Legal information
Privacy policy
These notes explain which data is processed when you visit our website, why it is needed and the rights available to you.
Last updated:
Who is responsible
The controller for this website is WF Steuerungstechnik GmbH, Zeppelinstraße 7–9, 75446 Wiernsheim, Germany. Contact: info@airleader.de or +49 (0) 7044 911 100.
This notice covers the public Airleader website, including its test address. Further processing within personal portal accounts, of plant and customer data and within the separate software download portal is outside the scope of this notice.
Visiting pages and downloading files
Your browser sends connection data needed to deliver a page or download. This includes your IP address, the time and requested address, browser and device information and, where applicable, the referring page. Content cannot be delivered without the data necessary for the connection.
We use Amazon Web Services (AWS), including Amazon S3 and the Amazon CloudFront content delivery network. The website origin is in the Frankfurt AWS region. CloudFront uses a global network; this does not mean that all connection data is processed exclusively in Germany or the EU.
The purposes are secure, reliable and fast delivery and the detection and prevention of faults and misuse. The legal basis is Article 6(1)(f) GDPR, reflecting our legitimate interest in securely operating this information service. The website and downloads cannot be retrieved without the data necessary for the connection.
Providers and international processing
Our hosting provider is Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg (AWS). Processing on our behalf is governed by the AWS Data Processing Addendum (DPA) and supplementary data protection provisions incorporated into the AWS contractual terms. AWS also uses affiliated companies and subprocessors to provide its services.
Global CloudFront delivery and the provision of AWS services may involve processing connection data outside the European Economic Area, particularly in the United States. Where a transfer is not covered by an applicable European Commission adequacy decision, the AWS contractual terms provide for EU Standard Contractual Clauses as safeguards under Article 46 GDPR. You may request information about the safeguards relevant to our processing, and a copy of them, at info@airleader.de. Links to the AWS data processing agreement and subprocessor list are provided below.
Account icon and portal connection
The website asks the Airleader portal whether you are signed in when it loads and again, for example, when you return to the browser window. Necessary connection data and any existing portal session cookies are sent to the portal. The website receives only a signed-in or signed-out status, not names, email addresses or plant data.
This display helps you find your personal access. Personal data processing for the status display is based on Article 6(1)(f) GDPR; our legitimate interest is convenient access to customer accounts. The status is not used for advertising or audience measurement.
Opening the sign-in page starts the personal portal login process. The portal uses secure sessions and additional authentication. The account and operational data involved are separate from simply visiting the public website.
Local learning progress, not advertising tracking
The public website currently integrates no advertising trackers, Google Analytics or embedded external analytics or marketing services. Fonts, images and scripts are served by the website itself. Existing portal cookies may be used for the status request described above.
The interactive fundamentals course stores completed modules and answers in your browser's local storage under airleader-fundamentals-progress. This function does not send them to our server. Course calculations also run in your browser. Progress remains until you delete the site's browser data; the course still works without available local storage.
The purpose is to resume the course you opened on the same device. Where personal data is processed, we rely on Article 6(1)(f) GDPR; our legitimate interest is a resumable course. You can delete your progress by clearing this website’s browser data or restrict local storage in your browser settings.
Contact and training enquiries
Phone and email links open your phone or email application. Clicking does not send a message. Training dates can prefill an email with the course type and date; you choose what to add and whether to send it.
When you contact us, we process your contact details, message and any documents you provide to handle your enquiry. Article 6(1)(b) GDPR applies where processing is necessary for a contract with you or steps taken at your request before entering into a contract. For other enquiries and communication with company representatives, we rely on Article 6(1)(f) GDPR; our legitimate interest is handling business enquiries. An enquiry does not subscribe you to a newsletter.
Access is limited to the people handling your request and the providers supporting communication and IT operations, as needed. Providing this information is voluntary. Without sufficient contact details and information about your request, we may be unable to help. Please send only information required for the request. In particular, remove unnecessary personal information and access credentials from support data archives before sending them.
Retention and deletion
Data is processed only as long as necessary for its purpose or required by statutory retention duties. Enquiries are deleted when completed unless further handling, a legal duty or legitimate defence of claims requires retention. Relevant criteria are the content of the correspondence, the resulting business relationship and applicable statutory retention and limitation periods. Statutory retention is based on Article 6(1)(c) GDPR; necessary retention to protect legal claims is based on Article 6(1)(f) GDPR.
Classic CloudFront access logs are disabled in the reviewed website configuration. This does not mean AWS processes no technical data. Portal function logs are scheduled for deletion after 7 or 30 days depending on the function; these are not deletion periods for portal accounts or business correspondence. Where technical data is needed to investigate a fault or security incident, further retention depends on the necessary investigation and, where applicable, the protection of legal claims.
Links to other services
The website links to demonstrations, software downloads and further information. External content is not automatically embedded by these links. When you open a link, the destination provider processes connection data under its own terms. The existing software download portal still requires separate credentials; signing into the Airleader portal does not automatically sign you in there.
Your rights and right to object
Subject to the GDPR, you may request access, rectification, erasure or restriction of processing. You have a right to data portability where its conditions apply. You may withdraw consent at any time with effect for the future.
Where processing is based on Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation. You may object to processing for direct marketing at any time. Contact info@airleader.de to do so.
You may complain to a supervisory authority, particularly in the country of your residence, workplace or the alleged infringement. The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg is a contact for our company in Baden-Württemberg.
Visiting the public website does not involve automated decisions with legal or similarly significant effects. These notes will be reviewed when functions or providers change.
Supervisory authority: complaints ↗