Privacy

Privacy Policy

This privacy policy explains how International Aerial Wildfire Suppression processes personal data on the public website, in the Contact & Request Center, Mission Control, Responder App and Government Portal.

Last updated: July 1, 2026

Controller

International Aerial Wildfire Suppression

Privacy contact

it@iaws-fire.org

Website

https://www.iaws-fire.org

Server-side protection

API keys, mail routing, Supabase secret access and what3words lookups are handled on the server side.

Operational location data

Location processing is tied to authorization, operational purpose, auditability and user-controlled permissions where applicable.

1. Controller

The controller is International Aerial Wildfire Suppression. Privacy and IT security requests can be sent to it@iaws-fire.org.

The serviceable address, legal form and register information will be added after completion of the official organizational registration.

2. Data categories

Depending on use, IAWS processes contact and ticket data, names, organization, country, email address, phone number, message content, attachments, technical logs, device information, account and role data, audit logs, push tokens and operational location, mission, resource and status data.

Protected areas may additionally process roles, permissions, incident assignments, responses, location sharing, uploads, chat metadata and security events.

3. Purposes

Data is used to provide the website, process requests, create tickets, send replies, authenticate users, control roles and access, provide maps and operational pictures, document alerts, support operations, prevent abuse and meet security and accountability requirements.

4. Legal bases

Processing may rely on consent, contractual or pre-contractual measures, legal obligations, vital interests in emergencies and legitimate interests in secure platform operation, IT security, abuse prevention, documentation and operational coordination.

5. Website, logs and security

When the website is accessed, technically required access data such as IP address, time, requested page, browser/device data, referrer and error logs may be processed to deliver the service and protect it against attacks.

The website is prepared for Vercel hosting. Database and authentication functions use Supabase. Email delivery may use IONOS SMTP.

6. Contact & Request Center

The contact form processes required and voluntary fields, category, priority, language, contact method, attachments, CAPTCHA/spam protection data and privacy consent.

Requests are routed server-side to the responsible IAWS department. Tickets, attachments, timeline events, replies and audit logs may be stored in Mission Control.

7. Accounts and RBAC

Protected areas process user accounts, email addresses, roles, simultaneous permissions, organization, region, station, login status, sessions, password onboarding, device activation and audit events.

Access is role-based. Government users, responders and Mission Control users only receive functions assigned to them by roles and permissions.

8. Location, maps, weather and what3words

If users activate location functions, IAWS may process GPS coordinates, accuracy, timestamps and derived coordinate systems such as UTM, MGRS and what3words.

Map, weather, elevation and location data may use OpenStreetMap/Nominatim, Open-Meteo, NASA FIRMS, Copernicus/ArcGIS sources and what3words. The what3words API key is used server-side only and is never delivered to the browser.

9. Push notifications and native app

For push notifications, test alarms, critical alerts and responder feedback, IAWS processes device IDs, push tokens, platform type, app version, delivery status, acknowledgement status, alert priority and technical events.

10. Cookies and local storage

IAWS uses technically required cookies, session information and local storage for login, language, security status, app activation, display options and necessary platform functions.

Non-essential analytics, tracking or marketing technologies are used only with consent where required.

11. Recipients, processors and transfers

Data may be shared with authorized IAWS users, incident command, partner authorities and technical providers such as hosting, database, email, map, weather, translation, security and push notification providers where required.

Some providers may process data outside the EU/EEA. Where required, IAWS uses appropriate safeguards such as EU Standard Contractual Clauses, adequacy decisions or additional safeguards.

12. Retention

Personal data is retained only as long as required for website operation, support, operational documentation, security, audits, legal claims or statutory retention. It is then deleted, anonymized or restricted.

13. Rights

Individuals may request access, correction, deletion, restriction, portability, objection and withdrawal of consent. Requests can be sent to it@iaws-fire.org. Complaints may also be filed with a competent data protection authority.

14. Updates

IAWS may update this policy when functions, providers, legal bases or operational processes change. The current version is available on this page.

International Aerial Wildfire Suppression - Together Above Beyond