Privacy Policy
Effective: 28 July 2026
Controller: LOXTU Limited, [registered address], United Kingdom
1. Who We Are
LOXTU Limited ("we", "our", "us") operates the LOXTU aviation crew scheduling platform at app.loxtu.com. We are the data controller for the purposes of applicable data protection laws, including the UK GDPR and EU GDPR.
2. What Data We Collect
We collect only the minimum data necessary to provide the service:
- Account data: email address (hashed + encrypted at rest)
- Authentication data: passkey credentials (public key only), OAuth provider ID
- Session data: IP address, User-Agent string, session tokens
- Usage data: login/logout timestamps, page views within the app
We do not collect: name, phone number, billing address, payment data, location beyond country-level, browsing history outside our app, or any special category data.
3. How We Collect Data
- Directly: when you create an account, register a passkey, or log in via email/OTP
- From third parties: when you choose to log in via Google OAuth (we receive your email address and Google ID)
- Automatically: IP address, User-Agent, and page interactions within the app
4. Legal Basis for Processing
- Contract (Art. 6(1)(b)): providing the crew scheduling service you signed up for
- Legitimate interests (Art. 6(1)(f)): security monitoring, fraud prevention, improving the service
- Consent (Art. 6(1)(a)): where you explicitly agree (e.g. optional features)
- Legal obligation (Art. 6(1)(c)): retaining audit logs for regulatory compliance
5. How We Store Data
All PII (email, user UUID) is encrypted at rest using AES-256-GCM with envelope encryption. The data encryption key (DEK) is itself encrypted with a key-encryption key (KEK). Authentication credentials (passkeys) store only public keys. Audit logs contain only hashed identifiers, not raw PII.
Data is stored in [hosting region] on encrypted volumes.
6. Third Parties
We share data only with essential sub-processors:
- Google LLC — OAuth authentication (if you choose Google login)
- [Hosting provider] — cloud infrastructure
- [Email provider] — transactional email delivery
Each sub-processor is bound by a Data Processing Agreement (DPA) that meets GDPR Art. 28 requirements.
7. International Transfers
Your data may be processed in the [UK/EU/US] region. We rely on UK adequacy decisions and/or Standard Contractual Clauses (SCCs) for any transfers outside the UK/EEA.
8. Retention
- Sessions: deleted after 30 days of inactivity
- Audit logs: retained for 12 months
- Identity data: retained until you request erasure
- OTP codes: deleted after expiry (10 minutes)
9. Your Rights
You have the right to:
- Access — request a copy of your data
- Rectification — correct inaccurate data
- Erasure — delete your account and all associated data
- Portability — export your data in machine-readable format
- Restriction — limit processing in certain circumstances
- Objection — object to processing based on legitimate interests
To exercise any of these rights, email privacy@loxtu.com or use the "Delete my account" button in the app.
10. Complaints
If you believe we are not handling your data lawfully, you have the right to lodge a complaint with:
- UK: Information Commissioner's Office (ICO) — ico.org.uk
- EU: Your local data protection authority
11. Security Measures
We implement appropriate technical measures (Art. 32):
- Envelope encryption for all PII
- Passkey (WebAuthn) authentication — no passwords stored
- Session tokens with fingerprinting
- Audit logging of all authentication events
- Regular security updates
12. Changes
We may update this policy. Material changes will be notified via email or an in-app notice. Continued use after changes constitutes acceptance.