FleetMargin is a B2B intelligence product for aviation MRO and parts companies. This policy covers two different groups of people, because we handle their data very differently:
FleetMargin is operated by Datawings Oy, a Finnish osakeyhtiö (Oy — private limited company), business ID (Y-tunnus) 3644510-8, registered address Tähdenlento 11a, 20900 Turku, Finland. [confirm with counsel: PRH's public Trade Register (checked directly, 6 August 2026) currently lists this business ID's registered name as "datawings.com", not "Datawings Oy" — correct this directly with PRH/YTJ if it was a filing mistake, ideally while registration is still pending (it was still marked "Unregistered" as of this check, meaning the name may still be amendable). Reconfirm the final registered name matches what's used here once registration completes]. For the purposes of GDPR, this entity is the data controller for everything described below.
When your organization uses FleetMargin, we hold:
We deliberately do not store a password for you, ever — sign-in is a one-time emailed link, not a password. There is no password database that could leak.
We do not currently collect payment card details ourselves; seat fees are invoiced directly. [confirm with counsel: update this section the moment any payment processor is integrated].
The core of the product is structured data about airlines and MRO companies, assembled from public sources: aviation registries operated by national authorities (such as the FAA, Australia's CASA, and Canada's civil aviation registry), regulatory filings and directives, aviation trade press, and companies' own public "leadership" or "about us" pages.
Some of this is personal data about identifiable people who are not our customers — for example, a named executive in a leadership-change article, a business contact listed on a company's own website, or an aircraft's registrant of record in a public registry. We do not collect anything from private accounts, paywalled sources, or LinkedIn — scraping LinkedIn is explicitly blocked in our own pipeline, not just avoided by convention.
Every fact we hold links back to where it came from. Where a fact is something we computed ourselves (for example, that an aircraft is entering a typical overhaul age window) rather than read from a source, it's labeled as computed, not presented as a citation.
For customer account data, our basis is performance of the contract with your organization (running the service you're paying for) and our legitimate interest in keeping the service secure.
For business-contact data about people who are not our customers, our intended basis is legitimate interest (GDPR Article 6(1)(f)) in providing business-to-business commercial intelligence from already-public sources, balanced against that person's own privacy interests. [confirm with counsel: this balancing test, and whether a formal Legitimate Interest Assessment should be documented, before relying on this basis for EU/UK data subjects].
We share data with a small number of service providers who process it on our behalf:
We do not sell any data, and we do not share it with advertisers — the product has no advertising or ad-tracking of any kind.
Some of these providers may process data outside Finland or the EU. [confirm with counsel: check each provider's Data Processing Agreement and transfer mechanism — e.g. Standard Contractual Clauses — before going live].
Customer account data is kept for as long as your organization has an active subscription, plus a limited period afterward for accounting and legal purposes.
Business-contact and company data is generally retained to preserve a history of what changed and when — that history is part of what makes the product useful (for example, showing that a company's registrant or leadership changed). We have not yet defined a formal retention schedule for this data. [confirm with counsel: GDPR expects retention to be tied to a documented purpose and reviewed periodically — this needs a real policy, not indefinite-by-default storage].
If you're a customer, or if you're a person who appears in our underlying company data, you can ask us to:
Reach us at the contact address below to make any of these requests. [confirm with counsel: response-time commitments — GDPR generally expects a response within one month].
Sessions use secure, HTTP-only cookies rather than a token your browser's JavaScript can read. Sign-in links are single-use and expire quickly. We don't store passwords, so there's no password database to steal.
The application uses exactly one cookie: a session cookie that keeps you signed in. It's functional, not advertising or analytics — this marketing site and the product currently run no third-party analytics or ad-tracking scripts at all. If that ever changes, this section will be updated first.
If this policy changes in a material way, we'll update the date at the top of this page and, for signed-in customers, say so directly rather than relying on you to notice.
Questions, requests, or objections about any of the above: heikkinenoliver8@gmail.com [swap for a dedicated business inbox, e.g. privacy@yourdomain, once one exists].