SCADAR.NET Privacy Policy
Last
updated: 30th September 2025
SCADAR.NET Privacy Policy
This Privacy Policy applies to SCADAR.NET and to any branded or white-label version of the SCADAR.NET platform operated or provided by CMC NV. This includes, but is not limited to:
- Stand-alone domains such as air-insite.com, and
- Sub-domains or branded instances such as elgi.scadar.net.
- All such variants operate under the same data protection principles, policies, and governance as defined in this Privacy Policy.
This
Privacy Policy explains how CMC NV (“we,” “us,” “our”) collects, uses,
and protects personal data when you use SCADAR.NET.
1. Who We Are
SCADAR.NET
is operated by CMC NV, registered in Belgium. We act as the data controller
for personal data processed in connection with SCADAR.NET.
2. Data We Collect
We may
collect:
Account information
: name, email address,
organisation details, login credentials.
Usage data
: activity within SCADAR.NET
(e.g. audits created, reports generated).
Device/technical data
: IP address, browser,
operating system, cookies.
Billing data
: payment and invoicing
details (where applicable).
Uploaded content
: data, reports, or
documents you choose to upload.
3. How We Use Your Data
We
process personal data to:
Deliver and manage your
SCADAR.NET subscription.
Provide support and respond
to enquiries.
Improve and develop the
platform (including anonymised analytics).
Manage billing, payments,
and account administration.
Comply with legal obligations.
4. Legal Bases for Processing
We rely
on the following legal grounds under GDPR/UK GDPR:
Performance of a contract
(to provide SCADAR.NET to you).
Legitimate interests (to
improve services, prevent misuse, maintain security).
Legal obligations (tax,
compliance, regulatory reporting).
Consent (where required,
e.g. for certain marketing communications).
5. Data Sharing
We do not
sell personal data. We may share it with:
6. Data hosting
Data is primarily hosted in
the EU/EEA.
7. Data Retention
Account data: retained for
the duration of your subscription and deleted within 12 months after
termination (unless required for legal or financial records).
Audit/log data: retained per
the quotas/limits in your subscription tier (see Annex A).
Backups: securely maintained
for disaster recovery, then overwritten.
8. Your Rights
Under
GDPR/UK GDPR, you have rights to:
Access your data.
Correct inaccurate data.
Request deletion (“right to
be forgotten”).
Restrict or object to
processing.
Request data portability.
Withdraw consent (where
processing is based on consent).
Requests
can be made via our support portal or by contacting us (see below).
9. Security
We
implement appropriate technical and organisational measures to protect data
against loss, misuse, and unauthorised access.
10. Contact Us