1Who we are
Airlens Ltd is an Irish-registered company (CRO No. 580860) with its registered office at Tipperary, Ireland, Eircode E34 TP89.
We develop and operate Passerello® — a Bluetooth-based access control system for yacht passerelles and bathing platforms, comprising a hardware controller, an iOS application, and this web portal at airlens.ie.
Airlens Ltd is the Data Controller for all personal data processed through the Passerello® system. We are subject to the General Data Protection Regulation (GDPR) as applied in Ireland and supervised by the Data Protection Commission (DPC).
Contact for data protection matters: info@airlens.ie
2What data we collect
We collect only the data necessary to operate the Passerello® system. We do not collect data for advertising or marketing purposes.
| Category | Data collected | Source |
|---|---|---|
| Owner account | Name, email address, language preference, account creation date, last login date | Provided by Airlens Ltd on purchase |
| Customer / billing | Company name, contact name, email, phone, billing address, invoice records | Provided by customer or collected at sale |
| User credentials | User ID (chosen by owner — may be a name), access expiry date, hashed access key | Created by vessel owner via the portal or app |
| Login activity | IP address, login date/time, success/failure status | Automatically recorded on each login attempt |
| Contact form | Name, email address, message content | Submitted voluntarily via the contact form |
| Device telemetry | Controller hardware ID, firmware version, last connection timestamp, vessel name | Automatically recorded when the iOS app connects to the controller |
We do not collect: payment card data (invoicing is handled directly), location data, biometric data, or any special category data under Article 9 GDPR.
Crew members who receive a provisioning link are identified only by a User ID chosen by the vessel owner — this may or may not be a real name. We do not collect email addresses or contact details for crew members.
3How we use your data
- To operate the Passerello® system — provisioning access credentials to authorised users, managing the controller, syncing user lists over Bluetooth
- To manage your owner account — authentication, account activation, password reset, language preferences
- To issue invoices — billing records, warranty tracking (first activation date + 2 years), statutory record-keeping
- To provide support — responding to contact form enquiries and technical support requests
- To maintain security — login audit logs to detect and prevent unauthorised access
- To meet legal obligations — retaining financial records as required by Irish company and tax law
We do not use your data for marketing, profiling, automated decision-making, or any purpose other than those listed above.
4Legal basis for processing
| Processing activity | Legal basis (GDPR Article 6) |
|---|---|
| Operating the Passerello® access control system | Article 6(1)(b) — Performance of a contract |
| Owner account management | Article 6(1)(b) — Performance of a contract |
| Issuing invoices and billing records | Article 6(1)(c) — Legal obligation (Companies Act, Tax legislation) |
| Login security audit logs | Article 6(1)(f) — Legitimate interests (preventing unauthorised access) |
| Responding to contact form enquiries | Article 6(1)(b) — Pre-contractual steps / Article 6(1)(f) — Legitimate interests |
5How long we keep your data
| Data category | Retention period | Reason |
|---|---|---|
| Owner account data | Duration of active account + 2 years after last login | Service operation; post-termination support |
| Customer and invoice records | 7 years from invoice date | Irish Revenue Commissioners requirement |
| Login audit logs | 90 days | Security monitoring; automatically purged |
| Provisioning tokens | 24 hours (or until used) | Single-use, short-lived by design |
| Contact form messages | Not stored — delivered by email only | No database record created |
| User credentials on device | Until removed by vessel owner or account deletion | Service operation |
When data is no longer required, it is deleted from our systems. Invoice records subject to a legal retention obligation are retained for the minimum required period and then deleted.
6Who we share data with
We do not sell, rent or share your personal data with third parties for their own purposes.
Access to personal data held in the Passerello® system is restricted to authorised Airlens Ltd staff only. No third-party processors (cloud services, analytics providers, marketing platforms) are used in the operation of this system.
We may disclose data where required to do so by law, court order, or at the request of a competent regulatory authority.
7Where your data is stored
All personal data is stored on servers located within the European Union. Our hosting infrastructure is operated via Plesk on an EU-based server. No personal data is transferred to countries outside the European Economic Area (EEA).
8Your rights
Under GDPR, you have the following rights in relation to your personal data:
To exercise any of these rights, contact us at info@airlens.ie. We will respond within 30 days. We may need to verify your identity before processing a request.
Owner portal users may request deletion of their account directly from within the portal via the Account & Data section.
If you are not satisfied with our response, you have the right to lodge a complaint with the Data Protection Commission (DPC):
- Website: www.dataprotection.ie
- Email: info@dataprotection.ie
- Phone: +353 57 868 4800
9Security
We take the security of your personal data seriously and implement appropriate technical and organisational measures, including:
- All passwords stored as bcrypt hashes — plain text passwords are never stored
- All data transmitted over HTTPS/TLS
- Access to the admin system requires authentication with brute-force protection
- Login audit logging to detect unauthorised access attempts
- Provisioning tokens are single-use and expire within 24 hours
- Owner accounts are isolated from internal staff accounts — separate tables, separate authentication
- PDF invoices served via authenticated download — not directly web-accessible
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission within 72 hours of becoming aware of the breach, and will notify affected individuals without undue delay where required.
10Cookies & website analytics
The public Passerello® website sets one functional cookie only:
passerello_lang, which remembers your chosen language for 30 days.
The owner portal additionally uses strictly necessary session cookies to maintain
your login. None of these are used for tracking, analytics or advertising, and no
consent banner is required for strictly necessary and functional cookies.
Website analytics. To understand how our website is used, we count page views using our own first-party, cookieless system, on the basis of our legitimate interest in operating and improving the site. For each page view we record the page visited, your language, the referring website's domain, and a broad device category. We do not set any analytics cookies and we do not store your IP address, your user agent, or any identifier that could recognise you across days: visitor numbers are estimated using a salted hash that is cryptographically discarded daily. This data never leaves our own server and is never shared with any third party.
We do not use Google Analytics or any third-party analytics, advertising cookies, or persistent tracking of any kind.
11Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The "Last updated" date at the top of this page indicates when it was most recently revised.
For significant changes affecting your rights, we will notify active owner portal users by email before the changes take effect.
12Contact us
Data Controller: Airlens Ltd
Registered number: CRO 580860
Address: Tipperary, Ireland, E34 TP89
Email: info@airlens.ie
Phone: +353 62 54514
For data protection enquiries, please use the email address above and include "Data Protection" in the subject line. We aim to respond within 5 business days.