Privacy
Privacy Policy
This privacy policy explains how International Aerial Wildfire Suppression processes personal data on the public website, in the Contact & Request Center, Mission Control, Responder App and Government Portal.
Last updated: July 1, 2026
Controller
International Aerial Wildfire Suppression
Privacy contact
it@iaws-fire.org
Website
https://www.iaws-fire.org
Server-side protection
API keys, mail routing, Supabase secret access and what3words lookups are handled on the server side.
Operational location data
Location processing is tied to authorization, operational purpose, auditability and user-controlled permissions where applicable.
1. Controller
The controller is International Aerial Wildfire Suppression. Privacy and IT security requests can be sent to it@iaws-fire.org.
The serviceable address, legal form and register information will be added after completion of the official organizational registration.
2. Data categories
Depending on use, IAWS processes contact and ticket data, names, organization, country, email address, phone number, message content, attachments, technical logs, device information, account and role data, audit logs, push tokens and operational location, mission, resource and status data.
Protected areas may additionally process roles, permissions, incident assignments, responses, location sharing, uploads, chat metadata and security events.
3. Purposes
Data is used to provide the website, process requests, create tickets, send replies, authenticate users, control roles and access, provide maps and operational pictures, document alerts, support operations, prevent abuse and meet security and accountability requirements.
4. Legal bases
Processing may rely on consent, contractual or pre-contractual measures, legal obligations, vital interests in emergencies and legitimate interests in secure platform operation, IT security, abuse prevention, documentation and operational coordination.
5. Website, logs and security
When the website is accessed, technically required access data such as IP address, time, requested page, browser/device data, referrer and error logs may be processed to deliver the service and protect it against attacks.
The website is prepared for Vercel hosting. Database and authentication functions use Supabase. Email delivery may use IONOS SMTP.
6. Contact & Request Center
The contact form processes required and voluntary fields, category, priority, language, contact method, attachments, CAPTCHA/spam protection data and privacy consent.
Requests are routed server-side to the responsible IAWS department. Tickets, attachments, timeline events, replies and audit logs may be stored in Mission Control.
7. Accounts and RBAC
Protected areas process user accounts, email addresses, roles, simultaneous permissions, organization, region, station, login status, sessions, password onboarding, device activation and audit events.
Access is role-based. Government users, responders and Mission Control users only receive functions assigned to them by roles and permissions.
8. Location, maps, weather and what3words
If users activate location functions, IAWS may process GPS coordinates, accuracy, timestamps and derived coordinate systems such as UTM, MGRS and what3words.
Map, weather, elevation and location data may use OpenStreetMap/Nominatim, Open-Meteo, NASA FIRMS, Copernicus/ArcGIS sources and what3words. The what3words API key is used server-side only and is never delivered to the browser.
9. Push notifications and native app
For push notifications, test alarms, critical alerts and responder feedback, IAWS processes device IDs, push tokens, platform type, app version, delivery status, acknowledgement status, alert priority and technical events.
10. Cookies and local storage
IAWS uses technically required cookies, session information and local storage for login, language, security status, app activation, display options and necessary platform functions.
Non-essential analytics, tracking or marketing technologies are used only with consent where required.
11. Recipients, processors and transfers
Data may be shared with authorized IAWS users, incident command, partner authorities and technical providers such as hosting, database, email, map, weather, translation, security and push notification providers where required.
Some providers may process data outside the EU/EEA. Where required, IAWS uses appropriate safeguards such as EU Standard Contractual Clauses, adequacy decisions or additional safeguards.
12. Retention
Personal data is retained only as long as required for website operation, support, operational documentation, security, audits, legal claims or statutory retention. It is then deleted, anonymized or restricted.
13. Rights
Individuals may request access, correction, deletion, restriction, portability, objection and withdrawal of consent. Requests can be sent to it@iaws-fire.org. Complaints may also be filed with a competent data protection authority.
14. Updates
IAWS may update this policy when functions, providers, legal bases or operational processes change. The current version is available on this page.
International Aerial Wildfire Suppression - Together Above Beyond