How this DPA works. This DPA describes how TarmacSync processes airport data, lists active subprocessors, and states our security and data-handling commitments. It applies when your airport signs an order form or participates in the Founding Airport Partner Program. TarmacSync acts as a data processor; your airport is the data controller.

1. Definitions

Airport Data means information your airport provides to TarmacSync — procurement policies, purchase descriptions, project context, funding information, uploaded documents, and related materials.

Processing means any operation performed on Airport Data, including collection, storage, retrieval, transmission, and deletion.

Subprocessor means a third party engaged by TarmacSync to process Airport Data as part of delivering the service.

2. Data processing scope

TarmacSync processes Airport Data only to provide the service, troubleshoot issues, and communicate about the service. We do not use Airport Data to train public AI models. Airport Data is not sold or shared for advertising.

Categories of data: airport configuration, procurement policies and thresholds, purchase descriptions, project context, funding information, uploaded policy and grant documents, conversation history, generated path reviews and evidence packets.

Purpose: operating the TarmacSync procurement intelligence workspace.

Duration: for the term of your subscription, plus applicable retention periods.

3. Subprocessors

TarmacSync uses the following subprocessors. All core subprocessors are located in the United States. Subprocessors marked when configured are enabled by deployment setting and are absent when not configured.

Core (always active)

SubprocessorPurposeData processedLocation
Neon (Database)Persistent storageAll structured dataUnited States (AWS us-east-1)
Resend (Transactional Email)Sign-in codes, notificationsRecipient email, message bodyUnited States
Vercel (Hosting)App hosting, CDN, serverless functionsHTTP request/response, server-side logsUnited States

When configured

SubprocessorPurposeData processedLocation
Google (Gemini AI)AI inference, PDF extractionConversation content, airport context, uploaded PDF textUnited States (Google Cloud)
Sentry (Error Monitoring)Error captureError messages, stack traces, request contextUnited States
Document Vault Object StoreUploaded document storagePolicy docs, grant agreements, attachmentsPer deployment
Hosted Malware ScannerUpload scanningObject keys, content type, file bytesPer deployment
Docling Document ConversionPDF extraction for knowledge indexUploaded document bytes, extracted textSelf-hosted by default
PDF OCR WorkerOCR for scanned PDFsUploaded document bytes, recognized textSelf-hosted by default

Outbound lookup services (not subprocessors — store no airport data)

ServicePurposeData sent
SAM.govVendor exclusion screeningVendor name strings
USAspending.govComparable federal award lookupsKeyword strings

TarmacSync will notify your airport before adding new subprocessors. Contact security@tarmacsync.com to object to a subprocessor or request a copy of individual subprocessor DPAs.

4. Security measures

  • TLS 1.2+ encryption in transit (HTTPS enforced).
  • AES-256 encryption at rest (Neon Postgres).
  • Application-layer tenant isolation with PostgreSQL row-level security (RLS) enforced on all tables.
  • Application connects as a database role without BYPASSRLS; a query missing tenant context returns zero rows.
  • Append-only, database-enforced audit logging. Application role holds no UPDATE or DELETE on the audit table.
  • Self-hosted identity — passwordless email one-time-code sign-in with TOTP 2FA (RFC 6238).
  • Three RBAC roles: owner, procurement, viewer. Org-scoped sessions, revocable on next request.
  • Sliding-window rate limiting. Fails closed — if the limiter is unreachable, the request is refused.
  • Secrets are server-side environment variables only. No secrets in client code, config files, or logs.

5. Data retention and deletion

Procurement sessions, evidence packets, and audit events are retained for 7 years (aligned with 2 CFR § 200.334, the federal procurement audit standard). Upon written request at the end of your subscription, TarmacSync will delete your airport's data within 30 days, subject to applicable legal retention obligations. Workspace owners can export org-scoped data at any time from Settings > Admin.

6. Breach notification

TarmacSync will notify your airport without undue delay, and no later than 72 hours, after becoming aware of a personal data breach affecting your Airport Data. Notification will describe the nature of the breach, the categories of data affected, and the measures taken or proposed to address it.

7. Cross-border transfers

All subprocessors operate in the United States. AI inference providers are configured for US-hosted processing. TarmacSync will document the provider configuration in your order form or service agreement.

8. Audit rights

Upon reasonable notice and no more than once per year, your airport may request evidence of TarmacSync's compliance with this DPA. TarmacSync will provide its most recent security documentation, subprocessor list, and responses to a reasonable security questionnaire.

9. Compliance scope

Application hosting (Vercel) and the database (Neon), where all airport data is stored and processed, hold SOC 2 Type II certifications. TarmacSync has not yet completed its own organizational SOC 2 audit — planned when enterprise requirements materialize. FedRAMP is not applicable (TarmacSync is not designed for CUI or FISMA workloads). An internal VPAT (WCAG 2.2 AA, ITI 2.5 format) is available on request. A formal penetration test is scheduled before enterprise-tier launch. SOC 2 reports from Vercel and Neon are available under NDA on request.

10. Contact

Security questions, subprocessor objections, or DPA requests: security@tarmacsync.com.