Privacy Policy
1. OVERVIEW
This policy sets out the personal data processing practices and your related rights in relation to the personal data collected about you when you use the OLEN Platform ("Platform").
We take your privacy very seriously. We ask that you read this privacy policy ("Policy") carefully as it contains important information about how we will use your personal data and how we will ensure we meet our legal obligations to you under the Spanish data protection rules (including associated guidance) (the "Data Protection Laws").
We are a controller of your information which means that we are responsible for looking after it. We will use your personal data fairly, lawfully and in a transparent manner, and in accordance with the Data Protection Laws.
Depending on the contractual setup, OLEN may act as a data processor on behalf of its customers (such as airlines, MROs or lessors), who remain the data controllers of operational data uploaded to the Platform.
2. PERSONAL DATA WE MAY COLLECT ABOUT YOU
2.1 Information that you provide
We will obtain personal information about you (such as your name, email address, job title, company and telephone number) when you register with us to access the Platform, or where the business organisation you represent has provided us with your information to enable us to register you as the business contact for your organisation and enable you to access the Platform.
We will also obtain personal information about you when you use the Platform, send us feedback, post material, contact us for any reason and by any medium, sign up to a service/ notification, report a problem with the Platform or otherwise communicate with us.
We will not ask you to provide sensitive personal data and a condition of you using the Platform, and being granted access to the Platform, is that you will not put any such information relating to yourself or any other person within any communications you share with us, or include it within any information submitted on the Platform. Sensitive personal data (or otherwise called special categories of personal data) means information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation or any information relating to criminal convictions or offences on the Platform.
Where you upload or share information relating to third parties (for example, colleagues, suppliers or other business contacts), you confirm that you have the authority to do so on behalf of your organisation
We may retain a record of any contact you make with us.
2.2 Information about you that we will collect
Cookies
We may monitor your use of the Platform through the use of cookies and similar tracking devices. For example, we may monitor how many times you use the Platform, which pages you visit, and collect traffic data. This information helps us build a profile of our users.. Some of this data will be aggregated or statistical, which means that we will not be able to identify you individually. For further information on our use of cookies, please see the sections on cookies below. For more information on cookies and how they work please visit www.allaboutcookies.org.
Device information
We may also collect information about your device each time you use the Platform. For example, we may collect information on the type of device that you are using and its unique device identifier (for example, IP Address, the IMEI number, the device’s mobile phone number, or the MAC address of the device’s wireless network interface), the type of browser that you are using, the operating system that you are using, network information and the time zone setting.
IP addresses and similar identifiers may be considered personal data under applicable data protection laws.
2.3 Information from third parties
Where you are the representative of a business we interact with (for example your employer) that business may provide us with information about you such as name, email address, job title, role within organisation, address and telephone number to enable us to register you as the business contact for your organisation and enable you to access the Platform.
2.4 Log File
Each time you access the Platform, our servers automatically record certain information (“log files”). This may include your Internet Protocol (IP) address, browser type and version, Internet service provider, referring/exit pages, date/time stamps and clickstream data. We use these logs—always in aggregated or pseudonymised form—solely to administer and secure the Platform, analyse performance, and detect misuse.
We do not merge log-file data with other information in a way that could directly identify you.
3. HOW WE USE YOUR PERSONAL DATA
The purpose of the Platform is to provide you/ your organisation with a means to manage or view information in relation to the management of certain assets ("Assets") and as a repository of information relating to such Assets ("Asset Documentation")
The main purpose for which we use personal information relating to you is to provide you with access to the Platform.
We also use your personal data for the following purposes:
-
to communicate with you and respond to requests and inquiries;
-
to notify you of any changes to the Platform or to our services that may affect you
-
to create and administer accounts and log in access to our Platform;
-
to engage in transactions with you and your employer;
-
for identification, and authentication purposes;
-
for research, statistical analysis and behavioural analysis;
-
to deliver functionality on the Platforms including customising future use for you
-
for service improvement, research and to contact you for surveys;
-
to analyse, develop and improve the function and performance of the Platform;
-
to manage security and operation of the Platform, our networks and systems;
-
to comply with applicable laws and regulations in the operation of our business;
We do not share or sell to other organisations for commercial purposes any personally identifiable data, unless we have your permission.
3.2 What is our Lawful basis for using your information
Performance of a Contract You may have directly entered into a contract with us for the provision of certain services. In order for us to fulfil our obligations under such contract (e.g. to provide you with the Asset Documentation and for you to provide us with requisite information), we will need to collect, process and share (as further detailed below) your personal information, to register and communicate with you on and through the Platform.
Legitimate Interest If you are the business representative of an organisation who has entered into an agreement with us, or you have been granted access to the Platform by another organisation, we need to collect and process your personal data for our legitimate interests to enable us to provide you access to the Platform, and provide the Asset Documentation to the relevant users as required.
We also use your personal data as set out in this privacy policy for our legitimate interests to enable us:
-
to administer the Platform
-
for research, statistical analysis and behavioural analysis;
-
to deliver functionality on the Platform
-
for service improvement, research and to contact you for surveys;
-
to analyse, develop and improve the function and performance of the Platform;
-
to manage security and operation of the Platform, our networks and systems;
As indicated below, we may also pass your personal data to members of our group and other third parties and this is also for our legitimate business interests.
We are required to carry out a balancing test of our legitimate business interests in using your personal data outlined above against your interests and rights under the Data Protection Laws. As a result of our balancing test, which is detailed below, we have determined, acting reasonably and considering the circumstances, that we are able to process your personal data in accordance with the Data Protection Laws on the basis that we have a legitimate business interest.
Legitimate interest We have a legitimate interest in processing your information as: to grant you access to the Platform, to provide the Platform services and facilities, to the use of data to improve our services and the Platform.
Necessity: We consider that it is reasonable for us to process your personal data for the purposes of our legitimate interests outlined above as we process your personal data only so far as is necessary to achieve the purpose outlined in this Policy.
Impact of processing: We consider that it is reasonable for us to process your personal data for the purposes of our legitimate interests outlined above as the processing of your personal data does not unreasonably intrude on your privacy.
Consent
We do not expect to process your personal data subject to consent, however where we do so we will inform you of the purpose of processing, obtain your consent, and where given you will have the right to withdraw your consent to processing at any time by contacting us on the contact details provided at the beginning of this privacy policy.
By using our website and Platform, you acknowledge that you have read and understood this Privacy Policy.
Legal Duty
We will also process your personal data, as necessary, to comply with applicable laws and regulations in the operation of our business.
4. DISCLOSURE OF YOUR PERSONAL DATA
We may disclose your personal data to:
-
other companies within our group, but only for the purposes specified in this Policy;
-
a third party who acquires our business or acquires substantially all of our assets, in which case the personal data shall be one of the acquired assets;
-
our agents and service providers;
-
cloud infrastructure and technology providers (such as Amazon Web Services) used to host and operate the Platform;
-
law enforcement and regulatory agencies in connection with any investigation to help prevent unlawful activity or as otherwise required by applicable law;
4.1 Transfers outside of the European Economic Area
The information which we collect about you may be transferred outside Spain and/or the European Economic Area for the purposes providing users with technical support. We will ensure that any such transfer shall be made in accordance with data protection laws and that the level of data protection will be at least as protective as that required in Spain and the European Economic Area.
4.2 Keeping your data secure
Ensuring the security of your information is an important part of our business. We take commercially reasonable and appropriate security measures to protect against unauthorised access to or unauthorised alteration, disclosure or destruction of data.
While we will use all reasonable efforts to safeguard your personal data, you acknowledge that the use of the internet is not completely secure and for this reason we cannot guarantee the security or integrity of any personal data that are transferred from you or to you via the internet; any transmission is at your own risk.
You are responsible for maintaining the confidentiality of your login credentials and for ensuring that access to the Platform from your organisation is appropriately managed.
4.2.1 Encryption and Additional Safeguards
• Data in transit between your device and the Platform is protected with Transport Layer Security (TLS) 1.2 or higher (visible as “https” in your browser).
•Data at rest in Amazon S3 buckets, database snapshots and backups is encrypted with AES-256 keys managed through AWS Key Management Service (KMS).
Production systems are hosted in ISO 27001-certified data centres; physical and logical access is restricted to authorised personnel following the principle of least privilege and protected by multi-factor authentication.
We maintain continuous security monitoring and logging of access attempts and other relevant events in order to detect, investigate and mitigate unauthorised activity.
​
4.3 Monitoring
We may monitor and record communications with you such as emails for the purpose of quality assurance, training, and compliance.
5. DATA RETENTION
We may retain your personal data (provided for account creation and log in purposes) for as long as you continue to use the Platform, have an online account with us, or for the period your organisation confirms that you are the business representative for them in relation to the sharing, use and processing of Asset Documentation./ information, and typically for up to seven years after the termination of your online registration with us, in order to enable us to deal with any issues or concerns you may have about the Platform, and also to allow us to bring and defend legal proceedings, or for as long as is necessary to fulfil the purposes outlined above. For information contained within any content uploaded this will be retained as part of the service record history relating to the Asset for the life of the Asset and up to seven years after in order for us to have a complete history relating to the Asset and allow us to deal with any claims or issues or bring and defend any legal proceedings.
We may however retain personal data for an additional period as is permitted or required under applicable laws, for legal, tax or regulatory reasons, for legitimate and lawful business purposes and for our own internal audit and record keeping purposes.
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. We will only use personal data for a purpose that is materially different than the purpose for which it was collected where your explicit consent to the new purpose has been provided. Such consent will be obtained prior to further processing under the different purpose.
6. YOUR RIGHTS
You have a number of rights under the Data Protection Laws in relation to the way we process your personal data, which are set out below. You may contact us using the details at the beginning of this Policy to exercise any of these rights.
In some instances, we may be unable to carry out your request, in which case we will write to you to explain why.
1. You have the right to request access to your personal data You have the right to request confirmation that your personal data is being processed, access to your personal data (through us providing a copy) and other information about how we process your personal data.
2. You have the right to ask us to rectify your personal data You have the right to request that we rectify your personal data if it is not accurate or not complete.
3. You have the right to ask us to erase your personal data You have the right to ask us to erase or delete your personal data where there is no reason for us to continue to process your personal data. This right would apply if we no longer need to use your personal data to provide the debt management services to you, where you withdraw your consent for us to process special categories of your personal data, or where you object to the way we process your personal data (see right 6 below).
4. You have the right to ask us to restrict or block the processing of your personal data You have the right to ask us to restrict or block the processing of your personal data that we hold about you. This right applies where you believe the personal data is not accurate, you would rather we block the processing of your personal data rather than erase your personal data, where we don't need to use your personal data for the purpose we collected it for but you may require it to establish, exercise or defend legal claims.
5. You have the right to port your personal data You have the right to obtain and reuse your personal data from us to reuse for your own purposes across different services. This allows you to move personal data easily to another organisation, or to request us to do this for you.
6. You have the right to object to our processing of your personal data You have the right to object to our processing of your personal data on the basis of our legitimate business interests, unless we are able to demonstrate that, on balance, our legitimate interests override your rights or we need to continue processing your personal data for the establishment, exercise or defence of legal claims.
7. You have the right not to be subject to automated decisions You have the right to object to any automated decision making, including profiling, where the decision has a legal or significant impact on you.
8. You have the right to withdraw your consent You have the right to withdraw your consent where we are relying on it to use your personal data.
7. COMPLAINTS
If you have any concerns regarding our processing of your personal data, or are not satisfied with our handing of any request may by you, or would otherwise like to make a complaint, please contact our privacy contact at support@olenmro.com in the first instance using the details at the start of this Policy, so that they can do their very best to sort out the problem.
8. USE OF COOKIES
8.1 What is a cookie?
A cookie is a small text file which is placed onto your device when you access our Platform. We use cookies and other online tracking devices on our Platform for several purposes as described below. enable the Platform to remember choices you have previously made (for example language settings) where such devices are necessary to enable the functionality of the Platform and enable you
In some cases, we will need your consent in order to use cookies on the Platform. We obtain this through the pop up notice which appears when you navigate to the Platform. The exception is where the cookie is essential in order for us to provide you with a service you have requested (for example to enable you to log in to the Platform and enable you to view Documentation or upload information to us, and for us to communication with you).
If you wish to remove cookies placed on your device by our Platform or stop our Platform placing further cookies on your device, you can do this at any time through your browser by following the instructions at www.allaboutcookies.org.
8.2 What categories of cookies are used on the Platform?
Strictly necessary cookies.
These are cookies that are required for the operation of our Platform. They enable core functionality such as security, network management and accessibility. We do not require your consent to place these cookies. Nevertheless, you may be able to block these cookies yourself on your device/ browser, but restricting these cookies is likely to mean that our site will not work as you would expect and certain functionality may be inoperable.
Non-essential cookies
Analytical/performance cookies.
These allow us to recognise and count the number of visitors and to see how visitors move around our Platform when they are using it. This helps us to improve the way our Platform works, for example, by ensuring that users are finding what they are looking for easily.
Functionality cookies.
These are used to recognise you when you return to our site. This enables us to personalise our content for you, greet you by name and remember your preferences (for example, your choice of language or region).
OLEN does not knowingly collect any Personal Identifiable Information from children under the age of 16. If you think that your child provided this kind of information on our website, we strongly encourage you to contact us immediately and we will do our best efforts to promptly remove such information from our records.
9. OUR CONTACT DETAILS
In this privacy policy, the terms "we", "our", and "us" are used to refer to OLEN TECH LABS 2000, S.L. We welcome your feedback and questions. If you have any questions in relation to this policy or generally how your personal data is processed by us please contact our Data Protection Officer by email at support@olenmro.com
10. CHANGES TO THIS PRIVACY POLICY
We may change this Policy from time to time. You should check this Policy frequently to ensure you are aware of the most recent version that will apply each time you use the Platform.
​
