Legal
Privacy Policy
This policy explains what personal data Akam Innovations collects through Cooman, why we collect it, who we share it with, how long we keep it and what you can ask us to do with it. It covers the Cooman web application, the Cooman Field mobile application for Android and iOS, and this website.
1. Who we are and who controls your data
Cooman is an integrated aviation management system published by Akam Innovations ("Akam", "we", "us"). Cooman is sold to aviation organisations: operators, CAR-145 and Part-145 maintenance organisations and CAMO organisations. We refer to those organisations as customers.
Almost everyone who uses Cooman does so because their employer gave them an account. That distinction matters for this policy, so we state it plainly:
- Your employer is the controller of the operational records. Flight records, journey logs, duty and rest hours, maintenance signatures, licences, authorisations and any other record you create in Cooman as part of your job belong to the customer organisation. It decides why they are held and for how long. Akam processes them on that organisation's instructions, under a contract. If you want a record corrected or explained, your organisation is the right first stop.
- Akam is the controller of the account and service data. Your login identity, security settings, support conversations, security logs and the technical data needed to keep the service running and safe are ours to manage, and this policy governs them.
- Akam is the controller of website and enquiry data. Anything you send us through cooman.app or by email to a Cooman address is handled by us directly.
We do not sell personal data. We do not use personal data held in Cooman for advertising, and we do not share it with advertising networks or data brokers.
2. What data we collect
We collect only what the service needs in order to work, to be secure and to produce records that stand up to a regulatory audit.
2.1 Account and identity data
- Name, employee or staff identifier, job role and organisation
- Work email address and work telephone number
- Authentication data: password hash, second factor enrolment, session tokens
- Permissions and role assignments within your organisation
2.2 Professional and licence data
Where your role requires it, your organisation records aviation credentials in Cooman so the system can refuse work you are not qualified or current to do. This can include licence numbers and validity, type ratings and route currency, medical certificate expiry, recurrent and continuation training records, and the scope of a certifying staff authorisation.
2.3 Operational records you create
Journey and technical log entries, defect reports, task card sign offs, certificates of release to service, duty and rest times, rosters, occurrence and safety reports, work orders and stores movements. These records identify who did what and when, because that is precisely what an aviation record is for.
2.4 Signature and confirmation data
When you sign a record electronically we store the fact of the signature, the identity it was bound to, the time, and the device and method used to confirm it. We never receive or store your fingerprint or face data. Biometric matching happens entirely on your own device using the operating system's secure hardware, and the device tells Cooman only that the check succeeded.
2.5 Content you attach
Photographs, voice notes, scans and documents you attach to a record, together with the record they belong to and the account that added them.
2.6 Device, log and diagnostic data
- Device model, operating system version and app version
- IP address, approximate region derived from it, and language setting
- Sign in events, security events and audit ledger entries
- Crash reports and error diagnostics, used to fix faults
2.7 What we do not collect
- We do not collect your device's precise or background location.
- We do not collect contacts, calendars, SMS, call logs or your photo library as a whole.
- We do not collect biometric templates, fingerprints or facial geometry.
- We do not collect health data, financial account data or any special category data other than the professional medical certificate expiry described in section 2.2.
- We do not track you across other applications or websites.
3. Device permissions used by the mobile app
Cooman Field asks for a small number of permissions. Each one is requested at the moment it is needed, is explained in the app when it is asked for, and can be refused. Refusing a permission disables the feature that needs it and nothing else.
| Permission | Why the app asks for it | If you refuse |
|---|---|---|
| Camera | Photograph a defect, a component data plate, a part tag or a paper document, and attach it as evidence to a record. Also used to scan barcodes and QR codes on parts and tooling. | You can still use the app, but you cannot capture photographic evidence or scan a part label. |
| Microphone | Record a short voice note against a defect or task when typing at the aircraft is impractical. Recording only ever starts when you press and hold the record control. | Voice notes are unavailable. No audio is captured at any other time. |
| Biometrics and device credential | Confirm that the person signing a record is the account holder, using the fingerprint, face or passcode already set up on your device. | You confirm signatures with your Cooman password and second factor instead. |
| Network access | Sync records with your organisation's Cooman environment. | The app works offline and syncs later, but it cannot be set up without a first connection. |
| Notifications | Alert you to a defect raised on your aircraft, a task assigned to you, or a record awaiting your signature. | You will not receive alerts. Everything is still visible in the app. |
4. Why we use it and on what legal basis
| Purpose | Data used | Basis |
|---|---|---|
| Providing the service to your organisation | Account, professional, operational and attached content | Performance of a contract with the customer; legitimate interest of the customer as employer |
| Meeting aviation regulatory obligations, including airworthiness and duty time records | Operational, professional and signature data | Legal obligation of the customer under applicable civil aviation regulation |
| Authenticating you and preventing unauthorised access | Account, security log and device data | Legitimate interest in securing the service |
| Diagnosing faults and improving reliability | Crash reports, error diagnostics, app and device version | Legitimate interest in a working product |
| Support you ask us for | Your message and the account context needed to answer it | Performance of a contract; your request |
| Responding to a sales enquiry from this website | The name, organisation and contact details you send us | Steps taken at your request before entering a contract |
We do not use your data to train machine learning models, and we do not make decisions producing legal effects about you by automated means alone. Where Cooman blocks an action, for example refusing a roster assignment because a currency has expired, it is applying a rule your organisation configured from the regulation, and a named person in your organisation can review it.
5. Who we share it with
We share personal data only in these situations.
- Within your organisation. Colleagues see what their role permits. A certifying engineer's signature is visible on the record they signed, because that is the point of the record.
- Service providers who run the infrastructure. Cloud hosting, database, storage, content delivery, email delivery, error reporting and push notification providers, engaged under contract, permitted to process data only on our instructions, and bound to confidentiality and security obligations.
- Regulators and auditors. Where your organisation is required to produce records to a civil aviation authority or an auditor, it does so from its own Cooman environment. We do not hand over customer records to a third party unless the customer instructs us to or the law requires it.
- Where the law requires it. In response to a valid legal process. We will tell the customer unless we are prohibited from doing so.
- In a corporate transaction. If Akam is acquired or reorganised, data may transfer as part of that transaction, subject to this policy continuing to apply.
We do not share personal data with advertisers, data brokers or analytics companies that would use it for their own purposes.
6. How we protect it
- Encryption in transit using TLS, and encryption at rest for stored data and backups.
- Separation between customer organisations enforced in the database itself, so one organisation cannot read another's records.
- Role based access control, with permissions granted against a named role rather than shared logins.
- Second factor authentication on account sign in and on signing actions.
- An append only audit ledger recording consequential actions, which we do not permit to be edited.
- Credentials held in the device's secure keystore on mobile, never in plain application storage.
- Least privilege access for our own staff, granted for a reason and logged.
- Regular patching, dependency review and security testing.
No system is perfectly secure. If a breach affects your personal data we will notify the affected customer organisation without undue delay, and notify the relevant supervisory authority and affected individuals where the law requires it.
7. How long we keep it
Aviation records are kept far longer than ordinary business records, because the regulation requires it. In broad terms:
| Record | Retention |
|---|---|
| Airworthiness, component life, maintenance and release records | For the life of the aircraft or component and for the period the applicable regulation requires afterwards |
| Flight, journey log and duty time records | For the period required by the applicable operations regulation, typically several years |
| Audit ledger entries | For the life of the customer's environment, since they are the evidence the records are trustworthy |
| Account and access data | While the account is active, then as needed for security and legal purposes |
| Support conversations | Up to 24 months from the last message |
| Website enquiries | Up to 24 months, unless a customer relationship begins |
| Backups | Rolling, with deleted data ageing out on the backup cycle |
The customer organisation sets its own retention periods within these limits, and it decides what happens to its records when its contract ends. See section 12 of the Terms of Service.
8. Deleting your account and your data
You can ask for your Cooman account to be deleted at any time. There are two routes, and which one applies depends on how you got the account.
8.1 If your organisation gave you the account
Ask your organisation's Cooman administrator to deactivate and delete it. They can do this from the user administration screen without our involvement. If you cannot reach them, write to [email protected] from your work email address with your name and organisation and we will pass the request on and confirm when it has been actioned.
8.2 Requesting deletion directly from Akam
Send an email to [email protected] with the subject "Account deletion request", stating your full name, the email address on the account and the organisation you work for. We will verify that the request comes from you, action it and confirm in writing within 30 days.
8.3 What is deleted and what is not
- Deleted: your login credentials, second factor enrolment, session tokens, notification tokens, device registrations, profile details and contact information, and any support conversation not needed for a legal purpose.
- Retained: aviation records that carry your name because you created or certified them. A journey log entry, a defect rectification and a certificate of release to service are legal records of who did the work. Removing the name would destroy the record's value as evidence and would put the operator in breach of the regulation. These stay for the statutory retention period described in section 7, and are then deleted or anonymised.
- Backups: deleted data persists in encrypted backups until they age out on the normal backup cycle, after which it is gone.
Uninstalling the mobile app removes the app and its local cache from your device. It does not delete your account, so use one of the routes above if that is what you want.
9. Your rights
Depending on where you live, you have some or all of the following rights. Under India's Digital Personal Data Protection Act 2023 these include the right to access a summary of your personal data, the right to correction and erasure, the right to nominate another person to exercise your rights, and the right to a grievance redressal mechanism. Under the UK and EU General Data Protection Regulation they include access, rectification, erasure, restriction, portability, objection and the right not to be subject to solely automated decisions.
- Ask what personal data we hold about you and get a copy of it.
- Ask us to correct data that is wrong or incomplete.
- Ask us to delete data, subject to the retention limits in sections 7 and 8.
- Ask us to restrict or object to a particular use.
- Withdraw consent where we relied on consent, without affecting what we did before you withdrew it.
- Complain to your data protection authority. In India that is the Data Protection Board of India.
Write to [email protected]. We respond within 30 days. If the data is held on behalf of a customer organisation we will forward the request to them and tell you that we have, because they decide it and not us.
10. Children
Cooman is a professional tool for aviation staff. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child's data has reached us, write to [email protected] and we will delete it.
11. International transfers
Customer data is hosted in the region agreed with the customer. Some of our service providers operate globally, so data may be processed outside the country where it was collected. Where that happens we rely on appropriate safeguards, including contractual protections such as standard contractual clauses and, for Indian customers, transfer only to countries not restricted by the Central Government. A customer that requires data residency in a specific country can be deployed that way.
12. Cookies and this website
This marketing website sets no cookies, runs no advertising trackers and embeds no third party analytics. It loads web fonts from Google Fonts, which means Google receives the request for the font file including your IP address. Nothing else on these pages contacts a third party.
The Cooman application at app.cooman.app uses strictly necessary cookies and local storage to keep you signed in and to remember interface preferences. These are required for the application to function and are not used for tracking or advertising.
13. Changes to this policy
We update this policy when the product or the law changes. The effective date and version at the top always tell you which text is current. If a change materially affects how we handle your personal data, we will notify customer organisations by email and, where the change affects app users directly, show a notice in the app before it takes effect. Continuing to use Cooman after a change takes effect means the updated policy applies.
14. Contact and grievance officer
For any question about this policy, a data request, or a complaint about how we handled your personal data:
- Data protection and privacy: [email protected]
- Grievance Officer (India, DPDP Act 2023): [email protected]
- General enquiries: [email protected]
- Support: [email protected]
- Publisher: Akam Innovations, India
If you are unsatisfied with our response you may complain to the Data Protection Board of India, or to the supervisory authority in your country of residence.