Legal
Privacy Policy
This policy explains how Lexodd Hypernova Pvt. Ltd. collects, uses, discloses, retains and protects personal data through the AVMX Pro platform and this website. It reflects our obligations under applicable US state privacy laws, including the California Consumer Privacy Act as amended by the CPRA, and equivalent statutes in Virginia, Colorado, Connecticut, Utah and Texas.
- Effective
- 14 August 2026
- Version
- 1.0
- Applies to
- AVMX Pro platform & website
1Who we are
AVMX Pro is an aviation maintenance, repair and overhaul (MRO) platform operated by Lexodd Hypernova Pvt. Ltd. (“Lexodd”, “we”, “us”), a company incorporated in India with offices at Visakhapatnam & Hyderabad, India.
AVMX Pro is enterprise software sold to airlines, MRO providers, lessors and aircraft operators. It is not a consumer service. The individuals whose personal data we handle are predominantly employees and contractors of our customers — engineers, technicians, planners, compliance officers and administrators — together with people who contact us through this website.
2Our role: controller and processor
Our obligations differ depending on whose data is involved.
| Context | Our role | What that means |
|---|---|---|
| This website | Business (controller) | We decide why and how we handle enquiry and contact data submitted to us. |
| Customer platform data | Service Provider (processor) | We process aircraft, maintenance and user records on our customer's instructions. The customer remains the Business and is responsible for the lawful basis of that processing. |
| Our own staff and business records | Business | Handled under our internal HR and business policies, outside the scope of this document. |
Where we act as a processor, the governing terms are those in the customer’s subscription agreement and data processing addendum, which take precedence over this policy in the event of conflict.
3Personal data we handle
| Category | Examples | Source |
|---|---|---|
| Account & identity | Name, work email address, assigned role, organization, password (stored only as a salted hash by our authentication provider), forced-password-change status | Provided by the customer administrator when creating a user |
| Operational activity | Work orders raised or completed, defects reported, labor hours recorded, parts issued, inspections signed off, records viewed or exported | Generated as the user works in the platform |
| Digital signatures | Signature images captured on a technician's device for work order sign-off | Drawn by the user on the mobile application |
| Photographs & attachments | Images of aircraft, components and defects uploaded from the field, which may incidentally include people | Uploaded by the user |
| Device & session | Device model, operating system version, application version, install identifier, push notification tokens, last-seen timestamp, IP address, session tokens | Collected automatically when the platform or mobile app is used |
| Audit records | Actor identity, action performed, record affected, timestamp and change metadata | Written automatically and immutably on every record change |
| Website enquiries | Name, company, work email, telephone number, organization type, fleet size and the message you send us | Submitted voluntarily through the demo request form |
4Sensitive personal data
The only category of sensitive personal information routinely handled by the platform isaccount credentials. Passwords are never stored in plain text; authentication is delegated to our identity provider, which stores only a salted cryptographic hash. Neither Lexodd staff nor customer administrators can retrieve a user’s password.
Digital signatures captured for maintenance sign-off are treated with the same care as sensitive personal data, because they authenticate an individual engineer against a regulated airworthiness record.
We do not collect financial information, health records, biometric identifiers, sexual orientation, precise geolocation or any other category defined as sensitive personal information under the CPRA.
5Why we process personal data
- To deliver the platform — authenticating users, applying role-based access, assigning and tracking maintenance work, and maintaining aircraft records.
- To meet aviation regulatory obligations — airworthiness records must attribute maintenance actions to identified, qualified individuals and must be retained and producible on demand by the governing authority.
- To maintain security and accountability — audit logging, access control, detecting misuse and investigating incidents.
- To operate and improve the service — diagnosing faults, monitoring availability and improving reliability.
- To respond to you — replying to demo requests and sales enquiries made through this website.
For website enquiries we rely on your consent, given when you submit the form. For platform processing we act on the documented instructions of our customer, who is responsible for establishing the lawful basis — typically the performance of an employment contract and compliance with a legal obligation.
6Automated processing and AI features
The platform includes optional AI capabilities: a daily fleet briefing, risk scoring, repeat-defect detection, parts demand forecasting and an engineering copilot that answers questions in natural language.
- These features operate on aircraft and maintenance data. Where a record references the individual who raised or completed it, that reference may be included in the context sent to the model.
- AI features are administrator-controlled and can be disabled globally or per feature. When disabled, no data is transmitted to the model provider.
- No automated decision produces a legal or similarly significant effect on an individual. AI output is advisory: a suggested inspection, a drafted work order or a ranked risk list. A qualified person decides and signs.
- We do not permit our model provider to train foundation models on data submitted through the platform.
8Cross-border transfer
Our infrastructure providers operate globally and data may be processed outside the United States. Transfers are made under the contractual protections offered by each provider, and we remain accountable for personal information we transfer to a service provider or contractor under our agreements with them.
Customers with data-residency obligations — including defense, government and certain national carriers — can request a region-pinned or dedicated deployment. Contact us before onboarding if this applies to you.
9How we protect personal data
We maintain reasonable security practices and procedures as required by Section 43A of the the reasonable-security standard imposed by US state privacy law. Our controls are documented in an Information Security Policy available to customers and auditors on request. In summary:
- Encryption in transit (TLS) and at rest for all database and file storage.
- Role-based access control across eight defined roles and granular permissions, enforced on the server for every request rather than by hiding controls in the interface.
- Row-level security in the database, so a session cannot read outside its authorization.
- An immutable audit log recording actor, action, record, timestamp and change metadata — including the originating platform for actions taken on mobile.
- Credentials stored in encrypted storage on mobile devices, with remote revocation of a lost or stolen device.
- Security headers, timing-safe verification of scheduled-task secrets and server-side input validation.
- Least-privilege administrative access, reviewed when roles change.
No system is absolutely secure. We do not represent that the platform is immune from every possible attack, and we describe our controls honestly rather than aspirationally.
10How long we keep data
| Data | Retention | Reason |
|---|---|---|
| Aircraft & maintenance records | For the life of the aircraft, or as directed by the customer and the governing aviation authority | Airworthiness records must be retained under civil aviation requirements and generally outlive the subscription |
| Audit logs | Retained for the life of the customer account and not editable or deletable through the application | Integrity of the audit trail is the point of it |
| User accounts | For the duration of the user's authorization; deactivated promptly on request by the customer administrator | Access should end when authorization ends |
| Device registrations & push tokens | Until the device is revoked, signed out or inactive | No reason to retain a token that cannot be delivered to |
| Website enquiries | 24 months from last contact, unless a commercial relationship begins | Sales follow-up and record of the enquiry |
On termination, customers may export their data. After the contractual export window closes, customer data is deleted from active systems and expires from backups on the backup cycle. We will not delete records where retention is required by law or by an aviation regulator.
11Your rights
Subject to applicable US state privacy law, you may:
- Ask what personal data of yours we hold and how it is processed;
- Ask us to correct data that is inaccurate, incomplete or out of date;
- Ask us to erase personal data that is no longer needed — subject to aviation record-keeping obligations, which will usually prevent erasure of maintenance actions attributed to you;
- Withdraw consent where processing is based on consent;
- Nominate another individual to exercise your rights in the event of death or incapacity;
- Appeal a refused request, and lodge a complaint with your state Attorney General or, in California, the California Privacy Protection Agency.
13Privacy requests and complaints
Questions, requests and complaints about the handling of personal data may be addressed to our Privacy Contact:
Privacy Contact
Lexodd Hypernova Pvt. Ltd.
Email: info@avmxpro.co or info@lexodd.com
Telephone: +91 91001 13290
Address: 2093 Philadelphia Pike, Claymont, DE 19703
We acknowledge requests within 10 business days and respond substantively within 45 days, extendable once by a further 45 days where the request is complex, as permitted under the CCPA. If you are not satisfied with our response, you may appeal to us and then complain to your state Attorney General.
14Changes to this policy
We review this policy at least annually and whenever we materially change how we handle personal data. The effective date and version at the top of this page indicate the current revision. Material changes affecting customers will be notified through the platform or to the customer’s nominated contact before they take effect.
Questions about this policy or our processing may be sent to info@avmxpro.co. See also our Terms & Conditions.