Terms of Service
Version 2026-09-07 · Effective 7 September 2026 · Replaces the 2026-07-25 draft
How this document is organised. Part A is the agreement between
Aurora Crew and the airline that subscribes to the platform. Part B is what an
individual user accepts when signing in. Schedule 1 sets out how personal data is
processed. Commercial specifics for each airline — the contracting entity, fees, term and any
service levels — are recorded in that airline's Order Form, which prevails over
these Terms wherever the two differ.
Part A — Agreement with the Operator
1. Parties, documents and precedence
- “Aurora Crew”, “we”, “us” means the person or entity identified as the provider in
the Order Form, trading as Aurora Crew.
- “Operator” means the air operator identified in the Order Form, which holds the
Air Operator Certificate under which the flights in the Service are conducted.
- “Order Form” means the written order, quotation or agreement signed or accepted
by the Operator that identifies the parties, the licensed modules, the fees, the term and any
service levels.
- “Service” means the Aurora Crew platform described in section 2, including the
web application, the Aurora Crew Ops desktop application, the Aurora Crew crew mobile applications,
the associated APIs and any documentation.
- “Operator Data” means all data the Operator or its users enter into or upload to
the Service, and everything the Service derives from it for the Operator.
- The Agreement consists of the Order Form, these Terms (Parts A and B and
Schedule 1) and the Privacy Policy. If they conflict, the Order Form
prevails, then Schedule 1, then Part A, then Part B, then the Privacy Policy.
2. What the Service is
The Service is a crew-operations platform for a scheduled airline. Depending on the modules
licensed in the Order Form it provides:
- Crew scheduling — roster construction, rule-based assignment, standby, days
off and blocks, duty-time and rest checking, swap and day-off requests, publication to crew.
- Itinerary and aircraft — the flight programme, weekly templates, tail
assignment and the record of the fleet.
- Operations control (CCO) — post-flight records (times, fuel, passengers,
cargo, notes), delay records, the duty sign-in board and crew warnings.
- Flight dispatch — a dispatch board recording readiness checks, a release
entered by the Operator's authorised person, aircraft changes, aircraft restriction (MEL/CDL)
records and station ground-equipment records, with the conflicts between them shown.
- Department oversight — chief pilot and chief cabin crew views of documents,
qualifications, currency and training.
- Crew portal and apps — each crew member's own roster, duty and rest limits,
documents, requests, notifications and duty sign-in.
- Platform administration — accounts, devices, security, backups and activity.
We may add, improve or withdraw features. A material reduction in the functionality
licensed in the Order Form will be notified to the Operator in writing at least 30 days
before it takes effect. During the current term a material reduction applies only with the Operator's
agreement; if the Operator does not agree, it may end the Agreement under the material reduction
paragraph of section 8, whether or not the ordinary notice date in section 7 has passed.
3. Software assistance and authorised decisions
This section states what the Service does and does not decide. It is central to the Agreement
and to how the Operator must use the Service.
- The Operator remains the operator. The Service assists the Operator's own
processes; it does not replace them, and nothing in it substitutes for the Operator's Operations
Manual, its Air Operator Certificate, its dispatch and flight-following arrangements, or the
requirements of its civil aviation authority.
- Legality checks are aids, not certifications. Flight-duty-period, rest,
consecutive-day, turnaround, qualification, currency and fleet-type checks are computed from the
rule set, airport data, fleet data and crew records configured, supplied or approved by the
Operator. The Operator is responsible for verifying every roster before it is published or
flown. A roster produced or checked with the Service is not a determination that it is lawful.
- A dispatch “release” in the Service is a record, not a release. The Flight
Dispatch board records that an authorised person of the Operator has entered a release and has
attested to the checks the board lists. The operational release of a flight, and every decision
it records — aircraft changes, readiness, MEL/CDL and ground-equipment status — is made by the
Operator's authorised personnel under the Operator's approved procedures. The Service does not
make those decisions and does not verify them against any source outside the Operator's own
inputs.
- Post-flight and delay records are the Operator's records. The Service stores
what the Operator's staff enter. It does not validate figures against aircraft systems, fuel
suppliers or the authority.
- Approvals are records of the Operator's decision. Where the Service allows an
authorised person to record a commander's discretion, a documented acceptance or another
mechanism relieving a warning, the Service records that decision and who made it. The decision,
its lawfulness and its justification are the Operator's.
- Notifications are best effort. In-app notifications and push notifications
depend on the crew member's device, network and the mobile platform's push service. The Service
records whether a notification was read or acknowledged; it cannot guarantee delivery. The
Operator must keep its own confirmed channel for time-critical changes.
- Roster generation is rule-based, not artificial intelligence. The assignment
engine applies the Operator's configured rules deterministically. It is not a machine-learning
model, it is not trained on Operator Data, and no Operator Data or crew data is transmitted to any
generative-AI or third-party machine-learning service. Outputs are repeatable and traceable to the
rules that produced them. If that ever changes, these Terms and the Privacy Policy will be revised
first and the acceptance version incremented.
4. Accounts, roles and security
- The Service is licensed to the Operator, not to individuals. The Operator decides who holds
which role and is responsible for everything done under accounts it authorises.
- Accounts are personal. Credentials must not be shared. The Operator must tell us promptly when
a user leaves or a credential may be compromised, so access can be withdrawn.
- Privileged roles (crew scheduling, itinerary, operations control, flight dispatch, department
heads, platform administration) are granted by the Operator and enforced by the Service on the
server, not only in the interface.
- Operational desk accounts are bound to approved devices and, where the Operator has enabled
it, may sign in only through the Aurora Crew Ops application. Two-step verification is available
to every account and we may require it for privileged accounts on notice. Sign-ins are evaluated
for account-takeover risk by the identity provider; a high-risk attempt may be challenged or
refused.
- The Operator must not, and must ensure its users do not, probe or circumvent access controls,
access data outside their remit, extract data in bulk other than through the export features
provided, or use the Service to store material unrelated to crew operations.
5. Operator Data
- Operator Data belongs to the Operator. We claim no ownership of it and use it only to provide,
secure, support and improve the Service for the Operator, and as Schedule 1 and the Privacy Policy
describe. We do not sell it, share it with other customers, or use it to train any model.
- The Operator is responsible for the accuracy and currency of the inputs the Service relies on:
rule sets, airport data, fleet data, crew records and documents. We do not warrant that a
configured rule set reflects current regulation.
- The Service provides exports (Excel, CSV, JSON) and backups (downloaded and held in the
Operator's own storage area of the platform) so the Operator can keep its own copies at any time.
The Operator should export at every publication and before any major change.
- Each airline's data is held in database tables, file storage and identity pools that belong to
that airline alone within our infrastructure. No other customer's data is stored with it.
6. Availability, support and third-party infrastructure
- The Service is delivered over the public internet from Amazon Web Services (US East, Ohio).
We rely on that infrastructure and on the mobile platforms' push services, and we are not
responsible for their unavailability.
- Unless the Order Form states a service level, no particular uptime is warranted. We will use
reasonable efforts to keep the Service available, to schedule maintenance outside the Operator's
peak hours where practical, and to tell the Operator about planned interruptions in advance.
- Support is provided by email at support@auroracrew.app
during the hours stated in the Order Form.
7. Fees, term and renewal
- Fees, the billing period, the currency and any taxes are as stated in the Order Form. Fees are
exclusive of taxes unless the Order Form says otherwise.
- Invoices are payable within the period stated in the Order Form, or within 30 days of the
invoice date if none is stated.
- The term and any renewal are as stated in the Order Form. Either party may decline renewal by
written notice at least 60 days before the end of the current term unless the Order Form provides
otherwise.
8. Suspension, termination and offboarding
- Suspension. We may suspend access, wholly or in part, where there is a credible
security threat, unlawful use, or fees remain unpaid 30 days after written notice. Where
circumstances allow we will give notice first, and we will restore access once the cause is
resolved.
- Termination for breach. Either party may terminate the Agreement by written
notice if the other materially breaches it and does not cure the breach within 30 days of notice.
- Termination for convenience. Either party may end the Agreement at the end of the
current term by the notice in section 7.
- Termination for material reduction. Within 60 days of receiving a notice under
section 2 that the Operator has not agreed to, the Operator may end the Agreement on 30 days' written
notice. Fees prepaid for the unexpired part of the term after the termination date are refunded
pro rata, and the wind-down period below applies. This remedy is available whatever the ordinary
notice date in section 7.
- Wind-down. For 30 days after the Agreement ends (the “wind-down period”) the
Operator retains read and export access so it can take a complete copy of its data — backup
files, roster and post-flight exports, and uploaded documents.
- After the wind-down period we disable the Operator's accounts and, within 60
further days, delete the Operator's live data and files. Backup copies are not deleted early but
fall off on their fixed cycle: database point-in-time recovery after 35 days, daily backups after
35 days, monthly backups after 365 days, previous versions of uploaded files after 365 days, and
backup files held in the platform's backup vault after at most 400 days. We will confirm in
writing when deletion is complete.
- What we keep. We retain only what the law or a regulator requires us to keep,
or what the Operator instructs us in writing to keep, and only for as long as that reason lasts.
Disabled accounts are retained rather than deleted so that the append-only change history
continues to name the people who made each change. This section is consistent with the
Privacy Policy, which governs the personal data involved.
9. Confidentiality
Each party will keep the other's confidential information in confidence and use it only for the
purposes of the Agreement — for us, Operator Data and the Operator's commercial terms; for the
Operator, the non-public workings, pricing and security arrangements of the Service. This does not
apply to information that is public, independently developed, or lawfully received from a third
party, or that must be disclosed by law, in which case the disclosing party will give notice where
lawful.
10. Warranties and disclaimer
- We warrant that the Service will perform materially as described in section 2 and that we will
provide it with reasonable skill and care.
- Except as expressly stated, the Service is provided as is. To the extent permitted by law, all
other warranties, conditions and terms, whether express or implied, are excluded — including any
implied warranty of merchantability, fitness for a particular purpose, accuracy or
non-infringement.
- The Service is not a substitute for the Operator's compliance with aviation regulation, and we
give no warranty that any roster, release, record or check produced with it complies with any
law, regulation or the Operator's own procedures.
11. Liability
- Neither party is liable to the other for indirect or consequential loss, or for loss of profit,
revenue, business or goodwill, however arising. For the Operator this includes, without
limitation, the cost or consequence of delayed, diverted or cancelled flights, crew replacement,
passenger claims and regulatory penalties, all of which arise from the Operator's operation and
not from the Service.
- We are not liable for loss of Operator Data to the extent the Operator could have avoided it by
using the export and backup features the Service provides.
- Each party's total liability under the Agreement in any 12-month period is limited to the fees
paid or payable by the Operator for the Service in the 12 months preceding the event giving rise
to the claim, or such other amount as the Order Form states.
- Nothing in the Agreement excludes or limits liability that cannot be excluded or limited under
the governing law, including for death or personal injury caused by negligence, or for fraud.
12. Indemnities
- The Operator will indemnify us against third-party claims arising from the Operator's
operations, its rosters, releases and records, its users' conduct, or Operator Data, except to the
extent caused by our breach of the Agreement.
- We will indemnify the Operator against third-party claims that the Service, as provided by us
and used in accordance with the Agreement, infringes that third party's intellectual property
rights. We may, at our option, modify or replace the affected part of the Service or terminate the
Agreement and refund prepaid fees for the unexpired term.
13. Changes to these Terms
We may update these Terms. Changes that affect the Operator commercially are notified to the
Operator in writing at least 30 days before they take effect and do not apply to the current term
without the Operator's agreement. Changes that alter what a user has agreed to under Part B
increment the acceptance version; users are asked to accept again when they next sign in, and the
version accepted is recorded against each account.
14. Governing law and disputes
The Agreement is governed by the law stated in the Order Form and any dispute is subject to the
courts named there. If the Order Form is silent, the Agreement is governed by the law of the
jurisdiction in which Aurora Crew is established, and the courts of that jurisdiction have exclusive
jurisdiction. Before starting proceedings the parties will try in good faith to resolve any dispute
between senior representatives for at least 30 days.
15. General
- Formal notices are given in writing to the addresses in the Order Form, and to us also by
email to support@auroracrew.app.
- The Agreement is the entire agreement between the parties about the Service and supersedes
prior proposals and discussions.
- Neither party may assign the Agreement without the other's written consent, except to a
successor to substantially all of its business. We may use subcontractors, including the
infrastructure providers named in Schedule 1, and remain responsible for them.
- If a provision is unenforceable it is severed and the rest continues. A failure to enforce a
right is not a waiver of it. Sections 5, 8, 9, 11, 12 and 14 survive termination.
Part B — What you accept when you sign in
You are reading this because your airline (the Operator) has contracted for Aurora Crew and has
given you an account. When you tick the acceptance box on the sign-in screen you accept
this Part B and acknowledge the Privacy Policy. You are
not a party to Part A and you accept no commercial obligation on the Operator's behalf; those rest
with the Operator under its Order Form.
- Your account is yours alone. Do not share your password or one-time codes, and
keep any device you use for the Service secured. Tell your scheduling department at once if you
think someone else has used your account.
- Use it for your airline's crew operations only. Do not try to see data about
colleagues outside what your role shows you, do not probe or circumvent the access controls, and
do not copy data in bulk other than through the export features you are given.
- What you enter is a record. Duty sign-ins, requests, acknowledgements and — for
operational roles — post-flight records, releases, approvals and other entries are stored with
your account name and the time, and form part of your airline's operational records. Enter only
what is true.
- Notifications are not the only channel. The Service tells you about roster
changes and reminds you of duties as a convenience. Your airline's official procedures for
reporting for duty and confirming changes still apply, and a missed notification is not a defence
to them.
- Your data. Your airline is the controller of the personal data the Service holds
about you; the Privacy Policy explains what is held, who can see it and how to ask for it to be
corrected or deleted.
Schedule 1 — Data processing terms
This Schedule forms part of the Agreement with the Operator and is the data-processing agreement
referred to in the Privacy Policy.
- Roles. For personal data in Operator Data, the Operator is the controller and
Aurora Crew is the processor. Aurora Crew is the controller of the enquiries submitted directly to
it, and of the operational and security telemetry of its own platform (request logs and sign-in
risk telemetry), which it holds to run and secure the Service.
- Instructions. We process Operator Data only to provide the Service as configured
by the Operator, as these Terms and the Privacy Policy describe, and as the Operator otherwise
instructs in writing. We will tell the Operator if an instruction appears to us to be unlawful.
- Sub-processors. Amazon Web Services, Inc. (hosting, database, file storage,
identity, backups — US East, Ohio); and the push-notification services of the mobile platforms
the Operator's users choose (Apple, Google, Mozilla), which receive the text of each push
notification in order to deliver it. We will notify the Operator before adding a sub-processor
that processes Operator Data and the Operator may object on reasonable grounds.
- Security. Encryption in transit and at rest; each airline's data in its own
tables, file store and identity pool; role-based access enforced on the server; device approval
for operational desks and, where the Operator has enabled it, sign-in only through the Aurora Crew
Ops application; risk-based sign-in evaluation; an append-only
record of changes to crew documents; access logging; and backups as section 8 describes. On written
request we will provide a description of these measures and the relevant AWS attestations.
- Confidentiality of staff. Persons we authorise to process Operator Data are bound
by confidentiality obligations.
- Assistance. We will assist the Operator, at the Operator's reasonable request,
in responding to data-subject requests and in meeting its security, breach-notification and
impact-assessment obligations, using the features of the Service where possible.
- Personal data breach. We will notify the Operator without undue delay, and in
any event within 72 hours, after becoming aware of a personal data breach affecting Operator
Data, with the information we have and updates as we learn more.
- International transfer. Operator Data is hosted in the United States. The
Operator, as controller, determines the lawful basis for that transfer under the law that applies
to it; we will enter into standard contractual terms or provide the information the Operator
reasonably needs to document it.
- Return and deletion. On termination, section 8 applies: export during the
wind-down period, then deletion of live data within 60 days and of backups on their fixed cycle,
subject only to what the law requires us to keep.
- Audit. Once in any 12-month period, or after a breach, the Operator may ask for
the information reasonably necessary to demonstrate our compliance with this Schedule.
Contact
Questions about these Terms: support@auroracrew.app.
Formal notices: to the address stated in the Order Form.