Privacy Policy
Effective Date: July 18, 2026
Last Updated: July 18, 2026 • Version 2.2
This Privacy Policy explains how the Virtual Royal Canadian Air Force (RCAFv) collects, uses, discloses, retains, and protects personal information through its public website, the LEAF personnel and operations platform, and related services. It is intended for applicants, members, former members, visitors, and other individuals whose personal information is processed by RCAFv.
1. Purpose, Scope, and Identity
1.1. Covered Services
This Policy applies to the public website at www.rcafv.org, the LEAF web application at pilots.rcafv.org, and any other RCAFv-operated website, application, form, or service that links to this Policy (collectively, the “Services”).
A single, canonical copy of this Policy shall be maintained on the main public website. Links to that copy shall be made readily available from the public website, LEAF, application and onboarding pages, and other points at which personal information is collected.
1.2. Organization and Controller
The Virtual Royal Canadian Air Force (RCAFv) is a voluntary, non-commercial Virtual Special Operations Association operating within the VATSIM network. For purposes of applicable data-protection law, RCAFv is the controller. Commander, RCAFv holds ultimate organizational accountability, and the Director, Air Personnel Management serves as Data Custodian, Privacy Lead, and Data Protection Coordinator.
Privacy administration is assigned to the Director, Air Personnel Management. Official privacy, legal, and security contact information appears in Section 14.
1.3. Simulation-Only Notice
RCAFv is a flight-simulation community. It is not affiliated with, endorsed by, or in any way connected to the Government of Canada, the Department of National Defence, the Canadian Armed Forces, or the real-world Royal Canadian Air Force. RCAFv ranks, appointments, records, and activities have no real-world military status or authority.
1.4. VATSIM Privacy Notice and Acknowledgment
RCAFv provides a conspicuous privacy notice and a link to this Policy on its main public website. Applicants and members shall be presented with an affirmative authorization and acknowledgment—described by VATSIM policy as member consent—to the collection and use of membership information under this Policy during application, onboarding, or another appropriate account workflow. This authorization documents notice and acceptance of the membership data practices described in this Policy. Where the GDPR or UK GDPR applies, each processing activity shall rely on the lawful basis identified in Section 3, and consent under Article 6(1)(a) shall be relied upon only for optional processing that can be refused or withdrawn without loss of unrelated core membership functions.
2. Personal Information Collected
2.1. Public Website and Technical Information
When an individual visits the Services, RCAFv may collect technical information generated by the web server or security systems, including Internet Protocol address, date and time of access, browser and device type, operating system, referring page, pages requested, response status, and security-event information. This information is used for security, abuse prevention, troubleshooting, and service performance.
2.2. Cookies and Similar Technologies
LEAF uses cookies or comparable local-storage technologies that are necessary for authentication, session management, security, and user preferences. RCAFv does not use advertising cookies or behavioral advertising technologies.
Application and account pages may use anti-abuse services, including CAPTCHA or similar fraud-prevention tools. Those providers may receive an Internet Protocol address, browser or device information, and interaction data under their own privacy terms. If RCAFv introduces analytics, advertising, or other non-essential technologies, the Services shall provide any consent mechanism required by applicable law before those technologies are activated.
2.3. Applicants
RCAFv may collect the following information from an applicant: full name; date of birth; country; preferred callsign; VATSIM Certificate Identification number (CID); email address; account credentials stored in protected form; application and entry-examination responses; operational division and airframe preferences; current or prior VATSIM organizational memberships; real-world pilot or military aviation experience voluntarily provided for Recognition of Prior Learning; simulator platform, license, add-on, or aircraft availability; communications concerning the application; application status and review history; Internet Protocol address; and anti-abuse or security signals.
2.4. Members
For members, RCAFv may maintain account and contact information; an assigned CFC operational identifier ordinarily used as the member’s default RCAFv flight-plan callsign; nonpublic database and administrative identifiers; rank, appointment, unit, duty-status, enlistment, commissioning, seniority, transfer, assignment, retirement, and release history; training, qualification, Recognition of Prior Learning, examination, checkride, instructor, and currency records; flight, mission, movement, ACARS, VATSIM, event, and activity records; Personnel Evaluation Reports; leave records; administrative counseling and disciplinary records; awards, decorations, citations, and nominations; access permissions and audit logs; official communications; and records necessary to administer retirement, reinstatement, or reapplication.
2.5. Information Received from Other Sources
RCAFv may receive or verify information through VATSIM, including CID, account status, ratings, network activity, and PRAMS information; through instructors, evaluators, commanders, and other authorized RCAFv officials; through partner VSOAs under an approved agreement; and through system-generated records created when an individual uses LEAF.
2.6. Personnel Information Display and Disclosure
RCAFv displays and discloses limited personnel information through a five-level access model to support organizational transparency, internal coordination, and virtual-aviation operations.
(a) Public Roster and Profile. RCAFv publishes a limited Pilot Roster and public pilot profile for organizational identification, public verification of membership status, and virtual-aviation operations. Publicly displayed information is limited to: (1) VATSIM CID; (2) virtual rank; (3) approved service-display name, consisting of first initial and surname; (4) CFC Operational Identifier; and (5) public service-status category.
(b) Limited Public Flight-Activity Display. A public pilot profile may display a limited activity log identifying the date of flight and the departure and arrival ICAO codes associated with the member’s approved flights. Command may also authorize display of the aircraft type. The public activity log shall not include pilot remarks, flight duration, attachments, administrative or evaluative comments, rejected or voided reports, mission-sensitive information, or access to the complete underlying flight report.
(c) Other Public-Disclosure Prohibitions. Except for the limited flight-activity information authorized under subsection (b), public profiles shall not display full names, organizational assignments, detailed personnel history, complete individual flight records, free-text remarks, total flight hours, total sorties, or date of last activity.
(d) Authenticated Member Directory. Members who authenticate through LEAF may access an internal service directory containing information concerning other members in an eligible status. The ordinary authenticated member directory is limited to: (1) internal service name; (2) rank; (3) position title; (4) CFC Operational Identifier; (5) organizational assignment; (6) duty station; and (7) duty status. This directory does not expose country, commission date, date of rank, aircraft assignment, transferred or credited hours, restricted records, or other personnel-history fields to ordinary authenticated peers. A member is eligible for authenticated-directory display only while holding an On Duty / Active or Approved Leave of Absence status.
(e) Authenticated Flight-Activity Display. Authenticated members may view the same limited flight-activity log displayed on a member’s pilot profile. Authentication does not authorize access to the complete flight report, pilot remarks, attachments, administrative annotations, instructor or evaluator comments, or rejected or voided reports.
(f) Authorized Official Access. Commanders, personnel officials, instructors, evaluators, and other designated officials may access additional personnel, qualification, and operational information where required by their assigned duties. Access shall be limited by assigned function and the operational need to know.
(g) Restricted Records. Access to restricted records, including Personnel Evaluation Reports, counseling, disciplinary records, complaints, and security records, is limited to specifically authorized officials. Authentication as a member or appointment to a staff position does not, by itself, confer access to restricted records.
2.7. Sensitive Information and Information Not Requested
RCAFv does not request payment-card information, government-issued identification numbers, biometric identifiers, precise geolocation, political opinions, religious or philosophical beliefs, racial or ethnic origin, trade-union membership, sexual-orientation information, or medical diagnoses as part of routine membership administration.
Members requesting leave or another accommodation are not required to provide a medical diagnosis or unnecessary personal detail. If sensitive information is voluntarily disclosed, RCAFv shall limit collection, access, use, and retention to what is strictly necessary and shall identify an applicable legal basis before processing it.
2.8. Required and Optional Information
Information identified as required on an application or LEAF form is necessary to evaluate eligibility, establish or secure an account, administer membership, meet VATSIM requirements, or perform the requested function. If required information is not provided, RCAFv may be unable to process an application, create or maintain an account, award a qualification, or provide the requested service. Optional fields shall be identified as optional and may be omitted without affecting unrelated membership functions.
3. Purposes and Lawful Bases
RCAFv processes personal information only for specified, legitimate purposes. For individuals in the European Economic Area or the United Kingdom, the principal lawful bases are set out below. VATSIM policy requirements are treated as membership and organizational requirements; they are not characterized as a statutory legal obligation unless an applicable law independently requires the processing.
Where RCAFv relies on legitimate interests, it shall document the purpose, necessity, and balancing of that interest against the rights and reasonable expectations of affected individuals. Where processing is based on consent, consent may be withdrawn at any time without affecting processing that was lawful before withdrawal. Withdrawal of optional consent shall not affect unrelated core membership functions.
| Purpose | Personal Data Category | GDPR Lawful Basis | Data Retention |
|---|---|---|---|
| Public-site security and account protection | IP addresses, browser/device information, access and security logs, authentication events, and anti-abuse signals. | Article 6(1)(f) — legitimate interests in protecting the Services, investigating abuse, preventing fraud, and maintaining reliable systems. | Ordinarily no longer than 90 days for rotating logs, unless required for a specific incident, audit, or legal claim. |
| Application review and enrollment | Application, eligibility, examination, experience, preference, identity, contact, and account-establishment information. | Article 6(1)(b) — steps requested before membership; Article 6(1)(f) — legitimate interests in eligibility review, fraud prevention, and administration. | Unsuccessful or abandoned applications are ordinarily retained for 90 days after final disposition. Accepted application data needed for membership becomes part of the member record. |
| Membership, training, operations, and routine communications | Service, assignment, training, qualification, flight, activity, account, and communication records. | Article 6(1)(b) — administration of membership terms; Article 6(1)(f) — legitimate interests in operating the VSOA. | For active membership and the applicable category-specific post-service period under Section 6 and the SORN. |
| Personnel evaluation, counseling, discipline, release, and reapplication | Evaluation, counseling, discipline, eligibility, release, and reapplication records. | Article 6(1)(f) — legitimate interests in fair administration, good order, safety, accountability, and records integrity. | Under the category-specific SORN schedule, with extended retention only where necessary and subject to review and minimization. |
| Public Pilot Roster and Retired List | VATSIM CID, virtual rank, first initial and surname, CFC Operational Identifier, and public service-status category. | Article 6(1)(f) — legitimate interests in public pilot verification, organizational identification, and VATSIM participation; Article 6(1)(b) where necessary to administer membership terms. | Public visibility while the person remains eligible for the applicable list; underlying records follow the LEAF retention schedule. |
| Authenticated Member Directory | Service-directory information, including internal service name, rank, position, CFC Operational Identifier, organizational assignment, duty station, and duty status. | Article 6(1)(f) — legitimate interests in internal identification, chain-of-command awareness, unit coordination, and virtual-aviation operations, balanced against members’ rights and reasonable expectations of privacy within an organized virtual military association. | Directory visibility while the member remains in an eligible status. Underlying records are retained under the applicable LEAF schedule and legal or organizational obligations. |
| PRAMS and other VATSIM administration | CID, ratings, qualifications, roster and activity evidence, training evidence, and necessary compliance information. | Article 6(1)(b) — administration of membership terms; Article 6(1)(f) — legitimate interests in VSOA and qualification administration. | For the applicable membership, qualification, audit, investigation, or claim period under the SORN. |
| Optional public profile fields or other optional uses | Information affirmatively selected or supplied for an optional purpose. | Article 6(1)(a) — consent. | Until consent is withdrawn or the optional purpose ends, subject to necessary evidence of the consent and withdrawal. |
| Compliance with applicable law and legal claims | Information reasonably necessary for binding legal process, regulatory compliance, or a legal claim. | Article 6(1)(c) where an actual legal obligation applies; Article 6(1)(f) for the establishment, exercise, or defence of legal claims. | For the applicable legal, regulatory, limitation, dispute, or preservation period. |
4. Disclosure and Access
4.1. Disclosure of Personal Information
RCAFv discloses personal information only as described in this Policy or as required by law. Disclosure is governed by the five-level access model:
(a) Public Access. Limited personnel information made available through the public Pilot Roster and public pilot profile, as described in Section 2.6(a).
(b) Member Self-Service Access. Access by an authenticated member to their own personnel, qualification, assignment, and flight information, subject to lawful withholding or system-security limitations.
(c) Authenticated Peer Access. Access by authenticated members to the internal service directory and other information specifically approved for peer visibility under Sections 2.6(d) and 2.6(e).
(d) Authorized Official Access. Access by officials whose assigned duties require access to additional personnel or operational information for command, administrative, training, evaluation, or security functions.
(e) Restricted Access. Access to sensitive or confidential records, such as disciplinary, complaint, or security files, limited to officials with a specific, designated need to know for that category of information.
4.2. VATSIM
RCAFv may disclose a member’s CID, M-Rating, qualification status, roster status, activity evidence, training evidence, disciplinary or compliance information, and other records required for PRAMS administration, VSOA oversight, audit, investigation, or enforcement of VATSIM policy. Disclosures shall be limited to the information reasonably required for the applicable VATSIM function.
4.3. Partner Organizations
Under an approved memorandum, agreement, or joint program, RCAFv may disclose relevant identity, qualification, training, assignment, or activity information to another VSOA or VATSIM organization. The disclosure shall be limited to the agreement’s purpose, and members shall receive appropriate notice where the disclosure is not otherwise reasonably expected as part of the requested activity.
4.4. Internal Access
RCAFv officials may access personal information only when access is reasonably necessary for an authorized duty. Access shall be controlled by role, function, and need to know. Personnel evaluation, counseling, disciplinary, security, and rights-request records shall receive heightened access restrictions.
4.5. Service Providers
RCAFv may use hosting, email, backup, security, CAPTCHA, content-delivery, and technical-support providers. A provider acting as a processor shall be subject to written terms addressing confidentiality, security, instructions, subprocessors, assistance with rights and breach obligations, and return or deletion of data. A current description of processor categories and applicable transfer safeguards may be requested through the privacy contact in Section 14.
4.6. Legal, Safety, and Integrity Disclosures
RCAFv may disclose information when required by applicable law, a binding court order, or a lawful authority; when reasonably necessary to establish, exercise, or defend a legal claim; or when necessary to protect the security of the Services, the rights or safety of individuals, or the integrity of RCAFv or VATSIM operations.
4.7. No Sale or Behavioral-Advertising Sharing
RCAFv does not sell personal information, rent personal information, or share personal information for cross-context behavioral advertising. RCAFv does not use personal information for commercial advertising or data-broker activity.
5. International Data Transfers
RCAFv’s principal LEAF web application and database infrastructure is hosted by DreamHost in Ashburn, Virginia, United States, and its principal hosted mail infrastructure is located in Hillsboro, Oregon, United States. Cloudflare Turnstile, content-delivery networks, support providers, and subprocessors may process limited technical information in other countries. RCAFv maintains the applicable provider and transfer information in its processor and transfer register.
For DreamHost processing in the United States, RCAFv relies on DreamHost’s Data Processing Addendum, which incorporates the European Commission Standard Contractual Clauses (Module 2) and the United Kingdom International Data Transfer Addendum. Other providers are evaluated for an adequacy decision, Data Privacy Framework participation, contractual safeguards, or another authorized transfer mechanism as applicable. RCAFv conducts and documents any transfer-risk assessment and supplementary measures required for the relevant service.
An individual’s acknowledgment that processing may occur internationally is not itself a transfer mechanism. Questions about international processing or available safeguards may be submitted to privacy@rcafv.org.
6. Retention, Archiving, and Deletion
RCAFv shall retain personal information only for as long as reasonably necessary for the purpose for which it was collected, an identified compatible purpose, an applicable legal requirement, or the establishment, exercise, or defense of a claim. Retention periods shall be implemented in LEAF and documented in the System of Records Notice or an internal retention schedule.
At the end of a retention period, information shall be deleted, anonymized, or placed in a restricted archive when continued historical retention is justified. Archives shall not remain available for routine personnel use. Retention exceptions shall be documented and reviewed periodically.
| Record Category | Ordinary Retention |
|---|---|
| Rotating website and security logs | No longer than 90 days, unless retained longer to investigate a specific security incident or legal claim. |
| Unsuccessful, withdrawn, or abandoned applications | 90 days after final disposition, unless a shorter period is requested and no fraud, security, appeal, or legal need requires continued retention. |
| Active-member records | For the duration of active membership and as otherwise stated below. |
| Retired-list records | For the duration of retired-list status, with periodic review and data minimization. |
| Routine records of released members | Ordinarily 3 years after the effective date of release. Cadets released under Release Item 5 may be retained for 1 year. |
| Training, qualification, flight, and service-history records | For the active or applicable post-release period; a minimized historical record may be retained longer where necessary to verify qualifications, prior service, or official organizational history. |
| Disciplinary and counseling case files | For the active proceeding, sanction, appeal, and ordinary post-release period. Longer retention is permitted only while necessary to enforce a continuing restriction, evaluate reapplication, resolve a dispute, protect safety or integrity, or establish, exercise, or defend a claim. Complete case files shall not be retained indefinitely merely because a finding was entered. |
| Final release classifications and reapplication restrictions | For as long as necessary to enforce the classification or restriction, subject to periodic review and minimization. |
| Awards and decorations | The formal award register and published citation may be retained indefinitely as an official historical record. Supporting nomination and deliberative records shall be retained only for the applicable administrative period. |
| Backups | Created manually before deployments and retained only as long as reasonably necessary for deployment recovery, incident response, or an approved hold. Backups are reviewed and securely deleted through the documented manual procedure. |
7. Individual Rights and Requests
7.1. Rights Available to All Individuals
Any individual may request information about RCAFv’s processing, correction of inaccurate account or profile information, removal of optional public-profile information, or review of a privacy concern. RCAFv may require proportionate information to verify identity and authority before disclosing or changing a record.
7.2. EEA and UK Rights
Subject to applicable conditions and exceptions, an individual in the EEA or UK may request access, rectification, erasure, restriction, or portability; may object to processing based on legitimate interests; may withdraw consent for consent-based processing; and may lodge a complaint with the supervisory authority for the individual’s habitual residence, place of work, or the location of the alleged infringement.
RCAFv shall respond without undue delay and ordinarily within one month. That period may be extended by up to two additional months when a request is complex or numerous, provided the individual is informed within the original one-month period. A fee shall not ordinarily be charged, but RCAFv may take action permitted by law for a manifestly unfounded or excessive request.
7.3. California Privacy Rights
To the extent the California Consumer Privacy Act or California Privacy Rights Act applies, and as a voluntary privacy practice where it does not, a California resident may request access to categories and specific pieces of personal information, correction, deletion, and information about sources, purposes, and disclosures. RCAFv does not sell personal information or share it for cross-context behavioral advertising.
A verified California request shall ordinarily be acknowledged and completed within 45 days, subject to a permitted extension of up to 45 additional days with notice. RCAFv shall not discriminate against an individual for exercising an applicable privacy right. An authorized agent may submit a request with appropriate proof of authority.
7.4. Canadian Privacy Rights
To the extent the Personal Information Protection and Electronic Documents Act or an applicable provincial privacy law applies, and as a voluntary privacy practice where it does not, an individual may request access to and correction of personal information and may challenge RCAFv’s compliance. Withdrawal of consent applies only to processing that is actually based on consent; it does not invalidate processing supported by another lawful basis.
7.5. Limitations
A request may be limited or refused where applicable law permits, including where disclosure would adversely affect another person’s rights, reveal protected security information, undermine an active investigation, or conflict with a justified retention requirement. RCAFv shall explain a refusal or limitation unless prohibited from doing so.
7.6. Submitting a Request
Requests shall be submitted through the contact information in Section 14. The request should identify the individual, the requested action, the relevant service or record, and a method for receiving the response. RCAFv shall maintain an internal record of requests and responses for accountability.
8. Cookies, Tracking Preferences, and External Assets
RCAFv uses only technologies necessary to provide, secure, and maintain the Services unless additional notice and consent are provided. Session and authentication cookies are required for LEAF and cannot be disabled through a privacy preference without preventing login or secure account use.
RCAFv does not engage in cross-site behavioral tracking. Because RCAFv does not sell or share personal information for behavioral advertising, browser Do-Not-Track and Global Privacy Control signals ordinarily do not change the Services’ core data practices. If a future service performs a covered sale, sharing, or non-essential tracking activity, RCAFv shall recognize legally required preference signals and provide the required controls.
Where practicable, RCAFv shall self-host static assets. When an external content-delivery, font, security, or CAPTCHA provider is used, RCAFv shall disclose the provider category, assess whether it acts as a processor or independent controller, and apply the appropriate contractual and transfer safeguards.
9. Security and Personal-Data Breaches
RCAFv shall maintain reasonable and proportionate technical and organizational measures appropriate to the nature and risk of the information processed. Measures may include encryption in transit, protected credential storage, role-based access, least-privilege permissions, audit logging, secure backups, patching, access review, incident response, and confidentiality obligations.
RCAFv cannot guarantee absolute security. Suspected unauthorized access, loss, alteration, or disclosure shall be reported promptly to security@rcafv.org. RCAFv shall document personal-data breaches, assess the risk to affected individuals, preserve relevant evidence, and make notifications required by applicable law. Where the GDPR or UK GDPR applies, RCAFv shall notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a reportable breach. Affected individuals shall be notified without undue delay when a breach is likely to create a high risk to their rights and freedoms.
Processors shall be required to notify RCAFv of a suspected personal-data breach without undue delay and to provide information needed for investigation, mitigation, and notification.
10. Children and Minimum Age
RCAFv requires applicants to be at least 16 years of age. RCAFv does not knowingly accept an application or create a membership account for a person under 16. If RCAFv learns that information was collected from a person under 16 contrary to this rule, the information shall be deleted or otherwise handled as required by law.
The minimum-age rule is an eligibility requirement. It is not intended to imply that all core processing is based on consent under Article 8 of the GDPR.
11. Automated Processing
LEAF performs two routine automated administrative processes: identity-verified email-address corrections after the account holder proves control of the replacement address, and approval of leave requests of 0-44 days under PERSMAN section 7.2.3.1. Neither process produces a legal or similarly significant adverse effect. RCAFv does not use solely automated processing to impose discipline, terminate membership, deny a material benefit, or make another materially adverse personnel, qualification, release, or reapplication decision.
Material personnel, qualification, disciplinary, release, and reapplication decisions remain subject to authorized human review. An individual may request review of a material decision that appears to rely on inaccurate data or an automated system function.
12. Accuracy and Member Responsibilities
Individuals shall provide accurate information and shall update material account or contact information when it changes. RCAFv shall take reasonable steps to keep information accurate and shall provide a process for correction.
Members shall not enter unnecessary sensitive information into free-text fields, leave requests, counseling records, or other LEAF forms. Authorized officials shall avoid copying or retaining personal information when a less intrusive record will satisfy the official purpose.
13. Changes to This Policy
RCAFv may amend this Policy to reflect changes in law, VATSIM policy, the Services, or organizational practices. The effective date and version shall be displayed at the beginning of the Policy, and material changes shall be communicated through LEAF, email, the main public website, or another appropriate channel before or when the change takes effect.
Where a change introduces a new consent-based purpose, RCAFv shall obtain new consent before beginning that processing. Continued use of the Services shall not be treated as consent to a use that legally requires a separate affirmative choice. The revision record at the end of this document summarizes material amendments.
14. Contact, Complaints, and Representatives
Privacy questions, rights requests, complaints, and reports of suspected data misuse may be directed to:
Director, Air Personnel Management
Virtual Royal Canadian Air Force
Privacy questions, rights requests, complaints, and international-transfer concerns: privacy@rcafv.org
Legal notices: legal@rcafv.org
Security incidents and vulnerability reports: security@rcafv.org
Privacy request form: pilots.rcafv.org/legal/privacy_request.php
RCAFv aims to acknowledge privacy inquiries promptly and to respond within the time required by applicable law. EEA and UK individuals may also complain directly to the competent supervisory authority. Transactional system messages may be sent from admin@rcafv.org or noreply@rcafv.org, but those addresses are not the designated channels for privacy-rights requests.
RCAFv is established in the United States and has not appointed a representative in the European Economic Area or the United Kingdom. Based on its limited, non-commercial operations, processing scale, and the nature of the information processed, RCAFv currently relies on the exemption from the representative requirement provided by Article 27(2)(a) of the GDPR and the corresponding provision of the UK GDPR. Individuals in those jurisdictions may submit privacy requests or complaints directly through the contact methods listed in this Policy. This position may be reviewed if RCAFv’s processing activities, membership, or legal obligations materially change.
Appendix A. California Personal-Information Categories
This appendix summarizes the categories of personal information described by California law. It is provided to the extent California law applies and as a voluntary transparency practice where RCAFv is not a covered business.
| Category | Examples Collected or Potentially Collected | Sources and Principal Uses |
|---|---|---|
| A — Identifiers | Name, email, VATSIM CID, assigned CFC operational identifier, nonpublic database identifiers, account name, and IP address | Directly from the individual, VATSIM, and system logs; used for identity, accounts, applications, security, public pilot verification, and administration. |
| B — Customer-record information | Name, email, date of birth, country | Directly from the individual; used for eligibility, contact, age verification, and administration. RCAFv does not request financial-account or government-ID information. |
| C — Protected classifications | Age derived from date of birth; other classifications are not requested | Used only for minimum-age eligibility. RCAFv does not request race, religion, sex, disability, or similar classifications. |
| D — Commercial information | Simulator platform, software license, add-on or aircraft availability | Directly from the applicant or member; used for training placement and operational qualification. No purchase transaction data is collected. |
| E — Biometric information | Not collected | Not applicable. |
| F — Internet or network activity | Logs, browser/device information, authentication events, LEAF interactions | Generated through use of the Services; used for security, troubleshooting, audit, and service operation. |
| G — Geolocation | Country; approximate location may be inferred from IP by a security provider | Used for eligibility, security, and transfer analysis. Precise geolocation is not collected. |
| H — Sensory information | Not routinely collected | RCAFv does not routinely collect audio, video, or similar sensory data through LEAF. |
| I — Professional or employment information | Real-world pilot or military aviation experience voluntarily provided | Directly from the applicant; used for Recognition of Prior Learning and training placement. |
| J — Education information | Training and qualification records created by RCAFv; no FERPA education records requested | Created by instructors, evaluators, and LEAF; used for progression, qualifications, and currency. |
| K — Inferences | Eligibility, training-entry, activity, currency, and qualification indicators | Derived from submitted and system records; used to support, not replace, authorized human decisions. |
Revision Record
| Revision Date | Summary of Changes | Version |
|---|---|---|
| 18 July 2026 | Personnel-view amendments establishing the five-level access model, authenticated service directory, inactive peer flight-history feature, and function-based official and restricted access. | 2.2 |
| 14 July 2026 | Final reconciliation of verified public-roster fields, automated administrative processing, Article 27 position, contacts, legal identity, hosting and transfer safeguards, and manual operational procedures. | 2.1 |
| 4 July 2026 | Initial publication. | 1.0 |
RCAFv