airspace.schendel.at - airspace data for the VarioTracker v2 watch app This server provides airspace data around the position of a watch running VarioTracker v2 (paragliding and hang gliding without aviation radio). It is run privately and non-commercially by the developer, on a best-effort basis without guaranteed availability. The app is free: no ads, no payments. NOT FOR PRIMARY NAVIGATION. Airspace data can be incomplete, outdated or wrong, and temporary restrictions (NOTAM, AIP SUP) may be missing. A pre-flight briefing with official sources is mandatory. The pilot is responsible for every flight. DATA SOURCES AND LICENCES - Airspace: openAIP (www.openaip.net), CC BY-NC 4.0 (https://creativecommons.org/licenses/by-nc/4.0/), modified (filtered, classified for paragliding, simplified). - The airspace windows and the built-in airspace data are derived from openAIP data and are licensed under CC BY-NC 4.0. - open flightmaps (www.openflightmaps.org), OFMA General Users' License. Report OFM data errors: https://www.openflightmaps.org - Terrain: AWS Terrain Tiles (Tilezen), zoom 9: Europe terrain data produced using Copernicus data and information funded by the European Union - EU-DEM layers; Global ETOPO1 terrain data U.S. National Oceanic and Atmospheric Administration United States 3DEP (formerly NED) and global GMTED2010 and SRTM terrain data courtesy of the U.S. Geological Survey. (attribution lines from https://github.com/tilezen/joerd/blob/master/docs/attribution.md) - Country borders: Natural Earth (public domain). In the app: Airspace: openAIP (www.openaip.net), CC BY-NC 4.0, modified (filtered, classified for paragliding, simplified) · open flightmaps (OFMA General Users' License) — report OFM data errors: openflightmaps.org · Terrain: USGS SRTM/GMTED, Copernicus EU-DEM (details: airspace.schendel.at) · Not for primary navigation. SERVICE AREA Full rules: AT, CH, DE, FR, IT (LI with CH). Basic rules (rq=basic): AD, BA, BE, CZ, DK, ES, GB, HR, HU, LU, MC, NL, PL, RS, SI, SK, SM, VA. KNOWN GAPS - CH VLK 5 km aerodrome zones and the IT 5 km aerodrome distance are approximated as caution zones (no usable exact source). - DE nature reserves and CH wildlife rest zones are not in any usable source. - FR regional parks and reserves (Bauges, Vercors, Contamines, ...) and IT regional parks: caution, legality unverified per park. - IT danger areas, IT/FR national parks and AT/SI MTAs: forbidden (*), pending verification (possible false alarms). - SUP/NOTAM areas: openAIP plus open flightmaps additions; very short SUPs can still be missed, so a pre-flight briefing is mandatory. - Live activation (HX, DABS, NOTAM) is not known: all such zones count as active (*). - SI 750 m / 300 m AGL regions are not modelled; SI is served with basic rules. - Openings (AT TRA, VOL LIBRE, gliding sectors) are not modelled: the surrounding airspace alarms; cut-outs inherit their parent. - Countries of the basic ring get the global rules only (rq=basic); the no-radio rule (RMZ, ATZ, FIZ, TIZ, TIA are forbidden) applies everywhere. PRIVACY NOTICE - airspace.schendel.at (airspace service of the VarioTracker v2 watch app) Controller: [not configured] Contact: [not configured] Purpose The service sends airspace data for the area around a watch running VarioTracker v2, so that the app can warn its pilot (paragliding and hang gliding without aviation radio) about airspace. What the watch sends, and when Nothing is sent before the pilot answers Yes to the first-start question of the app ("Send position rounded to ~5 km to airspace.schendel.at for airspace updates?"), or switches the "Online data" setting on in the Garmin Connect app. While Online data is on, the watch sends its position rounded to 0.05 degrees (about 5.5 x 3.8 km) in a request header (X-Pos) or in the body of a POST request, together with the app version and, in further request headers or the POST body, short hashes of the airspace data it already holds. URLs never carry the position or anything derived from it: the parts of a larger download are named by a random one-time token. Legal basis - Position transfer: consent, Art. 6(1)(a) GDPR, given in the first-start question. You can withdraw your consent at any time with the "Online data" setting on the watch or in the Garmin Connect app; the watch then stops all transfers at once. The withdrawal does not affect transfers made before it. - Technical IP logs (see below): Art. 6(1)(f) GDPR, the legitimate interest in operating and securing the service. What the server does with the position The rounded position is used only in memory, to select the airspace data of that area. It is never written to a log or to disk. The server keeps an in-memory cache from the rounded 0.05-degree cell to the prepared data, and from each one-time token to the data it names (without time, IP address or any device identifier); both are lost at every restart. A request makes the server update the airspace data of the countries near that position when they are older than a day; the server keeps, per country, the time of its last update (needed for the daily check), so such a time can show that some request near that country was made then. What is logged where, and for how long - Application log: route, status, duration, the version of the whole airspace data set (the same for every request at a given time) and the app version of each request. It contains no position, no position cell, nothing derived from the position (such as the version or rules level of the data of that area), no IP address and no hash sent by the watch. The data updates that requests trigger are logged only in an hourly summary. It is part of the container log of the cluster and is rotated by size. - Reverse proxy (ingress-nginx): access logs are off. Its error lines (for example rate-limit rejections and upstream errors) contain the client IP address and the requested URL: the route, the app version, the part size and, for the parts of a larger download, the random one-time token; never the position or anything derived from it. They are rotated by size. - Tunnel endpoint (HAProxy on a rented server): a TCP connection log with the client IP address and time in the system journal, retained by size. Requests from the watch pass through the Garmin Connect app on the paired phone, so the IP address seen is normally that of the phone's connection. Requests a watch sends over LTE without the phone may pass through Garmin infrastructure; Garmin's own privacy terms apply to that part. Recipients No data is passed on to third parties. There are no cookies, no tracking and no analytics. Your rights Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), to object to processing based on legitimate interest (Art. 21) and to withdraw consent at any time (Art. 7(3)); write to the contact above. As the server stores no position and no identifier, it usually holds no data it could link to you. You have the right to lodge a complaint with a data-protection supervisory authority (Art. 77 GDPR). CONTACT [not configured]. Support is best effort.