Part 1
SkyRoster Subscription Agreement
Aircraft-based SaaS subscription. Pay by SWIFT USD top-up from abroad to HEINAK YEVHEN.
1. Provider / Виконавець (фізична особа)
HEINAK YEVHEN / Гейнак Євген
Private individual (not a legal entity).
SkyRoster subscriptions are paid by SWIFT USD top-up from abroad to the Receiver’s USD card account.
- Address / Адреса
- 04050, Ukraine, c. Kyiv, st. Hertsena, build 35, fl. 211
- Contact
- Service domains
*.skyroster.net
2. SWIFT payment details (USD from abroad)
- Receiver / Отримувач
- HEINAK YEVHEN
- IBAN
- UA623220010000026202301673360
- SWIFT / BIC
- UNJSUAUKXXX
- Bank
- JSC "UNIVERSAL BANK" / АТ «УНІВЕРСАЛ БАНК»
- Receiver address
- 04050, Ukraine, c. Kyiv, st. Hertsena, build 35, fl. 211
- Currency
- USD (foreign top-up)
- Payment reference
-
Invoice
payment_ref(e.g. SR-FBA-20260801-3) + company IATA
3. Subject of the Agreement
The Provider grants the Customer (airline / operator company identified by its 3-letter tenant code on {iata}.skyroster.net) a non-exclusive, non-transferable right to access and use the SkyRoster software-as-a-service workplace for the subscription term, subject to this Agreement and the Terms of Use, Data & Privacy, and Security parts of this Legal document.
SkyRoster is a multi-tenant Flight Operations workplace (roster, OCC, flight planning aids, planned loadsheet, runway advisory, HR/docs, crew self-service). It is not a certified AFM performance calculator, not an ATC-filed flight plan system of record, and not a substitute for the Customer’s SMS / Ops Manual obligations.
4. Pricing (aircraft-based)
Billing unit = active aircraft in the Customer’s fleet register (fleet_aircraft with is_active = 1), not crew seats or user seats.
- First 2 active aircraft: free (USD 0 / month).
- When the fleet exceeds 2 aircraft: monthly fee = USD 200 (covers the first 2) + USD 100 for each additional aircraft.
| Active aircraft | Monthly (USD) |
|---|---|
| 1–2 | 0 (free tier) |
| 3 | 300 |
| 4 | 400 |
| 5 | 500 |
| n > 2 | 200 + (n − 2) × 100 |
Fees are exclusive of taxes/VAT unless the invoice states tax included. Currency of account is USD; other currencies may be accepted at the Provider’s published rate on the invoice date.
5. Invoicing, payment & activation
- Customer accepts this Agreement in the Billing screen (electronic acceptance with name / role is binding).
- Provider issues a monthly invoice for the current fleet count when the paid tier applies.
- Customer pays by SWIFT / bank transfer using the invoice payment reference within 14 calendar days of issue (unless otherwise stated).
- Upon cleared funds, subscription status becomes active for the invoice period.
- Late payment may move status to past_due; Provider may restrict adding aircraft or suspend paid-tier features after notice.
Free tier (≤ 2 aircraft) does not require payment. Increasing fleet above 2 requires acceptance of this Agreement and payment of the issued invoice.
6. Term, changes & termination
The Agreement renews monthly with each paid period. Either party may terminate with 30 days’ written notice (email via Feedback is sufficient). On termination, Customer may export its tenant data within 30 days; thereafter the Provider may delete the tenant database in line with the Privacy part of this document.
Provider may update pricing with at least 30 days’ notice published on the Billing page and/or by email. Continued use after the effective date constitutes acceptance, except that price increases apply from the next invoice period.
7. Warranties & liability
Service is provided “as available”. Provider will use commercially reasonable efforts for availability and data integrity. Total liability of the Provider under this Agreement in any 12-month period is limited to the fees paid by the Customer in that period. Neither party is liable for indirect, incidental, or consequential damages (including operational delay, ATC fines, or lost revenue), except for wilful misconduct or breaches of confidentiality / data protection duties that cannot be limited by law.
Customer remains solely responsible for operational decisions, regulatory compliance (EASA/FAA/national), crew duty legality, and official flight documentation.
8. Data, security & governing law
Processing of personal and operational data is described in Data & Privacy. Security measures are described in Security. Product use rules are in Terms of Use.
Governing law: Ukraine. Disputes: negotiation first; then courts of Ukraine at the Provider’s address, unless mandatory rules apply.
Language: English controls for product UI and this published text; payment identity is the Receiver name and IBAN above.
Part 2
Terms of Use
Rules for using the SkyRoster Flight Operations workplace.
1. Who may use SkyRoster
Access is granted only to persons authorised by the Customer airline that owns the tenant subdomain. Roles (company_admin, occ, crew) define access levels inside one workplace — not separate products.
Platform administration (admin.skyroster.net) is reserved for the Provider. Customers must not attempt to access other tenants’ data or the platform admin host.
2. Acceptable use
- Use the Service for legitimate airline operational planning and crew management.
- Keep credentials, Passkeys, and WhatsApp OTP codes confidential; do not share admin accounts.
- Do not upload malware, unlawful content, or data you are not entitled to process.
- Do not reverse-engineer, scrape, overload, or probe other tenants.
- Do not present SkyRoster outputs as certified AFM, ATC-filed plans, or official weather/NOTAM briefings without independent verification.
- Respect third-party API terms (weather, maps, travel search) used through the Service.
3. Customer content & fleet accuracy
Customer owns its operational data (crew, duties, flights, documents). Customer warrants that fleet registrations and active aircraft counts used for billing are accurate. Misrepresenting fleet size to avoid fees is a material breach.
4. Advisories & AI assists
Weather decode, NOTAM boards, runway analysis, planned loadsheet, great-circle flight plans, and optional AI assists (departure advisory, ops WhatsApp drafts, EASA cite explanations, feedback triage) are decision-support tools only. The PIC / Operator remains responsible for all flight decisions.
5. Suspension
Provider may suspend access for unpaid invoices (paid tier), security incidents, legal compulsion, or material breach, after reasonable notice where practicable.
6. Related documents
These Terms incorporate the Subscription Agreement, Data & Privacy, and Security parts of this Legal document. Provider: HEINAK YEVHEN (private individual). Contact: Feedback.
Part 3
How we use data
What we process, why, tenancy isolation, retention, and your rights.
1. Controller
For platform account and billing data: HEINAK YEVHEN (Гейнак Євген), private individual. Contact details: Feedback.
For crew / ops data inside a tenant: the airline Customer is typically the controller; the Provider acts as processor under the Subscription Agreement.
2. What we process
- Identity & access: display name, email (optional), WhatsApp number, Passkey credentials, role, theme prefs.
- HR / crew: ranks, bases, leave, layovers, document metadata and uploaded scans (as entered by Customer).
- Ops: roster duties, FSTD sessions, flights, flight plans, loadsheets, runway analyses, NOTAM notes, weather cache keys.
- Logbook: pilot logbook entries derived from duties/flights for export.
- Billing: tenant code, fleet counts, invoices, agreement acceptance records.
- Technical: Host-based tenancy, cookies for theme/session, server logs (IP, User-Agent, timestamps).
3. Purposes & legal bases
- Provide and secure the Service (contract / legitimate interest).
- Bill and collect subscription fees (contract).
- Optional AI assists (departure advisory, WA drafts, EASA cite explain, feedback triage) — only when enabled; prompts may include flight/weather/NOTAM or feedback text; not used to train public models by the Provider beyond the AI vendor’s terms.
- WhatsApp OTP / notifications via Meta WhatsApp Cloud API when configured.
- Legal compliance and dispute handling.
4. Tenancy isolation
Tenant is resolved only from the HTTP Host ({iata}.skyroster.net). Each airline has a separate SQLite database file. Platform reference data (airports, airlines, aircraft types, FTL catalogs) is shared read-only. Customer A cannot read Customer B’s database through the application.
5. Sharing
We do not sell personal data. We share with:
- Infrastructure / hosting providers under contract.
- WhatsApp / Meta (OTP and notifications when used).
- Google Analytics, when enabled on marketing hosts: hashed email/phone the user provided, for measurement matching.
- Optional AI vendor (Gemini) when Customer triggers AI features.
- Public weather/NOTAM sources (ICAO lookups; not personal data).
- Authorities when legally required.
6. Retention
Tenant data is retained while the subscription/tenant is active and for up to 30 days after termination for export, then deleted or anonymised unless longer retention is required by law or unresolved invoices/disputes. Billing records may be kept per Ukrainian accounting rules (typically up to 3+ years).
7. Rights
Depending on applicable law (incl. GDPR where it applies), individuals may request access, correction, deletion, restriction, or portability via the Customer admin or via Feedback. Crew should first contact their airline admin for tenant-held records.
Part 4
Security
Authentication, tenant isolation, and operational security practices.
1. Authentication
- Passkeys (WebAuthn) preferred for staff and crew.
- WhatsApp Cloud API one-time codes as fallback / onboarding.
- Session cookies signed with a server secret; HTTPS via Caddy wildcard TLS on
*.skyroster.net.
2. Isolation & data at rest
- Host-header tenancy; reserved
adminsubdomain never serves airline OCC. - One SQLite WAL database per tenant under
data/tenants/{iata}.db; platform DB separate. - OS-level file permissions and host firewalling; secrets only in environment (never in git).
3. Application controls
- Role-based access within the tenant (admin / OCC / crew self-service
/m). - Upload size limits for crew documents; stored outside public URL space where configured.
- No cross-tenant SQL: connections open only the resolved tenant file.
4. Third parties
Weather (NOAA AWC), optional FAA NOTAM, maps (OpenFreeMap), WhatsApp, and optional Gemini are used over TLS. API keys are server-side only. Weather/NOTAM outages must not block core OCC forms — errors are shown, workflows remain usable.
5. Customer responsibilities
- Assign least-privilege roles; revoke leavers promptly.
- Protect devices used for Passkeys and WhatsApp OTP.
- Classify and minimise personal data uploaded to document storage.
- Report suspected incidents without delay via Feedback.
6. Incident response
Provider investigates security incidents affecting confidentiality or integrity of Customer data and notifies affected Customers without undue delay when required by law or contract. Card PANs are not collected by SkyRoster; fees are paid by SWIFT USD transfer to the published Receiver.