Last updated August 5, 2026
CoreX SMS is safety management software that [Company Legal Name] licenses to individual aviation operators ("Organizations"). Each Organization is a separate, isolated tenant: your data is never visible to another Organization's users.
For most of the personal data described below, your Organization is the data controller — they decide who gets an account, what roles they hold, and how long records are kept beyond any regulatory minimum. [Company Legal Name] acts as a data processor, operating the software on the Organization's behalf. If you have a question about how your specific employer uses your data, your Organization's safety manager or admin is the right first contact.
To operate the safety reporting, hazard tracking, audit, and safety-performance features your Organization has licensed; to meet the safety record-keeping obligations aviation regulators impose on your Organization (for example, ICAO Annex 19-aligned SMS documentation requirements); and, where you've given it, to send account-related notifications like report reminders.
Safety reports, hazard records, and their audit trails are retained as long as your Organization's applicable safety record-keeping regulations require, even if the person who filed them later leaves or asks to have their personal data erased — the underlying safety record stays, but see Section 5 for what erasure does to your personal identity within it.
You can download a copy of the personal data tied to your account at any time from My Profile. You can also request your account be erased there, or ask your Organization's admin to do it on your behalf.
Erasure removes your name, phone number, date of birth, and job title from your profile, and permanently locks the account, but it does not delete safety reports, hazards, or audits you filed — those remain as anonymized compliance records ("Deleted User") for the reasons in Section 4. Free-text content you wrote inside a report (which may reference your own name) is not automatically redacted, since it may be part of a retained safety record; contact your Organization's admin if you need help with that.
We don't sell personal data, to these providers or anyone else.
Access to your Organization's data is isolated from every other Organization on the platform, and restricted within your Organization by role (reporter, safety manager, admin, audit manager). Files and signed download links expire after a few minutes rather than being permanently public.
If this policy changes materially, we'll update the "Last updated" date above. [Describe how your Organization will notify users of material changes — e.g. a system message banner, email, etc.]
Questions about this policy, or a data request that isn't covered by the self-service export/erase tools above, can be sent to [privacy contact email].