Privacy Policy
This policy explains what information Contract4Me collects, how we use it to match aviation professionals to contracts, and the choices you have. It applies to contractors, clients and visitors to our platform.
1. Information we collect
Account details (name, email, role), professional data you provide (licences, ratings, availability, work preferences) and documents you upload for verification. For clients, we collect company and staff-request information. We also collect usage and device data to keep the service secure.
2. How we use your information
To operate the matching engine, verify credentials, coordinate assignments, process timesheets and payments, and communicate about your account. Candidate identities shown to clients are anonymised until a proposal is accepted.
3. Sharing and disclosure
We share only what is necessary: a placed contractor’s safe identity with the hiring client. We never sell personal data. Bank details, passport data and contact information are never exposed to clients. We do not currently use a third-party payment processor — bank details are held solely so that we can pay you, are visible only to you and our staff, and are never included in invoices or emails; you can always see and export your own. Some of the providers that process data on our behalf, and where that processing happens, are described in sections 7 and 8.
4. Data retention
We keep records for as long as your account is active and as required for tax, compliance and audit obligations. You can request deletion at any time from Account & Privacy.
5. Your rights (GDPR)
You may access, correct, export or delete your personal data, and object to certain processing. Use the export and delete tools in Account & Privacy, or contact our Data Protection Officer.
6. Contact
Questions about this policy? Email privacy@c4m.aero and we’ll respond within 30 days.
7. Automated document checks (AI)
Documents you upload — passports, licences, training and type certificates, CVs — and the receipts and timesheets you submit are sent to our AI provider, Anthropic, and read by its Claude models so the details on them can be extracted; your identity and qualification documents are also checked against your profile. Alongside the file we send only what the check needs: the name on your profile, and for a type-rating certificate the aircraft types you have declared. These checks assist our team — they do not decide anything on their own. An automated check records its own result on the document, receipt or timesheet it read, and may tidy a document’s title; you can see those results on your own documents. What the check reads reaches your profile only after a person confirms it — an admin for document verification, or you for the details taken from your CV — and activating a contractor account is always a manual admin action. The operational information we give our internal operations assistant is aggregate counts and category labels only; questions our team types into that assistant are also sent to the AI provider, and can contain whatever the person typing includes. Anthropic’s commercial API terms provide that content submitted through the API is not used to train its models; that is a commitment from our provider rather than something we can verify ourselves, and we never license or sell your documents for AI training.
8. Where your data is stored and the law that applies
Your account records, profile data and the documents you upload are held in a single Supabase project provisioned in the European Union (Frankfurt, Germany). Documents sit in a private storage bucket in that project and are never served from a public URL. Some of the providers that help us run the platform — including our AI provider and our email delivery provider — may process data outside the EEA; we are finalising with counsel the safeguards for those transfers, and this policy will name each provider and the basis it relies on. We handle personal data under the EU GDPR and, where it applies, the UK Data Protection Act 2018.