AviSyst Privacy Breach Procedure

Helitronics Limited · Effective 21 August 2026 · Last updated 21 August 2026

This is Helitronics Limited’s procedure for privacy incidents affecting AviSyst (the iOS and Android apps, app.avisyst.com, and www.avisyst.com). It sits with the AviSyst Privacy Policy.

It is written to meet Part 6 of the New Zealand Privacy Act 2020 (notifiable privacy breaches), the Privacy Regulations 2020 (public notices), Information Privacy Principle 5 (security), and Office of the Privacy Commissioner (OPC) guidance current as at August 2026, including the Privacy Amendment Act 2025.

1. Purpose and law

Helitronics Limited will:

Knowledge of an employee or agent counts as knowledge of Helitronics Limited (Privacy Act s 117 and OPC guidance). Anyone at AviSyst who sees a possible breach must escalate it at once — do not wait for a “privacy officer” to discover it independently.

2. Who does what

Role Responsibility
Anyone (staff, contractor, operator) Report a suspected incident immediately to info@avisyst.com with the subject line PRIVACY INCIDENT.
Privacy Officer The director of Helitronics Limited, via info@avisyst.com. Leads assessment, OPC NotifyUs, individual notification, and the incident log.
Technical lead Contain the incident (revoke access, rotate keys, disable a compromised path, recover or wipe a device where possible).
Operator (aviation company using AviSyst) For records the operator entered and Helitronics holds on its behalf (Privacy Act s 11), the operator is the agency that must notify OPC and affected people if the breach is notifiable. Helitronics will tell the operator immediately and assist.

3. What counts as a privacy breach

A privacy breach (Privacy Act s 112) is unauthorised or accidental access to, or disclosure, alteration, loss, or destruction of, personal information — or AviSyst being unable to access the information (including ransomware or a prolonged outage that locks people out of their own information).

Examples in this product include:

Near misses (caught before personal information left AviSyst’s control) are logged and reviewed even when they are not notifiable.

4. Serious harm (notifiable breaches)

A breach is notifiable if it has caused serious harm, or is likely to cause serious harm, to an affected individual (Privacy Act ss 112–115). Assess using s 113, including:

Serious harm can include physical harm, identity theft, financial fraud, psychological harm, employment harm, blackmail, or a risk to someone’s safety.

If anyone’s physical safety may be at immediate risk, contact New Zealand Police first, then continue this procedure and notify OPC.

If you are unsure whether harm is “serious”, treat it as notifiable and use OPC’s NotifyUs self-assessment. When in doubt, notify.

5. How staff and operators report an incident

  1. Stop the leaking path if you can do so safely (do not destroy evidence you may need).
  2. Email info@avisyst.com immediately with: what happened, when, whose information may be involved, how many people (if known), whether it is still happening, and what you have already done.
  3. Do not email copies of the compromised personal information to extra people “for awareness”.
  4. Do not post details in public channels, group chats, or social media.

Helitronics will acknowledge the report the same day it is received (or the next calendar day if it arrives overnight) and start containment.

6. Respond: contain, assess, notify, prevent

Step What we do
Contain Cut off unauthorised access; rotate credentials and API keys; recall or ask deletion of a misdirected email where possible; remote-wipe a lost device if available; disable a broken export or function; preserve logs.
Assess Identify the personal information involved, the companies and people affected, whether children are involved, whether the information is still exposed, and whether s 113 serious harm is likely. Document the decision and reasons at the time.
Notify OPC (if notifiable), affected individuals (unless an exception applies), the operator, and other agencies in section 10. Incremental updates are allowed (s 117(5)) as facts become known. Do not delay OPC while waiting for a perfect headcount.
Prevent Fix the root cause, review access control and logging, brief staff, and record lessons in the incident log.

Target times

Action Target
Escalate internally Immediately on suspicion
Contain Same hour if still leaking; otherwise as soon as practicable
Decide if notifiable As soon as an initial assessment shows serious harm is likely
Notify OPC As soon as practicable; OPC expects within 72 hours of awareness
Notify affected people / operator As soon as practicable after the notifiable assessment (see delays below)

7. Notify the Privacy Commissioner

Use OPC NotifyUs. Do not attach customer or passenger personal information to the report. Include:

Update OPC when material facts change, using the PBN reference NotifyUs issues. Print or save a copy of the notification for the incident file.

8. Notify affected people

For a notifiable breach, notify each affected individual as soon as practicable, directly where we hold accurate contact details (email, phone, or in person). A notification must include the matters in Privacy Act s 117(2):

Public notice

If it is not reasonably practicable to notify people individually (unknown identities or no usable contact details), give public notice that is free to access on app.avisyst.com and in at least one other channel likely to reach those people (Privacy Regulations 2020, regulation 12). The notice must:

Exceptions, representatives, and delay

Even if a breach is not notifiable, Helitronics may still tell affected people or the operator where that is the fair and transparent thing to do.

9. Operator records and section 11

AviSyst stores operational records (DFRs, manifests, safety files, staff profiles the operator maintains) for the operator. Under Privacy Act s 11, information held by an agent for another agency is treated as held by that agency. OPC’s position:

Helitronics remains responsible for notifying OPC and individuals for AviSyst account data, authentication identifiers, crash diagnostics, and marketing-site data that we collect as an agency in our own right.

10. Other agencies

Consider, without sending extra copies of personal information:

Do not notify the Civil Aviation Authority solely because of a privacy incident unless the operator’s exposition or another aviation rule requires it, or flight safety is affected.

11. Records and review

The Privacy Officer keeps an incident file (not in public git) with:

After a notifiable breach, or after a serious near miss, complete a short review within 15 working days: what failed, what we changed, and whether staff need a briefing. Practice this procedure at least once a year (a tabletop exercise is enough).

Access and correction requests (IPP 6 and 7) are separate from breaches. Respond as soon as reasonably practicable and within 20 working days unless the request is transferred to another agency (Privacy Act ss 44 and 63, as amended 24 September 2025). Time may be extended with written reasons within those 20 working days (s 48).

12. AviSyst examples

Scenario Likely path
DFR PDF emailed to the wrong staff member in the same company Contain (recall / ask delete). Assess sensitivity (passenger names, crew, times). Often not “serious harm” if a trusted colleague returns it unopened — still log it. If the PDF includes a child’s details, next-of-kin, or went outside the company, reassess as notifiable.
Passenger manifest visible to another operator because of an access-control bug Shut the path immediately. Treat as likely notifiable. Tell the affected operator(s). Helitronics notifies OPC for the system failure; operators notify (or we notify on their behalf) people we can identify.
Lost unlocked phone with an open AviSyst session Revoke sessions, change passwords, remote-wipe if possible. Harm depends on what was cached and whether the device was found. Assess s 113; notify if serious harm is likely.
Ransomware or inability to access operator records This is a privacy breach even without a leak. Notify OPC if serious harm is likely (including inability to operate safely or identity data held to ransom). CERT NZ and the operator the same day.
Firebase / Google / SendGrid reports a provider breach Treat their notice as Helitronics becoming aware. Contain with the provider. Assess AviSyst data in scope. Notify operators. Notify OPC if notifiable. Do not wait for the provider to notify affected individuals on our behalf unless we have confirmed they will, and when.

13. Contacts

Helitronics Limited
NZBN 9429043337231 · GST 120-820-540
AviSyst Privacy Officer: info@avisyst.com
Privacy Policy: https://app.avisyst.com/privacy.html
This procedure: https://app.avisyst.com/privacy-breach.html

Office of the Privacy Commissioner: www.privacy.org.nz · NotifyUs: notify a breach