Introduction
Airbus SAS and its affiliates[1] (also known as, "Airbus", or "we" or "us") appreciate your interest in our products, services and business lines and your use of Airbus Customer Portals (including AirbusWorld, Airbus Spares, Airbus Services Store) including applications on them.
Airbus is committed to protecting the rights of individuals and to complying with applicable personal data protection laws and regulations. We want you to feel comfortable using Airbus Customer Portals.
This Privacy Notice will inform you of the personal data we collect when you access/use the Portal; how we use and disclose your data; how you can control the use and disclosure of your data; and how we protect your personal data. Airbus Customer Portals might include links to other portals or applications which are not necessarily covered by this Privacy Notice. In this event, we encourage you to carefully read the privacy policies of such portals.
A company requesting access to the Airbus Customer Portals must first sign the following documents: Airbus General Terms and Conditions (GTC),
Company Registration Form (CRF), UEA commitment letter. When the documents have been signed,
the User Entity Administrator (UEA) account is created. The UEA is responsible for end-user account creation, modification and deletion for employees of their company.
At each step, Personal Data is requested, stored and processed by Airbus. This is detailed below.
[1] = Affiliates such as but not limited to Satair A/S, Airbus Canada Limited Partnership, GIE ATR, Airbus Americas Customer Services Inc., Airbus US A220 Inc.
1. What is Personal Data?
Personal Data is information that can be used to identify a person either directly or indirectly. It includes information such as name, contact details, identification numbers, financial data, location data or online identifiers.
2. Which sources and what personal data do we use?
Before your company accesses Airbus Customer Portal for the first time, documents that contain Personal Data are filled and signed:
Company Registration Form, UEA commitment letter and General Terms and Conditions.
These three documents are common to the Airbus Customer Portals (AirbusWorld, Airbus Spares and Airbus Services Store). In these contractual documents,
some particular persons are requested to provide Personal information:
- The signatory of the Company Registration Form (CRF):
You sign on behalf of the company you belong to, and so you hire your company. In the CRF, you must fill mandatory information: name and job title. - The administrator of the company:
In the CRF, you provide your given name, family name, job title, phone number, professional email address, ID or passport number with date of issue and date of expiry. This is because you act in your company on behalf of Airbus regarding the user's management of your company and to comply with laws and regulations. - The UEA commitment letter:
You are acting as User Entity Administrator in your company, so you have been asked to give your last name, first name and job title and to sign the UEA commitment letter. - The General Terms and Conditions (GTC):
You are duly representing your company, so you have been asked to give your last name, first name and job title and to sign the GTC. - Specific cases for applications that required additional contract signature:
The persons in charge of ordering for the company are requested to fill the relevant contract for access to the application where name, first name and job title must be given.
After the Airbus Customer Portal access is given to your company, the UEA of your company creates end-user accounts. Airbus will collect, use and process the following personal data through him:
- Identification data: your name and first name, professional email address.
- Professional data: Company name, professional phone number* and job title*.
- IT data: any information generated as a result of using Airbus Customer Portals, such as logs, IP address, the date and length of visit to the site, the pages you view, etc.
- Account information: Role and permissions, settings and preferences, login, password.
We may collect this Personal Data:
- indirectly for those Personal Data made available from your company. For example, when asking for your account creation, your User Entity Administrator enters your Personal Data.
- directly from you. For example, when filling a TechRequest, you get asked optionally to enter your phone number and your job title.
3. What are the purposes of the processing of your Personal Data?
By using Airbus Customer Portals and their applications, Airbus will process your personal data for the following purposes:
-
To manage Airbus Customer Portals Browsers / Administration. We use your personal data for administrative purposes, including access right management, to help us better understand how our customers access and use our portals and applications; to provide reports to prospective partners, service providers, regulators, and others.
-
To implement and maintain security, anti-piracy, fraud prevention, and other services designed to protect our customers, partners and us; and to enforce our policies, directives and processes.
-
To communicate with you. We use your personal data to communicate with you, including responding to requests for assistance or in the course of collaborative online forum areas with other AirbusWorld users if activated. We can communicate with you in a variety of ways, including email.
-
To provide customer service. We use your personal data for customer service purposes, including providing services to you (including through the e-Commerce portal for product and services requests), for technical support (through SB reporting or TechRequest for example) or other similar purposes and to establish and maintain customer accounts.
-
To comply with legal and compliance obligations and/or to protect us and others. We use your personal data when situations involve potential threats to the safety of any person or violations of policies, to manage consent collection and legal claims, terms, and other policies, to comply with applicable legal obligations, including export control regulations, responding to an authority or court order or discovery request.
-
Analytics. Airbus Customer Portals use your professional email address and/or Airbus External login ID for statistical purposes in order to improve the performance and efficiency of the Portals.
We will use your personal data for the above purposes only. If we need to use your personal data for an unrelated purpose, we will notify you prior to further personal data processing and provide you with the relevant privacy information notice.
4. What is the basis for the processing of your personal data?
Subject to the applicable law, we process your personal data under the following legal basis:
- Within the scope of a legitimate interest while taking into account the minimum privacy impact for you.
- For the purposes described in section 3 above;
- For the analysis and optimization of the Airbus Customer Portal;
- For ensuring IT security on Airbus network and the IT operation of Airbus.
- On the basis of Airbus' legal obligations.
Airbus, as any other company, is subject to legal obligations and regulations. In some cases the processing of your personal data will be necessary for Airbus in order to fulfil these obligations, including without limitation Export Control or anti-corruption.
5. Who will receive your personal data?
Subject to applicable law, we may disclose your personal data to the following recipient(s) on a need to know basis:
- Airbus and its affiliates;
- Authorized persons working for or on behalf of Airbus; including our agents, service providers providing the variety of products and services we need (e.g. Third party service providers and advisers providing the variety of products and services we need such as IT maintenance and support, customer support, procurement services, compliance and security services, etc.);
- Your company for which you are working for as an employee that have signed the applicable Airbus World General Terms and Conditions;
- Other AirbusWorld users in the frame of the collaborative online forum only;
- Airbus business partners in connection with Airbus activities (including law firm/consultancy firms,..);
- Other authorized third parties in connection with a reorganization or sale of Airbus businesses and/or assets;
- Law enforcement or government authorities where necessary to comply with applicable law or in response to any subpoenas, court orders, or to establish or exercise our legal rights or to defend against legal claims.
6. Is any of your personal data transferred overseas?
Airbus processes your personal data mostly in the European Economic Area and in Canada for Airbus Canada operating outside the European Economic Area. On occasion personal data is transferred to the relevant recipients as described in Section "Who will receive your personal data?" including entities in third countries, in particular for support purposes. This transfer is subject to appropriate safeguards to ensure an adequate level of protection and consequently to protect your privacy right.
Any transfers within Airbus affiliates as authorised recipients are limited to Airbus daily business activities and internal organisation. Such transfers are covered by an intra-group agreement ( Binding Corporate Rules ). The Binding Corporate Rules includes contractual protections to ensure that your personal data receives an adequate level of protection wherever it is transferred within Airbus.
In addition, we may share some personal data to third parties located outside the European Economic Area and the UK, subject to one of the following safeguards:
- We will only transfer personal data to countries which are recognised as providing an adequate level of legal protection or where we are satisfied that arrangements are in place to protect your privacy rights,
- transfers to service providers and other third parties will be protected by contractual commitments (such as the European Commission-approved Standard Contractual Clauses) or other legally acceptable mechanisms that ensure an adequate level of protection, and
- any requests for personal data information we receive from law enforcement or regulators will be carefully checked before personal data is disclosed.
If you have any questions regarding transfers, please contact us (dataprotection@airbus.com) for further details.
7. How long will your personal data be stored?
We retain your personal data as long as reasonably necessary for the purposes for which it was collected. In particular:
- For the AirbusWorld access right management:
- After 6 months of inactivity, the account is deactivated by Airbus and deleted after one year following the desactivation.
- When the account is deactivated and deleted by your UEA, the account and associated personal data is deleted one year after the deletion
- For AirbusWorld analytics purposes, the retention period is one year maximum after the data collection.
- For incident/bug resolution management, the personal data is kept for 6 months after the data collection.
In some circumstances, we may retain your personal data for a longer period of time than is needed for those purposes such as where we are required to do so in accordance with legal, regulatory, tax or accounting requirements.
8. What about the security of your personal data?
We use technical and organizational security measures in order to protect the personal data we have under our control against accidental or intentional manipulation, loss, destruction and against access by unauthorized persons. Our security procedures are continually enhanced as new technology becomes available.
9. What are your rights and how to exercise them?
At any time you may exercise your personal data protection rights as listed below by contacting us at dataprotection@airbus.com:
Right to access/obtain a report detailing the information held about you:
You have the right to obtain confirmation as to whether or not your personal data is being processed by Airbus and if so, what specific data is being processed.Right to correct personal data:
You have the right to rectify or request to have rectified any inaccurate personal data concerning you.Right to be forgotten:
In some cases, for instance, when the personal data is no longer necessary in relation to the Purposes for which they were collected, you have the right for your personal data to be erased.Right to restrict the processing of your personal data:
You have the right to restrict the processing of your personal data, for instance when the processing is unlawful and you oppose the erasure of your personal data. In such cases, your personal data will only be processed with your consent or for the exercise or defense of legal claims.Right to data portability:
You have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format and/or transmit those personal data to another data controller.Right to object:
In some cases required by law, you may ask us to stop processing your personal data.
10. How to exercise your rights and/or contact Airbus in respect of your personal data?
If you want to exercise your rights or you are unhappy with the way in which your personal data has been processed or
should you have any questions regarding the processing of your personal data, you may refer in the first instance to the Airbus Data Protection Officer,
who is available, at the following email address: dataprotection@airbus.com
or you can write to the address below:
Airbus SAS, Head of Privacy, 2 rond-point Emile Dewoitine 31700 Blagnac cedex France.
In case of doubt of your identity, we may ask you to justify it by enclosing a copy of any identity document.
11. Are you obliged to provide your personal data?
In the context of accessing Airbus Customer Portals, some personal data is strictly necessary, any failure to provide the requested personal data may result in not being able to grant you the appropriate access rights and thus fulfil our contractual and/or legal obligations or to achieve the expected results.
12. Do we use automated decision-making or conduct profiling?
As a matter of principle, we do not use fully automated decision-making processes. In the event that we should use such processes in individual cases, we will if prescribed by law, specifically inform you of this and of your rights in this respect as required by law.
13. How to ask for assistance from the competent authorities?
If you remain unsatisfied, then you have the right to lodge a complaint to a Data Protection Supervisory Authority such as:
- FRANCE: CNIL: Supervisory Authority France
- GERMANY: Each German federal state has its own Data Protection Authority that can be found under the following link:
https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html
(see tab "Aufsichtsbehörden für den nicht-öffentlichen Bereich", i.e. Data Protection Authorities for the private sector)
- SPAIN: AEPD.Supervisory Authority Spain
- UK: ICO: Supervisory Authority UK
- Canada: Office of the Privacy Commissioner of Canada; Commission of Access to Information Quebec
14. Additional Notice
For California residents
Pursuant to the California Consumer Privacy Act of 2018 (“CCPA”).
We don’t sell your personal information to third parties and we will not sell your personal information to third parties unless provided otherwise
by a specific privacy notice. We do not discriminate against California residents who exercise their CCPA privacy rights.
To exercise your California privacy rights please refer to the section “How to exercise your rights”.
For Chinese residents
We may provide and transfer your personal information to other entities in and outside of China in accordance with this privacy notice or
for other legitimate reasons. We will comply with the applicable obligations and requirements under China Personal Information Protection Law
in relation to sharing and cross-border transfers of personal information.
For Canadian residents
Pursuant to Canada’s Personal Information Protection and Electronic Data Act (“PIPEDA”).
In regard to cross-border transfers of personal data, your personal data may be sent to another jurisdiction for processing as described
by our privacy notice and while the information is in another jurisdiction it may be accessed by the courts,
law enforcement and national security authorities of such jurisdiction.
15. Cookies
15.1. What are cookies?
Cookies are small files or amount of information that may be stored to, accessed and removed from your device when you access Airbus Customer Portal.
They are widely used in order to make websites work, or work more efficiently, as well as to provide information to the owners of the site.
We may use Cookies:
- to record the preferences of our users,
- to enable us to optimize the design of Airbus Customer Portals,
- to ease navigation, and increase the user-friendliness of Airbus Customer Portals,
- to analyze the usage of Airbus Customer Portals, and/or to identify the most popular sections of Airbus Customer Portals,
- to provide content that is more accurately suited to your needs, and, in doing so, Airbus Customer Portals. Cookies can be used to determine whether there has been any contact between us and your device in the past,
- to facilitate secure online access so that you do not need to enter your user ID and password again when you access Airbus Portal.
15.2. Which cookies do we use?
Cookies contain personal data. The table below aims to inform you about the type and purpose of each cookie, the issuer (Airbus or third party)
and the retention period that we may use on our Airbus Customer Portals. The personal data is never kept in cookies after your session has been closed.
Other cookies that you could see are not listed below because they do not use personal data.
TYPE OF COOKIES | PURPOSE | RETENTION PERIOD | ISSUER | MANDATORY |
---|---|---|---|---|
Siteminder cookies | Identification for SSO connection | Session duration | Airbus | YES |
Tomcat cookies | AirbusSpares portal session control("jsessionid") | Session duration | Airbus | YES |
WCP cookies | Save the actions done by the user relative to the internet pages built | Session duration | Airbus | YES |
WCC cookies | Save the actions done by the user relative to the documents acceded | Session duration | Airbus | YES |
Fed search cookies | Save the search actions done by the user (user login used as key) | Session duration | Airbus | YES |
Technical/Network cookies | Load balancing use | Session duration | Airbus | YES |
Cognito cookies | Session management for the AWS platform | Session duration | Airbus | YES |
PostHog | Analytics | 13 months | Airbus | YES |
We use Cookies which are strictly necessary for technical reasons and are marked as "mandatory" on the table above.
Those Cookies do not require consent from you.
In case the list of cookies evolves with non-mandatory cookies (including for analytical purposes),
we will update this list of cookies accordingly and we will seek your consent prior to its deployment.
To find out more about cookies, including how to see what cookies have been set and how to manage and delete them, visit www.aboutcookies.org or www.allaboutcookies.org.
16. Modification of the Privacy Notice
Airbus will update this Privacy Notice from time to time in order to reflect the changes in our practices and services and also to remain compliant to Data Protection Laws and Regulations. We will inform you of any substantial modification in how we process your personal data.