Data Processing Agreement
Terms governing processing of personal data when Tegi S.à r.l.-S. acts as a processor for organization customers.
Last Updated: 04/08/2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Tegi S.à r.l.-S. (“Pilotflows”, “Processor”, “we”, or “us”) and the customer organization that uses Pilotflows organization features (“Controller”, “you”, or “Organization”). It applies where the GDPR or other applicable data protection law requires a written processing agreement under Article 28.
For processing where we act as an independent controller (for example account administration, billing, security, or product analytics), see our Privacy Policy.
1. Roles and scope
Flight schools, clubs, dropzones, and other Organizations upload and manage data about their members, students, instructors, jumpers, shop customers, and related individuals. For that organization-managed personal data in the Services, the Organization is the controller and Pilotflows is the processor.
Pilotflows acts as an independent controller where we determine the purposes and means of processing — for example operating user accounts, platform billing, security monitoring, abuse prevention, and product improvement — as described in the Privacy Policy. This DPA does not apply to that controller processing.
Organizations may publish their own legal sections (terms, disclaimers, and similar notices) in their shop footer and related surfaces. Those documents are the Organization’s terms with itscustomers. This DPA governs only the processor relationship between the Organization and Pilotflows; it does not replace the Organization’s own customer-facing legal terms.
2. Subject matter, duration, nature, and purpose
Subject matter. Provision of the Pilotflows Services, including hosting, storage, retrieval, display, transmission, and related technical processing of organization-managed personal data.
Duration. For the term of the Organization’s use of the Services, and thereafter until personal data is deleted or returned under section 10.
Nature and purpose. Processing necessary to provide, secure, support, and improve the contracted Services according to the Organization’s configuration and documented instructions — including member and student management, training and certificate records, flight and jump operations, hangar and gear workflows, accounting and shop features, and related communications through the Services.
3. Categories of data subjects and personal data
Depending on how the Organization uses the Services, data subjects may include organization members, students, instructors, pilots, skydivers and jumpers, shop customers, staff, and other individuals whose data the Organization stores in Pilotflows.
Personal data may include, without limitation:
- Identity and contact details (name, email, phone, address)
- Professional and membership information (roles, affiliations, ratings)
- Certificates, licences, medical expiry dates, and related documents
- Training records, lesson progress, and instructional notes
- Flight history, jump manifests, gear assignments, and operational logs
- Billing, invoicing, and shop transaction data relating to the Organization’s customers
- Other content the Organization or its authorized users upload
The Organization determines which categories it collects and is responsible for a lawful basis and any required notices or consents.
4. Processing instructions
Pilotflows processes personal data only on documented instructions from the Controller, including the main services agreement, product configuration, support requests the Organization initiates, and this DPA, unless required to do otherwise by applicable law. In that case, we will inform the Controller before processing, unless the law prohibits such notice. Use of the Services constitutes instructions to process personal data as needed to deliver the configured features.
5. Confidentiality
Pilotflows ensures that persons authorized to process personal data are bound by appropriate confidentiality obligations — by contract, professional duty, or statute — and that access is limited to personnel who need it to perform their roles.
6. Security measures
Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, Pilotflows implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk. Those measures are described in our Security Policy, which is incorporated by reference for the purposes of this DPA.
7. Sub-processors
The Controller authorizes Pilotflows to engage the sub-processors listed in Annex A. Pilotflows remains responsible for sub-processors to the extent required by applicable law, and imposes data-protection obligations on them that are no less protective than those in this DPA in relevant respects.
Material changes to the authorized list are reflected on our What Powers Us page and in Annex A. Organizations that require advance notice of specific changes may contact us at the address in section 13; where legally required, we will provide a reasonable opportunity to object to a material new sub-processor before it processes the Organization’s data.
8. Assistance with data subject requests
Taking into account the nature of the processing, Pilotflows assists the Controller by appropriate technical and organizational measures, insofar as possible, for fulfilling the Controller’s obligation to respond to data subject requests. The Organization remains responsible for verifying and responding to requests about organization-managed personal data; Pilotflows will not respond as controller for that data except where required by law or expressly instructed by the Organization.
9. Personal data breaches
If Pilotflows becomes aware of a personal data breach affecting organization-managed personal data we process on behalf of the Controller, we will notify the Controller without undue delay and provide information reasonably available to help the Controller meet its own notification obligations. Investigation, mitigation, and notifications when we act as an independent controller are further described in section 9 (Data breach) of our Privacy Policy.
10. Deletion or return on termination
At the end of processing services, Pilotflows will, at the Controller’s choice and subject to available product features, delete or return organization-managed personal data and delete existing copies, unless applicable law requires storage. Backup and archival copies may persist for a limited period consistent with our retention practices, then be deleted in the ordinary course. Deletion options are described in product documentation and the Privacy Policy.
11. Audit rights
Pilotflows makes available information necessary to demonstrate compliance with this DPA, and allows for and contributes to audits, including inspections by the Controller or an auditor it mandates, subject to reasonable notice, confidentiality, security, and operational constraints. Where possible, audits rely on documentation, certifications, or reports we already maintain. On-site audits require mutual agreement on scope, timing, and cost allocation where not mandated otherwise by law.
12. International transfers
Where personal data is transferred outside the EU/EEA in connection with the Services, Pilotflows uses appropriate safeguards such as the European Commission’s Standard Contractual Clauses (SCCs) or other mechanisms recognized under applicable data protection law — consistent with section 6 of our Privacy Policy. Sub-processor locations are indicated in Annex A.
13. Contact
Questions about this DPA or processing under it: [email protected]
Tegi S.à r.l.-S., Luxembourg
Annex A — Authorized subprocessors
The following subprocessors may process personal data on behalf of Pilotflows in connection with the Services. Current as of 4 August 2026. Operational vendors that do not process customer personal data as subprocessors (for example internal issue tracking) are omitted here and may appear on our What Powers Us page.
| Name | Purpose | Location |
|---|---|---|
| AirNav Radar | Flight and aircraft data enrichment for logbook and hangar features | United States |
| Amazon Web Services (AWS) | Object storage and related cloud services for files and application data | European Union and United States |
| Apple | App Store distribution and authentication when you use Sign in with Apple | United States |
| Apple In-App Purchase | In-app subscription and purchase processing on Apple platforms | United States |
| Apple Push Notification service (APNs) | Delivery of push notifications to Apple devices | United States |
| AVWX | Aviation weather (METAR/TAF) data for tools and in-product weather | United States |
| Better Stack | Centralized application logging and operational observability | European Union / United States |
| Calendly | Scheduling and meeting booking | United States |
| Cloudflare | DNS, CDN, edge security, and bot protection (e.g. Turnstile) where you submit data | European Union |
| Expo Push | Push notification delivery for Expo / React Native mobile clients | United States |
| Firebase Analytics (iOS SDK) | Mobile app usage analytics on Pilotflows for iOS (Google Analytics for Firebase via firebase-ios-sdk) | United States / regional processing per Google |
| Google Ads | Advertising measurement: browser tags with Consent Mode (marketing consent) and server-side offline conversion uploads of SHA-256 hashed email plus click IDs (gclid / gbraid / wbraid) | United States / regional processing per Google |
| Google Analytics | Website and product usage analytics (Google Analytics 4 via gtag), loaded only after analytics cookie consent; related Firebase Analytics streams power mobile measurement where configured | United States / regional processing per Google |
| Google Play Billing | In-app subscription and purchase processing on Google Play for the Pilotflows Android app | United States / regional processing per Google |
| Hetzner | Server hosting and compute where the service and your data are processed | Germany (EU data centers) |
| Mapbox | Maps and location-related features in the product | United States |
| Meta (Pixel and Conversions API) | Advertising measurement: Meta Pixel in the browser (marketing consent) and Conversions API server-side events with SHA-256 hashed email, external ID, IP address, and user agent | United States / regional processing per Meta |
| Meta Facebook iOS SDK | Mobile advertising and attribution events on iOS (consent-gated) | United States / regional processing per Meta |
| MongoDB | Primary database for accounts, organizations, logbooks, and related application data | European Union |
| RevenueCat | In-app subscription management and receipt validation | United States |
| SendGrid | Transactional and notification email to your email address | United States / regional processing per Twilio SendGrid |
| Sentry | Error and performance monitoring, including Session Replay sampled at 10% of sessions with all text masked and all media blocked | United States / regional processing per Sentry |
| Stripe | Payment processing and billing | United States and European Union |
| Twilio | SMS delivery to you when we send text messages | United States / regional processing per Twilio |
| Upstash | Managed Redis for caching, job queues, and related application data | United States / EU (per Upstash region) |
| Web Push | Browser push notification delivery via the Web Push protocol | Varies by browser push service |
| xAI | AI-assisted processing of logbook and import content you choose to submit (images/PDFs processed in-request and not retained on Pilotflows; temporary xAI Files API upload then deleted; in-memory extraction session ~15 minutes) | United States |