This Data Processing Addendum forms part of the agreement between XOps (the "Processor") and the customer operating a XOps workspace (the "Controller") and applies whenever we process personal data on the Controller's behalf.
1. Subject matter and duration
Processing of Customer Data to provide the XOps platform, for the duration of the subscription plus the 30-day export window.
2. Nature and purpose of processing
Hosting, storage, display, computation (feasibility analysis, roster optimisation, flight-time-limitation checks, fatigue scoring), notification delivery, export to systems the Controller connects, and related support.
3. Categories of data subjects and data
- Data subjects: the Controller's crew members and staff; its customers' contact persons; platform users.
- Personal data: identification and contact details; employment data (base, rank, employee id); duty and roster records; qualification, licence, medical-expiry, passport and visa metadata (dates and document references — the Controller should not upload document scans it does not need); preference and bid records; messages and acknowledgements.
- Special categories: not required by the Service. Fatigue-model outputs are derived operational scores, not health records; the Controller must not upload medical content beyond expiry dates.
4. Controller instructions
We process Customer Data only on documented instructions — the agreement, the workspace configuration (including which integrations are connected), and instructions given through the Service — unless required otherwise by law, in which case we inform the Controller unless prohibited.
5. Confidentiality and personnel
Persons authorised to process Customer Data are bound by confidentiality and receive appropriate data-protection instruction.
6. Security (art. 32)
- Multi-tenant isolation: every record is scoped to the Controller's company.
- Role-based access control enforced in views and the service layer.
- TLS for data in transit; encrypted storage at the infrastructure layer.
- Audited approvals with frozen decision snapshots; outbound-email audit log.
- Access to production limited to authorised personnel with logged access.
7. Subprocessors
The Controller authorises the following subprocessors. We will give at least 30 days' notice before adding or replacing one; the Controller may object on reasonable data-protection grounds.
| Subprocessor | Purpose | Location |
|---|---|---|
| Brevo (Sendinblue SAS) | Transactional email delivery | EU (France) |
| Hosting / infrastructure provider(s) named in the order form | Compute, storage, backups | Per order form |
| LLM provider named in the workspace AI configuration | AI-assisted analysis (only when the feature is used) | Per provider |
Systems the Controller connects itself (e.g. LEON, XOps, SMS/WhatsApp gateways) act on the Controller's instructions and are not our subprocessors.
8. Data-subject requests and assistance
We forward requests received directly from data subjects to the Controller and, taking into account the nature of processing, assist with requests, security, breach notification, and data-protection impact assessments.
9. Breach notification
We notify the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Data, with the information reasonably available to us.
10. International transfers
Transfers outside the EEA/UK occur only with appropriate safeguards (adequacy decision, or Standard Contractual Clauses with the UK addendum where applicable).
11. Deletion and return
On termination, Customer Data is available for export in standard formats for 30 days, then deleted from production systems; backup copies expire on their normal rotation schedule.
12. Audit
We make available information reasonably necessary to demonstrate compliance and allow audits as required by art. 28(3)(h), subject to reasonable notice, frequency limits, and confidentiality.