GDPR SOVEREIGNTY

GDPR Compliance

EU General Data Protection Regulation (Regulation (EU) 2016/679)

AeroFind AG is fully committed to compliance with the EU General Data Protection Regulation (GDPR). In the aviation ground support industry, passenger records, flight routing itineraries, and baggage tags constitute highly sensitive, regulative Personally Identifiable Information (PII). AeroFind has been structurally designed around the concept of Data Protection by Design and by Default (GDPR Article 25).

1. Deployment-Controlled Data Boundary

AeroFind can be deployed as a customer-controlled self-hosted installation or as a cloud-hosted trial/pilot environment. The exact data location, hosting provider, support access model, and sub-processors must be documented for each deployment before live passenger data is processed. Trial environments should use fictional or demo data unless a signed processing agreement and production security sign-off are in place.

2. Key Technical Protections

To aid airport operators ("Data Controllers") in fulfilling their GDPR obligations, the Platform implements several automated security gates:

  • Configurable Retention and Erasure: Closed or delivered baggage reports, cabin lost/found records, and operational logs can be purged by configured retention jobs. DSAR export and anonymisation workflows support the Controller's handling of data subject rights.
  • Role-Based Access Control (RBAC): Access to baggage claims, intake photos, and dispatch coordinates is limited exclusively to authorized terminal staff and couriers based on strict local credentials.
  • Audit Logging: Operational actions are recorded in an HMAC-chained audit log to support accountability and tamper-evidence reviews.

3. Transfers, Hosting and Sub-processors

AeroFind does not require a non-EU transfer by default, but live deployments may use hosting, email/SMS, courier, WorldTracer/SITA, AI, backup, or support providers. Each enabled processor, processing country, transfer mechanism, support access location, and security measure must be recorded in the AVV/DPA and processor register before production use.

4. Data Protection Officers & DPA Setup

AeroFind includes an AVV/Data Processing Agreement template and processor documentation pack for customer review. A signed AVV/DPA, approved retention schedule, hosting-location confirmation, sub-processor list, and support-access description are required before production use with live personal data. For detailed software audit reports, database entity relationship diagrams, or custom firewall configuration guidelines, please contact our compliance desk at support@aerofind.online.