AURORA Air

AURORA Air
UAS FLIGHT CONTROL

Free · Non-Profit · Community Driven
Last updated: 10 August 2026

Privacy Policy · AURORA Air

1. Controller and contact

Benjamin M. Boenigk
Wiesenstr. 9
63165 Mühlheim am Main
Germany
air@aurora-os.de

2. Hosting and server logs

The platform is operated on a virtual server supplied by dogado GmbH. When pages are requested, technically necessary connection data such as IP address, timestamp, requested resource, referrer and browser information may be processed in server logs for delivery, security and fault analysis.

3. Account and flight data

Registration stores email address, password hash, display name, country, language and verification status. Optional profile data may include the remote pilot certificate number, qualification and validity as well as the public part of the UAS operator registration number. Drone data may include the assigned public operator number, aircraft serial number, Remote ID details, insurance information, notes and images. The three secret suffix characters of a full operator registration string are neither required nor intentionally stored. For flight documentation, pilot, qualification, operator and aircraft data may be retained as a historical snapshot together with mission data, location, coordinates, checklists, weather, NOTAM confirmation, readiness, personal flight notes and timestamps. Passwords and one-time tokens are not stored in plain text.

4. Contact form and email

When you contact us, we process your name, email address, subject and message to handle and answer your enquiry. Processing is based on Art. 6(1)(b) GDPR where the enquiry concerns contractual or pre-contractual matters and otherwise on our legitimate interest in responding to communications under Art. 6(1)(f) GDPR. Messages are sent through the configured mail server and retained only as long as needed to answer the enquiry or comply with legal retention duties. A hidden anti-bot field and short session-based sending limits protect the form; no advertising or analytics tracking is used.

5. Cookies and transactional email

A technically necessary session cookie keeps users signed in and protects forms. Transactional email is used for address verification and password reset. Mail events are recorded for delivery auditing and rate limiting. No advertising or analytics cookies are currently used.

6. Device location and external services

Location is requested only after active browser permission. The browser sends coordinates to BigDataCloud for a readable location and to Open-Meteo for current weather. Icons are served locally. Official AIS/UAS-zone websites open only when selected. These external providers may receive connection data and request contents. Named planning locations are stored in the account only after explicit selection.

7. Retention and user rights

Data is retained while the account and associated records are needed. Users can permanently delete their account, drones and flight data in their profile. Expired one-time tokens become unusable; operational mail logs may be retained for security and rate-limit evidence. Subject to applicable law, users may request access, correction, deletion, restriction, portability or object to processing and may complain to a supervisory authority.