Skip to content
Legal

FlightLogger — Data Processing Agreement

Last modified: 16th September 2024

This Data Processing Agreement reflects the parties' agreement with respect to the Processing of Personal Data by us on behalf of you in connection with the FlightLogger Service under the FlightLogger Standard SaaS Agreement between you and FlightLogger. Questions can be sent to support@flightlogger.net.

1Preamble

  1. This Data Processing Agreement (the Clauses) set out the rights and obligations of the data controller and the data processor, when processing personal data as defined GDPR on behalf of the data controller.
  2. The Clauses have been designed to ensure the parties' compliance with Article 28(3) of Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation).
  3. In the context of the provision of the FlightLogger Service as further described in the main agreement between the parties, the data processor will process personal data on behalf of the data controller in accordance with the Clauses.
  4. The Clauses shall take priority over any similar provisions contained in other agreements between the parties.
  5. Five appendices are attached to the Clauses and form an integral part of the Clauses.
  6. Appendix A contains details about the processing of personal data, including the purpose and nature of the processing, type of personal data, categories of data subject and duration of the processing.
  7. Appendix B contains the data controller's conditions for the data processor's use of sub-processors and a list of sub-processors authorised by the data controller.
  8. Appendix C contains the data controller's instructions with regards to the processing of personal data, the minimum security measures to be implemented by the data processor and how audits of the data processor and any sub-processors are to be performed.
  9. Appendix D contains provisions for other activities which are not covered by the Clauses.
  10. Appendix E contains the EU Standard Contractual Clauses for transfers from data processors within EU to data controllers outside EU and provides the transfer mechanism in terms of GDPR chapter V for data controllers located outside EU.
  11. The Clauses along with appendices shall be retained in writing, including electronically, by both parties.
  12. The Clauses shall not exempt the data processor from obligations to which the data processor is subject pursuant to the General Data Protection Regulation (the GDPR) or other legislation.

2The rights and obligations of the data controller

  1. The data controller is responsible for ensuring that the processing of personal data takes place in compliance with applicable data protection legislation.
  2. The data controller has the right and obligation to make decisions about the purposes and means of the processing of personal data.
  3. The data controller shall be responsible, among other, for ensuring that the processing of personal data, which the data processor is instructed to perform, has a legal basis.

3The data processor acts according to instructions

  1. The data processor shall process personal data only on documented instructions from the data controller, unless required to do so by Union or Member State law to which the processor is subject. The data processor shall inform the data controller of such requirements, if the requirements lead to a processing that would not have taken place anyway to comply with the data controller's instructions. Such instructions shall be specified in appendices A and C. Subsequent instructions can also be given by the data controller throughout the duration of the processing of personal data, but such instructions shall always be documented and kept in writing, including electronically, in connection with the Clauses.
  2. The data processor shall immediately inform the data controller if instructions given by the data controller, in the opinion of the data processor, contravene the GDPR or the applicable EU or Member State data protection provisions.

4Confidentiality

  1. The data processor shall only grant access to the personal data being processed on behalf of the data controller to persons under the data processor's authority who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality and only on a need to know basis. The list of persons to whom access has been granted shall be kept under periodic review. On the basis of this review, such access to personal data can be withdrawn, if access is no longer necessary, and personal data shall consequently not be accessible anymore to those persons.
  2. The data processor shall at the request of the data controller demonstrate that the concerned persons under the data processor's authority are subject to the abovementioned confidentiality.

5Security of processing

  1. This section 6 shall only apply to data controllers being subject to GDPR.
  2. Article 32 GDPR stipulates that, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the data controller and data processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

    The data controller shall evaluate the risks to the rights and freedoms of natural persons inherent in the processing and implement measures to mitigate those risks. Depending on their relevance, the measures may include the following:

    1. Pseudonymisation and encryption of personal data;
    2. the ability to ensure ongoing confidentiality, integrity, availability and resilience of processing systems and services;
    3. the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;
    4. a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.
  3. According to Article 32 GDPR, the data processor shall also — independently from the data controller — evaluate the risks to the rights and freedoms of natural persons inherent in the processing and implement measures to mitigate those risks. To this effect, the data controller shall provide the data processor with all information necessary to identify and evaluate such risks.
  4. Furthermore, the data processor shall assist the data controller in ensuring compliance with the data controller's obligations pursuant to Articles 32 GDPR, by inter alia providing the data controller with information concerning the technical and organisational measures already implemented by the data processor pursuant to Article 32 GDPR along with all other information necessary for the data controller to comply with the data controller's obligation under Article 32 GDPR.

    If subsequently — in the assessment of the data controller — mitigation of the identified risks require further measures to be implemented by the data processor, than those already implemented by the data processor pursuant to Article 32 GDPR, the data controller shall specify these additional measures to be implemented in Appendix C.

6Use of sub-processors

  1. The data processor shall meet the requirements specified in Article 28(2) and (4) GDPR in order to engage another processor (a sub-processor).
  2. The data processor shall therefore not engage another processor (sub-processor) for the fulfilment of the Clauses without the prior general written authorisation of the data controller.
  3. The data processor has the data controller's general authorisation for the engagement of sub-processors. The data processor shall inform in writing the data controller of any intended changes concerning the addition or replacement of sub-processors at least 90 days in advance, thereby giving the data controller the opportunity to object to such changes prior to the engagement of the concerned sub-processor(s). Longer time periods of prior notice for specific sub-processing services can be provided in Appendix B. The list of sub-processors already authorised by the data controller can be found in Appendix B.
  4. Where the data processor engages a sub-processor for carrying out specific processing activities on behalf of the data controller, the same data protection obligations as set out in the Clauses shall be imposed on that sub-processor by way of a contract or other legal act under EU or Member State law, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of the Clauses and the GDPR.

    The data processor shall therefore be responsible for requiring that the sub-processor at least complies with the obligations to which the data processor is subject pursuant to the Clauses and the GDPR.

  5. A copy of such a sub-processor agreement and subsequent amendments shall — at the data controller's request — be submitted to the data controller, thereby giving the data controller the opportunity to ensure that the same data protection obligations as set out in the Clauses are imposed on the sub-processor. Clauses on business related issues that do not affect the legal data protection content of the sub-processor agreement, shall not require submission to the data controller.
  6. If the sub-processor does not fulfil his data protection obligations, the data processor shall remain fully liable to the data controller as regards the fulfilment of the obligations of the sub-processor. This does not affect the rights of the data subjects under the GDPR — in particular those foreseen in Articles 79 and 82 GDPR — against the data controller and the data processor, including the sub-processor.

7Transfer of data to third countries or international organisations

  1. Any transfer of personal data to third countries or international organisations by the data processor shall only occur on the basis of documented instructions from the data controller and shall always take place in compliance with Chapter V GDPR.
  2. In case transfers to third countries or international organisations, which the data processor has not been instructed to perform by the data controller, is required under EU or Member State law to which the data processor is subject, the data processor shall inform the data controller of that legal requirement prior to processing unless that law prohibits such information on important grounds of public interest.
  3. Without documented instructions from the data controller, the data processor therefore cannot within the framework of the Clauses:
    1. transfer personal data to a data controller or a data processor in a third country or in an international organization
    2. transfer the processing of personal data to a sub-processor in a third country
    3. have the personal data processed in by the data processor in a third country
  4. The data controller's instructions regarding the transfer of personal data to a third country including, if applicable, the transfer tool under Chapter V GDPR on which they are based, shall be set out in Appendix C.6.
  5. The Clauses shall not be confused with standard data protection clauses within the meaning of Article 46(2)(c) and (d) GDPR, and the Clauses cannot be relied upon by the parties as a transfer tool under Chapter V GDPR.

8Assistance to the data controller

  1. This section only applies where the data controller is subject to GDPR. For data controllers not subject to GDPR, the requirements for the data processor to provide assistance for the data controller's fulfilment of the data controller's obligations pursuant to applicable law, shall be laid down in Appendix D.
  2. Taking into account the nature of the processing, the data processor shall assist the data controller by appropriate technical and organisational measures, insofar as this is possible, in the fulfilment of the data controller's obligations to respond to requests for exercising the data subject's rights laid down in Chapter III GDPR.

    This entails that the data processor shall, insofar as this is possible, assist the data controller in the data controller's compliance with:

    1. the right to be informed when collecting personal data from the data subject
    2. the right to be informed when personal data have not been obtained from the data subject
    3. the right of access by the data subject
    4. the right to rectification
    5. the right to erasure ('the right to be forgotten')
    6. the right to restriction of processing
    7. notification obligation regarding rectification or erasure of personal data or restriction of processing
    8. the right to data portability
    9. the right to object
    10. the right not to be subject to a decision based solely on automated processing, including profiling
  3. In addition to the data processor's obligation to assist the data controller pursuant to Clause 5.4., the data processor shall furthermore, taking into account the nature of the processing and the information available to the data processor, assist the data controller in ensuring compliance with:
    1. The data controller's obligation to without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the competent supervisory authority, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons;
    2. the data controller's obligation to without undue delay communicate the personal data breach to the data subject, when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons;
    3. the data controller's obligation to carry out an assessment of the impact of the envisaged processing operations on the protection of personal data (a data protection impact assessment);
    4. the data controller's obligation to consult the competent supervisory authority, as determined by the data controller, prior to processing where a data protection impact assessment indicates that the processing would result in a high risk in the absence of measures taken by the data controller to mitigate the risk.
  4. The parties shall define in Appendix C the appropriate technical and organisational measures by which the data processor is required to assist the data controller as well as the scope and the extent of the assistance required. This applies to the obligations foreseen in Clause 9.1. and 9.2.

9Notification of personal data breach

  1. In case of any personal data breach as defined in GDPR, the data processor shall, without undue delay after having become aware of it, notify the data controller of the personal data breach.
  2. The data processor's notification to the data controller shall, if possible, take place within 48 hours after the data processor has become aware of the personal data breach to enable the data controller to comply with the data controller's obligation to notify the personal data breach to the competent supervisory authority, cf. Article 33 GDPR or — for data controllers not subject to GDPR — the applicable legislation.
  3. In accordance with Clause 8(3)(a), the data processor shall assist the data controller in notifying the personal data breach to the competent supervisory authority, meaning that the data processor is required to assist in obtaining the information listed below which, pursuant to Article 33(3) GDPR, shall be stated in the data controller's notification to the competent supervisory authority:
    1. The nature of the personal data including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
    2. the likely consequences of the personal data breach;
    3. the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
  4. The parties shall define in Appendix C all the elements to be provided by the data processor when assisting the data controller in the notification of a personal data breach to the competent supervisory authority.

10Erasure and return of data

On termination of the provision of personal data processing services, the data processor shall be under obligation to delete all personal data processed on behalf of the data controller and certify to the data controller that it has done so unless Union or Member State law requires storage of the personal data.

11Audit and inspection

  1. The data processor shall make available to the data controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 and the Clauses and allow for and contribute to audits, including inspections, conducted by the data controller or another auditor mandated by the data controller.
  2. Procedures applicable to the data controller's audits, including inspections, of the data processor and sub-processors are specified in appendices C.7. and C.8.
  3. The data processor shall be required to provide the supervisory authorities, which pursuant to applicable legislation have access to the data controller's and data processor's facilities, or representatives acting on behalf of such supervisory authorities, with access to the data processor's physical facilities on presentation of appropriate identification.

12The parties' agreement on other terms

The parties may agree other clauses concerning the provision of the personal data processing service specifying e.g. liability, as long as they do not contradict directly or indirectly the Clauses or prejudice the fundamental rights or freedoms of the data subject and the protection afforded by the GDPR.

13Commencement and termination

  1. The Clauses shall become effective on the date of both parties' signature. If the Clauses are entered into as an integrated part of another agreement, the Clauses shall become at the same time as the other agreement becomes effective.
  2. Both parties shall be entitled to require the Clauses renegotiated if changes to the law or inexpediency of the Clauses should give rise to such renegotiation.
  3. The Clauses shall apply for the duration of the provision of personal data processing services. For the duration of the provision of personal data processing services, the Clauses cannot be terminated unless other Clauses governing the provision of personal data processing services have been agreed between the parties.
  4. If the provision of personal data processing services is terminated, and the personal data is deleted or returned to the data controller pursuant to Clause 10.1. and Appendix C.4., the Clauses may be terminated by written notice by either party.
  5. Signature — Signatures not required — agreement forms an integrated part of the commercial agreement for the use of the FlightLogger Service.

14Data controller and data processor contacts/contact points

  1. The parties may contact each other using the following contacts/contact points:
  2. The parties shall be under obligation continuously to inform each other of changes to contacts/contact points.

Name: [NAME]   Position: [POSITION]   Telephone: [TELEPHONE]   E-mail: [E-MAIL]

Name: [NAME]   Position: [POSITION]   Telephone: [TELEPHONE]   E-mail: [E-MAIL]

These fields are completed per customer as part of the signed agreement.

Appendix A

Information about the processing

A.1. The purpose of the data processor's processing of personal data on behalf of the data controller is:

Provision of the FlightLogger Service on a Software-as-a-Service basis.

A.2. The data processor's processing of personal data on behalf of the data controller shall mainly pertain to (the nature of the processing):

The data processor will operate and monitor the platform, in which data is processed. The data processor will not access or perform specific processing procedures for individual data controllers unless requested by the data processor to do so or necessary to fulfil a specific request from a data processor.

A.3. The processing includes the following types of personal data about data subjects:

About students

  • Call Sign
  • Email
  • First name
  • Last name
  • Phone
  • Address
  • Post code
  • City
  • Country
  • Date of birth
  • Place of birth
  • Emergency contact (next of kin)
  • License number
  • Training records
  • Flight records

About instructors

  • Call Sign
  • Email
  • First name
  • Last name
  • Phone
  • Address
  • Post code
  • City
  • Country
  • Date of birth
  • Place of birth
  • Emergency contact (next of kin)
  • License number

About crew

  • Call Sign
  • Email
  • First name
  • Last name
  • Phone
  • Address
  • Post code
  • City
  • Country
  • Date of birth
  • Place of birth
  • Emergency contact (next of kin)
  • License number
  • Flight records

About administrators

  • Call Sign
  • Email
  • First name
  • Last name
  • Phone
  • Address
  • Post code
  • City
  • Country
  • Date of birth
  • Place of birth
  • Emergency contact (next of kin)

About other staff

  • Call Sign
  • Email
  • First name
  • Last name
  • Phone
  • Address
  • Post code
  • City
  • Country
  • Date of birth
  • Place of birth
  • Emergency contact (next of kin)

About renters

  • Call Sign
  • Email
  • First name
  • Last name
  • Phone
  • Address
  • Post code
  • City
  • Country
  • Date of birth
  • Place of birth
  • Emergency contact (next of kin)
  • License number
  • Flight records

About guests

  • Call Sign
  • Email
  • First name
  • Last name
  • Phone
  • Address
  • Post code
  • City
  • Country
  • Date of birth
  • Place of birth
  • Emergency contact (next of kin)

A.4. Processing includes the following categories of data subject:

Students, instructors, crew, administrators and other staff at the data controller.
Renters and guests at the data controller.

A.5. The data processor's processing of personal data on behalf of the data controller may be performed when the Clauses commence. Processing has the following duration:

The processing shall commence when the data controller is granted access to the FlightLogger Platform and continue until the data controller's use of the FlightLogger Platform ceases and all data processed on behalf of the data controller has been ultimately deleted.

Appendix B

Authorised sub-processors

B.1. Approved sub-processors

On commencement of the Clauses, the data controller authorises the engagement of the following sub-processors:

Name Address Description of Processing
Heroku 415 Mission Street, Suite 300, San Francisco, CA 94105 Hosting of platform
Amazon Web Services Greenhills Road, Tymon North, Dublin, Ireland Hosting of platform
SendGrid Herndon, VA; Las Vegas, NV; and Chicago, IL Email service
Stripe 354 Oyster Point Boulevard, South San Francisco, California, 94080, USA Payment
NewRelic San Francisco HQ, 188 Spear St., Suite 1000, San Francisco, CA USA 94105 DevOps tool to monitor and debug platform
Sentry 45 Fremont Street, 8th Floor, San Francisco, CA 94105 DevOps tool to capture application exceptions
CloudFlare 101 Townsend St, San Francisco, USA DNS
BlueSnap 800 South Street, Suite 640, Waltham MA, USA Payment processing

The data controller shall on the commencement of the Clauses authorise the use of the abovementioned sub-processors for the processing described for that party. The data processor shall not be entitled — without the data controller's explicit written authorisation — to engage a sub-processor for a 'different' processing than the one which has been agreed upon or have another sub-processor perform the described processing.

B.2. Prior notice for the authorisation of sub-processors

Please refer to clause 6.3.

Appendix C

Instruction pertaining to the use of personal data

C.1. The subject of/instruction for the processing

The data processor's processing of personal data on behalf of the data controller shall be carried out by the data processor performing the following: The data processor shall handle technical operations of the FlightLogger Platform. Furthermore, the data processor shall provide support to the data controller in accordance with specific instructions as issued by the data controller from time to time.

C.2. Security of processing

The level of security shall take into account that accuracy of information processed in the system is critical to ensure compliance with legislation on training of air traffic personnel. Therefore, a moderate to high level of security is required.

The data processor shall hereafter be entitled and under obligation to make decisions about the technical and organisational security measures that are to be applied to create the necessary (and agreed) level of data security.

Data is hosted in Amazon Web Services (AWS), and the data processor relies on the technical security at AWS as applicable from time to time as being sufficient to address the risk level relevant to the data processed in the system and the purpose for which such data is processed.

All data stored as part of the Service is subject to AWS' backup procedures as well as AWS' disaster recovery procedures. Furthermore, FlightLogger will create a snapshot of the database once every 24 hours.

FlightLogger staff does not access or interact with customer data or applications as part of normal operations. There may be cases where we are requested to interact with customer data at the request of the customer for support purposes or to ensure data integrities on software updates.

C.3. Assistance to the data controller

The data processor shall insofar as this is possible — within the scope and the extent of the assistance specified below — assist the data controller in accordance with Clause 8.1. and 8.2. by implementing the following technical and organisational measures: The data processor's personnel shall be trained to assist data controllers with identifying, extracting, correcting or deleting data stored in the FlightLogger platform, preferably by instructing the data controller in order for the data controller to be able to carry out the required activities by using the tools available in the Platform.

C.4. Storage period/erasure procedures

Personal data is stored until it is deleted by the data controller or the data controller instructs the data processor to do so.

Upon termination of the provision of personal data processing services, the data processor shall either delete or return the personal data in accordance with Clause 10.1., unless the data controller — after the signature of the contract — has modified the data controller's original choice. Such modification shall be documented and kept in writing, including electronically, in connection with the Clauses.

C.5. Processing location

Processing of the personal data under the Clauses cannot be performed at other locations than the following without the data controller's prior written authorisation: At the data controller's and the data processor's locations, as well as at any location of the sub-processors listed in appendix B, clause B.1.

C.6. Instruction on the transfer of personal data to third countries

If the data controller does not in the Clauses or subsequently provide documented instructions pertaining to the transfer of personal data to a third country, the data processor shall not be entitled within the framework of the Clauses to perform such transfer.

The data controller hereby permits and instructs the data processor to transfer the personal data to Amazon Web Services with the consequence that data will be transferred to any country from where Amazon Web Services is supported.

The data processor shall ensure the existence of a transfer mechanism — for example EU Standard Contractual Clauses — with Amazon Web Services, as well as the data processor shall implement any supplementary measures considered necessary to ensure that data subjects enjoy a level of protection essentially equivalent to the level of protection within EU, even when data is exported.

Furthermore, if the data controller is located outside the EU, the data controller also instructs the data processor to make data processed in the FlightLogger Platform available to the data controller in the countries where the data controller is located. For such transfers, Appendix E shall apply.

C.7. Procedures for the data controller's audits, including inspections, of the processing of personal data being performed by the data processor

FlightLogger staff does not access or interact with customer data or applications as part of normal operations. The underlying technical platform is operated by third parties as accounted for in appendix B, section B.1.

At the data controller's request, the data processor will work loyally with the data controller to provide appropriate documentation of the data processor's compliance with its obligations in this data processing agreement.

C.8. Procedures for audits, including inspections, of the processing of personal data being performed by sub-processors

The data processor will — on an annual basis — collect relevant certificates and audit reports from Amazon and verify that Amazon on an ongoing basis maintains a setup providing reasonable assurance that Amazon complies with its obligations as per the data processing agreement entered into with Amazon, and that Amazon at any time maintains a level of security appropriate to the risks to the rights and freedoms of the data subjects, arising out of the processing carried out in the FlightLogger Platform.

Appendix D

The parties' terms of agreement on other subjects

No additional terms have been agreed under this Appendix D.

Appendix E

EU Standard Contractual Clauses

Applicable for data controllers located in countries outside EU/EEA that are not recognized by the EU Commission as ensuring an adequate level of protection. Module: Processor to Controller.

Section I

Clause 1 — Purpose and scope

The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) for the transfer of personal data to a third country.

The Parties: (i) the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter 'entity/ies') transferring the personal data, as listed in Annex I.A (hereinafter each 'data exporter'), and (ii) the entity/ies in a third country receiving the personal data from the data exporter, directly or indirectly via another entity also Party to these Clauses, as listed in Annex I.A (hereinafter each 'data importer') have agreed to these standard contractual clauses (hereinafter: 'Clauses').

These Clauses apply with respect to the transfer of personal data as specified in Annex I.B. The Appendix to these Clauses containing the Annexes referred to therein forms an integral part of these Clauses.

Clause 2 — Effect and invariability of the Clauses

These Clauses set out appropriate safeguards, including enforceable data subject rights and effective legal remedies, pursuant to Article 46(1) and Article 46(2)(c) of Regulation (EU) 2016/679 and, with respect to data transfers from controllers to processors and/or processors to processors, standard contractual clauses pursuant to Article 28(7) of Regulation (EU) 2016/679, provided they are not modified, except to select the appropriate Module(s) or to add or update information in the Appendix. This does not prevent the Parties from including the standard contractual clauses laid down in these Clauses in a wider contract and/or to add other clauses or additional safeguards, provided that they do not contradict, directly or indirectly, these Clauses or prejudice the fundamental rights or freedoms of data subjects.

These Clauses are without prejudice to obligations to which the data exporter is subject by virtue of Regulation (EU) 2016/679.

Clause 3 — Third-party beneficiaries

Data subjects may invoke and enforce these Clauses, as third-party beneficiaries, against the data exporter and/or data importer, with the following exceptions: (i) Clause 1, Clause 2, Clause 3, Clause 6, Clause 7; (ii) Clause 8.1(b) and Clause 8.3(b); (iii) N/A; (iv) N/A; (v) Clause 13; (vi) Clause 15.1(c), (d) and (e); (vii) Clause 16(e); (viii) Clause 18.

Paragraph (a) is without prejudice to rights of data subjects under Regulation (EU) 2016/679.

Clause 4 — Interpretation

Where these Clauses use terms that are defined in Regulation (EU) 2016/679, those terms shall have the same meaning as in that Regulation. These Clauses shall be read and interpreted in the light of the provisions of Regulation (EU) 2016/679. These Clauses shall not be interpreted in a way that conflicts with rights and obligations provided for in Regulation (EU) 2016/679.

Clause 5 — Hierarchy

In the event of a contradiction between these Clauses and the provisions of related agreements between the Parties, existing at the time these Clauses are agreed or entered into thereafter, these Clauses shall prevail.

Clause 6 — Description of the transfer(s)

The details of the transfer(s), and in particular the categories of personal data that are transferred and the purpose(s) for which they are transferred, are specified in Annex I.B.

Clause 7 — Docking clause (Optional)

An entity that is not a Party to these Clauses may, with the agreement of the Parties, accede to these Clauses at any time, either as a data exporter or as a data importer, by completing the Appendix and signing Annex I.A. Once it has completed the Appendix and signed Annex I.A, the acceding entity shall become a Party to these Clauses and have the rights and obligations of a data exporter or data importer in accordance with its designation in Annex I.A. The acceding entity shall have no rights or obligations arising under these Clauses from the period prior to becoming a Party.

Section II — Obligations of the Parties

Clause 8 — Data protection safeguards

The data exporter warrants that it has used reasonable efforts to determine that the data importer is able, through the implementation of appropriate technical and organisational measures, to satisfy its obligations under these Clauses.

8.1 Instructions — The data exporter shall process the personal data only on documented instructions from the data importer acting as its controller. The data exporter shall immediately inform the data importer if it is unable to follow those instructions, including if such instructions infringe Regulation (EU) 2016/679 or other Union or Member State data protection law. The data importer shall refrain from any action that would prevent the data exporter from fulfilling its obligations under Regulation (EU) 2016/679, including in the context of sub-processing or as regards cooperation with competent supervisory authorities. After the end of the provision of the processing services, the data exporter shall, at the choice of the data importer, delete all personal data processed on behalf of the data importer and certify to the data importer that it has done so, or return to the data importer all personal data processed on its behalf and delete existing copies.

8.2 Security of processing — The Parties shall implement appropriate technical and organisational measures to ensure the security of the data, including during transmission, and protection against a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access (hereinafter 'personal data breach'). In assessing the appropriate level of security, they shall take due account of the state of the art, the costs of implementation, the nature of the personal data, the nature, scope, context and purpose(s) of processing and the risks involved in the processing for the data subjects, and in particular consider having recourse to encryption or pseudonymisation, including during transmission, where the purpose of processing can be fulfilled in that manner. The data exporter shall assist the data importer in ensuring appropriate security of the data in accordance with paragraph (a). In case of a personal data breach concerning the personal data processed by the data exporter under these Clauses, the data exporter shall notify the data importer without undue delay after becoming aware of it and assist the data importer in addressing the breach. The data exporter shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

8.3 Documentation and compliance — The Parties shall be able to demonstrate compliance with these Clauses. The data exporter shall make available to the data importer all information necessary to demonstrate compliance with its obligations under these Clauses and allow for and contribute to audits.

Clause 9 — Use of sub-processors

N/A

Clause 10 — Data subject rights

The Parties shall assist each other in responding to enquiries and requests made by data subjects under the local law applicable to the data importer or, for data processing by the data exporter in the EU, under Regulation (EU) 2016/679.

Clause 11 — Redress

The data importer shall inform data subjects in a transparent and easily accessible format, through individual notice or on its website, of a contact point authorised to handle complaints. It shall deal promptly with any complaints it receives from a data subject.

[OPTION: The data importer agrees that data subjects may also lodge a complaint with an independent dispute resolution body at no cost to the data subject. It shall inform the data subjects, in the manner set out in paragraph (a), of such redress mechanism and that they are not required to use it, or follow a particular sequence in seeking redress.]

Clause 12 — Liability

Each Party shall be liable to the other Party/ies for any damages it causes the other Party/ies by any breach of these Clauses. Each Party shall be liable to the data subject, and the data subject shall be entitled to receive compensation, for any material or non-material damages that the Party causes the data subject by breaching the third-party beneficiary rights under these Clauses. This is without prejudice to the liability of the data exporter under Regulation (EU) 2016/679. Where more than one Party is responsible for any damage caused to the data subject as a result of a breach of these Clauses, all responsible Parties shall be jointly and severally liable and the data subject is entitled to bring an action in court against any of these Parties. The Parties agree that if one Party is held liable under paragraph (c), it shall be entitled to claim back from the other Party/ies that part of the compensation corresponding to its/their responsibility for the damage. The data importer may not invoke the conduct of a processor or sub-processor to avoid its own liability.

Clause 13 — Supervision

N/A

Section III — Local Laws and Obligations in Case of Access by Public Authorities

Clause 14 — Local laws and practices affecting compliance with the Clauses

(where the EU processor combines the personal data received from the third country-controller with personal data collected by the processor in the EU)

The Parties warrant that they have no reason to believe that the laws and practices in the third country of destination applicable to the processing of the personal data by the data importer, including any requirements to disclose personal data or measures authorising access by public authorities, prevent the data importer from fulfilling its obligations under these Clauses. This is based on the understanding that laws and practices that respect the essence of the fundamental rights and freedoms and do not exceed what is necessary and proportionate in a democratic society to safeguard one of the objectives listed in Article 23(1) of Regulation (EU) 2016/679, are not in contradiction with these Clauses.

The Parties declare that in providing the warranty above, they have taken due account in particular of: (i) the specific circumstances of the transfer, including the length of the processing chain, the number of actors involved and the transmission channels used; intended onward transfers; the type of recipient; the purpose of processing; the categories and format of the transferred personal data; the economic sector in which the transfer occurs; the storage location of the data transferred; (ii) the laws and practices of the third country of destination — including those requiring the disclosure of data to public authorities or authorising access by such authorities — relevant in light of the specific circumstances of the transfer, and the applicable limitations and safeguards; (iii) any relevant contractual, technical or organisational safeguards put in place to supplement the safeguards under these Clauses, including measures applied during transmission and to the processing of the personal data in the country of destination.

The data importer warrants that, in carrying out the assessment above, it has made its best efforts to provide the data exporter with relevant information and agrees that it will continue to cooperate with the data exporter in ensuring compliance with these Clauses. The Parties agree to document the assessment and make it available to the competent supervisory authority on request.

The data importer agrees to notify the data exporter promptly if, after having agreed to these Clauses and for the duration of the contract, it has reason to believe that it is or has become subject to laws or practices not in line with the requirements above, including following a change in the laws of the third country or a measure (such as a disclosure request) indicating an application of such laws in practice that is not in line with the requirements above.

Following such a notification, or if the data exporter otherwise has reason to believe that the data importer can no longer fulfil its obligations under these Clauses, the data exporter shall promptly identify appropriate measures (e.g. technical or organisational measures to ensure security and confidentiality) to be adopted by the data exporter and/or data importer to address the situation. The data exporter shall suspend the data transfer if it considers that no appropriate safeguards for such transfer can be ensured, or if instructed by the competent supervisory authority to do so.

Clause 15 — Obligations of the data importer in case of access by public authorities

(where the EU processor combines the personal data received from the third country-controller with personal data collected by the processor in the EU)

15.1 Notification — The data importer agrees to notify the data exporter and, where possible, the data subject promptly (if necessary with the help of the data exporter) if it: (i) receives a legally binding request from a public authority, including judicial authorities, under the laws of the country of destination for the disclosure of personal data transferred pursuant to these Clauses; such notification shall include information about the personal data requested, the requesting authority, the legal basis for the request and the response provided; or (ii) becomes aware of any direct access by public authorities to personal data transferred pursuant to these Clauses in accordance with the laws of the country of destination; such notification shall include all information available to the importer. If the data importer is prohibited from notifying the data exporter and/or the data subject under the laws of the country of destination, the data importer agrees to use its best efforts to obtain a waiver of the prohibition, with a view to communicating as much information as possible, as soon as possible, and agrees to document its best efforts. Where permissible under the laws of the country of destination, the data importer agrees to provide the data exporter, at regular intervals for the duration of the contract, with as much relevant information as possible on the requests received. The data importer agrees to preserve this information for the duration of the contract and make it available to the competent supervisory authority on request.

15.2 Review of legality and data minimisation — The data importer agrees to review the legality of the request for disclosure, in particular whether it remains within the powers granted to the requesting public authority, and to challenge the request if, after careful assessment, it concludes that there are reasonable grounds to consider that the request is unlawful under the laws of the country of destination, applicable obligations under international law and principles of international comity. The data importer shall, under the same conditions, pursue possibilities of appeal, seeking interim measures with a view to suspending the effects of the request until the competent judicial authority has decided on its merits, and shall not disclose the personal data requested until required to do so under the applicable procedural rules. The data importer agrees to document its legal assessment and any challenge to the request for disclosure and, to the extent permissible, make the documentation available to the data exporter and the competent supervisory authority on request. The data importer agrees to provide the minimum amount of information permissible when responding to a request for disclosure, based on a reasonable interpretation of the request.

Section IV — Final Provisions

Clause 16 — Non-compliance with the Clauses and termination

The data importer shall promptly inform the data exporter if it is unable to comply with these Clauses, for whatever reason. In the event that the data importer is in breach of these Clauses or unable to comply with these Clauses, the data exporter shall suspend the transfer of personal data to the data importer until compliance is again ensured or the contract is terminated. The data exporter shall be entitled to terminate the contract, insofar as it concerns the processing of personal data under these Clauses, where: (i) the data exporter has suspended the transfer of personal data and compliance with these Clauses is not restored within a reasonable time and in any event within one month of suspension; (ii) the data importer is in substantial or persistent breach of these Clauses; or (iii) the data importer fails to comply with a binding decision of a competent court or supervisory authority regarding its obligations under these Clauses.

Personal data collected by the data exporter in the EU that has been transferred prior to the termination of the contract shall immediately be deleted in its entirety, including any copy thereof. The data importer shall certify the deletion of the data to the data exporter. Until the data is deleted or returned, the data importer shall continue to ensure compliance with these Clauses. Either Party may revoke its agreement to be bound by these Clauses where (i) the European Commission adopts a decision pursuant to Article 45(3) of Regulation (EU) 2016/679 that covers the transfer of personal data to which these Clauses apply; or (ii) Regulation (EU) 2016/679 becomes part of the legal framework of the country to which the personal data is transferred.

Clause 17 — Governing law

These Clauses shall be governed by the law of a country allowing for third-party beneficiary rights. The Parties agree that this shall be the law of Denmark.

Clause 18 — Choice of forum and jurisdiction

Any dispute arising from these Clauses shall be resolved by the courts of Denmark.

Annex I

A. List of Parties

Data exporter(s): Name and Address: The entity defined as the data processor in the Data Processing Agreement, for which these Standard Contractual Clauses form Appendix E. Contact person's name, position and contact details: Please refer to section 15 of the Data Processing Agreement. Activities relevant to the data transferred: Data importer's use of the Services provided by the Data exporter. Signature and date: Signed as an integrated part of the Data Processing Agreement. Role: Processor.

Data importer(s): Name and Address: The entity defined as the data controller in the Data Processing Agreement, for which these Standard Contractual Clauses form Appendix E. Contact person's name, position and contact details: Please refer to section 15 of the Data Processing Agreement. Activities relevant to the data transferred: Data importer's use of the Services provided by the Data exporter. Signature and date: Signed as an integrated part of the Data Processing Agreement. Role: Controller.

B. Description of Transfer

Categories of data subjects: Please refer to Appendix A, clause A.4 of the Data Processing Agreement.

Categories of personal data transferred: Please refer to Appendix A, clause A.3 of the Data Processing Agreement.

Frequency of the transfer: Continuous.

Nature of the processing: Data importer's use of the Service provided by the data exporter.

Purpose(s) of the data transfer: Data importer is using the Service provided by the Data exporter for processing of personal data.

Retention period: The processing will commence upon the parties entering into the Data Processing Agreement, for which these clauses form Appendix E, and shall continue until the Data Importer ceases the use of the Service and all personal data is deleted.

Sub-processors: Please refer to Appendix B of the Data Processing Agreement.

  1. Where the data exporter is a processor subject to Regulation (EU) 2016/679 acting on behalf of a Union institution or body as controller, reliance on these Clauses when engaging another processor (sub-processing) not subject to Regulation (EU) 2016/679 also ensures compliance with Article 29(4) of Regulation (EU) 2018/1725, to the extent these Clauses and the data protection obligations set out in the contract between the controller and processor are aligned, in particular where they rely on the standard contractual clauses included in Decision 2021/915.
  2. This includes whether the transfer and further processing involves personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data or biometric data for the purpose of uniquely identifying a natural person, data concerning health or a person's sex life or sexual orientation, or data relating to criminal convictions or offences.
  3. The data importer may offer independent dispute resolution through an arbitration body only if it is established in a country that has ratified the New York Convention on Enforcement of Arbitration Awards.
  4. As regards the impact of such laws and practices on compliance with these Clauses, different elements may be considered as part of an overall assessment, including documented practical experience with prior instances of requests for disclosure from public authorities, or the absence of such requests, covering a sufficiently representative timeframe, corroborated by objective, reliable information on the existence or absence of such requests within the same sector.
Everything You Need - In One Aviation-Ready Platform

See FlightLogger
in Action

From scheduling flights and assigning instructors to managing aircraft maintenance and role-based access, FlightLogger keeps every moving part of your training program in sync. Stay audit-ready, eliminate paperwork, and streamline your daily operations - whether you run one base or a dozen.