Back to homepage

Privacy Policy

Version 1.0 · Effective date: 11 September 2026

ReadyFlyLog Privacy Policy

ItemDetails
Version1.0
StatusFinal publication ready English
Effective date11 September 2026
Last reviewed11 September 2026

This Privacy Policy explains how ReadyFlyLog processes personal data when it provides the ReadyFlyLog web service, administers accounts and subscriptions, supports Customers, and processes Workspace data on a Customer's instructions. It also explains the separate responsibilities of ReadyFlyLog and each Customer, the use of Google Drive and Google APIs, retention, international transfers, and individual rights.

The central distinction is that ReadyFlyLog is a controller for its own account, commercial, security, support, and legal-compliance activities, while each Customer is the controller of personal data processed inside its organizational Workspace. ReadyFlyLog processes that Workspace Personal Data for the Customer under the ReadyFlyLog Data Processing Agreement.

1 Who We Are

ReadyFlyLog is operated by Sándor Levente Szabó e.v., a Hungarian individual entrepreneur. When this Policy says ReadyFlyLog, we, us, or our, it refers to this operator.

ItemDetails
Registered address9400 Sopron, Semmelweis utca 10., Hungary
Individual entrepreneur registration number61070435
Registry and authorityNAV, Individual Entrepreneurs Register (Egyéni Vállalkozók Nyilvántartása)
Hungarian tax number91404451-1-28
EU VAT numberHU91404451
Privacy contactreadyflylog@gmail.com

2 Scope and Key Terms

This Policy applies to visitors to the ReadyFlyLog website, account holders, invited users, Customer Administrators, persons identified in records submitted to a Workspace, and people who contact us. The Terms and Conditions govern use of the Service. The Data Processing Agreement governs ReadyFlyLog's processing of Workspace Personal Data for a Customer.

  • Customer means the person or organization that creates, subscribes to, or controls a ReadyFlyLog Workspace.
  • Workspace means the Customer-controlled environment in which authorized users manage operational records.
  • Workspace Personal Data means personal data entered, generated, or otherwise processed in a Workspace for the Customer's purposes.
  • Controller Data means personal data ReadyFlyLog processes for its own account, contractual, commercial, security, support, and legal purposes.
  • Google Drive Connection means the optional connection that allows ReadyFlyLog to work with specific files in a user's Google Drive account through the permissions the user grants.

3 Our Data Protection Roles

Processing contextReadyFlyLog roleWho decides the purpose and meansMain governing document
Accounts, contracts, subscriptions, billing, Terms acceptance, platform security, support, commercial and capacity administrationControllerReadyFlyLogThis Policy and the Terms and Conditions
Flight, aircraft, maintenance, membership, Pilot Balance, and related organizational records inside a WorkspaceProcessorThe CustomerThe Data Processing Agreement and Customer instructions
Customer-owned files accessed through an optional Google Drive ConnectionProcessor for the Customer's purpose; user-authorized access to GoogleThe Customer, with the user choosing the Google account and files made availableThe Data Processing Agreement, Google authorization, and applicable Google terms

The same item can involve both roles. For example, an email address may be Controller Data when used to administer an account and Workspace Personal Data when it identifies a pilot in a Customer's operational record. We apply the rules relevant to each processing purpose.

4 Personal Data We Process

The Service processes the categories below according to the features a Customer and its users use. A field or category listed here may not be present in every account or Workspace.

CategoryTypical dataMain source
Account and profileName, email address, phone number if provided, account and authentication identifiers, account status, and current or last WorkspaceThe user and authentication service
Customer and WorkspaceWorkspace name, base airport, Customer and billing identity, address, country, tax or VAT details, subscription, trial, and lifecycle statusCustomer Administrators and commercial administration
Membership and accessWorkspace membership, role, invitation, acceptance, and access statusCustomer Administrators, invited users, and the Service
Flight recordsDates, times, landings, route, remarks, PIC, instructor or student designation, user identifiers, cost, discount, and correction historyAuthorized Workspace users
Pilot Balance recordsInternal top-ups, debits, discounts, and related entries used for Customer accounting inside the WorkspaceAuthorized Workspace users; these records are not a bank account, wallet, or payment service
Maintenance and expense recordsMaintenance actions, counters, expenses, actor identifiers, timestamps, and audit historyAuthorized Workspace users
Aircraft recordsAircraft identification, operational details, status, and capacity-related informationAuthorized Workspace users and the Service
Aircraft document referencesDocument metadata, file name, MIME type, size, Google Drive file identifier, folder reference, aircraft association, uploader, and timestampsAuthorized users and Google Drive
Google connectionConnected Google email address and account identifier, root folder reference, authorization scope, encrypted or otherwise protected access credentials and tokens, and connection actionsThe user, Google, and the Service
Terms and legal evidenceIdentity, Terms version, UTC timestamp, acceptance source, IP address, and user agentThe user and the Service
Commercial and capacity requestsRequester, aircraft block count, monthly or annual selection, currency, immutable EUR price snapshot, request status, administrator, and resolverCustomer Administrators, ReadyFlyLog, and the Service
Security and auditAuthentication events, role changes, commercial actions, Master Admin actions, impersonation reason, access context, timestamps, IP address, user agent, and error or security tracesThe Service, ReadyFlyLog, and infrastructure providers
Support and communicationsMessage content, attachments voluntarily supplied, contact details, delivery metadata, and support historyThe sender, ReadyFlyLog, and transactional email provider
Browser storageSession and authentication state, the readyflylog-cookie-consent acknowledgement value, and session-limited synthetic demo stateThe Service and the user's browser
User initiated external queriesBriefing, weather, airport-related, or translation input and returned results where a supported Google API feature is usedThe user, the Service, and the relevant Google API

5 Data We Do Not Intend to Collect

ReadyFlyLog does not provide medical certificate management, medical expiry tracking, diagnosis or health-record functionality, pilot licence document storage, qualification or rating tracking, currency tracking, or a training syllabus and progress module. These retired or excluded functions are not part of the current Service.

The aircraft document feature is for aircraft-related documents. Users must not intentionally use it for medical or health records, pilot licence files, personal pilot documents, or unrelated storage. The Service checks supported file type and size but does not promise semantic inspection of every uploaded file. If prohibited or excessive personal data is submitted, the Customer should remove it promptly and contact us if assistance is needed.

6 How We Use Controller Data

PurposeTypical dataLegal basis under the GDPR
Create and administer accounts; provide the contracted Service; manage trials, subscriptions, and accessAccount, Workspace, membership, contract, and service-use dataArticle 6(1)(b), performance of a contract or steps requested before a contract
Issue and administer manual invoices; keep tax and commercial records; respond to lawful authoritiesBilling identity, address, country, tax and VAT details, invoice and payment statusArticle 6(1)(c), legal obligation; Article 6(1)(b) where needed to perform the contract
Record Terms acceptance and protect legal claimsIdentity, version, timestamp, source, IP address, and user agentArticle 6(1)(b), contract administration; Article 6(1)(f), legitimate interests in reliable evidence and claim handling
Secure the platform, prevent fraud and misuse, investigate errors, and maintain auditabilityAuthentication, access, audit, error, device, IP, user-agent, and Master Admin recordsArticle 6(1)(f), legitimate interests in service security, accountability, and abuse prevention; Article 6(1)(c) where a legal duty applies
Provide support and transactional service communicationsContact details, message content, service context, and delivery metadataArticle 6(1)(b), service performance; Article 6(1)(f), legitimate interests in reliable support and operational communications
Review and decide commercial and aircraft-capacity requestsRequest details, EUR price snapshot, status, and administrator actionsArticle 6(1)(b), contract steps and performance; Article 6(1)(f), legitimate interests in consistent commercial administration
Establish, exercise, or defend claims and comply with legal processRelevant account, contract, audit, support, and billing recordsArticle 6(1)(c), legal obligation; Article 6(1)(f), legitimate interests in claim handling

Where we rely on legitimate interests, we consider the purpose, necessity, and effect on individuals. You may object as described in section 14. Where we ask for consent for a genuinely optional future purpose, consent will be specific and may be withdrawn. Authorizing a Google connection is a technical permission and does not by itself determine the GDPR legal basis for every related processing activity.

ReadyFlyLog does not use Controller Data for newsletter distribution, behavioral advertising, or cross-site profiling. We do not make decisions that produce legal or similarly significant effects solely by automated means.

7 Processing on Customer Instructions

For Workspace Personal Data, the Customer determines the purpose and legal basis, decides which users may access the Workspace, provides required privacy information, responds to individual requests, and ensures that its instructions and submitted data are lawful. ReadyFlyLog processes that data only on documented Customer instructions, including the instructions in the Terms, the Data Processing Agreement, and ordinary use of the Service.

If an individual contacts us about Workspace Personal Data, we may direct the request to the relevant Customer and assist that Customer under the Data Processing Agreement. We may process a limited copy of the request as Controller Data to authenticate the requester, maintain security, and document our response.

8 Google Drive and Google API Data

A Customer or authorized user may choose to connect a Google account. ReadyFlyLog requests the Google Drive drive.file scope, which limits the application to specific files that the user uses with ReadyFlyLog, including files created by, opened with, or specifically selected for the application. ReadyFlyLog does not request general access to every file in the user's Google Drive.

Aircraft document file bytes remain in the Customer's connected Google Drive. ReadyFlyLog has no internal storage bucket for those document file bytes. We store the metadata, Drive identifiers and folder references needed to display and manage the reference in the Service, together with protected authorization credentials and connection information. Archiving, unlinking, or deleting a ReadyFlyLog reference does not delete the underlying Google Drive file.

The user can remove ReadyFlyLog's access through the Google Account permissions page. Revocation stops future access after the authorization is no longer valid, but it does not delete files in Google Drive or automatically erase ReadyFlyLog account, Workspace, audit, or reference data. A verified deletion request may be submitted to the Customer or to us, depending on the data and role involved.

ReadyFlyLog may also send a user-initiated query to an applicable Google API for supported briefing, weather, airport-related, or translation functionality. The Service uses the query and response only to provide the requested feature and related security or troubleshooting.

ReadyFlyLog's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use it for advertising, or allow human access except where the user has given affirmative permission for support, where access is necessary for security or abuse investigation, where law requires it, or where the data is aggregated and no longer identifies a person.

Google explains the drive.file scope at Google OAuth scopes.

The applicable policy is available at Google API Services User Data Policy.

9 Browser Storage

ReadyFlyLog currently uses only browser storage that is necessary to sign users in, maintain the requested session, remember that the cookie notice was acknowledged, and keep synthetic demo state within a browser session. We do not currently use Google Analytics, Meta Pixel, PostHog, Plausible, marketing pixels, behavioral advertising technology, or similar non-essential analytics.

The ReadyFlyLog Cookie and Browser Storage Notice gives the current inventory, purpose, duration criteria, and user controls. If we introduce non-essential analytics or marketing technology, we will first update that notice and deploy any consent mechanism required by law.

10 Recipients and Service Providers

We disclose personal data only to recipients that need it for the relevant purpose, are authorized by the Customer where required, or receive it under law. Recipient categories include:

  • Lovable and its managed cloud and infrastructure provider chain for application hosting, database, authentication, server functions, security, and error reporting;
  • Resend for transactional authentication, invitation, and service email;
  • Google for an optional, user-authorized Google Drive Connection and supported user-initiated Google API features;
  • Számlázz.hu, operated by KBOSS.hu Kft., where used outside the application for ReadyFlyLog's manual invoicing as a controller-side service provider;
  • professional advisers, insurers, auditors, and public authorities where reasonably necessary and legally permitted; and
  • Customer Administrators and authorized Workspace users according to roles and access settings established by the Customer.

The current direct processor chain, Customer-directed integrations, controller-side providers, transfer information, and change-notice process appear in the ReadyFlyLog Subprocessor and Service Provider Information document.

11 International Data Transfers

The primary application data region reported and verified for the current ReadyFlyLog deployment is Ireland in the European Union. Some providers or their authorized onward providers may process limited personal data in the United States or other countries. Where the GDPR requires a transfer mechanism, we use an adequacy decision, the European Commission's Standard Contractual Clauses, another lawful safeguard, or a permitted derogation, as applicable. We assess provider terms and the nature of the data rather than promising that every processing operation occurs only in the EEA.

12 Retention

We keep personal data only for as long as needed for the purpose stated below, the Customer's documented instructions, and applicable legal requirements. The period may be extended where a legal hold, authority request, fraud or security investigation, or claim requires preservation. We then delete, anonymize, or isolate the data as appropriate.

Data or contextRetention criteria
Account and subscription administrationWhile the account or commercial relationship remains active, then for the period reasonably needed to close the account, resolve disputes, and meet legal obligations.
Terms acceptance and material audit evidenceOrdinarily while the relevant account, Workspace, or commercial relationship is active, and longer where needed for limitation periods, security, fraud prevention, or legal claims.
Billing, invoice, and tax recordsFor the period required by applicable Hungarian tax, accounting, and record-keeping law.
Workspace Personal DataAccording to Customer instructions and the Data Processing Agreement. An approximately 30-day read-only retrieval period may be provided after termination where technically, legally, and securely appropriate; it does not promise automatic deletion on day 30.
Google Drive filesControlled by the Customer in its Google Drive account. Closing, unlinking, or deleting a ReadyFlyLog reference does not delete the underlying Drive file.
Google connection credentials and metadataWhile the connection is active and as needed to complete revocation, disconnection, security, or verified deletion steps, subject to limited residual logs and protected provider backups.
Support, email delivery, error, and security recordsFor as long as needed to provide support, maintain reliable delivery, investigate the issue, protect the Service, and handle related claims or legal obligations.
Browser storageUntil sign-out, session expiry, browser-session end, acknowledgement reset, or user clearing, depending on the item described in the Cookie and Browser Storage Notice.

ReadyFlyLog does not currently offer self-service account deletion. A user may request account closure or deletion by emailing us. Membership removal, Workspace cancellation, account closure, Workspace data deletion, and deletion of Google Drive files are separate actions and may require authorization from different persons.

13 Security

We use technical and organizational measures appropriate to the risks of the current Service. These include HTTPS and TLS in transit, provider-level encrypted storage, workspace-level access controls and row-level security, role checks, protected server and database functions, server-side secrets, restricted financial writes, file type and size validation, the limited Google Drive scope, and audit records for sensitive commercial, role, Master Admin, capacity, and impersonation actions. Master Admin access uses the ordinary authenticated account system, requires a reason for impersonation, and records the action in an append-only audit trail.

No service can guarantee absolute security or uninterrupted availability. We do not publish unsupported promises about backup frequency, retention, recovery objectives, point-in-time recovery, selective restoration, or certifications. Customers remain responsible for their own Google Drive controls, exports, access administration, and business-continuity needs.

14 Individual Rights

Subject to the conditions and exceptions in applicable law, an individual may request access, rectification, erasure, restriction, or portability of personal data; object to processing based on legitimate interests; withdraw consent where consent is the basis; and complain to a supervisory authority. Withdrawing consent does not affect earlier lawful processing.

Send a request to readyflylog@gmail.com and describe the relevant account or Workspace. We may request information reasonably needed to verify identity, authority, and scope. For Workspace Personal Data, the Customer is normally responsible for deciding the request, and we will assist the Customer as required by the Data Processing Agreement.

15 Supervisory Authority

You may complain to the Hungarian National Authority for Data Protection and Freedom of Information or to another competent supervisory authority, particularly in the EEA country of your habitual residence, place of work, or the alleged infringement.

ItemAuthority details
NameHungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address1055 Budapest, Falk Miksa utca 9-11., Hungary
Postal address1363 Budapest, Pf. 9., Hungary
Emailugyfelszolgalat@naih.hu
Telephone+36 (1) 391 1400
Websitehttps://naih.hu/

16 Required and Optional Data

Account, authentication, contract, and minimum Workspace administration data are required to create and operate the Service. If these data are not provided, we may be unable to create the account, provide access, enter or perform the contract, issue a required invoice, or protect the platform. A Google Drive Connection, optional phone number, and supported user-initiated Google API features are voluntary; declining them may make the related feature unavailable without preventing use of unrelated features.

17 Service Communications

ReadyFlyLog sends transactional communications needed for authentication, invitations, account security, support, and service administration. ReadyFlyLog does not currently operate a newsletter, marketing broadcast, or advertising preference center. If that changes, we will provide the notices and choices required by law before using personal data for the new purpose.

18 Changes to This Policy

We may update this Policy when the Service, law, or provider chain changes. We will publish the new version and effective date. Where a change materially affects individuals or Customer instructions, we will provide additional notice through the Service or by email where reasonably appropriate. Earlier versions may be retained for accountability.

19 Contact

For privacy questions, rights requests, account closure, or concerns about prohibited data, contact Sándor Levente Szabó e.v. at readyflylog@gmail.com or by post at 9400 Sopron, Semmelweis utca 10., Hungary.

ReadyFlyLog Privacy Policy | Version 1.0 | Effective date: 11 September 2026