Privacy Notice
Information under Articles 13 and 14 GDPR about how EastProd s.r.o. processes personal data in XCInsight.
1. Controller
The controller is EastProd s.r.o. Contact details are shown below. We have not appointed a data protection officer unless a legal obligation to do so arises.
2. Data categories
Account data: name, e-mail, password hash, locale, account and email-verification status, legal-acceptance records. Pilot profile: wing, size, EN class, all-up weight, harness, experience, approximate flight hours and optional notes.
Flight and location data: IGC/GPS track, timestamps, coordinates, altitude and derived flight metrics, thermals, glides, launch site, terrain/weather context, comparisons and stored AI analyses. Location tracks can reveal habits and places and are treated as personal data.
Billing data: plan, Stripe customer/subscription identifiers, subscription status, billing cycle and timestamps. Card numbers and CVC are entered into Stripe-hosted interfaces and are not stored by XCInsight.
Technical/security data: session data, IP/network identifiers, security and rate-limit events, server logs, device/browser information and diagnostic data. For legal evidence, some events store one-way hashes rather than full IP/user-agent values.
Team data: membership, role, invitations, join requests, audit records and access to flights shared inside a Team.
Support and legal requests: messages, complaints, privacy requests and statutory withdrawal requests.
3. Purposes and legal bases
We process account, profile, flight, team and requested AI data to perform the contract (Article 6(1)(b) GDPR).
We process security, abuse prevention, service integrity, diagnostics, fraud prevention and limited operational records on the basis of legitimate interests (Article 6(1)(f)), balanced against user rights.
We process billing, accounting, consumer-law records and legal requests to comply with legal obligations (Article 6(1)(c)) and, where necessary, to establish, exercise or defend legal claims.
Consent is used only where required for optional processing such as future non-essential analytics or marketing. Consent can be withdrawn at any time without affecting prior lawful processing.
4. AI processing
When you request an AI analysis or narrative, relevant flight metrics, environmental context, requested location/time information and limited profile context may be sent to an AI provider to generate the response. We minimise the data sent and do not send passwords or full payment-card details.
AI outputs can be cached or stored with the flight or forecast request so repeated viewing does not necessarily require a new generation.
5. Recipients and subprocessors
We use service providers for hosting, e-mail, payments, maps, AI and environmental data. The current operational list is published on the Subprocessors page.
Stripe receives payment and billing information through its hosted interfaces. Depending on the processing activity, Stripe may act as our service provider and/or as an independent controller under its own legal obligations.
6. International transfers
Some providers may process data outside Slovakia or the EEA. Where GDPR requires transfer safeguards, we rely on an adequacy decision, Standard Contractual Clauses or another lawful transfer mechanism and supplementary measures where appropriate.
7. Retention
Account and flight data are generally kept while the account is active and are deleted or anonymised after account deletion, subject to legal holds, backup cycles and records that must be retained by law.
Operational/security logs are normally rotated within approximately 180 days unless a security incident or legal claim requires longer retention. Backups are normally rotated within approximately 90 days.
Billing, accounting, contract-acceptance, withdrawal and transaction records may be retained for the statutory accounting, tax, consumer-protection and limitation periods, which can be up to 10 years depending on the record and legal requirement.
8. Your GDPR rights
Subject to statutory conditions, you can request access, rectification, erasure, restriction, portability and object to processing based on legitimate interests. Where processing is based on consent, you may withdraw that consent.
We normally respond within one month. That period can be extended where GDPR permits. We may verify identity before acting on a request.
9. Complaints
You may contact us first and you also have the right to lodge a complaint with the Slovak Office for Personal Data Protection or another competent EEA supervisory authority, particularly in the Member State of your habitual residence or place of work.
10. Automated decision-making
XCInsight does not currently make decisions producing legal or similarly significant effects on users solely by automated processing. AI analysis is advisory and must not be treated as an authoritative safety decision.
11. Security
We apply measures such as password hashing, access controls, CSRF protection, rate limits, restrictive security headers, signed Stripe webhooks and minimised access to secrets. No internet service can guarantee absolute security.
12. Children and capacity
XCInsight is not directed at young children. Where a user lacks legal capacity to enter into a contract or to consent to a particular data-processing activity, appropriate parent or guardian involvement is required.
13. Changes
We update this Notice when processing, providers or law materially change. Significant changes are communicated where required, and versioned acceptance/acknowledgement may be requested.
14. LIVE flight data and mobile diagnostics
When LIVE is used, XCInsight can process current GPS coordinates, timestamps, altitude, speed, heading and accuracy; barometric pressure, relative altitude and vertical speed; approximate AGL; terrain or layer availability; nearby mapped-hazard counts; and technical state such as network and battery information where supported. These data are processed to provide the requested LIVE flight-computer functions under Article 6(1)(b) GDPR.
The mobile app also creates local JSONL diagnostic logs for flight validation and troubleshooting and currently retains up to the 10 most recent debug sessions on the device. These logs remain on the device unless the user deliberately shares them. XCInsight does not automatically upload those debug files.
When optional LIVE AI is enabled, the current AI request contains derived telemetry such as climb or sink, approximate AGL and data-status or hazard-count summaries. Raw flight-track coordinates and user identity are not included in that AI generation request. Operational diagnostics and abuse prevention can be processed on the basis of legitimate interests under Article 6(1)(f) GDPR.
XCInsight infrastructure uses encrypted Amazon S3 backup archives for resilience. The current backup configuration expires weekly archives after 84 days and pre-deployment archives after 30 days; legal holds or incident-response needs can require a different retention period.
15. Google sign-in
If you choose Sign in with Google, Google authenticates your account and provides XCInsight with the Google account identifier, verified e-mail address, display name and, where available, profile image. XCInsight does not receive your Google password.
This processing is optional and is used to create, link or authenticate your XCInsight account under Article 6(1)(b) GDPR. Using e-mail/password authentication remains a separate option. Google authentication does not constitute acceptance of XCInsight Terms or Privacy; those remain an explicit XCInsight step.
Team sharing and recipients
If you join an XCInsight team, other current members of that team become recipients of the flight and profile information made available in the team interface, including flight locations and tracks. This sharing is necessary to provide the team feature you explicitly join and is processed as part of providing the requested service.
Leaving a team or being removed stops future authenticated team access. Information another member previously viewed, exported, screenshotted or otherwise lawfully obtained outside XCInsight cannot always be technically recalled. Team invitations and membership events are logged for security, administration and dispute handling.
EastProd s.r.o.
- Registered office
- Janigova 1326/21, 040 23 Košice - mestská časť Sídlisko KVP, Slovakia
- Company ID
- 54 504 872
- Tax ID
- 2121698579
- VAT
- Not registered for VAT
- Register
- Commercial Register of the Municipal Court Košice, Section Sro, Insert No. 53800/V
- info@webnest.sk
- Phone
- +421 917 947 989
- Service
- https://xcinsight.com