IUSW Privacy Statement

Iris Privacy statement, version 01-01, 25.10.2024

Privacy statement regarding protection of personal data in relation to the Iris User Support Website and Iris Service Desk

All personal data are dealt with in compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (hereinafter referred to as “GDPR”).

The following data protection information notice outlines the criteria by which the data is collected, managed and used in relation to the Iris User Support Website and Iris Service Desk.

 

1. Identity of the controller

ESSP S.A.S., as IRIS Service Provider
3, rue Tarfaya - CS 84432
31405 Toulouse Cedex 4 – France

Recept: +33(0)5 61 28 19 54
Email: personaldata.essp@essp-sas.eu

 

2. Purpose of processing

Iris User Support Website registration *

The purpose of the processing is the management, administration of the Website, including the following activities:

  • To enable access to specific contents and to the subscription to Iris related notifications.
  • Dissemination of specific Iris User Support Website related news.
  • Dissemination of specific consultations and of the annual Iris User Satisfaction survey.
  • To perform analysis on the usage and statistics.
  • General administration and technical maintenance of the Website
     

Iris Documentation subscription

The purpose of the processing is the management of the Iris documentation subscriptions, including the following activities:

  • Management of the Iris Documentation subscription function.
  • Monitoring on the Iris documentation subscriptions use / activity.
  • Dissemination of the annual Iris User Satisfaction survey.
     

Iris Service Desk contact form

The purpose of the processing is the management of the Iris Service Desk, including the following activities:

  • Management of the Iris related questions / tickets.
  • Monitoring on the Iris Service Desk use / activity.
  • Dissemination of specific consultations and of the annual Iris User Satisfaction survey.


Other data processing operations may result from those mentioned above (e.g. satisfaction surveys). In this case, you will be informed of the terms and conditions of such processing prior to its implementation.
 

3. Data concerned

Iris User Support Website registration *

Data necessary for the Website related activities, administration and maintenance:

  • Mandatory data: e-mail address, username, first & last name, country, signed Iris Working Agreement (“IWA”), name of organisation.
  • Optional data: phone, fax, position in the organisation, organisation type and service level. This optional information allows us to get to know you better and take better care of your requests to the support Website.
     

Iris Documentation subscription

Data necessary for the management of the Iris documentation subscription function:

  • Mandatory data: e-mail address, subscription preferences
     

Iris Service Desk contact form

Data collected through the Iris Service Desk contact form, required for the Iris Service Desk management:

  • Mandatory data: name, e-mail address, country, name of organisation, subject, question
  • Optional data: name of organisation, country, service level. This optional information allows us to get to know you better and take better care of your requests to the Service Desk.


Some data may be requested on an optional basis (e.g. your name as part of a satisfaction survey). The purpose of this optional information is to enable us to refine our processing, services or surveys with a view to improving them. You are never obliged to provide this optional information and not providing it will never have any consequences whatsoever.
 

4. Legal basis

ESSP operate, provide, and lead the Iris service commercialisation to European Air Navigation Service Providers (ANSPs). In this respect, the legal basis for the processing carried out by ESSP is the contract ("IWA") concluded between ESSP and its customers, notably through acceptance of the Iris terms of use.

On the other hand, for processing involving the sending of electronic communications (e.g. newsletters, satisfaction surveys), the legal basis is your consent. You must consent to receiving such content, and you may withdraw your consent at any time. To do this, you can use the link at the bottom of the e-mail, contact the Service Desk or, if you have any difficulty, contact the DPO at personaldata.essp@essp-sas.eu.

 

5. Recipients of the data processed

Persons which have access to the personal data on the basis of the ‘need to know’ principle:

  • A limited number of persons managing the Iris Website and Iris Documentation subscription activities among ESSP staff and,
  • A limited number of persons working for companies providing support to ESSP activities (as regards the Iris service provision) or companies providing IT support or hosting services to ESSP.

These recipients of the personal data concerned are bound by confidentiality clauses regarding the use, disclosure and protection of the personal data.

A full list of data sub-processors is available on request by sending an email to personaldata.essp@essp-sas.eu.

 

6. Information on the retention period of personal data

In accordance with our legal obligations, your data will be stored once you have unsubscribed from all Iris services:

  • 5 years for most of your data
  • 10 years for financial/accounting data

Users can unregister from the Iris Support Website database by editing their profiles in the “My Account” section of the Website after logging in. Personal data will be deleted once a user is no longer registered in the Website*.

Users can unregister from the Iris Documentation Subscription database in the Website by unselecting the required check-boxes from the subscriptions sections in the Website and pressing the “unsubscribe” button. Personal data will be deleted once a user is no longer subscribed to any item*.

* This deletion concerns "in production" data only. The data will be kept as archives for the above-mentioned periods.

For any processing that does not comply with these general operating rules, you will be given precise information about the retention period before the processing is carried out (e.g. satisfaction surveys are retained while the service is operational and are anonymized thereafter).

If you experiment any difficulty, contact the DPO at personaldata.essp@essp-sas.eu.

 

7. Information on storage of the personal data and possible transfer of data

Personal data are electronically stored in:

  • For Iris User Support Website registration and Iris Documentation subscription request: *
    • Iris User Support Website database: hosting services sub-contracted to a company which uses Amazon* servers located in Europe
    • Specific Website activity database: ESSP servers (Spain and France)
       
  • For Iris Service Desk contact form:
    • Iris User Support Website database: hosting services sub-contracted to a company which uses Amazon* servers located in Europe.
    • Iris Service Desk mailbox: ESSP servers (France)
    • Specific Iris Service Desk database: ESSP servers (Spain and France)

*As an American company, Amazon is likely to generate data flows from outside the EU to the United States. These flows are governed by the European Commission's standard contractual clauses and are authorized by the European Commission's adequacy decision of July 10, 2023. ESSP has nevertheless decided to implement an additional security measure which is encryption. Data hosted in Amazon servers is indeed encrypted in such way so that Amazon cannot access the data in clear text.

 

8. Additional information on cookies and other trackers

When you visit our Website, cookies are placed on your computer, cell phone or tablet. When you visit our site for the first time, a banner informs you of the presence of these cookies and invites you to indicate your choice. Cookies are only stored if you accept them.

A "cookie" is a piece of information, generally small in size and identified by a name, which may be transmitted to your browser by a web site to which you connect. Your web browser will store it for a certain period of time, and send it back to the web server each time you reconnect. Cookies have many uses: they can be used to memorize your customer ID with a merchant site, the current contents of your shopping basket, an identifier enabling your browsing to be tracked for statistical or advertising purposes, etc.

We use two types of cookies:

  • Technical cookies necessary for site operation (without consent)
  • Audience measurement cookies enabling us to understand how you interact with the site in order to improve it (with consent only)
     

Technical cookies

Name of cookie

Use

Retention period

cookie-agreed / cookie-agreed-version

Keep your cookie choices

6 month



Audience measurement cookies

Name of cookie

Use

Retention period

_ga

Store and count pageviews

13 month

_gat

Read and filter questions from bots

13 month

_gid

Store and count pageviews

13 month

 

9. The data subject's rights

Data subjects have the right of access, rectification, restriction of processing and right to erasure of their personal data at any time under the conditions set out in Articles 15, 16, 17 and 18 of the GDPR.

For processing based on consent, data subjects also have the right to withdraw their consent at any time.

Requests shall be addressed to ESSP Data Protection Officer by email at personaldata.essp@essp-sas.eu or by mail at:

ESSP S.A.S.
For the Data Protection Officer
3, rue Tarfaya - CS 84432
31405 Toulouse Cedex 4 - FRANCE

Data subjects are entitled to lodge an appeal at any time with the Commission Nationale de l'Informatique et des Libertés (CNIL) at www.cnil.fr should they consider that the processing operations do not comply with Regulation (EU) No 2016/679.


* For sake of clarity, at the time of publishing this Website and T&C, the ANSP Portal is not yet ready and available and therefore the registration option is not yet available.