CharterLogic

Data Processing Addendum

Last updated: May 2026

1. Purpose and Scope

This DPA applies where CharterLogic processes “Client Personal Data” (such as passenger names or crew details) on behalf of the Client. CharterLogic acts as the Data Processor, and the Client acts as the Data Controller.

2. Processing Instructions

CharterLogic shall process data only to provide the Chartering, Costing, and Quoting services defined in the Terms of Service. We will not process Client Data for any other purpose unless required by law.

3. Technical and Organisational Measures

CharterLogic implements industry-standard security, including:

  • Tenant Isolation: Strict logical separation of data between different airline tenants.
  • Encryption: Data is encrypted at rest and in transit.
  • Audit Logging: Forensic logging of all data mutations and exports (PDF generation).
  • Access Control: Role-Based Access Control (RBAC) and mandatory MFA options.

4. Sub-processors

The Client provides general authorisation for CharterLogic to engage sub-processors. We maintain an up-to-date list of these entities (see below).

5. Data Breaches

We will notify the Client without undue delay (within 72 hours) after becoming aware of a personal data breach affecting Client Data.

Sub-processor List

GDPR requires transparency about the infrastructure stack used to handle data. The current list of sub-processors is available on request from privacy@charterlogic.app.

Contact

Data processing enquiries: privacy@charterlogic.app.