interests (6(1)(f)); legal obligation (6(1)(c))
Tell business contacts about GHSLink productsName, work emailLegitimate interests (6(1)(f)), or consent where the law requires it. You can opt out at any time.

Where we rely on legitimate interests, we have weighed them against your rights; you can ask us for details and object at any time (section 8). We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.

5. Who receives it

  • Your organisation: administrators of the workspaces you use can see your account details and your activity in their workspace.
  • Other organisations you work with through GHSLink: for example, an operator requesting a service sees the FBO's confirmation, and the FBO sees the request and the requester's contact details.
  • Our sub-processors, who host and run the Services for us under contract. They are listed on the Sub-processors page.
  • Professional advisers, auditors, insurers and, if the business is sold or reorganised, the buyer, under confidentiality.
  • Authorities, where the law requires it or to protect the rights and safety of people or the Services.

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

6. International transfers

Some of our providers are outside the European Economic Area and the United Kingdom, mainly in the United States. Where data is transferred there, we rely on an adequacy decision (including the EU–US Data Privacy Framework and its UK extension, where the provider is certified) or on the European Commission's Standard Contractual Clauses with the UK Addendum, together with supplementary measures such as encryption in transit and at rest. You can ask us for a copy of the safeguards.

7. How long we keep it

DataHow longWhy
Account details (name, email, sign-in records, roles)While the account is open, then deleted or anonymised within 30 days of closureTo provide the account and keep it secure
Records of which Terms a person accepted, and when6 years after the account closesTo show what was agreed if a claim is made (limitation periods)
Workspace records: trips, legs, visits, services, bookings, transport jobs, contacts, tasksCustomer-controlled while the workspace is open; deleted within 90 days after it closes (30 days to export, then 60 to delete)To provide the Services to the customer
Messages and attachments synced from a mailbox the customer connects24 months after the last message in a conversation by default; removed within 30 days of the mailbox being disconnectedTo show the customer its correspondence alongside the work it relates to
Baggage scans (bag tag number, who scanned it and when)90 days after the flight by default, or longer if the customer asks, to support baggage claimsTo reconcile loaded and collected baggage
Invoices, credit notes, payments and billing contacts6 years after the end of the financial year they relate toTax and company law record-keeping
Privacy requests and our responses3 years after the request is closedTo show we handled requests as the law requires
Security and access logs held by our hosting providersUp to 90 days, on each provider's standard cycleTo detect, investigate and prevent misuse
Database backupsUp to 30 days on a rolling cycle; deleted data leaves backups as they expireTo recover from failures
Approximate device location (drivers, for the local weather panel)Not stored: used once to look up the weather and discardedTo show road conditions where the driver is

8. Your rights

Depending on where you are, you have the right to:

  • access the personal data we hold about you and get a copy;
  • have inaccurate data corrected;
  • have data erased, where there is no good reason for us to keep it;
  • restrict or object to our processing, including objecting at any time to direct marketing and to processing based on legitimate interests;
  • receive data you gave us in a portable format;
  • withdraw consent, where we rely on it, without affecting what we did before.

Email privacy@ghslink.com to use these rights. We will reply within one month (we may extend that by two further months for complex requests, and will tell you if so), and may need to confirm your identity first. There is normally no charge.

You can complain to a data protection authority, in particular where you live or work or where you think the law was broken. Our lead authority is [LEAD SUPERVISORY AUTHORITY, e.g. the Data Protection Commission (Ireland)]. We would appreciate the chance to put things right first.

9. Additional information by region

United Kingdom: references to the GDPR include the UK GDPR and the Data Protection Act 2018. You can complain to the Information Commissioner's Office (ico.org.uk).

California and other US states with privacy laws: in the last 12 months we collected the categories of personal information described in section 3 (identifiers, commercial information, internet activity, approximate geolocation, professional information) for the business purposes in section 4, and disclosed them to the service providers in section 5. We do not sell or share personal information, and we do not use sensitive personal information to infer characteristics. You have the right to know, delete and correct personal information and not to be discriminated against for using these rights; an authorised agent may make a request for you. Use the contact details in section 1.

Elsewhere: we apply the protections in this policy to everyone, and will comply with any additional rights your local law gives you.

10. Security

We protect personal data with encryption in transit and at rest, access controls that separate each customer's data at the database level, least-privilege access for our own staff, and regular security reviews. No system is perfectly secure; if a breach puts your rights at high risk we will tell you without undue delay.

11. Children

GHSLink is a business service and is not directed at children. Accounts are for people aged 18 or over.

12. Changes to this policy

We will post any changes here with a new effective date, and tell account holders by email or in the Services before significant changes take effect.

Privacy Policy | GHSLink