AviSyst Privacy Policy

Effective 21 August 2026 · Last updated 21 August 2026

This Privacy Policy explains how Helitronics Limited, a New Zealand company and the developer of AviSyst (“AviSyst”, “we”, “us”), collects, uses, stores and discloses personal information in the AviSyst iOS app, Android app, the operations website at app.avisyst.com, and the marketing website at www.avisyst.com.

AviSyst is an invite-only aviation operations product for operators and their authorised staff. It is not a consumer social app, it is not used for advertising, and we do not sell personal information.

If you work for an aviation operator that uses AviSyst, that operator is typically responsible for the operational records it enters (including passenger manifests, payment method notes, flight records, safety reports and staff details). AviSyst provides the software and hosting those operators use to keep those records.

1. Who we are

AviSyst is operated by Helitronics Limited, a company incorporated in New Zealand. NZBN 9429043337231. GST number: 120-820-540.

Privacy questions, access and correction requests, and complaints can be sent to the AviSyst Privacy Officer at info@avisyst.com.

App identifiers: iOS bundle ID and Android package com.helitronics.avisyst.

2. New Zealand privacy law

Helitronics Limited is an “agency” under the New Zealand Privacy Act 2020. This policy is intended to meet that Act as amended by the Privacy Amendment Act 2025, including:

When an aviation operator uses AviSyst to store its operational records, Helitronics often holds that information as the operator’s agent (Privacy Act s 11). The operator remains the agency responsible for that operational information. Helitronics is the agency for AviSyst accounts, authentication, crash diagnostics, and the marketing site.

3. Scope

This policy covers:

The marketing site does not create accounts or take a password. If you use Login there, you are sent to app.avisyst.com, where this policy’s account and operational rules apply. This policy does not cover third-party websites, payment terminals, or other operator systems that are not provided by AviSyst.

4. Device permissions Google and Apple require us to explain

The mobile app requests certain device permissions. We ask only when the related feature is used. You can refuse a permission; that feature will not work until it is allowed. We do not use these permissions for advertising, analytics beyond crash diagnosis, or tracking across other apps and websites.

Permission Why AviSyst uses it
Camera Photograph Weather and NOTAM briefing materials, safety-report evidence, and currency / competency documents. On supported devices, a handwriting pad may use on-device text recognition to convert a printed passenger name into text.
Photos / photo library / media images Attach existing photos or documents for Weather and NOTAM briefings, safety reports, and staff currency records. AviSyst does not require access to your entire library in the background. Photos are selected by you for a specific operational record.
Location (when in use, approximate) Calculate sunrise, first light, sunset and last light, and show an approximate current position in Pilot Tools. Location is requested only while the app is in use. We do not use background location, do not run a location tracking service, and do not sell location data.
Microphone Not used. AviSyst does not record audio.
Contacts, calendar, Bluetooth, motion, tracking (IDFA) Not used for advertising or tracking. We do not request App Tracking Transparency permission.

Android builds request coarse (approximate) location only, not precise GPS permission. iOS may still return a more precise fix if the operating system already has one; we still use that reading only for daylight calculations and the on-screen position display.

5. Information we collect

Account and staff information

Accounts are invite-only. An operator admin adds you before you can create a login. Depending on your role, this may include:

Operational aviation records

Device and technical information

6. Information we collect from someone else (IPP 3A)

From 1 May 2026, when Helitronics collects personal information about you from someone other than you, we must take reasonable steps, as soon as reasonably practicable, to make sure you know: that we have collected it; the purpose; the intended recipients; our name and address; any particular law that authorises or requires the collection; and your rights of access and correction (IPP 3A). IPP 3A does not apply to personal information collected before 1 May 2026.

That happens in AviSyst in these usual cases:

We may not notify under IPP 3A where a listed exception applies — for example the person has already been made aware of the IPP 3A matters, the information is publicly available, notification is not reasonably practicable, or it would prejudice the purpose of collection. Direct collection from you is covered by IPP 3 and this policy.

7. Camera, photos and files

Camera and photo access is used only for operational documents you choose to attach:

AviSyst does not use your camera or photos to build advertising profiles, does not scan your library in the background, and does not share photos with other apps for marketing.

8. Location

AviSyst uses location while you are using the app to calculate first light, sunrise, sunset and last light, and to show an approximate current position in Pilot Tools. That helps crews manage last-light constraints. We request this permission only when you use those features.

9. Passenger names, weights and manifests

Crew may enter passenger information on a flight, including name, seat, body weight (kg), whether the passenger was briefed, route, estimated time and flight type. This is used for:

Passengers do not create AviSyst accounts. Their details are entered by authorised crew acting for the operator. Names may be typed or converted from handwriting on the device as described above.

Passenger records belong to the operator’s operational files. Access is limited to users in that operator’s AviSyst company (and AviSyst support, only as needed to run or repair the service).

10. Payment records

AviSyst does not take card payments, does not use Apple Pay or Google Play Billing for passenger fares, and does not collect card numbers, CVV codes, PIN numbers or full payment-account credentials.

For some flights, crew record how the operator was paid for that passenger flight, for the operator’s own operations and invoicing. That may include:

If a passenger pays by card, that transaction happens on the operator’s own terminal, point-of-sale or accounting system — not inside AviSyst. AviSyst only stores the method and amount the crew enter as a flight record.

Operator invoice numbers and customer names may also be stored against flights for the operator’s administration. That is business invoicing data, not an in-app purchase.

11. How we use information

We do not use personal information to show third-party advertising.

12. Who we share information with

We disclose personal information only as needed:

We do not sell personal information. We do not share it for cross-context behavioural advertising.

13. Service providers

AviSyst uses these categories of providers:

Those providers may process data in New Zealand, Australia and other countries (including the United States). We use them only to run AviSyst.

14. Retention and aviation records

Aviation law and the operator’s exposition / SMS may require flight, duty, training, safety and passenger records to be kept for set periods. AviSyst therefore retains operational records for the operator even if a user deletes their login.

Account credentials and the link between your email and a login are removed when you delete your account (see below). Staff profile fields and historical DFRs, manifests, PDFs, safety files and currency documents remain with the operator until the operator asks us to change or remove them, or until a longer legal retention period ends.

Crash logs are kept only as long as needed to diagnose stability issues. Local photos on a device can be removed when you delete them in the app or uninstall the app.

15. Account deletion

You can delete your AviSyst login from Account Settings in the iOS app, Android app, or website. Deletion removes your Firebase Authentication account so that email can no longer sign in, until an operator invites you again.

Account deletion does not erase all aviation records. DFRs, passenger manifests, payment-method notes, safety reports, duty history and similar operational files are retained because operators must keep them for regulatory periods. If you need a particular operational record changed or removed, discuss that with your operator. The operator can then contact AviSyst at info@avisyst.com if our help is required.

16. Security

We use industry-standard controls appropriate to an operations system, including encrypted transport (HTTPS), access control by company and role, server-side permission checks, and App Check. No method of transmission or storage is completely secure. Please keep your device and password protected and sign out on shared devices.

17. Privacy breaches

A privacy breach includes unauthorised or accidental access, disclosure, alteration, loss or destruction of personal information, or AviSyst being unable to access it (for example ransomware).

If a breach has caused, or is likely to cause, serious harm, it is a notifiable privacy breach. Helitronics must notify the Privacy Commissioner as soon as practicable (the Commissioner expects this within 72 hours of becoming aware) and notify affected people unless a lawful exception applies. Full steps, roles, and examples are in the AviSyst Privacy Breach Procedure.

Report a suspected incident immediately to info@avisyst.com with the subject PRIVACY INCIDENT. If the records belong to an operator, we tell that operator at once so it can meet its own Privacy Act duties.

18. Disclosure outside New Zealand

IPP 12 limits sending personal information to a foreign person or entity. AviSyst’s hosting and email providers process data in New Zealand, Australia and other countries, including the United States (see section 13). We disclose to those providers because we believe on reasonable grounds they are required to protect the information in a way that, overall, provides comparable safeguards to the Privacy Act (including under their contracts with us).

We do not sell personal information overseas. If we ever needed to disclose personal information to a foreign recipient that did not meet IPP 12’s comparable-safeguards tests, we would only do so with your authorisation after telling you that the recipient may not have to protect the information to the same standard as the Privacy Act — unless another IPP 12 ground applied.

19. Unique identifiers

We assign AviSyst identifiers (including a Firebase Authentication user ID and internal staff/company keys) only because they are necessary to run accounts and access control (IPP 13). We do not use another agency’s identifier (for example an IRD number or driver licence number) as our AviSyst user ID.

An Aviation Reference Number (ARN) is recorded where the operator needs it for aviation records. We do not assign ARNs; we store the number the operator or staff member supplies so the operator can use it for that aviation purpose.

20. Your rights

You can ask Helitronics for access to personal information we hold about you (IPP 6) and to correct it (IPP 7). Email info@avisyst.com. We will respond as soon as reasonably practicable, and within 20 working days, unless we transfer the request to another agency (for example your operator) that holds the information. If we need more time we will say so within those 20 working days, with reasons, and tell you that you can complain to the Privacy Commissioner about the extension.

Staff users should usually start with their operator for operational records (DFRs, manifests, duty, safety files). You can still email us and we will help or transfer the request. If we refuse access or correction, we will say so and you may ask us to attach a statement of correction to the record.

If we cannot resolve a complaint, you may contact the Office of the Privacy Commissioner (New Zealand) at www.privacy.org.nz.

Some operators using AviSyst are based in Australia or elsewhere. Those operators remain responsible for personal information they enter, and additional local privacy or aviation laws may apply to them. If European or similar privacy laws apply to you, you may also have rights to access, correction, erasure, restriction, objection and data portability, subject to legal exceptions — including where we or the operator must keep aviation records.

21. Children

AviSyst is a workplace tool for invited aviation staff. It is not directed at children, and we do not knowingly allow anyone under 16 to create an AviSyst account.

An operator’s crew may still record a child’s name and weight on a passenger manifest when that child is carried as a passenger (for example a scenic flight). That information is entered by crew for safety, weight and balance, and the operator’s records. It is not collected from the child through a child-directed experience in the app. From 1 May 2026 the operator should take reasonable IPP 3A steps toward a parent or guardian, unless an exception applies.

22. Cookies, diagnostics and advertising

23. Changes

We may update this policy when the product or the law changes. The “Last updated” date at the top will change. The current version will always be published at https://app.avisyst.com/privacy.html. The Privacy Breach Procedure is at https://app.avisyst.com/privacy-breach.html.

24. Contact and complaints

Helitronics Limited
NZBN 9429043337231 · GST 120-820-540
AviSyst Privacy Officer
Email: info@avisyst.com
Operations: https://app.avisyst.com
Marketing: https://www.avisyst.com
Privacy policy: https://app.avisyst.com/privacy.html
Privacy breach procedure: https://app.avisyst.com/privacy-breach.html