SkyRoster

SkyRoster · v2026-08-08

Legal

Subscription, terms of use, data & privacy, and security — one document.

Subscription agreement Terms of use Data & privacy Security

Part 1

SkyRoster Subscription Agreement

Aircraft-based SaaS subscription. Pay by SWIFT USD top-up from abroad to HEINAK YEVHEN.

1. Provider / Виконавець (фізична особа)

HEINAK YEVHEN / Гейнак Євген

Private individual (not a legal entity).

SkyRoster subscriptions are paid by SWIFT USD top-up from abroad to the Receiver’s USD card account.

Address / Адреса
04050, Ukraine, c. Kyiv, st. Hertsena, build 35, fl. 211
Contact
  • ceo@skyroster.net
  • +1 (646) 260-4904
Service domains
*.skyroster.net

2. SWIFT payment details (USD from abroad)

Receiver / Отримувач
HEINAK YEVHEN
IBAN
UA623220010000026202301673360
SWIFT / BIC
UNJSUAUKXXX
Bank
JSC "UNIVERSAL BANK" / АТ «УНІВЕРСАЛ БАНК»
Receiver address
04050, Ukraine, c. Kyiv, st. Hertsena, build 35, fl. 211
Currency
USD (foreign top-up)
Payment reference
Invoice payment_ref (e.g. SR-FBA-20260801-3) + company IATA

3. Subject of the Agreement

The Provider grants the Customer (airline / operator company identified by its 3-letter tenant code on {iata}.skyroster.net) a non-exclusive, non-transferable right to access and use the SkyRoster software-as-a-service workplace for the subscription term, subject to this Agreement and the Terms of Use, Data & Privacy, and Security parts of this Legal document.

SkyRoster is a multi-tenant Flight Operations workplace (roster, OCC, flight planning aids, planned loadsheet, runway advisory, HR/docs, crew self-service). It is not a certified AFM performance calculator, not an ATC-filed flight plan system of record, and not a substitute for the Customer’s SMS / Ops Manual obligations.

4. Pricing (aircraft-based)

Billing unit = active aircraft in the Customer’s fleet register (fleet_aircraft with is_active = 1), not crew seats or user seats.

  • First 2 active aircraft: free (USD 0 / month).
  • When the fleet exceeds 2 aircraft: monthly fee = USD 200 (covers the first 2) + USD 100 for each additional aircraft.
Active aircraftMonthly (USD)
1–20 (free tier)
3300
4400
5500
n > 2200 + (n − 2) × 100

Fees are exclusive of taxes/VAT unless the invoice states tax included. Currency of account is USD; other currencies may be accepted at the Provider’s published rate on the invoice date.

5. Invoicing, payment & activation

  1. Customer accepts this Agreement in the Billing screen (electronic acceptance with name / role is binding).
  2. Provider issues a monthly invoice for the current fleet count when the paid tier applies.
  3. Customer pays by SWIFT / bank transfer using the invoice payment reference within 14 calendar days of issue (unless otherwise stated).
  4. Upon cleared funds, subscription status becomes active for the invoice period.
  5. Late payment may move status to past_due; Provider may restrict adding aircraft or suspend paid-tier features after notice.

Free tier (≤ 2 aircraft) does not require payment. Increasing fleet above 2 requires acceptance of this Agreement and payment of the issued invoice.

6. Term, changes & termination

The Agreement renews monthly with each paid period. Either party may terminate with 30 days’ written notice (email via Feedback is sufficient). On termination, Customer may export its tenant data within 30 days; thereafter the Provider may delete the tenant database in line with the Privacy part of this document.

Provider may update pricing with at least 30 days’ notice published on the Billing page and/or by email. Continued use after the effective date constitutes acceptance, except that price increases apply from the next invoice period.

7. Warranties & liability

Service is provided “as available”. Provider will use commercially reasonable efforts for availability and data integrity. Total liability of the Provider under this Agreement in any 12-month period is limited to the fees paid by the Customer in that period. Neither party is liable for indirect, incidental, or consequential damages (including operational delay, ATC fines, or lost revenue), except for wilful misconduct or breaches of confidentiality / data protection duties that cannot be limited by law.

Customer remains solely responsible for operational decisions, regulatory compliance (EASA/FAA/national), crew duty legality, and official flight documentation.

8. Data, security & governing law

Processing of personal and operational data is described in Data & Privacy. Security measures are described in Security. Product use rules are in Terms of Use.

Governing law: Ukraine. Disputes: negotiation first; then courts of Ukraine at the Provider’s address, unless mandatory rules apply.

Language: English controls for product UI and this published text; payment identity is the Receiver name and IBAN above.

Part 2

Terms of Use

Rules for using the SkyRoster Flight Operations workplace.

1. Who may use SkyRoster

Access is granted only to persons authorised by the Customer airline that owns the tenant subdomain. Roles (company_admin, occ, crew) define access levels inside one workplace — not separate products.

Platform administration (admin.skyroster.net) is reserved for the Provider. Customers must not attempt to access other tenants’ data or the platform admin host.

2. Acceptable use

  • Use the Service for legitimate airline operational planning and crew management.
  • Keep credentials, Passkeys, and WhatsApp OTP codes confidential; do not share admin accounts.
  • Do not upload malware, unlawful content, or data you are not entitled to process.
  • Do not reverse-engineer, scrape, overload, or probe other tenants.
  • Do not present SkyRoster outputs as certified AFM, ATC-filed plans, or official weather/NOTAM briefings without independent verification.
  • Respect third-party API terms (weather, maps, travel search) used through the Service.

3. Customer content & fleet accuracy

Customer owns its operational data (crew, duties, flights, documents). Customer warrants that fleet registrations and active aircraft counts used for billing are accurate. Misrepresenting fleet size to avoid fees is a material breach.

4. Advisories & AI assists

Weather decode, NOTAM boards, runway analysis, planned loadsheet, great-circle flight plans, and optional AI assists (departure advisory, ops WhatsApp drafts, EASA cite explanations, feedback triage) are decision-support tools only. The PIC / Operator remains responsible for all flight decisions.

5. Suspension

Provider may suspend access for unpaid invoices (paid tier), security incidents, legal compulsion, or material breach, after reasonable notice where practicable.

6. Related documents

These Terms incorporate the Subscription Agreement, Data & Privacy, and Security parts of this Legal document. Provider: HEINAK YEVHEN (private individual). Contact: Feedback.

Part 3

How we use data

What we process, why, tenancy isolation, retention, and your rights.

1. Controller

For platform account and billing data: HEINAK YEVHEN (Гейнак Євген), private individual. Contact details: Feedback.

For crew / ops data inside a tenant: the airline Customer is typically the controller; the Provider acts as processor under the Subscription Agreement.

2. What we process

  • Identity & access: display name, email (optional), WhatsApp number, Passkey credentials, role, theme prefs.
  • HR / crew: ranks, bases, leave, layovers, document metadata and uploaded scans (as entered by Customer).
  • Ops: roster duties, FSTD sessions, flights, flight plans, loadsheets, runway analyses, NOTAM notes, weather cache keys.
  • Logbook: pilot logbook entries derived from duties/flights for export.
  • Billing: tenant code, fleet counts, invoices, agreement acceptance records.
  • Technical: Host-based tenancy, cookies for theme/session, server logs (IP, User-Agent, timestamps).

3. Purposes & legal bases

  • Provide and secure the Service (contract / legitimate interest).
  • Bill and collect subscription fees (contract).
  • Optional AI assists (departure advisory, WA drafts, EASA cite explain, feedback triage) — only when enabled; prompts may include flight/weather/NOTAM or feedback text; not used to train public models by the Provider beyond the AI vendor’s terms.
  • WhatsApp OTP / notifications via Meta WhatsApp Cloud API when configured.
  • Legal compliance and dispute handling.

4. Tenancy isolation

Tenant is resolved only from the HTTP Host ({iata}.skyroster.net). Each airline has a separate SQLite database file. Platform reference data (airports, airlines, aircraft types, FTL catalogs) is shared read-only. Customer A cannot read Customer B’s database through the application.

5. Sharing

We do not sell personal data. We share with:

  • Infrastructure / hosting providers under contract.
  • WhatsApp / Meta (OTP and notifications when used).
  • Google Analytics, when enabled on marketing hosts: hashed email/phone the user provided, for measurement matching.
  • Optional AI vendor (Gemini) when Customer triggers AI features.
  • Public weather/NOTAM sources (ICAO lookups; not personal data).
  • Authorities when legally required.

6. Retention

Tenant data is retained while the subscription/tenant is active and for up to 30 days after termination for export, then deleted or anonymised unless longer retention is required by law or unresolved invoices/disputes. Billing records may be kept per Ukrainian accounting rules (typically up to 3+ years).

7. Rights

Depending on applicable law (incl. GDPR where it applies), individuals may request access, correction, deletion, restriction, or portability via the Customer admin or via Feedback. Crew should first contact their airline admin for tenant-held records.

Part 4

Security

Authentication, tenant isolation, and operational security practices.

1. Authentication

  • Passkeys (WebAuthn) preferred for staff and crew.
  • WhatsApp Cloud API one-time codes as fallback / onboarding.
  • Session cookies signed with a server secret; HTTPS via Caddy wildcard TLS on *.skyroster.net.

2. Isolation & data at rest

  • Host-header tenancy; reserved admin subdomain never serves airline OCC.
  • One SQLite WAL database per tenant under data/tenants/{iata}.db; platform DB separate.
  • OS-level file permissions and host firewalling; secrets only in environment (never in git).

3. Application controls

  • Role-based access within the tenant (admin / OCC / crew self-service /m).
  • Upload size limits for crew documents; stored outside public URL space where configured.
  • No cross-tenant SQL: connections open only the resolved tenant file.

4. Third parties

Weather (NOAA AWC), optional FAA NOTAM, maps (OpenFreeMap), WhatsApp, and optional Gemini are used over TLS. API keys are server-side only. Weather/NOTAM outages must not block core OCC forms — errors are shown, workflows remain usable.

5. Customer responsibilities

  • Assign least-privilege roles; revoke leavers promptly.
  • Protect devices used for Passkeys and WhatsApp OTP.
  • Classify and minimise personal data uploaded to document storage.
  • Report suspected incidents without delay via Feedback.

6. Incident response

Provider investigates security incidents affecting confidentiality or integrity of Customer data and notifies affected Customers without undue delay when required by law or contract. Card PANs are not collected by SkyRoster; fees are paid by SWIFT USD transfer to the published Receiver.

Document version 2026-08-08. Electronic acceptance in SkyRoster Billing has the same effect as a signed counterpart.

About Not a job board Feedback Legal Trip demo Crew supply Crew jobs
v0.3.0 · 2026 SkyRoster