Article 28 processor terms
Data Processing Addendum
The processor agreement that accompanies every SeyAero subscription, including populated Annexes I–III, SCC module elections, the UK IDTA, a 48-hour breach clock and audit rights.
- Controller
- Oluwaseyi Aerospace LLC
- Product
- SeyAero
- Effective
- 24 August 2026
- Version
- v1.0
1. Incorporation and roles
This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer ("Controller") and Oluwaseyi Aerospace LLC ("Processor") and applies whenever the Processor processes personal data on the Controller's behalf.
For case data the Controller is the customer organisation; the Processor acts only on documented instruction. For account data the Processor acts as an independent controller under its Privacy Notice. Where the Controller is a state safety investigation authority acting under ICAO Annex 13 and national law, that statutory mandate is the Controller's lawful basis and the Processor does not assess it.
2. Processing instructions
The Processor processes personal data only on documented instructions from the Controller, which comprise this DPA, the Terms, the configuration of the platform, and any instruction issued through the platform interface or a support ticket.
The Processor will notify the Controller if, in its opinion, an instruction infringes GDPR, UK GDPR or another applicable data protection law, and may suspend the affected processing until the instruction is withdrawn or amended.
Where the Processor is required by Union, Member State or other applicable law to process beyond instruction, it will inform the Controller before processing unless the law prohibits that notice on important grounds of public interest.
3. Annex I — Subject matter, duration, nature and purpose
- Subject matter — provision of the SeyAero aviation occurrence investigation platform.
- Duration — the subscription term plus the post-termination export and deletion windows.
- Nature and purpose — hosting, storage, indexing, timeline synchronisation, transcription, extraction, statistical modelling, search-plan generation, reporting and audit logging.
- Categories of data subject — flight and cabin crew, air traffic controllers, maintenance and ground personnel, witnesses, passengers, next of kin, investigators and platform users.
- Categories of personal data — identity and contact details, employment and licensing data, duty and training records, voice recordings and transcripts, location and travel data, statements, imagery, and technical/usage data.
- Special categories — health and medical certification data, biometric characteristics inherent in voice recordings, and data revealing trade union membership where present in crew records. Processed under Article 9(2)(g)/(j) as determined by the Controller.
- Frequency — continuous for the duration of the case.
4. Annex II — Technical and organisational measures
- Encryption: TLS 1.2+ in transit; AES-256 at rest; managed key rotation with keys held separately from data.
- Access control: per-case row-level authorisation, role-based permissions, unique named accounts, optional and enforceable TOTP MFA, federated SSO via Google Workspace and Microsoft Entra ID.
- Integrity: SHA-256 hash-chained audit ledger over evidence and administrative actions; signed chain-of-custody manifests; signed report releases.
- Segregation: logical tenant isolation; production data never used in development or test environments.
- Resilience: point-in-time recovery, encrypted backups, documented restoration testing.
- Personnel: confidentiality undertakings, background screening where lawful, least-privilege and just-in-time production access, mandatory security and Annex 13 confidentiality training.
- Vulnerability management: dependency scanning, patching to severity-based SLAs, periodic penetration testing with summary reports available under NDA.
5. Annex III — Subprocessors
The Controller grants general written authorisation for the Processor to engage subprocessors listed in the published subprocessor register. The Processor imposes data protection obligations on each subprocessor no less protective than this DPA and remains fully liable for their performance.
The Processor gives at least thirty (30) days' notice before adding or replacing a subprocessor. The Controller may object on reasonable data protection grounds within that period; if the parties cannot agree a remedy, the Controller may terminate the affected service without penalty for the unused prepaid term.
6. International transfers
Where processing involves transfer of personal data out of the EEA, the UK or Switzerland to a country without an adequacy decision, the parties incorporate by reference the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, with: Clause 7 docking active; Clause 9(a) Option 2, thirty (30) days' notice; Clause 11 optional independent redress not selected; Clause 17 governed by Irish law; Clause 18(b) courts of Ireland.
For UK transfers the International Data Transfer Addendum (version B1.0) applies, with Tables 1–4 populated by this DPA and the order form, and the ICO as the relevant regulator. For Swiss transfers references to the GDPR are read as references to the revFADP and the FDPIC is the competent authority.
The Processor maintains a transfer impact assessment, will challenge unlawful access demands, and will notify the Controller of any binding request for disclosure unless legally prohibited.
7. Personal data breach
The Processor notifies the Controller without undue delay and in any event within forty-eight (48) hours of becoming aware of a personal data breach affecting Controller data, providing the nature of the breach, categories and approximate volumes affected, likely consequences, measures taken and a named contact, updated as the investigation progresses.
The Processor assists the Controller with notifications to supervisory authorities and data subjects. Notification is not an admission of fault.
Given the sensitivity of protected safety information, the Processor will also flag any unauthorised internal access to case content on the customer-visible audit chain, whether or not it constitutes a notifiable breach.
8. Assistance, audits and DPIAs
The Processor assists the Controller, taking into account the nature of processing and information available, with data subject requests, security obligations under Article 32, breach notification under Articles 33–34, and data protection impact assessments and prior consultation under Articles 35–36.
The Processor makes available information necessary to demonstrate compliance and allows audits by the Controller or an independent auditor bound by confidentiality: once per twelve (12) months on thirty (30) days' notice, more frequently following a breach or regulator instruction, conducted during business hours without unreasonable disruption and without access to other customers' data.
9. Return and deletion
On termination the Controller may export case data for ninety (90) days in structured, machine-readable form. Thereafter the Processor deletes or irreversibly anonymises personal data within thirty (30) days, including from backups on their normal rotation cycle (not exceeding thirty-five (35) further days), except where retention is required by law. Audit-chain metadata that records the fact of actions, without case content, may be retained for evidential-integrity purposes.
Written confirmation of deletion is provided on request.
10. Liability and order of precedence
Liability under this DPA is subject to the limitations in the Terms, except where a mandatory provision of applicable data protection law prohibits limitation. In the event of conflict, the SCCs prevail over this DPA, and this DPA prevails over the Terms, in each case only on data protection matters.
This document is contractual but is not legal advice to you. Where a signed enterprise agreement exists between you and Oluwaseyi Aerospace LLC, that agreement prevails over this page to the extent of any conflict. Questions: legal@seyaero.com.
