App Privacy Policy
This policy covers the Walk‑Check mobile application. Data processed through the forms on this website is covered by the separate website privacy policy.
1. Who is the controller
The app is used by aviation organisations: flying clubs, aircraft rental operators and ground handlers. For the walkaround records created in the app, your organisation is the controller, that is the one that gave you access. Walk - Check Systems s. r. o. operates the service and acts as a processor; the exact split is set out in the data processing agreement concluded with your organisation. The service is run for us technically by STENVARD s. r. o. as a sub-processor under a data processing agreement.
Walk - Check Systems s. r. o., IČO 55973426
Registered seat: Bakulínyho 1177/9, 980 61 Tisovec
E-mail: office@walkcheck.eu
2. What the app collects
- Video of the walkaround. The footage you record while walking around the aircraft.
- Phone motion. The gyroscope is used to derive which position around the aircraft you were standing at and for how long. It is data about your movement during the walkaround. The course of the phone’s rotation is sent to the server together with the record.
- A single location fix when you prepare a walkaround. The app asks for permission and reads one position to suggest the place of the walkaround from the nearest airfield. It requests coarse location only: 5 km accuracy is enough to recognise an airfield. The coordinates never leave the phone, are not sent to the server or into the record, and only the place name goes in. You can decline the permission; the app keeps working and you type the place yourself.
- Walkaround details. Aircraft registration, place (the app suggests it from the nearest airfield; you can overwrite it or type your own), walkaround type and, where relevant, a rental reference or, for training, the student’s name.
- Your identity. The email you sign in with and an internal account identifier. Both also appear in the PDF report for your organisation; the proof shared with a third party and its PDF carry a pseudonym instead. The account also keeps a record of when and which version of the terms you accepted.
- Technical details of the recording. Resolution, frame rate, codec and a checksum of the file.
- A photo of the placard, if you use it. The app can read the aircraft registration from a photo. When you do that, the photo is sent to our server and on to Amazon Bedrock in European AWS regions, which reads the text from it. The photo is not stored anywhere; it is processed and discarded. It is used only when you tap for it; nothing is photographed automatically.
- Data you enter about others. The email of a member you invite to the organisation, and the organisation’s billing details (name, company ID, address, invoicing email) if you fill them in.
3. What the app does NOT collect
- No audio. The microphone is never used. Only picture is recorded.
- No location tracking. The app does not follow you while recording and does not send anywhere the coordinates it reads from the phone: the single location fix taken when you prepare a walkaround only suggests the place and stays on the phone.
- No contacts or advertising identifiers. The app reads nothing from Photos and adds to them only a still frame of a walkaround video that you save yourself in the player (section 11).
- No advertising. The app contains no third party advertising or tracking library and uses no advertising identifiers. The app does measure screen usage; that is covered separately in section 5.
4. People who appear in the footage
The walkaround takes place on an apron or in front of a hangar, so other people inevitably enter the frame. Before the record is sealed, the server blurs a person whose face is visible in the frame; someone who keeps their back turned the whole time, and the hand of the person filming, stay unblurred. Only the blurred version leaves our storage: it is what plays in the app and in the console, and what the PDF and the shared link are made from.
We keep the original recording. Blurring is processing that can go wrong: it can fail or blur badly, and without the original the record would be lost. The original therefore stays in closed storage with no public access, encrypted, in the same AWS region in Frankfurt. We do not release it to your organisation or to anyone you send the record to; only our blurring oversight may look at it. The record’s seal carries the digest of both the original and the blurred version. After 30 days the original moves to an archive storage class, and it is deleted together with the record (section 8).
5. Measurement of app usage
The app measures which screens are used so that we know what gets in people’s way in the field. What is sent is the screen name, the app version, the time, a random number for the app launch and a random number stored locally in the app. The last one persists between launches, so it is a persistent pseudonymous identifier.
What is not sent: the aircraft registration, any record identifier, location, or a system device identifier. That random number cannot be linked to a specific person outside this app.
The data is received by a service on app.kovrin.dev, operated by our technology partner STENVARD s. r. o., and from there it goes to the Conseto analytics service. As with any connection over the internet, the service also receives the phone’s IP address and the app identifier (user agent) and passes them on to Conseto.
6. What it is used for
- To evidence that the walkaround happened, in what scope and when.
- To settle a dispute on aircraft handover and return about who caused damage.
- With your organisation’s consent, also to train the model that recognises aircraft parts, in the Learning fleet programme. The consent is given by the organisation’s administrator in the app, who can change it at any time in Organisation. Only blurred footage from walkarounds is used for training, never the original. Without that consent the organisation’s records are not used for this purpose.
7. Where the data is stored
Walkaround records and your account are stored in Amazon Web Services in the Frankfurt region (eu-central-1), that is inside the European Union. The placard photo is processed by Amazon Bedrock in European AWS regions (section 2). Usage measurement data (section 5) is stored by the Kovrin and Conseto services, both operated in Frankfurt. Two things go beyond these services. First, a cryptographic digest of the record (32 bytes) is sent to an independent time stamping authority (freetsa.org) so that it can be proven the record existed at that time. The digest contains no video and no personal data, and nothing can be reconstructed from it. Second, on Android only: the app includes the Google ML Kit library, which reads QR codes on the phone itself, and that library on its own sends Google diagnostic data about how it runs (device, installation identifier, performance). The app cannot switch this off.
8. How long we keep records, and when they are deleted
Records are kept as evidence for at least four years. This is tied to the limitation period of the dispute the record is meant to settle. During that time the evidence video can be played straight away; after that it moves to a deep archive and is kept there as evidence.
To be plain about it: a sealed record cannot be altered without it showing. It is held by a seal, a hash chain and a timestamp, and anyone can verify that independently of us. This is deliberate, not a limitation: if a face could be removed after the fact, so could damage, and the record would stop being evidence.
A sealed record is not deleted directly by whoever recorded it, nor by your organisation: its deletion is requested. After the request the record is hidden in the organisation and Walk‑Check keeps it as evidence, so that claims arising from the walkaround can be established. We actually delete it only on a justified request, and only as an exception (for example when a person is in the frame and there is no reason to keep the record), and for test footage that is not evidence.
A record that is not yet sealed can be cancelled straight away in the app by whoever recorded it.
Under irreversible storage no one can delete a record for four years, not us and not our cloud administrator. Only some records from the first months of operation are stored that way, and every record states it itself, in its PDF and on the shared link.
When a record is actually deleted, the video, the stills and the original are deleted and shared links are revoked. The chain of proofs permanently keeps the walkaround details (registration, place, time, type, any rental reference or student’s name), the digest, the signature and a trace of who deleted the record, when and why: without them, verification of the other records would stop adding up.
This is why persons are blurred before sealing rather than after.
9. Your rights
You have the right of access to your data, to rectification, to restriction of processing, to portability and to object to processing. You exercise them with your organisation as the controller, and we will assist it in doing so.
The right to erasure is limited for a sealed record: we keep it as evidence for establishing claims arising from the walkaround and delete it only on a justified request (section 8). It is also limited for a record under an irreversible lock and for the data that remain in the chain of proofs after a record is deleted (section 8). For everything else (your account, your email, a record that is not yet sealed) it is not limited.
If you believe your data is being processed unlawfully, you may lodge a complaint with the Slovak Data Protection Authority.
10. How to delete your account
There are two ways to do it and both lead to the same result:
- Delete it yourself in the app: on Home tap your initials to open the Account screen, then Delete account. The deletion happens immediately.
- Or write to office@walkcheck.eu from the address the account is registered to. We will delete it and confirm the deletion to you.
What is deleted: the login account, the name and email in your account, and your membership of the organisation.
What remains: the records you made, kept in the organisation as evidence (section 8). Deleting the account does not delete them; you can ask for a sealed record to be deleted before you delete the account. They do not carry your name or email: the PDF for the organisation shows the internal account identifier instead, and the shared proof and its PDF show a pseudonym, a short string that cannot be traced back to you. If you were invited to the organisation, the invitation with your email address stays with the organisation that sent it. If you asked for a change of the organisation’s plan, its history also keeps the email address the request came from.
You do not have to delete the account. For a sealed record you made, you request deletion in the app in the record detail; a record that is not yet sealed you cancel yourself. To have another record or other data deleted, ask your organisation or write to office@walkcheck.eu. Only the limit from section 8 applies.
11. Permissions the app asks for
- Camera. Without it there is nothing to record; it is the core of the app.
- Internet. To upload the record to the server.
- Location, coarse only. Once when you prepare a walkaround, to suggest the place (section 2). You can decline it.
The camera is the permission the app always asks you for, location when you prepare a walkaround; on iPhone it additionally asks for permission to add to Photos only at the moment you save a still frame of a walkaround video in the player; never otherwise. In the Google Play permission list the Android version additionally shows storage, network state and vibration: these come from the libraries the app is built on, are never requested from you, and serve the app's own files and the phone's tap feedback. The app uses nothing else.
12. Contact
For data protection matters write to office@walkcheck.eu.
13. Changes
We may update this policy. The date of the last change is shown at the top. We will inform your organisation of any material change.