1. Who we are
This Privacy Policy explains how Teuda (“Teuda”, “we”, “us”) processes information in connection with the Service available at teuda.tech and related applications.
Contact for privacy requests: hello@teuda.tech
This Policy should be read together with our Terms of Service. Capitalised terms not defined here have the meaning given in the Terms where applicable.
2. Scope
This Policy covers:
- Visitors to our marketing site
- Users invited to a Customer organisation on Teuda
- People whose information appears in Customer Data (for example, an inspector’s name on a report), to the extent we process that data as described below
It does not cover third-party websites linked from Teuda, or how a recipient handles a PDF or share link once Customer Data has left our Service under your instruction.
3. Controller and processor roles
For account, billing contact, and Service administration data (who has a login, support emails, subscription contacts), Teuda generally acts as an independent controller.
For Customer Data inside the product — inspections, findings, photos, annotations, checklist states, notes, and similar operational content — Teuda generally acts as a processor on behalf of the Customer organisation, which determines the purposes of that processing (for example, running an inspection programme). The Customer is responsible for ensuring it has a lawful basis to collect and instruct us to process that content, including any personal data it contains.
If your organisation requires a written data processing agreement (DPA), contact hello@teuda.tech.
4. Categories of data we process
Depending on how you use Teuda, we may process:
- Identity and account data — name, email address, role within the Company, authentication-related identifiers, and profile details you provide
- Organisation data — company name, team structure, aircraft register entries you create (registration, type, MSN, and similar identifiers)
- Inspection and operational content (Customer Data) — inspection metadata, checklist progress, remarks and findings, severities, recommended actions, cost estimates you enter, document checklist status, signatures or signature images, free-text notes, and related timestamps
- Media — photographs, annotated images, and other files you upload in connection with inspections or documents
- Sharing and export activity — creation of share links, expiry settings, and that exports were generated (not a transcript of every page viewed by every recipient)
- Technical and security logs — IP address, device/browser type, app version, approximate timestamps, and diagnostic events needed to operate and secure the Service
- Communications — messages you send to support or sales (for example to hello@teuda.tech)
- Billing-related contacts — where applicable, names and emails used for invoices or subscription administration
We do not require special-category data to use Teuda. Please avoid uploading irrelevant sensitive personal data. Photos may incidentally show people in hangars or on the ramp; treat them as confidential Customer Data.
5. Purposes and legal bases
We process information to:
- Provide, maintain, sync, and improve the Service (performance of a contract / legitimate interests)
- Authenticate users, enforce roles, and protect against abuse (legitimate interests / legal obligation where applicable)
- Respond to support and security reports (contract / legitimate interests)
- Send service notices (security, downtime, material Terms or Privacy changes) (contract / legitimate interests)
- Process subscriptions and prevent fraud related to billing (contract / legitimate interests)
- Comply with law and establish or defend legal claims (legal obligation / legitimate interests)
Where we rely on legitimate interests, we balance those interests against your rights. You may object as described in Section 10.
We do not sell personal data. We do not use Customer Data to advertise unrelated products to third parties. Optional product updates or marketing emails, if any, will be sent only where permitted (for example consent or soft opt-in under applicable law) and will include an unsubscribe option.
7. International transfers
Teuda is offered to aviation teams that may operate across borders. Infrastructure providers may process data in the European Economic Area and in other countries with different data-protection laws.
Where personal data is transferred internationally, we use appropriate safeguards recognised under applicable law (for example, standard contractual clauses or an adequacy decision), supplemented by provider security measures.
8. Retention
We keep information only as long as needed for the purposes above:
- Active accounts and Customer Data — for the life of the Customer relationship and a reasonable wind-down period after termination so you can export data (typically up to 30 days unless a longer period is agreed or legally required)
- Backups — for a limited rolling period, then overwritten in the ordinary course
- Security and audit logs — for a period appropriate to detect and investigate abuse, then deleted or aggregated
- Billing and tax records — as required by accounting and tax law
- Support correspondence — for as long as needed to resolve your request and for a reasonable follow-up period
When Customer Data is deleted from live systems, residual copies in backups become inaccessible in normal operations and age out automatically.
9. Security
We implement technical and organisational measures designed to protect personal data and Customer Data against unauthorised access, alteration, disclosure, or destruction. These include, at a high level:
- Encrypted transit for traffic between your devices and our Service
- Authentication and role-based access within each Company
- Logical separation of Customer organisations so one Company cannot query another’s data through normal product use
- Access limited to personnel who need it to operate or support the Service
- Monitoring and processes aimed at detecting and responding to security incidents
We do not publish a detailed inventory of security controls, tooling, or configurations. Doing so would not improve your privacy and could help attackers. Enterprise Customers may receive more detail under a mutual NDA or security questionnaire.
No method of transmission or storage is perfectly secure. You remain responsible for device security, strong unique passwords (or SSO where offered), timely deactivation of leavers, and careful use of share links and offline devices.
If we become aware of a personal-data breach affecting you, we will notify you and/or supervisors as required by applicable law.
10. Your rights
Depending on where you live and your relationship to the data, you may have rights to:
- Access personal data we hold about you
- Rectify inaccurate personal data
- Erase personal data in certain circumstances
- Restrict or object to certain processing
- Data portability for data you provided to us as a controller
- Withdraw consent where processing is consent-based
- Lodge a complaint with a supervisory authority (in Lithuania, the State Data Protection Inspectorate — VDAI — or your local authority)
To exercise rights related to your user account, email hello@teuda.tech. For Customer Data controlled by your employer or operator, we may redirect you to your Company admin, who instructs us as controller of that content.
We may need to verify your identity before fulfilling a request.
12. Children
Teuda is a business service for aviation professionals. It is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will take appropriate steps to delete it.
13. Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. For material changes, we will provide additional notice (for example email to Company admins or an in-product notice) when required or appropriate.
The current version is always available at teuda.tech/privacy.
14. Contact
Privacy and data-protection requests: hello@teuda.tech
Website: https://teuda.tech
If you are an EU/EEA resident and we appoint an EU representative or DPO in the future, we will publish those details here.