1. Scope and precedence
- This Data Processing Agreement (“DPA”) forms part of the Terms of Service between [Legal entity name] trading as Wingcert (“Processor”, “we”) and the Customer identified on the Order Form (“Controller”, “you”).
- It applies to all processing of personal data we carry out on your behalf in providing the Service.
- In case of conflict on data protection matters, this DPA prevails over the Terms of Service. The Standard Contractual Clauses, where they apply, prevail over both.
- No signature is required: this DPA takes effect automatically when you accept the Terms of Service. A countersigned copy is available on request for your records.
2. Definitions
Controller, processor, data subject, personal data, personal data breach, processing and supervisory authority have the meanings given in the GDPR.
- Data Protection Law
- Regulation (EU) 2016/679 (GDPR), the UK GDPR and Data Protection Act 2018 where applicable, Directive 2002/58/EC as implemented nationally, and any other applicable data protection law.
- Customer Personal Data
- Personal data contained in Customer Data, which we process on your behalf under the Agreement.
- SCCs
- The Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914.
- Sub-processor
- Any processor we engage to process Customer Personal Data.
3. Roles and instructions
- You are the controller and we are the processor in respect of Customer Personal Data. Where you are yourself a processor for a third-party controller, you warrant that you have the authority to give the instructions in this DPA.
- We process Customer Personal Data only on your documented instructions, including as to transfers, unless required to do otherwise by Union or Member State law. Where such a legal requirement applies, we will inform you before processing unless that law prohibits it on important grounds of public interest.
- Your documented instructions are: this DPA, the Terms of Service, the Order Form, the configuration you apply within the Service, and any further written instruction you give that is consistent with them.
- We will inform you if, in our opinion, an instruction infringes Data Protection Law. We may suspend the affected processing until the instruction is confirmed, withdrawn or amended.
- The subject matter, duration, nature and purpose of processing, the types of personal data and the categories of data subjects are set out in Annex I.
4. Our obligations as processor
We comply with Article 28(3) GDPR. Specifically we will:
- process Customer Personal Data only on your documented instructions (clause 3);
- ensure that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality, whether contractual or statutory, that survives the end of their engagement;
- implement and maintain the technical and organisational measures required by Article 32, as set out in Annex II, and not materially degrade them during the term;
- respect the conditions in clause 5 for engaging sub-processors;
- assist you, by appropriate technical and organisational measures and insofar as possible, in responding to requests to exercise data subject rights (clause 7);
- assist you in ensuring compliance with Articles 32 to 36, taking into account the nature of processing and the information available to us (clauses 6 and 8);
- at your choice, delete or return Customer Personal Data at the end of the provision of services, and delete existing copies unless law requires storage (clause 9); and
- make available all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits and inspections (clause 10).
We also maintain a record of processing carried out on your behalf, as required by Article 30(2), and make it available to a supervisory authority on request.
5. Sub-processors
- You give general written authorisation for us to engage sub-processors, subject to this clause.
- The sub-processors engaged at the effective date are listed in Annex III.
- We will give you at least [30] days' notice before adding or replacing a sub-processor, by email to your notification address and by updating Annex III. You may subscribe to notifications at [email protected].
- You may object on reasonable data protection grounds within that notice period. We will work with you in good faith to resolve the objection — by proposing a change to the processing, an alternative sub-processor, or a commercially reasonable workaround. If we cannot resolve it within [30] days, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused remainder of the term.
- We impose on each sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and we remain fully liable to you for the sub-processor's performance.
- Where a sub-processor is outside the EEA, we ensure an appropriate transfer mechanism under clause 11 is in place before any transfer.
6. Personal data breach
- We will notify you without undue delay, and in any event within [24] hours, after becoming aware of a personal data breach affecting Customer Personal Data.
-
Our notification will include, so far as available at the time:
- the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned;
- the name and contact details of our contact point for further information;
- the likely consequences of the breach; and
- the measures taken or proposed to address it and mitigate its effects.
- Where the information cannot be provided at once, we will provide it in phases without further undue delay, and will keep you updated [at least every 24 hours] until containment is confirmed.
- We will cooperate with you and take the reasonable steps you direct to assist your investigation, mitigation and remediation.
- Notification is not an acknowledgement of fault or liability.
- Assessing whether a breach must be notified to a supervisory authority under Article 33 or communicated to data subjects under Article 34 is your responsibility as controller. We will not notify a supervisory authority or data subjects on your behalf unless you instruct us in writing.
A single incident can trigger both Article 33 GDPR (72 hours to your supervisory authority) and IS.I.OR.230 Part-IS (72 hours to your competent authority, where there is a significant risk to aviation safety). Our [24]-hour commitment is set to leave you working time inside both. See Annex IV.
7. Data subject rights
- The Service provides functionality allowing you to access, correct, export and delete Customer Personal Data yourself. In most cases this is sufficient for you to respond to a data subject request without our involvement.
- Where it is not, we will provide reasonable assistance, taking into account the nature of processing and the information available to us.
- If we receive a request directly from a data subject relating to Customer Personal Data, we will not respond to it substantively. We will, without undue delay, tell the data subject to contact you and forward the request to you.
- We may charge a reasonable fee for assistance that is disproportionate to the nature of the request, having told you before incurring it.
8. Data protection impact assessments and prior consultation
Taking into account the nature of processing and the information available to us, we will provide reasonable assistance with your data protection impact assessments under Article 35 and any prior consultation with a supervisory authority under Article 36. This normally takes the form of the documentation described in clause 10.3 and written answers to your specific questions.
9. Deletion and return
- You may export Customer Personal Data in a structured, commonly used, machine-readable format at any time during the term, using the Service's own export functionality.
- For [60] days after termination or expiry we will retain Customer Personal Data and provide reasonable assistance with export.
- After that period we will delete Customer Personal Data from live systems, and from backups on the ordinary rotation cycle described in Annex II, unless Union or Member State law requires storage. Data pending deletion from backups remains encrypted and is not processed for any other purpose.
- We will certify deletion in writing on request.
- Where you must retain records to satisfy an aviation regulatory retention obligation, you may instruct us in writing to retain them for a defined period; additional fees may apply.
10. Audits and inspections
- We will make available all information reasonably necessary to demonstrate compliance with Article 28 and this DPA.
- You may audit us, or appoint an independent auditor who is not our competitor and who is bound by confidentiality, once per twelve-month period — and additionally following a personal data breach affecting you, or where a supervisory authority or competent authority requires it.
- We may satisfy an audit request by providing current documentation — our security overview, ISMS scope statement, penetration test summary, completed security questionnaires or a third-party assessment report — where it fairly addresses the scope of your request. If it does not, the audit proceeds.
- Audits require [30] days' notice, take place during business hours, must not unreasonably disrupt our operations, and must not compromise the confidentiality or security of other customers' data.
- Each party bears its own audit costs. We may charge for assistance exceeding [X] person-days per audit at our then-current professional services rates, having told you before incurring it.
- Access exercised by a supervisory authority, or by your competent authority under Annex IV, is not subject to the frequency limit in clause 10.2 or the notice period in clause 10.4.
11. International transfers
- We host Customer Personal Data in the European Union by default and will not transfer it outside the EEA except in accordance with this clause.
-
Where a transfer to a third country occurs, it takes place only under:
- an adequacy decision under Article 45;
- the SCCs, incorporated by reference into this DPA and completed as set out in clause 11.3; or
- another mechanism under Chapter V GDPR.
-
Where the SCCs apply they are completed as follows:
- Module Two (controller to processor) applies between you and us; Module Three (processor to processor) applies between us and a sub-processor.
- Clause 7 (docking clause) applies.
- Clause 9: Option 2, general written authorisation, with the notice period in clause 5.3 of this DPA.
- Clause 11: the optional independent dispute resolution paragraph does not apply.
- Clause 17: governed by the law of [Member State].
- Clause 18(b): the courts of [Member State].
- Annex I, II and III of the SCCs are populated by Annex I, Annex II and Annex III of this DPA respectively.
- We have carried out a transfer impact assessment for each transfer and will make it available on request. Where local law would prevent us meeting the SCCs, we will inform you and, if no supplementary measure is sufficient, suspend the transfer.
- For personal data subject to the UK GDPR, the SCCs apply as modified by the UK International Data Transfer Addendum issued under section 119A of the Data Protection Act 2018.
12. Part-IS undertakings
Where you are subject to Commission Implementing Regulation (EU) 2023/203 or Commission Delegated Regulation (EU) 2022/1645, the undertakings in Annex IV apply in addition to the rest of this DPA and are given contractual force by it. They are drafted to let you discharge your obligation under IS.I.OR.235 in respect of the services we provide.
13. Liability
- Liability under this DPA is subject to the limitations and exclusions in clause 15 of the Terms of Service, except where Data Protection Law prohibits their application.
- Nothing in this DPA limits a data subject's rights under Article 82 GDPR, or either party's liability to a supervisory authority.
- Where the SCCs apply, nothing in this DPA limits liability in a way inconsistent with them.
14. Term and general
- This DPA takes effect with the Terms of Service and continues while we process Customer Personal Data on your behalf. Clauses that by their nature should survive, do.
- We may update this DPA where required by a change in Data Protection Law, a supervisory authority decision, or a change to the SCCs, on [30] days' notice. Updates will not materially reduce the protections it provides.
- If any provision is held invalid, the remainder continues in force.
- This DPA is governed by the law stated in clause 22 of the Terms of Service, subject to clause 11.3 where the SCCs apply.
Annex I — Details of processing
A. List of parties
| Data exporter (Controller) | Data importer (Processor) | |
|---|---|---|
| Name | The Customer named on the Order Form | [Legal entity name] t/a Wingcert |
| Address | As stated on the Order Form | [Registered address] |
| Contact | The data protection contact on the Order Form | [email protected] |
| Activities | Operation of an aviation organisation and its management system | Provision of the Wingcert compliance and safety management platform |
| Role | Controller | Processor |
B. Description of processing
| Categories of data subjects | Your personnel, including post-holders, managers, engineers, certifying staff, flight and cabin crew, auditors and administrative staff; contractors and agency personnel; personnel of your subcontracted organisations where you record them; individuals named in audit records, findings, occurrence reports and safety reports, including reporters. |
| Categories of personal data | Identification and contact data (name, employee number, work email, telephone); employment data (job title, department, post-holder nomination, line manager); qualification data (licences, type ratings, certifying-staff authorisations, training records, competency assessments and expiry dates); activity data (audit participation, findings raised and owned, corrective actions, document acknowledgements, electronic signatures); content data (free-text entries, photographic and documentary evidence); and system data (user identifiers, IP addresses, device and session data, audit trail entries). |
| Special categories | Not intended. The Service is not designed for Article 9 data. If you configure it to hold such data, you are responsible for establishing a lawful basis and an Article 9 condition, and for applying the additional restrictions in Annex II. [If you intend to support medical certificate tracking, this row must be revised and a DPIA carried out.] |
| Sensitive by context | Occurrence and hazard reports processed under Regulation (EU) No 376/2014, including reporter identity where not anonymised, which attract protection of information sources and just-culture obligations. |
| Nature and purpose | Hosting, storage, structuring, retrieval, transmission, backup and deletion of records, for the purpose of providing compliance monitoring, audit management, findings and corrective action tracking, document control, training and qualification management, risk and safety management, reporting, and related support. |
| Frequency | Continuous for the duration of the Agreement. |
| Duration | For the term of the Agreement, plus the retention and deletion periods in clause 9. |
| Sub-processor processing | As described in Annex III, for the duration of each sub-processor engagement. |
C. Competent supervisory authority
Determined under Article 3 of the SCCs. Where the exporter is established in the EU, the supervisory authority of the exporter's Member State. Our lead supervisory authority is [name of authority].
Annex II — Technical and organisational measures
Unlike the security page, this is a promise you can be sued on. Delete every measure not actually implemented today. An aspirational Annex II is a breach of contract waiting to be discovered during incident response.
| Measure | Implementation |
|---|---|
| Pseudonymisation and encryption | TLS 1.2+ in transit with HSTS enforced; AES-256 at rest for databases, object storage and backups. Passwords stored only as salted hashes using a memory-hard algorithm. |
| Confidentiality | Role-based access control modelled on post-holder structure; MFA available to all users and enforceable organisation-wide; least-privilege administrative access, logged and reviewed [quarterly]; confidentiality undertakings for all personnel. |
| Integrity | Append-only audit trail recording actor, action, object, timestamp and source address for every create, update, approve and delete. Peer review required for all production code changes. |
| Availability and resilience | Automated encrypted backups on a [daily] cycle with [35]-day retention, stored separately from production; RPO [1] hour, RTO [4] hours; offline-capable mobile application. |
| Restoration of availability | Documented disaster recovery procedures, with restore testing [at least annually] and results recorded. |
| Regular testing and evaluation | Automated dependency and secret scanning in the build pipeline; static analysis; independent penetration testing [annually]; annual review of the ISMS. [Remove any item not yet in place.] |
| Tenant separation | Every record carries its tenant identity and is filtered at the data-access layer, with isolation covered by automated tests on every build. |
| Access to premises and systems | Production infrastructure hosted with [provider] in [EU region], holding [certifications]. Databases are not reachable from the public internet. |
| Logging and monitoring | Centralised security logs retained [12] months, protected against modification by generating accounts; automated alerting on authentication anomalies, privilege changes and unusual export volumes. |
| Incident management | Documented incident response plan tested [annually]; customer notification within [24] hours per clause 6. |
| Personnel | Background screening proportionate to role where lawful; security awareness training at induction and annually; access revoked [within X hours] of departure. |
| Data minimisation and retention | Configurable retention per record type; deletion and return per clause 9. |
| Safety report protection | Access to reporter identity restrictable to a named safety manager role, separate from ordinary administrators; every access logged. |
| Sub-processor governance | Pre-engagement assessment, written Article 28 contracts, [annual] review, and the flow-down in clause 5.5. |
Annex III — Sub-processors
The following sub-processors are authorised at the effective date. We give [30] days' notice of changes under clause 5.3.
Every third party that can touch customer data must appear here, including hosting, email delivery, error monitoring, support desk and analytics. An incomplete list is one of the most common findings in a customer data protection audit.
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| [Hosting provider] | Infrastructure hosting and storage | [EU region] | Within EEA — none required |
| [Email delivery provider] | Transactional email (notifications, alerts) | [Location] | [SCCs / adequacy / N/A] |
| [Error monitoring provider] | Application error and performance monitoring | [Location] | [SCCs / adequacy / N/A] |
| [Support desk provider] | Customer support ticketing | [Location] | [SCCs / adequacy / N/A] |
| [Backup / object storage] | Encrypted backup storage | [EU region] | Within EEA — none required |
Annex IV — Part-IS schedule
This annex applies where you are subject to Commission Implementing Regulation (EU) 2023/203 or Commission Delegated Regulation (EU) 2022/1645. It exists so that you can demonstrate to your competent authority that the requirements of IS.I.OR.235 (or IS.D.OR.235) are met in respect of the services we provide.
1. Oversight
We acknowledge that we perform the contracted services under your oversight, and that responsibility for compliance with Part-IS remains yours. We will cooperate with your monitoring, including by completing questionnaires, attending review meetings at reasonable frequency, and responding to your findings.
2. Risk assessment support
We will provide the information you reasonably require to include our services in your information security risk assessment under IS.I.OR.205 — including a description of the interfaces between our systems and yours, a data-flow description, our hosting arrangements, and the controls in Annex II.
3. Competent authority access
We grant your competent authority, and EASA where it acts as competent authority, access upon request to the extent necessary to determine continued compliance with the applicable requirements. This includes access to relevant records, to personnel responsible for the services, and — where reasonably required and subject to appropriate safeguards for other customers' confidentiality — to our facilities. This right is not subject to the audit frequency limit in clause 10.2 or the notice period in clause 10.4.
4. Incident notification
We will notify you without undue delay, and in any event within [24] hours, of any information security incident or vulnerability affecting the Service that could plausibly represent a significant risk to aviation safety in your operation. We will provide the information reasonably available to us, and will continue to provide updates — including the recovery actions taken and the preventive measures identified — so that you can make both the report required within 72 hours under IS.I.OR.230 and the follow-up report that provision requires.
The decision whether a condition is reportable, and any report to your competent authority, remains yours.
5. Findings
Where your competent authority raises a finding under IS.I.OR.225 that concerns our services, we will support your response with the evidence, root cause information and remediation detail you require, within the timescale set by your authority.
6. Records
We retain records relating to information security risk assessments, incidents, training and reviews for [5] years, and will make those relating to the services provided to you available on request, supporting your obligation under IS.I.OR.245.
7. Flow-down
We impose obligations equivalent to sections 3 and 4 of this annex on any sub-processor or sub-contractor material to the security of the Service.
8. Changes
We will notify you of changes to the Service or to our infrastructure that materially affect the information security risk picture you have assessed, with reasonable notice to allow you to update your assessment under IS.I.OR.255.
A countersigned copy, and our completed security questionnaire, are available on request.