Data Processing Agreement

Effective 1 October 2026 · All legal documents

Draft. This document is awaiting legal review, and details in [square brackets] are still to be confirmed.

1. Scope and roles

This Data Processing Agreement ("DPA") forms part of the Terms of Service between [COMPANY LEGAL NAME] ("GHSLink", the processor) and the Customer (the controller). It applies to personal data in Customer Data that GHSLink processes for the Customer ("Customer Personal Data"). Terms such as "personal data", "processing", "controller", "processor" and "personal data breach" have the meanings in the GDPR and the UK GDPR ("Data Protection Law").

Where the Customer is itself a processor for someone else, GHSLink is its sub-processor and the Customer confirms its controller has authorised this.

2. Details of the processing (Annex I)

Subject matter and durationProviding the Services for the term of the Customer's subscription, and deletion afterwards under clause 10
Nature and purposeHosting, storing, organising, displaying, transmitting and deleting Customer Data so the Customer can plan, coordinate, record and bill aviation and ground transport work
Categories of data subjectsThe Customer's staff and Users; its clients and their contacts; passengers and crew; drivers; other people named in bookings, trips, messages or connected mailboxes
Categories of personal dataNames; business contact details; job roles; travel and itinerary details (flights, times, airports, pickup and drop-off addresses); aircraft registrations linked to people; baggage tag numbers; message content and attachments; account activity
Special category dataNone intended. The Customer must not submit it (Acceptable Use Policy)
FrequencyContinuous

3. Processing on instructions

GHSLink processes Customer Personal Data only on the Customer's documented instructions, which are the Terms, this DPA and the Customer's use and configuration of the Services, unless the law requires otherwise (in which case GHSLink will tell the Customer first, unless the law forbids it). GHSLink will tell the Customer if it believes an instruction breaks Data Protection Law.

4. Confidentiality

GHSLink ensures that everyone it authorises to process Customer Personal Data is bound by confidentiality, and gives access only to those who need it to provide, support or secure the Services.

5. Security measures (Annex II)

  • Encryption of data in transit (TLS) and at rest.
  • Separation of each customer's data enforced in the database (row-level security), tested automatically on every change to the rules.
  • Role-based access within each workspace, controlled by the Customer; server-side checks on every change.
  • Least-privilege access for GHSLink staff; administrative access limited to named people, with an additional access gate.
  • Passwords stored only as salted hashes by the authentication provider; secrets kept out of source code.
  • Security headers, rate limits on sign-up and email, and dependency monitoring.
  • Regular database backups by our hosting provider, with a documented restore procedure.
  • Documented incident response, and a security review of significant changes before release.

6. Sub-processors

The Customer gives general authorisation for GHSLink to use sub-processors. The current list is on the Sub-processors page. GHSLink will give at least 30 days' notice (by email to workspace administrators or on that page, which the Customer can subscribe to) before adding or replacing one. The Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate the affected Services and receive a refund of prepaid fees for them.

GHSLink imposes data protection obligations on each sub-processor no less protective than this DPA, and remains liable for its sub-processors.

7. International transfers

GHSLink will transfer Customer Personal Data outside the EEA or the UK only with a valid transfer mechanism under Data Protection Law, such as an adequacy decision or the Standard Contractual Clauses (with the UK Addendum), together with any supplementary measures needed. To the extent the Customer transfers data to GHSLink in a way that needs such a mechanism, the Standard Contractual Clauses (module two, or module three where the Customer is a processor) are incorporated by reference, with Annexes I and II as set out in this DPA.

8. Helping the Customer

  • Data subject requests: GHSLink will pass on any request it receives about Customer Personal Data without responding itself (other than to redirect the person), and will help the Customer answer requests, including through export and deletion features.
  • GHSLink will give reasonable help with data protection impact assessments and prior consultations with regulators about the Services.
  • GHSLink will make available the information needed to show compliance with this DPA, and allow audits: first through its security documentation and answers to reasonable questionnaires, and, where that is not enough or a regulator requires it, an audit by the Customer or its independent auditor, on 30 days' notice, no more than once a year, at the Customer's cost and under confidentiality.

9. Personal data breaches

GHSLink will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, as far as then known, the nature of the breach, the categories and approximate numbers of people and records affected, the likely consequences and the measures taken or proposed, and will be updated as more becomes known. GHSLink will take reasonable steps to contain the breach and help the Customer meet its own notification duties.

10. Return and deletion

During the subscription the Customer can export and delete its data using the Services. When it ends, GHSLink will provide an export on request made within 30 days, then delete Customer Personal Data within a further 60 days, unless the law requires it to be kept. Deleted data leaves backups as they expire (within 30 days).

The default retention periods GHSLink applies as processor while the subscription runs are:

DataDefault period
Workspace records: trips, legs, visits, services, bookings, transport jobs, contacts, tasksCustomer-controlled while the workspace is open; deleted within 90 days after it closes (30 days to export, then 60 to delete)
Messages and attachments synced from a mailbox the customer connects24 months after the last message in a conversation by default; removed within 30 days of the mailbox being disconnected
Baggage scans (bag tag number, who scanned it and when)90 days after the flight by default, or longer if the customer asks, to support baggage claims

11. Liability and precedence

Each party's liability under this DPA is subject to the limits in the Terms, except where Data Protection Law does not allow it. If this DPA conflicts with the Terms on data protection, this DPA wins; if the Standard Contractual Clauses apply and conflict with either, they win.

Data Processing Agreement | GHSLink