';
Slide
GDPR Compliance Statement

Last updated: 25 June 2026 · Version: 1.0

In plain English — this is our commitment to handling personal data lawfully and transparently under UK data protection law. It summarises how WhatFBO meets the UK GDPR and the Data Protection Act 2018. For full detail on what we collect, see our Privacy Policy.

1. Our commitment

WhatFBO is committed to protecting the privacy and rights of every pilot, operator and FBO on the platform. We process personal data in line with the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR).

2. Controller and contact

Data controller: Avia Index Limited (trading as WhatFBO), company number 16783750, The Maltings, Rosemary Lane, Halstead, Essex, CO9 1HZ, United Kingdom

Data protection contact / DPO: Ben Howard — [email protected]

Supervisory authority: UK Information Commissioner’s Office (ICO). Registered — registration number C1967268 (interim — formal ZA number to follow once issued)

3. The principles we follow

We apply the seven UK GDPR principles to everything we do:

  • lawfulness, fairness and transparency;
  • purpose limitation — data used only for the purposes we’ve stated;
  • data minimisation — we collect only what we need;
  • accuracy — we keep data correct and up to date;
  • storage limitation — we keep data no longer than necessary;
  • integrity and confidentiality — we keep data secure; and
  • accountability — we can demonstrate our compliance.
4. Lawful bases

We always have a lawful basis before processing. Across the platform we rely on contract (account and membership services), legitimate interests (publishing reviews and FBO profiles, security and improvement), consent (marketing and non-essential cookies) and legal obligation (tax, accounting and lawful requests). Our full mapping is in the Privacy Policy and Record of Processing Activities (ROPA).

5. Your rights

We uphold all data-subject rights under UK GDPR — access, rectification, erasure, restriction, objection, portability, and the right to withdraw consent. Requests to [email protected] are actioned within one month and free of charge in most cases.

6. Security

We protect personal data with appropriate technical and organisational measures, including encryption in transit and at rest, access controls, hashed passwords, least-privilege access, logging, and regular review.

7. Data breaches

We take breaches seriously and act fast. Any personal-data breach is logged and assessed; where it is likely to result in a risk to individuals we notify the ICO within 72 hours, and we notify affected individuals where the risk is high.

8. Processors and contracts

Our suppliers are bound by data-processing agreements. We use vetted processors (hosting, analytics, email, payments) under written contracts meeting Article 28 UK GDPR, and we only use processors that provide sufficient guarantees.

9. International transfers

Transfers outside the UK are safeguarded using UK adequacy regulations or appropriate safeguards such as the UK IDTA or the UK Addendum to the EU SCCs.

10. Accountability

We can demonstrate compliance. We maintain a Record of Processing Activities, conduct Data Protection Impact Assessments (DPIAs) for higher-risk processing, apply data protection by design and by default, and train our people. These are governed by our internal Data Protection Policy.

11. Complaints

Tell us first — but you can always go to the regulator. If you have concerns, contact [email protected]. You also have the right to complain to the ICO at ico.org.uk or 0303 123 1113.


WhatFBO | www.whatfbo.com | [email protected]

Whatfbo.com