Privacy Policy
Last updated: 3 August 2026
1. Introduction
Job Avion ("we", "us") operates a "Privacy-First" aviation recruitment and management platform. We are committed to protecting your personal data in compliance with the General Data Protection Regulation (GDPR) and applicable laws.
This policy outlines how we handle your data, with a special focus on our "Silent Matching" technology and AI-driven features. By using Job Avion, you trust us with your professional history, and we take that responsibility seriously.
2. Information We Collect
To provide our specialized services (Digital Logbook, Job Matching), we collect the following types of information:
- Identity & Contact Data: Name, email address, phone number, and location.
- Identity Documents: If you are an individual user (specialist or student), a scan of your national ID card and/or passport, together with the limited details read from it. Companies never upload identity documents. See section 6 for exactly what is stored, why, and who can see it — for job applications, the answer is nobody.
- Professional Aviation Data: CVs/Resumes, EASA/FAA Licenses (Part-66, ATPL, CPL), Medical Certificates, Type Ratings, and employment history.
- Logbook Data: Specific flight records, maintenance tasks (ATA chapters), and experience logs entered by you into the Digital Logbook.
- Voice Recordings (optional): If you use the voice input in Avion Copilot, the audio you record is uploaded and transcribed to text via OpenAI Whisper (through our AI provider). The audio file is deleted immediately after transcription — only the resulting text remains in your chat, where you can review and edit it before sending.
- Payment Information: We use Stripe for payments. We do not store full credit card numbers on our servers; we only store the payment token provided by Stripe.
3. How We Use Your Information
We use your data to operate the platform, but with a strict separation between public and private visibility.
The "Silent Matching" Protocol (Core Feature)
- Anonymity: Your Candidate Profile is hidden by default. Employers can search for your skills, licenses, and experience, but they cannot see your name, photo, or contact details.
- The "Unlock": Your identity is revealed to an Employer ONLY if you actively apply for a job or if you explicitly accept ("Unlock Profile") an interest request from them.
Other Uses
- AI Processing & Matching: We use Artificial Intelligence to analyze your skills and suggest relevant jobs or identify training gaps (e.g., missing modules). The AI also processes your queries to provide educational support.
- Learning Quality: When you take practice tests in Avion Copilot, we keep statistics about your answers (topic, correct/incorrect) and any question reports you submit. These are used to personalise your study plan and to improve the quality of AI-generated questions.
- Service Provision: To maintain your Digital Logbook and allow you to export your data.
- Third-Party Sharing: We do not sell your data. We share it only with the service providers needed to run the platform, and with employers or partners only when you choose to reveal yourself to them. Every recipient is named in section 10.
4. Cookies & Local Storage
We use a small number of strictly necessary cookies and local-storage items to keep JobAvion working (such as your sign-in session, language, and consent choice). The banner additionally offers three optional categories — Preferences, Analytics and Marketing — each off by default and each loading nothing unless you switch it on. Nothing runs unless you switch it on. Marketing controls two conversion tags — Google Ads and the Meta Pixel — which tell us whether an advert we paid for ended in a sign-up; neither script is even fetched while the category is off. Analytics and Preferences currently control nothing. Every item, its purpose and its lifetime is named in the Cookie Policy.
You can review every item we store, and accept, reject or change your choices at any time, in our dedicated Cookie Policy or via the "Cookie settings" link in the footer.
5. Data Security
Article 32 GDPR requires us to describe the measures we actually take, not to assert that we are secure. These are the measures in place:
- Encryption in transit. Every connection to the platform, and every connection between the platform and its providers, is encrypted with TLS. The site is served only over HTTPS.
- Encryption at rest. The database and the file storage are encrypted at rest, as are the backups.
- Passwords. We never store your password. We store a bcrypt hash with a per-password salt and a deliberately slow work factor, so that the hash cannot practically be reversed even if the database were stolen. If you sign in with Google we never receive a password at all.
- Sensitive files are held separately. Identity documents, passports and driver documents are written to a private storage area that has no public address. They can only be reached through a short-lived link, valid for one hour, issued to a signed-in user who is entitled to see that specific file. There is no URL that anyone can guess or share permanently.
- Upload filtering. Uploads are checked by file type and extension before they are accepted, so that executable and archive formats cannot reach the private area.
- Access control. Every request is checked against the identity of the signed-in user and the role that user holds. Company data and specialist data are separated, and one account cannot read another account's data by changing an identifier in a request.
- Least privilege inside the company. Avion Technic Ltd. is a small company. Administrative access to production data is limited to the people who need it to run the service, is used only to operate and support the platform, and is logged.
- Payment data. Card numbers never reach our systems. Payment pages are hosted by Stripe, which is PCI-DSS certified.
- Monitoring. We keep security and access logs, and automated checks run against the platform to detect abuse, fraud and unusual activity.
- Breach notification. If a personal-data breach occurs that is likely to result in a risk to your rights, we notify the Bulgarian supervisory authority within 72 hours of becoming aware of it, and we notify you directly where the risk is high (Articles 33 and 34 GDPR).
What we cannot promise. No online service is immune from attack, and we do not claim to be. Please use a password you do not reuse elsewhere, and tell us at once at office@jobavion.com if you believe your account has been accessed by someone else or if you have found a vulnerability. We do not pursue security researchers who report a genuine finding to us in good faith, who do not access or alter other users' data, and who give us a reasonable period to fix it before publishing.
- Data Ownership: You retain full ownership of your Logbook data. You have the right to export this data in a portable format at any time.
- GDPR Rights: As a user, you have the right to request access to your data, correct inaccuracies, or request the deletion of your account ("Right to be Forgotten"). Section 15 sets out every right in full.
- Data Retention: We keep each category of data for a defined period, set out in full in section 12.
6. Identity Documents
Individual users can hold up to two identity documents on their profile: a national ID card and a passport. Companies never upload either. The two are used for two different purposes, and those purposes have different legal bases, so we describe them separately below. Everything in this section applies to both documents unless it says otherwise.
6.1 Purpose one — confirming that an applicant is a real person
To apply for a job listing on Job Avion, you must have one verified identity document on file — either your ID card or your passport. A passport is accepted in place of an ID card because several countries, including the United Kingdom, Ireland and Denmark, do not issue a national ID card.
- Why: companies receiving applications need to be able to trust that a real, identifiable person is behind them. Fake and duplicate applicant accounts are the single most common form of abuse on hiring platforms, and they damage both the companies who waste time on them and the genuine candidates competing with them.
- Legal basis — legitimate interest, Article 6(1)(f) GDPR, as recognised for fraud prevention in Recital 47. We deliberately do not present this as consent: consent that you must give in order to receive the service is not freely given and therefore not valid (Article 7(4) GDPR; EDPB Guidelines 05/2020). We have weighed our interest against your rights and concluded it is proportionate because the document is never disclosed to anyone, only minimal fields are retained, and the alternative — an unverified applicant pool — would harm all other users. You can object to this processing at any time under Article 21 GDPR (see 6.7); in practice, objecting means you can use the rest of the platform but not submit job applications.
- Who sees the document: nobody. For hiring purposes the file is never shown to any company, never appears on your profile, never appears in your certificate list, and is never shared with other users. A company sees only that your identity was verified — not the document, not the document number, not the issuing country.
6.2 Purpose two — carrying an aircraft part across a border
If you offer to carry an aircraft part in person ("personal courier" / AOG transport), a passport specifically is required, because these jobs cross borders and the company hiring you has a legitimate need to know who is holding its part.
- Legal basis — your explicit consent, Article 6(1)(a) GDPR. Unlike purpose one, this is genuine consent: the sharing is optional, it is separate from the rest of the platform, and refusing it costs you nothing except that one type of job. You give it separately for each individual job, by ticking a consent box at the moment you apply, and it is recorded together with the exact wording you agreed to and a timestamp.
- Who can see it: only the company that posted the specific transport job you applied for, and only for that job. Your ID card is never reachable by a company under any circumstances — a grant is only ever for the passport.
- How long access lasts: during the job, and for 30 days after the job is closed. After that the access locks automatically.
- Re-access: after those 30 days the company may ask, in writing and with a stated reason, to view the document again. You will be notified and can deny, ask for more information, or share again. If you share again, access lasts 7 days and then locks once more.
- Withdrawal: you can withdraw consent for any job at any time, and delete the document from your profile at any time. Withdrawal takes effect immediately and does not affect the lawfulness of processing before it.
6.3 What we store, and what we do not
- Stored: the scan or photograph itself, its file name, and the details you confirm after the automated check: your name as printed, the document type, the issuing country, the issue and expiry dates, and the last four characters of the document number.
- Not stored: the full document number, and any address printed on the document. Neither is needed for either purpose above, so neither is kept.
- How it is stored: in a private area of our cloud storage that is not served through our public content delivery network. There is no public link to the file. Where access is permitted at all, it is granted as a one-off, cryptographically signed link that expires after 60 seconds.
6.4 The automated check
Before a document is saved, the file is sent to our AI provider (Google Gemini, through our processing proxy) to confirm that it really is an identity document of the type you are uploading, that it is legible, and that it contains no prohibited content. The provider also reads the fields listed in 6.3 so you can confirm or correct them; if you correct them, the file is checked once more against what you entered. Files that fail the check are deleted immediately and nothing is recorded against your profile. The document is not used to train any AI model.
This check is not an automated decision in the sense of Article 22 GDPR, because it produces no legal or similarly significant effect on you: a failed check means only that you can upload a different or clearer file, and no record of the failure is kept. Where an automated step would determine access to something significant, the Court of Justice has held that it falls within Article 22 (Case C-634/21, SCHUFA) — our check does not, but if you believe a document was wrongly refused you can contact us and a person will look at it.
6.5 This is not biometric data
We do not extract, generate or compare facial templates or any other biometric identifier from your document. The photograph on the page is not processed to identify you, so this is not "biometric data for the purpose of uniquely identifying a natural person" under Article 4(14) GDPR and Article 9 does not apply to the hiring use. Passport sharing under 6.2 is nonetheless handled on explicit consent, because of the sensitivity of handing a travel document to a third party.
6.6 Retention
- A document is kept only while it is on your profile. Deleting it from your profile removes the file from our storage, and removing your ID card or passport immediately restores the corresponding restriction (no job applications, or no transport jobs).
- Files that fail the automated check are deleted immediately, with nothing recorded.
- Consent records for passport sharing (which job, what wording, when) are kept after the document itself is deleted, as legal evidence that consent was given and later withdrawn.
- Access grants expire on the schedule in 6.2: 30 days after a job closes, or 7 days after a re-grant.
6.7 Your rights
You may at any time request access to what we hold, correct it, delete the document, withdraw consent for any passport share, or object under Article 21 GDPR to the identity check described in 6.1 — that right is specifically relevant here because we rely on legitimate interest rather than consent for that purpose. Use the contact details in section 7. You also have the right to lodge a complaint with the Bulgarian supervisory authority, the Commission for Personal Data Protection (КЗЛД), cpdp.bg.
Copying an identity document is permitted under Bulgarian data protection practice where it is necessary and proportionate to a clearly stated purpose. The purposes above are the only ones for which we hold these documents, and we do not use them for anything else.
6.8 What this is not
The automated check confirms that the file is a legible identity document and that the details you confirmed match it. It is not an authenticity check: Job Avion does not verify that a document is genuine or validly issued, and a verified badge is not a guarantee of identity. A company that has been given access to a passport can report a document it believes is wrong or fraudulent, which flags it for our review and notifies you — but the final assessment of the person carrying its part remains the responsibility of the company hiring you.
7. Why We Are Allowed to Process Your Data
Every use of your personal data needs a legal basis under Article 6 GDPR. This is ours, purpose by purpose.
- Creating and running your account; delivering the features you subscribe to; billing you — performance of a contract, Article 6(1)(b). Without this data we cannot provide the service, so providing it is a requirement of using the platform.
- Publishing your profile, listings, applications and posts to the users you choose to show them to — performance of a contract, Article 6(1)(b). What is visible to whom is controlled by you through your visibility settings and Silent Matching (section 3).
- Confirming an applicant is a real person — legitimate interest, Article 6(1)(f), as described in section 6.1.
- Sharing a passport with a company for a specific transport job — explicit consent, Article 6(1)(a), given per job (section 6.2).
- Security, fraud prevention, abuse and spam detection, content moderation, and enforcing our Terms — legitimate interest, Article 6(1)(f) (Recital 47), and legal obligation, Article 6(1)(c), where the Digital Services Act requires us to act on notices and orders.
- AI matching, suggestions and Copilot answers — performance of a contract where you have asked for the feature, Article 6(1)(b); legitimate interest for measuring and improving quality using data that no longer identifies you, Article 6(1)(f).
- Service e-mails — verification, security alerts, billing, and notifications about activity on your account — performance of a contract, Article 6(1)(b). You can switch off non-essential notifications in your settings; verification, security and billing messages cannot be switched off while the account exists.
- Marketing e-mails about new features or offers — consent, Article 6(1)(a), which you may withdraw at any time via the unsubscribe link, or legitimate interest in respect of our own similar services to existing customers, where the law allows and always with an opt-out.
- Optional cookies and local storage — consent, Article 6(1)(a) and Article 5(3) of the ePrivacy Directive. Strictly necessary items rely on Article 6(1)(f). See our Cookie Policy.
- Invoices, accounting records and tax — legal obligation, Article 6(1)(c), under Bulgarian accounting and tax law.
- Establishing, exercising or defending legal claims — legitimate interest, Article 6(1)(f).
Where we rely on legitimate interest, you have the right to object at any time under Article 21 GDPR, and we will stop unless we can demonstrate compelling legitimate grounds that override your interests. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of what was done before you withdrew it.
8. Health Data and Other Sensitive Information
Aviation careers involve documents that reveal health information. A medical certificate (Class 1, Class 2, Class 3, LAPL or a maintenance-related medical) shows that an authority has assessed your fitness, and is therefore data concerning health under Article 9 GDPR.
- Adding a medical certificate is entirely optional. You can hold a complete profile, apply for jobs and use every other feature without it. We never require one.
- Where you choose to add one, we process it on the basis of your explicit consent, Article 9(2)(a) GDPR, given by the act of adding it after being shown this notice, and, where you make it visible to a company, by your separate decision to share it.
- We store only the fields you enter — class, issuing authority, issue and expiry dates, limitations if you enter them — and the file if you upload one. We do not process any medical finding, diagnosis or examination result, and we do not ask for one.
- We use it for exactly two things: reminding you before it expires, and showing it to a company when you decide to share it. It is never used for matching against your will, never sold, and never used to train an AI model.
- Withdrawal is immediate: deleting the certificate from your profile deletes the file and the fields, and withdraws the consent for the future.
We do not knowingly collect any other special-category data (racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic or biometric data, sex life or sexual orientation), we do not process criminal-conviction data, and we ask you not to enter such information into free-text fields, CVs, messages or feedback.
9. Where Data About You Comes From When It Does Not Come From You
Most of what we hold, you gave us. In a few cases we receive data about you from someone else, and Article 14 GDPR requires us to tell you:
- From a company you worked with — confirmation or rejection of an employment link you claimed, and, where the company chooses to give it, feedback about your engagement (see the rules and your rights in Section 18.6 of the Terms of Use).
- From another user — an invitation, a referral, a message, an application to a listing of yours, or a report about your content.
- From Google — if you choose "Sign in with Google", your name, e-mail address and profile picture, and nothing else. We never receive your Google password and no access to your Google account.
- From Stripe — the result of a payment, the last four digits and brand of the card, and the billing country. We never receive the full card number.
- Generated by us — match scores, activity and security logs, moderation records, credit-usage records.
10. Who We Share Data With
We do not sell your personal data, and we do not share it with data brokers. Data goes to four kinds of recipient and no others.
a) Other users, and only as you direct. A company sees your identity when you apply to its listing or accept its interest request. Anything you publish — a listing, a forum post, a company page — is visible to the audience you selected. Feedback you write is published without your name (Section 18.4 of the Terms).
b) Service providers acting on our instructions. We engage each of the following under a written agreement that permits it to use the data only to deliver its service, and not for its own purposes. Some of them engage their own sub-processors; where that is the case we say so, because it affects who ultimately handles your data:
- OpenKBS — our platform provider. Our application, our database, our uploaded files and our outbound e-mail all run on infrastructure that OpenKBS operates, and every AI request we make is routed through it. OpenKBS is our processor; the parties below marked "engaged through OpenKBS" are its sub-processors, not companies we contract with directly.
- Amazon Web Services (engaged through OpenKBS) — the underlying cloud: compute, database, object storage, content delivery and the e-mail sending service.
- Stripe Payments Europe Ltd (Ireland) — subscriptions, payments and invoicing. Stripe is an independent controller for its own fraud-prevention and regulatory purposes; see stripe.com/privacy.
- OpenAI (engaged through OpenKBS) — text models and speech-to-text used by Avion Copilot, by the voice-input feature and by our abuse screening.
- Google (engaged through OpenKBS) — Gemini models used by Copilot, by image moderation and by document reading. Separately, and only if you choose it, Google Ireland Ltd provides "Sign in with Google"; in that case Google acts as its own controller for the sign-in.
- OpenStreetMap Foundation — map tiles and place lookup. When a map is displayed, your IP address reaches the tile server, in the same way as loading any image from another site.
What we send to an AI model, and what we do not. We want to be precise here rather than reassuring.
- Sent: what you type into Avion Copilot; audio you record with the voice-input button; text and images you publish, which are screened automatically before they go live; the content of a job listing or profile when a match is calculated; and files an administrator uploads to build course material.
- Sent only after a first, non-AI filter: a private message is examined by a model only if a simple pattern check has already flagged it as a possible attempt to move a deal off-platform or to abuse another user. Ordinary conversation is never sent to a model.
- Never sent: your identity document, your passport and your medical certificate are never transmitted to any AI model. They are stored, shown to you, and shown to the specific counterparty you unlock them for. Nothing more.
- Never used to train: we do not use your content to train, fine-tune or evaluate any model, and we do not license it to anyone who does. Our platform provider states that it does not train models on customer data and that it configures AI providers with data-protection settings, including zero data retention where the provider offers it. We rely on that statement; we do not hold a direct contract with OpenAI or Google and therefore cannot make a promise on their behalf. If you want the current position in writing before you use an AI feature, ask us at the address in section 17 and we will pass on what our provider has confirmed to us.
c) Authorities, where we must. We disclose data to a court, a supervisory authority, a law-enforcement body or a regulator where we receive a valid, legally binding order. We check that each order is valid and limit what we hand over to what is actually required, and we notify the user concerned unless the order or the law forbids it.
d) Advertising providers, and only if you switch the Marketing category on. We advertise the platform on Google and on Facebook and Instagram, and we measure whether an advert we paid for ended in a sign-up. If — and only if — you consent, a conversion tag from Google Ireland Ltd and from Meta Platforms Ireland Ltd loads in your browser and tells that provider that a sign-up occurred, together with the browser identifier named in table 3.4 of the Cookie Policy. These two are not our processors: each is an independent controller for what it then does with that signal, which is why this is a separate category and why it is the only category on this list that asks your permission first. We deliberately do not enable the features that would send them more — Google's enhanced conversions, Meta's automatic advanced matching, or Meta's server-side Conversions API — so no e-mail address, telephone number or name of yours is transmitted to either, in hashed form or otherwise. While the category is off, neither script is fetched at all.
If we are ever involved in a merger, acquisition or sale of assets, personal data may transfer to the acquirer, who would remain bound by this policy. You would be told before that happened.
11. Where Your Data Is Stored, and Transfers Outside the EEA
We have configured this service to run in the European Union. Our application, our database and our uploaded files are deployed to the Frankfurt region of our cloud infrastructure, and our backups are taken in the same region. That is the configuration we chose and the configuration we maintain.
Two honest qualifications. First, our platform provider operates in several regions worldwide, and we cannot rule out that a platform-level operation — an administrative action, a support intervention, a log — touches infrastructure outside the EU. Second, AI inference is not region-bound: when you use an AI feature, the text, image or audio for that single request is sent to the model provider, which may process it outside the European Economic Area, typically in the United States. If that matters to you, do not use the AI features; nothing on the platform requires you to.
Where personal data is transferred outside the EEA, we rely on the safeguards in Chapter V GDPR: the European Commission's adequacy decision for the EU–US Data Privacy Framework where the recipient is certified under it, and otherwise the European Commission's Standard Contractual Clauses together with supplementary technical measures such as encryption in transit, pseudonymisation and data minimisation. You may request details of the safeguards applied to a specific transfer using the contact details in section 17, and we will obtain them from our provider where we do not hold them ourselves.
12. How Long We Keep Things
We keep personal data only for as long as it serves the purpose it was collected for, and then delete or anonymise it.
- Account, profile, logbook and certificates — for as long as your account exists. Deleting your account deletes this data from the live system immediately, apart from what is listed below.
- Identity documents — only while they are on your profile; deleting one removes the file at once (section 6.6).
- Medical certificates — only while on your profile; deleted immediately on removal (section 8).
- Applications and the messages attached to them — while the account exists, and in any event no longer than 3 years after the last activity on the application, so that both sides retain the record of an engagement.
- Private messages — while both accounts exist; deleted with the account, except where retained as evidence in an open moderation, fraud or legal matter.
- Published content — listings, posts, feedback — until you delete it or your account is closed. Feedback you have written is retained without your name where deleting it would misrepresent the aggregate score, and is otherwise removed.
- Consent records — 3 years after the consent ends, as evidence that it was given and withdrawn.
- Security and access logs — 12 months, then deleted.
- Moderation records — notices, decisions, statements of reasons — 3 years, as required to handle complaints and to demonstrate compliance with the Digital Services Act.
- Invoices, payment records and accounting documents — 10 years, as required by Bulgarian accounting and tax law. These cannot be deleted on request during that period.
- Data needed to establish, exercise or defend a legal claim — until the claim and any limitation period ends.
- Backups — copies persist in encrypted backups for a limited period after deletion from the live system — normally no more than 35 days — and are then overwritten in the ordinary cycle. Backups are restored only to recover from an incident, never to bring back data you deleted.
13. Automated Processing and AI
The platform uses AI to suggest matches, summarise, draft, answer regulatory questions and screen content for abuse. No hiring, rejection or shortlisting decision is made by the platform. A match score is a recommendation shown to a human, who decides. Accordingly we do not carry out automated decision-making producing legal or similarly significant effects on you within the meaning of Article 22 GDPR.
Where an automated check does restrict something — a document check, a content screen, an account restriction — you are told, you are told whether automated means were used, and you can ask for a human to look at it (Section 3.2.1 and Section 22.2 of the Terms of Use).
The main factors used in matching, and their relative importance, are described in Section 20 of the Terms. If you want to know how a specific recommendation about you was produced, ask us and we will explain the factors that applied in your case, in terms you can understand, without disclosing anything that would allow the system to be manipulated or that would reveal a third party's data.
14. Our Role and the Employer's Role
For the operation of the platform, Avion Technic Ltd. is the controller of your data.
When a company receives your application, or you unlock your profile to it, that company becomes an independent controller of the data it receives. From that point, how it stores, uses and retains your data, and how long for, is governed by its privacy notice and is its responsibility, not ours. Its recruitment decisions, and its compliance with employment and equal-treatment law, are likewise its own. If you want your data erased from a company's systems, you must address that company directly; we will help you identify who received what.
15. Your Rights
Under the GDPR you have the right to:
- be informed — this policy;
- access your data and receive a copy (Article 15). Where a copy would reveal another person's data — for example the identity of someone who wrote feedback about you — we redact what is necessary to protect them and give you the rest, together with the reason. We never refuse a request outright on that ground;
- rectification of inaccurate or incomplete data (Article 16);
- erasure (Article 17), subject to the retention periods above where the law requires us to keep something;
- restriction of processing (Article 18);
- data portability — a machine-readable export of the data you provided (Article 20). Your logbook can be exported at any time from your account;
- object to processing based on legitimate interest, and to direct marketing at any time (Article 21);
- withdraw consent at any time, without affecting the lawfulness of prior processing (Article 7(3));
- not be subject to a decision based solely on automated processing producing legal or similarly significant effects (Article 22) — see section 13;
- lodge a complaint with a supervisory authority (Article 77).
Write to office@jobavion.com to exercise any of these. We answer within one month, extendable by two further months for complex requests, in which case we tell you within the first month. Exercising your rights is free; we may charge a reasonable fee only for manifestly unfounded or excessive repeat requests.
You may complain to the Bulgarian supervisory authority — the Commission for Personal Data Protection (Комисия за защита на личните данни, cpdp.bg) — or to the authority in your country of residence or place of work.
16. Children
The platform is intended for people pursuing or working in an aviation profession and is not directed at children. You must be at least 16 years old to create an account, or older where the law of your country sets a higher age for a service of this kind. If we learn that we hold data about a child below that age, we delete the account and the data.
17. Contact Us
If you have any questions about this Privacy Policy, or if you wish to exercise your GDPR rights (such as data deletion or export), please contact us at:
- Data Controller: Avion Technic Ltd.
- Company ID (EIK): 208530294
- VAT ID: BG208530294
- Address: j.k. Mladost 3, bl. 376, ent. 1, fl. 8, app. 35, 1712 Sofia, Bulgaria
- Email: office@jobavion.com