How your account, your identity documents and your data are protected.
TJ-Aero is hosted in an ISO/IEC 27001:2022 certified environment.
Our hosting provider, Hostinger, holds ISO/IEC 27001:2022 certification for its information-security management, independently audited by TÜV Thüringen. See their certificate ↗
TJ-Aero is built to meet the EU General Data Protection Regulation (and the UK GDPR) and Sri Lanka’s Personal Data Protection Act, No. 9 of 2022. Here is what that means in practice. Points marked “Checked just now” are tested automatically against the live system when this page loads — if one ever fails, it says so here rather than claiming it.
Lawful and transparent GDPR Arts. 5, 6, 12–14 · PDPA Part I
The Privacy Notice says what we collect, why, on what legal basis, who receives it, where it is stored and for how long. See it
Only what is needed GDPR Art. 5(1)(c) · PDPA Part I
Your passport copy is used only to verify you and is deleted as soon as you are verified. No verified member’s copy is on file.
Security of your data GDPR Art. 32 · PDPA Part I
Passport numbers are stored encrypted. Every connection uses TLS 1.3. Two-factor sign-in is available to everyone, and access to identity documents is limited to verification staff and logged.
Kept only as long as needed GDPR Art. 5(1)(e) · PDPA Part I
Retention periods run automatically every night: activity logs after 12 months, declined registrations after 12 months, deleted accounts’ agreement records after six years.
Activity logs deleted after 12 months GDPR Art. 5(1)(e) · PDPA Part I
No search or activity record older than 12 months is held.
Health information protected GDPR Art. 9 · PDPA special categories
A medical certificate is held only with your explicit consent, and other members never see the document.
Marketing only with consent GDPR Arts. 6–7 · PDPA Part IV
News emails are off unless you ask for them, your consent is recorded, and an unsubscribe is final.
No tracking GDPR Art. 25 · ePrivacy
No analytics or advertising trackers. Pages load their scripts, maps software and fonts from our own server; only map tiles come from OpenStreetMap.
Your rights, in your hands GDPR Arts. 15–22 · PDPA Part II
Download a copy of your data (machine-readable), correct your profile, switch off news emails, or delete your account — all yourself, in Account Settings. Anything else: write to us and we reply within one month. See it
Breaches handled by the book GDPR Arts. 33–34 · PDPA
A written procedure: contain, assess, and notify the data protection authority within 72 hours and affected members where the risk is high.
If you think we have not handled your data properly, tell us first at contact@tj-aero.com. You can also complain to the Data Protection Authority of Sri Lanka (www.dpa.gov.lk) or, in the EU or UK, to your local data protection authority.
Please tell us privately at contact@tj-aero.com before sharing it anywhere else. We read every report and will reply.
No system is perfectly secure, and we do not claim otherwise.
Privacy Notice · Terms & Conditions · AI Policy · Raffles Online Platforms