ALTO Cadence Cabin Control — Privacy Policy

Effective Date: August 12, 2026

Last Updated: August 2026

This Privacy Policy (“Policy”) applies to the ALTO Cadence Cabin Control,  a commercial application for business aviation cabin management and in-flight entertainment provided by Heads Up Technologies (the “Service”). The Service is made available by Heads Up Technologies (“we,” “us,” or “our”) to end users (passengers) through aircraft operators, who are our direct commercial customers. This Policy describes how we collect, use, and protect personal information through the Service. If you have questions about how your aircraft operator handles your personal information collected outside of the Service, please contact the operator directly.

If you choose to use our Service, then you agree to the collection and use of information as described in this Policy. The personal information that we collect is used for providing and improving the Service. We will not use or share your information with anyone except as described in this Policy.

NOTICE AT COLLECTION

We collect, and in the past 12 months have collected, the following categories of information from and about you: identifiers, internet or similar network activity. and geolocation data. We collect these categories of information from you in order to provide our services to you, to run our business, to communicate with you, and as required by law. We may have disclosed each of these categories of personal information for a business purpose as described below. We have not “sold” or “shared” personal information in the past 12 months, as those terms are defined by the CCPA.

Data stored by the Service may be removed by uninstalling the Service. Where logging limited IP addresses is needed for security, the data will be retained by default for 90 days before automatic deletion. If the Service communicates with other Third-Party Devices on the network, contact those providers for their storage and deletion policies.

INFORMATION WE COLLECT AND USE

When connected to an aircraft, the Service communicates with our devices for the purpose of controlling the aircraft cabin. This requires the transmission of your IP address to facilitate communication.

You may request to connect to our server over the internet to demonstrate the Service’s functionality. We may log:

  • Device Information. The IP address, timestamp, device identifier, or mobile operating system.
  • Information You Submit. We may collect information when you send us a message through the “Contact Us” page or similar features.

HOW WE COLLECT YOUR INFORMATION

We collect your information in different ways. Below are some examples of how we may collect your information.

  • Directly From You. For example, when you submit an inquiry to us.
  • For example, when you visit and navigate our Service on any device.
  • From Third Parties. We may receive information about you from other sources. For example, this may include receiving information from business customers.

The Service is a native mobile application and does not use browser cookies. The Service may store session tokens and application preferences locally on your device in secure, application-specific storage. This local data is cleared whenever the application is restarted or uninstalled.

HOW WE USE YOUR INFORMATION

No username or further personal information is required to access the Service. The data that we collect, as described above, is used for logging and security purposes and is stored locally on the device to retain user preferences. These settings are not transferred off the device. Below are additional examples of how we may use your information:

  • To Facilitate our Service. We may use your information to make our Service and business better. We may also use your information to provide you with information about our business.
  • To Respond to Your Requests or Questions. This may include responding to your feedback.
  • For Security Purposes. This could include protecting our company and consumers who use our products and services. It may also include protecting our Service.
  • As otherwise Permitted By Law or As We May Notify You.
  • As Requested or Directed By You.

HOW WE SHARE YOUR INFORMATION

We may share your information in the following ways:

  • We may share your information with our parent, subsidiary, and affiliate entities.
  • With Our Service Providers. We may share your information with third parties who perform services on our behalf. For example, this may include companies that send emails on our behalf or help us run our Service.
  • With Any Successors to All or Part of Our Business. For example, if we merge with, are acquired by, or sell part of our business to another entity. This may include an asset sale, corporate reorganization or other change of control.
  • To Comply With the Law or To Protect Ourselves. For example, this could include responding to a court order or subpoena. It could also include sharing information if a government agency or investigatory body requests. We might share information when we are investigating a potential fraud.
  • For Other Reasons We May Describe to You.
  • As Requested or Directed By You.

THIRD-PARTY PROVIDERS

In limited aircraft configurations, it may be required that the Service communicate directly with other devices on the aircraft network (“Third-Party Devices”); this requires the transmission of your IP address to these devices. No other personal information is transmitted. These Third-Party Devices operate independently of us. The storage and usage of your IP address by these Third-Party Devices is governed by the privacy policies of those providers. You may contact us for information on which other networked devices are used in a particular aircraft.

We may also need to use third-party service providers to properly provide the Service. We currently use the following third-party service provider:

  • Newtek —Newtek provides cloud infrastructure that may process limited data (such as IP addresses and security log data) as described in this Policy. Newtek’s privacy policy (available at https://www.newtekone.com/privacy-policy/) governs their independent handling of this data.
  • IPM—Newtek’s servers are operated by IPM (privacy policy available at https://www.ipm.com/privacy-policy/).

YOUR RIGHTS UNDER THE GDPR (EU/EEA USERS)

If you are located in the European Union (“EU”) or European Economic Area (“EEA”), the following applies to you under the General Data Protection Regulation (“GDPR”).

If you are located in the United Kingdom (“UK”), the UK General Data Protection Regulation (“UK GDPR”) applies to you. The rights and protections described in this section apply equally to UK residents, and references to EU/EEA data protection authorities include the UK Information Commissioner’s Office (ICO).

Data Controller

Heads Up Technologies is the data controller responsible for personal information collected through this Service. Our contact details are provided in the “Contact Us” section below.

Lawful Basis for Processing

We process your personal information on one of the following lawful bases:

  • Legitimate interests: We log limited IP address data for security and service integrity purposes. Our legitimate interest in maintaining the security of our systems is balanced against the minimal privacy impact of this limited logging.
  • Contractual necessity: Transmission of your IP address to facilitate cabin network communication is necessary to provide the Service you have requested.

Your Data Subject Rights

Under the GDPR, you have the following rights with respect to your personal data:

  • Right of Access: You may request a copy of the personal data we hold about you.
  • Right to Rectification: You may request correction of inaccurate personal data.
  • Right to Erasure: You may request deletion of your personal data where there is no compelling reason for its continued processing.
  • Right to Restriction of Processing: You may request that we restrict the processing of your personal data in certain circumstances.
  • Right to Data Portability: Where processing is based on consent or contract and carried out by automated means, you may receive your data in a structured, commonly used, machine-readable format.
  • Right to Object: You may object to processing based on our legitimate interests.
  • Right Regarding Automated Decision-Making: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. We do not engage in automated decision-making or profiling using the personal data collected through this Service.

To exercise any of these rights, please contact us using the details in the “Contact Us” section. We will respond within the timeframe required by applicable law.

International Data Transfers

If personal data is transferred outside the EU/EEA (for example, if Newtek’s cloud infrastructure is located outside the EU/EEA), such transfers will be conducted in accordance with GDPR Chapter V, including through Standard Contractual Clauses or other appropriate safeguards as required. Please contact us for further information on the transfer mechanisms we use.

Right to Lodge a Complaint

If you believe we have not handled your personal data in accordance with the GDPR, you have the right to lodge a complaint with your local Data Protection Authority (DPA). A list of EU/EEA DPAs is available at: https://edpb.europa.eu/about-edpb/board/members_en.

YOUR RIGHTS UNDER STATE PRIVACY LAWS

Depending on your state of residence, you may have the rights listed below with respect to the personal information that we maintain about you. In particular, if you are a California resident, the California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”), gives you specific rights regarding your personal information.

Categories of Personal Information We Collect

We collect the following categories of personal information, as described above:

  • Identifiers: IP addresses, used for cabin network communication and, where applicable, security logging as described in this policy.
  • Device preferences: User settings stored locally on your device and not transmitted off-device.

We do not collect “sensitive personal information” as defined under the CCPA/CPRA (such as social security numbers, financial account information, precise geolocation, racial or ethnic origin, or health information) through this Service.

Business Purpose for Collection

We collect this information for the following business purposes, as described above:

  • To provide and operate the cabin control and in-flight entertainment service;
  • For security, fraud prevention, and service integrity; and
  • To maintain and improve the Service.

Sale or Sharing of Personal Information

We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising purposes.

Your Privacy Rights

Depending on your state of residence, you may have the rights listed below. We may take steps to verify your identity, as permitted or required under applicable law, before we process your request. Verification may include asking you to provide information about yourself that we can match against information already in our possession.

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of that information, the business purposes for collection, and the categories of third parties with whom we have shared it.
  • Right to Delete: You may request deletion of personal information we have collected about you, subject to certain exceptions permitted by law.
  • Right to Correct: You may request correction of inaccurate personal information we maintain about you.
  • Right to Opt-Out of Sale/Sharing: As stated above, we do not sell or share personal information for cross-context behavioral advertising. No opt-out mechanism is currently required.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA privacy rights.
  • Financial Incentives: We do not offer financial incentives, price differences, or service differences in exchange for the collection, retention, or sale of your personal information.

To submit a verifiable consumer request, please contact us using the information in the “Contact Us” section. We will respond within 45 days as required by the CCPA, with a possible 45-day extension where reasonably necessary.

You may designate an authorized agent to submit a privacy request on your behalf. To do so, you must provide the agent with written permission to act on your behalf, and we may require you to verify your identity directly with us and confirm that you provided the agent permission to submit the request.

Children’s Privacy

This Service is meant for adults. We do not knowingly collect personally identifiable information from persons under the age of 13 (or 16 for users in EU/EEA jurisdictions) (the “Age Threshold”). If you are a parent or guardian and think your child under the Age Threshold has provided us with personal information, please contact us at info@heads-up.com with the subject “COPPA Information Request.” You may also write to us at the address listed at the end of this Policy. Upon verification, we will promptly delete such information from our records.

Security

We value your trust in providing us your personal information, thus we are striving to use industry-standard security measures, including encrypted data transmission and access controls, to protect your personal information. But remember that no method of transmission over the internet, or method of electronic storage is 100% secure and reliable, and we cannot guarantee its absolute security.

Links to Other Sites

This Service may contain links to other sites. If you click on a third-party link, you will be directed to that site. Note that these external sites are not operated by us. Therefore, we strongly advise you to review the privacy policy of these websites. We have no control over, and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

Changes to the Privacy Policy

We may update our Policy from time to time. Thus, you are advised to review this page periodically for any changes. We will notify you of any material changes by posting the updated Policy on this page and, where required by applicable law or where practicable, by providing notice through the Service itself or by email. Changes are effective immediately after they are posted on this page.

Contact Us

If you have any questions or suggestions about our Policy, do not hesitate to contact us at info@heads-up.com.