RotorLog All legal documents
Legal

Organisation & Data-Processing Terms

Last updated: July 20, 2026 Version 1.0

The short version. These terms apply to organisations that use RotorLog to work with their pilots' data. A pilot always controls their own logbook; an organisation only ever sees the slice a pilot grants it; and RotorLog processes that data on tightly-scoped, privacy-protective terms. They supplement our Terms and Privacy Policy.

On this page
  1. Scope and roles
  2. Details of processing (Article 28(3) GDPR)
  3. Scope, masking and pilot control
  4. Our obligations as processor
  5. Sub-processors
  6. International transfers
  7. Security measures
  8. Retention on termination
  9. Records and audit
  10. Precedence and contact

Scope and roles

These Organisation and Data-Processing Terms apply where an organisation (an operator, school, or similar; the “Organisation”) uses RotorLog's organisation features to receive or manage data that pilots share with it. Three roles matter:

  • The pilot is the data subject and remains the controller of their own logbook. Nothing about the organisation features changes a pilot's ownership of their records.
  • The Organisation is a separate controller for the pilot data it receives, within the scope the pilot has granted, and is responsible for its own lawful use of that data (for example for compliance and rostering).
  • OOS provides the RotorLog platform. In operating the organisation features on the Organisation's behalf, OOS acts as the Organisation's processor for the shared pilot data, and as controller for the underlying account and platform data as described in our Privacy Policy.

Details of processing (Article 28(3) GDPR)

Subject matterProvision of RotorLog's organisation features to the Organisation
DurationFor the term of the Organisation's use, plus any retention period described below
Nature and purposeStoring, syncing, displaying and reporting on pilot data shared with the Organisation, so the Organisation can meet its operational and compliance needs
Categories of data subjectsThe Organisation's pilots and members
Categories of dataThe logbook, currency, duty and profile data that each pilot chooses to share, within the granted scope

Scope, masking and pilot control

The platform is built so that an Organisation can never see more than a pilot allows:

  • A recipient only ever sees the intersection of the pilot's granted scope and its own role; nothing widens that automatically.
  • Sensitive detail is minimised even within a share. For example, instructor signature images and precise location coordinates are never transmitted.
  • Changes an Organisation proposes (such as planned duties, currency requirements, or corrections) take effect only when the pilot accepts them in their own app.
  • A pilot can pause or revoke a grant at any time.

Our obligations as processor

Where OOS acts as the Organisation's processor, OOS will:

  • process the shared pilot data only to provide the Service and on the Organisation's documented instructions, as reflected in these terms and the product's settings;
  • ensure that personnel authorised to access the data are bound by confidentiality;
  • implement appropriate technical and organisational security measures (see Security measures);
  • assist the Organisation, taking into account the nature of processing, with data-subject requests and with its security, breach-notification and impact-assessment obligations;
  • notify the Organisation without undue delay after becoming aware of a personal-data breach affecting the shared data;
  • at the end of the relationship, delete or return the shared data, subject to the retention described below and to any legal retention obligation.

Sub-processors

The Organisation authorises OOS to engage the sub-processors listed on our Sub-processors page to help provide the Service. Each is engaged under a written contract with data-protection obligations. On request, we will inform an Organisation of material changes to that list so it can object on reasonable data-protection grounds.

International transfers

Shared pilot data is stored in the European Union. Where a sub-processor processes data outside the EEA, appropriate safeguards apply, as described in our Privacy Policy.

Security measures

Our measures include encryption in transit and at rest; strict, controlled access to production systems; database-level isolation so one account cannot read another's data; scope-and-role enforcement applied in the backend (not merely in the interface) for every shared read; identifying share links only by a hashed token; and logging access to shared pages without storing raw IP addresses.

Retention on termination

While a grant is active, the Organisation views the pilot's data live within scope; no separate copy is made. When a connection ends, the Organisation may retain a frozen, scope-limited copy of the data the pilot had shared, for a period the Organisation configures (by default around two years, and subject to a maximum), for its own compliance records. This copy never contains more than was shared, and the pilot can see in their app that such a copy exists. Expired copies are purged.

Records and audit

OOS will make available information reasonably necessary to demonstrate compliance with these terms and, where required by applicable law, allow for and contribute to audits, subject to reasonable confidentiality and security conditions.

Precedence and contact

If these terms conflict with our general Terms on the processing of shared pilot data, these terms prevail for that subject. For a signed data-processing agreement or any organisation data-protection question, contact legal@rotorlog.com.

© 2026 OOS · RotorLog is a product of OOS (KVK 42109194).
All legal Privacy Terms Contact