Draft for review — these terms are not yet in force.

These documents are working drafts prepared for review by qualified counsel. They still contain bracketed placeholders, they create no obligations, and they do not describe every feature as it exists today. We will publish the final versions before they apply to anyone.

Legal

Privacy Policy

DRAFT v0.1 · last edited 2026-08-19 · not in force

DRAFT v0.1 — 19 August 2026 — prepared for review by qualified counsel; not yet in force.

Key points (non-binding summary — the numbered clauses prevail)

  • Vistason is a business-to-business marketplace. We process personal data about the people who use the Platform for a business (Authorised Users), the directors, representatives and beneficial owners named in a customer's KYC/KYB file, counterparties' staff in deal rooms, and people who contact us or register for early access.
  • PostReach AI Limited is the controller for account, user, KYC, compliance and Platform-operation data. Where a customer uploads inventory or other files that happen to contain personal data, we act as that customer's processor under our Data Processing Addendum.
  • We verify every customer (KYC/KYB) and screen all accounts and every deal against sanctions and export-control lists because the law requires it. Screening "hits" are always reviewed by a person before any decision is taken.
  • We share personal data only with the parties needed to run a deal (the counterparty, [PAYMENT SERVICES PROVIDER], [KYC PROVIDER], forwarders you ask us to contact), with our hosting and tooling sub-processors, and with authorities where required. Transfers outside the EEA/UK rely on adequacy decisions, the EU Standard Contractual Clauses and the UK Addendum.
  • We keep KYC records for [5] years after the relationship ends, transaction records for [10] years and logs for [12] months, unless the law or a dispute requires longer.
  • You have the GDPR rights of access, rectification, erasure, restriction, portability and objection, and may complain to a supervisory authority (in Spain, the AEPD [to be confirmed]).
  • Today the Platform uses only strictly necessary cookies; we will ask for consent before placing analytics cookies.

1. Who we are and how to contact us

1.1 This Privacy Policy ("Policy") explains how PostReach AI Limited, a company incorporated in Hong Kong under company number 77341984, whose registered office is at Room 1805-06, 18th Floor, Hollywood Plaza, 610 Nathan Road, Kowloon, Hong Kong ("Vistason", "we", "us"), collects, uses, shares and protects personal data in connection with https://vistason.com, the Vistason marketplace, the Hangar seller console, deal rooms, Tenders, Radar want-lists and alerts, and related services (the "Platform").

1.2 Under the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR and the Data Protection Act 2018 (together "Data Protection Law"), Vistason is the controller of the personal data described in clause 2.3 and a processor of the data described in clause 2.4.

1.3 Contact: legal@vistason.com; post: PostReach AI Limited, Room 1805-06, 18th Floor, Hollywood Plaza, 610 Nathan Road, Kowloon, Hong Kong, attention Privacy. Data Protection Officer / privacy contact: [—]. EU/UK representative under Article 27 GDPR (if applicable): [—].

1.4 Read this Policy with our Terms of Service, Cookie Policy, Data Processing Addendum ("DPA") and Legal Notice. Capitalised terms not defined here have the meaning given in the Terms of Service.

2. Scope

2.1 The Platform is for businesses only; we do not open accounts for consumers. The people who use the Platform, or whose data is submitted to us, are nonetheless individuals, and this Policy explains how we treat their personal data.

2.2 This Policy applies to ("you"): (a) website visitors; (b) prospects who submit the early-access form, request a demo or contact us before an account exists; (c) account holders and Authorised Users — natural persons registered by or for a customer business (airline, lessor, MRO, OEM, broker, teardown broker or similar) under a role such as Admin, Approver, Lister, Buyer or Viewer; (d) representatives, directors, officers, signatories and ultimate beneficial owners ("UBOs") of a customer or prospective customer whose details are submitted for KYC/KYB, even if they never use the Platform; (e) counterparty staff — employees and contractors of the other party to a deal, or of a forwarder, inspector, payment services provider or other third party, who take part in a deal room or correspond with us about a transaction; and (f) support and business contacts.

2.3 Vistason as controller. We are the controller for website and account data; Authorised User data; KYC/KYB, sanctions and export-control screening data; transaction, offer, tender and deal-room data needed to operate the Platform and comply with the law; billing, support, communications, security, usage and marketing data.

2.4 Vistason as processor. Inventory exports, listing files, trace documents, purchase orders and other documents uploaded by a customer may incidentally contain personal data (the technician who signed a release certificate, an employee's email in a spreadsheet, a contact name in a shop report). For that data the customer is the controller and Vistason is its processor, acting only on the customer's instructions under the DPA. If you are a customer's employee with a question about such data, please contact your employer first; we will help them respond.

2.5 This Policy does not cover the independent processing of third parties with whom we share data — [PAYMENT SERVICES PROVIDER], [KYC PROVIDER], forwarders, or the counterparty to a deal (clause 8). Each is responsible for its own privacy notice.

3. Personal data we collect

3.1 Not every category applies to every person.

3.2 Identity and contact data — name, business email and telephone, job title, employer, business address, language, time zone and profile details.

3.3 Company role and authority data — your Platform role, linked customer account(s), approval limits and signing authority set by your employer, and records of who invited, authorised or removed you.

3.4 KYC/KYB and compliance data — for the representatives, directors, signatories and UBOs named by a customer: full name, date of birth, nationality, country of residence, position, percentage of ownership or control; copies of government-issued identity documents and, where required, proof of address; corporate documents naming individuals (incorporation certificates, registers of directors and shareholders, powers of attorney, ownership charts); politically exposed person ("PEP") status; sanctions, denied-party, adverse-media and export-control screening results ("no match", "possible match", "confirmed match") and reviewer notes; end-use and end-user statements naming individuals; export licence details. We do not deliberately collect special-category data (Article 9 GDPR); identity documents and screening may incidentally reveal nationality or, rarely, political exposure, which we process only for the purposes in clause 6.

3.5 Transaction, offer and tender data — listings created or viewed, want-lists and Radar alert criteria, offers, counter-offers, bids, awards and acceptances, deal-room events, purchase orders, invoices and fee statements, settlement funding and release events (amounts, dates, references — never card or bank credentials), shipping details (addresses, contact names, forwarder references), inspection outcomes, SNAD claims and dispute files.

3.6 Communications data — messages, attachments and activity in deal rooms (shared with the counterparty, clause 8.3), support tickets, emails, call notes and feedback.

3.7 Device and usage data — IP address, browser and operating system, device identifiers, referring URL, pages and features viewed, timestamps, clicks, search queries, error reports, and the technical and security logs generated by our hosting and edge providers.

3.8 Billing data — billing contacts, invoice and VAT details, payment references, Radar subscription tier (Free / Pro / Enterprise) and renewal status. Card and bank details used to pay the settlement account or a subscription are collected directly by [PAYMENT SERVICES PROVIDER] or [PAYMENT PROCESSOR] and are not stored by Vistason.

3.9 Marketing data — preferences, consents, opt-outs and what we have sent you.

3.10 Early-access form data — name, business email, company name and type, role and any free-text message (clause 14).

4. Sources

4.1 You — when you register, submit a form, list material, make or accept an offer, bid in a Tender, message in a deal room, contact support or browse the Platform.

4.2 Your employer or the customer that onboards you — a customer's Admin may invite you, set your role and submit your details and, for directors and UBOs, identity documents and corporate records for KYC/KYB.

4.3 The counterparty to a deal — for example when a Seller enters a consignee contact or a Buyer names an inspector.

4.4 Public and official sources — company and beneficial-ownership registers, aviation regulatory databases, court and insolvency records and public websites, used to verify what we are told.

4.5 KYC and screening providers and list publishers — [KYC PROVIDER] and similar providers, and the publishers of sanctions, denied-party and export-control lists including OFAC, the US Commerce Department (Entity, Denied Persons and Unverified Lists), the US State Department, the European Union, the UN Security Council and the UK Office of Financial Sanctions Implementation, plus adverse-media sources.

4.6 Our service providers — hosting, edge, email, analytics (when introduced) and payment providers generate technical and transactional records about your use of the Platform.

5. Purposes and legal bases

5.1 We process personal data only where Article 6 GDPR allows it:

PurposeLegal basis
Creating and administering accounts, authenticating users, enforcing roles and permissionsContract with the customer (Art. 6(1)(b)); legitimate interest in administering Authorised Users who act for a customer (Art. 6(1)(f))
Operating the marketplace — listings, offers, counter-offers, Tenders, deal rooms, fee statements, settlement and freight coordinationContract (Art. 6(1)(b)); legitimate interest in operating a managed B2B marketplace (Art. 6(1)(f))
KYC/KYB verification, sanctions and export-control screening, PEP checks, transaction monitoring, record-keepingLegal obligation (Art. 6(1)(c)) under anti-money-laundering, sanctions and export-control law; where no specific obligation applies, legitimate interest in preventing financial crime and prohibited exports (Art. 6(1)(f)); Art. 10 GDPR / national law for offence data
Invoicing, fee and subscription collection, accounting, tax, auditContract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c))
Preventing and investigating fraud, misuse, Suspected Unapproved Parts, counterfeit or stolen material, bid-rigging and other breaches of the Terms of Service; securing the Platform (access logging, intrusion detection, rate limiting, backup, incident response)Legitimate interest in protecting the Platform, customers and the aviation supply chain and in network and information security (Art. 6(1)(f), recital 49); legal obligation where applicable
Resolving disputes and SNAD claims, releasing or returning settlement funds, establishing, exercising or defending legal claimsContract (Art. 6(1)(b)); legitimate interest in fair dispute resolution and defending our rights (Art. 6(1)(f))
Customer support; improving the Platform, aggregated statistics, testing featuresContract (Art. 6(1)(b)); legitimate interest in responding to enquiries and improving our service (Art. 6(1)(f)); consent for analytics cookies (Art. 6(1)(a))
Product updates, newsletters and marketing about Vistason; non-essential cookiesConsent (Art. 6(1)(a) and e-privacy law) or, for existing business contacts, legitimate interest in B2B direct marketing (Art. 6(1)(f)), always subject to your right to opt out
Responding to courts, regulators, customs, export-control and law-enforcement authorities; corporate transactions (financing, merger, acquisition, restructuring)Legal obligation (Art. 6(1)(c)); legitimate interest in cooperating with lawful requests and in conducting the transaction (Art. 6(1)(f))

5.2 Where we rely on legitimate interests we have balanced them against your rights and freedoms; you may ask for a summary of the assessment and may object (clause 12.6). Consent may be withdrawn at any time without affecting earlier processing.

5.3 Some data is a legal or contractual requirement: without KYC/KYB data we cannot open or keep open a customer's account, and without identity and contact data we cannot give an Authorised User access.

6. KYC/KYB, sanctions and export-control processing

6.1 Why. Aviation surplus material is subject to strict sanctions and export-control regimes. Before a customer can list, offer, bid or buy — and again for each deal — we verify who we are dealing with and whether the transaction is permitted, to comply with, or avoid facilitating a breach of: EU and national anti-money-laundering laws; EU, UN, UK and US sanctions (including OFAC programmes); the US Export Administration Regulations (including ECCN classification and EAR99 determinations); the US ITAR (ITAR-controlled items are not permitted unless separately enabled and licensed); the EU Dual-Use Regulation (EU) 2021/821; UK export controls; and other national controls.

6.2 What. We, and [KYC PROVIDER] acting for us, collect and verify the data in clause 3.4, confirm the identity of representatives and UBOs, check them against sanctions, denied-party, PEP and adverse-media lists, and repeat sanctions and denied-party screening on the parties to each deal and, where relevant, on consignees, end users and forwarders. Where the material or destination requires it we may ask for end-use and end-user statements and evidence of export authorisations. Accounts are re-screened periodically and when lists are updated; transactions are screened before the settlement funds are accepted and again before they are released.

6.3 Consequences. If screening produces a possible match, our compliance team reviews it (clause 7.3). We may then ask for more information, place a hold on an account or deal, refuse, cancel or unwind a transaction, hold or return the settlement funds, and — where legally required or permitted — report to competent authorities. The contractual consequences are in the Terms of Service.

6.4 Offence data. Screening can reveal alleged or actual criminal conduct. We process such data only as permitted by Article 10 GDPR and the law of [COUNTRY], for compliance purposes, with access restricted to the compliance team.

6.5 Retention. KYC/KYB and screening records are kept for [5] years after the business relationship ends, or longer where a law, regulatory request or claim requires (clause 10).

7. Automated processing and AI-assisted tools

7.1 AI-assisted inventory normalisation. When a Seller uploads an inventory export we use AI models from Google (Gemini) and Anthropic to normalise part numbers, condition codes, ATA chapters, quantities and descriptions. These tools are meant for material data, not personal data. Before data is sent we filter out or minimise personal data in inventory files (for example by stripping columns that appear to contain names, emails or phone numbers), and our contracts prohibit the providers from training on the data. Any residual personal data is processed by them as our sub-processor under the DPA.

7.2 Matching and alerts. Radar matches want-lists against listings using part numbers, condition codes, quantity and location; it does not profile individuals.

7.3 Screening is reviewed by people. Sanctions, denied-party and PEP screening uses automated name-matching. A system-generated "possible match" never by itself results in a refusal, hold, cancellation or report. Every possible match is reviewed by a trained member of our compliance team who considers identifying details (date of birth, nationality, address, corporate links) and, where appropriate, asks the customer for clarification before any decision.

7.4 No solely automated decisions with legal effect. We do not take decisions with legal or similarly significant effects on you based solely on automated processing (Article 22 GDPR). If we ever do, we will tell you, ensure a lawful basis, and give you the right to human intervention, to express your view and to contest the decision. Fraud and security tooling may temporarily block or challenge a suspicious session; lasting action on an account is confirmed by a person.

8. Recipients

8.1 We share personal data only as described here, only to the extent necessary, and under appropriate contractual protections.

8.2 Within a customer account. Admins and Approvers can see the activity of the Authorised Users linked to their account because they are responsible for it.

8.3 Counterparties in a deal. Once a Seller and a Buyer negotiate or enter a deal room, each side sees the other's business identity, the names, roles and contact details of participating Authorised Users, deal-room messages and documents, and the transaction record. Shipping, consignee and inspection contacts are shared as needed to perform the sale. Before a deal is agreed, counterparties may be shown on a masked or company-level basis as described in the Terms of Service. Each counterparty is an independent controller of what it receives.

8.4 Payment services provider. [PAYMENT SERVICES PROVIDER], a [REGULATED STATUS] entity, holds the settlement account through which Vistason receives the purchase price for a deal and releases it, and receives the data needed to operate that account, perform its own due diligence and execute Vistason's funding and release instructions; it is an independent controller for its regulatory obligations.

8.5 KYC provider. [KYC PROVIDER] receives identity documents and corporate data to verify them and returns verification and screening results, acting as our processor or, for its own regulatory records, as an independent controller.

8.6 Forwarders, inspectors and logistics providers receive pickup and delivery addresses, contact names and numbers, shipment details and dangerous-goods declarations when you request a freight quote, shipment or inspection, and act as independent controllers.

8.7 Sub-processors, by category: cloud hosting and content delivery (Vercel); DNS, edge network, key-value storage for the early-access form and security services (Cloudflare); database and file storage ([SUPABASE], planned); product analytics ([POSTHOG], planned, consent-based); transactional email (Amazon Web Services — Amazon SES); AI inventory normalisation (Google — Gemini; Anthropic), as limited in clause 7.1; support tooling [SUPPORT TOOL]; invoicing and subscription billing [BILLING TOOL]. The current list, locations and functions are in Annex 3 of the DPA and available from [PRIVACY EMAIL ADDRESS].

8.8 Authorities. We disclose personal data to courts, regulators, customs, export-control, sanctions, tax and law-enforcement authorities and financial intelligence units where legally required or permitted, including suspicious-transaction reports, export-licence applications and responses to lawful requests; where permitted we inform the affected customer.

8.9 Advisers, insurers and corporate transactions. Lawyers, auditors, accountants and insurers receive data under confidentiality. In a financing, merger, acquisition, reorganisation or asset sale, data may be shared with the prospective counterparty and its advisers under confidentiality and transferred to the successor, which will be bound by this Policy or one offering equivalent protection.

8.10 We do not sell personal data or share it for third-party marketing.

9. International transfers

9.1 Vistason is established in the EEA. Customers and counterparties are worldwide and some providers operate from outside the EEA and UK, including the United States, so personal data may be transferred to, stored in or accessed from those countries.

9.2 For any transfer outside the EEA or UK we ensure one of the following applies: (a) an adequacy decision of the European Commission or, for UK data, the UK Secretary of State (including the EU–US Data Privacy Framework for certified US recipients); (b) the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), using the module matching the parties' roles, supplemented by a transfer impact assessment and additional measures where needed; (c) for UK-GDPR transfers, the UK International Data Transfer Addendum to the EU Standard Contractual Clauses or the UK International Data Transfer Agreement; or (d) an Article 49 GDPR derogation — for example where the transfer is necessary to perform a contract in your interest (sharing consignee details with a forwarder in the destination country) or for legal claims.

9.3 Transfers to counterparties, forwarders and authorities in a shipment's destination country are typically necessary to perform the sale and for export and customs compliance. You may request details of the mechanisms we use, or a copy of the relevant clauses (commercial terms redacted), at [PRIVACY EMAIL ADDRESS].

10. Retention

10.1 We keep personal data only as long as necessary, then delete or anonymise it. Where several periods apply to one record, the longest applies.

CategoryRetention
KYC/KYB and compliance records (identity and corporate documents, screening results, review notes, end-use statements)[5] years after the business relationship ends (anti-money-laundering law); longer if a regulator, investigation or claim requires
Transaction records (offers, acceptances, tender records, deal-room contents, invoices, fee statements, settlement events, shipping and dispute files)[10] years from the end of the financial year of completion (commercial and tax law; defence of claims)
Account and Authorised User profile dataLife of the account plus [12] months, unless a longer period above applies
Technical, security and access logs[12] months, unless retained as evidence in an incident or dispute
Support tickets and general correspondence[36] months after closure
Early-access form data[12] months from submission, unless an account is opened (it then becomes account data) or you ask us to delete it sooner
Marketing consents and opt-outsWhile subscribed, plus a suppression record for as long as needed to honour an opt-out
BackupsRotated on a [30]-day cycle; deleted data leaves backups at the end of the cycle

10.2 Both parties to a deal can export the deal record during the retention period; afterwards it is deleted or anonymised. A legal hold, regulatory request or ongoing dispute suspends deletion until resolved.

11. Security

11.1 Our technical and organisational measures include: encryption in transit (TLS 1.2 or higher) and at rest for databases and file storage; role-based, least-privilege access with prompt revocation on role change or departure — Vistason's own Tower operator console has no second authentication factor of its own, and Vistason's policy is to enable multi-factor authentication on the infrastructure consoles behind it (Supabase, Vercel, Amazon Web Services, Cloudflare and Google Workspace), each of which offers it; enforcement of account- and role-level permissions; logging and monitoring of access to production systems and KYC data, with restricted access to identity documents; secure development, dependency and vulnerability management and review of providers' security certifications; regular tested backups and a documented incident-response plan; confidentiality obligations and data-protection training for staff and contractors. Annex 2 of the DPA contains more detail.

11.2 No system is completely secure. If a personal data breach affects you, we will notify the supervisory authority and, where required, you or your employer under Articles 33 and 34 GDPR. Keep your credentials confidential, use a strong unique password and multi-factor authentication where offered, and tell us at [SECURITY EMAIL ADDRESS] immediately if you suspect your account is compromised.

12. Your rights

12.1 Subject to the conditions and exceptions in Data Protection Law, you have the right to:

12.2 Access — confirmation of whether we process your data, a copy of it and the information in Article 15 GDPR.

12.3 Rectification — correction of inaccurate or incomplete data. Authorised Users can edit most profile data in account settings; KYC data is corrected through the customer's Admin or by contacting us.

12.4 Erasure — deletion where no legal basis remains. We cannot delete data we must keep (KYC/KYB records within [5] years, transaction records within [10] years) or need for legal claims.

12.5 Restriction — limitation of processing in the circumstances of Article 18 GDPR.

12.6 Objection — to processing based on legitimate interests, on grounds relating to your situation; we will stop unless we show compelling overriding grounds or need the data for legal claims. You may object to direct marketing at any time without giving reasons.

12.7 Portability — to receive data you provided, processed by automated means on the basis of contract or consent, in a structured, machine-readable format, and to have it transmitted to another controller where feasible.

12.8 Withdrawal of consent — at any time (for example via an unsubscribe link or your cookie preferences), without affecting earlier processing.

12.9 Automated decisions — not to be subject to solely automated decisions with legal or similarly significant effects (clause 7.4).

12.10 Complaint — to a supervisory authority, in particular where you live, work or where the alleged infringement occurred. Our lead authority is expected to be the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, https://www.aepd.es [to be confirmed]; for UK data subjects, the Information Commissioner's Office, https://ico.org.uk. We would welcome the chance to resolve your concern first, but you need not contact us before complaining.

12.11 How to exercise rights. Email [PRIVACY EMAIL ADDRESS] or write to the address in clause 1.3. We may verify your identity. We respond within one month, extendable by two months for complex or numerous requests (we will tell you). Requests are free unless manifestly unfounded or excessive. If your request concerns data we process on a customer's behalf (clause 2.4), we will refer it to the customer and help it respond, as the DPA requires.

12.12 If you are outside the EEA and UK you may have similar rights under local law (for example Switzerland, Brazil, Canada or certain US states), which we will honour where they apply. Because the Platform is business-to-business, many consumer-oriented privacy laws may not apply to data about you in your business capacity.

13. Cookies

13.1 The Platform currently uses only strictly necessary cookies and local storage — to keep you signed in, protect forms against cross-site request forgery, balance load and protect against bots at the edge, and remember basic preferences. These need no consent.

13.2 We have not deployed analytics cookies. When we introduce product analytics ([POSTHOG], planned) we will show a consent banner before any analytics cookie or identifier is set, record your choice and let you change it at any time. We use no marketing cookies. See the Cookie Policy for the full table.

14. Early-access and contact forms

14.1 Before an account exists you may submit our early-access (waitlist) form. We store the data in clause 3.10 in a key-value store operated by Cloudflare (Workers KV) at the edge, and may copy it to our CRM or database when we follow up.

14.2 We use it to assess and prioritise onboarding requests, contact you about early access and the Platform and, if you opted in, send product updates. Legal bases: legitimate interest in responding to business enquiries and developing our customer base; consent for optional marketing.

14.3 Early-access data is kept for [12] months from submission and then deleted, unless an account is opened (the data then becomes part of the account record) or you ask us to delete it earlier. Other enquiries are kept for the correspondence period in clause 10.1.

15. Children

15.1 The Platform is a business service for authorised representatives of companies. It is not directed at, and we do not knowingly collect data from, anyone under 18 (or the local age of majority). If you believe a minor has given us personal data, contact us and we will delete it.

16. Third-party sites and counterparties

16.1 The Platform links to third-party sites and services (payment, forwarder and regulatory portals). We are not responsible for their content or privacy practices. Counterparties, forwarders, [PAYMENT SERVICES PROVIDER] and [KYC PROVIDER] process personal data under their own notices.

17. Changes

17.1 We may update this Policy to reflect changes in the Platform, our providers or the law; the "updated" date shows the last change. For material changes we will give notice through the Platform and/or by email to account Admins at least [30] days before they take effect where practicable. The current version is at https://vistason.com/legal/privacy-policy.

18. Contact

18.1 Send questions, requests and complaints to legal@vistason.com, or by post to PostReach AI Limited, Room 1805-06, 18th Floor, Hollywood Plaza, 610 Nathan Road, Kowloon, Hong Kong, attention Privacy. DPO / privacy contact: [—].