Privacy policy
Last updated:
What Wind HQ collects, why, how long it keeps it, and who it goes to. There are no trackers and no advertising, on this site or in the product.
Who we are
Wind HQ is a lesson-scheduling platform for kite schools, available at windhq.app and its subdomains. It is operated by Sergei Fedorov Računarsko Programiranje pr cpp Beograd, a sole trader registered in Belgrade, Serbia, trading as Wind HQ. That entity is the data controller described below.
For anything in this policy — a question, a request about your own data, or a complaint — write to hello@windhq.app. A person reads it.
Two different relationships are described below, and which one applies to you changes your rights.
- For this website and for your own platform account, we are the controller of your data.
- For the lesson data a school records about its students, the school is the controller and we are its processor: we hold and process that data on the school’s instructions, under a contract with the school. If you are a student and want data corrected or deleted, your school can act on it directly; we will help either of you.
This website sets no cookies and runs no trackers
The pages you are reading now are static files. They set no cookies, load nothing from a third party, and run no JavaScript at all — there is no analytics, no advertising network, no session replay, no tag manager, and no consent banner, because there is nothing to consent to. Our web server keeps ordinary request logs (IP address, time, path, user agent) for 30 days, for security and debugging.
Inside the product, one essential cookie holds your login session. It is set by us, marked HttpOnly and Secure, cannot be read by JavaScript, and exists only to keep you signed in. It carries no tracking identifier.
What we collect, and why
If you have an account
- Identity and contact: your name, email address, and — if you give one — a phone number and a messaging handle (WhatsApp or Telegram). We need these to sign you in and to reach you when a lesson changes.
- Language preference, so that we write to you in your own language.
- Your relationships to schools: which schools you belong to, in what capacity, and since when.
- Authentication data held by our identity provider. If you sign in with Google or Apple, we receive your name and email address from them and nothing else. We never see or store your password.
If you take lessons at a school using the platform
- Lesson records: scheduled and completed lessons, the instructor, the spot, and the conditions the lesson was planned under.
- Equipment allocations and, to compute them, your body weight and riding level. Weight is used for exactly one purpose — matching a kite size to the wind — and is visible to your school’s staff, never to other students.
- Progression against the certification levels your school teaches to.
- Messages we sent you about lessons, and whether each was delivered and whether you answered it. This is what stops the system asking you the same question four times, and what lets a school show that it did tell you. We do not track whether you opened an email: doing that means a tracking pixel, and there is no pixel in anything we send you.
- Automated voice calls, at the last step of a confirmation chase: that the call was placed, whether it connected, and which key you pressed to answer. The call is not recorded and no audio is kept — the keypress is the whole of what comes back.
- Payments, where your school takes them through the platform: the amount, currency, date and status. Card details are handled by the payment provider and never reach us. For this data your school is the controller and we are its processor — except for our own accounting records of what your school pays us, where we are the controller and tax law sets the retention.
What we deliberately do not collect
- No location tracking. We record which spot a lesson is at, not where you are.
- No advertising or behavioural profiles, and no data sold or shared for them.
- No health records, and nowhere to put them. Weight and riding level are collected to match a kite size to the wind. Beyond that, the platform has no free-text field about a rider at all — no notes box, no comments, no “anything else we should know”. That is a deliberate design decision rather than an omission: a notes box is where a condition, a medication or an injury ends up, and once it is there it is special-category data being held by us with no safeguard around it. So there is no box. Schools are contractually obliged not to record health information in the platform, and there is no field in which they could.
Why we are allowed to hold it
- To perform our contract with you — running your account and delivering the service.
- Our legitimate interests — keeping the service secure, preventing abuse, and keeping an accurate record of scheduling decisions so that a disagreement between a school and a student can be settled by fact.
- Legal obligation — financial records we are required to keep.
- Your consent, where you choose to link a messaging account. You can unlink it at any time and we will use another channel.
We send no marketing email. If that ever changes it will be a separate, opt-in choice, and this paragraph will say so before the first message goes out.
Who else processes it
We use a small number of service providers, each for a stated purpose and under a contract that forbids them using your data for their own.
- Fly.io — application hosting and the public edge.
- Supabase — the databases and file storage.
- Auth0 (Okta) — authentication, including social sign-in where you choose it.
- Mailgun (Sinch) — transactional email — invitations, confirmations, receipts.
- Meta (WhatsApp Business) — lesson messages, where your school has connected WhatsApp.
- Telegram — lesson messages, where you have linked a Telegram account.
- Twilio — automated voice calls at the last step of a confirmation chase.
Where it is stored
Wind HQ runs in more than one part of the world, and where your data lives follows from the law that applies to it rather than from what is convenient for us. Account and lesson data is placed in a region that satisfies the rules governing you and your school, and the region a school’s data belongs to is recorded against that school and does not drift.
We deliberately do not publish a list of data-centre locations. The list changes as the platform is deployed into new regions; the rule above does not, and it is the rule that determines what happens to your data. If you want to know where yours is held, ask us and we will tell you.
The people who operate the service are in Serbia, so running it means reaching that data from there. Serbian data-protection law is aligned with the GDPR and Serbia is a party to the Council of Europe’s Convention 108+; where a transfer needs standard contractual clauses, we use them.
Messaging and voice providers operate internationally, so a message you asked us to send you may be transmitted outside your country. That transfer happens because you chose that channel, and you can change or unlink it at any time.
We do not sell data to anyone, and we do not disclose it to public authorities except where a valid legal order requires it.
How long we keep it
- Your account for as long as it exists. Delete it and we remove your profile within 30 days.
- Lesson and equipment history for as long as the school keeps its account, because it is the school’s record of its own business. When the school leaves, its data is deleted within 90 days.
- Financial records for as long as tax law requires.
- Server logs for 30 days.
Some of our records are append-only by design: a schedule change, once made, is not edited away, because both sides rely on the history being honest. Deleting your account removes the identifiers from those records rather than rewriting them.
We would rather name that precisely than let it sound like more than it is. What remains is pseudonymised, not anonymous: it is stripped of the fields that identify you, but we are not claiming it could never be re-linked, and while that is true it stays personal data. We keep it under GDPR Art. 17(3)(e) and its equivalents — the establishment, exercise or defence of legal claims, which in practice means a dispute between a school and a rider about what was agreed on a given day — and, for financial entries, under the legal obligation to keep books. If you want the record itself gone rather than de-identified, ask, and we will tell you honestly which parts we can remove and which we are required to keep.
Your rights
Wherever you are, you can ask us to show you the data we hold about you, correct it, delete it, hand it to you in a portable form, or stop a particular use of it. You may also object to processing we base on legitimate interests, and withdraw a consent you gave without that affecting anything done before you withdrew it.
Several regimes apply to this service at once — where we are established, where our users are, and where the data is held — so rather than name the one nearest to us, here is the authority for each:
- Serbia — the Personal Data Protection Act (ZZPL): the Commissioner for Information of Public Importance and Personal Data Protection.
- Brazil — the LGPD: the ANPD.
- Egypt — the Personal Data Protection Law (Law No. 151 of 2020): the Personal Data Protection Centre (PDPC).
- European Union — the GDPR: your national data protection authority.
That list is not a limit. If you are somewhere else, your own country’s data protection authority is open to you on the same terms, and we will deal with it.
Write to hello@windhq.app and we will answer within 15 days, or sooner where the law applying to you requires it. We will not charge you and we will not ask you why. (Fifteen rather than the thirty a European reader might expect: Brazil’s LGPD gives the shorter deadline, and promising two different speeds to two readers of the same page would be a way of promising the slower one to everybody.)
Students under 18
Kite schools teach minors, so the platform holds data about them. A platform account requires you to be 18 or over. Where a student is a minor, the school records the lesson data under the authority of a parent or guardian, who may exercise every right above on the student’s behalf. We do not knowingly create accounts for children, and if you believe one exists, tell us and we will remove it.
Security
Traffic is encrypted in transit and data is encrypted at rest. Each school’s data is isolated at the database level rather than by application code alone. Login tokens are held on our servers and never given to your browser. Only the people who need access to run the service have it, and administrative actions are logged. No system is perfect; if we suffer a breach that puts you at risk, we will tell the relevant authority within 72 hours of becoming aware of it, and tell you without undue delay.
Changes
When this policy changes materially we will update the date at the top of this page and tell account holders by email before the change takes effect. Wind HQ is in pilot and is being built quickly; that is a reason for us to keep this page current, not a reason for you to have to check it.