Privacy Policy
Fly UVA, Inc. (“Fly UVA”, “UVA”, “we”, “us”)
This notice explains what personal data Fly UVA collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it — including your rights under the EU General Data Protection Regulation (Regulation (EU) 2016/679).
Effective: 5 August 2026 | Version: 2.0 | Last reviewed: 5 August 2026
Applies to: flyuva.org, crew7.flyuva.org, docs.flyuva.org
This document is a GDPR Article 13 and 14 notice.
The short version
We are a non-profit flight-simulation community. We collect the information we need to run a pilot roster and record your simulated flights — nothing more. This summary is here to make the notice readable; it does not replace the detail below, and the sections that follow are what actually govern how we handle your data.
-
We collect what the roster needs. Your name, email, date of birth, the flights you file, and the technical data our website records to stay online and secure.
-
We never sell your data. No sale, no rental, no trade, no advertising networks — ever. Section 5 names every party that does receive data and why.
-
Your data is stored in the United States. We are a US organization on US hosting. If you are in the EEA or UK, section 6 explains exactly what that means for you.
-
You can get a copy, a correction, or a deletion. Email hr@flyuva.org. We respond within one month, free of charge. Section 8 lists every right you have.
1. Who We Are
For the purposes of the GDPR, the data controller — the organization that decides why and how your personal data is used — is:
| Legal entity | Fly UVA, Inc., a non-profit corporation |
| Incorporated in | Oregon, United States |
| Entity number | EIN 41-2934756 |
| Registered office | Springfield, Oregon 97477, United States |
| Privacy contact | hr@flyuva.org |
| Websites covered | flyuva.org, crew7.flyuva.org, docs.flyuva.org |
Data Protection Officer
We are not required to appoint a Data Protection Officer under Article 37 GDPR: we are not a public authority, our core activities do not involve large-scale systematic monitoring, and we do not process special categories of data at scale. Privacy requests are handled by our Human Resources department via the privacy address above.
EU representative (Article 27)
We have not appointed a representative in the European Union. We are a small volunteer non-profit with a limited number of EEA members, and we have recorded a documented assessment of this position which we review annually. This does not limit your rights in any way: EEA and UK members can reach us directly at hr@flyuva.org, and you retain the right to complain to your national supervisory authority as set out in section 14.
Why this notice mentions EU law. We are established in the United States, but we accept members who live in the European Economic Area and the United Kingdom. Article 3(2) GDPR applies to organizations outside the Union that offer services to people inside it, so the GDPR applies to how we handle those members’ data — regardless of the fact that membership is free. Where this notice describes a GDPR right, that right is available to you as a matter of law if you are in the EEA or UK.
2. What Personal Data We Collect
The tables below list every category of personal data our systems hold about you. Items marked Required must be provided to hold membership; everything else is optional and there is no consequence if you leave it out.
2.1 Data you give us
| Data | Where it comes from | Status |
|---|---|---|
| First and last name | Membership application | Required |
| Email address | Membership application | Required |
| Date of birth (used to confirm you are 14 or over) | Membership application | Required |
| Password (stored only as a one-way hash — we never see it) | Registration | Required |
| Home hub / base airport | Membership application, or a later hub transfer request | Required |
| VATSIM ID (CID) | Membership application or profile | Optional |
| IVAO ID | Membership application or profile | Optional |
| Country and timezone | Profile | Optional |
| Discord username and Discord account ID | Profile, or the optional Discord account link | Optional |
| Profile avatar image | Profile upload | Optional |
| “How did you hear about us” | Membership application | Optional |
| Messages you send us | Contact form, email, support requests | Optional |
| Newsletter / event mailing preference | Your opt-in choice | Optional |
Why we ask for your real name. We ask for a real first and last name so that we can be reasonably confident members are who they say they are — it keeps our roster accountable, keeps your record consistent with any VATSIM or Discord account you choose to link, and lets our staff verify who they are dealing with if a membership question or dispute arises. Your full name is not shown publicly — our roster, leaderboards and public pages display your first name and last initial only.
2.2 Data created by your use of UVA
| Data | Detail |
|---|---|
| Pilot ID | The member identifier we assign to you (e.g. UAL1234), plus your airline, rank, hub and membership status. |
| Flight reports (PIREPs) | Departure and arrival airports, aircraft, route, flight time, fuel, landing rate, on-time performance, remarks, and any log or telemetry submitted by an ACARS client. |
| Aggregate flight statistics | Total flights, total and transferred flight hours, awards, rank progression, tour and event participation. |
| Aircraft and route usage | Which aircraft and routes you fly, used for fleet and network planning. |
| API key | A credential issued to your account so an ACARS client can file reports on your behalf. |
| Application and moderation records | Who reviewed your application, when, the outcome, and — if declined — the reason recorded. |
| Staff notes | Free-text notes our staff may add to your member record for continuity (for example, an approved leave of absence or the outcome of a support request). These notes are part of your personal data and are disclosed to you if you make an access request under section 8. Our staff are instructed not to record health, beliefs, or other sensitive information. |
| Consent and acceptance records | Whether you accepted our terms, whether you opted in to mailings, and when. |
2.3 Technical data collected automatically
| Data | Detail |
|---|---|
| IP address | Recorded when you register and updated at each login. IP addresses are personal data under EU law and we treat them accordingly. |
| Login timestamps | The date and time of your most recent sign-in. |
| Web server access logs | IP address, date and time, the pages requested, referring page, browser and operating system identifier (user agent), and response status. |
| Session and security cookies | See section 10. |
| Anti-spam signals | Data processed by hCaptcha when you submit our registration form. See sections 5 and 10. |
| Error and diagnostic logs | Technical detail recorded when something goes wrong, which can include the request that failed and the account associated with it. |
2.4 Data we do not collect
We do not collect payment card details, government identification, or any special category of data under Article 9 GDPR — that is, data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation. Please do not send us this kind of information; if you do, we will delete it.
3. Data We Receive From Other Sources
Not all of the data we hold comes directly from you. Article 14 GDPR requires us to tell you where the rest of it comes from.
| Source | What we receive | Why |
|---|---|---|
| VATSIM public data feed | Your VATSIM CID, the name registered on your VATSIM account, callsign, and live network activity while you are connected under a UVA callsign. | To confirm your VATSIM membership is valid and to credit network flights to your UVA record. This is drawn from VATSIM’s publicly published network data feed. |
| ACARS flight tracking clients | Flight telemetry — position, altitude, speed, fuel, phase of flight, landing rate — submitted through the client you choose to install. | To record your flight automatically instead of requiring a manual report. |
| Discord | Your Discord account ID and server nickname, only if you choose to link your Discord account. | To apply your pilot ID, rank and hub roles automatically in our Discord server. |
4. Why We Use Your Data, And Our Lawful Basis
Article 6 GDPR requires us to have a specific lawful basis for every purpose we use your data for, and Article 13(1)(c) requires us to tell you what it is. This table is that disclosure. Where we rely on legitimate interests, we also name the interest, as Article 13(1)(d) requires.
| Purpose | Lawful basis | Explanation |
|---|---|---|
| Reviewing your membership application | Article 6(1)(b) — steps taken at your request before entering into a contract | You ask to join; we need your application data to decide. Applications are reviewed by a person, not by a machine. |
| Creating and running your member account | Article 6(1)(b) — performance of a contract | Our membership terms form a contract between us, even though membership is free. We cannot maintain a roster without an account record. |
| Recording your flights, hours, ranks and awards | Article 6(1)(b) — performance of a contract | This is the service you signed up for. A virtual airline that does not record your flights is not providing it. |
| Operating ACARS flight tracking | Article 6(1)(b) — performance of a contract | Applies only if you install and use an ACARS client, which is your choice. |
| Sharing member and flight data with VATSIM for verification and compliance audits | Article 6(1)(f) — legitimate interests | Our interest, and VATSIM’s: maintaining the integrity of a shared simulation network, confirming that members flying under our callsigns are in good standing, and responding to a VATSIM compliance query. We have assessed this against your interests and consider the impact minimal, since the data involved is the same identity and flight data VATSIM already holds about you as its own member. |
| Service and account emails — password resets, flight report accepted or rejected, rank changes, hub transfers, membership status, changes to this policy | Article 6(1)(b) — performance of a contract | These are not marketing and you cannot unsubscribe from them while you hold an account, because they are how we administer your membership. Closing your account stops them. |
| Event announcements, newsletters and community mailings | Article 6(1)(a) — consent | Sent only if you opt in. You can withdraw at any time using the unsubscribe link in every message or by emailing us; withdrawal is as easy as opting in, and does not affect the lawfulness of anything we sent before you withdrew. |
| Site security, anti-spam and abuse prevention — hCaptcha, IP logging, login records, rate limiting, ban enforcement | Article 6(1)(f) — legitimate interests | Our interest: preventing automated account creation, credential-stuffing and abuse of our registration form, and keeping the site available. Recital 49 GDPR expressly recognizes network and information security as a legitimate interest. We enabled these controls in response to a real, documented spam campaign against our registration form. |
| Fleet and route planning — analyzing which aircraft and routes are flown | Article 6(1)(f) — legitimate interests | Our interest: deciding which aircraft to add to the virtual fleet and which routes to schedule. Outputs are aggregated across the membership; we are not profiling you individually. |
| Website traffic analysis — server log statistics | Article 6(1)(f) — legitimate interests | Our interest: understanding how the site is used and diagnosing faults. See section 10 — this is server-log analysis, not tracking software on your device. |
| Discord role and nickname synchronisation | Article 6(1)(a) — consent | Entirely optional. Linking your Discord account is an affirmative action you take, and unlinking it withdraws that consent — we then delete the stored Discord identifiers from your member record. |
| Staff notes on member records | Article 6(1)(f) — legitimate interests | Our interest: continuity of staff decisions across a volunteer team, and fair handling of disputes. You can see these notes at any time by making an access request. |
| Age eligibility checks and birthday recognition | Article 6(1)(f) — legitimate interests, with the Article 8 conditions in section 11 | Our interest: confirming applicants meet our minimum age of 14, and recognizing members’ birthdays within the community. Your date of birth is not shown on your public roster entry. |
| Keeping records of removed or banned members | Article 6(1)(f) — legitimate interests | Our interest: preventing a removed member from rejoining under a new identity, and defending ourselves if a decision is challenged. Article 17(3)(e) GDPR permits retention for the establishment, exercise or defense of legal claims. We keep only an identifier, the reason and the date — not the full account. |
| Backups and disaster recovery | Article 6(1)(f) — legitimate interests | Our interest: being able to restore the site after a failure. Article 32 GDPR requires us to be able to do this. |
If you object to a legitimate-interests purpose. Where we rely on legitimate interests, you have the right under Article 21(1) GDPR to object on grounds relating to your particular situation. We will stop that processing unless we can demonstrate compelling legitimate grounds that override your interests, or we need the data to establish, exercise or defend legal claims. Email hr@flyuva.org and tell us which purpose and why. You can also ask us for our assessment of any of these interests.
Providing your data. Your name, email address, date of birth, home hub and a password are a contractual requirement of membership, along with acceptance of our terms: without them we cannot create or maintain your account, and your application cannot be granted. Every other field described in section 2.1 — including your VATSIM ID — is optional, and declining to provide it has no effect on your membership.
5. Who We Share Your Data With
This is the complete list. We do not share your personal data with anyone else, and we will update this section before adding a recipient to it.
| Recipient | Relationship | What they receive, and why |
|---|---|---|
| Our web hosting provider | Processor | Hosts our websites, databases, backups and email. They can technically access all data we hold, but may only act on our documented instructions and may not use it for their own purposes. |
| VATSIM vatsim.net |
Independent controller | Your name, pilot ID, VATSIM CID and flight records, where needed for verification or a compliance audit. VATSIM decides independently how it uses data you hold with them, under their own privacy policy. |
| hCaptcha Intuition Machines, Inc., US |
Processor | Your IP address, browser data and interaction signals when you submit our registration form, used to tell a person from an automated script. See their privacy policy. |
| ACARS client vendors vmsACARS (phpVMS), smartCARS 3 (TFDi Design) |
Processor | Only if you install that client: your account credentials for the client, and the flight telemetry it transmits. Each vendor also operates its own privacy policy for the software itself. |
| Discord Discord Inc., US |
Independent controller | Only if you link your account: your pilot ID, first name and last initial, and hub — used to set your server nickname and roles. Everything you do on Discord itself is governed by Discord’s privacy policy, not this one. |
| vaCentral phpVMS central statistics |
Independent controller | Aggregate airline statistics and, where enabled, pilot flight totals shared with the phpVMS virtual airline directory. |
| Law enforcement or a regulator | — | Only where we are legally compelled to disclose, or where disclosure is necessary to establish, exercise or defend legal claims. We will tell you if this happens unless we are prohibited from doing so. |
| A successor organization | Controller | If UVA merges with or transfers its operations to another organization, member records may transfer with it. We will notify you in advance and this policy will continue to apply until you are given a new one. |
We do not sell, rent or trade your personal information — under any circumstances. We do not use advertising networks, we do not share data with data brokers, and we do not permit any recipient above to use your data for their own marketing.
Public visibility. Your first name, last initial, pilot ID, rank, hub and flight statistics appear on our public roster, leaderboards and live map. Your email address, full surname, IP address and staff notes are never published.
6. International Transfers
Fly UVA is established in the United States and all of our systems — website, database, backups and email — are hosted in the United States. If you are in the EEA or the UK, this section explains what that means and what protects you.
6.1 Data you send us directly
When you complete our registration form or update your profile, you are sending your data to us on your own initiative. Under the European Data Protection Board’s Guidelines 05/2021, that is not a “transfer” under Chapter V GDPR, because you are the one sending it and a data subject is not an exporter. Every other obligation in the GDPR still applies to us in full — this notice, your rights, our security duties and our breach duties are all unaffected.
6.2 Onward disclosures to our vendors and partners
When we pass data on to a recipient listed in section 5, that is a restricted transfer and we must provide an appropriate safeguard for it. We rely on the following, in this order:
-
The EU–US Data Privacy Framework. Where a recipient is self-certified under the Framework, the European Commission’s adequacy decision of 10 July 2023 covers the transfer and no further safeguard is needed.
-
Standard Contractual Clauses. Where a recipient is not certified, we rely on the European Commission’s standard contractual clauses as incorporated into our agreement with that recipient, together with an assessment of the risk of the transfer.
You have the right under Article 13(1)(f) GDPR to obtain a copy of the safeguards we rely on for any specific recipient. Email hr@flyuva.org and name the recipient and we will provide it.
Being straight with you about what this means. The United States has not been found to provide a general level of data protection equivalent to the EU’s. In practice, the data we hold is a hobby flight-simulation roster: names, email addresses, simulated flights and IP addresses. It contains no financial data, no identity documents and no special category data. We think the risk to you is low, but you are entitled to know the position rather than be reassured about it. If you would prefer not to have your data stored in the United States, we are not able to offer EEA hosting, and the honest answer is that UVA membership is not right for you.
7. How Long We Keep Your Data
Article 5(1)(e) GDPR requires that we keep personal data no longer than necessary. These are our retention periods.
| Data | Retention | Why |
|---|---|---|
| Active member account | For as long as you are a member | Needed to provide the service. |
| Account after you leave or are removed | 12 months, then anonymized | A grace period so returning members keep their history and pilot ID. After that, identifying fields are permanently removed. |
| Declined applications | 24 hours | Long enough for our staff to reverse a decision made in error. Deleted automatically the next day, including the reason recorded. We keep nothing about applicants who never became members. |
| Flight reports and flight statistics | Retained indefinitely, detached from your identity once your account is anonymized | Historic fleet and route statistics survive without remaining personal data. |
| IP address and login timestamps on your account | For as long as your account is open | Used to detect unauthorized access to your account. Removed together with the rest of your record when your account is closed. |
| Web server access logs | 30 days | Security monitoring and fault diagnosis only. |
| Error and diagnostic logs | 30 days, then rotated out | Long enough to investigate a fault. |
| Traffic statistics | Retained as aggregate monthly totals | Aggregates only; individual-level detail is purged on the log schedule above. |
| Removal and ban records | 3 years | Minimal record only — identifier, reason and date — under Article 17(3)(e) GDPR. |
| Correspondence with us | 2 years after the matter is closed | So we can pick up a thread and evidence what was agreed. |
| Backups | Until they age out of our hosting provider’s rotation | A deletion takes effect immediately in our live systems and works its way out of backups as those backups are cycled. We do not restore deleted data from a backup. |
When we say anonymized, we mean your name, email address, IP address, VATSIM ID, Discord identifiers and staff notes are permanently removed and cannot be recovered — not that your record is hidden or flagged inactive.
8. Your Rights
If you are in the European Economic Area or the United Kingdom, you have all of the following rights. They are not conditional and you do not need to give a reason to ask us about them. We extend the same rights to every member wherever they live, as a matter of policy.
| Right | What it means |
|---|---|
| Access — Article 15 | Ask whether we hold data about you, and get a copy of it along with the information in this notice. The first copy is free. |
| Rectification — Article 16 | Have inaccurate data corrected and incomplete data completed. Most profile fields you can correct yourself in the Crew Center. |
| Erasure — Article 17 | Have your data deleted where it is no longer needed, where you withdraw consent and there is no other basis, or where you successfully object. Limited exceptions apply — see the retention table for ban records. |
| Restriction — Article 18 | Have us pause processing while a dispute about accuracy or a legitimate-interests objection is resolved. |
| Portability — Article 20 | Receive the data you gave us, and your flight history, in a structured, commonly used, machine-readable format, and have it sent to another organization where technically feasible. We provide this as a CSV export. |
| Objection — Article 21 | Object to any processing we base on legitimate interests, on grounds relating to your situation. See the note in section 4. |
| Withdraw consent — Article 7(3) | Where we rely on consent — mailings and Discord linking, and nothing else — withdraw it at any time. Withdrawal is as easy as giving it, and does not affect the lawfulness of processing carried out before you withdrew. |
| Complain — Article 77 | Lodge a complaint with a supervisory authority. See section 14. |
Your right to object to marketing is absolute. You may object at any time to our use of your data for direct marketing — including our newsletter and event announcements — and we must stop immediately. There is nothing to weigh up and no reason required. Use the unsubscribe link in any message, turn the preference off in your Crew Center profile, or email hr@flyuva.org. You will still receive essential service emails about your account.
How to exercise your rights
Email hr@flyuva.org from the address registered on your account, and tell us what you want. There is no form to complete.
-
Timescale. We will respond without undue delay and in any event within one month of receiving your request. If your request is complex, we may extend by up to two further months — we will tell you within the first month if that happens, and why.
-
Cost. Free. We may charge a reasonable fee, or refuse, only if a request is manifestly unfounded or excessive — for example repeated identical requests — and we will explain our reasoning if we do.
-
Identity. If we have genuine doubt about who is asking, we may ask you to confirm your identity — normally by replying from your registered email address. We will not use this as an obstacle.
-
Onward notification. Where we correct or delete your data, we will tell each recipient it was disclosed to, unless that proves impossible or disproportionate. You can ask us who those recipients were.
-
If we refuse. We will tell you within one month, explain why, and tell you that you can complain to a supervisory authority and seek a judicial remedy.
9. How We Protect Your Data
Article 32 GDPR requires security measures appropriate to the risk. Rather than a general assurance, here is what we actually do.
Measures in place
-
All connections to our websites are encrypted in transit with TLS.
-
Passwords are stored only as salted one-way hashes. We cannot read your password and will never ask you for it.
-
Administrative access is role-based: staff accounts are granted only the permissions their role requires, and access to member records is limited to staff who need it.
-
Automated spam and abuse controls on registration and login.
-
Regular backups, held for the period stated in section 7.
-
Log rotation and enforced retention limits so old records do not accumulate.
-
A periodic internal review of accounts, access and these measures.
If something goes wrong
If a personal data breach occurs, we will notify the competent supervisory authority within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to your rights and freedoms (Article 33 GDPR). Where a breach is likely to result in a high risk to you, we will contact you directly and without undue delay, describe what happened and what we are doing about it (Article 34 GDPR). We keep an internal record of all breaches, including those we are not required to report.
No system is completely secure. We do not claim our measures are impenetrable, and no method of transmitting or storing data online can be guaranteed. Please use a strong, unique password for your account and tell us at hr@flyuva.org if you believe your account has been compromised or if you have found a security issue on our site.
10. Cookies And Website Analytics
We use a small number of cookies, all of them strictly necessary to operate the site or to keep it secure. We do not use advertising cookies, tracking pixels or cross-site profiling, and we do not deploy any third-party analytics software on your device.
| Cookie | Set by | Purpose | Duration |
|---|---|---|---|
uva_session / laravel_session |
UVA (first party) | Keeps you signed in to the Crew Center and links your browser to your session. | 2 hours of inactivity |
XSRF-TOKEN |
UVA (first party) | Protects forms against cross-site request forgery. | Session |
remember_web_* |
UVA (first party) | Set only if you tick “remember me” at login. | Up to 5 years, or until you sign out |
| hCaptcha storage | Intuition Machines, Inc. (third party) | Set when the anti-spam challenge loads on our registration form, to distinguish a person from an automated script. We do not control what hCaptcha stores; see their privacy policy. | Set by hCaptcha |
Because these cookies are strictly necessary to deliver a service you have asked for, we do not need your consent to set them and we do not show a cookie banner. You can block or delete cookies in your browser settings, but the Crew Center will not be able to keep you signed in if you block the session cookie.
Website statistics
Our traffic statistics are produced by AWStats and Webalizer, which analyze the access logs our web server already writes. They do not place anything on your device, do not read your device storage, and cannot follow you to another website. They do process IP addresses, which we rely on legitimate interests for (section 4) and retain for the period in section 7. We have made a deliberate decision not to use Google Analytics or any comparable client-side analytics product.
Do Not Track
We do not track you across other websites, so there is nothing for a Do Not Track signal to disable. We honor it by default simply by not doing the thing it asks us to stop.
11. Age Requirements And Younger Members
Minimum age
You must be at least 14 years old to hold a UVA membership, anywhere in the world. This is why we ask for your date of birth when you apply.
If you are in the EEA or the UK
Article 8 GDPR sets an age of digital consent of 16, which individual countries may lower to no less than 13. The age that applies to you is the one set by your own country, not ours — it is 16 in some member states, and 15, 14 or 13 in others.
Our minimum age of 14 sits below that threshold in several countries. So if you are 14 or 15 and your country sets its age of digital consent higher, you can still join — but we need a parent or guardian’s consent for anything we rely on consent for, as set out below.
If you are under the age of digital consent in your country, we require verifiable consent from your parent or guardian before you can opt in to our mailings or link a Discord account, and before we process your data on the basis of consent for any other purpose. In practice we do this by asking for a parent or guardian’s email address and obtaining their confirmation directly. Article 8(3) GDPR also preserves your country’s own rules on whether a minor can enter into a contract, which may independently affect membership.
A parent or guardian can contact us at hr@flyuva.org at any time to review what we hold about their child, have it corrected, have it deleted, or withdraw their consent.
If you are in the United States
Separately from the above, the Children’s Online Privacy Protection Act (COPPA) applies to us as a US organization. COPPA governs the collection of personal information from children under 13; our minimum age of 14 sits above that threshold, and we do not knowingly collect personal information from anyone under 13. If we learn that we have, we will delete it promptly.
If you are a younger member reading this. Here is the short version: we keep your name, your email, and a record of the flights you fly with us. We do not sell it and we do not show it to advertisers. If you want to know what we have about you, or you want it deleted, ask a parent or guardian to email us and we will sort it out.
12. Automated Decision-Making
We do not make decisions about your membership based solely on automated processing. Every application is reviewed by a member of our staff, and so is every decision to suspend or remove a member.
Some parts of the site are automated, and we mention them so the picture is complete: our registration form uses an automated anti-spam check that can reject a submission; flight reports may be automatically accepted or flagged against our flight rules; and rank progression and awards are calculated automatically from your flight hours. None of these produce legal effects or similarly significant effects for you, but if an automated outcome looks wrong you can ask a person to review it — email hr@flyuva.org or contact staff in the Crew Center, and we will look at it manually.
We do not profile you for marketing purposes and we do not build behavioral profiles of members.
13. Changes To This Policy
We will update this notice when our practices change. When we do:
-
We will post the new version here with an updated effective date and version number.
-
For a material change — a new purpose, a new recipient, a new lawful basis, or a longer retention period — we will email members at least 30 days before it takes effect.
-
Where a change requires your consent, we will ask you for it separately. We will not treat your continued use of the site or your silence as agreement to anything.
Version history
| Version | Date | Summary of changes |
|---|---|---|
| 2.0 | 5 August 2026 | Rewritten as a GDPR Article 13 and 14 notice. Added lawful bases for each purpose, the full recipient list, an international transfers section, specific retention periods, the complete set of data subject rights including restriction, portability and objection, a cookie table, an automated decision-making statement, and breach notification commitments. Corrected the age statement for the EEA, removed the incorrect COPPA justification for collecting legal names, and removed the statement that continued use of the site constitutes acceptance. |
| 1.0 | 2025 | Initial privacy policy. |
This notice was last reviewed on 5 August 2026.
14. Contact Us, And How To Complain
Talk to us first
Any question about this notice, and any request to exercise a right in section 8:
| Privacy requests | hr@flyuva.org |
| Membership & HR | hr@flyuva.org |
| Post | Fly UVA, Inc. Springfield, Oregon 97477 United States We are a volunteer organization without a staffed office. If you need to serve a document or send correspondence by post, email us first at hr@flyuva.org and we will provide a full postal address for delivery. |
| Website | www.flyuva.org |
We would genuinely rather fix a problem than have you take it elsewhere — but the route below is your right and using it costs you nothing with us.
Complain to a supervisory authority
If you are in the EEA, Article 77 GDPR gives you the right to lodge a complaint with the supervisory authority in the member state of your habitual residence, your place of work, or the place of the alleged infringement — without prejudice to any other administrative or judicial remedy. A list of national authorities is published by the European Data Protection Board.
If you are in the United Kingdom, you may complain to the Information Commissioner’s Office.
You also have the right under Articles 78 and 79 GDPR to an effective judicial remedy against a supervisory authority or against us.
