Scope and roles
These Organisation and Data-Processing Terms apply where an organisation (an operator, school, or similar; the “Organisation”) uses RotorLog's organisation features to receive or manage data that pilots share with it. Three roles matter:
- The pilot is the data subject and remains the controller of their own logbook. Nothing about the organisation features changes a pilot's ownership of their records.
- The Organisation is a separate controller for the pilot data it receives, within the scope the pilot has granted, and is responsible for its own lawful use of that data (for example for compliance and rostering).
- OOS provides the RotorLog platform. In operating the organisation features on the Organisation's behalf, OOS acts as the Organisation's processor for the shared pilot data, and as controller for the underlying account and platform data as described in our Privacy Policy.
Details of processing (Article 28(3) GDPR)
Scope, masking and pilot control
The platform is built so that an Organisation can never see more than a pilot allows:
- A recipient only ever sees the intersection of the pilot's granted scope and its own role; nothing widens that automatically.
- Sensitive detail is minimised even within a share. For example, instructor signature images and precise location coordinates are never transmitted.
- Changes an Organisation proposes (such as planned duties, currency requirements, or corrections) take effect only when the pilot accepts them in their own app.
- A pilot can pause or revoke a grant at any time.
Our obligations as processor
Where OOS acts as the Organisation's processor, OOS will:
- process the shared pilot data only to provide the Service and on the Organisation's documented instructions, as reflected in these terms and the product's settings;
- ensure that personnel authorised to access the data are bound by confidentiality;
- implement appropriate technical and organisational security measures (see Security measures);
- assist the Organisation, taking into account the nature of processing, with data-subject requests and with its security, breach-notification and impact-assessment obligations;
- notify the Organisation without undue delay after becoming aware of a personal-data breach affecting the shared data;
- at the end of the relationship, delete or return the shared data, subject to the retention described below and to any legal retention obligation.
Sub-processors
The Organisation authorises OOS to engage the sub-processors listed on our Sub-processors page to help provide the Service. Each is engaged under a written contract with data-protection obligations. On request, we will inform an Organisation of material changes to that list so it can object on reasonable data-protection grounds.
International transfers
Shared pilot data is stored in the European Union. Where a sub-processor processes data outside the EEA, appropriate safeguards apply, as described in our Privacy Policy.
Security measures
Our measures include encryption in transit and at rest; strict, controlled access to production systems; database-level isolation so one account cannot read another's data; scope-and-role enforcement applied in the backend (not merely in the interface) for every shared read; identifying share links only by a hashed token; and logging access to shared pages without storing raw IP addresses.
Retention on termination
While a grant is active, the Organisation views the pilot's data live within scope; no separate copy is made. When a connection ends, the Organisation may retain a frozen, scope-limited copy of the data the pilot had shared, for a period the Organisation configures (by default around two years, and subject to a maximum), for its own compliance records. This copy never contains more than was shared, and the pilot can see in their app that such a copy exists. Expired copies are purged.
Records and audit
OOS will make available information reasonably necessary to demonstrate compliance with these terms and, where required by applicable law, allow for and contribute to audits, subject to reasonable confidentiality and security conditions.
Precedence and contact
If these terms conflict with our general Terms on the processing of shared pilot data, these terms prevail for that subject. For a signed data-processing agreement or any organisation data-protection question, contact legal@rotorlog.com.