Data Processing Agreement
Quick links
- Definitions
- Scope of this DPA and Relationship of the Parties
- Vendor as a Controller
- Vendor Processing of Personal Data
- Sub-processing
- Cooperation and Individual Rights
- Security and Audits
- International Transfers
- Deletion and Return of Data
- Limitation of Liability
- General
- Schedule 1 (C2P and P2P Transfers)
- Schedule 2 (C2C Transfers)
- Schedule 3
- Schedule 4
- Schedule 5
This Data Processing Addendum, including its schedules and the Standard Contractual Clauses (together, “DPA“), is incorporated into and forms part of the Propeller Terms and Conditions and any Order Form entered into between Customer and Vendor (together, the “Agreement“). In this DPA, “Vendor” means the Propeller entity identified in the applicable Order Form, and “Customer” means the entity identified as the Customer in the applicable Order Form. This DPA applies to the extent Vendor processes Personal Data on behalf of Customer in connection with the Services.
This DPA is effective as of the effective date of the Agreement. No signature is required: this DPA binds the parties upon the Agreement taking effect, by virtue of its incorporation into the Agreement.
The parties agree as follows:
1. Definitions
1.1 “Affiliate” means any entity that is directly or indirectly controlled by, controlling or under common control with an entity. “Control” for purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.
1.2. “Applicable Data Protection Law” means all worldwide data protection and privacy laws and regulations applicable to the Personal Data in question, including, where applicable, European Data Protection Law and all laws and regulations of the United States, including the CCPA.
1.3. “CCPA” means Title 1.81.5 California Consumer Privacy Act of 2018 (California Civil Code §§ 1798.100–1798.199), including any amendments and its implementing regulations that become effective on or after the effective date of this DPA (as amended, superseded or replaced from time to time).
1.4. “European Data Protection Law” means (i) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data (General Data Protection Regulation) (“EU GDPR“) (ii) the EU GDPR as saved into UK law by virtue of section 3 of the UK’s European Union (Withdrawal) Act 2018 (“UK GDPR“) and the UK Data Protection Act 2018 (together, “UK Data Protection Law“); (iii) the Swiss Federal Data Protection Act of 19 June 1992 and its corresponding ordinances (“Swiss DPA“); (iv) the e-Privacy Directive (the Directive 2002/58/EC); (v) any applicable data protection laws made under or pursuant to or that apply in conjunction with (i), (ii), (iii) or (iv) (in each case, as may be amended, superseded or replaced from time to time).
1.5. “Europe” means the European Economic Area (the “EEA“), United Kingdom (“UK“) and Switzerland.
1.6. “Personal Data” means information relating to an identified or identifiable natural person (“data subject“). An identified or identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity, including any data that is protected as “personal data”, “personally identifiable information” or “personal information”, under Applicable Data Protection Law and processed by Vendor in accordance with Section 2.1 of this DPA in connection with the Services, and as more particularly described in Schedules 1 and 2 of this DPA (as applicable).
1.7. “Restricted Transfer” means: (i) where the EU GDPR applies, a transfer of personal data from the EEA to a country outside of the EEA which is not subject to an adequacy determination by the European Commission; (ii) where the UK GDPR applies, a transfer of personal data from the UK to any other country which is not based on adequacy regulations pursuant to Section 17A of the Data Protection Act 2018; and (iii) where the Swiss DPA applies, a transfer of personal data to a country outside of Switzerland which is not included on the list of adequate jurisdictions published by the Swiss Federal Data Protection and Information Commissioner.
1.8. “Security Incident” means a personal data breach or any unauthorized access or breach of security leading to, or reasonably believed to have led to, the theft, accidental or unlawful destruction loss, alteration, unauthorized disclosure or access to any Personal Data processed by Vendor (and/or any processor or Sub-processor) under or in connection with the Agreement.
1.9. “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses adopted by the European Commission in its Implementing Decision (EU) 2021/91 of 4 June 2021.
1.10. “Sub-processor” means any third-party or service provider (including any Vendor Affiliates) engaged by Vendor in its role as a processor, which processes any Personal Data relating to this DPA and/or the Agreement. Vendor’s list of Sub-processors can be found at https://trust.propelleraero.com/subprocessors. The term “Sub-processor” shall also include any third-party appointed by a Sub-processor to process any Personal Data relating to this DPA and/or the Agreement.
1.11. “UK Addendum” means the “UK Addendum to the EU Standard Contractual Clauses” issued by the Information Commissioner’s Office under s.119A(1) of the UK Data Protection Act 2018.
1.12. The terms “controller“, “processor“, “supervisory authority“, “personal data breach” and “processing” shall have the meaning given to them in European Data Protection Law and “process”, “processes” and “processed” shall be interpreted accordingly. The terms “consumer“, “personal information“, “business“, “sale” (including the terms “sell,” “selling,” “sold,” and other variations thereof) and “service provider” shall have the meaning given to them in the CCPA.
2. Scope of this DPA and Relationship of the Parties
2.1. Scope. This DPA applies where and only to the extent Vendor processes any Personal Data protected by Applicable Data Protection Law under the Agreement in the course of providing the Services pursuant to the Agreement as follows:
2.1.1. Where and to the extent Customer is a controller or business (as applicable) and Vendor and/or each relevant Vendor Affiliate processes Personal Data as a processor or service provider (as applicable), Vendor shall be a processor or service provider (as applicable) of the Personal Data and this DPA shall apply accordingly;
2.1.2. Where Customer is a processor or service provider of the Personal Data covered by this DPA on behalf of third-party controllers or businesses (“Third Party Controllers”), Vendor and/or each relevant Vendor Affiliate shall be a Sub-processor or service provider (as applicable) of the Personal Data and this DPA shall apply accordingly;
2.1.3. Where and to the extent Customer is a controller or business (as applicable) and Vendor and/or each relevant Vendor Affiliate processes Personal Data as a controller or business (as applicable), Vendor will process such Personal Data in compliance with Applicable Data Protection Law, Sections 2, 3, 7.2, 7.3, 7.4, 7.5, 8, 10, and 11 of this DPA, and Schedules 2 and 3 of this DPA, to the extent applicable, only.
2.2. Compliance with Law. Each party will comply with its obligations under Applicable Data Protection Law in respect of the Personal Data it processes under the Agreement and this DPA. If Applicable Data Protection Law and corresponding obligations related to the processing of Personal Data change, the parties shall discuss in good faith any necessary amendments to this DPA.
2.3. California. The parties agree that: (i) Vendor shall not retain, use or disclose Personal Data for any purpose other than the permitted purposes under this DPA; (ii) Personal Data was not sold to Vendor and Vendor shall not sell Personal Data subject to the CCPA; and (iii) Vendor shall not retain, use or disclose Personal Data outside of the direct business relationship between Customer and Vendor. Vendor certifies that it understands the restrictions set out in this Section 2.3 and will comply with them.
2. Vendor as a Controller
3.1. Independent Controllers. Each party shall be individually and separately responsible for complying with the obligations that apply to it as a separate and independent controller under Applicable Data Protection Law and neither party shall be responsible for the other party’s compliance with Applicable Data Protection Law.
3.2. Vendor Controller Obligations. Vendor and each Vendor Affiliate shall:
3.2.1. comply with all applicable European Data Protection Law when processing Personal Data;
3.2.2. only Process the Personal Data in order to perform its obligations under the Agreement; and,
3.2.3. notify Customer within 72 hours upon becoming aware of a Security Incident affecting Customer’s Personal Information and, where reasonably practicable, provide a copy of any proposed notification and consider in good faith any comments made by Customer before notifying any affected third party.
4. Vendor Processing of Personal Data
4.1. Vendor Processor Purposes for Processing. Vendor will at all times (and shall ensure that any of its Sub-processors as applicable): (i) process the Personal Data solely for the purposes defined in the Agreement (“Permitted Purpose“), particularly under Schedules 1 and 2 of this DPA, and only in accordance with Customer’s documented lawful instructions; and (ii) not process the Personal Data for its own purposes or those of any third-party. Vendor shall not (a) sell or disclose Personal Data for monetary or other valuable consideration; (b) retain, use or disclose Personal Data for any purpose other than for the Permitted Purpose, including retaining, using or disclosing Personal Data for a commercial purpose other than performing the Services under the Agreement; or (iii) retain, use, or disclose Personal Data outside the direct business relationship between vendor and Customer.
4.2. Reservation of Rights. Vendor shall not at any time acquire any ownership, license, rights, title, or other interest in or to Personal Data, all of which shall, as between Customer and Vendor, be and remain the proprietary and confidential information of Customer.
4.3. Vendor Processor Obligations. In the event that Vendor or any of its authorized third parties, including its Sub-processors (as applicable), collects any Personal Data on behalf of Customer or furnishes or otherwise provides Personal Data to Customer in relation to the Services, then Vendor represents, warrants, and covenants that (i) it shall (and shall procure that any of its Sub-processors) do so in compliance with all Applicable Data Protection Law; and (ii) it has (and has ensured that its Sub-processors have) provided appropriate notice to individuals and obtained all necessary consents, approvals, and authorizations to provide such Personal Data to Customer in compliance with Applicable Data Protection Law and any instructions provided by Customer.
4.4. Compliance with Applicable Data Protection Law. Each Party shall comply with its obligations under Applicable Data Protection Law with respect to any Personal Data it processes under this DPA and the Agreement.
4.5. Third Party Controller Notices. Where Customer is itself a processor or service provider (as applicable) of the Personal Data acting on behalf of a Third Party Controller, Customer shall serve as the sole point of contact for Vendor and Vendor need not interact directly with (including to seek any authorizations directly from) any such Third Party Controller, other than through the regular provision of the Services to the extent required under the Agreement. Where Vendor would (including for the purposes of the SCCs) otherwise be required to provide information, assistance, cooperation, or other notification to such Third Party Controller, Vendor shall provide it solely to Customer.
5. Sub-processing
5.1. Authorized Sub-processors. Customer generally authorizes Vendor to engage Sub-processors in accordance with this Section 5 and approves Vendor’s use of the Sub-processors listed in the Sub-processors List referenced at Schedule 4 (accessible via https://trust.propelleraero.com/).
5.2. Notice. Vendor will update the Subprocessors List at least 14 days before appointing a new Subprocessor and will provide Customer with a mechanism to receive notifications of new Sub-processors (together, a “Change Notice”), which is presently available as an opt-in update notification at https://trust.propelleraero.com/.
5.3. Objections to Sub-processors. Customer may object to a new Sub-processor on reasonable grounds related to the protection of Personal Data by sending an email to security@propelleraero.com describing its legitimate, good-faith objection (an “Objection Notice”) within 14 days of a Change Notice , in which case Vendor may satisfy the objection by (a) not using the new Sub-processor to process Customer Personal Data; (b) taking corrective steps requested by Customer in its Objection Notice; or (c) ceasing to provide the parts of the Services that involve the new Sub-processor Processing Customer Personal Data, subject to a mutual agreement of the Parties to adjust the remuneration for the Services considering their reduced scope. If none of the options outlined above are reasonably available and Customer’s objection cannot be resolved to the Parties’ mutual satisfaction, either Party may terminate the affected Order upon written notice to the other Party, with such termination effective as of the date specified in the notice. For the avoidance of doubt, on such termination Customer shall not be entitled to any pro-rated or other refund of fees prepaid or otherwise due under the affected Order Form or Agreement. If Customer does not provide an Objection Notice within 14 days of a Change Notice, Customer will be deemed to have authorized Vendor’s use of the Subprocessor and to have waived its right to object.
5.4. Sub-processor Requirements. To the extent Personal Data is subject to European Data Protection Law, Vendor shall:
5.4.1. enter into a written agreement with each Sub-processor imposing data protection terms that require Sub-processor to protect Personal Data to the standard required by applicable European Data Protection Law and this DPA (including its Schedules);
5.4.2. retain Sub-processors which present sufficient guarantees in terms of security and data protection in accordance with European Data Protection Law;
5.4.3. ensure the Sub-processor processes Personal Data strictly for the Permitted Purpose;
5.4.4. remain responsible for its compliance with the obligations of this DPA and for any acts or omissions of the Sub-processor that cause Vendor to breach any of its obligations under this DPA.
6. Cooperation and Individual Rights
6.1. Notices and Requests. Vendor shall, taking into account the nature of the processing, reasonably cooperate with Customer to enable Customer (or its Third Party Controller) to respond to any requests, complaints or other communications from data subjects, consumers, governmental and regulatory or judicial bodies relating to the processing of the Personal Data under the Agreement, including requests from data subjects seeking to exercise their rights under Applicable Data Protection Law. In the event that any such request, complaint or communication is made directly to Vendor by a data subject, Vendor shall promptly notify Customer in writing at privacy@[customer email] (or best customer contact email address available to Vendor) and shall not respond to such communication without Customer’s express authorization.
6.2. Government or Regulatory Requests. If Vendor becomes aware that any government agency or authority (including law enforcement or national security) requests access to the Personal Data (whether on a voluntary basis or through a subpoena or court order), Vendor shall: (i) promptly notify Customer by email; (ii) inform the government agency that Vendor is a processor of the data and is not authorized to disclose the data, and that Vendor will need to immediately notify Customer regarding the request; (iii) attempt to redirect the agency to request the data directly from Customer; (iv) reasonably cooperate with all instructions of Customer, including if Customer (or its Third Party Controller) wishes to limit, challenge or protect against disclosure; and (v) not provide access to the data unless and until authorized by Customer in writing. Vendor shall not be required to comply with the obligations under Section 6.2(i) to (v) in full if it is under a legal prohibition or mandatory legal compulsion that prevents it from complying. Vendor shall use reasonable and lawful efforts to challenge any such prohibition or compulsion, and Vendor shall only disclose the Personal Data to the extent it is legally required to do so and in accordance with applicable lawful process. In no event shall Vendor knowingly disclose the Personal Data in a massive, disproportionate, and indiscriminate manner that goes beyond what is necessary in a democratic society.
6.3. DPIA Assistance. If a processing activity under this Agreement is likely to pose a high risk to data subjects, Vendor will assist Customer (or its Third Party Controller) to carry out a data protection impact assessment. If a reasonable request is made by the Customer, Vendor will also help Customer consult the relevant data protection authority about that activity.
6.4. Customer Requests. Vendor will promptly deal with all inquiries from Customer relating to its processing of the Personal Data under the Agreement including making available all information necessary to demonstrate its compliance with Applicable Data Protection Law and this DPA.
6.5. Cooperation with Customer. Vendor undertakes to assist Customer in complying with Customer’s obligations regarding:
6.5.1. Prior consultation with a supervisory authority (as per Article 28.3 f and Article 36 in the GDPR)
6.5.2. Notification of a personal data breach to the supervisory authority and the data subjects, for instance in section 7.5 (as per article 28.3 f and Article 33-34 in the GDPR)
7. Security and Audits
7.1. Security Audit Standards. Vendor shall maintain records in accordance with SOC 2, Type II. Upon request, Vendor shall make available copies of relevant external compliance certifications, audit report summaries and/or other documentation reasonably required by Customer to verify Vendor’s compliance with this DPA (presently available at https://trust.propelleraero.com/). Upon request, Vendor shall also respond to necessary Customer security questionnaires and meet by teleconference or in person to address any follow up questions if necessary.
7.2. Security Measures. Taking into account the state of the art, the costs of implementation, and the nature, scope context and purposes of the Processing as well as the risk of varying likelihood and severity to the rights and freedoms of natural persons, Vendor shall implement and maintain appropriate technical and organizational security measures designed to protect Personal Data (including but not limited to Security Incidents) and to preserve the security and confidentiality of Personal Data. Such measures will include, at minimum, those measures described in Schedule 3 of this DPA (“Security Measures“). Vendor shall ensure that any person who is authorized by Vendor to process Personal Data shall be under an appropriate obligation of confidentiality (whether a contractual or statutory duty), including to ensure that the authorized person processes any Personal Data only for the purpose of delivering the Services under the Agreement to Customer.
7.3. Updates to Security Measures. Vendor shall regularly and periodically determine whether upgrades, additions or modifications of applicable controls or Security Measures are required to meet the obligations under this DPA, including upon actual or constructive knowledge of relevant changes in technology and internal and external threats to Personal Data and the Services. For clarity, Customer acknowledges that the Security Measures are subject to technical progress and development and that Vendor may update and/or modify the Security Measures from time to time, provided that such updates and/or modifications do not result in the degradation of the overall security of the Personal Data and continue to exceed the measures described in Schedule 3.
7.4. Data Access. Vendor shall ensure that any person who processes Personal Data on Vendor’s behalf: (a) is required to protect and process all Personal Data in a manner consistent with the terms of the Agreement and this DPA; and (b) will receive appropriate training by Vendor regarding the protection of Personal Data prior to receiving access to Personal Data.
7.5. Security Incident Response. Upon becoming aware of a Security Incident affecting Customer’s Personal Data, Vendor shall notify affected Customer within 72 hours in accordance with Section 3.2.3 and shall provide timely information relating to the Security Incident as it becomes known to Vendor, including the type of data affected, the categories and approximate number of affected person(s), and steps taken to mitigate the Security Incident.
7.6. Security Audits. On written request from Customer, Vendor shall provide written responses (which may include audit report summaries/extracts) to all reasonable requests for information made by Customer related to the Vendor’s processing of Personal Data necessary to confirm Vendor’s compliance with this DPA. Customer will first seek to verify Vendor’s compliance with this DPA through the documentation made available by Vendor (including the documents available at https://trust.propelleraero.com/) and the written responses described above. Where such means are insufficient to demonstrate Vendor’s compliance, Customer may conduct (directly or through a third-party auditor that is not a competitor of Vendor, subject to written confidentiality obligations) an audit of Vendor to verify Vendor’s compliance with the terms of this DPA. Any audit under this section must meet the following requirements: (a) Customer must provide Vendor at least 30 days’ prior written notice of a proposed audit unless otherwise required by a competent supervisory authority or Data Protection Laws; (b) Customer may not perform more than one audit in any 12-month period, except where required by a competent supervisory authority; (c) Customer and Vendor must mutually agree on the time, scope, and duration of the audit in advance; (d) Customer must reimburse Vendor for its time expended in connection with an audit at Vendor’s reasonable professional service rates, which will be made available to Customer on request; (e) Customer must ensure that its representatives performing an audit protect the confidentiality of all information obtained through the audit in accordance with the Agreement, execute an enhanced mutually agreeable nondisclosure agreement if requested by Vendor, and abide by Vendor’s security policies while on Vendor’s premises; and (f) Customer must promptly disclose to Vendor any written audit report created, and any findings of noncompliance discovered, as a result of the audit.
8. International Transfers
8.1. Processing Locations. Customer acknowledges and agrees that Vendor may transfer and process Personal Data to and in the United States, Australia, Singapore and anywhere else in the world where Vendor, its Affiliates or its Sub-processors maintain data processing operations. A current description of the locations in which Vendor stores and processes data is available at Where is my Propeller data stored and Processed?, as updated by Vendor from time to time. Vendor shall at all times ensure such transfers are made in compliance with the requirements of Applicable Data Protection Law and this DPA.
8.2. European Data Transfers. Vendor shall not transfer, whether by direct or onwards transfer, any Personal Data under this DPA that is protected by European Data Protection Laws (“European Data“) in or to any country, territory or recipient not recognized as providing an adequate level of protection for Personal Data (within the meaning of European Data Protection Law) (a “non-Adequate Country“), unless it first takes all such measures as are necessary to ensure the transfer is in compliance with European Data Protection Law. If Vendor processes European Data in a non-Adequate Country, such transfer shall take place on the basis of:
8.2.1. the EU-U.S. Data Privacy Framework (“EU-U.S. DPF”) and the UK Extension to the EU-U.S. DPF, as applicable; or
8.2.2. the EU SCCs and/or UK Addendum, as applicable.
In the event the Services are covered by more than one transfer mechanism, the transfer of European Data will be subject to a single transfer mechanism in the order listed in this Section 8.2. If the EU-U.S. DPF, or the UK Extension to the EU-U.S. DPF, is declared invalid, or if Vendor fails to re-certify for the EU-U.S. DPF, then the transfer of Personal Data will be subject to the transfer mechanism listed in Section 8.2.2.
8.3. Standard Contractual Clauses. The parties agree that where Customer transfers (directly or via onward transfer) European Data to Vendor located in a non-Adequate Country and the transfer mechanism listed in Section 8.2.1. does not apply, the parties agree to be subject to the Standard Contractual Clauses, which shall be automatically incorporated by reference and form an integral part of this DPA, as follows:
| SCC Element/Clause | Vendor as a Processor/Sub-processor | Vendor as a Controller |
| Module | Module Two (Section 2.1.1) or Three (Section 2.1.2) will apply | Module One will apply |
| Clause 7 – Docking Clause | Will apply | Will apply |
| Clause 9 – Sub-processors | Option 2 will apply, and the time period for prior notice of Sub-processor changes is identified in Section 5 above | N/A |
| Clause 11 – Optional Language | Will not apply | Will not apply |
| Clause 17 – Option | Option 1 will apply | Option 1 will apply |
| Clause 17 – Governing Law | Ireland | Ireland |
| Clause 18(b) – Forum | Courts of Ireland | Courts of Ireland |
| Annex I | Deemed completed with the information set out in Schedule 1 of this DPA | Deemed completed with the information set out in Schedule 2 of this DPA |
| Annex II | Subject to Sections 7.2 and 7.3 of this DPA, Annex II of the SCCs shall be deemed completed with the information set out in Schedule 3 to this DPA | Subject to Sections 7.2 and 7.3 of this DPA, Annex II of the SCCs shall be deemed completed with the information set out in Schedule 3 to this DPA |
8.3.1. UK Transfer Mechanism. In relation to European Data that is protected by the UK GDPR, the SCCs: (i) shall apply as completed in accordance with Sections 8.3.1 and 8.3.2 above; and (ii) shall be deemed amended as specified by the UK Addendum attached as Schedule 5, which shall deemed executed by the parties and incorporated into and form an integral part of this DPA. Any conflict between the terms of the SCCs and the UK Addendum shall be resolved in accordance with Section 10 and Section 11 of the UK Addendum.
8.3.2. Swiss Transfer Mechanism. To the extent the European Data is subject to the Swiss DPA, Vendor agrees to process such European Data in compliance with the SCCs, which are incorporated herein in full by reference and form an integral part of this DPA in accordance with Sections 8.3.1 and 8.3.2 and the following modifications:
i. references to “Regulation (EU) 2016/679” shall be interpreted as references to the Swiss DPA;
ii. references to specific Articles of “Regulation (EU) 2016/679” shall be replaced with the equivalent article or section of the Swiss DPA;
iii. references to “EU”, “Union” and “Member State” shall be replaced with references to “Switzerland”;
iv. Clause 13(a) and Part C of Annex II shall not be used and the “competent supervisory authority” shall be the Swiss Federal Data Protection and Information Commissioner;
v. references to the “competent supervisory authority” and “competent courts” shall be replaced with references to the “Swiss Federal Data Protection and Information Commissioner” and “applicable courts of Switzerland”;
vi. in Clause 17, the SCCs shall be governed by the laws of Switzerland;
vii. in Clause 18(b), disputes shall be resolved before the courts of Switzerland; and
viii. the SCCs shall also protect the data of legal entities until the entry into force of the revised Swiss Federal Data Protection Act.
8.4. Alternative Transfer Mechanism. Vendor shall promptly notify Customer in the event that a data protection authority and/or Applicable Data Protection Law no longer permits the lawful transfer of Personal Data to Vendor pursuant to the terms of this DPA and/or requires that the parties adopt an alternative transfer solution that complies with Applicable Data Protection Law, then without prejudice to any other right or remedy available to Customer, Vendor shall work with Customer and promptly take all reasonable and appropriate steps Customer may deem necessary to ensure such processing or transfer is in compliance with Applicable Data Protection Law.
9. Deletion & Return of Data
9.1. Deletion & Return. Upon Customer’s request prior to or within 14 days of termination or expiry of this DPA or Agreement, Vendor shall (and shall request that any Sub-processor shall) either securely destroy or return to Customer all Personal Data (including copies) in its possession or control in accordance with Schedule 1 of this DPA. Any relevant data stored in backups will be deleted according to Vendor’s retention schedule. This requirement shall not apply to the extent that Vendor is required by any applicable law to retain some or all of the Personal Data, in which event Vendor shall, on ongoing basis, isolate and protect the security and confidentiality of such Personal Data and prevent any further processing except to the extent required by such law and shall destroy or return to Customer all other Personal data; and/or immediately cease processing all Personal Data.
10. Limitation of Liability
10.1. Limitation of Liability. This DPA is fully subject to any limitations of liability set forth in the Agreement. Notwithstanding the foregoing, nothing in this DPA is intended to limit the parties’ direct liability towards data subjects or applicable supervisory data protection authorities where such liability cannot be limited by applicable law.
11. General
11.1. Disclosures. Vendor acknowledges that Customer may disclose this DPA and any relevant privacy provisions in the Agreement to the US Department of Commerce, the Federal Trade Commission, European data protection authority, or any other US or EU judicial or regulatory body upon their request.
11.2. Survival. The obligations placed upon the Vendor under this DPA (including, to the extent applicable, the Standard Contractual Clauses) shall survive so long as Vendor and/or its Sub-processors process Personal Data on behalf of Customer. The provisions contained in this DPA and its attachments, exhibits and schedules that by their context are intended to survive termination or expiration will survive. The accrued rights and liabilities of the parties, as well as any express or implied obligations of the parties shall survive termination of this DPA.
11.3. Governing Law. This DPA is governed by the law which governs the Agreement and any dispute between the parties is to be handled as set out in the Agreement, unless required otherwise by Applicable Data Protection Law or the Standard Contractual Clauses.
11.4. Order of Precedence. It is not the intention of either party to contradict or restrict any of the provisions set forth in the SCCs and, accordingly, if and to the extent the SCCs conflict with any provision of the Agreement (including this DPA), the SCCs shall prevail to the extent of such conflict.
11.5. Modifications. This DPA may not be modified except by a subsequent written instrument signed by both parties.
11.6. Severability. If any part of this DPA is held unenforceable, the DPA will be interpreted with the unenforceable portion of the DPA deleted, and the validity of all remaining parts will not be affected.
11.7. Conflicts. Except for the changes made by this DPA, the Agreement remains unchanged and in full force and effect. In the event of any conflict between this DPA and any data privacy provisions set out in any Agreement, the parties agree that the terms of this DPA shall prevail.
11.8. Customer Entities. Each corporate entity of Customer has the right to enforce all the provisions of this DPA.
Schedule 1 (C2P and P2P Transfers)
Description of Processing Activities/Transfer
Annex 1(A) List of Parties:
| Data Exporter | Data Importer |
| Name: [company] | Name: Propeller Aero, Inc. |
| Address: | Address: 3033 Larimer Street, Denver CO 80205, USA |
| Contact person’s name, position and contact details: [Insert] | Contact person’s contact details: privacy@propelleraero.com.au |
| Activities relevant to the transfer: See Annex 1(B) below | Activities relevant to the transfer: See Annex 1(B) below |
| Role: Controller or processor | Role: Processor |
Annex 1(B) Description of Transfer:
| Description | |
| Categories of data subjects: |
X Employees – past, present, potential, and future staff (including volunteers, agents, interns, and temporary workers) of Customer ☐ Spouses and dependents – past, present, potential, and future spouses and |dependents of employees of Customer X Business partners, suppliers and vendors – past, present, potential and future advisors, consultants, suppliers, contractors, subcontractors, and other professionals engaged by Customer and related staff X Customers – past, present, potential, and future business customers of Customer ☐ Customer Contacts – past, present, potential, and future subscribers and other contacts of Customer customers ☐ Visitors – past, present, potential, and future prospects, customers, or others who visit Customer online properties ☐ Other – please specify: |
| Categories of personal data: | X Customer Customer data (name, username, email address, online identifiers such as IP address)
X Customer Customer Contact data (email addresses, device identifiers) X Customer Customer financial information (credit card details, account details, payment information) X Customer Employee data (job title, company name, grade, geographic location, employee performance and evaluation data, discipline information, previous roles, benefits information such as leave requests, health insurance company) X Customer Employee IT information (account or portal log on and/or registration details, usage data, location data) ☐ Other – please specify: |
| Sensitive data: | ☐ Yes
X No If yes, please specify: |
| If sensitive data, the applied restrictions or safeguards | X N/A
☐ See Schedule 3 for applied restrictions and safeguards |
| Frequency of the transfer: | ☐ Continuous
☐ One-off X The transfer may occur on a continuous or one-off basis depending on the Services provided by Vendor. |
| Purpose, nature and subject matter of processing: | Vendor is a processor or sub-processor to Customer and will Process Personal Data as necessary to perform the Services pursuant to the Agreement and as further instructed by Customer in its use of the Services. |
| Duration of the processing: | The duration of the data processing under this DPA is until the termination of the Agreement in accordance with its terms plus the period from the expiry of the Agreement until deletion of the Personal Data in accordance with the terms of the Agreement and the DPA. |
| Retention period (or, if not possible to determine, the criteria used to determine that period): | Upon Customer’s request prior to or within 14 days of termination or expiry of this DPA or Agreement, whichever happens first, Vendor shall (and shall request that any Sub-processor shall) either securely destroy or return to Customer all Personal Data in its possession or control, save that this requirement shall not apply to the extent Vendor is required by applicable law to retain some or all of the Personal Data, which Vendor shall securely isolate and protect and prevent any further processing and destroy in accordance with applicable law. |
Annex 1(C) Competent Supervisory Authority:
The competent supervisory authority, in accordance with Clause 13 of the SCCs will be determined in accordance with European Data Protection Law.
Schedule 2 (C2C Transfers)
Description of Processing Activities/Transfer
Annex 2(A) List of Parties:
| Data Exporter | Data Importer |
| Name: [company] | Name: Vendor is the party identified as the Vendor in the Agreement and this DPA. |
| Address: | Address: 3033 Larimer Street, Denver CO 80205, USA |
| Contact person’s name, position and contact details: [Insert] | Contact person’s contact details: privacy@propelleraero.com.au |
| Activities relevant to the transfer: See Annex 1(B) below | Activities relevant to the transfer: See Annex 1(B) below |
| Role: Controller | Role: Controller |
Annex 2(B) Description of Transfer:
| Description | |
| Categories of data subjects: |
X Employees – past, present, potential, and future staff (including volunteers, agents, interns, and temporary workers) of Customer ☐ Spouses and dependents – past, present, potential, and future spouses and dependents of employees of Customer X Business partners, suppliers and vendors – past, present, potential and future advisors, consultants, suppliers, contractors, subcontractors, and other professionals engaged by Customer and related staff X Customers – past, present, potential, and future business customers of Customer ☐ Customer Contacts – past, present, potential, and future subscribers and other contacts of Customer customers ☐ Visitors – past, present, potential, and future prospects, customers, or others who visit Customer online properties ☐ Other – please specify: |
| Categories of personal data: | X Customer Customer data (name, username, email address, online identifiers such as IP address)
X Customer Customer Contact data (email addresses, device identifiers) ☐ Customer Customer financial information (credit card details, account details, payment information) X Customer Employee data (job title, company name, grade, geographic location, employee performance and evaluation data, discipline information, previous roles, benefits information such as leave requests, health insurance company) X Customer Employee IT information (account or portal log on and/or registration details, usage data, location data) ☐ Other – please specify: |
| Sensitive data: | ☐ Yes
X No If yes, please specify: |
| If sensitive data, the applied restrictions or safeguards | X N/A
☐ See Schedule 3 for applied restrictions and safeguards |
| Frequency of the transfer: | ☐ Continuous
☐ One-off X The transfer may occur on a continuous or one-off basis depending on the Services provided by Vendor. |
| Purpose, nature and subject matter of processing: | Only as described in Section 3.2.2 of this DPA. |
| Retention period (or, if not possible to determine, the criteria used to determine that period): | Vendor will not, and will not permit any third party, to retain the Personal Data for longer than the period during which Vendor has a legitimate need to retain the Personal Data in accordance with the DPA and in compliance with Applicable Data Protection Law. |
Annex 2(C) Competent Supervisory Authority:
The competent supervisory authority, in accordance with Clause 13 of the SCCs will be determined in accordance with European Data Protection Law.
Schedule 3
Technical and Organizational Measures
Description of the technical and organisational security measures implemented by the processor(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, as well as the risks for the rights and freedoms of natural persons.
Technical and Organizational measures may change from time to time. For the most recent information, please visit our Platform Security page at this link: https://www.propelleraero.com/propeller-platform-security/.
The following technical and organizational measures were implemented by the Vendor according to the general state of the art:
Physical Security
Server and Network Security
Propeller hosts the majority of its application on the Amazon Web Services (AWS) platform. AWS provides state-of-the-art data center security that complies with industry standards such as SOC, PCI DSS, and ISO 27001. All physical network and server security responsibility for these parts of the application is delegated to AWS. For more information regarding AWS’s physical security practices, check out their security whitepaper.
Propeller hosts its own dedicated server fleet for the intensive data processing tasks required to generate the 3D models that Propeller produces. These servers and their network are housed in secure buildings, protected by self-closing, swipe-access doors, alarms, and security cameras. They are further protected by a locked physical barrier around the servers themselves.
Office Security
Our physical offices are secured with self-closing, self-locking doors only accessible by electronic swipe card or keycode. All access is securely logged, and we only delegate control system access to select, trusted individuals. Further, all our entrances and stairwells are monitored and recorded by security cameras. The premises are also alarmed outside of office hours with a back-to-base motion detection system. Automated fire suppression systems are installed, as well.
Staff Devices
All devices used by our staff members are required to be password protected, with automatic locking after short periods of disuse in addition to full-disk encryption. Staff are further required to enable multi-factor authentication (MFA) on all services that provide it.
Network Security
Much like our physical network security, the majority of our virtual network security is handled by AWS. Amazon provides completely isolated environments where we deploy our applications, and they do so for over one million companies and government organizations across the globe. Some well-known clients who use Amazon to protect their data include NASA, Shell, Autodesk, British Gas, GE, Hitachi, Lafarge, Trimble, and the US State Department. For more information regarding AWS’s virtual network security practices, check out their security whitepaper and their trust centre.
On top of the security outlined above, Propeller implements several other best practice measures on premises and in AWS to further ensure your data’s safety:
Firewalls
We use network firewalls to restrict access to systems from external networks and between systems internally. By default, all access is denied and only explicitly allowed ports and protocols are permitted based on business need. Each system is assigned to a firewall security group or has a firewall policy based on the system’s function. To mitigate risk, our firewalls restrict access to only the ports and protocols required for a system’s specific function.
We also use dedicated web application firewalls (WAFs) to protect HTTP-based services through rate limiting and packet inspection. These firewalls inspect requests for malicious payloads such as SQL injection, cross site scripting (XSS), and other known attacks, and block them accordingly. They similarly provide protection from distributed denial of service (DDoS) attacks through rate limiting and by blocking requests from known malicious botnets.
Intrusion Detection and Monitoring
All network traffic and API calls to underlying AWS infrastructure are securely logged and continuously analyzed against integrated threat intelligence feeds and using machine learning to detect suspicious behaviour.
If something is detected, an alert is immediately sent to our security team, who assess the threat and deals with it appropriately.
Change Control
We maintain all configuration in code to maintain transparency when it comes to underlying network and infrastructure changes. It’s checked into version control and all changes are reviewed for security, scalability, and durability before deployment. We also test all changes thoroughly in a dedicated staging environment before deployment to the production environment.
Server Isolation
Per best practices, servers are isolated in private subnets so they cannot be accessed from the internet. Should access be required, it can only be obtained via a bastion host that’s been hardened against attack. This narrows the possible attack vectors, allows for logging of access, and creates an easy way to revoke access if there is an attack.
Server Security
Security Patching
Propeller’s servers are automatically and continuously patched with the latest security updates. This ensures that we are able to minimize our exposure to known vulnerabilities.
Disk Encryption
Propeller’s servers employ the use of full disk encryption to ensure that data stored on them is not accessible to others. This protects the data both in case of physical access to the servers and when disks are disposed of.
Application Security
Change Control
As a web application, code changes are made and deployed in a continuous manner. No action is required to update to the latest version beyond refreshing the browser. In order to maintain application security, code quality, and minimize the introduction of bugs, we follow a strict software development life cycle (SDLC).
Design and Development
New features and changes are thoroughly architected and designed. Once approved, development begins and all code is checked into source control.
Review
All code changes are subject to peer review for quality, performance, and correctness. Code is also reviewed from a security standpoint, adhering to the OWASP top 10 guidelines.
Staging Release
After the review period, changes are deployed into a staging environment where they’re thoroughly tested by developers and our QA team. We perform both feature and regression testing to ensure that changes behave as intended and haven’t introduced errors elsewhere.
Production Release
When this testing is complete and any required fixes are made, the changes are deployed in a staggered release for customer use. Large or experimental changes may be deployed as beta features for a limited time. Users may have (or may request) the ability to opt out of features that impact existing workflows during this time.
Post Release
Feedback and bug reports are gathered from customers, and changes and fixes are made as appropriate.
Emergencies
In rare situations where changes must be applied quickly to recover from a security or downtime incident, some of the above steps such as code reviews, testing, and the staging release may be skipped by limited permitted staff members. Should this occur, all changes made during an emergency fix will be subject to standard review and testing once things have returned to normal.
Authentication and Authorization
Passwords
Propeller’s main login method is via email address and password. Your password is never stored in plain text. All passwords are salted and hashed multiple times using the PBKDF2 algorithm with a SHA256 hash, as recommended by the National Institute of Standards and Technology (NIST).
Passwords must also meet two complexity requirements: (1) be at least nine characters long and (2) must not exist in this list of top 20,000 most common passwords.
Should you forget your password, it can be reset by providing the email linked to your account. A link with a cryptographic token is sent to the address provided, allowing you to reset your password.
Single Sign On (SSO)
Users with Google or Trimble Connect accounts may use the respective “Sign in with” buttons to log into Propeller for a single sign on experience without any additional setup.
Customers can have their own SSO providers (such as Ping Identity or Okta) integrated into their portals for an additional fee. Integration can be achieved with providers that support the OAuth2, OpenID Connect, or SAML protocols.
Users must first be invited by another user with the correct permissions before SSO can be used.
Multi-Factor Authentication (MFA)
MFA is not supported when logging in with an email and password, however, customers can provide and enforce MFA by integrating an SSO solution with multifactor support. All Propeller employees are required to login with MFA to further ensure data safety.
Cookies
Once a user is logged in, Propeller stores session tokens as secure, HTTP-only cookies on the user’s browser to identify them as having access. This is further protected through the use of cross site request forgery (CSRF) tokens and strict CORS policies to prevent cross-domain requests and unauthorized use of the cookie. Cookies expire after two weeks, which means users are automatically logged out. The Propeller mobile app automatically refreshes session tokens provided the user opens the app at least once every two weeks.
Vulnerability Mitigation
In addition to the code reviews mentioned above, we use several other measures to ensure vulnerabilities are not present in the application.
Dependency Analysis
Static analysis is run on all code repositories to scan their dependencies for known vulnerabilities as recorded in the National Vulnerability Database (NVD), managed by NIST. The containers in which Propeller deploys its services and applications are similarly scanned. Automated alerts are sent to relevant developers who apply the recommended fix as promptly as possible based on the relevance and severity of the issue.
Penetration Testing
We have also employed third-party penetration testers to find and report vulnerabilities in our application and systems. Once a report is made, it’s triaged, assessed for severity, and the vulnerability is patched appropriately.
Data Sanitization
User inputted data may be stored in a database and re-rendered in the browser. This can open the opportunity for SQL injection and cross site scripting (XSS) attacks. In order to prevent these attacks, web application firewalls block all requests detected to contain malicious payloads. For further security, all data entered into databases or rendered to HTML is sanitised appropriately.
Logging and Monitoring
In order to provide an audit trail and to enable quick investigation of potential threats or issues, all requests to Propeller services are securely logged with enough information to recreate events.
Some information that may be logged includes IP addresses, request headers, request payloads, device information, status codes, response times, and failed login attempts. We never log confidential or sensitive data. All logs are retained and backed up for the duration of their usefulness. Additionally, error rates and performance metrics are constantly monitored to ensure you have the best possible end-user experience.
Availability
AWS is well known for its stability and reliability. This is backed up by service level agreements that ensure uptime and keep AWS accountable for downtime. Nevertheless, outages can occur in exceptional circumstances.
As such, we’ve designed all of our services to be highly available and failure-resilient. To accomplish this, we replicate all compute and database functions across multiple instances in multiple, geographically separated AWS availability zones. All hosts and applications are also constantly monitored for availability. Should a failure occur, an automated fallback is initiated. This strategy mitigates both instance and data center-level failure.
Our data processing systems are similarly designed such that we automatically fall back to using AWS servers if our dedicated server fleet is unavailable. This means that these systems are just as available as if they were hosted in the cloud, across multiple data centers.
Furthermore, the services comprising the application are monitored using an external tool that monitors uptime from several locations across the globe. If an outage occurs, a technical member of our staff is alerted immediately and a resolution is made as quickly as possible based on the severity of the outage. Propeller endeavors to maintain a 99% yearly uptime.
Scalability
Since the beginning, we’ve designed the Propeller Platform to meet the large data requirements that come with processing, hosting, analyzing, and serving survey-grade mapping data across the globe. We do this primarily by leveraging AWS’s effectively infinite scalability and global coverage. This, coupled with demand-based, application-, and infrastructure-level autoscaling, means that we can quickly and easily scale up our applications, and the underlying infrastructure, to meet any level of demand.
Information Security
Propeller classifies all user-submitted information as confidential and essential. We use several methods to ensure that customer data is always available and secure:
Data Storage and Transmission
All data submitted to and from the Propeller Platform is encrypted and transmitted securely over HTTPS using TLSv1.2 or higher, with a 128-bit cipher or higher, depending on the client. All internal transfers of data between Propeller services are similarly protected by encryption.
Once submitted, all data is stored securely in AWS with access controls preventing unauthorized access. S3 buckets are configured to be private by default and access keys or pre-signed URLs are required to access the data. Similarly, databases are password protected and may be accessed from only whitelisted IP addresses. Access and permissions to alter or delete data is only delegated where necessary and based on the principle of least privilege.
All data for processing or display is uploaded to an S3 bucket located in the Australian AWS region, unless a Customer has elected to have their data stored in a specific region for a fee. From here the data is transferred, with encryption, to on-premises or AWS servers in Australia or Singapore for processing. These servers store this data, with encryption, until it is no longer required for processing.
Any outputs resulting from processing are pushed to an S3 bucket in the AWS region closest to the customer, which may be in one of several sites across the globe. Available storage locations that can be used to store customer data include India, South Korea, Singapore, Australia, Japan, Canada, Germany, Ireland, England, France, South America and the United States of America. Propeller does not store any customer data in Russia or China. This is done to improve delivery performance when customers request the data.
Metadata and other data entered into the platform are stored in RDS databases located in a US-based AWS region.
Where practicable, all data is encrypted at rest, including in queues, databases, data volumes, and S3 using AES256 encryption. Encryption keys are created, managed, and secured using the AWS Key Management Service (KMS). We automatically rotate keys yearly.
Access Controls
In addition to the aforementioned storage level access controls, the Propeller Platform provides user-configurable access controls at an application level. We deny access to the data within a portal or site by default, and require a portal administrator, or another user with the Manage Access permission, to invite a user to view the data within a portal. It’s possible to specify fine-grained permissions when granting access, allowing the principle of least privilege to be applied. To make it easier to manage users and their permissions, they can be grouped into teams that can also be assigned permissions.
Disaster Recovery
In the unlikely event of customer data loss, procedures and safeguards are in place to ensure recovery. The majority of customer data is stored in Amazon’s S3 which is rated to have 99.999999999% durability. All services are expected to perform daily backups at a minimum, ensuring we do not lose more than 24 hours of data in the case of an emergency recovery. All services will be documented and automated such that they could be restored from a critical failure within 48 hours. On top of this, object versioning is enabled by default on all buckets, which ensures that even if an object is deleted or overwritten, it can be recovered.
The remaining customer data is stored in continuously backed-up Amazon RDS databases, providing point-in-time recovery to the minute. Furthermore, daily snapshots, alongside continuous replication to a hot spare with automatic failover in another availability zone, provides more redundancy and resilience to instance and data center-level failures.
Similarly, all application services are deployed in a highly available manner with automatic recovery from instance and data center-level failures.
Business Continuity
Operating since 2014, we have a proven track record of delivering excellence to our many customers across the globe. As a part of this, all customer data is available for download through the Platform. In the exceedingly unlikely event that Propeller should cease business operations, or if you would like to take your business elsewhere, your data will remain available for download for a reasonable amount of time (60 days).
Privacy
Propeller complies with all local privacy laws, including the General Data Protection Regulation (GDPR), and is committed to keeping your personal data safe and secure. For more information, view our privacy policy.
Data Breaches
In the event of unauthorized access to your data we will notify you as soon as possible (within 72 hours) after becoming aware of the issue affecting your data.
Schedule 4
List of Vendors Sub-processors as at time of the DPA and Agreement
Vendor’s current Sub-processors are listed at https://trust.propelleraero.com/subprocessors.
You can view this list at any time, and also manage your notification preferences at this link.
Schedule 5
UK Addendum
This Schedule 5 forms part of this DPA and applies in accordance with Section 8.3.3 (UK Transfer Mechanism) of the DPA.
| Start Date | The date of the Agreement | |
| Parties | Exporter | Importer |
| Parties’ details |
Name: [CUSTOMER] (“Customer”) Address: Contact person’s name, position and contact details: |
Name: Propeller Aero, Inc.
Address: 3033 Larimer Street, Denver CO 80205, USA Contact person’s contact details: privacy@propelleraero.com.au |
| Addendum SCCs | The Approved SCCs, including the Appendix Information and with only the following modules, clauses or optional provisions of the approved SCCs brought into effect for the purposes of this Addendum: See Section 8.3.3 of the DPA |
| Appendix Information | See Schedules 1 and 2 to this DPA |
| Ending this Addendum when the Approved Addendum changes | Neither Party |
| Mandatory Clauses | Part 2: Mandatory Clauses of the UK Addendum, as it is revised under Section 18 of those Mandatory Clauses |