Data Protection and Handling Policy
Introduction
Purpose of this policy
This policy has been put in place to achieve the following aims:
- To comply with applicable data protection law, including the UK General Data Protection Regulation and the Data Protection Act 2018.
- To ensure good data protection practice.
- To protect members, staff, and other individuals.
- To protect the organisation.
Types of data
BAVirtual collects a range of personal data on members at the time of joining. This data includes:
- The date of application.
- Full name as registered with VATSIM.
- Date of birth and, therefore, age.
- Email address.
- VATSIM network ID. Applicants must be a VATSIM member to join BAVirtual as outlined in the BAVirtual Policy.
- Country and city of residence.
- IP address from the location where the application is submitted.
A list of members and their registered names is available to all other members when logged in to BAVMS.
In addition, whilst connected to the BAVirtual server via Merlin, information specific to the simulated aviation operation at that time is collected. The only personal information that is visible is behind password protection and is not publicly visible. Whilst the ACARS system is visible publicly, only membership IDs are stated and no personal details can be seen related to the visible ID unless the member is logged in. Once logged in, members' names and IDs are visible on the ACARS system, being linked to details of the flight being conducted by each member.
Policy Statement
BAVirtual is committed to:
- Complying with applicable data protection law and good practice.
- Respecting individuals' rights, including:
- The right to be informed.
- The right of access.
- The right to rectification.
- The right to erasure.
- The right to restrict processing.
- The right to data portability, where applicable.
- The right to object.
- Rights relating to automated decision-making and profiling, where applicable.
- Being open and honest with individuals whose personal data is held.
- Providing training and support for staff who handle personal data, so that they can act confidently and consistently.
- Assessing, documenting and responding appropriately to personal data breaches, including notifying the Information Commissioner's Office and affected individuals where required by law.
Key risks are detailed in the Specific Risks paragraph below.
Responsibilities
The Board of Directors
Overall responsibility for ensuring data protection and overall compliance with the relevant standards and legislation rests collectively with the BAVirtual Board of Directors.
Data Protection Officer
There is no appointed Data Protection Officer within BAVirtual as the organisation does not regularly process data on a large scale, due to the nature of the data that is collected and controlled, and the circumstances in which it is collected.
Specific Directors with access to personal details
Several members of the Board of Directors have specific responsibilities requiring access to membership details. They also oversee other staff members accessing personal data collected by BAVirtual:
CEO – The CEO, as the leader of the VA, has access to member's details which may be required when carrying out his duties in overseeing the running of the VA.
Director of Membership – in order to process applications to join BAVirtual and manage membership issues for existing members, has full access to all personal details held about existing members and people who apply to join BAVirtual.
Director of Technical Services – oversees all technical aspects of running BAVirtual including managing member's accounts and the permissions of staff members to those accounts. Other members of the Board of Directors may from time to time be tasked with specific responsibilities pertaining to the control and storage of data.
Staff and Volunteers
All staff members are required to read, understand and accept any policies and procedures that relate to the personal data they may handle in the course of their work within BAVirtual as detailed in this policy. BAVirtual expects the highest standard of probity of all staff at all levels. No access to data is to take place unless there is a valid reason for such access.
Enforcement
BAVirtual has a zero-tolerance policy towards inappropriate access to data stored on our secure server. Any such access will result in the individual concerned being prohibited from having further access for a minimum period of 10 years. This may result in the member being excluded from BAVirtual.
Security
Scope
BAVirtual's Security policy applies to all the servers belonging to BAVirtual, including, but not limited to Data Servers, Statistic Servers, or Web Servers.
Setting security levels
BAVirtual operates on a segmented security approach, where only the access required with approval by the BAVirtual Board of Directors to complete a required job function is granted. BAVirtual employs access monitoring systems to ensure that access is not being abused and can be tracked back to a specific individual.
Security measures
BAVirtual uses appropriate encryption in transit, including current versions of TLS, to protect data transmitted between systems. BAVirtual also uses change-auditing, logging and monitoring controls to provide visibility into server and network activity. IP address restrictions, key-based authentication and other access controls are used, where appropriate, to limit server access to authorised personnel. Passwords are stored using appropriate one-way cryptographic hashing and are not stored in plain text.
Business continuity
In order to ensure business continuity, BAVirtual retains data backups of relevant systems to ensure recovery of impacted systems while maintaining data integrity and security. Access to these backups is granted only to authorised individuals.
Specific risks
The main specific risks to the security of data are:
- Phishing attacks to gain account access;
- Access by means of Trojan or keylogging programmes on member's systems;
- Inappropriate or unauthorised access to non-entitled data by staff members who have been granted system access.
Mitigation of the first two risks is by encouraging members who have a higher level of access to ensure they adhere to good security practices on their personal systems. The last risk is mitigated by training, access logging and reverting changes made by those who misuse access.
Data recording and storage
Accuracy
BAVirtual takes reasonable steps to ensure that personal data is accurate and, where necessary, kept up to date. Members and staff are encouraged to report any information they believe is inaccurate or incomplete so that it can be reviewed and corrected where appropriate.
Updating
Members may request that personal data held about them is corrected or updated. Requests may be made verbally or in writing, although members are encouraged to raise a ticket with the Membership Department so that the request can be recorded and managed securely. Tickets may be raised at this location.
BAVirtual will investigate whether the information is inaccurate or incomplete and will correct it where appropriate.
Storage
Personal data may be stored in databases, application systems, support systems, logs, monitoring platforms and securely maintained backups. Access is limited according to role and operational need.
Retention periods
Personal data is retained only for as long as reasonably necessary for the purposes for which it was collected, to operate BAVirtual, meet applicable legal obligations, resolve disputes or establish, exercise or defend legal claims. Retention periods are determined according to the nature of the information, the purpose for which it is held and the risks associated with its continued retention.
Archiving
BAVirtual may retain inactive or historic records where there is a continuing operational, evidential or legal need. Archived information remains subject to appropriate access controls and retention requirements.
Transparency
Commitment
BAVirtual is committed to ensuring all members are aware of what data is collected and why we do so. As outlined in the statement of legitimate interests, data is collected for the purpose of ensuring the provision of and smooth operation of BAVirtual as a VA so that members can jointly enjoy the simulated aviation environment it provides. Personal data will not be sold or disclosed to third parties for their own purposes. BAVirtual may provide limited personal data to contracted service providers acting as data processors where this is necessary to operate, secure, maintain or improve BAVirtual's services, or where disclosure is required by law.
Error monitoring and diagnostics
BAVirtual uses Sentry, a third-party application monitoring and error-reporting service, to identify software faults, investigate technical problems and improve the security, reliability and performance of its systems.
When an error or performance issue occurs, limited technical information may be transmitted to Sentry. Depending on the system and the circumstances of the error, this may include:
- The member's BAVirtual identification number or an internal account identifier.
- IP address and approximate geographic information derived from it.
- Browser, device and operating system information.
- The page or function being accessed.
- The date and time of the event.
- Diagnostic information, including error messages, application logs and technical details relating to the request.
BAVirtual does not intentionally send passwords, authentication credentials or special category personal data to Sentry. Appropriate controls and data-scrubbing measures are used to minimise the personal data included in diagnostic reports.
This information is processed for BAVirtual's legitimate interests in maintaining secure, reliable and functional services. Sentry acts as a data processor on behalf of BAVirtual and processes this information only for the provision of its monitoring and diagnostic services.
Information submitted to Sentry is stored and processed in the United States. Where personal data is transferred outside the United Kingdom, BAVirtual relies on appropriate legal safeguards provided through Sentry's data processing terms, including applicable international data transfer provisions, to protect that information.
Diagnostic information is retained only for as long as reasonably necessary to investigate faults, maintain system security and improve BAVirtual's services.
Website security and delivery
BAVirtual uses Cloudflare to deliver, protect and improve the availability, security and performance of its websites and online services.
When a member or visitor accesses a BAVirtual service, Cloudflare may process limited technical information relating to the request. Depending on the service being accessed, this may include:
- IP address and approximate geographic location.
- Browser, device and operating system information.
- The requested page, domain or network resource.
- The date and time of the request.
- Information used to identify and prevent malicious, automated or otherwise suspicious traffic.
- Technical information relating to website performance, security events and network activity.
This information is processed for BAVirtual's legitimate interests in maintaining the security, availability, reliability and performance of its online services. Cloudflare acts as a data processor on behalf of BAVirtual when processing personal data to provide these services.
Cloudflare operates a global network and information may therefore be processed outside the United Kingdom. Where this involves an international transfer of personal data, BAVirtual relies on appropriate safeguards contained within Cloudflare's data processing terms.
Information processed through Cloudflare is retained in accordance with the retention periods applicable to the Cloudflare services used by BAVirtual and only for as long as necessary for security, operational and diagnostic purposes.
Procedures
Details on how to exercise rights in relation to the data held is detailed in the relevant sections of this policy.
Responsibility
All staff within BAVirtual are responsible for members' data at all times. The various departments most closely associated with members' data are the BAVirtual Directors as highlighted above, and their associated staff. Where staff require to use data for statistical and management purposes aggregated pseudonymised data should be used where possible.
Right of Access
Responsibility
Requests for personal data under the Right of Access are the responsibility of the Membership Team. Such requests are required to be complied with within one month of the request being received. If circumstances prevent this from occurring, an extension of a further two months may be instituted by BAVirtual, providing that the member making the request is informed of this fact before the expiration of the original one month deadline.
Procedure for making request
Right of access requests must be in writing, preferably via Ticket (https://support.bavirtual.co.uk/). If a staff member at a lower level receives anything that might reasonably be construed to be a request for access they have a responsibility to pass this to the Director of Membership without delay.
Provision for verifying identity
Where the person managing the access procedure does not know the individual personally there should be provision for checking their identity before handing over any information.
Charging
BAVirtual does not charge any fee for providing data for requests under the Right of Access.
Procedure for granting access
The Director of Membership is responsible for handling requests under the Right of Access provisions. Requests will be made via raising a ticket with the Membership Department. The data will then be proofread and sent to the member making the request. Because of the potentially sensitive nature of comments on a members record, as well as ensuring there is no retaliation or harassment against BAVirtual Staff, and to protect the privacy of staff members, names of those staff who have made entries on a members record, along with any security measures adopted by BAVirtual, are redacted before sending it to the member.
Right of Rectification
Responsibility
Accurate personal data is important to BAVirtual and its members.
Procedure for making requests
Right of rectification requests should in the first instance be made by ticket at (https://support.bavirtual.co.uk/) by the member making the request. If staff at a lower level receive anything that might reasonably be construed to be a request for rectification they have a responsibility to direct the member to contact the Membership Department.
Disputes
Where there is a dispute between a member and BAVirtual over the accuracy of data, the member shall be empowered to make any final decision on whether to alter data or not. This decision should be communicated to the member making the request within one calendar month of the request having been made.
Charging
BAVirtual does not charge any fee for requests under the Right of Rectification.
Lawful Basis
Underlying principles
BAVirtual asserts that it has a legitimate interest in collecting and storing the personal data outlined above.
The reasons for this claim are:
- BAVirtual is a voluntary community promoting flight, and all members seeking to join have an obvious interest in such activities.
- The data collected is the minimum required to allow for the smooth and optimal running of the VA, solely for the enjoyment of its members.
- That the data is necessary to allow for BAVirtual staff to properly manage the VA, both in day-to-day operations, and in circumstances where a member(s) may act in a manner contrary to the BAVirtual Policy.
- That is because all members have a shared interest in these aims that the collection of such data should be reasonably expected by all members.
Members under 16 years
BAVirtual does not accept membership from any individual under 16 years of age. Members found to have falsified their age will have their account closed immediately.
Opting out
Notwithstanding BAVirtual's claim of legitimate interest, members may at their discretion object to this claim and/or request that BAVirtual cease processing of a member's personal data. These two rights are known as the Right to Object, and the Right to Restrict Processing. Members must be aware that if they choose to exercise either of these rights BAVirtual is obliged to close their accounts in order to comply with their wishes and they will no longer be a member of BAVirtual.
Timing of opting out
While a notification of an objection to BAVirtual's claim of legitimate interest, or a request to suspend processing may be made at any time, such claims may not be made retrospectively.
Right of Erasure
Responsibility
Requests for deletion of personal data under the Right of Erasure are the responsibility of the member concerned. Such requests are required to be complied with within one calendar month of the request being received. If circumstances prevent this from occurring, an extension of a further two months may be instituted by BAVirtual, providing that the member making the request is informed of this fact before the expiration of the original one-month deadline.
Procedure for making requests
Right of erasure requests should be in writing, preferably by ticket at (https://support.bavirtual.co.uk/). On receipt of a verbal request for erasure (in Discord, for example), staff concerned should immediately ask the member making the request to confirm the request in writing as above. If staff at a lower level receive anything that might reasonably be construed to be a request for erasure they have a responsibility to pass this to the Director of Membership without delay.
Provision for verifying identity
Where the person managing the erasure procedure does not know the individual personally there should be provision for checking their identity before deleting any information.
Charging
BAVirtual does not charge any fee for deleting data under the Right of Erasure.
Procedure for granting erasure.
BAVirtual shall evaluate all requests for erasure. BAVirtual reserves the right to retain any data that it believes is in its legitimate interest to do so, or that is required to establish, exercise, or defend any legal claims.
Staff training & Acceptance of Responsibilities
Induction
All staff who have access to any kind of personal data should have their responsibilities outlined during their induction procedures.
Continuing training
If there are opportunities to raise Data Protection issues during staff training, team meetings, supervisions, etc. these shall be undertaken.
Procedure for staff signifying acceptance of policy
All staff given access to member's details shall receive training on data access procedures via the documents outlined above. All such members are required to acknowledge that they have received this training, that they understand the requirements of them, and their acknowledgement to be bound by them. Electronic mail is an acceptable (and the preferred) method for this acknowledgement. This acknowledgement will be recorded on the member's records.
Policy review
Responsibility
The responsibility for review of this policy rests with the Board of Directors and will normally be annually.
Procedure
At a minimum this review shall require:
- Consultation with the full Board of Directors.
- Specific consultation with all Directors with responsibilities under this policy.
- Analysis of all audits of data access during the period of validity of the current policy.
- Analysis of any data breaches during the period of validity of the current policy.
Revision History
| Rev. No | Date Entered | Revision History |
|---|---|---|
| 1.0 | N/A | Original publication. |
| 1.1 | February 2024 | Full review. |
| 1.2 | September 2025 | Reviewed and minor updates to reference the membership ticket system made |
| 1.3 | July 2026 | Added information about the use of Sentry and Cloudflare, updated data storage and retention provisions, and made related security and wording improvements. |