ReadyFlyLog Privacy Policy
| Item | Details |
|---|---|
| Version | 1.0 |
| Status | Final publication ready English |
| Effective date | 11 September 2026 |
| Last reviewed | 11 September 2026 |
This Privacy Policy explains how ReadyFlyLog processes personal data when it provides the ReadyFlyLog web service, administers accounts and subscriptions, supports Customers, and processes Workspace data on a Customer's instructions. It also explains the separate responsibilities of ReadyFlyLog and each Customer, the use of Google Drive and Google APIs, retention, international transfers, and individual rights.
The central distinction is that ReadyFlyLog is a controller for its own account, commercial, security, support, and legal-compliance activities, while each Customer is the controller of personal data processed inside its organizational Workspace. ReadyFlyLog processes that Workspace Personal Data for the Customer under the ReadyFlyLog Data Processing Agreement.
1 Who We Are
ReadyFlyLog is operated by Sándor Levente Szabó e.v., a Hungarian individual entrepreneur. When this Policy says ReadyFlyLog, we, us, or our, it refers to this operator.
| Item | Details |
|---|---|
| Registered address | 9400 Sopron, Semmelweis utca 10., Hungary |
| Individual entrepreneur registration number | 61070435 |
| Registry and authority | NAV, Individual Entrepreneurs Register (Egyéni Vállalkozók Nyilvántartása) |
| Hungarian tax number | 91404451-1-28 |
| EU VAT number | HU91404451 |
| Privacy contact | readyflylog@gmail.com |
2 Scope and Key Terms
This Policy applies to visitors to the ReadyFlyLog website, account holders, invited users, Customer Administrators, persons identified in records submitted to a Workspace, and people who contact us. The Terms and Conditions govern use of the Service. The Data Processing Agreement governs ReadyFlyLog's processing of Workspace Personal Data for a Customer.
- Customer means the person or organization that creates, subscribes to, or controls a ReadyFlyLog Workspace.
- Workspace means the Customer-controlled environment in which authorized users manage operational records.
- Workspace Personal Data means personal data entered, generated, or otherwise processed in a Workspace for the Customer's purposes.
- Controller Data means personal data ReadyFlyLog processes for its own account, contractual, commercial, security, support, and legal purposes.
- Google Drive Connection means the optional connection that allows ReadyFlyLog to work with specific files in a user's Google Drive account through the permissions the user grants.
3 Our Data Protection Roles
| Processing context | ReadyFlyLog role | Who decides the purpose and means | Main governing document |
|---|---|---|---|
| Accounts, contracts, subscriptions, billing, Terms acceptance, platform security, support, commercial and capacity administration | Controller | ReadyFlyLog | This Policy and the Terms and Conditions |
| Flight, aircraft, maintenance, membership, Pilot Balance, and related organizational records inside a Workspace | Processor | The Customer | The Data Processing Agreement and Customer instructions |
| Customer-owned files accessed through an optional Google Drive Connection | Processor for the Customer's purpose; user-authorized access to Google | The Customer, with the user choosing the Google account and files made available | The Data Processing Agreement, Google authorization, and applicable Google terms |
The same item can involve both roles. For example, an email address may be Controller Data when used to administer an account and Workspace Personal Data when it identifies a pilot in a Customer's operational record. We apply the rules relevant to each processing purpose.
4 Personal Data We Process
The Service processes the categories below according to the features a Customer and its users use. A field or category listed here may not be present in every account or Workspace.
| Category | Typical data | Main source |
|---|---|---|
| Account and profile | Name, email address, phone number if provided, account and authentication identifiers, account status, and current or last Workspace | The user and authentication service |
| Customer and Workspace | Workspace name, base airport, Customer and billing identity, address, country, tax or VAT details, subscription, trial, and lifecycle status | Customer Administrators and commercial administration |
| Membership and access | Workspace membership, role, invitation, acceptance, and access status | Customer Administrators, invited users, and the Service |
| Flight records | Dates, times, landings, route, remarks, PIC, instructor or student designation, user identifiers, cost, discount, and correction history | Authorized Workspace users |
| Pilot Balance records | Internal top-ups, debits, discounts, and related entries used for Customer accounting inside the Workspace | Authorized Workspace users; these records are not a bank account, wallet, or payment service |
| Maintenance and expense records | Maintenance actions, counters, expenses, actor identifiers, timestamps, and audit history | Authorized Workspace users |
| Aircraft records | Aircraft identification, operational details, status, and capacity-related information | Authorized Workspace users and the Service |
| Aircraft document references | Document metadata, file name, MIME type, size, Google Drive file identifier, folder reference, aircraft association, uploader, and timestamps | Authorized users and Google Drive |
| Google connection | Connected Google email address and account identifier, root folder reference, authorization scope, encrypted or otherwise protected access credentials and tokens, and connection actions | The user, Google, and the Service |
| Terms and legal evidence | Identity, Terms version, UTC timestamp, acceptance source, IP address, and user agent | The user and the Service |
| Commercial and capacity requests | Requester, aircraft block count, monthly or annual selection, currency, immutable EUR price snapshot, request status, administrator, and resolver | Customer Administrators, ReadyFlyLog, and the Service |
| Security and audit | Authentication events, role changes, commercial actions, Master Admin actions, impersonation reason, access context, timestamps, IP address, user agent, and error or security traces | The Service, ReadyFlyLog, and infrastructure providers |
| Support and communications | Message content, attachments voluntarily supplied, contact details, delivery metadata, and support history | The sender, ReadyFlyLog, and transactional email provider |
| Browser storage | Session and authentication state, the readyflylog-cookie-consent acknowledgement value, and session-limited synthetic demo state | The Service and the user's browser |
| User initiated external queries | Briefing, weather, airport-related, or translation input and returned results where a supported Google API feature is used | The user, the Service, and the relevant Google API |
5 Data We Do Not Intend to Collect
ReadyFlyLog does not provide medical certificate management, medical expiry tracking, diagnosis or health-record functionality, pilot licence document storage, qualification or rating tracking, currency tracking, or a training syllabus and progress module. These retired or excluded functions are not part of the current Service.
The aircraft document feature is for aircraft-related documents. Users must not intentionally use it for medical or health records, pilot licence files, personal pilot documents, or unrelated storage. The Service checks supported file type and size but does not promise semantic inspection of every uploaded file. If prohibited or excessive personal data is submitted, the Customer should remove it promptly and contact us if assistance is needed.
6 How We Use Controller Data
| Purpose | Typical data | Legal basis under the GDPR |
|---|---|---|
| Create and administer accounts; provide the contracted Service; manage trials, subscriptions, and access | Account, Workspace, membership, contract, and service-use data | Article 6(1)(b), performance of a contract or steps requested before a contract |
| Issue and administer manual invoices; keep tax and commercial records; respond to lawful authorities | Billing identity, address, country, tax and VAT details, invoice and payment status | Article 6(1)(c), legal obligation; Article 6(1)(b) where needed to perform the contract |
| Record Terms acceptance and protect legal claims | Identity, version, timestamp, source, IP address, and user agent | Article 6(1)(b), contract administration; Article 6(1)(f), legitimate interests in reliable evidence and claim handling |
| Secure the platform, prevent fraud and misuse, investigate errors, and maintain auditability | Authentication, access, audit, error, device, IP, user-agent, and Master Admin records | Article 6(1)(f), legitimate interests in service security, accountability, and abuse prevention; Article 6(1)(c) where a legal duty applies |
| Provide support and transactional service communications | Contact details, message content, service context, and delivery metadata | Article 6(1)(b), service performance; Article 6(1)(f), legitimate interests in reliable support and operational communications |
| Review and decide commercial and aircraft-capacity requests | Request details, EUR price snapshot, status, and administrator actions | Article 6(1)(b), contract steps and performance; Article 6(1)(f), legitimate interests in consistent commercial administration |
| Establish, exercise, or defend claims and comply with legal process | Relevant account, contract, audit, support, and billing records | Article 6(1)(c), legal obligation; Article 6(1)(f), legitimate interests in claim handling |
Where we rely on legitimate interests, we consider the purpose, necessity, and effect on individuals. You may object as described in section 14. Where we ask for consent for a genuinely optional future purpose, consent will be specific and may be withdrawn. Authorizing a Google connection is a technical permission and does not by itself determine the GDPR legal basis for every related processing activity.
ReadyFlyLog does not use Controller Data for newsletter distribution, behavioral advertising, or cross-site profiling. We do not make decisions that produce legal or similarly significant effects solely by automated means.
7 Processing on Customer Instructions
For Workspace Personal Data, the Customer determines the purpose and legal basis, decides which users may access the Workspace, provides required privacy information, responds to individual requests, and ensures that its instructions and submitted data are lawful. ReadyFlyLog processes that data only on documented Customer instructions, including the instructions in the Terms, the Data Processing Agreement, and ordinary use of the Service.
If an individual contacts us about Workspace Personal Data, we may direct the request to the relevant Customer and assist that Customer under the Data Processing Agreement. We may process a limited copy of the request as Controller Data to authenticate the requester, maintain security, and document our response.
8 Google Drive and Google API Data
A Customer or authorized user may choose to connect a Google account. ReadyFlyLog requests the Google Drive drive.file scope, which limits the application to specific files that the user uses with ReadyFlyLog, including files created by, opened with, or specifically selected for the application. ReadyFlyLog does not request general access to every file in the user's Google Drive.
Aircraft document file bytes remain in the Customer's connected Google Drive. ReadyFlyLog has no internal storage bucket for those document file bytes. We store the metadata, Drive identifiers and folder references needed to display and manage the reference in the Service, together with protected authorization credentials and connection information. Archiving, unlinking, or deleting a ReadyFlyLog reference does not delete the underlying Google Drive file.
The user can remove ReadyFlyLog's access through the Google Account permissions page. Revocation stops future access after the authorization is no longer valid, but it does not delete files in Google Drive or automatically erase ReadyFlyLog account, Workspace, audit, or reference data. A verified deletion request may be submitted to the Customer or to us, depending on the data and role involved.
ReadyFlyLog may also send a user-initiated query to an applicable Google API for supported briefing, weather, airport-related, or translation functionality. The Service uses the query and response only to provide the requested feature and related security or troubleshooting.
ReadyFlyLog's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use it for advertising, or allow human access except where the user has given affirmative permission for support, where access is necessary for security or abuse investigation, where law requires it, or where the data is aggregated and no longer identifies a person.
Google explains the drive.file scope at Google OAuth scopes.
The applicable policy is available at Google API Services User Data Policy.
9 Browser Storage
ReadyFlyLog currently uses only browser storage that is necessary to sign users in, maintain the requested session, remember that the cookie notice was acknowledged, and keep synthetic demo state within a browser session. We do not currently use Google Analytics, Meta Pixel, PostHog, Plausible, marketing pixels, behavioral advertising technology, or similar non-essential analytics.
The ReadyFlyLog Cookie and Browser Storage Notice gives the current inventory, purpose, duration criteria, and user controls. If we introduce non-essential analytics or marketing technology, we will first update that notice and deploy any consent mechanism required by law.
10 Recipients and Service Providers
We disclose personal data only to recipients that need it for the relevant purpose, are authorized by the Customer where required, or receive it under law. Recipient categories include:
- Lovable and its managed cloud and infrastructure provider chain for application hosting, database, authentication, server functions, security, and error reporting;
- Resend for transactional authentication, invitation, and service email;
- Google for an optional, user-authorized Google Drive Connection and supported user-initiated Google API features;
- Számlázz.hu, operated by KBOSS.hu Kft., where used outside the application for ReadyFlyLog's manual invoicing as a controller-side service provider;
- professional advisers, insurers, auditors, and public authorities where reasonably necessary and legally permitted; and
- Customer Administrators and authorized Workspace users according to roles and access settings established by the Customer.
The current direct processor chain, Customer-directed integrations, controller-side providers, transfer information, and change-notice process appear in the ReadyFlyLog Subprocessor and Service Provider Information document.
11 International Data Transfers
The primary application data region reported and verified for the current ReadyFlyLog deployment is Ireland in the European Union. Some providers or their authorized onward providers may process limited personal data in the United States or other countries. Where the GDPR requires a transfer mechanism, we use an adequacy decision, the European Commission's Standard Contractual Clauses, another lawful safeguard, or a permitted derogation, as applicable. We assess provider terms and the nature of the data rather than promising that every processing operation occurs only in the EEA.
12 Retention
We keep personal data only for as long as needed for the purpose stated below, the Customer's documented instructions, and applicable legal requirements. The period may be extended where a legal hold, authority request, fraud or security investigation, or claim requires preservation. We then delete, anonymize, or isolate the data as appropriate.
| Data or context | Retention criteria |
|---|---|
| Account and subscription administration | While the account or commercial relationship remains active, then for the period reasonably needed to close the account, resolve disputes, and meet legal obligations. |
| Terms acceptance and material audit evidence | Ordinarily while the relevant account, Workspace, or commercial relationship is active, and longer where needed for limitation periods, security, fraud prevention, or legal claims. |
| Billing, invoice, and tax records | For the period required by applicable Hungarian tax, accounting, and record-keeping law. |
| Workspace Personal Data | According to Customer instructions and the Data Processing Agreement. An approximately 30-day read-only retrieval period may be provided after termination where technically, legally, and securely appropriate; it does not promise automatic deletion on day 30. |
| Google Drive files | Controlled by the Customer in its Google Drive account. Closing, unlinking, or deleting a ReadyFlyLog reference does not delete the underlying Drive file. |
| Google connection credentials and metadata | While the connection is active and as needed to complete revocation, disconnection, security, or verified deletion steps, subject to limited residual logs and protected provider backups. |
| Support, email delivery, error, and security records | For as long as needed to provide support, maintain reliable delivery, investigate the issue, protect the Service, and handle related claims or legal obligations. |
| Browser storage | Until sign-out, session expiry, browser-session end, acknowledgement reset, or user clearing, depending on the item described in the Cookie and Browser Storage Notice. |
ReadyFlyLog does not currently offer self-service account deletion. A user may request account closure or deletion by emailing us. Membership removal, Workspace cancellation, account closure, Workspace data deletion, and deletion of Google Drive files are separate actions and may require authorization from different persons.
13 Security
We use technical and organizational measures appropriate to the risks of the current Service. These include HTTPS and TLS in transit, provider-level encrypted storage, workspace-level access controls and row-level security, role checks, protected server and database functions, server-side secrets, restricted financial writes, file type and size validation, the limited Google Drive scope, and audit records for sensitive commercial, role, Master Admin, capacity, and impersonation actions. Master Admin access uses the ordinary authenticated account system, requires a reason for impersonation, and records the action in an append-only audit trail.
No service can guarantee absolute security or uninterrupted availability. We do not publish unsupported promises about backup frequency, retention, recovery objectives, point-in-time recovery, selective restoration, or certifications. Customers remain responsible for their own Google Drive controls, exports, access administration, and business-continuity needs.
14 Individual Rights
Subject to the conditions and exceptions in applicable law, an individual may request access, rectification, erasure, restriction, or portability of personal data; object to processing based on legitimate interests; withdraw consent where consent is the basis; and complain to a supervisory authority. Withdrawing consent does not affect earlier lawful processing.
Send a request to readyflylog@gmail.com and describe the relevant account or Workspace. We may request information reasonably needed to verify identity, authority, and scope. For Workspace Personal Data, the Customer is normally responsible for deciding the request, and we will assist the Customer as required by the Data Processing Agreement.
15 Supervisory Authority
You may complain to the Hungarian National Authority for Data Protection and Freedom of Information or to another competent supervisory authority, particularly in the EEA country of your habitual residence, place of work, or the alleged infringement.
| Item | Authority details |
|---|---|
| Name | Hungarian National Authority for Data Protection and Freedom of Information (NAIH) |
| Address | 1055 Budapest, Falk Miksa utca 9-11., Hungary |
| Postal address | 1363 Budapest, Pf. 9., Hungary |
| ugyfelszolgalat@naih.hu | |
| Telephone | +36 (1) 391 1400 |
| Website | https://naih.hu/ |
16 Required and Optional Data
Account, authentication, contract, and minimum Workspace administration data are required to create and operate the Service. If these data are not provided, we may be unable to create the account, provide access, enter or perform the contract, issue a required invoice, or protect the platform. A Google Drive Connection, optional phone number, and supported user-initiated Google API features are voluntary; declining them may make the related feature unavailable without preventing use of unrelated features.
17 Service Communications
ReadyFlyLog sends transactional communications needed for authentication, invitations, account security, support, and service administration. ReadyFlyLog does not currently operate a newsletter, marketing broadcast, or advertising preference center. If that changes, we will provide the notices and choices required by law before using personal data for the new purpose.
18 Changes to This Policy
We may update this Policy when the Service, law, or provider chain changes. We will publish the new version and effective date. Where a change materially affects individuals or Customer instructions, we will provide additional notice through the Service or by email where reasonably appropriate. Earlier versions may be retained for accountability.
19 Contact
For privacy questions, rights requests, account closure, or concerns about prohibited data, contact Sándor Levente Szabó e.v. at readyflylog@gmail.com or by post at 9400 Sopron, Semmelweis utca 10., Hungary.
ReadyFlyLog Privacy Policy | Version 1.0 | Effective date: 11 September 2026