Privacy policy
Website Privacy Statement
Effective Date: 25.09.2026
Last Updated: 25.09.2026
1. Introduction
At GM Helicopters, protecting your privacy is a priority. As an EASA-approved CAMO / MRO / Operator, we handle personal data in strict compliance with the EU General Data Protection Regulation (GDPR – Regulation (EU) 2016/679) and applicable aviation regulations.
This statement explains how we process personal data collected through our website, including contact forms, CV submissions and regulatory reporting functions.
2. Data Controller
The Data Controller responsible for your personal data is:
GM Helicopters SIA
M SOLA, Jumprava Parish, Ogre District, LV-5022, Latvia
Email: info@gmhelicopters.com
Phone: +371-65068350
Data Protection Officer (DPO): aigars@gmhelicopters.com
3. What Data We Collect
a) Data you provide directly
- Contact forms: name, email, phone, message content
- Career applications: CV, cover letter, work history, qualifications, licenses, certificates, references
b) Data collected automatically
- Cookie and usage data (see Section 10 – Cookies)
4. Purposes & Legal Basis of Processing
|
Purpose |
Examples |
GDPR Legal Basis |
|
Respond to contact form enquiries |
General enquiries, customer support |
Art. 6(1)(f) Legitimate interest |
|
Recruitment & CV processing |
Evaluating candidates for employment, verifying qualifications & licenses |
Art. 6(1)(b) Contract (pre-contractual steps) |
|
Staff licensing & competence management |
Verification of Part-66, training, recurrent qualifications |
Art. 6(1)(c) Legal obligation |
|
Website functionality & analytics |
Cookies, usage tracking, security logs |
Art. 6(1)(f) Legitimate interest |
5. Recipients of Personal Data
- Internal staff with a need-to-know basis (e.g., HR, compliance, quality, IT)
- Approved service providers (hosting, IT, analytics) bound by GDPR-compliant contracts
- Regulators (EASA, National Aviation Authorities) where required under EU aviation safety law
- Authorities in the event of a legal obligation (e.g., accident/incident investigations)
We do not sell personal data to third parties.
6. International Data Transfers
Where data is transferred outside the EEA, we apply safeguards such as:
- EU Standard Contractual Clauses (SCCs), or
- Transfers to countries with an EU adequacy decision.
7. Retention Periods
- Contact forms: retained up to 1 year
- Job applications:
- Recruited staff: kept in personnel file for 3 years after employment ends (aligned with aviation recordkeeping requirements)
- Non-recruited applicants: kept for 2 years
- Spontaneous applications: max 1 year
- Cookies/log data: see Cookie Policy for details
8. Your GDPR Rights
You have the right to:
- Access, rectify, or erase your data
- Restrict or object to processing
- Withdraw consent at any time (for consent-based processing)
- Receive your data in a portable format
- Lodge a complaint with your National Data Protection Authority
9. Security Measures
We use organisational and technical safeguards including:
- Secure servers (TLS/SSL encryption)
- Role-based access control and authentication
- Regular audits in line with aviation safety and IT standards
- Staff training on GDPR and aviation data protection obligations
10. Cookies & Tracking
Our website uses cookies to:
- Enable core functionality (session management)
- Improve performance and user experience
- Analyse usage (with anonymised analytics)
Non-essential cookies will only be placed with your consent. You may manage or block cookies in your browser. See our Cookie Policy for full details.
11. Updates
We may update this Privacy Statement to reflect legal, regulatory, or operational changes. Updates will be posted on this page with the effective date.