GDPR Policy

Introduction

The Virtual Hong Kong Government Flying Service[WE in this page] , operating within the VATSIM Network, is committed to protecting the privacy and personal data of our members, pilots, controllers, and visitors in compliance with the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679). This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you interact with our website, services, or participate in our virtual aviation operations.

As a VSOA in the VATSIM Network, we process data necessary for safe and efficient simulated flight operations, member management, and community engagement. By using our website or services, you consent to the practices described herein. If you do not agree, please do not use our services.


Data Controller

Data Controller: Virtual Hong Kong Government Flying Service (VHKGFS)

Personal Data We Collect

We collect the following categories of personal data:

CategoryExamplePurpose
Identity DataName, VATSIM CID (Pilot/Controller ID), callsign, email addressMember registration, account management, communication
Contact DataEmail, Discord usernameNotifications, event scheduling, support
Technical DataIP address, VATSIM tracking data Website functionality, security, performance analytics

How We Collect Your Data

  1.  Directly from you: Registration forms, profile updates, flight bookings.
  2. Automatically: Cookies, server logs, Discord/Simbrief API integrations.
  3. From third parties: VATSIM Network (e.g., certification data), analytics tools.

Legal Basis For Processing

We process your data based on:

  1. Consent (Art. 6(1)(a)): For non-essential cookies, marketing.
  2. Contract (Art. 6(1)(b)): For VATSIM operations and membership services.
  3. Legitimate Interests (Art. 6(1)(f)): Site security, analytics (balanced against your rights).
  4. Legal Obligation (Art. 6(1)(c)): VATSIM compliance.

You can withdraw consent at any time via your account settings

How We Use Your Data

  1. Provide and improve virtual flying services (e.g., flight scheduling, ATC coordination).
  2. Communicate updates, events, and safety briefings.
  3. Ensure compliance with VATSIM Code of Conduct.
  4. Analyze usage for service enhancements.
  5. Prevent fraud and abuse

Sharing Your Data

We share data only as necessary:

  1. VATSIM Network: For certification, tracking, and network operations.
  2. Service Providers: Hosting (e.g., VATSIM servers), analytics (e.g., Google Analytics โ€“ anonymized), email tools (compliant with GDPR).
  3. Legal Authorities: If required by law.

No data is sold to third parties. All recipients are GDPR-compliant via Data Processing Agreements (DPAs).

International Transfers

As a global virtual network, data may be transferred outside the EEA (e.g., to VATSIM servers in the US). We use:

  1. EU-US Data Privacy Framework.
  2. Standard Contractual Clauses (SCCs).
  3. Adequacy decisions where applicable.

Data Retention

  1. Active Members: Indefinitely while the account is active.
  2. Inactive Accounts: 24 months post-last activity, then anonymized/deleted.
  3. Logs: 12 months for security.

Requests for deletion honored unless legally required.

Your GDPR Rights

You have the following rights:

  1. Access (Art. 15): Request a copy of your data.
  2. Rectification (Art. 16): Correct inaccurate data.
  3. Erasure (“Right to be Forgotten”) (Art. 17): Delete your data (subject to legal holds).
  4. Restriction (Art. 18): Limit processing.
  5. Portability (Art. 20): Receive data in structured format.
  6. Object (Art. 21): To process based on legitimate interests.
  7. Withdraw Consent (Art. 7): At any time.

Security Measures

  1. Encryption (HTTPS, data at rest).
  2. Access controls (role-based).
  3. Regular audits and backups.
  4. Breach notification within 72 hours (Art. 33/34).

Changes to This Policy

VHKGFS may update this policy. Changes posted here with notice via email/banner. Continued use constitutes acceptance


Version 1.0
28/11/2025 13:34 by VHKGFS