This is Helitronics Limited’s procedure for privacy incidents affecting AviSyst (the iOS and Android apps, app.avisyst.com, and www.avisyst.com). It sits with the AviSyst Privacy Policy.
It is written to meet Part 6 of the New Zealand Privacy Act 2020 (notifiable privacy breaches), the Privacy Regulations 2020 (public notices), Information Privacy Principle 5 (security), and Office of the Privacy Commissioner (OPC) guidance current as at August 2026, including the Privacy Amendment Act 2025.
1. Purpose and law
Helitronics Limited will:
- treat every suspected privacy incident as urgent until it is contained and assessed;
- notify the Privacy Commissioner of a notifiable privacy breach as soon as practicable after we become aware of it (OPC expects this within 72 hours, even if investigation is still underway);
- notify affected individuals as soon as practicable, unless a lawful exception or delay in the Act applies;
- tell the operator immediately when the incident involves that operator’s aviation records, so the operator can meet its own Privacy Act duties; and
- keep an incident log, including near misses, and fix the cause.
2. Who does what
| Role | Responsibility |
|---|---|
| Anyone (staff, contractor, operator) | Report a suspected incident immediately to info@avisyst.com with the subject line PRIVACY INCIDENT. |
| Privacy Officer | The director of Helitronics Limited, via info@avisyst.com. Leads assessment, OPC NotifyUs, individual notification, and the incident log. |
| Technical lead | Contain the incident (revoke access, rotate keys, disable a compromised path, recover or wipe a device where possible). |
| Operator (aviation company using AviSyst) | For records the operator entered and Helitronics holds on its behalf (Privacy Act s 11), the operator is the agency that must notify OPC and affected people if the breach is notifiable. Helitronics will tell the operator immediately and assist. |
3. What counts as a privacy breach
A privacy breach (Privacy Act s 112) is unauthorised or accidental access to, or disclosure, alteration, loss, or destruction of, personal information — or AviSyst being unable to access the information (including ransomware or a prolonged outage that locks people out of their own information).
Examples in this product include:
- a DFR, passenger manifest, staff profile, or safety report sent or shown to the wrong company or person;
- an email (invite, DFR close pack, weekly digest) going to the wrong address, or using To/Cc instead of Bcc for a group;
- staff browsing another company’s records, or a former staff member still having access;
- a lost or stolen phone, laptop, or backup that holds AviSyst data;
- unauthorised login, phishing, or a compromised admin account;
- a Firebase / Google Cloud / SendGrid incident affecting AviSyst data;
- publishing personal information on a public page, screenshot, or support ticket by mistake.
Near misses (caught before personal information left AviSyst’s control) are logged and reviewed even when they are not notifiable.
4. Serious harm (notifiable breaches)
A breach is notifiable if it has caused serious harm, or is likely to cause serious harm, to an affected individual (Privacy Act ss 112–115). Assess using s 113, including:
- action already taken to reduce harm;
- sensitivity of the information (identity documents, dates of birth, next-of-kin, body weight, fatigue scores, safety reports, children’s names on manifests, ARNs, location history);
- who obtained, or may obtain, the information (trusted return vs unknown or malicious actor);
- whether the information was protected (encryption, remote wipe, passwords);
- any other relevant matter, including cultural harm and vulnerability (for example family violence).
Serious harm can include physical harm, identity theft, financial fraud, psychological harm, employment harm, blackmail, or a risk to someone’s safety.
If you are unsure whether harm is “serious”, treat it as notifiable and use OPC’s NotifyUs self-assessment. When in doubt, notify.
5. How staff and operators report an incident
- Stop the leaking path if you can do so safely (do not destroy evidence you may need).
- Email info@avisyst.com immediately with: what happened, when, whose information may be involved, how many people (if known), whether it is still happening, and what you have already done.
- Do not email copies of the compromised personal information to extra people “for awareness”.
- Do not post details in public channels, group chats, or social media.
Helitronics will acknowledge the report the same day it is received (or the next calendar day if it arrives overnight) and start containment.
6. Respond: contain, assess, notify, prevent
| Step | What we do |
|---|---|
| Contain | Cut off unauthorised access; rotate credentials and API keys; recall or ask deletion of a misdirected email where possible; remote-wipe a lost device if available; disable a broken export or function; preserve logs. |
| Assess | Identify the personal information involved, the companies and people affected, whether children are involved, whether the information is still exposed, and whether s 113 serious harm is likely. Document the decision and reasons at the time. |
| Notify | OPC (if notifiable), affected individuals (unless an exception applies), the operator, and other agencies in section 10. Incremental updates are allowed (s 117(5)) as facts become known. Do not delay OPC while waiting for a perfect headcount. |
| Prevent | Fix the root cause, review access control and logging, brief staff, and record lessons in the incident log. |
Target times
| Action | Target |
|---|---|
| Escalate internally | Immediately on suspicion |
| Contain | Same hour if still leaking; otherwise as soon as practicable |
| Decide if notifiable | As soon as an initial assessment shows serious harm is likely |
| Notify OPC | As soon as practicable; OPC expects within 72 hours of awareness |
| Notify affected people / operator | As soon as practicable after the notifiable assessment (see delays below) |
7. Notify the Privacy Commissioner
Use OPC NotifyUs. Do not attach customer or passenger personal information to the report. Include:
- Helitronics Limited, NZBN 9429043337231, AviSyst, sector/industry;
- Privacy Officer contact (name, email, phone);
- when the breach happened and when we identified it;
- whether it is ongoing;
- approximate number of people and types of personal information;
- cause, who may have the information, likely harm, and containment steps;
- whether affected people and operators have been told, and if not, why;
- any other authorities notified.
Update OPC when material facts change, using the PBN reference NotifyUs issues. Print or save a copy of the notification for the incident file.
8. Notify affected people
For a notifiable breach, notify each affected individual as soon as practicable, directly where we hold accurate contact details (email, phone, or in person). A notification must include the matters in Privacy Act s 117(2):
- a description of what happened and what information was / was not involved;
- whether we know who may have the information (do not name them unless needed to prevent a serious threat to life or health);
- what we are doing to reduce harm;
- what the person can do to protect themselves;
- confirmation that the Privacy Commissioner has been notified under s 114;
- their right to complain to OPC and how to do that (www.privacy.org.nz);
- a Helitronics contact for questions: info@avisyst.com.
Public notice
If it is not reasonably practicable to notify people individually (unknown identities or no usable contact details), give public notice that is free to access on app.avisyst.com and in at least one other channel likely to reach those people (Privacy Regulations 2020, regulation 12). The notice must:
- describe the breach without identifying any affected individual;
- state steps people can take to reduce harm;
- confirm OPC has been notified;
- state the right to complain to OPC;
- give a Helitronics contact for enquiries.
Exceptions, representatives, and delay
- Do not notify, or give public notice, if that would prejudice NZ security/defence/international relations, prejudice maintenance of the law by a public sector agency, endanger someone’s safety, or reveal a trade secret (s 116). Still notify OPC.
- If the person is under 16 and notification is not in their interests, or a health practitioner consultation indicates notification would likely prejudice their health, notify a parent, guardian, or other representative instead, after considering the person’s circumstances (s 116).
- You may delay individual or public notice while the security risk of notifying outweighs the benefit (for example until a vulnerability is patched). Revisit that decision as soon as the risk drops. Never delay notifying OPC on that ground.
Even if a breach is not notifiable, Helitronics may still tell affected people or the operator where that is the fair and transparent thing to do.
9. Operator records and section 11
AviSyst stores operational records (DFRs, manifests, safety files, staff profiles the operator maintains) for the operator. Under Privacy Act s 11, information held by an agent for another agency is treated as held by that agency. OPC’s position:
- If Helitronics only holds the information for the operator and does not use it for Helitronics’ own purposes, the operator notifies OPC and affected people. Helitronics must tell the operator immediately and help contain and investigate.
- If Helitronics also uses the information for its own purposes (for example service security, crash diagnosis, or support), both Helitronics and the operator may have to notify. We will agree who speaks to affected people (usually the operator, as they have the relationship) and make that clear in the notice.
Helitronics remains responsible for notifying OPC and individuals for AviSyst account data, authentication identifiers, crash diagnostics, and marketing-site data that we collect as an agency in our own right.
10. Other agencies
Consider, without sending extra copies of personal information:
- CERT NZ — cyber incidents: www.cert.govt.nz
- New Zealand Police — crime, theft, or immediate safety risk
- Netsafe or IDCARE — support for affected people where identity misuse is likely
- the operator’s Chief Pilot / safety manager, where aviation records are involved
- insurer, legal adviser, and Apple/Google only if their incident channels are required
Do not notify the Civil Aviation Authority solely because of a privacy incident unless the operator’s exposition or another aviation rule requires it, or flight safety is affected.
11. Records and review
The Privacy Officer keeps an incident file (not in public git) with:
- date/time reported, contained, assessed, and notified;
- facts known at each stage and the s 113 harm assessment;
- decision to notify or not, with reasons;
- NotifyUs reference, copies of notices, and operator communications;
- root cause, fix, and follow-up date.
After a notifiable breach, or after a serious near miss, complete a short review within 15 working days: what failed, what we changed, and whether staff need a briefing. Practice this procedure at least once a year (a tabletop exercise is enough).
Access and correction requests (IPP 6 and 7) are separate from breaches. Respond as soon as reasonably practicable and within 20 working days unless the request is transferred to another agency (Privacy Act ss 44 and 63, as amended 24 September 2025). Time may be extended with written reasons within those 20 working days (s 48).
12. AviSyst examples
| Scenario | Likely path |
|---|---|
| DFR PDF emailed to the wrong staff member in the same company | Contain (recall / ask delete). Assess sensitivity (passenger names, crew, times). Often not “serious harm” if a trusted colleague returns it unopened — still log it. If the PDF includes a child’s details, next-of-kin, or went outside the company, reassess as notifiable. |
| Passenger manifest visible to another operator because of an access-control bug | Shut the path immediately. Treat as likely notifiable. Tell the affected operator(s). Helitronics notifies OPC for the system failure; operators notify (or we notify on their behalf) people we can identify. |
| Lost unlocked phone with an open AviSyst session | Revoke sessions, change passwords, remote-wipe if possible. Harm depends on what was cached and whether the device was found. Assess s 113; notify if serious harm is likely. |
| Ransomware or inability to access operator records | This is a privacy breach even without a leak. Notify OPC if serious harm is likely (including inability to operate safely or identity data held to ransom). CERT NZ and the operator the same day. |
| Firebase / Google / SendGrid reports a provider breach | Treat their notice as Helitronics becoming aware. Contain with the provider. Assess AviSyst data in scope. Notify operators. Notify OPC if notifiable. Do not wait for the provider to notify affected individuals on our behalf unless we have confirmed they will, and when. |
13. Contacts
Helitronics Limited
NZBN 9429043337231 · GST 120-820-540
AviSyst Privacy Officer:
info@avisyst.com
Privacy Policy:
https://app.avisyst.com/privacy.html
This procedure:
https://app.avisyst.com/privacy-breach.html
Office of the Privacy Commissioner: www.privacy.org.nz · NotifyUs: notify a breach