Airbus CyberSecurity (also known as, “Airbus”, or “we” or “us”) appreciates your interest in its products, services and business lines and your use of our websites, portals and”apps” (“Websites”). Your privacy is important to us and we want you to feel comfortable using our websites. The protection of your privacy and personal data is an important concern to which we pay special attention throughout our business processes. Personal data collected during use of our website is processed by us according to the legal regulations valid for the countries in which the websites is maintained. In addition, our Binding Corporate Rules Airbus BCR’s protect customer and partner data throughout the entire organisation. However, the website will include links to other websites or applications which are not necessarily covered by this Privacy Notice. In this event, we encourage you to carefully read the privacy policies of such websites.
Airbus is committed to protecting the rights of individuals in line with the General Data Protection Regulation (reference EU2016/679) of the European Parliament as well as each applicable national personal data protection laws and regulations (collectively referred as “Data Protection Laws and Regulations”).
Privacy Notice index
This Privacy Notice will inform you of the personal data we collect when you access/use the Website; how we use and disclose your data; how you can control the use and disclosure of your data; and how we protect your personal data.
- What is Personal Data?
- Which sources and what Personal Data we use?
- What are the purposes of the processing of your Personal Data?
- What is the basis for processing of your Personal Data?
- Who will receive your Personal Data?
- Will your Personal Data be transferred to a third country outside the European Economic Area?
- For how long will your Personal Data be stored?
- What are your rights and how to exercise them?
- Am I obliged to provide my Personal Data?
- To what extent will decision-making be automated?
- Will profiling take place?
- How can I contact the responsible for processing my Personal Data?
- Can I ask for assistance to the Data Protection Supervisory Authorities?
- Modification of the Privacy Notice
What is personal data?
Personal data is information that can be used to identify a person either directly or indirectly. A ‘personal identifier’ is a piece of information that can identify an individual. This definition covers a wide range of personal identifiers to constitute personal data, including name, address, email address, identification number, location data or online identifier.
Which sources and what Personal Data do we use?
When you use this Website, Airbus will collect, use and process any personal data you provide us (e.g. your name, date of birth, company name etc.) and any information generated as a result of using the website, such as IP address, the date and length of visit to the site, the pages you view etc.
What are the purposes of the processing of your Personal Data?
By using the Website, Airbus will collect and process your personal data in accordance with this. Your personal data may be used for the following purposes:
1. Website Browsers / Administration.
o We use your Personal Data for administrative purposes, including to help us better understand how our customers access and use our websites and applications; to provide reports to prospective partners, service providers, regulators, and others; to implement and maintain security, anti-piracy, fraud prevention, and other services designed to protect our customers, partners and us; and to enforce our policies, directives and processes.
o To the extent permitted by law or with your consent, we may use your Personal Data for marketing and promotional purposes, including communications through email or equivalent electronic means. For example, we use your Personal Data, such as your email address, to send news and newsletters, special offers, promotions and competitions, or to otherwise contact you about services or information we think will interest you.
o We use your Personal Data to communicate with you, including responding to requests for assistance. We can communicate with you in a variety of ways, including email and via your social media accounts if you have agreed, and/or text message.
3. Research and development.
o We use your Personal Data for research and development purposes, including to improve our websites, applications, services, and customer experience and for other research and analytical purposes dedicated to improving our products, services, businesses, operations and processes.
4. Legal compliance.
o We use your Personal Data to comply with applicable legal obligations, including to respond to an authority or court order or discovery request.
5. To protect us and others.
o Where we believe it is necessary to investigate, prevent or take action regarding illegal activities, suspected fraud, situations involving potential threats to the safety of any person or violations of policies, terms, and other policies.
What is the basis for processing of your Personal Data?
As a responsible company, we need a lawful basis for collecting and/or processing your data. We generally rely on a number of grounds (reasons) for our business processing
We process your Personal Data in accordance with the provisions set out in the GDPR and the relevant applicable Data Protection Laws and Regulations. The purposes for processing your Personal Data are:
1. To comply with contractual obligations.
When you subscribe to a particular service through the Website, the purposes of processing your Personal Data are primarily determined by that service and we will process your information so that we can provide that service to you.
2. As a result of your consent.
When you have consented to the processing of your Personal Data by us for certain services through the Website you can withdraw consent at any time by following the instructions provided in the application process or by contacting us at email@example.com. For further information on the right of withdrawal, please see below Section “Am I obliged to provide my Personal Data?”
3. Within the scope of a legitimate interest. On occasion we may not need your permission to use your data, given our legitimate interest to do so but we must inform you that we do this; examples of this are:
o For the analysis and optimisation of the Website.
o For ensuring IT security and the IT operation of Airbus.
o For prevention and investigation of criminal acts.
3. On the basis of Airbus’ legal obligations or in the public interest.
Airbus, as any other company, is subject to legal obligations and regulations. In some cases the processing of your Personal Data will be necessary for Airbus in other to fulfil these obligations.
Who will receive your Personal Data?
- Authorised persons working for or on behalf of Airbus CyberSecurity;
- Our agents, service providers and advisers (e.g. Third party service providers and advisers providing the variety of products and services we need such as IT maintenance and support, procurement services, compliance and security services, etc.);
- Other authorised third parties in connection with a reorganisation or sale of Airbus businesses and/or assets
- Law enforcement or government authorities where necessary to comply with applicable law.
Will your Personal Data be transferred to a third country outside the European Economic Area (EEA)?
Airbus processes your personal data mostly in the EEA. On occasion Personal Data is transferred to Airbus SE or affiliates of Airbus, on a need-to-know basis, including entities outside the EEA. This transfer is subject to appropriate safeguards, and through the legal framework of our Binding Corporate Rules, that that can be found on our website www.airbus-cyber-security.com or viewed here Airbus BCR’s or through alternative contractual frameworks where a third party is engaged to help us provide web-services to you.
Which countries will Airbus transfer personal data to?
Our Binding Corporate Rules allow us to transfer personal data within our international organisation, and they include a list of countries (below) which are structured to allow us to transfer personal information to the countries where we have a presence. For Airbus, France and Germany are where most of our processing of personal information takes place and below is a list of countries where Airbus operates,
Algeria, Australia, Belgium, Brazil, Canada, Chile, China, Czech republic, Denmark, Egypt, Finland, France, French Guyana, Germany, Greece, Hong Kong, Hungary, India, Indonesia, Ireland, Italy, Japan, Kazakhstan, Libya, Malaysia, Mexico, Morocco, Netherlands, New Zealand, Norway, Oman, Philippines, Poland, Qatar, Romania, Russia, Saudi Arabia, Singapore, Slovakia, South Africa, South Korea, Spain, Sweden, Taiwan, Tanzania, Thailand, Tunisia, Turkey, United Kingdom, United States of America, Uruguay, United Arab Emirates, Vietnam.
For how long will your Personal Data be stored?
We process and store your Personal Data for as long as is required to meet our contractual and statutory obligations. If your Personal Data is no longer required for the performance of the contractual or statutory obligations, these will be erased on a regular basis unless further processing is necessary, for instance, for preserving particular evidence under the applicable Data Protection Laws and Regulations, or in the context of legal liabilities limitation.
We use technical and organisational security measures in order to protect the data we have under our control against accidental or intentional manipulation, loss, destruction and against access by unauthorised persons.
Our security procedures are continually enhanced as new technology becomes available.
What are your rights and how to exercise them?
You may at any time exercise your data protection rights
- Right to access/obtain a report detailing the information held about you: You have the right to obtain confirmation as to whether or not your Personal Data is being processed by Airbus and if so, what specific data is being processed.
- Right to correct Personal Data: You have the right to change any inaccurate Personal Data concerning you.
- Right to be forgotten: In some cases, for instance, when the Personal Data is no longer necessary in relation to the purposes for which they were collected, you have the right for your Personal Data to be erased.
- Right to stop the processing of your data: You have the right to restrict the processing of your Personal Data by Airbus, for instance when the processing is unlawful and you oppose the erasure of your Personal Data. In such cases, your Personal Data will only be processed with your consent or for the exercise or defense of legal claims.
- Right to data portability: Under some circumstances provided by law, you have the right to receive the Personal Data concerning you in a structured, commonly used and machine-readable format and/or transmit those Personal Data to another controller.
- Right to object and to withdraw consent: please see below section “Am I obliged to provide by Personal Data?”
To this effect, please contact Airbus in writing either by e-mail at the following address:
firstname.lastname@example.org or you can write to the addresses below, enclosing a copy of a document evidencing your identity.
Airbus SA, Head of Data Protection, HAP, 1 rond-point Maurice Bellonte 31700 Blagnac cedex. France
Am I obliged to provide my Personal Data?
You may at any time object to the processing of your Personal Data or where your consent is required, withdraw such consent by contacting us at email@example.com; However, please note that if you withdraw your consent, you may not be able to access and use certain information, features or services of the Website.
To what extent will decision-making be automated?
As a matter of principle, we do not use fully automated decision-making processes. In the event that we should use such processes in individual cases we will inform you of this and of your rights in this respect separately if prescribed by law.
Will profiling take place?
As a matter of principle, your Personal Data will not be processed automatically with the objective of evaluating certain personal aspects (profiling). In the event that we should process your Personal Data with the objective of conducting profiling we will inform you of this and of your rights in this respect separately if prescribed by law.
How can I contact the responsible for processing my Personal Data?
If you are unhappy with the way in which your personal data has been processed or should you have questions regarding the processing of your Personal Data, you may refer in the first instance to the Airbus Data Protection Officer, who is available for enquiries or complaints, at the following email address:
firstname.lastname@example.org or you can write to the address below:
Airbus SAS : Head of Data Protection, HAP, 1 rond-point Maurice Bellonte 31700 Blagnac cedex. France
Can I ask for assistance to the competent authorities?
If you remain unsatisfied, then you have the right to apply directly to a Data Protection Supervisory Authority. Listed below are the four main European countries where Airbus operates and the relevant Supervisory Authority
WHAT ARE COOKIES?
Only the cookie on your device is identified. Personal details can be saved in cookies, provided that you have consented. For example, in order to facilitate secure online access so that you do not need to enter your user ID and password again.
WHICH COOKIES DO WE USE?
Please find below a table with specific information for each cookie that we may use on our Website:
|NAME OF COOKIES||PURPOSE||RETENTION PERIOD|
|cookies-banner||Cookies policy approval.||Session duration|
|_ga||Used to distinguish users.||12 months|
|_gid||Used to distinguish users.||24 hours|
|_gat||Used to throttle request rate.||1 minute|
|NID||These cookies use an unique identifier for tracking purposes.||7 days|
|Cookies||Used to hide the cookies banner once it has been closed by the user.||12 months|