Data Processing Agreement
The roles, the safeguards, and the shutdown clause. Aircraft owners are the data controller; we’re the processor.
Draft pending counsel review. This document is a working draft, not a final binding contract. Lawyer review is scheduled before public launch.
Roles
You (the aircraft owner, partnership, or flying club) are the data controller for the records you put into Yolog — logbook entries, photos, mechanic certificate numbers, document uploads, and any personal information you choose to add. Yolog Aviation Inc. is the data processor, processing your data only on your instructions and only to deliver the service.
What we process, and why
- Logbook entries and signatures — to compute the cryptographic chain, render PDFs, and surface compliance dashboards.
- Aircraft metadata (registration, make/model, serial, hours) — to drive AD applicability matching and compliance scheduling.
- Mechanic certificate numbers — to validate identity at signing time against the FAA Airmen registry. We never share these with third parties.
- Email addresses and phone numbers — transactional only: sign-in links, mechanic-link receipts, compliance reminders. No marketing without explicit opt-in.
- Operational metadata (IP, user agent, timestamps) — security audit trail; never sold or shared.
Sub-processors
We use a small set of named sub-processors, each under their own DPA with us. We’ll give 30 days’ written notice before adding or removing any sub-processor.
- Render — application hosting (US region).
- Cloudflare R2 — document and backup object storage (US region).
- Resend (email) and Twilio (SMS) — transactional notifications.
- Stripe — billing. We never see card numbers.
- Sentry — error reporting. Logbook content is scrubbed before transmission.
- Anthropic — OCR-only, used to extract structured data from scanned paper logbooks you upload. Your content is never used to train models per Anthropic’s API terms.
Where data lives
Primary store: managed PostgreSQL in a US region with point-in-time recovery and AES-256 disk encryption. Backups: daily, encrypted under a key separate from the primary, replicated to a second cloud provider. Documents: object storage with versioning enabled and cross-region replication.
Security
- TLS 1.3 in transit; HSTS enforced.
- AES-256 at rest, with sensitive PII fields additionally application-encrypted under a key separate from the database.
- Two-factor authentication available for all accounts; required for destructive operations like aircraft transfer.
- Append-only audit log of every meaningful action, exportable on request.
- Annual penetration test post-50 paying customers.
Breach notification
If a breach affects your data we will notify you within 72 hours of discovery, with what we know, what we don’t, and the steps we’re taking. If we don’t know yet whether you’re affected, we’ll tell you that too.
Shutdown clause
If Yolog Aviation Inc. ceases operations — voluntarily, through acquisition, or otherwise — you receive no less than 180 days’ written notice and a complete data export in PDF and CSV. Your hash chain is portable and verifies offline — each entry’s SHA-256 hash links to the one before it, so anyone with a SHA-256 library can recompute the chain and confirm it is unbroken, with no key or trusted party required. Your records do not depend on us being around.
Termination
Cancel any time. Data stays exportable for 90 days after cancellation, moves to cold storage for 18 months, then is deleted. You can request earlier deletion at any point during the export window; we’ll honor it within 30 days.
Last updated: pending. Effective: pending counsel review.