Draft for review — these terms are not yet in force.

These documents are working drafts prepared for review by qualified counsel. They still contain bracketed placeholders, they create no obligations, and they do not describe every feature as it exists today. We will publish the final versions before they apply to anyone.

Legal

Data Processing Addendum (DPA)

DRAFT v0.1 · last edited 2026-08-19 · not in force

DRAFT v0.1 — 19 August 2026 — prepared for review by qualified counsel; not yet in force.

Key points (non-binding summary — the numbered clauses prevail)

  • This Data Processing Addendum ("DPA") applies where Vistason processes personal data on behalf of a business customer — for example the customer's own users' contact data, counterparties' contacts the customer records, or inventory files that happen to contain employee names. For that data the customer is the controller and Vistason is its processor.
  • Vistason is an independent controller — not the customer's processor — for KYC/KYB, sanctions and export-control screening, fee billing and the operation of the Platform itself; that processing is governed by the Privacy Policy, not this DPA.
  • As processor, Vistason acts only on the customer's documented instructions, keeps personal data confidential and secure (Annex 2), assists with data-subject requests and breach obligations, and deletes or returns the data at the end of the service.
  • Sub-processors are listed in Annex 3 (currently Vercel, Cloudflare, [SUPABASE], [POSTHOG], Amazon Web Services (Amazon SES), [KYC PROVIDER], [PAYMENT SERVICES PROVIDER], Google (Gemini) and Anthropic for AI normalisation, with personal data minimised). We give [30] days' notice of changes and the customer may object.
  • International transfers rely on adequacy decisions, the EU Standard Contractual Clauses (Module 2 / Module 3) and the UK Addendum, which are incorporated by reference.
  • We notify the customer of a personal data breach affecting its data without undue delay and in any event within [72] hours of becoming aware (target [48] hours).
  • Liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms, this DPA prevails for data-protection matters.

1. Background and scope

1.1 This DPA forms part of the agreement between PostReach AI Limited ("Vistason", the "Processor" where acting as such) and the business customer identified in the relevant account or order ("Customer", the "Controller" where acting as such) under which Vistason provides the Vistason marketplace, the Hangar seller console, deal rooms, Tenders, Radar and related services (the "Services"), as governed by the Vistason Terms of Service (the "Agreement").

1.2 This DPA applies to the extent that Vistason processes Customer Personal Data (defined in clause 1.4) on the Customer's behalf in providing the Services. It is entered into to satisfy Article 28(3) GDPR and the equivalent provisions of the UK GDPR.

1.3 "Data Protection Law" means the GDPR (Regulation (EU) 2016/679), the UK GDPR and Data Protection Act 2018, the ePrivacy rules as implemented in the relevant Member State or the UK, and any other data-protection law applicable to a party's processing under this DPA. Terms such as "controller", "processor", "personal data", "processing", "data subject" and "personal data breach" have the meanings given in the GDPR.

1.4 "Customer Personal Data" means personal data contained in content and data that the Customer (including its Authorised Users) submits to or generates in the Services and for which the Customer determines the purposes and means of processing, including: (a) identity and contact data of the Customer's own Authorised Users to the extent the Customer directs its administration; (b) contact details of the Customer's counterparties, consignees, inspectors and forwarder contacts that the Customer records in the Services; and (c) personal data incidentally contained in inventory exports, listing files, trace documents (for example the name and signature of the technician on an FAA 8130-3 / EASA Form 1), purchase orders, shop reports and other uploaded documents.

2. Roles of the parties

2.1 Vistason as processor. For Customer Personal Data, the Customer is the controller (or, where the Customer acts for its own affiliates or clients, a processor, in which case Vistason is a sub-processor and the Customer warrants that its instructions are authorised by the relevant controller), and Vistason is the processor.

2.2 Vistason as independent controller. Vistason is an independent controller — and this DPA does not apply — where it determines the purposes and means of processing, namely: (a) KYC/KYB verification, sanctions, denied-party and export-control screening and related compliance record-keeping; (b) operating, securing, maintaining and improving the Platform, including access logs, security monitoring and aggregated analytics; (c) billing, fee statements, subscriptions, accounting and tax; (d) its own legal obligations, including reports to authorities; and (e) direct communications with Authorised Users about the Services. That processing is described in the Vistason Privacy Policy.

2.3 Counterparties. When Customer Personal Data is shared with the counterparty to a deal, with [PAYMENT SERVICES PROVIDER] for its own regulatory obligations, or with a forwarder or inspector, each recipient acts as an independent controller of what it receives, as described in the Privacy Policy. Such sharing at the Customer's request or as an inherent function of the Services is a documented instruction under clause 4.1.

2.4 Each party is responsible for its own compliance with Data Protection Law in its respective role. Where the parties are independent controllers, nothing in this DPA makes them joint controllers within the meaning of Article 26 GDPR.

3. Subject matter, duration, nature and purpose

3.1 Subject matter: the processing of Customer Personal Data necessary to provide the Services described in the Agreement.

3.2 Duration: the term of the Agreement plus the period until deletion or return under clause 9.

3.3 Nature of processing: hosting, storage, transmission, structuring, normalisation (including AI-assisted normalisation of inventory data as limited by clause 6.4), display to authorised recipients, backup, retrieval, disclosure at the Customer's instruction, and deletion.

3.4 Purpose: to enable the Customer to list, market, tender, buy and sell aviation surplus material through the Services, to communicate in deal rooms, and to manage shipping, inspection and settlement of its transactions.

3.5 Categories of data subjects: the Customer's Authorised Users, employees and contractors; employees and contacts of the Customer's counterparties, consignees, forwarders and inspectors; individuals named in trace and transaction documents (for example certifying technicians and signatories).

3.6 Categories of personal data: name, business contact details, job title and role, employer, signatures, user activity within the Customer's account, and personal data incidentally contained in uploaded business documents. No special categories of personal data (Article 9 GDPR) are intended to be processed; the Customer agrees not to submit them. The Services are not designed for data relating to criminal convictions or offences on the Customer's behalf.

4. Processor obligations

4.1 Instructions. Vistason will process Customer Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by EU, Member State or UK law to which Vistason is subject — in which case Vistason will inform the Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest. The Agreement, this DPA, the Customer's configuration of the Services and its use of Platform features (for example inviting a counterparty into a deal room or requesting a freight quote) constitute the Customer's complete documented instructions. Additional instructions require agreement of both parties.

4.2 Lawfulness notice. Vistason will inform the Customer without undue delay if, in its opinion, an instruction infringes Data Protection Law; it may suspend the affected processing until the instruction is confirmed or amended. Vistason is not obliged to review instructions for legality generally.

4.3 Confidentiality. Vistason ensures that persons authorised to process Customer Personal Data are bound by contractual or statutory confidentiality obligations and receive appropriate data-protection training, and that access is limited to what each role requires.

4.4 Security. Vistason implements and maintains the technical and organisational measures described in Annex 2, and in any event measures appropriate to the risk as required by Article 32 GDPR. Vistason may update Annex 2 from time to time, provided the changes do not materially reduce the overall level of protection.

4.5 Data-subject requests. Taking into account the nature of the processing, Vistason will assist the Customer by appropriate technical and organisational measures, insofar as this is possible, to fulfil the Customer's obligation to respond to data-subject requests under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection). If a data subject contacts Vistason directly about Customer Personal Data, Vistason will not respond substantively (except to direct them to the Customer) and will forward the request to the Customer without undue delay.

4.6 Assistance. Vistason will assist the Customer, taking into account the nature of the processing and the information available to it, in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification to authorities and data subjects, data protection impact assessments and prior consultation). Assistance beyond what is included in the Services may be charged at reasonable rates, except where the need arises from Vistason's breach of this DPA.

4.7 Records and cooperation. Vistason maintains the records required by Article 30(2) GDPR and will cooperate with supervisory authorities as required by law, informing the Customer of any authority contact concerning Customer Personal Data unless prohibited.

5. Sub-processors

5.1 General authorisation. The Customer authorises Vistason to engage the sub-processors listed in Annex 3 and, subject to this clause 5, to appoint replacements or additions.

5.2 Notice and objection. Vistason will give the Customer at least [30] days' written notice (email to the account Admin or notice in the Platform) before authorising a new sub-processor to process Customer Personal Data. The Customer may object on reasonable data-protection grounds within that period. The parties will then discuss in good faith; if no solution is found (for example a configuration that avoids the sub-processor), the Customer may terminate the affected Services with pro-rata refund of prepaid fees as its sole remedy, per the Terms of Service.

5.3 Flow-down. Vistason will impose on each sub-processor, by written contract, data-protection obligations materially equivalent to those in this DPA, including Article 28(3) terms and appropriate security measures, and will remain fully liable to the Customer for the performance of each sub-processor's obligations.

5.4 Current list. Annex 3 sets out the current and planned sub-processors. The list is also available on request from [PRIVACY EMAIL ADDRESS] and, when published, at https://vistason.com/legal/subprocessors.

6. International transfers

6.1 Vistason will not transfer Customer Personal Data outside the EEA or the UK except in compliance with Chapter V GDPR / UK GDPR.

6.2 Where a transfer to a third country without an adequacy decision is necessary, the parties incorporate by reference the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914): Module Two (controller to processor) where the Customer is a controller, and Module Three (processor to processor) where the Customer is itself a processor, with: clause 7 (docking) included; clause 9(a) option 2 (general authorisation, [30] days' notice); clause 11 optional redress language not included; clause 17 option 1, governing law of [Ireland / Spain — to be confirmed]; clause 18 courts of [Ireland / Spain — to be confirmed]; Annexes I and II completed by clauses 3, 5 and Annexes 1–3 of this DPA.

6.3 For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the EU SCCs (as issued by the ICO) is incorporated, with the tables completed by the corresponding details of this DPA. For Swiss data, the SCCs apply as adapted by the Swiss FDPIC's requirements.

6.4 AI normalisation providers. Inventory data may be processed by Google (Gemini) and Anthropic for AI-assisted normalisation of part numbers, condition codes and ATA chapters. Vistason applies filtering to remove or minimise personal data before submission (for example stripping columns that appear to contain names, emails or telephone numbers), contracts on terms prohibiting the providers from using the data to train models, and treats any residual personal data as Customer Personal Data processed under this clause 6 and Annex 3.

6.5 If a transfer mechanism relied on is invalidated or amended, the parties will cooperate in good faith to implement a lawful alternative promptly.

7. Personal data breach

7.1 Vistason will notify the Customer without undue delay, and in any event within [72] hours (with a target of [48] hours), after becoming aware of a personal data breach affecting Customer Personal Data.

7.2 The notification will, to the extent then known (and supplemented as information becomes available), describe: the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, the measures taken or proposed to address the breach and mitigate its effects, and a contact point.

7.3 Vistason will take reasonable steps to contain and remediate the breach, will document it as required by Article 33(5) GDPR, and will reasonably cooperate with the Customer's own notification obligations. Vistason's notification is not an admission of fault. The Customer is responsible for notifying its supervisory authority and data subjects where required; Vistason will not notify authorities or data subjects on the Customer's behalf unless legally required or agreed.

8. Audits and reports

8.1 Vistason will make available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 GDPR, including summaries of third-party certifications and audit reports covering Vistason and its material sub-processors (for example SOC 2 or ISO/IEC 27001 reports of hosting providers, where available: [—]).

8.2 Where the information under clause 8.1 is insufficient to demonstrate compliance, the Customer (or an independent auditor mandated by it and not a competitor of Vistason) may audit Vistason's relevant processing, subject to: [30] days' notice; at most once per [12] months, except after a personal data breach or where required by a supervisory authority; normal business hours; confidentiality undertakings; no access to other customers' data; and the Customer bearing its own costs and Vistason's reasonable costs beyond [1] day of assistance per audit.

8.3 Audit rights in respect of hyperscale sub-processors (Vercel, Cloudflare, [SUPABASE], Google, Anthropic) are exercised through those providers' published audit reports and certifications.

9. Deletion and return

9.1 During the term, the Customer may retrieve, correct and delete Customer Personal Data through the Services' export and administration features.

9.2 On termination or expiry of the Agreement, Vistason will, at the Customer's choice made within [30] days, return Customer Personal Data in a structured, commonly used, machine-readable format and/or delete it, and will delete remaining copies within [90] days, except: (a) data Vistason must retain under EU, Member State or UK law (for example transaction records retained for [10] years and KYC records for [5] years, which Vistason retains as an independent controller under the Privacy Policy); (b) deal records that the counterparty is entitled to retain for its own compliance; and (c) backup copies, which are deleted or overwritten in the ordinary rotation cycle of [30] days and are not restored except for disaster recovery. Data retained under this clause remains protected by this DPA until deleted.

9.3 On request, Vistason will confirm deletion in writing.

10. Liability, term, precedence

10.1 Each party's liability arising out of or related to this DPA (including the incorporated SCCs, to the extent permitted by their clause 12) is subject to the exclusions and limitations of liability in the Terms of Service, except that nothing limits either party's liability for matters that cannot be limited under applicable law or a data subject's rights against either party under the SCCs or Data Protection Law.

10.2 This DPA takes effect when the Agreement takes effect (or, for existing customers, on acceptance) and continues until Vistason ceases to process Customer Personal Data under clause 9.

10.3 In case of conflict: (a) the SCCs prevail over this DPA to the extent of the conflict; (b) this DPA prevails over the Agreement for data-protection matters; and (c) the Agreement governs everything else. If any provision is invalid, the remainder stays in force and the parties will replace the invalid provision with a valid one reflecting its intent.

10.4 This DPA is governed by the law governing the Agreement ([Spain — to be confirmed]), except where the SCCs require otherwise.

Annex 1 — Description of processing

As set out in clause 3: subject matter (clause 3.1), duration (clause 3.2), nature (clause 3.3), purpose (clause 3.4), data subjects (clause 3.5), personal data categories (clause 3.6). Sensitive data: none intended. Frequency: continuous during the term. Retention: clause 9 and the Privacy Policy retention table. Competent supervisory authority (SCC Annex I.C): [AEPD, Spain — to be confirmed].

Annex 2 — Technical and organisational measures (Article 32 GDPR)

  1. Encryption: TLS 1.2+ for all data in transit; encryption at rest for databases, file storage and backups; secrets managed in a dedicated secret store, not in code.
  2. Access control: role-based, least-privilege access for staff; unique named accounts; access reviews at least every [6] months; prompt revocation on role change or departure. Vistason's own Tower operator console has no second authentication factor of its own; the infrastructure and sub-processor consoles behind it — Supabase, Vercel, Amazon Web Services, Cloudflare and Google Workspace — offer multi-factor authentication, and Vistason's policy is to enable it on each of them. Customer-side access is governed by the Customer's own role assignments (Admin / Approver / Lister / Buyer / Viewer).
  3. Logical separation: account-level tenancy controls; deal-room content visible only to the participants of the deal; KYC documents segregated with restricted access.
  4. Logging and monitoring: centralised logging of access to production systems and administrative actions; security alerting; logs retained [12] months.
  5. Backups and continuity: automated backups with [daily] frequency, encrypted, tested restores; recovery objectives [RTO/RPO — to be defined]; multi-region edge delivery via Cloudflare and Vercel.
  6. Incident response: documented incident-response plan with severity classification, escalation paths, the customer-notification commitment in clause 7, and post-incident review.
  7. Vulnerability management: dependency scanning, timely patching of critical vulnerabilities [target: within [72] hours for critical, [30] days for high], periodic penetration testing [—], secure development lifecycle with code review.
  8. Organisational: confidentiality undertakings and data-protection training for all staff and contractors; vendor security assessment before onboarding sub-processors; records of processing; designated privacy contact [—].

Annex 3 — Sub-processors

Sub-processorFunctionLocation / hosting regionTransfer mechanism
Vercel Inc.Cloud hosting, serverless compute, content deliveryUSA / global edge [region to be confirmed]EU–US DPF and/or SCCs Module 3
Cloudflare, Inc.DNS, CDN, edge security, Workers KV (early-access form storage)USA / global edgeEU–US DPF and/or SCCs Module 3
[SUPABASE] (planned)Database, authentication, file storage[EU REGION — to be confirmed]Intra-EEA, or SCCs if applicable
[POSTHOG] (planned)Product analytics (consent-based; no analytics cookies until consent)[EU CLOUD — to be confirmed]Intra-EEA, or DPF/SCCs
Amazon Web Services, Inc. (Amazon SES)Transactional email delivery: account, offer, order and settlement notifications, daily digests and security mail — recipient name and email address onlyUSA (AWS region us-east-1, Northern Virginia)EU–US DPF and/or SCCs Module 3
[KYC PROVIDER]Identity verification, KYC/KYB, sanctions and PEP screening (also an independent controller for its own regulatory records)[—][—]
[PAYMENT SERVICES PROVIDER]Operation of the settlement account and payment processing (primarily an independent controller; sub-processor only for limited support functions, if any)[—][—]
Google LLC (Gemini)AI-assisted normalisation of inventory data — personal data minimised per clause 6.4; no training on customer data[EU endpoints where available — to be confirmed]DPF and/or SCCs
Anthropic, PBCAI-assisted normalisation of inventory data — personal data minimised per clause 6.4; no training on customer dataUSA [— to be confirmed]DPF and/or SCCs
[SUPPORT TOOL]Customer support ticketing[—][—]
[BILLING TOOL]Invoicing and subscription billing[—][—]

Questions and the current list: legal@vistason.com.