wiki

Managing Personal Data in Leon: Reversible vs. Irreversible Functions Explained

Managing Personal Data in Leon: Reversible and Irreversible Options Explained

Leon offers several distinct mechanisms for limiting, hiding, or removing personal data — and while they may sound similar, each operates on a different level and carries different consequences. The single most important question to ask before touching any of them is: can the data be brought back afterwards? This article groups Leon's five data-privacy functions along exactly that line — reversible versus irreversible — explains how each works, and suggests when to use which.

The five functions at a glance

Category

Function

Where configured

What it affects

Reversible

Auto-archive PAX list

Admin Panel > Phonebook

PAX lists on past flights

Reversible

Automatically mask PAX after given days

Admin Panel > General Settings > Phonebook

PAX contact details (passport) in the Phonebook

Reversible

Mask users enabled

Admin Panel > General Settings > Phonebook

Contact details of inactive Users

Irreversible

Automatically delete PAX after given days

Admin Panel > General Settings > Phonebook

PAX profiles not used for a given period

Irreversible

Permanently delete & anonymize

User / PAX / Company profile

The entire profile (User, PAX, or Company)

The reversible group hides data while keeping it in the Leon database — a visibility layer that can be lifted with the right permission or a Restore button. The irreversible group actually erases data, and once it is gone, it cannot be recovered under any circumstances.


Part I — Reversible functions: hiding data without losing it

These functions are safe to use as everyday privacy hygiene. They reduce who can see sensitive information, but a user with the appropriate permission can always bring the data back.

Auto-archive PAX list — cleaning up past flights

This function automatically archives passenger lists from flights after a configurable number of days from departure (minimum 30 days; leaving the field empty disables the feature). It is configured in the Admin Panel > Phonebook by an administrator holding the Operator General Settings Edit permission.

When a PAX list is archived, Leon:

  • removes all passenger contacts and their details (names, document data, labels) from the flight,

  • retains the passenger count, so operational statistics remain intact,

  • marks the list as archived, clearly visible in the OPS module.

Archiving runs automatically every day at 03:30 UTC. The archived data is not destroyed — it stays in the Leon database, and users with the PAX Archived Restore permission can bring the full list back using the Restore button in the OPS > PAX view. After a manual restore, the list is not immediately re-archived by the next scheduled run, giving you time to review the data. Note that while a list is archived, manual editing is blocked and the PAX change history is unavailable until the list is restored.

Important caveat: enabling auto-archiving may break external integrations that rely on passenger data from past flights. Verify your integrations before switching it on.

Automatically mask PAX after given days — hiding passenger details in the Phonebook

Where auto-archiving targets flight records, this setting targets contact profiles. Configured in the Admin Panel > General Settings > Phonebook tab, it automatically masks passenger contact information (currently the passport number) for PAX who haven't been used in trip bookings or sales quotes within a defined number of days.

The configuration has two options: Mask PAX enabled (activates the feature) and Mask PAX after (number of days of inactivity before masking). For a PAX to be masked, all of the following must be true:

  • the PAX is not a User,

  • the PAX is not marked as 'Deleted',

  • the PAX is not marked as 'Is representative',

  • the PAX was a passenger on a past flight but has not been assigned to any flight within the configured period.

Once masked, the passport number becomes unavailable for preview — in the PAX profile, in the OPS > PAX tab on a flight, and in the Requests/Quotes > PAX tab of a quote. Access is controlled by the Contact Mask privilege: users with it set to EDIT can preview masked details via the eye icon and unmask them through the UNMASK option in the PAX profile. Users with the privilege set to DENY see a message that they don't have permissions to unmask passports.

Mask users enabled — the same idea, applied to Users

The Mask users enabled setting, also in Admin Panel > General Settings > Phonebook, extends masking to user profiles. When enabled, contact information for all inactive user contacts is masked automatically.

The unmasking mechanics are identical to PAX masking: the Contact Mask privilege set to EDIT allows previewing and unmasking through the Phonebook panel or the Users section, while DENY blocks access entirely.


Part II — Irreversible functions: erasing data for good

These functions permanently destroy data. There is no Restore button, no Unmask option, and no support ticket that can bring the information back. Treat every activation as a deliberate compliance decision, not a cleanup shortcut.

Automatically delete PAX after given days — automated retention enforcement

Masking's heavier sibling lives in the same place: Admin Panel > General Settings > Phonebook tab. Instead of hiding data, this function automatically removes passenger details from the system if the PAX has not been assigned to any flight within a specified timeframe. By default it is turned off for all operators.

The configuration consists of:

  • Delete PAX enabled — activates automatic deletion,

  • Send notification 7 days before deletion to: — a mandatory email address (when the feature is enabled) that receives a list of passenger names scheduled for deletion seven days in advance,

  • Delete PAX after — the number of days of flight inactivity after which PAX data is deleted; the minimum threshold is 30 days.

Two safety valves are built in: the 7-day advance notification gives you a window to react before anything is removed, and individual passengers can be excluded entirely — in the PAX profile in the Phonebook, the Misc tab contains a Never delete automatically checkbox for VIPs, owners, or frequent flyers that must always stay in the database.

The wiki explicitly warns to use this function with extreme caution: deleted data cannot be recovered. Where masking is a visibility filter, automatic deletion is a true retention policy executed by the system.

Permanently delete & anonymize — the GDPR-grade erasure

This is the heaviest tool in the set, created specifically to comply with Regulation (EU) 2016/679 (GDPR) and the "right to be forgotten." It exists separately for Users, PAX, and Companies, and it is always a manual, per-profile action confirmed by an explicit warning pop-up.

For Users, the process is: go to Settings > Users, mark the user as deleted by unticking both 'Can log into Leon' and 'Active' in the Account restrictions section, update, then edit the user again and click Permanently delete & anonymize data at the bottom of the page. A confirmation pop-up warns that the action is irreversible. After deletion:

  • the profile disappears permanently from both Settings > Users and the Phonebook,

  • anywhere the user was assigned to an operation (flight, positioning, office duty), the user code is replaced by -D-, and the CREW tab shows "Permanently Deleted" instead of a name,

  • reports such as the Custom Flights List show -D- for that crew member.

An admin can verify who performed a deletion using the CHECK PERMANENTLY DELETED USERS button by entering the deleted user's code.

For PAX, the flow runs through the Phonebook: edit the PAX, delete it, edit it again, and click Permanently delete & anonymize data. Afterwards, the profile is gone from the Phonebook, and on any flight the passenger was added to, "Permanently Deleted" appears instead of the name — including in tooltips in the SCHEDULE view and in reports.

For Companies, an analogous permanent delete & anonymize option is available when editing a company in the Phonebook.

In every variant, the warning is the same: once the data has been deleted, it cannot be recovered.


How to choose the right function

The decision tree starts with one question: do you need the data gone, or just out of sight?

If the data must remain recoverable, stay in Part I. Use masking (PAX and Users) as your baseline privacy layer — sensitive document numbers stay hidden from most staff while a small group with the Contact Mask privilege can unmask them when operationally necessary. Add auto-archiving of PAX lists for routine retention hygiene on operational records: passenger details disappear from old flights automatically, PAX counts stay intact for reporting, and the Restore function covers audits, investigations, or regulatory requests. Verify your integrations before enabling archiving.

If your policy or the law requires actual erasure, move to Part II — carefully. Enable automatic PAX deletion only when your data-retention policy demands hard erasure of stale profiles, and only after configuring the notification email to a monitored inbox and marking key contacts (owners, VIPs, regulars) with Never delete automatically. Reserve manual permanently delete & anonymize for documented GDPR erasure requests from former crew members, passengers, or clients, handled case by case — and before executing, confirm that no retention obligation (e.g., aviation record-keeping requirements) mandates keeping the data.

A sensible layered setup for most operators: reversible functions (masking + auto-archiving) enabled as the default, irreversible functions used sparingly — automatic deletion only under an explicit retention policy, and manual permanent deletion only on formal request.