Data Protection Policy

How the IVAO United Kingdom & Ireland Division safeguards personal data and upholds your rights.

Last updated September 2026

Working alongside our Privacy Policy

This policy sets out how we protect personal data and uphold your rights. For the detail of what data we hold and why, see our Privacy Policy. It operates within the wider IVAO Privacy Policy, which takes precedence where they differ.

1Purpose & scope

This Data Protection Policy explains the commitments and safeguards the IVAO United Kingdom & Ireland Division ("XU Division", "we") applies to personal data processed through this website (xu.ivao.aero). It applies to all members whose data we handle and to all staff who handle it on our behalf.

2Our data-protection principles

We handle personal data in line with the following principles:

1

Lawfulness, fairness & transparency

We process data on a clear legal basis and tell you how and why through our Privacy Policy.

2

Purpose limitation

We collect data for specified division purposes and do not reuse it for unrelated ones.

3

Data minimisation

We collect only what is necessary to run division services - nothing more.

4

Accuracy

We keep data accurate and up to date, and let you correct it.

5

Storage limitation

We keep data only for as long as it is needed, then remove or anonymise it.

6

Integrity & confidentiality

We protect data with appropriate security and restrict access to authorised staff.

7

Accountability

We take responsibility for how data is handled and can demonstrate our compliance.

3Roles & responsibility

The XU Division is responsible for personal data processed through this website, operating within the systems and framework of the International Virtual Aviation Organisation. Day-to-day responsibility rests with the Web Department, and every staff member with access to member data is accountable for handling it in line with this policy.

4Lawful bases for processing

We process personal data on the basis of providing our service to you as an IVAO member, our legitimate interest in keeping the platform secure and functional, your consent for optional features (such as linking Discord or connecting Google Calendar), and compliance with applicable obligations. You can withdraw consent for optional features at any time.

5Your rights

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate or incomplete data;
  • Erase data where it is no longer needed;
  • Restrict or object to certain processing;
  • Port data you provided to another service where applicable;
  • Withdraw consent for optional features at any time.

To exercise any of these, contact xu-web@ivao.aero. Requests concerning your core IVAO membership are handled by IVAO HQ.

6Security measures

  • All traffic to the website is served over encrypted connections (HTTPS).
  • Access to member data is restricted to authorised staff and governed by role-based permissions on a least-privilege basis.
  • Sensitive credentials, such as third-party OAuth tokens, are stored encrypted at rest and never exposed to other members or in client-side code.
  • Administrative actions are logged to support auditing and accountability.
  • We apply security updates and review access as part of routine maintenance.

No online service can be guaranteed completely secure, but we take reasonable technical and organisational measures to protect your data.

7Data minimisation & retention

We collect only the data needed to run division services and retain it only as long as necessary - typically while your IVAO membership is active and for a reasonable period afterwards for records, safety and dispute resolution. Logs are rotated routinely and integration tokens are deleted when you disconnect. See the retention detail in our Privacy Policy.

8Processors & international transfers

Where we rely on third-party services to deliver features you enable - such as Discord and Google - those providers process the relevant data under their own terms and safeguards, which may involve transfers outside your country. We share only what is necessary for the feature to work, and only when you have chosen to enable it.

9Data breaches

If we become aware of a personal-data breach, we will assess its scope and impact without undue delay, take steps to contain and remediate it, and notify affected members and IVAO HQ where there is a risk to your rights, in line with applicable requirements. Suspected breaches can be reported to xu-web@ivao.aero.

10Staff obligations

Staff may access member data only where their role requires it, must keep it confidential, and must use it solely for legitimate division purposes. Misuse of member data is a serious breach of trust and is handled under IVAO's disciplinary processes.

11Requests & complaints

To make a data-protection request or raise a concern, email xu-web@ivao.aero. We aim to respond within a reasonable time. If you are not satisfied, you may escalate to IVAO HQ, and you may also have the right to complain to your local data-protection authority.

12Review of this policy

We review this policy periodically and update it as our practices or obligations change. The date at the top of this page reflects the latest revision.

13Contact

For any data-protection matter, contact the Web Department at xu-web@ivao.aero. See also our Privacy Policy and Terms of Use.

Cookie Notice

We use cookies to enhance your browsing experience and analyse site traffic. By clicking "Accept", you consent to our use of cookies.