Important Notice
This Data Processing Agreement applies when NetJet Labs processes personal data on behalf of a Client
(Data Controller) who is subject to the General Data Protection Regulation (GDPR) or similar data
protection laws.
This DPA should be executed as a separate agreement between the parties. It supplements
our Terms of Service and Privacy Policy.
1. Definitions and Scope
Parties to This DPA
- Data Controller (Client): The organization that determines the purposes and means
of personal data processing
- Data Processor (NetJet Labs): We process personal data only as instructed by the
Data Controller
Subject Matter
This DPA governs our processing of personal data when:
- You (Client) provide us with data containing personal information
- We process that data as a Data Processor on your behalf
- The processing is subject to GDPR, CCPA, or similar laws
- We provide software development, maintenance, or consulting services
Definitions
Personal Data: Any information relating to an identified or identifiable natural person
(subject)
Processing: Any operation on personal data (collection, storage, use, deletion, etc.)
Data Subject: The individual to whom personal data relates
GDPR: General Data Protection Regulation (EU) 2016/679
2. Nature, Scope, and Duration of Processing
Processing Details
| Aspect |
Description |
| Purposes |
Software development, system implementation, maintenance, support, performance analysis |
| Types of Data |
As specified in individual Project Agreements (e.g., customer data, employee data, financial
data) |
| Categories of Data Subjects |
As specified in Project Agreements (e.g., customers, employees, users) |
| Duration |
For the term of the Service engagement plus retention periods in our Privacy Policy |
Specific Instructions
We process personal data only in accordance with:
- The Data Controller's written instructions (Project Agreement)
- This Data Processing Agreement
- Our Privacy Policy (as incorporated by reference)
- Applicable data protection laws
We do not determine the purpose or means of processing. We are a Data Processor and
follow your instructions.
3. Data Controller's Obligations
You Agree to:
Lawful Basis
- Ensure you have a lawful basis for processing personal data (consent, contract, legal obligation,
etc.)
- Provide clear instructions regarding processing
- Maintain compliance with GDPR Articles 12-22 (data subject rights)
Data Quality and Accuracy
- Ensure personal data provided is accurate and complete
- Update us of changes to instructions or requirements
- Ensure legality of the data before sharing
Authorization and Consent
- Ensure data subjects are informed of processing (privacy notice)
- Obtain necessary consents where required
- Honor data subject rights (access, deletion, etc.)
Transparency
- Inform data subjects about our role as processor
- Provide privacy notices mentioning NetJet Labs
- Disclose processing details
Data Protection Impact Assessment
- Conduct DPIA if processing involves high risk
- Consult with DPA if required by GDPR Article 36
- Share DPIA results with us if requested
Contractual Framework
- Ensure adequate contracts with sub-processors
- Maintain record of processing activities (Article 30)
- Keep documentation available for audits
4. Data Processor's Obligations
Our Commitments
Instruction Compliance
- Process personal data ONLY as instructed by you
- Not expand processing scope without written authorization
- Refuse unlawful instructions
- Notify you if an instruction appears unlawful (without liability)
Confidentiality
- All personnel accessing personal data are under confidentiality obligations
- Confidentiality obligations continue after employment
- We do not use data for our own purposes
Security Measures (Article 32)
We implement appropriate technical and organizational measures:
- Encryption: In transit (TLS/SSL) and at rest (AES-256)
- Access Controls: Limited access to authorized staff only
- Authentication: Strong password policies and MFA
- Network Security: Firewalls and intrusion detection
- Monitoring: 24/7 security monitoring and logging
- Incident Response: Procedures for responding to breaches
- Regular Testing: Penetration testing and security audits
- Backup: Secure, redundant backups in multiple locations
- Physical Security: Controlled access to facilities
- Staff Training: Regular data protection training
Note: Security measures are implemented according to Annex 2 (Appendix) of this DPA and are subject to
periodic review and updates.
Employee Obligations
- All employees with access to personal data sign confidentiality agreements
- Regular data protection training provided
- Staff understand obligations under GDPR
- Background checks conducted for sensitive roles
Documentation and Audits
- Maintain records of processing activities
- Provide audit reports upon request
- Permit audits by you or your auditor
- Cooperate with data protection authorities
- Provide certification of compliance if requested
Data Subject Rights (Article 28, 34-39)
We assist you in fulfilling data subject rights:
- Right to Access: Provide requested data within 15 days
- Right to Rectification: Correct inaccurate data
- Right to Erasure: Delete data upon request (with exceptions)
- Right to Restrict: Limit processing of data
- Right to Portability: Provide data in portable format
- Right to Object: Cease processing for specific purposes
- Automated Decision-Making: Provide safeguards where applicable
Response timeframes will be accommodated based on complexity.
Breach Notification (Article 33-34)
- Notify you immediately (without undue delay, ideally within 24 hours) of any personal data breach
- Provide details of: nature, scope, affected data subjects, likely impact
- Provide information to help you comply with breach notification requirements
- Cooperate in breach investigation and remediation
- Provide forensic analysis if requested
International Transfers (Chapter V, Section 4)
If we transfer personal data outside the EEA:
- We use appropriate safeguards (SCCs, Binding Corporate Rules)
- We require Sub-processors to implement safeguards
- We notify you of any transfer arrangements
- We assist with GDPR Article 44-50 compliance
Sub-Processors (Article 28.4, 28.6)
- Approved sub-processors listed in Annex 1
- Prior notification required before adding new sub-processors
- Objection mechanism allows you to block sub-processors
- Sub-processors bound by written contracts imposing same obligations
- Current sub-processors listed at: https://netjetlabs.com/sub-processors
5. Data Subject Rights Assistance
Your Responsibility
As Data Controller, you are responsible for responding to data subject requests. We assist by:
Access Requests (Article 15)
- Providing copies of personal data within 15 days
- Confirming processing activities
- Providing processing details in understandable format
- No charge unless request is manifestly unfounded
Rectification Requests (Article 16)
- Correcting inaccurate personal data
- Completing incomplete data
- Notifying recipients of corrections (where applicable)
Erasure Requests (Article 17)
- Deleting personal data from active systems
- Removing from backups within 90 days
- Notifying recipients of deletion
- Exceptions: legal obligations, legitimate interests
Restriction Requests (Article 18)
- Stopping processing of data while accuracy is verified
- Limiting use during dispute resolution
- Maintaining secure storage during restriction period
Portability Requests (Article 20)
- Providing data in structured, machine-readable format
- Transferring data to another processor if requested
- Supporting direct transfers to third parties
Objection and Automated Decision-Making (Article 21-22)
- Ceasing processing for direct marketing purposes
- Providing human review for automated decisions where required
- Documenting objections and responses
Response Timeframes
- Standard requests: 15-30 days
- Complex requests: 45 days (with extension notice)
- Urgent requests: 2-3 business days if feasible
Costs
- Assistance is provided without charge as part of the service
- Reasonable expenses (development, migration) may be charged
- Excessive requests may incur reasonable fees
6. International Data Transfers
Applicable Framework
If we transfer personal data outside the EEA, we ensure adequate safeguards:
Standard Contractual Clauses (SCCs)
- Module 1 (Controller-to-Processor): Used between you and us
- Module 2 (Processor-to-Processor): Used with our sub-processors
- SCCs are available upon request
- SCCs binding on all parties
Adequacy Decisions
- We monitor EU Commission adequacy decisions
- If a country is deemed adequate, SCCs may not be needed
- We notify you of any changes
Safeguards Assessment
- We assess laws in destination countries
- We verify no surveillance laws override GDPR
- We assist with supplementary measures if needed
- We review judicial remedies available to data subjects
Your Role
- Approve international transfer arrangements before engagement
- Conduct Transfer Impact Assessment if required
- Inform data subjects about transfers
- Ensure legal basis for international transfers
7. Sub-Processors
Current Sub-Processors
We currently use the following sub-processors (Annex 1):
| Sub-Processor |
Purpose |
Location |
| Amazon Web Services (AWS) |
Cloud hosting and data storage |
Multiple regions (selectable) |
| Google Cloud |
Cloud services and analytics |
Multiple regions |
| SendGrid |
Email delivery |
USA |
| Stripe |
Payment processing |
USA |
| GitHub |
Code repository and collaboration |
USA |
Complete current list and DPAs: https://netjetlabs.com/sub-processors
Adding New Sub-Processors
If we need to add new sub-processors:
- We provide 30 days written notice
- Notice includes: name, purpose, location, DPA status
- You have 15 days to object in writing
- Reasonable objections will be honored
- If unresolved, either party can terminate services
Sub-Processor Obligations
All sub-processors are bound by written agreements requiring:
- Processing only as instructed
- Confidentiality obligations
- Same security measures as NetJet Labs
- Subcontracting restrictions
- Assistance with data subject rights
- Deletion of data upon termination
- Audit rights and cooperation
Our Responsibility
- We remain liable to you for sub-processor performance
- We select sub-processors carefully
- We monitor sub-processor compliance
- We address your concerns about sub-processors
8. Data Breach Notification
Breach Definition
A breach of personal data means unauthorized or accidental:
- Destruction of personal data
- Loss of personal data
- Alteration of personal data
- Unauthorized disclosure or access
- Any processing accident with impact on data protection
Our Notification Obligations (Article 33)
Timeline
- Notify you without undue delay (target: within 24 hours)
- Notification even if we don't know full details
- Update with additional information as investigation proceeds
Notification Content
We will provide:
- Nature and scope of the breach
- Personal data categories affected
- Number of data subjects impacted (if known)
- Likely consequences for data subjects
- Measures taken to address the breach
- Measures to mitigate harm
- Our contact for further information
Your Responsibilities
- You are responsible for notifying your supervisory authority (if required)
- You are responsible for notifying affected data subjects (if required)
- We will assist in these notifications if needed
- We will preserve evidence and logs
Investigation and Remediation
- We will conduct root cause analysis
- We will identify affected data and systems
- We will implement remedial measures
- We will provide forensic report if requested
- Costs are covered by our service agreement
No Liability
We have no liability for:
- Your delay in notifying data subjects
- Consequences of the breach itself (we're not liable for breach damages)
- Your failure to implement our recommendations
9. Audits and Inspections
Audit Rights (Article 28.3.h)
Your Audit Rights
You may audit our processing activities:
- Annual audit included as part of services
- Additional audits available with 30 days notice
- On-site audits with reasonable access to facilities and systems
- Desk audits via remote access
- Reasonable costs covered by you if beyond standard annual audit
Inspection Procedures
- Advance notice required (30 days minimum)
- Reasonable hours and frequency
- NDA requirements for audit team
- Subject to confidentiality of other clients' data
- We provide records of processing activities
Regulatory Audits
- We permit audits by regulators (DPA, EDPB)
- We cooperate with data protection authorities
- We notify you of regulatory audits (except where prohibited)
- We share audit findings with you unless prohibited
Certification and Compliance
- We maintain SOC 2 Type II certification (or equivalent)
- We provide annual compliance certificate upon request
- We document compliance measures in detail
- We conduct regular security assessments
10. Data Deletion and Return
At End of Services
Data Return
- We will provide all personal data in structured format
- Typically within 30 days of termination
- In format you specify (CSV, JSON, database backup, etc.)
- Encryption applied if requested
- Technical support provided for data import
Data Deletion
- We will delete personal data from active systems within 90 days
- Backups deleted within 90 days
- Backup tapes physically destroyed or securely wiped
- Certificate of deletion provided upon request
- Exception: if legally required to retain data
Retention Exceptions
We may retain personal data if:
- Required by tax law (typically 7 years)
- Required by contract law (typically 3-7 years)
- Required by litigation hold
- Required by regulatory authority
Client Responsibility
- You are responsible for deleting your copy
- You remain liable for data you retain
- You must ensure your sub-processors delete data
11. Liability and Indemnification
Our Liability
Processor Liability
We are liable for:
- Violations of GDPR data processor obligations
- Failure to implement security measures
- Unauthorized disclosure of personal data
- Failure to assist with data subject rights
- Failure to notify of breaches
Limitations
- We are not liable for losses caused by your instructions or failure to comply with GDPR
- We are not liable for data loss due to your failure to maintain backups
- We are not liable for unauthorized access if you don't secure credentials
- See Terms of Service for overall liability caps
Your Responsibility
You Are Liable For:
- Violations of GDPR data controller obligations
- Failure to obtain lawful basis for processing
- Failure to inform data subjects
- Failure to respond to data subject requests
- Failure to comply with data protection authority requests
Indemnification
You agree to indemnify us for:
- Claims arising from your violation of GDPR
- Claims arising from your unlawful instructions
- Claims that your data infringes third-party rights
- Claims arising from your failure to obtain proper consents
- Regulatory fines resulting from your violations
We agree to indemnify you for:
- Claims that we violated GDPR processor obligations
- Claims that we failed to implement security measures
- Claims arising from our breach or misconduct
- Regulatory fines resulting from our violations
12. Term and Termination
Term
- This DPA is effective upon execution
- Continues for the duration of the service engagement
- Survives termination of services for 5 years for retention obligations
Termination Obligations
Upon termination or expiry:
- We stop processing personal data immediately
- We delete or return data per Section 10
- Confidentiality obligations continue
- Liability obligations continue for past processing
Early Termination
- For convenience: 30 days notice (see Terms of Service)
- For cause: Immediate upon material breach
- Data return required regardless of cause
13. GDPR Compliance Summary
Key Principles
| GDPR Requirement |
How We Comply |
| Lawfulness of processing |
You ensure lawful basis; we follow your instructions |
| Fairness and transparency |
We disclose processing details; you inform data subjects |
| Purpose limitation |
We process only for your specified purposes |
| Data minimization |
We process only data necessary for your purposes |
| Accuracy |
You ensure accuracy; we don't alter data |
| Storage limitation |
We delete or return data per Section 10 |
| Integrity and confidentiality |
We implement technical and organizational measures (Section 4) |
| Accountability |
We maintain records and provide audit access |
Articles Addressed
- ✓ Article 5 (Principles) - Lawfulness, fairness, transparency, data minimization, accuracy, storage
limitation, integrity, accountability
- ✓ Article 12-22 (Data Subject Rights) - Access, rectification, erasure, restriction, portability,
objection
- ✓ Article 28 (Data Processing Agreement) - This DPA
- ✓ Article 32 (Security) - Technical and organizational measures
- ✓ Article 33-34 (Breach Notification) - Immediate notification
- ✓ Article 44-50 (International Transfers) - Appropriate safeguards
Effective Date: July 17, 2024
Version: 1.0
DPA ID: NETJET-LABS-DPA-v1.0-2024
Next Review: January 17, 2025
Note: This DPA incorporates by reference the Security Measures detailed in Annex 2. For
current sub-processor list, visit: https://netjetlabs.com/sub-processors
↑ Back to Top