AERLYO
PrivacyTerms / CGUCopyrightReturn to AERLYO
LEGAL / PRIVACYPrivacy noticeControllerController rolesData we processPurposes and legal basesAutomation and AISharingRetentionYour rightsRegional noticesContact
AERLYO LEGAL / THOTH GROUP LLC

Privacy notice

Effective 20 July 2026 · Version 2026-07-20.3

In plain language

AERLYO uses the information needed to create accounts, process aviation requests, verify marketplace roles, operate the live workflow and protect the service. Passenger accounts are free. We do not sell personal data or use it for cross-context behavioral advertising. Public ADS-B positions are informational and are not proof that an aircraft is available.

1. Who controls your data

Thoth Group LLC, a Delaware limited liability company, operates AERLYO and is the controller of personal data processed through aerlyo.com and the AERLYO applications, except where an identified licensed operator or other participant acts as an independent controller for its own legal, safety, crew, passenger or transportation records.

Privacy requests may be sent to privacy@nawaeurope.com. Commercial agreements may identify additional contact and registered-office details. Where EU, UK or other local law requires a representative, the applicable representative will be identified before AERLYO actively offers commercial service in that territory.

1A. Controller, processor and participant roles

Thoth generally acts as an independent controller for account identity, marketplace matching, memberships, security, fraud prevention, audit, support, service-fee and legal-compliance records. A licensed operator generally acts as an independent controller for passenger acceptance, manifests, carriage, safety, crew, permits, border, operational and incident records. An aircraft owner, travel agent, ground-transfer provider, insurer, payment provider or identity provider may be an independent controller for its own regulated service and legal duties.

Where a signed agreement expressly appoints Thoth to process personal data only on a business customer’s documented instructions, the parties’ data-processing addendum controls that processing. Nothing in this notice transfers an operator’s operational control or its independent aviation duties to Thoth. Participants must give their own required notices and may not use marketplace data for unrelated marketing, profiling, resale or circumvention.

2. Scope

This notice applies to visitors, passengers, travel agents and their authorized client contacts, aircraft owners, licensed operators, pilots, operations workers, administrators and business contacts using AERLYO. It does not replace an air operator’s passenger privacy notice, government border or security notices, airport notices, or the terms of independent payment, transfer, insurance, identity-verification, mapping and aviation-data providers.

3. Personal data we process

Account and contactName, email, country, account role, organization, account status, password hash, verification status, login timestamps and communication preferences.
Trip and passenger requestOrigin, destination, timing, number of travelers, lead-traveler name and email when submitted by an authorized travel agent, agency reference, whole-aircraft or seat preference, service level, request status, messages and workflow history. Passport, health or special-assistance data is not collected in the ordinary passenger request form; an operator may lawfully request it later under its own controlled process.
Professional, agency and aircraftOperator, owner or travel-agency organization; responsible persons and beneficial ownership; government identity evidence; agency, seller-of-travel or aviation registrations; accreditation; client authority and money safeguards; professional liability; pilot qualifications and medical/recency evidence; aircraft registration, ownership or control, maintenance, airworthiness, insurance, base airport, seats, verification and tracking consent. Uploaded evidence, issuer, document number, expiry, integrity hash, automated findings and human review history are stored in protected systems.
Membership and conciergePlan, service level, preferences, transfer- or insurance-coordination requests, agreement version and hash, acceptance time, renewal and membership status. A third-party transfer provider or insurer may request additional data directly under its own notice.
CommercialQuotes, taxes and fees, currency, commission basis and rate, invoices, subscription records, hosted-checkout references, authorization/capture/refund/chargeback status and transaction evidence. Card numbers and security codes must be entered only with the payment provider and are not intended to reach AERLYO servers.
Location and aviation dataAirport choices, optional device location used to suggest nearby airports, aircraft base, opted-in licensed live aircraft position, and minimized public ADS-B observations. Precise device location is requested only when the user invokes a location feature and grants permission.
Device, fraud and securityIP address, secure session cookie, CSRF token, browser and request metadata, rate-limit events, authentication events, device or account relationships, document-integrity signals, sanctions/risk indicators, immutable domain events and audit records.
Support, safety and legalQuestions, complaints, incident or safety reports, rights requests, correspondence, evidence, investigation, legal-hold and resolution records.

Sources

We receive data from you; your authorized travel agent or organization; authorized marketplace participants; transfer and insurance partners when selected; hosted payment, security, sanctions, communications and identity providers; document issuers or registries where verification is permitted; licensed aviation-data providers; public airport directories; ADS-B contributors; and authorities or partners where permitted by law. An agent must have lawful authority to provide client data and must give the client the required notices.

4. Live airspace and aircraft location

The public radar displays fresh ADS-B observations provided by adsb.lol contributors under the Open Data Commons Open Database License 1.0. The public AERLYO response is minimized to a daily rotating aircraft identifier, broadcast callsign, aircraft type, position, altitude, speed, track, observation age and distance. Public responses do not include registration. Provider responses are normally cached for ten seconds; a prior response may be used for up to 120 seconds during a temporary upstream interruption and is labeled as reconnecting.

For verified aircraft that an owner or operator has explicitly opted into AERLYO matching, a contracted provider such as Flightradar24 may later provide position data under a separate commercial license. Location data only ranks candidates. It does not prove commercial availability, airworthiness, crew readiness, price or authority to operate.

5. Purposes and legal bases

Provide the service and contractCreate accounts; record requests; show role-specific workspaces; coordinate operator and pilot decisions; administer memberships; respond to support.
Legitimate interestsSecure the platform; prevent fraud; maintain auditability; improve usability; rank relevant verified supply; establish or defend legal claims. We balance these interests against individual rights.
Legal obligationsTax, accounting, sanctions, consumer, privacy, aviation, law-enforcement and record-preservation duties that apply to Thoth Group LLC or a participating operator.
ConsentOpt-in aircraft matching, optional communications, precise device location, sensitive data and other processing where the law requires consent. Consent may be withdrawn prospectively.
Vital interestsLimited processing needed to protect life or physical safety in an emergency.

AERLYO does not make a solely automated decision that legally confirms a flight, rejects a professional license or otherwise produces a similarly significant effect. Matching is a recommendation; authorized humans make commercial and operational decisions.

5A. Matching, document screening and automated assistance

AERLYO uses rules and scoring to find eligible supply, order time-limited offers, detect duplicate transactions, protect accounts and prescreen professional documents. Relevant matching factors may include airport or fresh opted-in aircraft position, distance, capacity, aircraft/operator relationship, approval status, availability and current trip commitment. Sponsorship is labeled and is not permitted to bypass eligibility, distance, safety, crew or release controls.

Document screening may inspect file integrity, readability, metadata, expiry, internal consistency, duplicate patterns and configured sanctions or issuer signals. A screening result is an administrative aid—not authentication by the issuer and not an aviation approval. A human administrator reviews required evidence and can approve, reject or request more information. An adverse professional decision must not be based solely on generative AI or a document score.

Where applicable law grants a right concerning a solely automated decision with legal or similarly significant effect, AERLYO provides meaningful information about the principal factors, a way to express the individual’s view and a route to human review. At present, aircraft dispatch, professional activation and operational flight release require authorized human actions.

6. Cookies, SDKs and device permissions

The current service uses an essential secure session cookie to keep you signed in and protect state-changing requests. It does not use advertising cookies or third-party behavioral analytics. If non-essential analytics, advertising or cross-app tracking is introduced, it will be disabled until the required notice, consent and platform permission are obtained. Airport-near-you functionality requests device location only after your action and browser or operating-system permission; coordinates are used to calculate nearby airports and are not stored as trip data unless you choose an airport and create a request. Browser or device controls can block cookies, notifications or location, but the related feature may then be unavailable.

7. When data is shared

  • Authorized marketplace participants: the passenger or authorized travel agent, licensed operator, assigned pilot, aircraft owner and authorized control staff receive only the information needed for their role and trip stage.
  • Transfer and insurance options: when the member or agent requests coordination, the minimum necessary contact and journey information may be sent to selected ground-transport or insurance providers so they can determine availability, eligibility or provide separate terms. No coverage or transfer is created until the user enters the provider’s contract.
  • Processors: hosting, infrastructure, security, communications, support, identity verification and future hosted payment providers process data under contract and instructions.
  • Aviation and airport data providers: limited route, aircraft or location queries may be sent where needed under their terms.
  • Authorities and safety: data may be disclosed to comply with law, lawful process, sanctions, aviation or security obligations, or to protect rights and safety.
  • Corporate transactions: data may transfer in a merger, financing, reorganization or sale subject to appropriate confidentiality and notice.
  • Professional advisers: auditors, insurers and legal or compliance advisers receive data when necessary and protected.

Thoth Group LLC does not sell personal data and does not share it for cross-context behavioral advertising. If that practice changes, we will update this notice and provide any required opt-out before the change applies.

8. International transfers

AERLYO is operated by a U.S. company and may process data in the United States and other countries where participants or processors are located. Those countries may provide different data-protection rules. Where required, Thoth Group LLC will use an adequacy decision, the European Commission’s standard contractual clauses, the UK addendum or international data-transfer agreement, contractual safeguards, transfer-risk assessments and supplementary technical or organizational measures, or another lawful mechanism. A copy or summary of the applicable safeguard may be requested where law provides. Mandatory rights in your home jurisdiction remain available.

9. Retention

We keep personal data only as long as reasonably necessary for the stated purpose and applicable law. The default schedule is: public ADS-B cache, normally 10 seconds and no more than 120 seconds as a resilience fallback; abandoned registration or incomplete request data, up to 90 days; routine security and access logs, up to 12 months unless an incident requires longer; account data, while active and generally up to 24 months after closure; trip, agreement, quote, payment, invoice, commission and audit records, generally seven years after the relevant transaction; professional verification evidence, for the relationship and generally up to five years afterward where legally justified; and privacy, complaint or legal-request records, generally three years after closure. A shorter local limit controls where required. Data may be isolated and preserved longer for a legal hold, chargeback, accident, safety report, fraud, tax, sanctions, aviation or regulatory obligation, then securely deleted, anonymized or rendered inaccessible.

10. Security and incident response

Controls include HTTPS, one-way password hashing, secure HttpOnly session cookies, CSRF protection, least-privilege role authorization, rate limiting, encrypted professional-document storage, integrity hashes, audit and domain events, private server-side storage, credential separation and data minimization. Payment credentials are write-only in administration and secret material is encrypted at rest. No system is perfectly secure, and this description is not a warranty against every incident. Users must maintain unique passwords, restrict organizational access and report suspected unauthorized access promptly.

We investigate suspected personal-data breaches, contain and remediate them, preserve appropriate evidence and notify affected people or authorities within the time required by applicable law where the notification threshold is met. Security reports should be sent to security@nawaeurope.com without accessing, downloading or disclosing more data than necessary.

11. Your choices and rights

Depending on your location and subject to lawful exceptions, you may ask to access or know, correct, delete, restrict or receive a portable copy of personal data; object to or opt out of certain processing; withdraw consent; appeal a refusal; and receive equal service without unlawful discrimination. You may also opt out of targeted advertising, sale, certain profiling or use of sensitive data where those practices exist. AERLYO currently does not sell personal data, run targeted advertising or make a qualifying solely automated decision.

An authenticated user can start permanent account deletion inside an AERLYO service from Account → Privacy and legal → Request account deletion. The request closes sign-in access and enters a controlled deletion review. Eligible account data is erased or anonymized; trip, safety, tax, fraud, sanctions, professional-qualification, claim and audit records remain protected only where and for as long as applicable law requires. If a travel agent or organization supplied your information and you do not have an account, contact us with the relevant agent, trip or agency reference.

You may send a request to privacy@nawaeurope.com from the account email and state your jurisdiction and request. An authorized agent may submit a request where law permits. We verify identity and authority proportionately, may limit information that would expose another person or security control, and may retain information required by law. We respond within the locally required period; Delaware requests are generally answered within 45 days. A denial will explain the reason and any appeal route. We do not require sensitive identity evidence unless reasonably necessary, and verification evidence is used only for the request.

12. Regional disclosures

European Economic Area and United Kingdom

GDPR or UK GDPR may apply when services are offered to people in those territories even though Thoth is a U.S. company. You may exercise rights to access, rectify, erase, restrict, port and object; withdraw consent; and complain to the supervisory authority where you live, work or believe an infringement occurred. Contract, legitimate interests, legal obligation, consent and vital interests are used as described above. You may object to legitimate-interest processing based on your circumstances. Matching does not replace human commercial or aviation decision-making. Any required EU or UK representative and data-protection contact must be appointed and published before active launch into that territory.

California

California residents may request to know/access, correct or delete covered personal information and may opt out of sale, sharing for cross-context behavioral advertising, or certain uses of sensitive personal information, subject to the CCPA’s scope and exceptions. The categories described in section 3 are collected for the business purposes in section 5 and disclosed to the participant and service-provider categories in section 7. AERLYO does not sell or share personal information for cross-context behavioral advertising and offers no financial incentive for personal data. We do not knowingly sell or share data of consumers under 16.

Delaware and other U.S. states

Where the Delaware Personal Data Privacy Act or a similar state law applies, residents may access, correct, delete and obtain portable data and opt out of sale, targeted advertising and qualifying profiling. A denied request may be appealed by replying to the decision. After a Delaware internal appeal, a complaint may be sent to the Delaware Department of Justice. State-specific exceptions, authentication and response periods apply.

Brazil, Canada and other jurisdictions

Where Brazil’s LGPD, Canadian private-sector privacy law or another local regime applies, we honor the applicable access, correction, deletion, portability, consent-withdrawal, information and complaint rights and use the locally recognized legal basis or accountability mechanism. A local representative, officer or regulator contact will be published where required before active market launch. Mandatory rights cannot be waived by contract.

13. Children

AERLYO accounts and trip requests are intended for adults aged 18 or older. The service is not directed to children under 13 and we do not knowingly collect their personal data. A parent or guardian who believes a child submitted data should contact us for review and deletion. Passenger details for minors may be processed later only through an adult account and the responsible licensed operator’s controlled travel process.

14. Changes

We may update this notice as the service, providers or law changes. The effective date and version will change, and material changes will be presented in the service or by another appropriate notice before they take effect where required.

15. Contact

Thoth Group LLC
Delaware, United States
Operator of AERLYO
privacy@nawaeurope.com

Security reports: security@nawaeurope.com. General legal notices: legal@nawaeurope.com.

© 2026 Thoth Group LLC. All rights reserved.AERLYO is operated by Thoth Group LLC, Delaware, United States.An idea by J. Faff, realized by Adel Ramzy’s development team.