Data Processing Addendum
Draft data processing addendum for customer-specific processing under GDPR.
Draft version: 2026-07-20
This is a pre-launch draft intended for platform evaluation and testing. It will be reviewed and updated before Aeroclaim becomes commercially available.
Structure and applicability
This Data Processing Addendum applies where the Operator processes personal data as processor on behalf of a business customer acting as controller. It does not apply to processing for which the Operator acts as independent controller, including account administration, security, legal compliance, audit logs and platform operation.
The parties shall identify the controller, processor, processing subject matter, categories of data, categories of data subjects, duration and instructions in the applicable order form, master agreement or onboarding documentation.
Documented instructions
The Operator shall process processor personal data only on documented instructions from the controller unless required by applicable law. The Platform functionality, customer configuration, uploaded content, support requests and written instructions constitute documented instructions.
The Operator shall promptly inform the controller if, in its opinion, an instruction infringes applicable data protection law, unless prohibited by law.
Confidentiality and personnel
The Operator shall ensure that persons authorised to process processor personal data are bound by confidentiality obligations or are subject to an appropriate statutory obligation of confidentiality.
Access shall be limited to personnel and subprocessors requiring access for Platform operation, support, security, maintenance, compliance or customer-requested services.
Security measures
The Operator shall implement appropriate technical and organisational measures considering the nature, scope, context and purposes of processing and the risks to individuals. Measures should include authentication, role-based access, audit logging, document access logs, encrypted transport, backups, least privilege and incident response.
Before production deployment, the Operator should complete a security hardening review covering private object storage, malware scanning, secrets management, monitoring, backup restoration, access reviews and vulnerability management.
Subprocessors
The controller grants general authorisation for subprocessors necessary to provide hosting, database, object storage, email, analytics, support, security and infrastructure services, subject to a production subprocessor list and appropriate flow-down data protection obligations.
The Operator remains responsible for subprocessor performance to the extent required by applicable data protection law.
Assistance, deletion and return
The Operator shall reasonably assist the controller with data subject requests, security obligations, breach assessment, data protection impact assessments and regulatory consultations, taking into account the nature of processing and information available to the Operator.
Upon termination, processor personal data shall be returned or deleted according to the customer agreement, except where retention is required or permitted for legal claims, audit logs, aviation traceability, export-control records, security, fraud prevention or statutory obligations.
