PRIVACY NOTICE
Related to Airbus Supply Portal
Document
updated in February 2021
1.
Introduction
Airbus SAS and its affiliates
(also known as, "Airbus", or "we" or "us")
appreciate your interest in our products, services and business lines and your
use of Airbus Supply Portal including applications on them. Your privacy is
important to us and we want you to feel comfortable using Airbus Supply Portal.
Personal Data collected to access and use Airbus Supply Portal is processed by
us according to General Terms and Conditions to access to and use of Airbus
Supplier Portals signed by your Company in the course its business activity
with Airbus.
Airbus is committed to
protecting the rights of individuals in line with the General Data Protection Regulation (reference EU2016/679) of the
European Parliament and of the Council of 27 April 2016 on the protection of
natural persons with regard to the processing of Personal Data and on the free
movement of such data (hereinafter referred as : "GDPR") as well as
each applicable national Personal Data protection laws and regulations
(collectively referred as "Data Protection Laws and Regulations").
This Privacy Notice will
inform you of the Personal Data we collect when you access/use the Airbus Supply Portal; how we use and
disclose your data; how you can control the use and disclosure of your data;
and how we protect your Personal Data. However, Airbus Supplier Portals will include links to
other portals or applications which are not necessarily covered by this Privacy
Notice. In this event, we encourage you to carefully read the privacy policies
of such portals.
2.
What is Personal Data?
Personal Data is
information that can be used to identify a person either directly or indirectly
(hereinafter referred as: "Personal Data". A "personal
identifier" is a piece of information that can identify an individual.
This definition covers a wide range of personal identifiers to constitute
Personal Data, including name, address, email address, identification number,
location data or online identifier.
3.
Which sources and what
Personal Data do we use?
Before accessing to Airbus Supply Portal at first company registration, Airbus will collect directly from the Administrator appointed in your Company, the following Administrator Personal Data via notably the Identity Administrator and Documentation Manager Registration Form and Company Administrator Registration Form:
·
Identification
data: Administrator title, first name and family name, professional email
address, signature
·
Professional
data : company legal name, address, post code, country, Phone number
·
the
date and length of visit to the site, the pages you view etc…
·
Account
information (role and permissions, settings and preferences, login, password)
When you use Airbus Supply Portal and their
applications, Airbus will collect, use and process the following Personal Data
you provide us:
·
Identification
data: your complete name, professional email address.
·
Professional
data : as mandatory data: company name, Phone number.
·
IT
data: any information generated as a result of using Airbus Portals, such as IP
address, the date and length of visit to the site, the pages you view etc…
·
Account
information (role and permissions, settings and preferences, login, password)
We may collect this
Personal Data:
▪
directly from you. For example, when
filling the Documentation Manager registration Form Company Administration Form
or a TechRequest, you get asked optionally to enter your phone number and your
job title.
▪
indirectly for those Personal Data
made available from your company via your Administrator. For example, when
asking for your Airbus Supply account creation, your User Entity Administrator
enters your Personal Data.
4.
What are the purposes of
the processing of your Personal Data?
By using Airbus Portal and
their applications, Airbus will collect and process your Personal Data in
accordance with this Privacy Notice. Your Personal Data may be used for the
following purposes (hereinafter referred as: the "Purposes"):
1.
Portal
Browsers / Administration.
We use your Personal Data
for administrative purposes, including to help us better understand how our
customers access and use our portals and applications; to provide reports to
prospective partners, service providers, regulators, and others; to implement
and maintain security, anti-piracy, fraud prevention, and other services
designed to protect our customers, partners and us; and to enforce our
policies, directives and processes.
2.
Outsourcing
and supplier management.
We use your Personal Data
in the course of the management of Airbus supply chain and of your Company’s
performance with regards to deliverables expected as per the relevant contract
with your Company. Airbus Supplier portal is a means allowing to improve the
exchange information between our both companies in the course of the
performance of the contract.
3.
Communication.
We use your Personal Data
to communicate with you, including responding to requests for assistance. We
can communicate with you in a variety of ways, including email.
4.
Legal
compliance.
We use
your Personal Data to comply with applicable legal obligations, including
responding to an authority or court order or discovery request.
5.
To
protect us and others.
Where we believe it is necessary to investigate, prevent or take
action regarding illegal activities, suspected fraud,
situations involving potential threats to the safety of any person or
violations of policies, terms, and other policies.
5.
What is the legal basis for
processing of your Personal Data?
In accordance with the GDPR,
in the course of your access and use of Airbus Supplier Portal, we may process
your Personal Data for the following purposes (hereinafter referred as the
“Purposes”) such as :
1. Within the scope of a legitimate interest while taking into account
the minimum privacy impact for you. On occasion we may not need your consent to
use your data, given our legitimate interest to do so but we must inform you
that we do this; examples of this are:
o
For
the analysis and optimization of the Airbus Supplier Portal.
o
For
ensuring IT security on Airbus network and the IT operation of Airbus.
2.
On the basis of Airbus’
legal obligations. Airbus,
as any other company, is subject to legal obligations and regulations. In some
cases the processing of your Personal Data will be necessary for Airbus in
order to fulfil these obligations, including
without limitation the GDPR, anti-corruption.
6.
Who will receive your
Personal Data?
We may
disclose your Personal Data to the following recipient(s) on a strict need to
know basis and for the purposes as outlined in this Privacy Notice:
● Airbus and its affiliates;
● Authorized persons working for or on behalf of Airbus; including our agents, service providers providing the variety of products and services we need such as (e.g. Third party service providers and advisers providing the variety of products and services we need such as IT maintenance and support, compliance and security services, etc.);
● Your company;
● Airbus business partners in connection with Airbus activities (including law firm/consultancy firms,..)
● Other authorized third parties in connection with a reorganization or sale of Airbus businesses and/or assets;
● Law enforcement or government authorities where necessary to comply with applicable law or in response to any subpoenas, court orders, or to establish or exercise our legal rights or to defend against legal claims.
7.
Which countries and/or
regions will Airbus transfer your Personal Data to?
Airbus processes your Personal Data mostly in the EEA. On
occasion Personal Data is transferred to the
relevant recipients as described in Section “Who
will receive your Personal Data?” including entities outside the EEA. This transfer is
subject to appropriate safeguards, and through the legal framework of our
Binding Corporate Rules, that can be found on our portal www.airbus.com or viewed here Airbus BCR's or through alternative
contractual frameworks (so called Standard
Contractual Clauses) or relevant adequacy decision where the relevant data
recipients as defined in Section “Who
will receive your Personal Data?” is engaged to help us providing/support services to Airbus.
Our
Binding Corporate Rules allow us to transfer Personal Data within our
international organisation for Airbus daily business activity and internal
organisation, and they include a list of countries where Airbus Affiliates
having signed the BCR and which might have access to your Personal Data if
relevant.
Australia, Belgium,
Brazil, Canada, Chile, China, Colombia, , Denmark, , Finland, France, Germany,
Hong Kong, Hungary, India, Indonesia, Ireland, Italy, Japan, Kazakhstan,
Malaysia, Mexico, Morocco, Netherlands, New Zealand, Nigeria, Norway, Oman,
Philippines, Poland, Qatar, Romania, Russia, Saudi Arabia, Singapore, Slovakia,
South Africa, South Korea, Spain, Switzerland, Taïwan, Thailand, Tunisia,
Turkey, United Kingdom, United Arab Emirates, Uruguay, United States of
America.
8.
How long will your Personal
Data be stored?
We process and store your
Personal Data as long as it is required to access and use our Airbus Portal
and/or meet our legal, contractual and statutory obligations. If your Personal
Data is no longer required, these will be erased on a regular basis unless
further processing is necessary, for instance, for preserving particular
evidence under the applicable Data Protection Laws and Regulations, or in the
context of legal statutes of limitation.
9.
What about the security of
your Personal Data?
We use technical and
organizational security measures in order to protect the Personal Data we have
under our control against accidental or intentional manipulation, loss,
destruction and against access by unauthorized persons. Our security procedures
are continually enhanced as new technology becomes available.
10. What are your rights and how to exercise them?
Under
some circumstances provided by law, you may at any time exercise your data
protection rights as listed below:
●
Right to access/obtain a
report detailing the information held about you: You have the right to
obtain confirmation as to whether or not your Personal Data is being processed
by Airbus and if so, what specific data is being processed.
●
Right to correct Personal
Data: You
have the right to change any inaccurate Personal Data concerning you.
●
Right to be forgotten: In some cases, for
instance, when the Personal Data is no longer necessary in relation to the
Purposes for which they were collected, you have the right for your Personal
Data to be erased.
●
Right to restrict the
processing of your Personal Data: You have the right to restrict the processing of your
Personal Data by Airbus, for instance when the processing is unlawful and you
oppose the erasure of your Personal Data. In such cases, your Personal Data
will only be processed with your consent or for the exercise or defence of
legal claims.
●
Right to data portability: you have the right to
receive the Personal Data concerning you in a structured, commonly used and
machine-readable format and/or transmit those Personal Data to another data
controller.
●
Right to object: In some cases required by
law, you may ask us to stop processing your Personal Data.
10.
How to exercise your rights and/or contact Airbus in respect of your Personal
Data?
If you want to exercise your rights or you are unhappy
with the way in which your Personal Data has been processed or should you have
any questions regarding the processing of your Personal Data, you may refer in
the first instance to the Airbus Data Protection Officer, who is available, at
the following email address: dataprotection@airbus.com or you can
write to the address below: Airbus SAS,
Head of Data Protection, 2 rond-point Emile Dewoitine 31700 Blagnac cedex France.
In case of doubt of your
identity, we may ask you to justify it by enclosing a copy of any identity
document.
11. Are you obliged to provide your Personal Data?
In the context of accessing
Airbus Supplier Portal, some Personal Data are strictly necessary, any failure
to provide the requested Personal Data may conduct us not being able to grant
you the appropriate access rights and thus fulfil our respective contractual
obligations with your company or to achieve the expected results.
12. Are your Personal Data the basis for automated
decision-making, including profiling?
As a matter of principle,
we do not use fully automated decision-making processes. In the event that we
should use such processes in individual cases, we will if prescribed by law,
specifically inform you of this and of your rights in this respect.
13. How to ask for assistance to the competent authorities?
If you remain unsatisfied,
then you have the right to lodge a complaint to a Data Protection Supervisory
Authority. Listed below are the four main European countries where Airbus
operates and the relevant Supervisory Authority:
●
FRANCE: CNIL: Supervisory Authority France
●
GERMANY: Each German federal state has its own Data
Protection Authority that can be found under the following link: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html
(see tab “„Aufsichtsbehörden für den nicht-öffentlichen Bereich“, i.e. Data
Protection Authorities for the private sector)
●
SPAIN: AEPD. Supervisory Authority Spain
●
UK: ICO: Supervisory Authority UK
Cookies are small files or
amount of information that may be stored to, accessed and remove from your
device when you access Airbus Portal.
For instance, a “Cookie”
may refer to “http cookie”, flash cookie” (used by some applications or website
relying on Flash technology), local storage area of your internet browser,
unique identifier
calculated from your internet browser
characteristics (also known as “browser fingerprinting”), or unique identifiers
related to your device or your internet browser (device serial number, MAC
address, Android ID, advertising ID, etc...)].
Cookies allows us to
recognize your device and store information about your preferences or past
actions. We may use Cookies:
(i)
to
record the preferences of our users,
(ii)
to
enable us to optimize the design of Airbus Portal,
(iii)
to
ease navigation, and increase the user-friendliness of Airbus Portal,
(iv)
to
analyze the usage Airbus Portal, and/or to identify the most popular sections
of Airbus Portal,
(v)
to
provide content that is more accurately suited to your needs, and, in doing so,
Airbus Portal. Cookies can be used to determine whether there has been any
contact between us and your device in the past,
(vi)
to
facilitate secure online access so that you do not need to enter your user ID
and password again when you access Airbus Portal.
Please find below a table
with specific information for cookies types that we may use on our Airbus
Portal. The Personal data are never kept in cookies after your session has been
closed.
Other cookies that you
could see are not listed below because they do not use Personal Data.
TYPE OF
COOKIES |
PURPOSE |
RETENTION
PERIOD |
MANDATORY |
Siteminder cookies |
Identification for SSO connection |
Session duration |
YES |
Tomcat cookies |
AirbusSpares session control(“jsessionid”) |
Session duration |
YES |
WCP cookies |
Save the actions done by the user relative to the
internet pages built |
Session duration |
YES |
WCC cookies |
Save the actions done by the user relative to the
documents acceded |
Session duration |
YES |
Fed search cookies |
Save the search actions done by the user (user login used as key) |
Session duration |
YES |
Technical/network
cookies |
Load balancing use |
Session duration |
YES |
When the Cookies we use are strictly necessary for
technical reasons, they are marked as “mandatory” on the table above. Those
Cookies does not require consent from you.
You can prevent Cookies from being stored on your device
by setting your browser to not accept cookies. The exact instructions for this
can be found in the manual for your browser. You can also delete Cookies
already on your device at any time through your browser’s settings.
For the purpose of
statistical analysis, we use analytics tools relying on specific Cookies. You
may object at any time to the collection and analysis of statistical data
regarding your access to and use of Airbus Portal through the cookies settings
interface mentioned above.
To find out more about
cookies, including how to see what cookies have been set and how to manage and
delete them, visit www.aboutcookies.org
or www.allaboutcookies.org.
15. Modification of the Privacy Notice
Airbus will update this
Privacy Notice from time to time in order to reflect the changes in our
practices and services and also to remain compliant to Data Protection Laws and
Regulations. We will inform you of any substantial modification in how we
process your Personal Data.
***************
******
*