Legal information
Privacy Notice
How personal data is processed when you use vSAS Live Operations. Last updated: 12 August 2026.
1. Controller and privacy contact
The controller responsible for the processing described in this notice is:
Fabian ZimberPrivate individual operating the open-source project shiftbloom studio
Up de Worth 6a
22927 Großhansdorf
Germany
Privacy email: fabian@shiftbloom.studio
2. Scope and data sources
This notice covers the web application, its same-origin API, and the operational data handled through them. Data comes from you, Virtual Airline administrators and dispatchers, the configured authentication provider, and—when live ACARS is enabled—participating Hoppie's ACARS stations.
The service is multi-tenant. Membership and operational records are restricted to the Virtual Airline organization associated with your authenticated account.
3. Processing activities and legal bases
| Data | Purpose | Legal basis | Retention criteria |
|---|---|---|---|
| Account identifiers, name, email or login identifier, organization, role, display name, and pilot callsign | Authenticate you, maintain membership, authorize tenant and role access, and administer the service | Article 6(1)(b) GDPR where needed to provide the requested member service; otherwise Article 6(1)(f) GDPR (operate and secure the voluntary service) | For the active account or membership and afterwards only while needed for account closure, legal obligations, or legal claims |
| Availability windows, schedule requests, preferences, notes, assigned flights, timestamps, and operational status | Build and coordinate requested virtual flight schedules and keep an operational history | Article 6(1)(b) GDPR where needed for the member service; otherwise Article 6(1)(f) GDPR (coordinate Virtual Airline operations) | While required for the member service and operational history; then deleted or anonymized unless obligations or claims require longer retention |
| Hoppie's ACARS station identifiers, virtual message text, direction, provider metadata, and timestamps | Exchange and display virtual operational messages through Hoppie's ACARS | Article 6(1)(b) GDPR where needed for the member service; otherwise Article 6(1)(f) GDPR (operate Virtual Airline communications) | While needed for current operations, support, abuse handling, and legal claims. The external Hoppie queue states a 24-hour message lifetime |
| Audit events, request IDs, authentication events, IP address, device/browser and server log data, and BotID challenge results and browser/request signals on protected mutations | Protect accounts and infrastructure, diagnose faults, prevent abuse, and establish or defend legal claims | Article 6(1)(f) GDPR (legitimate interests in secure and reliable operations) | Only for the period necessary for security review, incident response, troubleshooting, and applicable claims; records are then deleted or aggregated |
| Aggregated page routes, referrers, coarse location and device categories, and browser performance metrics | Understand service usage and improve reliability and performance | Article 6(1)(a) GDPR (consent); the optional telemetry remains off until allowed | According to the configured Vercel Analytics and Speed Insights retention periods; Web Analytics visitor hashes reset daily |
You are not legally required to provide this information. Account and core operational data are, however, necessary to provide the signed-in service. Without them, an account or requested dispatch function may not be available.
4. Recipients and service providers
Authorized Virtual Airline members receive only the information their operational role permits. The following providers process data to run the service:
- Clerk, Inc. — account authentication, organization membership, sessions, and abuse protection. See the Clerk Data Processing Addendum.
- Vercel Inc. — application hosting, delivery, server execution, infrastructure logs, privacy-preserving web analytics, performance measurement, and bot and abuse detection. See the Vercel Data Processing Addendum.
- Neon, LLC — managed application database and backups. See the Neon Data Processing Agreement.
- Hoppie's ACARS — only when a tenant configures its Hoppie ground station. Station identifiers and messages are relayed through a Netherlands-hosted hobby network. Hoppie warns that ACARS is not a private messaging system and messages may be visible to others. Never put personal, confidential, or special-category data in an ACARS message. See the Hoppie privacy statement.
5. International transfers
Some providers are established in the United States or use subprocessors outside the European Economic Area. Where personal data is transferred to a country without an EU adequacy decision, the controller relies on an applicable transfer mechanism such as the EU Standard Contractual Clauses and supplementary safeguards. Where a provider is validly certified, the EU–US Data Privacy Framework may be used. Current subprocessor and transfer details are available from the provider documents linked above.
7. Your rights
Subject to the applicable conditions, you have the right to access your data (Article 15 GDPR), rectify inaccurate data (Article 16), erase data (Article 17), restrict processing (Article 18), receive portable data (Article 20), and object to processing based on legitimate interests (Article 21). You may also withdraw consent at any time for future processing. This deployment relies on consent only for optional Vercel Analytics and Speed Insights.
Send a request to fabian@shiftbloom.studio. We may need to verify your identity before disclosing or changing account data.
8. Complaints
You have the right to lodge a complaint with a data-protection supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or the alleged infringement. The authority configured for the controller is Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD).
9. Security and automated decisions
The service uses role-based access, tenant isolation, encrypted transport, encrypted storage for provider credentials, request-level audit identifiers, and security headers. Access is limited to people and providers who need it for the stated purposes. No solely automated decision with legal or similarly significant effects is made. BotID automatically classifies protected requests for abuse prevention as described above; it is not used for marketing or member evaluation.
10. Changes to this notice
This notice is updated when processing purposes, providers, browser storage, or legal requirements change. A changed notice version causes the cookie notice to be shown again. Material changes that require consent will not take effect for optional processing until valid consent has been obtained.