top of page

PRIVACY POLICY

X1 Platform Privacy Policy

Last Updated: Jun, 08 2026

This Privacy Policy (“Policy”) describes the privacy practices of X-1 and its affiliates.


For purposes of this Policy, “X-1,” “we,” “us,” or “our” means GMSTEK, LLC, doing business as X-1, together with its affiliates, subsidiaries, parent companies, successors, and assigns, including any successor or parent entity operating under the X-1 Group name.


This Policy explains how information is collected, used, processed, retained, and disclosed with respect to your use of X-1’s products, services, applications, integrations, websites, and support services.


For purposes of this Policy, the “X-1 Platform” includes, but is not limited to, X-1FBO, X-1 Data Hub, X-1 Pilot, X-1 Inspect, X-1 Intelligence, X-1 Property, the X-1FBO Connector for Microsoft Dynamics 365 Business Central, and any other products, services, applications, integrations, websites, or support services provided by X-1.


Please read this Policy carefully to understand our practices regarding your information. By using any part of the X-1 Platform, you represent that you are 18 years old or older.


We reserve the right to change the provisions of this Policy at any time. We will indicate the date of the latest update at the top of this page. For material changes, we will notify you by email, by notice on the X-1 Platform, or by another legally appropriate method. You are responsible for ensuring that we have an up-to-date and deliverable email address for you, and for periodically visiting the X-1 Platform and this Policy to check for any changes.


Your continued use of the X-1 Platform following the posting of changes constitutes acceptance of any changes in our privacy practices, to the extent permitted by applicable law and except where your affirmative consent is required.


A. What Information Does This Policy Apply To?

This Policy applies to personal data, personal information, customer business data, operational data, technical data, diagnostic data, and aggregated or de-identified data that X-1 processes in connection with the X-1 Platform.

For purposes of this Policy, “personal data” or “personal information” means information that can be directly or indirectly associated with an individual by reference to an identifier, such as a name, email address, identification number, online identifier, account credential, or other information by which an individual can be identified using reasonable means.

For purposes of this Policy, “customer business data” means data submitted to, stored in, processed by, transmitted through, or generated through the X-1 Platform in connection with a customer’s use of X-1 products or services. This may include operational, transactional, financial, service, aircraft, fuel, hangar, tenant, pricing, invoice, payment, scheduling, and other business records, depending on the products and services used by the customer.

Information covered by this Policy may include information we receive:

  1. From you when you create or use a user account for the X-1 Platform.

  2. Through your use of the X-1 Platform.

  3. Through information submitted by customers, users, or administrators.

  4. In email, text, support tickets, forms, and other electronic communications between you and X-1.

  5. When you interact with our website, advertising, applications, or third-party integrations.

  6. Through any site, application, service, or integration operated by X-1 or one of its affiliates that contains a link to this Policy.

  7. Through diagnostic, operational, technical, or telemetry activity generated by X-1 products, including the X-1FBO Connector for Microsoft Dynamics 365 Business Central.

  8. Through support, implementation, configuration, training, maintenance, monitoring, or product improvement activities.

Depending on the context, X-1 may act as a data controller, business, processor, or service provider under applicable privacy laws. For example, X-1 may act as a controller or business for website activity, account administration, support communications, product diagnostics, and internal product analytics. X-1 may act as a processor or service provider when processing customer business data on behalf of a customer under a separate agreement.


B. Data Privacy Rights

Depending on where you reside and how you interact with the X-1 Platform, you may have certain rights regarding your personal data.


General Data Protection Regulation, UK GDPR, and Similar Laws

If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with similar privacy laws, you may have the following rights with respect to your personal data, subject to applicable legal limitations:

  1. Right of Access: Request access to personal data we process about you.

  2. Right to Rectification: Request correction of inaccurate or incomplete personal data.

  3. Right to Erasure: Request deletion of personal data in certain circumstances.

  4. Right to Restriction of Processing: Request that we limit how your personal data is processed.

  5. Right to Data Portability: Request to receive personal data in a portable format or transfer it to another controller.

  6. Right to Object: Object to certain processing of your personal data based on your circumstances, including certain direct marketing activities.

  7. Right to Withdraw Consent: Withdraw consent where processing is based on consent.

  8. Right Related to Automated Decision-Making: Avoid being subject to decisions based solely on automated processing, including profiling, where applicable law provides this right.

  9. Right to Lodge a Complaint: Lodge a complaint with a supervisory authority where applicable.

California Privacy Laws

If you are a California resident, you may have additional rights under the California Consumer Privacy Act, as amended, including:

  1. The right to know the categories and specific pieces of personal information collected about you.

  2. The right to know the purposes for which personal information is collected, used, disclosed, sold, or shared.

  3. The right to request deletion of personal information, subject to legal exceptions.

  4. The right to request correction of inaccurate personal information.

  5. The right to opt out of the sale or sharing of personal information, where applicable.

  6. The right to limit the use and disclosure of sensitive personal information, where applicable.

  7. The right not to be discriminated against for exercising your privacy rights.

X-1 does not sell personal information. To the extent any analytics, advertising, or similar technology is deemed a “sale” or “sharing” under applicable California privacy law, you may contact us to exercise applicable opt-out rights.


To exercise any privacy rights, contact us using the contact information listed at the end of this Policy.


C. How X-1 Uses Information?

X-1 uses personal information, customer business data, operational data, technical data, diagnostic data, and aggregated or de-identified data to provide, operate, secure, monitor, support, improve, and develop the X-1 Platform.

Specifically, X-1 may process information for the following purposes:


C.1 Platform Operation and Service Delivery

X-1 may process information as reasonably necessary to provide and operate the X-1 Platform, including to:

  1. Provide access to X-1 products and services.

  2. Configure, validate, and support customer environments and integrations.

  3. Process data submitted through the X-1 Platform.

  4. Support workflows, reporting, analytics, notifications, integrations, and customer-configured processes.

  5. Maintain customer accounts, user accounts, permissions, security settings, and access controls.

  6. Provide implementation, onboarding, training, maintenance, and support services.

C.2 System Management, Support, and Troubleshooting

To operate, monitor, troubleshoot, and support the X-1 Platform, X-1 may access and process information as needed to:

  1. Resolve customer support requests.

  2. Investigate errors, outages, synchronization failures, data transfer issues, performance issues, and product defects.

  3. Perform system updates, maintenance, testing, and validation.

  4. Confirm that integrations, connectors, applications, and workflows are operating correctly.

  5. Monitor reliability, stability, availability, security, and performance.

  6. Protect the integrity and continuity of the X-1 Platform.

This access is conducted securely and limited to personnel or service providers with a legitimate business need.


C.3 Platform Improvement and Product Development

X-1 may use information processed through the X-1 Platform to improve, upgrade, enhance, and develop X-1 products and services.

This may include using information to:

  1. Improve existing products, services, workflows, reports, dashboards, analytics, alerts, integrations, and user experiences.

  2. Develop new products, services, features, analytics, reports, dashboards, alerts, and operational tools.

  3. Improve product reliability, data quality, synchronization performance, workflow performance, and support processes.

  4. Identify recurring errors, configuration issues, customer needs, product usage patterns, and opportunities for improvement.

  5. Evaluate and improve the performance of X-1 applications, connectors, integrations, and related systems.

  6. Support internal research, testing, validation, and product planning.

C.4 User Accounts

Your information allows X-1 to create and maintain user accounts, manage access to X-1 resources, authenticate users, provide permissions, and customize the user experience.


C.5 Service Content

Any content you share through the X-1 Platform, including comments, support requests, forms, uploads, records, or other submitted information, may be processed to provide the relevant service, support the customer relationship, and protect the integrity and security of the X-1 Platform.


C.6 Diagnostic Data and Product Reliability

X-1 may use limited diagnostic, technical, and operational data to monitor system performance, detect failures, investigate errors, improve synchronization reliability, support troubleshooting, and improve the quality and reliability of X-1 products and integrations.

Additional details specific to the X-1FBO Connector for Microsoft Dynamics 365 Business Central are provided in Section D below.


C.7 Research, Analytics, and Industry Benchmarking

X-1 may use aggregated, anonymized, or de-identified data for research, analytics, product development, operational analysis, industry benchmarking, pricing analysis, market insights, service improvement, performance measurement, and the development of new or improved products and services.

For example, X-1 may use aggregated, anonymized, or de-identified data to analyze industry trends, regional pricing patterns, fuel volume trends, hangar and real estate utilization, service activity, operational performance, product reliability, integration performance, and other aviation-related market or operational indicators.

X-1 will not use aggregated, anonymized, or de-identified data in a manner that is intended to identify a specific customer, user, aircraft, transaction, invoice, fuel ticket, payment, tenant, vendor, counterparty, or other identifiable business record.


C.8 Market Research and Analysis

X-1 may use aggregated, anonymized, or de-identified data for market research, regional pricing analysis, operational insights, product planning, and industry benchmarking. For example, X-1 may generate region-specific pricing data or provide insights to fulfill certain contractual obligations, such as government, enterprise, or industry analysis obligations.

In all such cases, X-1 uses confidentiality protections and seeks to ensure that the data cannot reasonably be linked to a specific customer, aircraft, transaction, individual, or identifiable business record.


C.9 Service Usage Statistics

X-1 may use analytics tools to understand how users engage with the X-1 Platform, identify usage trends, improve usability, and support product development.


C.10 Direct Marketing

Occasionally, X-1 may use your information to notify you about new services, updates, special offers, events, or other information that may be relevant to you. You may opt out of marketing communications where required by applicable law.


C.11 Relevant Content

X-1 may analyze collected information to present content, product information, or service information that we believe may be relevant to you based on your use of the X-1 Platform.


C.12 Detecting and Preventing Fraud

X-1 may use information to monitor for fraudulent, unauthorized, abusive, or unlawful activity and to protect the X-1 Platform, X-1 customers, users, and third parties.


C.13 Legal Claims and Compliance

X-1 may process or disclose information when necessary to comply with legal obligations, respond to lawful requests, enforce agreements, protect rights or property, defend legal claims, or cooperate with law enforcement or regulatory authorities.


D. Diagnostic Data for the X-1FBO Connector for Microsoft Dynamics 365 Business Central

D.1 Purpose of Connector Diagnostic Data

X-1 may collect and process limited diagnostic data from the X-1FBO Connector for Microsoft Dynamics 365 Business Central, referred to in this Section as the “Connector,” for the purpose of detecting, investigating, and resolving synchronization failures, monitoring product health, improving service reliability, and providing technical support for the Connector.


D.2 Categories of Diagnostic Data

The Connector’s diagnostic data is limited to technical and operational metadata related to the Connector and its execution. This may include:

  1. Tenant identifiers.

  2. Environment identifiers and environment type.

  3. Microsoft Dynamics 365 Business Central version.

  4. Connector extension version.

  5. Event names and event identifiers.

  6. Timestamps.

  7. Error codes and failure categories.

  8. Object, table, page, report, or codeunit identifiers.

  9. Durations, counts, status values, and similar technical values necessary to understand Connector execution.

  10. Sync job identifiers or correlation identifiers used to investigate Connector activity.

  11. Configuration status values necessary to determine whether the Connector is operating as expected.

D.3 No Customer Business Data or Personal Data Intended in Diagnostic Telemetry

The Connector is designed so that its diagnostic telemetry does not include customer business data, transaction content, or personally identifiable information.


X-1 does not intend for the Connector’s diagnostic telemetry to transmit customer names, customer contact information, invoice content, payment content, cardholder data, payment card data, fuel ticket details, transaction amounts, document descriptions, aircraft records, tail numbers, or similar business records.


Because some technical identifiers may be treated as personal data or personal information under certain privacy laws if they can be associated with a person, account, tenant, or environment, X-1 handles Connector diagnostic telemetry in accordance with this Policy and applicable privacy obligations..


D.4 Storage, Location, and Retention

Diagnostic telemetry from the Connector is stored in Microsoft Azure Application Insights in the Azure region used for the X-1 telemetry environment associated with the Connector deployment. The current Connector telemetry environment is located in the East US Azure region in the United States.

Connector diagnostic telemetry is retained for 90 days unless a different period is required by law or needed for security, fraud prevention, enforcement, legal claims, or compliance purposes.

X-1 may change the applicable Azure region, telemetry architecture, or retention period in the future to support product requirements, customer-specific configurations, legal requirements, data residency requirements, security, continuity, or operational needs. If X-1 makes a material change to these practices, X-1 will update this Policy or provide legally appropriate notice.


D.5 How X-1 Uses Connector Diagnostic Data

X-1 uses Connector diagnostic telemetry to:

  1. Detect failed or degraded synchronization activity.

  2. Investigate product defects and integration errors.

  3. Monitor reliability, stability, and service health.

  4. Support troubleshooting and customer support requests.

  5. Improve the Connector and related support processes.

  6. Validate whether Connector versions, configuration settings, or Business Central environments are operating as expected.

  7. Identify recurring error patterns or performance issues..

D.6 Customer Control and Opt-Out

The Connector includes an in-product setting labeled “Share Diagnostics with X-1.” Customers may disable this setting in the Connector’s Interface Setup page.


When this setting is disabled, the Connector will stop transmitting publisher-scoped diagnostic telemetry to X-1. Disabling the setting stops future diagnostic telemetry transmission but does not automatically delete diagnostic telemetry previously transmitted to X-1. Previously collected diagnostic telemetry will be handled in accordance with this Policy, including the retention and deletion practices described in this Policy.


Disabling “Share Diagnostics with X-1” does not affect other data processing that may occur through X-1FBO, the X-1 Platform, Microsoft Dynamics 365 Business Central, customer-configured integrations, customer support activity, or X-1’s use of aggregated, anonymized, or de-identified data as described elsewhere in this Policy and applicable customer agreements..


D.7 Data Subject Requests and Deletion

Where applicable, X-1 will handle requests relating to Connector diagnostic telemetry in accordance with applicable law and X-1’s privacy obligations.


Connector diagnostic telemetry is keyed primarily to technical tenant and environment identifiers. X-1 may use those identifiers to locate and, where appropriate, delete or purge Connector diagnostic telemetry from Azure Application Insights, including through Microsoft’s available delete or purge capabilities.


Because Connector diagnostic telemetry is designed not to include customer business data or personally identifiable information, X-1 may need sufficient technical information from a customer to identify the relevant tenant, environment, time period, or telemetry records..


E. Aggregated and Anonymized Data Use

X-1 may use data processed through the X-1 Platform to create aggregated, anonymized, or de-identified information for legitimate business purposes, including research, analytics, product development, operational analysis, industry benchmarking, pricing analysis, service improvement, performance measurement, market insights, and the development of new or improved products and services.


For example, X-1 may use aggregated, anonymized, or de-identified data to analyze industry trends, regional pricing patterns, fuel volume trends, hangar and real estate utilization, service activity, operational performance, product reliability, integration performance, and other aviation-related market or operational indicators.


X-1 may use and disclose aggregated, anonymized, or de-identified information for lawful business purposes, provided that such information does not identify a specific customer, user, aircraft, transaction, invoice, fuel ticket, payment, tenant, vendor, counterparty, or other identifiable business record.


X-1 does not claim ownership of customer business data submitted to the X-1 Platform. However, X-1 may process customer business data as described in this Policy, applicable customer agreements, and applicable law. X-1 may create, own, use, and disclose aggregated, anonymized, or de-identified data, statistics, analyses, benchmarks, models, insights, and other outputs derived from customer business data, usage data, operational data, technical data, diagnostic data, and other data processed through the X-1 Platform, provided that such outputs do not identify the customer or expose identifiable customer business records.


X-1 takes reasonable measures designed to prevent aggregated, anonymized, or de-identified data from being associated with a specific individual, customer, household, aircraft, transaction, account, invoice, fuel ticket, payment, tenant, vendor, or other identifiable business record.


X-1 publicly commits to maintain and use de-identified data in de-identified form and not to attempt to reidentify such data, except where necessary to test or validate the effectiveness of X-1’s de-identification processes or as otherwise permitted by applicable law.


Where X-1 shares aggregated, anonymized, or de-identified information with customers, partners, vendors, industry participants, government agencies, or other third parties, X-1 will use reasonable measures designed to prevent the recipient from using the information to identify a specific customer, user, aircraft, transaction, invoice, fuel ticket, payment, tenant, vendor, counterparty, or other identifiable business record.


Nothing in this Policy gives X-1 the right to publicly disclose a customer’s identifiable confidential information, customer-specific pricing, customer-specific transaction records, or customer-specific operational records without authorization, except as otherwise permitted under this Policy, an applicable customer agreement, or applicable law.


F. How Do We Protect Your Information?

X-1 implements administrative, technical, and organizational security measures designed to protect against unauthorized access to personal information, customer business data, operational data, technical data, and diagnostic data.


These measures may include access controls, authentication controls, logging, monitoring, encryption where appropriate, secure development practices, employee training, and internal processes that limit access to authorized personnel with a legitimate business need.


When performing benchmarking, market research, support, product analysis, or service improvement activities, X-1 uses commercially reasonable efforts to protect customer confidentiality and reduce the risk of re-identification.


No method of transmission or storage is completely secure. X-1 cannot guarantee absolute security, but we work to maintain safeguards appropriate to the nature of the information we process.


G. How Can You Access and Correct Your Information?

X-1 strives to provide you with access to your personal data and will correct or delete it at your request, subject to applicable legal, contractual, technical, and business requirements.


You may contact us at privacy@x1fbo.com for access, correction, deletion, portability, opt-out, or other privacy-related requests.


X-1 may need to verify your identity or authority before responding to certain requests. If you are submitting a request on behalf of an organization, customer, or another individual, X-1 may request evidence that you are authorized to make the request..


H. Data Retention

X-1 retains personal information while your account is active or as needed to provide services, support customers, comply with legal obligations, resolve disputes, enforce agreements, prevent fraud, maintain security, or support legitimate business purposes.


Customer business data may be retained in accordance with applicable customer agreements, product configuration, backup practices, legal requirements, and customer instructions.


Connector diagnostic telemetry is retained for 90 days unless a different period is required by law or needed for security, fraud prevention, enforcement, legal claims, or compliance purposes.


Aggregated, anonymized, or de-identified data may be retained for longer periods where it no longer identifies a specific individual or customer and is used for legitimate business, analytics, benchmarking, research, product improvement, or market insight purposes.


I. Children Under the Age of 18

The X-1 Platform is not intended for children under the age of 18. X-1 does not knowingly collect personal information from individuals under the age of 18.


If X-1 learns that it has collected personal information from a child under the age of 18 without appropriate authorization, X-1 will take steps to delete that information as required by applicable law.


J. Disclosure of Personal Data

X-1 may disclose personal information, customer business data, operational data, technical data, diagnostic data, or aggregated, anonymized, or de-identified data:

  1. To subsidiaries, affiliates, contractors, service providers, hosting providers, professional advisors, and vendors supporting our business.

  2. To customers or account administrators where disclosure is necessary to provide the X-1 Platform.

  3. To Microsoft Azure or other infrastructure providers used to host, monitor, secure, or operate the X-1 Platform.

  4. As part of a merger, acquisition, financing, divestiture, reorganization, bankruptcy, sale of assets, or similar corporate transaction.

  5. To fulfill the purpose for which you provide the information.

  6. To comply with legal obligations, court orders, subpoenas, regulatory requests, law enforcement requests, or other lawful processes.

  7. To enforce agreements, protect rights or property, prevent fraud, or address security or technical issues.

  8. With your consent or at your direction.

  9. In aggregated, anonymized, or de-identified form for lawful business purposes, including research, analytics, benchmarking, product development, market analysis, and industry insights.

X-1 does not sell personal information.


K. Data Controller, Processor, Business, and Service Provider Roles

X-1 is located in the United States at:

18001 Old Cutler Road
Suite 472
Palmetto Bay, FL 33157


Depending on the context and applicable law, X-1 may act as a data controller or business for certain information, including account information, website activity, support communications, product diagnostics, administrative information, and internal product analytics.


When X-1 processes customer business data on behalf of a customer through the X-1 Platform, X-1 may act as a processor or service provider under applicable privacy laws and the relevant customer agreement.


Customers are responsible for determining whether they have the necessary rights, permissions, notices, and legal bases to provide customer business data to X-1 or to process such data through the X-1 Platform.


L. Transfers of Data

Personal information, customer business data, operational data, technical data, diagnostic data, and aggregated, anonymized, or de-identified data may be processed in the United States and in other locations where X-1, its affiliates, or its service providers maintain facilities or infrastructure.


X-1 uses Microsoft Azure as a cloud infrastructure provider for certain X-1 Platform services, including certain telemetry, monitoring, hosting, and operational functions.


Where information is transferred across borders, X-1 uses appropriate legal and contractual safeguards as required by applicable law. These safeguards may include customer agreements, data processing agreements, standard contractual clauses, applicable adequacy decisions, Data Privacy Framework participation by relevant service providers, or other lawful transfer mechanisms.


M. Contact Information and Inquiries

For questions or concerns regarding this Policy, or to submit a privacy-related request, please contact X1 at:

Email: privacy@x1fbo.com
Address:
X1
18001 Old Cutler Rd.
Suite 472
Palmetto Bay, FL 33157

bottom of page