Service scope and controller information
This technical notice covers the website, Flight Desk API, operations console and iOS app offered under the AKINCI JET brand. The official identity/name of the controller under the Personal Data and an address suitable for formal notices must be verified by the authorised operator before publication and displayed on this page. The current service contact channels are info@akincijet.com and +90 532 410 32 79.
Personal data processed
In the current production release, user accounts are created and verified only through Sign in with Apple. This may involve Apple’s app-specific user identifier (sub), Apple’s verified email or private relay address, name if supplied, authorisation data, and an internal user identifier generated on the server. We may also process an email address that you provide in a flight or contact form. The email one-time-code implementation remains in the software but is administratively disabled; until a verified delivery provider is configured, that path does not create an account or verification challenge and does not send a code.
When you send a flight or contact request, we may process your full name and telephone number; the account email or private relay address supplied by Apple and any email address you provide in the form; origin and destination, outbound and optional return date, passenger count, aircraft preference, and notes about baggage, pets or other special requests. Please do not enter sensitive or unnecessary information in free-text fields.
For service security we may process the connection time, a one-way digest derived from the IP address, rate-limit records, audit records and other limited technical data. After a flight request is submitted, its status, operations offers, customer responses, messages and approved flight details may also be recorded.
On the device, the mobile app stores the account session credential in iOS SecureStore and the language preference and multiple flight drafts in AsyncStorage. A draft may contain route, date/time, passenger, baggage, pet, transfer, aircraft, notes and contact details. Drafts are not sent to the AKINCI JET server until submission; the relevant draft is removed after successful submission. Submitted requests, offers, customer responses, messages and operational approval are linked to the server-side account and retrieved through the server session.
If push functionality is separately configured and an iOS token is submitted, the token, platform and language may be linked to the request. Token registration alone does not send a notification; delivery requires a separately configured provider and sending worker.
Purposes of processing
Data is processed to receive and validate your request, assess suitable air-taxi or jet options, communicate quotations and operational details, coordinate connections and transfers, provide support, prevent misuse, protect information security and comply with applicable legal obligations.
Collection method and legal grounds
Data may be collected electronically through website and mobile-app forms, the Flight Desk API, operations messages, email, telephone or WhatsApp when you choose that channel. The legal ground applicable to each data category and transfer, and whether consent is required, must be verified before publication against the actual operating model.
Recipients and transfers
Only where necessary, data may be disclosed to technical processors for functions such as hosting and delivery of email communications chosen by the user; to Apple as the only enabled user authentication and authorisation provider in the current production release; to suitable licensed aircraft operators, ground-handling, transfer, FBO, catering and similar service providers needed to assess or fulfil the flight; and to public authorities legally entitled to receive it. Email sign-in is administratively disabled; until a verified delivery provider is configured, no verification challenge is created, no code is sent and no data is disclosed to an email-delivery provider for that purpose. Every disclosure is limited to its purpose and the minimum necessary data.
If a technical provider, or an external channel you choose such as WhatsApp, uses infrastructure outside Türkiye, an international transfer takes place only when the conditions and safeguards required by applicable Personal Data provisions are met. The external provider’s own privacy terms also apply when you choose that channel.
Retention periods
The software does not select a default business-record retention period. The operator must document and publish the periods that apply to uncompleted requests, offers, approved flights, messages, email, audit records, provider logs and backups according to verified legal and operational requirements.
If AKINCI_DATA_RETENTION_DAYS is configured and the scheduled purge job is run, it deletes only requests in closed or cancelled status whose last update is older than the configured period, together with linked records. Active, reviewing or approved requests are not selected by this automatic purge. The job does not itself delete email mailboxes, external-provider logs or backups.
Rate-limit buckets use a one-way IP digest and a 10-minute window; expired buckets are removed by later rate-limit operations. Language and drafts are stored in AsyncStorage and the account session credential in SecureStore. Sign-out and in-app account deletion explicitly clear this local account data and the drafts. Because SecureStore data may persist after app removal depending on operating-system behaviour, removing the app alone is not represented as guaranteed deletion of every local credential.
In-app account deletion permanently removes the account and its linked requests, offers, messages, responses and approvals from the live database. If Apple is linked, revocation of the Apple authorisation is attempted; if the first attempt fails, encrypted revocation data is queued for retry. Email mailboxes, provider logs and backups are not automatically erased by this action. Any operational or legal retention requirement for approved-flight records must be decided separately before release.
Your rights and applications
Subject to the conditions in Article 11 of the Personal Data, you may ask whether your data is processed, request information, question whether it is used for its purpose, learn recipients in Türkiye or abroad, correct incomplete or inaccurate data, request deletion or destruction, ask that correction or deletion be notified to recipients, object to a result produced exclusively by automated analysis, and seek compensation for unlawful processing.
Send your request to info@akincijet.com with the subject “Personal Data Request”, or call +90 532 410 32 79 for information about the request channel. State the scope of your request and contact details that help us identify the relevant record. We request only necessary and proportionate information for identity verification. Requests are answered free of charge within the applicable legal period, unless an officially permitted cost applies.
Security, children and updates
We apply transport security, access restrictions, data minimisation and abuse-prevention measures. No electronic system can guarantee absolute security; if an incident occurs, applicable mitigation and notification obligations are followed.
The forms and mobile app are intended for adults authorised to make a flight request. We do not seek to collect children’s contact details knowingly. If an adult responsible for a flight must provide information about a child passenger, only the minimum operationally necessary information should be shared.
This notice may be updated when the service or law changes. The current version and effective date are published on this page.