Check2Fly logo
Check2FlyEuropean drone flight rules at a glance
Back to map

Information Document

Privacy Policy

This privacy policy describes what data may be processed when using Check2Fly, for what purpose it is used, and what rights are available to the user.

Last updated: July 26, 2026

1. Data controller

The controller of personal data processed in connection with Check2Fly is Grzegorz Kniażuk, a sole trader operating under the business name Grzegorz Kniażuk Software Development, ul. Garbarska 18A/98, 20-340 Lublin, Poland, Polish tax identification number (NIP) 9462761962, REGON 543548683, entered in the Polish Central Register and Information on Economic Activity (CEIDG).

For privacy matters, personal data, or requests to delete data, contact kontakt@kniazuk.dev.

2. Scope of data

The service does not require creating an account or submitting forms with personal data for ordinary use of the content.

The service does not set a minimum age for access to publicly available content. It is not specifically directed at children and does not collect the user’s age.

The service does not provide a contact form, and the controller does not operate a newsletter or email marketing. Correspondence data is processed only when a user voluntarily sends a message to the contact address, in particular with a question, an error report, a complaint, or a request concerning data-protection rights.

In such a case, the data may include the sender’s email address, name or signature, message content and metadata, attachments, and any other information voluntarily provided by the sender. The controller does not require data beyond what is necessary to handle the matter. Third-party data, location, flight or incident details, photographs, or recordings should not be sent unless they are necessary to handle the matter.

A complaint may also be sent by traditional post to the controller’s address. In that case, the data may include a postal return address, name or signature if provided voluntarily, the complaint content, enclosed documents, and postal metadata visible on the envelope. After delivery, only the controller has access to the paper correspondence.

The service does not intentionally collect or require special categories of personal data within the meaning of Article 9 GDPR, medical data, data concerning criminal convictions or offences, or copies or numbers of identity documents. Users should not provide such data in messages or attachments.

However, while using the service, technical data may be processed, in particular:

  • IP address or approximate location data resulting from the network connection,
  • data about the device, operating system, browser, and screen resolution,
  • information about page views, visit duration, clicks, and the way the service is used,
  • the preference regarding consent to or refusal of analytics stored locally in the browser.

The public version of the service currently runs on Vercel. Technical logs generated by this infrastructure may include: date and time; HTTP method; host name, requested path, and query parameters; response status code; IP address and approximate location derived from it; User-Agent; referring page; request, deployment, session, or trace identifiers; processing region; cache and firewall information; route, middleware, or function invocation metadata, including execution time and memory usage; and error messages and technical events.

Not every field is present for every request. The application code does not implement its own request logger or a log export integration and does not intentionally write request bodies, email correspondence, or form data to logs. Technical errors arising while the application is running may be recorded by Vercel.

Displaying the interactive map directly downloads from OpenStreetMap Foundation (OSMF) servers only the tiles needed for the current view. In doing so, the browser sends OSMF connection data, in particular the IP address, browser and device type, operating system, referring page, request date and time, and the addresses of the requested tiles.

3. Purposes and legal bases of processing

Personal data is processed only to the extent necessary for the following purposes and on the legal bases indicated:

  • providing the Check2Fly information service electronically, including functions and settings selected by the user - Article 6(1)(b) GDPR, meaning performance of the contract for the provision of electronic services,
  • ensuring the security, reliability, and technical maintenance of the service, keeping necessary logs, and diagnosing errors - Article 6(1)(f) GDPR; the controller’s legitimate interest is the secure and efficient operation of the service,
  • analyzing traffic and the use of the service with Microsoft Clarity - Article 6(1)(a) GDPR, meaning the user’s consent; Clarity is activated only after consent has been given,
  • remembering and respecting the analytics decision - Article 6(1)(f) GDPR; the controller’s legitimate interest is managing the user’s privacy choice and preventing analytics from being activated contrary to that choice,
  • handling emails and reports concerning the service - Article 6(1)(f) GDPR; the controller’s legitimate interest is responding, verifying reports, and improving the content and operation of the service,
  • handling complaints and correspondence sent by traditional post - Article 6(1)(f) GDPR; the controller’s legitimate interest is reviewing complaints, providing responses, and documenting how the matter was resolved,
  • displaying the OpenStreetMap base layer of the interactive map - Article 6(1)(f) GDPR; the controller’s legitimate interest is providing a clear and useful way to select a country on the map, while requests are limited to tiles needed for the current view and are not used for Check2Fly analytics,
  • establishing, pursuing, or defending legal claims - Article 6(1)(f) GDPR; the controller’s legitimate interest is protecting its rights.

Regardless of the GDPR bases above, storing information in the terminal device and accessing it (cookies and local storage) is governed by Article 361 of the Polish Electronic Communications Law (PKE): functional mechanisms rely on the exemption for what is necessary to provide the service requested by the user, while Microsoft Clarity analytics requires consent. Details are described in section 4.

4. Cookies and local storage

The service uses first-party cookies and local storage to remember the language version, theme, and analytics decision. These mechanisms do not activate Microsoft Clarity.

Storing this information in the browser and accessing it is based on Article 361 of the Polish Electronic Communications Law (PKE). The first-party cookies and local storage used to remember the selected language version, theme, and analytics decision are necessary to provide functionality explicitly chosen by the user and therefore do not require separate consent. Activating Microsoft Clarity analytics cookies, by contrast, requires the end user’s consent within the meaning of Article 361 PKE, applied in accordance with Article 6(1)(a) GDPR.

Microsoft Clarity cookies are analytics mechanisms and may appear only after voluntary consent to analytics. The list reflects the cookies identified in the current Microsoft documentation; the actual set of third-party cookies may be smaller depending on the project settings, the consent signal passed, and browser protections. The stated lifetimes are maximum or typical values and may be shorter.

You can delete browser-stored data in your browser settings. Deleting functional cookies may remove the remembered language or theme, while deleting the clarity-consent entry will cause the analytics question to be displayed again.

Browser storage mechanisms used by Check2Fly and Microsoft Clarity
NameProviderPurposeTypeLifetimeCategory and condition of use
preferred-localeCheck2FlyRemembers the language version of the service.First-party cookie1 yearFunctional - operates without analytics consent.
theme-preferenceCheck2FlyRemembers the light or dark theme selected by the user.First-party cookie1 yearFunctional - set after changing the theme, without analytics consent.
clarity-consentCheck2FlyStores a versioned record of the Clarity decision: the “accepted” or “declined” status, decision date, notice version, and expiry date, so the choice is respected on later visits.localStorageValid for 270 days; the entry is deleted during an open session after expiry or on the next visit, and earlier if the decision or notice version changes or the website data is clearedNecessary to remember the privacy choice - it does not activate analytics itself.
_clckMicrosoft ClarityPersists the pseudonymous Clarity user ID and preferences specific to this website.Clarity first-party cookieUp to 1 yearAnalytics - only after consent.
_clskMicrosoft ClarityConnects several page views by a user into a single Clarity session recording.Clarity first-party cookieUp to 1 dayAnalytics - only after consent.
CLIDMicrosoft ClarityIndicates when Clarity first recognised the browser on a website using Clarity.Third-party cookie (Microsoft domain)Up to 1 yearThird-party Clarity - may be set only after consent; depends on settings and the browser.
ANONCHKMicrosoft ClarityIndicates whether MUID is transferred to the ANID cookie; Clarity does not use ANID, so the value is 0.Third-party cookie (Microsoft domain)Up to 10 minutesThird-party Clarity - may be set only after consent; depends on settings and the browser.
MRMicrosoft ClarityIndicates whether the MUID identifier should be refreshed.Third-party cookie (Microsoft domain)Up to 7 daysThird-party Clarity - may be set only after consent; depends on settings and the browser.
MUIDMicrosoft ClarityIdentifies unique browsers visiting Microsoft websites for advertising, analytics, and operational purposes.Third-party cookie (Microsoft domain)Up to 1 yearThird-party/advertising - the service always sends ad_Storage: denied, so it does not consent to this cookie being set.
SMMicrosoft ClaritySynchronises the MUID identifier across Microsoft domains.Third-party cookie (Microsoft domain)Until the browser session endsThird-party Clarity - may be set only after consent; depends on settings and the browser.

Microsoft Clarity cookie documentation

5. Microsoft Clarity analytics

After consent is given, the service may activate Microsoft Clarity, an analytics tool used to study how the website is used.

Clarity may collect data about user interactions with the website, such as page views, clicks, scrolling, device and browser parameters, and technical session-related data.

The tool is not started unless the user accepts analytics. The decision to consent or refuse is stored locally in the browser and can be changed at any time using the “Privacy settings” button. Withdrawing consent sends a refusal signal to Clarity, ends the current analytics session, and removes Clarity cookies from the browser. The decision record is valid for 270 days; once it expires or the notice version changes, the service asks for a choice again.

If applicable law does not allow a minor to consent to analytics independently, acceptance must be given or authorised by the holder of parental responsibility; otherwise analytics must be declined. Refusing analytics does not restrict access to content or the service’s basic functions.

The record remains solely in the browser and is not sent to the controller. It shows the current status, decision date, and notice version on that device, but it is not a central historical register and cannot demonstrate a particular user’s earlier decision after the website data is deleted.

The service does not contain forms or fields in which users provide personal data. The controller has not configured advertising or user identification for advertising purposes. The service does not call Clarity’s user-identification function and, regardless of analytics consent, always sends the ad_Storage: denied signal.

6. Recipients of data

Data may be disclosed or entrusted, solely to the extent necessary to provide the relevant service, to the following recipients or categories of recipients:

Messages are not forwarded or imported into another mailbox, copied to an external ticketing system, or shared with other persons on the controller’s side; only the controller has access to them. The kontakt@kniazuk.dev mailbox has been added to the Gmail app as a separate IMAP account. The app acts as an email client connecting to the Hostinger server; messages remain in the Hostinger mailbox, although selected copies may be cached temporarily on the controller’s device.

Only the service administrator has administrative access to the Vercel, Hostinger, and Microsoft Clarity accounts and dashboards, as well as to the contact mailbox. No other persons on the controller’s side have such access.

  • Vercel Inc. and its subprocessors - as providers of the hosting platform and content delivery network on which the public version of the application runs; they may process connection data, request and function logs, diagnostic data, and service-generated data. To the extent covered by Vercel’s Data Processing Addendum, Vercel acts as a processor for Customer Data and as an independent controller for Service-Generated Data,
  • Hostinger International Ltd. and its subprocessors - as providers of the kontakt@kniazuk.dev mailbox and domain services; they may process the content and metadata of correspondence,
  • Microsoft Ireland Operations Limited - as the provider of Microsoft Clarity and an independent controller of data relating to the use of that tool; it receives interaction data and technical session data only after consent to analytics has been given,
  • Google Ireland Limited and other Google group entities - as providers of the Gmail app used by the controller solely as an IMAP client for the kontakt@kniazuk.dev mailbox. Google does not provide this mailbox, and correspondence is not automatically imported into a Gmail account. Google may process technical and diagnostic data relating to the app and, depending on settings and enabled features, data necessary to provide selected Gmail features under the Google Privacy Policy,
  • OpenStreetMap Foundation (OSMF) and its infrastructure and CDN providers, including Fastly - as providers of the map base-layer tiles; when the map is opened, they receive technical request data, which OSMF processes as an independent controller,
  • the postal or courier operator selected to send a response to a complaint - it receives only the addressee’s details, postal address, and shipment metadata necessary for delivery,
  • public authorities or other entities authorised by law - only where disclosure is required by applicable law.

Google Privacy Policy

OpenStreetMap Foundation privacy policy

OSMF tile-user privacy FAQ

7. Transfers outside the EEA

Some providers or their subprocessors may process data outside the European Economic Area (EEA). Where a recipient is located in a country covered by a European Commission adequacy decision, the transfer is based on that decision. In other cases, safeguards include in particular the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914 and, where required, supplementary measures.

You can obtain information about the safeguards used or a copy of them, to the extent that it may be made available, by writing to kontakt@kniazuk.dev.

  • Vercel - Vercel Inc. is established in the United States and identifies the United States as its primary processing location, while data may also be processed in other countries by Vercel and its subprocessors. Vercel states that it relies on the EU-U.S. Data Privacy Framework and, where required, standard contractual clauses or other appropriate mechanisms. Transfers covered by Vercel’s Data Processing Addendum are subject to standard contractual clauses,
  • Microsoft Clarity - European Union customers contract with Microsoft Ireland Operations Limited; transfers to Microsoft Corporation in the United States are based on standard contractual clauses,
  • Hostinger - Hostinger International Ltd. is established in Cyprus, and data may be processed in Cyprus, Lithuania, the Netherlands, the United Kingdom and, depending on the subprocessor and service, in other countries. Transfers to the United Kingdom are based on the European Commission adequacy decision, while transfers to countries without such a decision are based on the standard contractual clauses specified in Hostinger’s Data Processing Addendum.
  • Google - technical and diagnostic data from the Gmail app and data required for enabled features may be processed by Google on servers in different countries. Adding the mailbox as a separate IMAP account does not itself automatically transfer the entire mailbox to Gmail servers; source messages remain stored by Hostinger,
  • OpenStreetMap - OSMF is established in the United Kingdom, which is covered by a European Commission adequacy decision. Tiles are nevertheless delivered through a global network of cache servers and external CDNs, so the country handling a particular request is selected dynamically and may be outside the EEA. As an independent controller, OSMF determines the locations, recipients, and safeguards for further processing in accordance with its privacy policy,

8. Data retention period

Data is deleted or anonymised after the periods specified below, unless continued retention is required by law or necessary to establish, pursue, or defend legal claims:

Once a month, the controller reviews correspondence and any incident-related materials. Messages for which 12 months have elapsed since the final response or closure of the matter are deleted from the inbox, sent folder, and trash unless they remain necessary to establish, pursue, or defend legal claims. Deletion from the Hostinger server is synchronised via IMAP with the Gmail app and its local cache.

Retention periods for Vercel logs and Microsoft Clarity data are enforced automatically by the providers. Incident materials are deleted after the incident is closed unless they are required in connection with a legal claim. Claim-related materials are reviewed again after the applicable limitation period expires and are then deleted.

  • Vercel runtime logs accessible to the controller - for a short period resulting from the current Vercel platform configuration and plan, typically up to 1 hour. This period is enforced by Vercel and may change with the service configuration or plan; the application code does not create a separate log archive. Logs isolated in connection with a security incident may be retained until it is resolved and then for the limitation period applicable to related claims,
  • service-generated data processed by Vercel as an independent controller - for the minimum period necessary to meet legal and contractual obligations, develop services, resolve disputes, enforce rights, and pursue other legitimate business purposes described in Vercel’s Privacy Notice; once the need ends, Vercel states that it deletes or anonymises the data,
  • data that enables playback of Microsoft Clarity session recordings - generally 30 days; after that period, Microsoft may retain a randomly selected sample of recordings for up to 9 months,
  • click data, heatmap data, visitor statistics, and sessions labelled or marked as favourites in Microsoft Clarity - up to 9 months; Microsoft also states that backups are deleted after the applicable retention period,
  • emails and related metadata - for up to 12 months after the final response or closure of the matter, unless earlier deletion is appropriate and there is no other basis for retention,
  • data relating to legal claims - only where a claim has arisen or can reasonably be expected, until the applicable limitation period expires; as a rule, this is 3 years for business-related claims or 6 years in other cases, taking account of the calendar-year-end rule where applicable,
  • the decision to consent to or refuse analytics - valid for 270 days from each decision. The localStorage entry contains an expiry date and is deleted after that date during an open session or on the next visit. Earlier deletion occurs if the decision or notice version changes or the website data is cleared; the controller does not maintain a central register of these decisions,
  • technical copies of email data maintained by Hostinger - neither the controller nor the application code creates its own backups containing user data. Hostinger may retain data from a deleted mailbox for recovery and states that it is permanently erased 30 days after the Hostinger Email account is deleted. Hostinger’s public documentation does not specify a separate retention period for copies following deletion of an individual message; such copies remain managed by Hostinger. Backups of Microsoft Clarity data are deleted after the applicable retention period,
  • complaints and other correspondence received on paper - for up to 12 months after the final response or closure of the matter, unless it is needed for longer in connection with a legal claim. After the retention period, documents are destroyed in a manner that prevents their content from being reconstructed,
  • local message copies cached by the Gmail app on the controller’s device - according to synchronisation and cache settings, until the account is removed from the app, the app cache is cleared, or the message is deleted. Source messages remain subject to the Hostinger mailbox retention period, while technical data processed by Google is retained for the periods described in the Google Privacy Policy,
  • access data from OpenStreetMap tile servers - for a temporary period determined by OSMF for network operations, security, and planning; OSMF does not publish one fixed retention period for these logs and states that, because of their temporary nature, access to the associated IP addresses or logs is generally not feasible. Check2Fly neither receives nor stores these logs,

9. Your rights

Depending on the circumstances and the legal basis for processing, you have the following rights:

  • access to your data and obtain a copy of it,
  • rectify inaccurate data or complete incomplete data,
  • erase data where one of the conditions set out in the GDPR applies,
  • restrict processing where one of the conditions set out in the GDPR applies,
  • data portability - where processing is automated and based on consent or a contract,
  • object - on grounds relating to your particular situation - to processing based on the controller’s legitimate interests,
  • withdraw consent at any time,
  • lodge a complaint with the President of the Polish Personal Data Protection Office (President of the UODO) or another competent supervisory authority, in particular in the country of your habitual residence, place of work, or the alleged infringement.

Requests concerning data-subject rights are handled by the service controller at kontakt@kniazuk.dev. If a request comes from an email address associated with the data or earlier correspondence, the controller sends a verification message to that address and asks for a reply from the same address. If the request was sent from another address or reasonable doubts remain, the controller asks only for the minimum information that can be compared with data already held, such as the approximate date and subject of an earlier message, a previously used return address, or a brief description of the matter. The controller does not request a copy or number of an identity document. If identity still cannot be confirmed safely, the controller informs the requester and does not disclose or alter the data until sufficient information has been provided to confirm identity.

We will respond without undue delay and, in principle, within one month of receiving the request. Due to the complexity or number of requests, this period may be extended by a further two months; we will notify you of the extension and the reasons for it within the first month.

Exercising these rights is generally free of charge. Where a request is manifestly unfounded or excessive, we may charge a reasonable fee reflecting administrative costs or refuse to act, in accordance with the GDPR.

You can withdraw your consent to Clarity analytics at any time using the permanently available “Privacy settings” button and choosing to decline analytics. Withdrawal takes effect immediately, ends the current analytics session, and removes Clarity cookies from the browser. It does not affect the lawfulness of processing based on consent before its withdrawal.

If you believe that the processing of your data infringes the GDPR, you may lodge a complaint with the President of the UODO. The Polish Personal Data Protection Office publishes detailed information on how to lodge a complaint:

How to lodge a complaint with the President of the UODO

10. Voluntary provision of data and automated processing

You are under no statutory obligation to provide personal data. However, simply opening the service automatically transmits technical data necessary to handle the connection: the IP address, requested URL, date and time of the request, network communication parameters, and HTTP headers made available by the browser, such as information about the browser type and device. Without processing basic connection data, the service cannot be delivered to your device or made to function securely and correctly.

Analytics data, such as page views, visit duration, clicks, scrolling, navigation through the service, screen resolution, and session information, is not necessary to use the basic functions. Microsoft Clarity processes it only after you have given voluntary consent. Refusing analytics does not restrict access to the content or basic functions of the service.

Sending an email and providing data in it is voluntary and is not a statutory or contractual requirement. To receive a reply or enable a report to be reviewed, however, you must provide at least a reply address and enough content to understand the matter. Without this information, the controller may be unable to respond, verify the report, or take the requested action.

The controller does not make decisions about users based solely on automated processing that produce legal effects or similarly significantly affect them.

Sending a complaint by traditional post and providing data in the letter is voluntary. An email or postal address for the response, a description of the problem, and the approximate date and circumstances of the event are sufficient to review the complaint. No other data is required unless additional information proves strictly necessary to review the particular matter.

Clarity automatically reconstructs sessions, creates heatmaps, and analyses how the service is used. Due to the broad definition of profiling in the GDPR, this processing may constitute profiling to the extent that it analyses user behaviour. The results are used solely to analyse usability and improve the service; the controller does not use them for scoring, individual decision-making, personalising offers, or producing legal or similarly significant effects for the user.

11. Language versions and changes to the privacy policy

The Polish version of this privacy policy is the source version. The other language versions were prepared using machine translation and are provided for users’ convenience.

In the event of discrepancies, the Polish version serves as the point of reference, without limiting any rights available to the data subject under the GDPR or other mandatory law. If you have any doubts about the wording of a translation, contact the controller at kontakt@kniazuk.dev.

The content of this privacy policy may be updated, especially when the way the service operates, the scope of the tools used, or legal requirements change.

The current version is always published on this page together with the date of the latest update.