Privacy Policy
1. Who We Are
The data controller is Cesare Paolo De Vecchi, trading as DEVECE AVIATION SERVICES BY CESARE PAOLO DE VECCHI, ul. Farbiarska 65G, 02-862 Warszawa, Poland (NIP 9512447039). For data-related enquiries, contact us at [email protected].
2. Data We Collect
2.1 Cabin Crew Candidates
Registration asks for your name, where you are based, your experience, and whether you hold a Cabin Crew Attestation. No documents are collected at registration. You may upload a CV from your dashboard. It is optional and it is stored until you delete it or delete your account. In total we hold:
- Full name, email address, and a password (hashed) if you set one
- Base or country of residence, the passports you hold, and date of birth (optional)
- Whether you hold a Cabin Crew Attestation, or are aspiring cabin crew
- Employment history, aircraft types, language proficiencies, and anything else you choose to add to your profile
- Availability and relocation preferences, and the airlines you have excluded
- Profile photo (optional)
- Messages you send and receive through the platform, and whether an invitation was accepted or declined
Verification (optional). If you ask to be verified, you show a crew identification document once. It is reviewed by a member of our team and the file is then deleted. We keep only the fact that your profile is verified, and the date. The file is never shown to airlines.
2.2 Airlines
- Authorised representative name and corporate email
- Airline name, IATA/ICAO codes, country of registration
- Recruitment search criteria and browsing activity on candidate profiles
2.3 Technical Data
- IP address, browser type and version, operating system (captured by our infrastructure)
- Log data (access times, pages viewed, error logs)
- Authentication session tokens (stored in browser localStorage, not cookies)
3. How We Use Your Data
- Platform operation, creating and managing your account and your profile
- Search, presenting candidate profiles to airlines that search the database, except to airlines the candidate has excluded
- Messaging, carrying messages between airlines and candidates on the platform
- Verification, looking once at a crew identification document, then deleting it and keeping only the verified flag
- Communications, transactional emails (account confirmation, password reset, and a notice that a message is waiting; message content is never put in an email)
- Legal compliance, responding to regulatory requests, enforcing our Terms & Conditions
- Security, fraud detection, abuse prevention, audit logging
4. Legal Basis for Processing
- Contract performance (Art. 6(1)(b) GDPR), processing necessary to provide the service you signed up for
- Consent (Art. 6(1)(a) GDPR), listing your profile in the database that airlines search, and the optional verification check; you may exclude any airline, withdraw consent, or delete your account at any time from your dashboard
- Legitimate interests (Art. 6(1)(f) GDPR), security, fraud prevention, platform improvement
- Legal obligation (Art. 6(1)(c) GDPR), compliance with applicable law
We do not ask you for special categories of data, such as health information, and you should not put any in your profile or in messages. If you send us such data anyway, for example in an email to support, we process it only to answer you.
5. Data Sharing
We do not sell personal data. We share data only as follows:
- Airlines, profile data is shared with airlines that hold an approved account, and never with an airline the candidate has excluded. Your email address is not shared with them: they message you on the platform
- Infrastructure providers, the hosting, database, file storage and email delivery providers that run the platform on our behalf, under written data processing agreements. A current list of our sub-processors is available on request at [email protected]
- Authorities, if required by court order or applicable law
6. International Transfers
Our primary database is hosted in the European Union, and file storage uses EU-based data centres. Where transfers outside the EEA occur, we rely on the EU Standard Contractual Clauses (SCCs) or an adequacy decision.
7. Retention
- Active accounts, profile data and messages are retained as long as your account is active
- Verification files, deleted as soon as the check is done. They are not archived or backed up for later review
- Deleted accounts, all personal data is deleted within 30 days of account deletion, except data required for legal or regulatory compliance (retained up to 6 years)
- Application logs, retained for 90 days for security purposes
8. Your Rights
Under GDPR, you have the following rights:
- Access (Art. 15), request a copy of your personal data
- Rectification (Art. 16), correct inaccurate data
- Erasure (Art. 17), "right to be forgotten", delete your account and all data via Settings → Privacy & GDPR, or by emailing us
- Restriction (Art. 18), restrict processing in certain circumstances
- Portability (Art. 20), export your data in a machine-readable format
- Objection (Art. 21), object to processing based on legitimate interests
- Withdraw consent, at any time, without affecting prior lawful processing
To exercise your rights, email [email protected]. We respond within 30 days. You also have the right to lodge a complaint with a supervisory authority. If you are based in Poland, the competent authority is the Urząd Ochrony Danych Osobowych (UODO), uodo.gov.pl.
9. Cookies & Tracking
EUCCDB.EU uses no analytics, advertising, or tracking cookies. We do not use Google Analytics, Meta (Facebook) Pixel, or any third-party advertising or behavioural trackers, and we never sell your data.
The only information stored on your device is strictly necessary or functional: your login session, held in your browser's localStorage so you stay signed in, and small functional cookies that may be set only when you use specific features, such as signing in or completing a security check. Under the ePrivacy Directive these are exempt from consent, so no cookie consent banner is required. If we ever add analytics or advertising, we will ask for your consent first.
Fonts and icons: Our typefaces are self-hosted on euccdb.eu. No font files are loaded from Google, so viewing our pages sends no data to any advertising or profiling network. Our icon set is loaded from a public content delivery network, which receives your IP address and browser details in order to serve the file, and which sets no cookie and does not track you.
10. Security
We implement appropriate technical and organisational measures including:
- TLS/HTTPS encryption in transit
- Database-level access rules, so users can only reach their own data
- Time-limited access links for any file shown for verification, which is deleted once reviewed
- Token-based authentication with server-side session validation
- Access controls limiting staff access to personal data
In the event of a personal data breach, we will notify affected users and the relevant supervisory authority within 72 hours as required by Art. 33 GDPR.
11. Children
EUCCDB.EU is a professional platform. We do not knowingly collect data from persons under the age of 16. If you believe we have received data from a minor, please contact us immediately at [email protected].
12. Changes to This Policy
We may update this policy. Material changes will be notified by email or a prominent notice on the platform at least 14 days before they take effect.
13. Contact
For all data protection enquiries:
Email: [email protected]
Website: euccdb.eu