中国南方航空标志

PRIVACY & COOKIE NOTICE

隐私政策与 Cookie 说明

生效日期2026 年 9 月 13 日
语言版本中文 / English

PRIVACY & COOKIE NOTICE

Privacy Policy & Cookie Notice

Effective date13 September 2026
Available languages中文 / English
01

我们处理哪些数据

  • 必要 Cookie 偏好:用于记住你已阅读 Cookie 提示的状态;该 Cookie 不包含姓名、邮箱或账号资料。
  • 技术与安全日志:若网站服务器启用访问或错误日志,可能包含 IP 地址、浏览器与设备信息、请求时间、访问路径、响应状态和基本安全事件信息。
  • 你主动提交的隐私请求:当你经 AOC 运控中心联系我们时,可能处理你主动提供的姓名、联系方式、请求内容及为核实身份所必需的最少信息。

我们不会主动收集敏感个人数据、精确位置、支付信息、营销画像或站内行为分析数据。

02

处理目的与法律依据

处理活动目的GDPR 法律依据
必要 Cookie 偏好记住 Cookie 提示状态,使页面按你的已知设置运行。GDPR 第 6(1)(f) 条:维护网站基本功能与减少重复提示的合法利益;在适用 ePrivacy 规则下作为技术必要 Cookie 使用。
安全与运维日志防止滥用、排查故障、维护网络与信息安全。GDPR 第 6(1)(f) 条:保护网站、服务与用户的合法利益。
隐私权利请求答复、核实和记录你行使数据保护权利的请求。GDPR 第 6(1)(c) 条:履行适用的数据保护义务;必要时亦基于第 6(1)(f) 条维护与解决请求。

若未来新增非必要 Cookie、分析工具、表单、账号或营销功能,我们会在启用前更新本政策,并在需要时取得可自由撤回、具体、知情且明确的同意。

03

Cookie 说明与设置

目前本网站仅使用下列第一方必要 Cookie;没有广告、分析、社交媒体或跨站追踪 Cookie。

重置 Cookie 偏好

你可随时删除此 Cookie;下次返回首页时将再次显示 Cookie 提示。

04

接收方、外部链接与国际传输

为托管本网站所必需的基础设施提供方可能代表控制者处理有限的技术数据。控制者应仅选用能够提供适当技术与组织措施的处理者,并在适用时签订 GDPR 第 28 条所要求的处理协议。

本站不会自动向 VATSIM、AOC 运控中心或其他第三方发送你的个人数据。你主动点击外部链接时,浏览器将直接连接至目标网站;目标网站的处理活动、Cookie 与跨境传输由其自身政策负责。本网站对外链采用 no-referrer 设置,减少向目标网站传送来源页信息。

如未来需要向欧洲经济区、英国或瑞士以外传输个人数据,控制者将依适用法律采取充分性决定、标准合同条款或其他适当保障措施,并在本政策中说明相关信息与获取副本的方式。

05

保存期限

  • Cookie 偏好:最多保存 365 天,或直至你在浏览器或本页面删除它。
  • 技术与安全日志:原则上不超过 30 天;如发生安全事件、需要防范滥用或适用法律要求,可能在必要且相称的范围内延长保存。
  • 隐私请求记录:保存至请求处理完毕后最多 3 年,用于证明合规、答复后续问题或处理法律主张;法律要求更长保存的除外。

控制者应在部署环境中实际配置上述日志轮转与删除期限;若该配置或网站功能发生变化,本政策会相应更新。

06

你的数据保护权利

在 GDPR 适用时,你有权请求访问、更正、删除、限制处理、数据可携带,以及在基于合法利益处理时提出反对。若任何未来处理依赖同意,你可随时撤回同意,且撤回不会影响撤回前处理的合法性。

请使用第 1 节的隐私请求渠道,并说明你的请求。为保护数据安全,我们可能在答复前要求最少且相称的信息核实身份。我们会在 GDPR 规定的期限内答复,通常为一个月;如需延期,将向你说明原因。

你也有权向你常住地、工作地或认为发生侵权地所在的主管数据保护机构提出投诉。

07

安全、儿童与自动化决策

控制者应采取与风险相称的技术与组织措施,例如 HTTPS 传输加密、访问控制、最小权限和及时更新服务器。请注意,互联网传输无法保证绝对安全。

本网站不面向儿童提供账号或主动收集儿童个人数据;如发现未经适当授权提交的儿童个人数据,将在适用法律允许或要求的范围内予以删除。

本网站不进行仅基于自动化处理、且对你产生法律或类似重大影响的决定,也不进行个人画像分析。

01

Personal data we process

  • Necessary cookie preference: the status showing that you have seen the Cookie notice. The cookie does not contain a name, email address, or account data.
  • Technical and security logs: if the Website server has access or error logging enabled, this may include IP address, browser and device information, request time, requested path, response status, and basic security-event information.
  • Privacy requests you submit: when you contact us through the AOC Operations Centre, we may process the name, contact details, request content, and minimum information needed to verify identity that you choose to provide.

We do not intentionally collect special-category data, precise location, payment information, marketing profiles, or on-site behavioural analytics data.

02

Purposes and legal bases

ActivityPurposeGDPR legal basis
Necessary cookie preferenceRemember the Cookie-notice status and run the Website according to a known setting.Article 6(1)(f): legitimate interests in essential website operation and avoiding repeat notices; used as a technically necessary cookie under applicable ePrivacy rules.
Security and operational loggingPrevent abuse, investigate faults, and maintain network and information security.Article 6(1)(f): legitimate interests in protecting the Website, service, and users.
Data-protection requestsRespond to, verify, and record requests to exercise data-protection rights.Article 6(1)(c): compliance with applicable data-protection obligations; where necessary, Article 6(1)(f) to manage and resolve requests.

If we add non-essential cookies, analytics, forms, accounts, or marketing features in the future, we will update this notice before enabling them and obtain freely given, specific, informed, and unambiguous consent where required.

03

Cookies and controls

At present, the Website uses only the following first-party necessary cookie. It has no advertising, analytics, social-media, or cross-site tracking cookies.

Reset your Cookie preference

You can delete this cookie at any time. The Cookie notice will appear again when you next return to the homepage.

04

Recipients, external links, and international transfers

Infrastructure providers needed to host this Website may process limited technical data on behalf of the controller. The controller should use processors that provide appropriate technical and organisational measures and, where applicable, enter into the processing agreements required by GDPR Article 28.

The Website does not automatically send your personal data to VATSIM, the AOC Operations Centre, or another third party. When you choose an external link, your browser connects directly to the destination website; its processing, cookies, and international transfers are governed by its own notice. The Website uses a no-referrer setting for external links to minimise referral-page information sent to the destination.

If personal data must later be transferred outside the EEA, UK, or Switzerland, the controller will use an adequacy decision, Standard Contractual Clauses, or another appropriate safeguard where required, and will explain the transfer and how to obtain a copy of the safeguards here.

05

Retention

  • Cookie preference: up to 365 days, or until you delete it in your browser or through this page.
  • Technical and security logs: normally no longer than 30 days; this may be extended only where necessary and proportionate for a security incident, abuse prevention, or a legal obligation.
  • Privacy-request records: up to 3 years after a request is closed, to demonstrate compliance, answer follow-up questions, or deal with legal claims, unless a longer period is required by law.

The controller should configure these log-rotation and deletion periods in the deployment environment. This notice will be updated if that configuration or the Website’s functionality changes.

06

Your data-protection rights

Where the GDPR applies, you may request access, rectification, erasure, restriction, and portability, and object to processing based on legitimate interests. If future processing relies on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

Please use the privacy-request channel in section 1 and describe your request. To keep data secure, we may ask for the minimum proportionate information to verify identity before responding. We will respond within the GDPR time limit, normally one month, and explain any extension.

You also have the right to lodge a complaint with the data-protection supervisory authority in your habitual residence, place of work, or place of the alleged infringement.

07

Security, children, and automated decisions

The controller should apply measures proportionate to risk, such as HTTPS transport encryption, access controls, least-privilege access, and timely server updates. No internet transmission can be guaranteed completely secure.

The Website does not offer accounts to children or intentionally collect children’s personal data. If we learn that children’s data has been submitted without appropriate authorisation, we will delete it where permitted or required by applicable law.

The Website does not make decisions based solely on automated processing that produce legal or similarly significant effects, and it does not carry out profiling.

08

Updates and deployment checks

We may update this notice when Website functionality, hosting arrangements, or legal requirements change. Material changes will be published on this page with a revised effective date.

Pre-publication checks for the Website operator

  • Confirm that the controller identity and privacy-request channel in section 1 remain valid. Add the legal name, registered address, DPO, or EU representative before publication where applicable.
  • Use HTTPS in production and actually configure server-log retention so it does not exceed the period stated in this notice.
  • Before adding analytics, advertising, embedded third-party content, registration forms, or accounts, reassess data flows, legal bases, processors, and the Cookie-consent mechanism.