✈ FleetMargin Legal

Privacy Policy

Last updated 6 August 2026
← Back to FleetMargin
This is a working draft, not finished legal advice. It was written to accurately describe what this product actually does today, but it has not been reviewed by a lawyer. Before you rely on it with real paying customers — especially given GDPR and Finnish data protection law — have a qualified data protection lawyer review and finalize it. Sections likely to need their attention are marked [confirm with counsel].
Contents
  1. Who this policy covers
  2. Who controls this data
  3. Data about your account and team
  4. Data about companies and their people
  5. Why we're allowed to process it
  6. Who we share data with
  7. How long we keep it
  8. Your rights, and theirs
  9. Security
  10. Cookies and tracking
  11. Changes to this policy
  12. Contact

01Who this policy covers

FleetMargin is a B2B intelligence product for aviation MRO and parts companies. This policy covers two different groups of people, because we handle their data very differently:

  • Customers — people at a client company who log in and use the product.
  • Third parties in our data — named contacts, executives, and registrants at the airlines and MRO companies our data covers. These people are not our customers and have not signed up for anything; their information reaches us because it's published in a public source.

02Who controls this data

FleetMargin is operated by Datawings Oy, a Finnish osakeyhtiö (Oy — private limited company), business ID (Y-tunnus) 3644510-8, registered address Tähdenlento 11a, 20900 Turku, Finland. [confirm with counsel: PRH's public Trade Register (checked directly, 6 August 2026) currently lists this business ID's registered name as "datawings.com", not "Datawings Oy" — correct this directly with PRH/YTJ if it was a filing mistake, ideally while registration is still pending (it was still marked "Unregistered" as of this check, meaning the name may still be amendable). Reconfirm the final registered name matches what's used here once registration completes]. For the purposes of GDPR, this entity is the data controller for everything described below.

03Data about your account and team

When your organization uses FleetMargin, we hold:

  • Your work email address, used only to send you a one-time sign-in link and, if enabled, periodic alert digests.
  • Your organization name and seat count.
  • Login activity: when you last signed in, and a session record tied to your browser so you stay signed in.
  • The IP address of sign-in requests, kept briefly to prevent abuse of the login system.

We deliberately do not store a password for you, ever — sign-in is a one-time emailed link, not a password. There is no password database that could leak.

We do not currently collect payment card details ourselves; seat fees are invoiced directly. [confirm with counsel: update this section the moment any payment processor is integrated].

04Data about companies and their people

The core of the product is structured data about airlines and MRO companies, assembled from public sources: aviation registries operated by national authorities (such as the FAA, Australia's CASA, and Canada's civil aviation registry), regulatory filings and directives, aviation trade press, and companies' own public "leadership" or "about us" pages.

Some of this is personal data about identifiable people who are not our customers — for example, a named executive in a leadership-change article, a business contact listed on a company's own website, or an aircraft's registrant of record in a public registry. We do not collect anything from private accounts, paywalled sources, or LinkedIn — scraping LinkedIn is explicitly blocked in our own pipeline, not just avoided by convention.

Every fact we hold links back to where it came from. Where a fact is something we computed ourselves (for example, that an aircraft is entering a typical overhaul age window) rather than read from a source, it's labeled as computed, not presented as a citation.

05Why we're allowed to process it

For customer account data, our basis is performance of the contract with your organization (running the service you're paying for) and our legitimate interest in keeping the service secure.

For business-contact data about people who are not our customers, our intended basis is legitimate interest (GDPR Article 6(1)(f)) in providing business-to-business commercial intelligence from already-public sources, balanced against that person's own privacy interests. [confirm with counsel: this balancing test, and whether a formal Legitimate Interest Assessment should be documented, before relying on this basis for EU/UK data subjects].

06Who we share data with

We share data with a small number of service providers who process it on our behalf:

  • Resend — delivers our sign-in and digest emails, and so processes your email address for that purpose.
  • Our hosting provider — [not yet finalized — insert once chosen] — stores the database and runs the application.

We do not sell any data, and we do not share it with advertisers — the product has no advertising or ad-tracking of any kind.

Some of these providers may process data outside Finland or the EU. [confirm with counsel: check each provider's Data Processing Agreement and transfer mechanism — e.g. Standard Contractual Clauses — before going live].

07How long we keep it

Customer account data is kept for as long as your organization has an active subscription, plus a limited period afterward for accounting and legal purposes.

Business-contact and company data is generally retained to preserve a history of what changed and when — that history is part of what makes the product useful (for example, showing that a company's registrant or leadership changed). We have not yet defined a formal retention schedule for this data. [confirm with counsel: GDPR expects retention to be tied to a documented purpose and reviewed periodically — this needs a real policy, not indefinite-by-default storage].

08Your rights, and theirs

If you're a customer, or if you're a person who appears in our underlying company data, you can ask us to:

  • Tell you what we hold about you.
  • Correct it, if it's wrong.
  • Delete it, or object to our processing it — including if you're a business contact who was never our customer and would simply prefer not to be listed.

Reach us at the contact address below to make any of these requests. [confirm with counsel: response-time commitments — GDPR generally expects a response within one month].

09Security

Sessions use secure, HTTP-only cookies rather than a token your browser's JavaScript can read. Sign-in links are single-use and expire quickly. We don't store passwords, so there's no password database to steal.

10Cookies and tracking

The application uses exactly one cookie: a session cookie that keeps you signed in. It's functional, not advertising or analytics — this marketing site and the product currently run no third-party analytics or ad-tracking scripts at all. If that ever changes, this section will be updated first.

11Changes to this policy

If this policy changes in a material way, we'll update the date at the top of this page and, for signed-in customers, say so directly rather than relying on you to notice.

12Contact

Questions, requests, or objections about any of the above: heikkinenoliver8@gmail.com [swap for a dedicated business inbox, e.g. privacy@yourdomain, once one exists].

© 2026 FleetMargin. All rights reserved.
Home Terms of Service