Policy Center

Data Processing Addendum

Last updated:Jul 20, 2026
Back

Data Processing Addendum

Draft data processing addendum for customer-specific processing under GDPR.

Draft version: 2026-07-20

Important legal note

This is a pre-launch draft intended for platform evaluation and testing. It will be reviewed and updated before Aeroclaim becomes commercially available.

Project owner and status
Aeroclaim is an independently owned, early-stage B2B aviation marketplace project based in Croatia.
Owner: Mario Matošević
Country: Croatia
Contact: info@aeroclaim.aero
The platform is currently under development and is not yet available for production use or live commercial transactions.
Legal operator details and final Terms of Service will be updated before commercial launch.
Clause 1

Structure and applicability

This Data Processing Addendum applies where the Operator processes personal data as processor on behalf of a business customer acting as controller. It does not apply to processing for which the Operator acts as independent controller, including account administration, security, legal compliance, audit logs and platform operation.

The parties shall identify the controller, processor, processing subject matter, categories of data, categories of data subjects, duration and instructions in the applicable order form, master agreement or onboarding documentation.

Clause 2

Documented instructions

The Operator shall process processor personal data only on documented instructions from the controller unless required by applicable law. The Platform functionality, customer configuration, uploaded content, support requests and written instructions constitute documented instructions.

The Operator shall promptly inform the controller if, in its opinion, an instruction infringes applicable data protection law, unless prohibited by law.

Clause 3

Confidentiality and personnel

The Operator shall ensure that persons authorised to process processor personal data are bound by confidentiality obligations or are subject to an appropriate statutory obligation of confidentiality.

Access shall be limited to personnel and subprocessors requiring access for Platform operation, support, security, maintenance, compliance or customer-requested services.

Clause 4

Security measures

The Operator shall implement appropriate technical and organisational measures considering the nature, scope, context and purposes of processing and the risks to individuals. Measures should include authentication, role-based access, audit logging, document access logs, encrypted transport, backups, least privilege and incident response.

Before production deployment, the Operator should complete a security hardening review covering private object storage, malware scanning, secrets management, monitoring, backup restoration, access reviews and vulnerability management.

Clause 5

Subprocessors

The controller grants general authorisation for subprocessors necessary to provide hosting, database, object storage, email, analytics, support, security and infrastructure services, subject to a production subprocessor list and appropriate flow-down data protection obligations.

The Operator remains responsible for subprocessor performance to the extent required by applicable data protection law.

Clause 6

Assistance, deletion and return

The Operator shall reasonably assist the controller with data subject requests, security obligations, breach assessment, data protection impact assessments and regulatory consultations, taking into account the nature of processing and information available to the Operator.

Upon termination, processor personal data shall be returned or deleted according to the customer agreement, except where retention is required or permitted for legal claims, audit logs, aviation traceability, export-control records, security, fraud prevention or statutory obligations.