Data Processing Addendum
This is a working draft prepared for review by qualified counsel. It is not legal advice and is not yet binding. Items in [SQUARE BRACKETS] are placeholders to be completed by REAT Global; notes marked “Counsel:” are decisions for review. See the placeholder register.
On this page
This Data Processing Addendum (“DPA”) forms part of the Tractrix Cloud Terms of Service (the “Agreement”) between the Customer and [LEGAL ENTITY NAME], trading as REAT Global (“REAT Global”). It applies whenever REAT Global processes Customer Personal Data on the Customer's behalf. An organisation owner or admin accepts it for the organisation in Tractrix Cloud (Organisation settings → Privacy), or it may be signed with an Order Form.
1. Scope and precedence
1.1 This DPA applies to Customer Personal Data processed by REAT Global in providing the Service. It does not apply to personal data for which REAT Global is an independent controller (account, security, billing and marketing data), which is described in the Privacy notice.
1.2 If this DPA conflicts with the Agreement, this DPA prevails for the processing of Customer Personal Data. If the Standard Contractual Clauses conflict with this DPA, the Standard Contractual Clauses prevail.
1.3 Capitalised terms not defined here have the meanings given in the Agreement.
2. Definitions
- Data Protection Laws
- All laws on the processing of personal data that apply to a party's processing under the Agreement, including the GDPR; the UK GDPR and Data Protection Act 2018; the Swiss Federal Act on Data Protection (nFADP); the California Consumer Privacy Act as amended (CCPA) and other US state privacy laws; the Brazilian LGPD; the South African POPIA; and other laws listed in the Privacy notice's regional supplements.
- Customer Personal Data
- Personal data in Customer Data processed by REAT Global on behalf of the Customer.
- controller, processor, data subject, personal data, processing, personal data breach, supervisory authority
- Have the meanings in the GDPR; equivalent terms in other Data Protection Laws (such as business, service provider, contractor, responsible party, operator, controlador and operador) are read accordingly.
- Sub-processor
- A third party engaged by REAT Global that processes Customer Personal Data.
- Standard Contractual Clauses (SCCs)
- The clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- UK Addendum
- The International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under s. 119A of the Data Protection Act 2018, version B1.0, in force 21 March 2022, as amended.
- Restricted Transfer
- A transfer of Customer Personal Data to a country that does not provide an adequate level of protection under the applicable Data Protection Laws.
3. Roles and details of processing
3.1 The Customer is the controller (or, where it acts for its own clients, a processor) of Customer Personal Data, and REAT Global is its processor (or sub-processor). The Customer is responsible for having a lawful basis and giving any notices required for the processing, and for the lawfulness of its instructions.
3.2 The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex I.
3.3 The Customer will not provide special-category data, criminal-offence data, or data of children to the Service, and will not upload classified or controlled data in breach of the Acceptable Use Policy.
4. Processing on instructions
4.1 REAT Global will process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers to a third country, unless required to do so by law to which REAT Global is subject; in that case it will inform the Customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest (GDPR Art. 28(3)(a)).
4.2 The Agreement, this DPA, and the Customer's use and configuration of the Service (for example uploading, running, sharing, exporting and deleting content, setting result retention and inviting members) are the Customer's complete documented instructions. Additional instructions require written agreement.
4.3 REAT Global will immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Laws (GDPR Art. 28(3), second subparagraph), and may suspend the affected processing until the instruction is confirmed or changed.
5. Confidentiality of personnel
REAT Global ensures that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b)), receive appropriate data protection and security training, and access Customer Personal Data only as needed to provide, support and secure the Service.
6. Security
6.1 REAT Global implements and maintains the technical and organisational measures in Annex II, which are designed to ensure a level of security appropriate to the risk as required by GDPR Art. 32 (Art. 28(3)(c)).
6.2 REAT Global may update these measures as technology and threats evolve, provided the overall level of security is not reduced. The Customer is responsible for its own secure use of the Service, including account and API token management, member roles and the security of data it exports.
7. Sub-processors
7.1 General authorisation. The Customer gives REAT Global general written authorisation to engage Sub-processors (Art. 28(2)). The current list is on the sub-processors page (Annex III).
7.2 Notice of changes. REAT Global will give at least 30 days' notice before adding or replacing a Sub-processor, by updating the sub-processors page and by e-mail to organisations that have subscribed to change notices (Organisation settings → Privacy) or to the owner of any organisation on a paid Plan. In an emergency (for example to maintain the security or availability of the Service) the notice period may be shorter, with notice given as soon as possible.
7.3 Objection. The Customer may object on reasonable data-protection grounds within the notice period by writing to [PRIVACY CONTACT EMAIL]. The parties will discuss the objection in good faith. If REAT Global cannot reasonably avoid using the new Sub-processor for the Customer's data, the Customer may terminate the affected subscription without penalty and receive a refund of prepaid Fees for the remaining period.
7.4 Flow-down and liability. REAT Global imposes on each Sub-processor, by written contract, data protection obligations that provide at least the same level of protection as this DPA, in particular sufficient guarantees of appropriate technical and organisational measures (Art. 28(4)). REAT Global remains fully liable to the Customer for each Sub-processor's performance.
8. Assistance
8.1 Data subject requests. Taking into account the nature of the processing, REAT Global assists the Customer by appropriate technical and organisational measures, insofar as possible, in responding to requests to exercise data subject rights (Art. 28(3)(e)). The Service lets the Customer access, correct, export and delete Customer Data itself. If REAT Global receives a request directly from a data subject about Customer Personal Data, it will not respond (other than to refer the data subject to the Customer) unless the Customer authorises it or the law requires, and will forward the request to the Customer without undue delay.
8.2 Other assistance. Taking into account the nature of the processing and the information available to it, REAT Global assists the Customer in ensuring compliance with its obligations under Arts 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation) (Art. 28(3)(f)), including by providing the information in this DPA and the security overview. Assistance beyond this that requires material effort may be charged at reasonable rates agreed in advance, except where the need arises from REAT Global's breach.
9. Personal data breach notification
9.1 REAT Global will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and in any event will aim to do so within 48 hours, so that the Customer can meet its own 72-hour notification obligation under Art. 33 GDPR.
9.2 The notification will be sent to the organisation owners' e-mail addresses (and any security contact the Customer has given us) and will describe, to the extent known: the nature of the breach, including the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and a contact point for more information. Where information is not available at once, REAT Global will provide it in phases without undue further delay.
9.3 REAT Global will take reasonable steps to contain, investigate and remediate the breach, keep a record of it, and cooperate with the Customer. Notification is not an acknowledgement of fault. REAT Global will not notify supervisory authorities or data subjects about a breach of Customer Personal Data on the Customer's behalf unless the Customer instructs it or the law requires it.
10. Government access requests
If a public authority requests access to Customer Personal Data, REAT Global will: (a) attempt to redirect the authority to request the data directly from the Customer; (b) notify the Customer promptly, unless legally prohibited, and if prohibited, use reasonable efforts to obtain a waiver; (c) review the legality of the request and challenge it where there are reasonable grounds to consider it unlawful, exhausting available remedies where appropriate; (d) disclose only the minimum data necessary to comply; and (e) document the request and its response. REAT Global will publish or provide on request aggregate information about such requests to the extent permitted by law. REAT Global has not built back doors into the Service and will not voluntarily grant authorities access to Customer Personal Data.
11. Information and audits
11.1 REAT Global makes available to the Customer all information necessary to demonstrate compliance with Art. 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or an independent auditor mandated by it (Art. 28(3)(h)).
11.2 To avoid disrupting the Service and the confidentiality of other customers, REAT Global will first answer written security questionnaires and provide its current security documentation, and any third-party certifications or audit reports it holds [SECURITY CERTIFICATIONS]. If that is not sufficient to demonstrate compliance, or a supervisory authority requires it, or after a personal data breach, the Customer may carry out an on-site or remote audit on at least 30 days' written notice, during business hours, no more than once a year (except after a breach or at an authority's request), by an auditor bound by confidentiality who is not a competitor of REAT Global, and at the Customer's cost. The parties will agree the scope in advance. REAT Global will inform the Customer immediately if, in its opinion, an audit instruction infringes Data Protection Laws.
12. Return and deletion
12.1 At the choice of the Customer, REAT Global will delete or return all Customer Personal Data after the end of the provision of the Service, and delete existing copies, unless the law requires storage (Art. 28(3)(g)). The Customer exercises this choice by exporting its data (as described in section 19 of the Cloud Terms) during the retrieval period of at least 30 days following termination; the Customer may also delete its data at any time before then.
12.2 After the retrieval period, REAT Global deletes Customer Personal Data from the live Service; deleted data is removed from backups when they expire, within [BACKUP RETENTION PERIOD]. Backups are protected and not used for any other purpose in the meantime. On request REAT Global will certify deletion in writing.
13. International transfers
13.1 Customer Personal Data is hosted in [HOSTING REGION]. REAT Global may transfer Customer Personal Data to other countries where it or its Sub-processors operate, subject to this section.
13.2 EEA transfers. To the extent the Customer's transfer to REAT Global, or REAT Global's onward transfer, is a Restricted Transfer under the GDPR, the SCCs are incorporated into this DPA by reference and apply as follows:
- Module Two (controller to processor) applies where the Customer is a controller, and Module Three (processor to processor) where the Customer is a processor;
- Clause 7 (docking clause) applies;
- Clause 9(a): Option 2 (general written authorisation) applies, with the notice period in section 7.2 of this DPA;
- Clause 11(a): the optional independent dispute resolution language does not apply;
- Clause 13: the competent supervisory authority is as set out in Annex I.C;
- Clause 17: Option 1 applies; the SCCs are governed by the law of [EU MEMBER STATE FOR SCCS];
- Clause 18(b): disputes are resolved by the courts of [EU MEMBER STATE FOR SCCS];
- Annexes I, II and III of the SCCs are completed with the information in Annexes I, II and III of this DPA;
- the audit, sub-processor, deletion and certification provisions of this DPA are the parties' agreed means of complying with the corresponding clauses of the SCCs.
13.3 UK transfers. For Restricted Transfers under the UK GDPR, the UK Addendum applies and is incorporated by reference. Table 1 is completed with the parties' details in Annex I; Table 2 with the modules and clause selections in section 13.2; Table 3 with Annexes I to III of this DPA; and in Table 4, both parties may end the UK Addendum as set out in its Section 19.
13.4 Swiss transfers. For Restricted Transfers under the nFADP, the SCCs apply as set out in section 13.2 with these amendments: references to the GDPR are read as references to the nFADP where the transfer is subject to it; the FDPIC is the competent supervisory authority; the term “member state” does not exclude data subjects in Switzerland from bringing claims in their place of habitual residence (Clause 18(c)); and, until the revised nFADP makes this unnecessary, the SCCs also protect data of legal entities where Swiss law requires.
13.5 Data Privacy Framework. Where a recipient is certified under the EU–US Data Privacy Framework, the UK Extension or the Swiss–US Data Privacy Framework, the parties may rely on that certification instead: [DPF CERTIFICATION STATUS].
13.6 Other jurisdictions. Where other Data Protection Laws restrict transfers (for example LGPD Art. 33, POPIA s. 72, Kenya DPA ss. 48–50, NDPA ss. 41–43, the Ethiopian Proclamation No. 1321/2024, the Saudi PDPL Transfer Regulations or PIPL Chapter III), the parties agree that the SCCs as incorporated above, adapted as needed, or the local standard clauses (such as the ANPD standard contractual clauses under Resolution CD/ANPD No. 19/2024) apply, and will execute any further documents the law requires.
13.7 Transfer impact. REAT Global has assessed the laws of the destination countries and will help the Customer with any transfer impact assessment by providing relevant information. If REAT Global can no longer comply with the transfer mechanism, it will notify the Customer, and the Customer may suspend the transfer and terminate the affected processing.
14. US state privacy law terms (CCPA service provider)
14.1 Where the CCPA applies, REAT Global is a service provider and receives Customer Personal Data for the limited and specified business purposes of providing, securing, supporting and improving the Service under the Agreement (Cal. Code Regs. tit. 11, § 7051). REAT Global:
- will not sell or share Customer Personal Data (as “sell” and “share” are defined in the CCPA);
- will not retain, use or disclose Customer Personal Data for any purpose (including any commercial purpose) other than the business purposes specified in the Agreement, or as otherwise permitted by the CCPA;
- will not retain, use or disclose Customer Personal Data outside the direct business relationship between REAT Global and the Customer;
- will not combine Customer Personal Data with personal information it receives from or on behalf of another person, or collects from its own interactions with consumers, except as permitted by the CCPA and its regulations;
- will comply with the obligations that apply to it under the CCPA and provide the same level of privacy protection as the CCPA requires of businesses;
- grants the Customer the right to take reasonable and appropriate steps to ensure that REAT Global uses Customer Personal Data consistently with the Customer's CCPA obligations (for example by the audit and information rights in section 11);
- will notify the Customer if it determines it can no longer meet its obligations under the CCPA;
- grants the Customer the right, on notice, to take reasonable and appropriate steps to stop and remediate unauthorised use of Customer Personal Data;
- will enable the Customer to comply with consumer requests, or comply with them when informed of them by the Customer; and
- will ensure that any sub-processor (contractor or service provider) it engages is bound by a written contract with the same obligations.
REAT Global certifies that it understands and will comply with these restrictions.
14.2 Where the Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Jersey, New Hampshire, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky or Rhode Island laws or any similar US state law apply, REAT Global is a processor and will: follow the Customer's instructions; ensure that each person processing Customer Personal Data is subject to a duty of confidentiality; delete or return Customer Personal Data at the end of the services as in section 12; make available information necessary to demonstrate compliance; allow and cooperate with reasonable assessments as in section 11; engage subcontractors only under written contracts that require them to meet the processor's obligations, with an opportunity for the Customer to object as in section 7; and assist the Customer in meeting its obligations, including in relation to data security, breach notification and data protection assessments.
15. Brazil (LGPD)
Where the LGPD applies, the Customer is the controlador and REAT Global the operador. REAT Global processes Customer Personal Data according to the Customer's lawful instructions (Art. 39), adopts the security measures in Annex II (Art. 46), notifies the Customer of security incidents that may create risk or relevant damage to data subjects as in section 9 so that it can inform the ANPD and data subjects within the period set by ANPD Resolution CD/ANPD No. 15/2024, and assists with data subject rights under Art. 18.
16. South Africa (POPIA)
Where POPIA applies, the Customer is the responsible party and REAT Global an operator. In accordance with sections 20 and 21 of POPIA, REAT Global: processes Customer Personal Data only with the knowledge or authorisation of the Customer; treats it as confidential and does not disclose it unless required by law or in the course of the proper performance of its duties; establishes and maintains the security measures referred to in section 19 (Annex II); and notifies the Customer immediately where there are reasonable grounds to believe that Customer Personal Data has been accessed or acquired by an unauthorised person (section 9 of this DPA).
17. Other Data Protection Laws
Where other Data Protection Laws impose processor obligations (for example PIPEDA and Québec's Law 25, Kenya's Data Protection Act 2019, Nigeria's NDPA 2023, Ethiopia's Proclamation No. 1321/2024, the UAE and Saudi PDPLs, India's DPDP Act 2023, Singapore's PDPA, Australia's Privacy Act 1988, New Zealand's Privacy Act 2020, Japan's APPI, Korea's PIPA and China's PIPL), REAT Global will comply with the obligations that apply to it as processor (or entrusted party) and the provisions of this DPA are to be read as implementing them. The parties will agree any additional terms that a local law makes mandatory.
18. Liability
Each party's liability under this DPA is subject to the exclusions and limitations of the Agreement, except that nothing limits a party's liability to data subjects under the SCCs or any liability that cannot be limited under Data Protection Laws. [Counsel: decide whether breaches of this DPA are subject to the general cap or to [DATA PROTECTION SUPER-CAP].]
19. Term and changes
This DPA lasts as long as REAT Global processes Customer Personal Data. REAT Global may update this DPA to reflect changes in Data Protection Laws, the Service or its Sub-processors, provided that the update does not materially reduce the protection of Customer Personal Data; material updates are notified as for changes to the Cloud Terms. Acceptance of a new version is recorded per organisation.
Annex I — Parties and description of processing
A. List of parties
| Data exporter | Data importer | |
|---|---|---|
| Name | The Customer, as identified in the organisation settings or Order Form | [LEGAL ENTITY NAME] (REAT Global) |
| Address | As given by the Customer | [REGISTERED ADDRESS] |
| Contact | The organisation owner(s) | [PRIVACY OFFICER NAME], [PRIVACY CONTACT EMAIL] |
| Activities | Use of Tractrix Cloud for airport and airside planning | Provision of Tractrix Cloud |
| Role | Controller (Module Two) or processor (Module Three) | Processor |
| Signature and date | By accepting this DPA in the Service or signing an Order Form that references it, on the date of acceptance. | |
B. Description of processing and transfer
- Categories of data subjects
- The Customer's Users (employees, contractors and consultants), and individuals whose names or other identifiers the Customer includes in projects, drawings, layer names, descriptions or reports (for example project team members or airport staff).
- Categories of personal data
- Identity and contact data of Users as shown within the organisation (name, e-mail address, role); attribution of projects, drawings and runs to the User who created them; any personal data contained in uploaded drawings, project descriptions or file and layer names. The Service is not designed for personal data; drawings normally contain only geometry.
- Sensitive data
- None intended. The Customer must not upload special-category data. Restrictions in the Acceptable Use Policy apply to security-sensitive infrastructure data.
- Frequency of transfer
- Continuous, for the duration of the Agreement.
- Nature of processing
- Hosting, storage, computation (simulation runs with the OpenAirside engine), rendering, export, backup, deletion, and access for support and security as instructed.
- Purpose
- Providing the Service to the Customer under the Agreement.
- Duration and retention
- For the term of the Agreement and the retrieval period in section 12, then deletion; results may be deleted earlier under a retention period set by the Customer's admins; backups expire within [BACKUP RETENTION PERIOD].
- Transfers to Sub-processors
- As listed on the sub-processors page, for hosting, database, e-mail delivery and support, for the duration above.
C. Competent supervisory authority
Where the Customer is established in the EEA, the supervisory authority of its member state of establishment (or lead authority). Where the Customer is not established in the EEA but falls under Art. 3(2) GDPR and has appointed a representative, the authority of the member state where the representative is established; otherwise the authority of the member state where the data subjects concerned are located. For the UK, the ICO; for Switzerland, the FDPIC.
Annex II — Technical and organisational measures
The measures below describe Tractrix Cloud as built. Items marked Planned are not yet in place and are not a commitment until this annex is updated to show them as implemented. Items marked Deployment depend on the production hosting configuration and are to be confirmed when the hosting provider is selected.
| Area | Measure | Status |
|---|---|---|
| Authentication | Passwords of at least 10 characters, hashed with Argon2id; constant-time verification including for unknown addresses; sign-up, resend and reset responses do not reveal whether an address is registered; e-mail verification required before sign-in | Implemented |
| Sessions | Short-lived (15-minute) signed access tokens, audience-bound and invalidated on password change or reset; access token held only in memory in the browser; refresh tokens random, stored only as SHA-256 hashes, rotated on every use with reuse detection that revokes the whole session family; refresh cookie HttpOnly, SameSite=Strict, path-restricted and Secure in production; custom request header required on cookie endpoints (CSRF defence in depth) | Implemented |
| One-time links | Verification, reset and invitation tokens are 256-bit random, single-use, stored as SHA-256 hashes and expire (24 hours, 60 minutes, 14 days) | Implemented |
| API tokens | High-entropy random tokens, shown once and stored only as SHA-256 hashes; bound to one user and one organisation; optional expiry; revocable by the user or an admin; stop working when the user leaves the organisation; cannot be used for account management; creation, revocation and last use recorded | Implemented |
| Multi-factor authentication and SSO | TOTP/WebAuthn second factor; SAML/OIDC single sign-on for Enterprise | Planned |
| Tenant isolation and access control | Every customer record carries its organisation identifier; all requests pass through a single authorisation layer that checks membership and role (viewer < member < admin < owner); child resources are loaded only through the organisation context, so identifiers from another tenant return “not found”; automated tests exercise every route family for cross-tenant access | Implemented |
| Rate limiting and abuse controls | Per-IP rate limits on sign-up, sign-in, verification, reset and password change; per-user limits on data exports and privacy requests; limits on request, upload and simulation size, path vertices, units per request, output density and run time; DXF and GeoJSON import caps on features and vertices | Implemented (single-instance; distributed rate limiting at the load balancer is Planned) |
| Application security headers | Content Security Policy without inline scripts; X-Frame-Options: DENY; X-Content-Type-Options: nosniff; Referrer-Policy; HSTS in production; Cache-Control: no-store on API responses; HTML reports served as attachments with a locked-down CSP | Implemented |
| Secrets management | The service refuses to start in production without a strong signing key; secrets, tokens and e-mail links are never written to logs; SMTP errors log only the error type | Implemented |
| Logging and monitoring | Security audit log of sign-ups, verification, sign-ins and failures, sign-out, refresh-token reuse, password changes and resets, organisation, member and invitation changes, token creation and revocation, project deletion, plan changes and privacy actions; never secrets; IP addresses truncated (/24 IPv4, /48 IPv6); retained 365 days; visible to organisation admins for their organisation | Implemented |
| Data minimisation and retention | Daily purge job for unverified accounts, expired tokens and sessions, old invitations, audit events and erased accounts, with configurable periods; pseudonymisation of audit and consent records on erasure; organisation-level result retention | Implemented |
| Encryption in transit | TLS (1.2 or higher) terminated at the reverse proxy for all external traffic; HSTS | Deployment |
| Encryption at rest | Database and backup volumes encrypted by the hosting provider (AES-256 or equivalent) | Deployment |
| Backups and recovery | Automated encrypted database backups retained for [BACKUP RETENTION PERIOD], with periodic restore tests; recovery objectives [RPO / RTO] | Deployment |
| Infrastructure | Container image built from the repository; runs as a non-root user; database schema managed by versioned migrations; health checks | Implemented |
| Secure development | Source code public and reviewable; automated test suite in continuous integration, including tenancy and migration tests; dependency pinning; code review of changes | Implemented |
| Vulnerability management | Coordinated disclosure policy and security.txt; automated dependency vulnerability scanning; periodic independent penetration test | Disclosure policy implemented; scanning and penetration testing Planned |
| Personnel | Confidentiality undertakings; least-privilege production access limited to named personnel, with access reviews; security and privacy training | Planned (to be formalised before general availability) |
| Incident response | Documented breach-response runbook with customer notification under section 9; annual rehearsal | Planned |
| Physical security | Provided by the hosting provider's certified data centres | Deployment |
| Business continuity | Open-source engine and documented protocol allow customers to continue work locally if the Service is unavailable | Implemented |
Annex III — Sub-processors
The authorised Sub-processors, their locations, the processing they perform and the transfer mechanism used are listed on the sub-processors page, which forms Annex III of this DPA and of the SCCs as updated under section 7.