Data Processing Agreement

Terms governing processing of personal data when Tegi S.à r.l.-S. acts as a processor for organization customers.

Last Updated: 04/08/2026

This Data Processing Agreement (“DPA”) forms part of the agreement between Tegi S.à r.l.-S. (“Pilotflows”, “Processor”, “we”, or “us”) and the customer organization that uses Pilotflows organization features (“Controller”, “you”, or “Organization”). It applies where the GDPR or other applicable data protection law requires a written processing agreement under Article 28.

For processing where we act as an independent controller (for example account administration, billing, security, or product analytics), see our Privacy Policy.

1. Roles and scope

Flight schools, clubs, dropzones, and other Organizations upload and manage data about their members, students, instructors, jumpers, shop customers, and related individuals. For that organization-managed personal data in the Services, the Organization is the controller and Pilotflows is the processor.

Pilotflows acts as an independent controller where we determine the purposes and means of processing — for example operating user accounts, platform billing, security monitoring, abuse prevention, and product improvement — as described in the Privacy Policy. This DPA does not apply to that controller processing.

Organizations may publish their own legal sections (terms, disclaimers, and similar notices) in their shop footer and related surfaces. Those documents are the Organization’s terms with itscustomers. This DPA governs only the processor relationship between the Organization and Pilotflows; it does not replace the Organization’s own customer-facing legal terms.

2. Subject matter, duration, nature, and purpose

Subject matter. Provision of the Pilotflows Services, including hosting, storage, retrieval, display, transmission, and related technical processing of organization-managed personal data.

Duration. For the term of the Organization’s use of the Services, and thereafter until personal data is deleted or returned under section 10.

Nature and purpose. Processing necessary to provide, secure, support, and improve the contracted Services according to the Organization’s configuration and documented instructions — including member and student management, training and certificate records, flight and jump operations, hangar and gear workflows, accounting and shop features, and related communications through the Services.

3. Categories of data subjects and personal data

Depending on how the Organization uses the Services, data subjects may include organization members, students, instructors, pilots, skydivers and jumpers, shop customers, staff, and other individuals whose data the Organization stores in Pilotflows.

Personal data may include, without limitation:

  • Identity and contact details (name, email, phone, address)
  • Professional and membership information (roles, affiliations, ratings)
  • Certificates, licences, medical expiry dates, and related documents
  • Training records, lesson progress, and instructional notes
  • Flight history, jump manifests, gear assignments, and operational logs
  • Billing, invoicing, and shop transaction data relating to the Organization’s customers
  • Other content the Organization or its authorized users upload

The Organization determines which categories it collects and is responsible for a lawful basis and any required notices or consents.

4. Processing instructions

Pilotflows processes personal data only on documented instructions from the Controller, including the main services agreement, product configuration, support requests the Organization initiates, and this DPA, unless required to do otherwise by applicable law. In that case, we will inform the Controller before processing, unless the law prohibits such notice. Use of the Services constitutes instructions to process personal data as needed to deliver the configured features.

5. Confidentiality

Pilotflows ensures that persons authorized to process personal data are bound by appropriate confidentiality obligations — by contract, professional duty, or statute — and that access is limited to personnel who need it to perform their roles.

6. Security measures

Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, Pilotflows implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk. Those measures are described in our Security Policy, which is incorporated by reference for the purposes of this DPA.

7. Sub-processors

The Controller authorizes Pilotflows to engage the sub-processors listed in Annex A. Pilotflows remains responsible for sub-processors to the extent required by applicable law, and imposes data-protection obligations on them that are no less protective than those in this DPA in relevant respects.

Material changes to the authorized list are reflected on our What Powers Us page and in Annex A. Organizations that require advance notice of specific changes may contact us at the address in section 13; where legally required, we will provide a reasonable opportunity to object to a material new sub-processor before it processes the Organization’s data.

8. Assistance with data subject requests

Taking into account the nature of the processing, Pilotflows assists the Controller by appropriate technical and organizational measures, insofar as possible, for fulfilling the Controller’s obligation to respond to data subject requests. The Organization remains responsible for verifying and responding to requests about organization-managed personal data; Pilotflows will not respond as controller for that data except where required by law or expressly instructed by the Organization.

9. Personal data breaches

If Pilotflows becomes aware of a personal data breach affecting organization-managed personal data we process on behalf of the Controller, we will notify the Controller without undue delay and provide information reasonably available to help the Controller meet its own notification obligations. Investigation, mitigation, and notifications when we act as an independent controller are further described in section 9 (Data breach) of our Privacy Policy.

10. Deletion or return on termination

At the end of processing services, Pilotflows will, at the Controller’s choice and subject to available product features, delete or return organization-managed personal data and delete existing copies, unless applicable law requires storage. Backup and archival copies may persist for a limited period consistent with our retention practices, then be deleted in the ordinary course. Deletion options are described in product documentation and the Privacy Policy.

11. Audit rights

Pilotflows makes available information necessary to demonstrate compliance with this DPA, and allows for and contributes to audits, including inspections by the Controller or an auditor it mandates, subject to reasonable notice, confidentiality, security, and operational constraints. Where possible, audits rely on documentation, certifications, or reports we already maintain. On-site audits require mutual agreement on scope, timing, and cost allocation where not mandated otherwise by law.

12. International transfers

Where personal data is transferred outside the EU/EEA in connection with the Services, Pilotflows uses appropriate safeguards such as the European Commission’s Standard Contractual Clauses (SCCs) or other mechanisms recognized under applicable data protection law — consistent with section 6 of our Privacy Policy. Sub-processor locations are indicated in Annex A.

13. Contact

Questions about this DPA or processing under it: [email protected]
Tegi S.à r.l.-S., Luxembourg

Annex A — Authorized subprocessors

The following subprocessors may process personal data on behalf of Pilotflows in connection with the Services. Current as of 4 August 2026. Operational vendors that do not process customer personal data as subprocessors (for example internal issue tracking) are omitted here and may appear on our What Powers Us page.

NamePurposeLocation
AirNav RadarFlight and aircraft data enrichment for logbook and hangar featuresUnited States
Amazon Web Services (AWS)Object storage and related cloud services for files and application dataEuropean Union and United States
AppleApp Store distribution and authentication when you use Sign in with AppleUnited States
Apple In-App PurchaseIn-app subscription and purchase processing on Apple platformsUnited States
Apple Push Notification service (APNs)Delivery of push notifications to Apple devicesUnited States
AVWXAviation weather (METAR/TAF) data for tools and in-product weatherUnited States
Better StackCentralized application logging and operational observabilityEuropean Union / United States
CalendlyScheduling and meeting bookingUnited States
CloudflareDNS, CDN, edge security, and bot protection (e.g. Turnstile) where you submit dataEuropean Union
Expo PushPush notification delivery for Expo / React Native mobile clientsUnited States
Firebase Analytics (iOS SDK)Mobile app usage analytics on Pilotflows for iOS (Google Analytics for Firebase via firebase-ios-sdk)United States / regional processing per Google
Google AdsAdvertising measurement: browser tags with Consent Mode (marketing consent) and server-side offline conversion uploads of SHA-256 hashed email plus click IDs (gclid / gbraid / wbraid)United States / regional processing per Google
Google AnalyticsWebsite and product usage analytics (Google Analytics 4 via gtag), loaded only after analytics cookie consent; related Firebase Analytics streams power mobile measurement where configuredUnited States / regional processing per Google
Google Play BillingIn-app subscription and purchase processing on Google Play for the Pilotflows Android appUnited States / regional processing per Google
HetznerServer hosting and compute where the service and your data are processedGermany (EU data centers)
MapboxMaps and location-related features in the productUnited States
Meta (Pixel and Conversions API)Advertising measurement: Meta Pixel in the browser (marketing consent) and Conversions API server-side events with SHA-256 hashed email, external ID, IP address, and user agentUnited States / regional processing per Meta
Meta Facebook iOS SDKMobile advertising and attribution events on iOS (consent-gated)United States / regional processing per Meta
MongoDBPrimary database for accounts, organizations, logbooks, and related application dataEuropean Union
RevenueCatIn-app subscription management and receipt validationUnited States
SendGridTransactional and notification email to your email addressUnited States / regional processing per Twilio SendGrid
SentryError and performance monitoring, including Session Replay sampled at 10% of sessions with all text masked and all media blockedUnited States / regional processing per Sentry
StripePayment processing and billingUnited States and European Union
TwilioSMS delivery to you when we send text messagesUnited States / regional processing per Twilio
UpstashManaged Redis for caching, job queues, and related application dataUnited States / EU (per Upstash region)
Web PushBrowser push notification delivery via the Web Push protocolVaries by browser push service
xAIAI-assisted processing of logbook and import content you choose to submit (images/PDFs processed in-request and not retained on Pilotflows; temporary xAI Files API upload then deleted; in-memory extraction session ~15 minutes)United States