The Club ("Controller") uses the WingVu SaaS platform to manage trial flights, scenic flight events and volunteer scheduling. WingVu ("Processor") processes personal data of the Club's members, guests, pilots and volunteers on behalf of the Controller. This Data Processing Agreement is concluded between the parties pursuant to Art. 28 GDPR and becomes effective with the Customer's acceptance of the Terms of Service.
(1) Subject of the processing is the provision of WingVu platform services to the Club.
(2) Duration of processing corresponds to the term of the main agreement. After termination § 8 applies.
(1) Nature: storing, structuring, displaying, transmitting to authorised recipients (club admins, pilots, flight directors, volunteers), backup, pseudonymisation.
(2) Purpose:
| Category | Example fields | Source |
|---|---|---|
| Master data | Name, e-mail, phone, address | Entered by user |
| Booking data | Event date, slot, aircraft, price, cancellation info | Club / end customer |
| Passenger details | First and last name, body weight (mandatory under German Aviation Act § 27c for MTOW calculation), child status | End customer in booking form |
| Volunteer and pilot data | Pilot licence number, availability, shift assignments | Club |
| Payment metadata | Provider reference (e.g. PayPal subscription ID), status, amounts | External payment provider |
| Technical data | Login timestamps, IP address, session ID | System |
Note: Bank account or full credit-card numbers are never processed by WingVu — these reside exclusively at the external payment provider (PayPal/Stripe).
(1) WingVu processes personal data only on documented instructions of the Controller. Documented instructions are, as a rule, the actions performed by the Controller within the platform functionality; additional individual instructions must be sent by e-mail to support@wingvu.com.
(2) WingVu ensures that all persons authorised to process personal data are bound by confidentiality or appropriate statutory obligations of secrecy.
(3) WingVu implements appropriate technical and organisational measures pursuant to Art. 32 GDPR; these are described in Annex 1 (TOMs).
(4) WingVu supports the Controller in fulfilling the rights of data subjects under Arts. 12–22 GDPR (access, rectification, erasure, restriction, portability, objection) and the obligations under Arts. 32–36 GDPR. Reasonable cost compensation may be charged unless the request is caused by WingVu's fault.
(5) WingVu shall notify the Controller without undue delay, at the latest within 24 hours of becoming aware, of any breach of personal data (Art. 33 GDPR). Notification is sent to the contact e-mail on file.
(6) WingVu supports the Controller on request in performing a data protection impact assessment (Art. 35 GDPR).
(7) After the end of the processing, WingVu deletes or returns the personal data (cf. § 8).
(1) The Controller agrees to the engagement of the following sub-processors:
| Sub-processor | Location | Purpose |
|---|---|---|
| Hetzner Online GmbH | Gunzenhausen, Germany | Hosting of platform servers (Falkenstein) |
| Hostinger International Ltd. | Kaunas, Lithuania | Delivery of transactional e-mails (SMTP) |
| Mistral AI | Paris, France | LLM for the optional help chatbot |
| Twilio Ireland Ltd. | Dublin, Ireland | SMS verification at tenant registration |
(2) The external payment providers PayPal Europe S.à r.l. (Luxembourg) and where applicable Stripe Payments Europe Ltd. (Ireland) are not sub-processors of WingVu but independent controllers for the payment processing. The Club concludes its own contract with the respective payment provider.
(3) WingVu informs the Controller at least 30 days before engaging additional sub-processors or replacing existing ones. The Controller may object within 30 days; in case of objection, WingVu may extraordinarily terminate the main agreement.
(4) WingVu concludes a GDPR-compliant agreement with each sub-processor.
(1) The Controller is solely responsible for the lawfulness of the data processing pursuant to Art. 5 et seq. GDPR. The Controller ensures that personal data of third parties entered into the platform has a valid legal basis (Art. 6 GDPR).
(2) The Controller fulfills its information obligations towards data subjects under Arts. 13/14 GDPR on its own responsibility (members, guests, pilots, volunteers). The Controller indicates in its privacy notice that WingVu is used as a processor for the booking and helper management.
(3) The Controller includes WingVu as a processor in its register of processing activities (Art. 30 GDPR).
(4) The Controller takes appropriate TOMs on its own side (in particular strong admin passwords, careful assignment of admin roles, regular account reviews, secure end devices).
(1) After termination of the main agreement, WingVu deletes all personal data of the Controller from live systems within 30 days.
(2) Backups in which the data is stored redundantly are overwritten as part of their regular rotation (max. 90 days after termination).
(3) Within the 30-day window, the Controller may request a data export. Format: JSON or CSV, free of charge, once.
(1) The Controller has the right to verify WingVu's compliance with this DPA. Upon request, WingVu provides suitable evidence (e.g. current TOM documentation, ISO certificates where available).
(2) On-site audits are possible with reasonable advance notice (at least 4 weeks) and no more than once per year. Costs are borne by the Controller unless the audit reveals material violations.
See the German master version for the full TOM list (covers access control, transmission control, input control, order control, availability and separation control).