Data Processing Addendum
This Data Processing Addendum supplements the TarmacSync Terms of Service and Privacy Policy for airport and public-agency customers.
Effective date: August 10, 2026
How this DPA works. This DPA describes how TarmacSync processes airport data, lists active subprocessors, and states our security and data-handling commitments. It applies when your airport signs an order form or participates in the Founding Airport Partner Program. TarmacSync acts as a data processor; your airport is the data controller.
1. Definitions
Airport Data means information your airport provides to TarmacSync — procurement policies, purchase descriptions, project context, funding information, uploaded documents, and related materials.
Processing means any operation performed on Airport Data, including collection, storage, retrieval, transmission, and deletion.
Subprocessor means a third party engaged by TarmacSync to process Airport Data as part of delivering the service.
2. Data processing scope
TarmacSync processes Airport Data only to provide the service, troubleshoot issues, and communicate about the service. We do not use Airport Data to train public AI models. Airport Data is not sold or shared for advertising.
Categories of data: airport configuration, procurement policies and thresholds, purchase descriptions, project context, funding information, uploaded policy and grant documents, conversation history, generated path reviews and evidence packets.
Purpose: operating the TarmacSync procurement intelligence workspace.
Duration: for the term of your subscription, plus applicable retention periods.
3. Subprocessors
TarmacSync uses the following subprocessors. All core subprocessors are located in the United States. Subprocessors marked when configured are enabled by deployment setting and are absent when not configured.
Core (always active)
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Neon (Database) | Persistent storage | All structured data | United States (AWS us-east-1) |
| Resend (Transactional Email) | Sign-in codes, notifications | Recipient email, message body | United States |
| Vercel (Hosting) | App hosting, CDN, serverless functions | HTTP request/response, server-side logs | United States |
When configured
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Google (Gemini AI) | AI inference, PDF extraction | Conversation content, airport context, uploaded PDF text | United States (Google Cloud) |
| Sentry (Error Monitoring) | Error capture | Error messages, stack traces, request context | United States |
| Document Vault Object Store | Uploaded document storage | Policy docs, grant agreements, attachments | Per deployment |
| Hosted Malware Scanner | Upload scanning | Object keys, content type, file bytes | Per deployment |
| Docling Document Conversion | PDF extraction for knowledge index | Uploaded document bytes, extracted text | Self-hosted by default |
| PDF OCR Worker | OCR for scanned PDFs | Uploaded document bytes, recognized text | Self-hosted by default |
Outbound lookup services (not subprocessors — store no airport data)
| Service | Purpose | Data sent |
|---|---|---|
| SAM.gov | Vendor exclusion screening | Vendor name strings |
| USAspending.gov | Comparable federal award lookups | Keyword strings |
TarmacSync will notify your airport before adding new subprocessors. Contact security@tarmacsync.com to object to a subprocessor or request a copy of individual subprocessor DPAs.
4. Security measures
- TLS 1.2+ encryption in transit (HTTPS enforced).
- AES-256 encryption at rest (Neon Postgres).
- Application-layer tenant isolation with PostgreSQL row-level security (RLS) enforced on all tables.
- Application connects as a database role without BYPASSRLS; a query missing tenant context returns zero rows.
- Append-only, database-enforced audit logging. Application role holds no UPDATE or DELETE on the audit table.
- Self-hosted identity — passwordless email one-time-code sign-in with TOTP 2FA (RFC 6238).
- Three RBAC roles: owner, procurement, viewer. Org-scoped sessions, revocable on next request.
- Sliding-window rate limiting. Fails closed — if the limiter is unreachable, the request is refused.
- Secrets are server-side environment variables only. No secrets in client code, config files, or logs.
5. Data retention and deletion
Procurement sessions, evidence packets, and audit events are retained for 7 years (aligned with 2 CFR § 200.334, the federal procurement audit standard). Upon written request at the end of your subscription, TarmacSync will delete your airport's data within 30 days, subject to applicable legal retention obligations. Workspace owners can export org-scoped data at any time from Settings > Admin.
6. Breach notification
TarmacSync will notify your airport without undue delay, and no later than 72 hours, after becoming aware of a personal data breach affecting your Airport Data. Notification will describe the nature of the breach, the categories of data affected, and the measures taken or proposed to address it.
7. Cross-border transfers
All subprocessors operate in the United States. AI inference providers are configured for US-hosted processing. TarmacSync will document the provider configuration in your order form or service agreement.
8. Audit rights
Upon reasonable notice and no more than once per year, your airport may request evidence of TarmacSync's compliance with this DPA. TarmacSync will provide its most recent security documentation, subprocessor list, and responses to a reasonable security questionnaire.
9. Compliance scope
Application hosting (Vercel) and the database (Neon), where all airport data is stored and processed, hold SOC 2 Type II certifications. TarmacSync has not yet completed its own organizational SOC 2 audit — planned when enterprise requirements materialize. FedRAMP is not applicable (TarmacSync is not designed for CUI or FISMA workloads). An internal VPAT (WCAG 2.2 AA, ITI 2.5 format) is available on request. A formal penetration test is scheduled before enterprise-tier launch. SOC 2 reports from Vercel and Neon are available under NDA on request.
10. Contact
Security questions, subprocessor objections, or DPA requests: security@tarmacsync.com.