AIROVIA
Compliance

Data Protection

AIROVIA applies governance-oriented data protection practices designed for public-sector, utility, and critical infrastructure engagement—prioritizing security, minimization, accountability, and privacy-by-design principles.

Last updated: 2026-01-03

1. Core Principles

AIROVIA’s approach is based on internationally recognized practices and applicable legal requirements. We aim to process data lawfully, transparently, and proportionately to the engagement objective.

2. Security Controls (High-Level)

Control selection depends on deployment scope and risk profile. For sensitive engagement contexts, AIROVIA may apply enhanced controls aligned with recognized information security frameworks.

3. Vendor and Subprocessor Management

Where service providers are used for hosting, communications, or operations support, AIROVIA applies vendor due diligence commensurate with the engagement context, including confidentiality obligations and appropriate safeguards.

4. Incident Response

AIROVIA maintains an incident response approach intended to identify, contain, and remediate security events. Where legally required, notifications will be made to relevant stakeholders and/or competent authorities.

5. Retention and Disposal

Data is retained only for as long as necessary to support engagement, meet compliance obligations, or resolve disputes. Disposal methods are designed to prevent unintended recovery.

6. Data Subject Requests

Subject to applicable law, individuals may request access, correction, deletion, or restriction of personal data. Requests can be submitted to info@airovia.io.

7. Public Sector and Utility Engagement

Where engagement relates to government or utility programs, additional governance and audit expectations may apply. AIROVIA is prepared to align documentation, access controls, and reporting practices with institutional requirements as part of a formal engagement process.

© AIROVIA TermsPrivacy PolicyData Protection