ENFRITDEES
Airlens Ltd

Privacy Policy

Passerello® — Smart Passerelle Control System

Last updated: 03 October 2026

1Who we are

Airlens Ltd is an Irish-registered company (CRO No. 580860) with its registered office at Tipperary, Ireland, Eircode E34 TP89.

We develop and operate Passerello® — a Bluetooth-based access control system for yacht passerelles and bathing platforms, comprising a hardware controller, an iOS application, and this web portal at airlens.ie.

Airlens Ltd is the Data Controller for all personal data processed through the Passerello® system. We are subject to the General Data Protection Regulation (GDPR) as applied in Ireland and supervised by the Data Protection Commission (DPC).

Contact for data protection matters: info@airlens.ie

2What data we collect

We collect only the data necessary to operate the Passerello® system. We do not collect data for advertising or marketing purposes.

Category Data collected Source
Owner account Name, email address, language preference, account creation date, last login date Provided by Airlens Ltd on purchase
Customer / billing Company name, contact name, email, phone, billing address, invoice records Provided by customer or collected at sale
User credentials User ID (chosen by owner — may be a name), access expiry date, hashed access key Created by vessel owner via the portal or app
Login activity IP address, login date/time, success/failure status Automatically recorded on each login attempt
Contact form Name, email address, message content Submitted voluntarily via the contact form
Device telemetry Controller hardware ID, firmware version, last connection timestamp, vessel name Automatically recorded when the iOS app connects to the controller

We do not collect: payment card data (invoicing is handled directly), location data, biometric data, or any special category data under Article 9 GDPR.

Crew members who receive a provisioning link are identified only by a User ID chosen by the vessel owner — this may or may not be a real name. We do not collect email addresses or contact details for crew members.

3How we use your data

  • To operate the Passerello® system — provisioning access credentials to authorised users, managing the controller, syncing user lists over Bluetooth
  • To manage your owner account — authentication, account activation, password reset, language preferences
  • To issue invoices — billing records, warranty tracking (first activation date + 2 years), statutory record-keeping
  • To provide support — responding to contact form enquiries and technical support requests
  • To maintain security — login audit logs to detect and prevent unauthorised access
  • To meet legal obligations — retaining financial records as required by Irish company and tax law

We do not use your data for marketing, profiling, automated decision-making, or any purpose other than those listed above.

4Legal basis for processing

Processing activityLegal basis (GDPR Article 6)
Operating the Passerello® access control system Article 6(1)(b) — Performance of a contract
Owner account management Article 6(1)(b) — Performance of a contract
Issuing invoices and billing records Article 6(1)(c) — Legal obligation (Companies Act, Tax legislation)
Login security audit logs Article 6(1)(f) — Legitimate interests (preventing unauthorised access)
Responding to contact form enquiries Article 6(1)(b) — Pre-contractual steps / Article 6(1)(f) — Legitimate interests

5How long we keep your data

Data categoryRetention periodReason
Owner account data Duration of active account + 2 years after last login Service operation; post-termination support
Customer and invoice records 7 years from invoice date Irish Revenue Commissioners requirement
Login audit logs 90 days Security monitoring; automatically purged
Provisioning tokens 24 hours (or until used) Single-use, short-lived by design
Contact form messages Not stored — delivered by email only No database record created
User credentials on device Until removed by vessel owner or account deletion Service operation

When data is no longer required, it is deleted from our systems. Invoice records subject to a legal retention obligation are retained for the minimum required period and then deleted.

6Who we share data with

We do not sell, rent or share your personal data with third parties for their own purposes.

Access to personal data held in the Passerello® system is restricted to authorised Airlens Ltd staff only. No third-party processors (cloud services, analytics providers, marketing platforms) are used in the operation of this system.

We may disclose data where required to do so by law, court order, or at the request of a competent regulatory authority.

7Where your data is stored

All personal data is stored on servers located within the European Union. Our hosting infrastructure is operated via Plesk on an EU-based server. No personal data is transferred to countries outside the European Economic Area (EEA).

8Your rights

Under GDPR, you have the following rights in relation to your personal data:

Right of access
Request a copy of the personal data we hold about you (Article 15).
Right to rectification
Request correction of inaccurate or incomplete data (Article 16).
Right to erasure
Request deletion of your personal data where there is no legal obligation to retain it (Article 17).
Right to restriction
Request that we restrict processing of your data in certain circumstances (Article 18).
Right to portability
Receive your data in a structured, machine-readable format (Article 20).
Right to object
Object to processing based on legitimate interests (Article 21).

To exercise any of these rights, contact us at info@airlens.ie. We will respond within 30 days. We may need to verify your identity before processing a request.

Owner portal users may request deletion of their account directly from within the portal via the Account & Data section.

If you are not satisfied with our response, you have the right to lodge a complaint with the Data Protection Commission (DPC):

9Security

We take the security of your personal data seriously and implement appropriate technical and organisational measures, including:

  • All passwords stored as bcrypt hashes — plain text passwords are never stored
  • All data transmitted over HTTPS/TLS
  • Access to the admin system requires authentication with brute-force protection
  • Login audit logging to detect unauthorised access attempts
  • Provisioning tokens are single-use and expire within 24 hours
  • Owner accounts are isolated from internal staff accounts — separate tables, separate authentication
  • PDF invoices served via authenticated download — not directly web-accessible

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission within 72 hours of becoming aware of the breach, and will notify affected individuals without undue delay where required.

10Cookies & website analytics

The public Passerello® website sets one functional cookie only: passerello_lang, which remembers your chosen language for 30 days. The owner portal additionally uses strictly necessary session cookies to maintain your login. None of these are used for tracking, analytics or advertising, and no consent banner is required for strictly necessary and functional cookies.

Website analytics. To understand how our website is used, we count page views using our own first-party, cookieless system, on the basis of our legitimate interest in operating and improving the site. For each page view we record the page visited, your language, the referring website's domain, and a broad device category. We do not set any analytics cookies and we do not store your IP address, your user agent, or any identifier that could recognise you across days: visitor numbers are estimated using a salted hash that is cryptographically discarded daily. This data never leaves our own server and is never shared with any third party.

We do not use Google Analytics or any third-party analytics, advertising cookies, or persistent tracking of any kind.

11Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The "Last updated" date at the top of this page indicates when it was most recently revised.

For significant changes affecting your rights, we will notify active owner portal users by email before the changes take effect.

12Contact us

Data Controller: Airlens Ltd

Registered number: CRO 580860

Address: Tipperary, Ireland, E34 TP89

Email: info@airlens.ie

Phone: +353 62 54514

For data protection enquiries, please use the email address above and include "Data Protection" in the subject line. We aim to respond within 5 business days.

← Back to Passerello®