Privacy Policy
A legal disclaimer
Last Updated On 07 August 2026.
Effective Date 05 February 2025.
This Privacy Policy describes the policies of Singapore Aviation Academy (SAA), Civil Aviation Authority of Singapore 60 Airport Boulevard, Changi Airport Terminal 2, #046-027, Singapore, 819643, email: qsm@caas.gov.sg, phone: +65 6542 1122; JAA Training Organisation (JAA TO), Beechavenue 1 - 19, Noord-Holland 1119RA, Netherlands (the), email: communications@jaato.com, phone: +31 (0)23 5679 790; and Incheon International Airport Corporation (IIAC), 23358 557, Yongyu-ro, Yeongjong-gu, Incheon, Republic of Korea, email: md_kang@airport.kr, phone: +82 032-741-2906 on the collection, use and disclosure of your information that we collect when you use our website (https://a7programme.com) (the “Service”). By accessing or using the Service, you are consenting to the collection, use and disclosure of your information in accordance with this Privacy Policy. If you do not consent to the same, please do not access or use the Service.
We may modify this Privacy Policy at any time without any prior notice to you, and will post the revised Privacy Policy on the Service. The revised Policy will be effective 180 days from when the revised Policy is posted in the Service, and your continued access or use of the Service after such time will constitute your acceptance of the revised Privacy Policy. We therefore recommend that you periodically review this page.
Information We Collect:
We will collect and process the following personal information about you:
-
Name
-
Email
-
Country
-
Organisation Name
-
Gender
How We Use Your Information:
We will use the information that we collect about you for the following purposes:
-
Marketing/ Promotional
-
Support
-
Administration info
If we want to use your information for any other purpose, we will ask you for consent and will use your information only on receiving your consent and then, only for the purpose(s) for which you grant consent, unless we are required to do otherwise by law.
How We Share Your Information:
We will not transfer your personal information to any third party without seeking your consent, except in limited circumstances as described below:
Ad service
Analytics
We require such third parties to use the personal information we transfer to them only for the purpose for which it was transferred and not to retain it for longer than is required for fulfilling the said purpose.
We may also disclose your personal information for the following: (1) to comply with applicable law, regulation, court order or other legal process; (2) to enforce your agreements with us, including this Privacy Policy; or (3) to respond to claims that your use of the Service violates any third-party rights. If the Service or our company is merged or acquired by another company, your information will be one of the assets that is transferred to the new owner.
Retention Of Your Information:
We will retain your personal information with us for 90 days to 2 years after user accounts remain idle or for as long as we need it to fulfil the purposes for which it was collected, as detailed in this Privacy Policy. We may need to retain certain information for longer periods, such as record-keeping / reporting in accordance with applicable law, or for other legitimate reasons like enforcement of legal rights, fraud prevention, etc. Residual anonymous information and aggregate information, neither of which identifies you (directly or indirectly), may be stored indefinitely.
Your Rights:
Depending on the law that applies, you may have a right to access and rectify or erase your personal data or receive a copy of your personal data, restrict or object to the active processing of your data, ask us to share (port) your personal information to another entity, withdraw any consent you provided to us to process your data, a right to lodge a complaint with a statutory authority and such other rights as may be relevant under applicable laws. To exercise these rights, you can write to us at communications@jaato.com. We will respond to your request in accordance with applicable law.
You may opt out of direct marketing communications or the profiling we carry out for marketing purposes by writing to us at communications@jaato.com.
Do note that if you do not allow us to collect or process the required personal information or withdraw the consent to process the same for the required purposes, you may not be able to access or use the services for which your information was sought.
Security:
The security of your information is important to us, and we will use reasonable security measures to prevent the loss, misuse or unauthorised alteration of your information under our control. However, given the inherent risks, we cannot guarantee absolute security, and consequently, we cannot ensure or warrant the security of any information you transmit to us, and you do so at your own risk.
Third Party Links & Use Of Your Information:
Our Service may contain links to other websites that are not operated by us. This Privacy Policy does not address the privacy policy and other practices of any third parties, including any third party operating any website or service that may be accessible via a link on the Service. We strongly advise you to review the privacy policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
Grievance / Data Protection Officer:
If you have any queries or concerns about the processing of your information that is available with us, you may email qsm@caas.gov.sg. We will address your concerns in accordance with applicable law.
Data Privacy Consent
By registering for the programme, you agree that the Incheon International Airport Corporation (IIAC) may collect, use, or disclose your personal data to the Singapore Aviation Academy (SAA) and the JAA Training Organisation (JAA TO) that collaborate for this joint programme or selected third-party service providers involved in this programme for general programme administration purposes. If you provide the personal data of third parties to the above-mentioned organisations, or if you complete this form on behalf of third parties, you represent and warrant that you are authorised to do so and that you have obtained their consent for the collection, use, and disclosure of their personal data for the above-stated purposes.
Privacy Statements on individual websites
As the user interacts with this website (https://a7programme.com) (the “Service”), the user may be redirected to the individual web properties of SAA, and/or JAA TO, and/or IIAC, leaving the "Service". Once the user interacts with any of the aforementioned web properties, the respective privacy policies of each organisation apply.
For more information about SAA, read the privacy statement here.
For more information about JAA TO, read the privacy statement here.
For more information about IIAC, read the privacy statement here.
All user interactions on those web properties, outside of this "Service", fall under the respective privacy policies, cookie statements, and terms of service.
Transfers of personal data to third countries or international organisations
Overview International Transfers of Personal Data
We may transfer, disclose, provide access to, entrust the processing of, or otherwise make personal data available only internally between our three organisations' operations located in the Netherlands, the Republic of Korea and Singapore.
The legal requirements applicable to an international transfer depend principally on the jurisdiction from which the personal data is transferred and the data protection laws applicable to the transferring organisation. We will only transfer personal data internationally where there is a lawful basis for the transfer and where the requirements of the applicable data protection legislation have been satisfied.
Where required, we will implement contractual, technical and organisational safeguards designed to ensure that personal data continues to receive an appropriate level of protection following the transfer.
International transfer framework
Netherlands → Republic of Korea
Transfers are governed by Chapter V of the General Data Protection Regulation (GDPR). The European Commission has recognised the Republic of Korea as providing an adequate level of protection for personal data under Article 45 GDPR. Where the recipient and processing fall within the scope of the applicable adequacy decision, personal data may therefore be transferred to the Republic of Korea without requiring an additional transfer mechanism solely because of the international transfer. Recipients in the Republic of Korea are also subject, where applicable, to the Korean Personal Information Protection Act (PIPA).
Netherlands → Singapore
Transfers are governed by Chapter V of the GDPR. Singapore is not currently subject to a European Commission adequacy decision. We will therefore use an appropriate transfer mechanism where required under Article 46 GDPR, such as the European Commission's Standard Contractual Clauses (SCCs), Binding Corporate Rules or another legally permitted safeguard. Where necessary, we will assess the circumstances of the transfer and implement supplementary contractual, organisational or technical measures. A derogation under Article 49 GDPR will only be relied upon where the applicable legal requirements are satisfied. Recipients in Singapore may additionally be subject to the Singapore Personal Data Protection Act 2012 (PDPA).
Republic of Korea → Netherlands
Transfers are governed by the Korean Personal Information Protection Act (PIPA), including Article 28-8 concerning cross-border transfers. The Korean Personal Information Protection Commission (PIPC) has recognised the European Union's personal data protection framework as providing a level of protection substantially equivalent to that provided under Korean law. Where the conditions of that recognition are satisfied, personal information may therefore be transferred from Korea to recipients in the Netherlands on that basis. Recipients in the Netherlands are subject, where applicable, to the GDPR and applicable Dutch data protection legislation.
Republic of Korea → Singapore
Transfers are governed by the Korean PIPA, including Article 28-8. Where an equivalence recognition does not apply, we will rely on another legally permitted basis for the overseas transfer. Depending on the circumstances, this may include the data subject's separate consent; a provision of applicable law, treaty or international agreement; processing or storage necessary for the conclusion or performance of a contract with the data subject, subject to applicable disclosure or notification requirements; an applicable certification mechanism; or another transfer basis permitted under Korean law. We will implement the safeguards required under the PIPA for personal information transferred overseas. Recipients in Singapore may additionally be subject to the Singapore PDPA.
Singapore → Netherlands
Transfers are governed by the Transfer Limitation Obligation under the Singapore PDPA. We will take appropriate steps to ensure that personal data transferred to the Netherlands receives a standard of protection comparable to that provided under the Singapore PDPA. This may be established through legally enforceable obligations applicable to the recipient, including applicable law, contractual arrangements, binding corporate rules, recognised certification mechanisms or other legally permitted measures. Recipients in the Netherlands are subject, where applicable, to the GDPR and applicable Dutch data protection legislation.
Singapore → Republic of Korea
Transfers are governed by the Transfer Limitation Obligation under the Singapore PDPA. We will take appropriate steps to ensure that personal data transferred to the Republic of Korea receives a standard of protection comparable to that provided under the Singapore PDPA. This may be established through legally enforceable obligations applicable to the recipient, including applicable law, contractual arrangements, binding corporate rules, recognised certification mechanisms or other legally permitted measures. Recipients in the Republic of Korea are subject, where applicable, to the Korean PIPA.
Safeguards for international transfers
Depending on the jurisdiction from which personal data is transferred and the circumstances of the transfer, the safeguards we apply may include:
-
an adequacy or equivalence decision issued or recognised by a competent data protection authority;
-
Standard Contractual Clauses or other approved contractual safeguards;
-
contractual provisions requiring the recipient to maintain an appropriate or comparable standard of personal data protection;
-
Binding Corporate Rules or equivalent intra-group safeguards;
-
recognised certification mechanisms or codes of conduct;
-
restrictions concerning onward transfers of personal data;
-
requirements concerning confidentiality, security, retention and deletion;
-
technical safeguards such as encryption, access controls and data minimisation;
-
organisational measures governing access to and handling of personal data; and
-
procedures enabling individuals to exercise their rights and obtain an effective remedy.
The particular safeguard used will depend on the applicable legislation, the destination of the personal data, the identity and status of the recipient and the nature and circumstances of the processing.
Your rights in relation to international transfers
An international transfer does not, by itself, remove the rights that you have under the data protection legislation applicable to our processing of your personal data.
Where the GDPR applies, you may, subject to the conditions and limitations established by law, have rights including the right to request access to, rectification or erasure of your personal data; restriction of processing; objection to processing; and data portability. You may also have the right to lodge a complaint with the competent data protection supervisory authority.
Where personal data is transferred on the basis of appropriate safeguards under Article 46 GDPR, you may request information concerning those safeguards and, where applicable, obtain a copy of the relevant safeguards, subject to the protection of confidential or commercially sensitive information.
Where the Korean PIPA applies, you may, subject to applicable conditions and exceptions, exercise rights relating to your personal information, including rights to request access, correction or deletion, and suspension of processing. Where required by Korean law, we will also provide information concerning overseas transfers, including relevant information regarding the personal information transferred, the destination and recipient, the purpose of the transfer and the applicable retention or processing arrangements.
Where the Singapore PDPA applies, you may, subject to applicable conditions and exceptions, request access to personal data held about you and information concerning its use or disclosure, and request the correction of errors or omissions in your personal data.
Where the recipient is independently subject to the data protection legislation of the receiving country, you may also have additional rights against that recipient under the laws of that jurisdiction.
Onward transfers
Where a recipient subsequently transfers personal data to another country, organisation or recipient, we will take appropriate steps, where required by applicable law, to ensure that the protection applicable to the personal data is not undermined by that onward transfer.
This may include imposing contractual restrictions on onward transfers, requiring the recipient to implement equivalent safeguards, or ensuring that an appropriate statutory transfer mechanism applies.
Transfers to international organisations
Where personal data is transferred to an international organisation, the transfer will be assessed according to the data protection legislation applicable to the transferring organisation.
For transfers subject to the GDPR, we will comply with Chapter V of the GDPR and rely, as applicable, on an adequacy decision, appropriate safeguards under Article 46 GDPR, or, in exceptional circumstances, a permitted derogation under Article 49 GDPR.
For transfers originating in the Republic of Korea, we will comply with the applicable cross-border transfer requirements under the Korean PIPA, including Article 28-8.
For transfers originating in Singapore, we will comply with the Transfer Limitation Obligation under the Singapore PDPA and take appropriate steps to ensure that the recipient provides a standard of protection comparable to that required under the PDPA.
IIAC
Transfers of personal data from the Republic of Korea
Where personal information is collected or otherwise processed in the Republic of Korea, any transfer of that personal information outside the Republic of Korea will be carried out in accordance with the Personal Information Protection Act (PIPA), including the requirements applicable to cross-border transfers of personal information.
Depending on the circumstances, a cross-border transfer may be made on the basis of a recognised equivalent level of protection in the receiving jurisdiction, the data subject's separate consent, a provision of applicable law, treaty or international agreement, an approved certification mechanism, or another basis permitted under the PIPA. Where processing or storage outside Korea is necessary for the conclusion or performance of a contract with the data subject, a transfer may also be made in accordance with the applicable PIPA requirements, including the relevant transparency requirements.
Where required, we will provide information concerning the personal information being transferred, the destination country, the recipient, the purpose of the transfer and use by the recipient, the period of retention and use, and the means by which the data subject may exercise applicable rights. We will also implement appropriate technical, organisational and contractual measures to protect personal information transferred overseas.
Transfer from the Republic of Korea to the Netherlands
The Netherlands is a Member State of the European Union and is subject to the General Data Protection Regulation (GDPR). The Personal Information Protection Commission of the Republic of Korea (PIPC) has recognised the European Union's personal data protection framework as providing a level of protection substantially equivalent to that provided under Korean law.
Accordingly, where the conditions of that recognition are met, personal information may be transferred from the Republic of Korea to recipients in the Netherlands on the basis of the PIPC's equivalence recognition, in accordance with the PIPA. Together with the European Commission's adequacy decision for the Republic of Korea, this provides for a framework for the free and safe flow of personal data between the Republic of Korea and the European Union without the need for an additional international transfer mechanism solely because the data is transferred between those jurisdictions.
Recipients established in the Netherlands are subject, where applicable, to the GDPR and applicable Dutch data protection legislation. This includes obligations relating to lawful, fair and transparent processing, purpose limitation, data minimisation, security and retention of personal data.
Data subjects retain their applicable rights under the PIPA, including rights relating to access, correction or erasure, and suspension of processing. Where the processing by the recipient in the Netherlands is subject to the GDPR, data subjects may additionally exercise applicable GDPR rights, including the rights of access, rectification and erasure, restriction of and objection to processing, and data portability where applicable, as well as the right to lodge a complaint with the competent European supervisory authority.
Transfer from the Republic of Korea to Singapore
Singapore has not been recognised by the Korean Personal Information Protection Commission as providing an equivalent level of protection for the purposes of the PIPA in the same manner as the European Union. A transfer of personal information from the Republic of Korea to Singapore will therefore be made only where another permitted basis for cross-border transfer under the PIPA applies.
Depending on the circumstances, this may include obtaining the data subject's separate consent to the overseas transfer; relying on a specific provision of law, treaty or international agreement; transferring to a recipient satisfying an applicable certification mechanism recognised by the PIPC; or, where processing or storage in Singapore is necessary for the conclusion or performance of a contract with the data subject, complying with the applicable PIPA transparency and notification requirements.
We will take appropriate measures to ensure the security of personal information transferred to Singapore and, where required, agree with the recipient on measures concerning information security, the handling of data-subject complaints, dispute resolution and other measures necessary to protect the rights of data subjects.
Recipients in Singapore may additionally be subject to Singapore's Personal Data Protection Act 2012 (PDPA). The PDPA establishes obligations relating to the collection, use, disclosure, protection, accuracy, retention and management of personal data. Subject to applicable exceptions, individuals may also have rights under the Singapore PDPA to request access to personal data held by an organisation and to request correction of inaccurate or incomplete personal data.
Data subjects continue to retain their applicable rights under the Korean PIPA following an overseas transfer, including rights relating to access, correction or erasure and suspension of processing.
JAA TO
This clause outlines the legal frameworks governing across-border data transfers and associated rights under the General Data Protection Regulation (GDPR). The Art. 44 GDPR “General principle for transfers”[1] apply.
Data Sharing with entity in South Korea (hereafter “IAAA”)
The European Commission has recognised that South Korea ensures an adequate level of data protection, as per its adequacy decision adopted on December 17, 2021. [2]
The Republic of Korea is a third country for the purposes of the GDPR. However, the European Commission has adopted an adequacy decision pursuant to Article 45 GDPR recognising that the Republic of Korea provides an adequate level of protection for personal data transferred from the EEA to entities falling within the scope of the Korean Personal Information Protection Act (PIPA).
The European Commission's first review of this decision, completed in July 2026, confirmed that the Republic of Korea continues to provide an adequate level of protection.
Accordingly, where the relevant recipient falls within the scope of the adequacy decision, personal data may be transferred from the EEA to the Republic of Korea without the need to implement an additional transfer safeguard under Article 46 GDPR. Processing in Korea is also subject, where applicable, to the PIPA and the supplementary Korean rules governing personal data transferred from the European Union.
Where the GDPR applies to our processing, data subjects continue to benefit from their applicable GDPR rights, including the rights of access, rectification and erasure, restriction of and objection to processing, data portability where applicable, and the right to lodge a complaint with the competent supervisory authority. Any onward transfer of personal data from the Republic of Korea will be assessed to ensure that the level of protection required by applicable data protection law is maintained.
This decision permits the transfer of personal data from the European Union to South Korea without requiring additional safeguards.
Data Sharing with entity in Singapore (hereafter “CAAS”)
Singapore is a third country for the purposes of the GDPR and is not currently subject to a European Commission adequacy decision under Article 45 GDPR. Where we transfer personal data from the EEA to a recipient in Singapore, we will therefore ensure that an appropriate transfer mechanism is in place in accordance with Chapter V of the GDPR.
Currently, Singapore does not have an adequacy decision from the European Commission. Therefore, to ensure the protection of personal data when transferred to CAAS, JAA TO has implemented appropriate safeguards in compliance with GDPR requirements. This can be assured using standard contractual clauses, for data transfers between entities through so-called Art. 47 GDPR “Binding Corporate Rules,”[3] through the commitment to comply with Art. 40 GDPR “Codes of Conduct”[4], which have been declared by the European Commission as being generally applicable which legally bind CAAS to uphold data protection standards equivalent to those within the EU.
Depending on the circumstances, such safeguards may include the European Commission's Standard Contractual Clauses pursuant to Article 46 GDPR, Binding Corporate Rules, an approved certification mechanism or code of conduct accompanied by binding commitments, or another legally permitted safeguard.
Where Standard Contractual Clauses or another Article 46 mechanism are used, we will assess the circumstances of the transfer and, where necessary, implement supplementary contractual, organisational or technical measures to ensure an appropriate level of protection. Derogations under Article 49 GDPR will be relied upon only where the requirements for the relevant derogation are satisfied.
Recipients in Singapore may additionally be subject to Singapore's Personal Data Protection Act 2012 (PDPA). Among other requirements, the Singapore PDPA includes a Transfer Limitation Obligation requiring organisations transferring personal data outside Singapore to ensure, in accordance with the applicable requirements, a standard of protection comparable to that provided under the PDPA.
Where the GDPR applies to our processing, data subjects retain their applicable GDPR rights. In addition, where personal data is transferred on the basis of safeguards under Article 46 GDPR, data subjects have the right to be informed about those safeguards and may contact us to obtain information about, or where applicable a copy of, the safeguards used for the transfer.
Your Rights
In accordance with the GDPR, you retain the following rights concerning your personal data:
-
Access: You may request confirmation as to whether your personal data is being processed and, if so, access to that data.
-
Rectification: You have the right to request the correction of any inaccurate or incomplete personal data.
-
Erasure: You can request the deletion of your personal data under certain conditions.
-
Restriction of Processing: You may request limitations on the processing of your personal data under specific circumstances.
-
Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
-
Objection: You can object to the processing of your personal data on grounds relating to your particular situation.
[1]https://gdpr-info.eu/art-44-gdpr/
[2] https://pipc.go.kr/eng/user/ltn/new/noticeDetail.do?bbsId=null&nttId=1782
