TachTab Privacy Policy
Last updated: July 29, 2026
Effective date: July 29, 2026
Saibernetic OÜ ("we", "us", "our", or "TachTab") is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use the TachTab software platform, website, and related services (collectively, the "Service").
1. Who We Are and How to Contact Us
Saibernetic OÜ is a private limited company (osaühing) registered in Estonia.
- Data Controller Name: Saibernetic OÜ
- Registry Code: 16058488
- Registered Address: Raadiku tn 8b/2-80, Lasnamäe linnaosa, 13812 Tallinn, Estonia
- Trading Name: TachTab
- Website: www.tachtab.com
- Privacy Contact Email: hello@tachtab.com
If you have any questions about this Privacy Policy or how we handle your personal data, please contact us at hello@tachtab.com.
2. Our Role: Controller vs. Data Processor
Under the EU General Data Protection Regulation (GDPR), a organization's role depends on who determines the purposes and means of processing personal data. For TachTab, the responsibilities are divided as follows:
2.1 Saibernetic OÜ as Data Controller
We act as an independent Data Controller for personal data collected to establish, administer, and maintain your account and our direct relationship with you. This includes:
- Account registration details (your name, email address, password/auth tokens);
- User roles and group membership links;
- Platform subscription billing records for TachTab services;
- Technical log data, device information, and security audit logs of platform access; and
- Customer support inquiries and direct communications with us.
Reasoning: Saibernetic OÜ independently determines the purpose and technical infrastructure for user account management, platform security, legal compliance, and TachTab billing.
2.2 Saibernetic OÜ as Data Processor (for Group Operational Data)
For the operational flight and co-ownership financial ledger data created within an aircraft group—such as specific flight log notes, engine-hour readings entered by pilots, cost-allocation formulas set by the group, fuel receipt uploads, and member-to-member invoices—the Aircraft Co-ownership Group (represented by the Group Admin) acts as the Data Controller, and Saibernetic OÜ acts as a Data Processor.
Reasoning: The group and its admin decide who is invited into the group, set the financial parameters and hourly rates, control expense splits, and manage their own Stripe merchant relationship. TachTab stores and processes this data strictly according to the group's setup and instructions to deliver the SaaS service.
3. Personal Data We Collect
We collect only the personal data necessary to provide you with a functional, secure financial ledger for shared aircraft ownership:
- Account & Identity Data: Full name, email address, account password (stored securely as a hash), and user role (TachTab operator, Group Admin, or Partner/Member).
- Group Ownership & Membership Data: Group membership associations, co-ownership share percentages, and group settings.
- Flight Activity Data: Flight dates, engine-hour meter readings (start/end), pilot name, and optional flight notes.
- Financial Ledger & Expense Data: Fuel receipts, group expense entries, monthly dues, issued invoices, line items, credit memos, payment amounts, payment timestamps, and Stripe payment identifiers.
- Audit Log Data: An append-only audit trail recording actions that alter financial balances, modify billing rates, or create/settle debts between members.
- Technical & System Data: IP addresses, browser types, access timestamps, and authentication tokens required to keep your session secure.
NOTE No Financial Credentials Stored: Payment card numbers, card expiration dates, CVVs, and bank account credentials never touch TachTab servers. All card payment processing and verification are handled directly by Stripe.
4. Legal Bases and Purposes of Processing
We process your personal data under the following legal bases pursuant to Article 6(1) of the GDPR:
| Purpose of Processing | Data Categories Involved | GDPR Legal Basis |
|---|---|---|
| Providing the Service: Operating your account, logging flight hours, calculating cost splits, generating monthly dues, and displaying statements. | Name, email, group membership, flight records, invoices, ledger entries. | Contract Performance (Art. 6(1)(b)): Processing is necessary to fulfill our contract with you to provide TachTab. |
| Payment Facilitation: Triggering direct charges between members and group Stripe accounts via Stripe Connect. | Member name, invoice amounts, Stripe payment IDs. | Contract Performance (Art. 6(1)(b)): Necessary to carry out requested payment settlements. |
| Accounting & Tax Compliance: Retaining source documents, invoices, credit memos, and transaction audit trails. | Names, invoice details, line items, transaction amounts, Stripe transaction IDs. | Legal Obligation (Art. 6(1)(c)): Mandatory retention under the Estonian Accounting Act (Raamatupidamise seadus § 12). |
| Security & System Integrity: Maintaining append-only audit trails, preventing fraud, protecting against unauthorized access. | IP addresses, login logs, append-only audit trails, session tokens. | Legitimate Interests (Art. 6(1)(f)): Our legitimate interest in securing our platform, preventing fraud, and ensuring financial auditability. |
| Customer Support: Responding to help requests, bug reports, and service inquiries. | Name, email, ticket communications. | Legitimate Interests (Art. 6(1)(f)): Our legitimate interest in providing reliable customer support. |
5. Infrastructure, Sub-processors, and Data Transfers
5.1 Infrastructure and Third-Party Sub-processors
We use reputable third-party infrastructure providers to host and run TachTab. These sub-processors are bound by strict Data Processing Agreements (DPAs) to protect your information:
- Supabase Inc.
- Function: Database storage and user authentication.
- Data Location: Hosted in primary data centers in Dublin, Ireland (eu-west-1).
- Vercel Inc.
- Function: Application hosting and serverless code execution.
- Data Location: Serverless functions execute in Dublin, Ireland.
- Stripe Payments Europe, Ltd. / Stripe, Inc.
- Function: Payment processing, merchant connection, and identity verification.
- Data Location: EU and US.
- Amazon Web Services (AWS) - Amazon SES
- Function: Transactional email delivery (sending monthly statements and invoice notifications).
- Data Location: US West (Oregon), United States (
us-west-2). Transactional emails contain your name, email address and invoice amounts, so this constitutes a transfer of personal data outside the EU/EEA. See Section 5.2 for the safeguards applied.
5.2 International Data Transfers
Your database storage and application execution take place within the European Union — specifically Dublin, Ireland.
Transactional email is sent from the United States. Amazon SES is configured in the us-west-2 (Oregon) region, so the emails we send you — statements and invoice notifications, containing your name, email address and invoice amounts — are processed outside the EU/EEA.
Where a sub-processor (Amazon Web Services, or Stripe, Inc.) processes data outside the EU/EEA, such transfers are safeguarded using legally approved transfer mechanisms under GDPR Chapter V:
- EU-U.S. Data Privacy Framework (DPF): Certified participation by US entities; and/or
- Standard Contractual Clauses (SCCs): Standard data protection clauses adopted by the European Commission.
6. Data Retention and Interaction with the Right to Erasure
6.1 Standard Retention Periods
- Active User Accounts: We retain your account profile data for as long as your account remains active.
- Closed Accounts: If you close your user account, your account login credentials will be erased or permanently anonymized within 30 days.
6.2 Financial Ledger Retention & Exception to GDPR Erasure
IMPORTANT Statutory Retention Notice: Under Section 12 of the Estonian Accounting Act (Raamatupidamise seadus), all accounting source documents, billed invoices, credit memos, payment records, and financial ledger audit logs must be retained for seven (7) years following the end of the financial year in which the transaction occurred.
- Interaction with GDPR Right to Erasure: Article 17(3)(b) of the GDPR provides an explicit exception to the right to erasure where processing is required for compliance with a legal obligation under EU or Member State law.
- What this means for you: If a member leaves a group or requests deletion of their personal data, TachTab will erase their login credentials and personal profile details, but must retain historic financial invoices, credit memos, fuel receipt records, and audit log entries for the full 7-year statutory period. These financial records will be archived securely and restricted solely to tax, accounting, and legal audit purposes.
7. Your Data Protection Rights under GDPR
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access (Art. 15): You have the right to request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16): You have the right to request correction of inaccurate or incomplete personal data.
- Right to Erasure / "Right to be Forgotten" (Art. 17): You have the right to request deletion of your personal data, subject to statutory retention exceptions described in Section 6.2 above.
- Right to Restriction of Processing (Art. 18): You may ask us to restrict the processing of your data in certain circumstances (e.g., while disputing data accuracy).
- Right to Data Portability (Art. 20): You have the right to receive your personal flight logs and financial data in a structured, commonly used, and machine-readable format (such as PDF or CSV export).
- Right to Object (Art. 21): You have the right to object to processing based on our legitimate interests.
To exercise any of these rights, please send an email to hello@tachtab.com. We will respond to your request within one (1) month of receipt.
8. Data Security
We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, loss, destruction, or alteration:
- All network traffic is encrypted in transit using TLS/HTTPS.
- Databases and backups are encrypted at rest using industry-standard encryption protocols.
- Financial ledger logs use an append-only structure to prevent tampering or unauthorized retroactive changes.
- Access to production environments is strictly restricted based on the principle of least privilege.
9. How to Lodge a Complaint (Supervisory Authority)
If you believe that our processing of your personal data infringes the GDPR or Estonian data protection laws, you have the right to lodge a complaint with a supervisory authority.
Our primary supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon - AKI):
- Name: Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
- Address: Tatari 39, 10134 Tallinn, Estonia
- Telephone: +372 627 4135
- Email: info@aki.ee
- Website: www.aki.ee
If you reside in another EU/EEA Member State, you may also lodge a complaint with your local national Data Protection Authority.
10. Updates to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our legal obligations or system features. We will notify you of any material changes by posting the updated policy on our website or sending an email notification at least 30 days before the changes take effect.