How this DPA works. This DPA describes how TarmacSync processes Airport Data and the categories of service providers that may support the service. Applicable provider and data-residency details will be documented during customer review. It applies when your airport signs an order form or participates in a product evaluation. TarmacSync acts as a data processor; your airport is the data controller.

1. Definitions

Airport Data means information your airport provides to TarmacSync - procurement policies, purchase descriptions, project context, funding information, uploaded documents, and related materials.

Processing means any operation performed on Airport Data, including collection, storage, retrieval, transmission, and deletion.

Subprocessor means a third party engaged by TarmacSync to process Airport Data as part of delivering the service.

2. Data processing scope

TarmacSync processes Airport Data only to provide the service, troubleshoot issues, and communicate about the service. We do not use Airport Data to train public AI models. Airport Data is not sold or shared for advertising.

Categories of data: airport configuration, procurement policies and thresholds, purchase descriptions, project context, funding information, uploaded policy and grant documents, conversation history, generated path reviews and evidence packets.

Purpose: operating the TarmacSync procurement intelligence workspace.

Duration: for the term of your subscription, plus applicable retention periods.

3. Subprocessors

TarmacSync may use the following categories of service providers to support the service. Providers marked when configured are enabled by deployment setting and are absent when not configured.

Core (always active)

When configured

Outbound lookup services (not subprocessors - store no airport data)

TarmacSync will notify your airport before adding new subprocessors. Contact security@tarmacsync.com to object to a subprocessor or request a copy of individual subprocessor DPAs.

4. Security measures

  • TLS 1.2+ encryption in transit (HTTPS enforced).
  • AES-256 encryption at rest (Neon Postgres).
  • Application-layer tenant isolation with PostgreSQL row-level security (RLS) enforced on all tables.
  • Application connects as a database role without BYPASSRLS; a query missing tenant context returns zero rows.
  • Self-hosted identity: passwordless email one-time-code sign-in with TOTP 2FA (RFC 6238).
  • Three RBAC roles: owner, procurement, viewer. Org-scoped sessions, revocable on next request.
  • Sliding-window rate limiting. Fails closed: if the limiter is unreachable, the request is refused.
  • Secrets are server-side environment variables only. No secrets in client code, config files, or logs.

5. Data retention and deletion

TarmacSync retains Airport Data for the subscription term and for any additional period reasonably necessary to provide the service, maintain security and business records, resolve disputes, and satisfy applicable contractual or legal obligations. Specific return, retention, and deletion requirements may be established in the applicable customer agreement. Workspace owners can export org-scoped data at any time from Settings > Admin.

6. Breach notification

TarmacSync will notify your airport without undue delay, and no later than 72 hours, after becoming aware of a personal data breach affecting your Airport Data. Notification will describe the nature of the breach, the categories of data affected, and the measures taken or proposed to address it.

7. Cross-border transfers

TarmacSync will document the applicable provider configuration and data-residency arrangements in your order form or service agreement. Airports with specific data-residency requirements should confirm the configuration with TarmacSync before use.

8. Audit rights

Upon reasonable notice and no more than once per year, your airport may request evidence of TarmacSync's compliance with this DPA. TarmacSync will provide its most recent security documentation, subprocessor list, and responses to a reasonable security questionnaire.

9. Compliance scope

Application hosting (Vercel) and the database (Neon), where all airport data is stored and processed, hold SOC 2 Type II certifications. TarmacSync has not yet completed its own organizational SOC 2 audit - planned when enterprise requirements materialize. FedRAMP is not applicable (TarmacSync is not designed for CUI or FISMA workloads). An internal VPAT (WCAG 2.2 AA, ITI 2.5 format) is available on request. SOC 2 reports from Vercel and Neon are available under NDA on request.

10. Contact

Security questions, subprocessor objections, or DPA requests: security@tarmacsync.com.