1. Who we are and how to contact us
ATC24Academy is a volunteer virtual aviation training community operating in connection with the 24 flight‑simulation environment on the Roblox platform. For the purposes of the European Union General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the United Kingdom General Data Protection Regulation ("UK GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the Brazilian General Data Protection Law ("LGPD"), the Canadian Personal Information Protection and Electronic Documents Act ("PIPEDA"), the Australian Privacy Act 1988, and other applicable data‑protection laws (collectively, "Data Protection Laws"), ATC24Academy is the controller of personal information collected through the Services.
You can reach us, including our data protection point of contact, through the official Discord community linked on the ATC24Academy website. Where a written communication is required, you may request a mailing address through that channel.
2. Scope
This document applies to personal information we collect from and about you through the Services, including the website atc24academy.com, the associated Discord community, our Discord bot, our Supabase‑backed application, our edge functions, our storage buckets, our email or webhook communications, and any related tools we operate.
It does not apply to third‑party services or platforms with which we integrate, such as Discord Inc., Supabase Inc., Cloudflare Inc., Lovable, or Roblox Corporation, when you use those services outside our Services. Their processing is governed by their own privacy notices.
3. Personal information we collect
3.1 Information you provide to us
- Account information from Discord sign‑in: your Discord user ID, username, global name, avatar, email address, and, where you grant it, Discord server membership information.
- Profile information stored in the profiles table, including display name, contact fields, and preferences you configure.
- Application information, including your username, Discord ID, age, reason for applying, role applied for, and free‑text answers to configured questions.
- Interview information, including scheduling, notes, outcomes, and any answers or transcripts recorded by staff.
- Exam information, including exam assignments, responses, scores, results, reviewer notes, and status.
- Training information, including training requests, session participation, checklist progress, endorsements, supervision assessments, and stage logs.
- Event and coordination information, including event applications, positions, invites, coordination room messages, and closed tickets.
- Leave‑of‑absence requests, including reasons and dates.
- Communications you send to us through Discord, forms, or webhooks, including any attachments.
3.2 Information collected automatically
- Log and device information such as IP address, user agent, referrer, timestamps, and pages viewed, collected by our hosting and edge providers for security, abuse prevention, and diagnostics.
- Session information from your Discord authentication session and from cookies described in Section 8.
- Application and exam activity signals: while you complete an application form or attempt an exam, we log paste events, tab‑visibility changes (that is, when you switch away from the tab and return, including the page title of the tab you are viewing when the change occurs), and window focus changes. These signals are attached to the submission and are visible only to authorised reviewers. See Section 12 for the Anti‑Cheating & Monitoring Policy.
- Dashboard logs for administrative actions performed within the Services.
3.3 Information from third parties
- Discord Inc.: identity, role membership, and, where authorised, guild membership.
- Content you post on our Discord server, including messages, reactions, and voice channel presence, which is subject to Discord's own terms and to our Community Guidelines in Section 11.
3.4 Sensitive personal information
We do not intentionally collect sensitive categories of personal information such as government‑issued identifiers, health data, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade‑union membership, genetic or biometric data, sex life, sexual orientation, or precise geolocation. Do not submit such information through the Services.
4. How we use your personal information (purposes and legal bases)
Where required by GDPR, UK GDPR, or similar laws, we rely on the following legal bases:
- Performance of a contract or steps taken at your request before entering into a contract, to create and administer your account, process applications and exams, run training sessions, and provide the Services.
- Legitimate interests, to operate, secure, improve, and moderate the Services; to detect and prevent fraud, cheating, abuse, and misuse; to keep audit logs; to enforce our Terms of Service and Policies; to communicate with members of the community; and to promote the Academy and its partners. Where we rely on legitimate interests, we balance those interests against your rights and freedoms, and you may object as described in Section 15.
- Consent, for optional communications, for cookies that are not strictly necessary, for participation in publicly displayed team or partners listings, and where otherwise required by law. You can withdraw consent at any time.
- Legal obligation, to comply with applicable laws, court orders, or lawful requests by public authorities.
- Vital interests, where processing is necessary to protect someone's life or safety.
Specific purposes include, without limitation:
- Creating, authenticating, and securing your account.
- Enabling applications, interviews, exams, training, events, coordination, endorsements, LOA management, and role assignments.
- Sending transactional and community messages, including announcements, DMs from our Discord bot, and webhook notifications.
- Detecting and investigating suspected cheating, plagiarism, harassment, spam, fraud, or other violations of the Terms of Service and community rules.
- Maintaining logs, backups, and audit trails.
- Complying with legal obligations and enforcing our rights.
- Improving the Services, understanding usage patterns, and developing new features.
5. How we share personal information
We share personal information only as described below and never sell personal information within the meaning of any Data Protection Law.
- Within the community: your Discord username, roles, participation in events and sessions, and public profile information may be visible to other members through the website (for example on team or event pages) and through the Discord server.
- Staff, reviewers, and instructors access application, interview, exam, training, session, and moderation information as necessary for their role, subject to the confidentiality expectations of the Academy.
- Service providers ("processors") that operate the Services on our behalf under contractual obligations, including:
- Discord Inc., for authentication, community hosting, DMs, role management, and interactions.
- Supabase Inc., for database, storage, edge functions, and auth infrastructure.
- Cloudflare Inc., for hosting, DNS, CDN, and edge computing.
- Lovable, for platform operation and dev/preview environments.
- Email delivery, analytics, and error‑monitoring providers we may engage from time to time.
- Successors: in the event of a change of control, merger, acquisition, or reorganisation of the Academy or of any successor operating entity.
- Legal and safety: where required or permitted by law, or where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of the Academy, its members, or the public, or to comply with legal process.
- With your consent: for any other disclosure we specifically ask you to authorise.
6. International transfers
The Services rely on providers that operate globally. Your personal information may be processed in countries other than your own, including the United States. Where required by Data Protection Laws, we rely on lawful transfer mechanisms, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions, or applicable derogations. You may request further information about the safeguards used by contacting us as described in Section 1.
7. Data retention
We retain personal information only for as long as is necessary for the purposes described in this document and to comply with our legal obligations. Indicative retention periods are:
- Account and profile data: for as long as your account is active, and up to twenty‑four (24) months after account closure for security and audit purposes, unless a longer period is required by law.
- Applications and interviews: for up to thirty‑six (36) months from submission, or longer if required to defend legal claims.
- Exams, responses, and activity logs: for up to thirty‑six (36) months from completion, so that we can investigate integrity issues and support appeals.
- Training, endorsements, and supervision records: for as long as your Academy membership continues, plus a reasonable historical archive period.
- Coordination messages, closed tickets, and moderation logs: for up to twenty‑four (24) months.
- Server and edge logs: as retained by our providers under their default policies, typically thirty (30) to ninety (90) days.
When personal information is no longer needed, we will delete or anonymise it, or, where deletion is not immediately possible (for example because of backups), we will securely store it and isolate it from any further processing until deletion is possible.
8. Cookies and similar technologies
The Services use cookies, local storage, and similar technologies. We categorise them as follows:
- Strictly necessary: required to authenticate you, keep you signed in, maintain your session, and secure the Services. These cannot be disabled without breaking core functionality.
- Functional: remember preferences such as your selected role or filter and improve the user experience.
- Analytics and performance: help us understand usage and diagnose issues. These are only used where permitted by law and, where consent is required, where you have provided it.
You can control cookies through your browser settings. Blocking strictly necessary cookies will prevent you from signing in and using the Services. Third parties, including Discord, may set their own cookies when you interact with their content or authentication flow; those cookies are governed by their own policies.
9. Security
We take reasonable and appropriate technical and organisational measures to protect personal information against unauthorised access, alteration, disclosure, or destruction. These measures include, without limitation: encryption in transit using TLS; use of managed database services with row‑level security; principle‑of‑least‑privilege access controls for staff; separation of the public anon key from the service‑role key; storage of secrets in server‑only environments; verified webhook signatures for external callers; audit logging of administrative actions; and periodic review of access.
No system is perfectly secure. You are responsible for keeping your Discord account credentials safe, enabling two‑factor authentication where available, and reporting any suspected compromise to us immediately.
If we become aware of a personal‑data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, affected users, in accordance with applicable law.
10. Acceptable Use Policy
You must use the Services lawfully and respectfully. Without limiting the Terms of Service, you must not:
- Attempt to bypass authentication, row‑level security, rate limiting, or any other security control.
- Probe, scan, or test the vulnerability of the Services except under a coordinated disclosure programme agreed with us in writing.
- Use another user's account or share your account.
- Send unsolicited commercial messages, spam, chain messages, phishing content, or malware.
- Impersonate a staff member, instructor, controller, pilot, partner, or third party.
- Interfere with the availability or integrity of the Services, including through denial‑of‑service techniques.
- Use the Services to distribute content that violates any law or the rights of any person.
- Engage in cheating, ghosting, exam collusion, or fraudulent training progression.
11. Community Guidelines
Our Discord community and any coordination tools operate under the following expectations, in addition to Discord's own guidelines: be respectful; keep aviation and simulation discussions constructive; assume good faith; do not doxx; do not harass; use appropriate channels; follow instructions from moderators, event coordinators, and instructors; and report violations through the designated channels rather than confronting other members publicly. Repeated or severe violations may lead to warnings, mutes, kicks, or bans, in addition to any account restrictions on the website.
12. Anti‑Cheating & Monitoring Policy
To maintain the integrity of our applications and exams, we log the following client‑side signals while you are completing an application or attempting an exam through the Services:
- The fact that a paste occurred, the length of the pasted text, a short preview of the pasted text (up to the first two hundred characters), and, where available, an identifier for the field into which the content was pasted.
- The fact that the browser tab lost or regained visibility, together with the current page title at the moment of the change.
- The fact that the browser window lost or regained focus, together with the elapsed time.
These signals are stored with the corresponding application or exam assignment, are visible only to authorised reviewers, and are used solely to detect and investigate academic dishonesty, plagiarism, unauthorised assistance, and other integrity issues. They are retained for the same period as the parent submission, as described in Section 7. We do not use these signals for advertising, for behavioural profiling outside integrity review, or for any other purpose. You may object to this processing at any time by choosing not to complete an application or exam through the Services.
13. Children's privacy
The Services are not directed at children under the age of thirteen (13). We do not knowingly collect personal information from children under 13. If you are a parent or legal guardian and believe that a child under 13 has provided personal information to us, please contact us so that we can delete the account and associated data. Where local law sets a higher digital‑consent age (for example, sixteen (16) in some European Union member states), we rely on the consent of a parent or guardian for users below that age.
14. Automated decision‑making and profiling
We do not use automated decision‑making, including profiling, that produces legal or similarly significant effects on you. Human staff review applications, interviews, exams, and role decisions. Anti‑cheating signals inform, but do not automatically determine, review outcomes.
15. Your rights
Subject to local law, you may have the following rights in relation to your personal information:
- Access: request confirmation whether we process your personal information and obtain a copy.
- Rectification: request correction of inaccurate or incomplete information.
- Erasure ("right to be forgotten"): request deletion where the legal grounds apply.
- Restriction: request that we limit our processing in certain circumstances.
- Objection: object to processing based on our legitimate interests, including for direct communication.
- Portability: receive certain data in a structured, commonly used, and machine‑readable format.
- Withdraw consent: where we rely on consent, withdraw it at any time without affecting the lawfulness of processing before withdrawal.
- Not to be subject to automated decisions with legal or similarly significant effects (see Section 14).
- Lodge a complaint with a supervisory authority, including your local data‑protection authority.
California residents have additional rights under the CCPA/CPRA, including the right to know the categories and specific pieces of personal information collected, the sources of that information, the business or commercial purposes for collecting it, and the categories of third parties with whom it is shared; the right to delete personal information; the right to correct inaccurate personal information; the right to opt out of the sale or sharing of personal information (we do not sell or share personal information as defined by the CCPA/CPRA); the right to limit the use of sensitive personal information (we do not intentionally collect such information for purposes that require this right); and the right not to be discriminated against for exercising these rights. Authorised agents may submit requests on your behalf with valid proof of authorisation.
Residents of the European Economic Area, the United Kingdom, Switzerland, Brazil, Canada, Australia, and other jurisdictions with similar laws may exercise the analogous rights available to them. To exercise any right, contact us through the channels in Section 1. We may need to verify your identity, typically by matching your Discord account.
16. DMCA / Copyright Policy
We respect the intellectual property rights of others and expect our users to do the same. If you believe that content on the Services infringes your copyright, please send a notice of infringement to us through the contact channel in Section 1. The notice should include: (a) a physical or electronic signature of the person authorised to act on behalf of the owner of the exclusive right; (b) identification of the copyrighted work claimed to have been infringed; (c) identification of the material claimed to be infringing and information reasonably sufficient to permit us to locate it; (d) your contact information; (e) a statement that you have a good‑faith belief that use of the material is not authorised by the copyright owner, its agent, or the law; and (f) a statement that the information in the notice is accurate and, under penalty of perjury, that you are the owner or authorised to act on behalf of the owner. We may remove or disable access to the material, notify the user who posted it, and terminate repeat infringers.
17. Accessibility
We aim to make the Services accessible to as many users as possible and to align our website with the Web Content Accessibility Guidelines (WCAG) 2.1 Level AA where reasonably practicable. If you encounter an accessibility barrier, please contact us so that we can address it.
18. Do Not Track and Global Privacy Control
Because there is no industry consensus on how to respond to "Do Not Track" browser signals, our Services do not currently respond to them. Where required by law, we honour recognised universal opt‑out mechanisms such as the Global Privacy Control (GPC) as an opt‑out of the sale or sharing of personal information, to the extent applicable; as noted in Section 15, we do not sell or share personal information as defined by the CCPA/CPRA.
19. Changes to this document
We may update this document from time to time. If we make material changes, we will update the "Last updated" date above and, where practicable, notify you through the Discord community or the website. Your continued use of the Services after any modification indicates your acceptance of the updated Policies.
20. Contact and complaints
If you have questions, concerns, or complaints about how we handle your personal information, please contact us as described in Section 1. If you are located in the European Economic Area, the United Kingdom, or another jurisdiction that provides a right to lodge a complaint with a supervisory authority, you may do so with your local authority, without prejudice to any other administrative or judicial remedy.