legal · data processing addendum
data processing addendum
effective: 2026-10-04 · Owner-approved 2026-10-04; no counsel review
1. scope & roles
This Data Processing Addendum ("DPA") applies to personal data that you (the customer) submit to Vector and that Wentzel Investments LLC, a Florida limited liability company (trading as Wentzel.ai) ("we") processes on your behalf. It forms part of the Terms of Service. For that data you are the controller (or processor acting for your own customer) and we are the processor (or sub-processor). We act as an independent controller for account and security-log data about your users (and billing data, if and when paid plans are enabled), as described in the Privacy notice.
2. what we process
Subject matter and duration: providing Vector to you for as long as your account is active, plus the post-termination export and deletion period described in section 7.
Categories of data subjects: your personnel and contractors (for example crew, dispatchers, administrators), your passengers, and your clients and their contacts.
Types of personal data, as you choose to enter them: identity and contact details, crew qualifications, endorsements, duty and rest records, flight and passenger manifest details, and account and audit-log data. Vector is not designed for special-category data; please do not submit it.
3. our obligations
- Process personal data only on your documented instructions, which are these terms, your configuration of Vector, and your use of its features, unless the law requires otherwise (in which case we tell you first where permitted).
- Ensure personnel with access are bound by confidentiality.
- Maintain the technical and organisational measures described in section 5.
- Not sell personal data and not use customer content to train shared or third-party models.
- Taking into account the nature of processing, reasonably help you respond to data-subject requests and meet your security, breach-notification, and impact-assessment obligations.
4. sub-processors
You authorise the sub-processors below. All are under contract requiring appropriate confidentiality and security measures. We will update this list before adding or replacing a sub-processor and will give you notice so that you can object on reasonable grounds; if we cannot resolve the objection, you may cancel.
- Cloudflare, Inc. (United States) — edge compute (Workers), CDN, D1 database, KV storage, DNS, DDoS mitigation, and the AI Gateway through which assistant requests are routed.
- Amazon Web Services, Inc. (United States) — transactional email (SES) and related platform services described on the Trust & Security page.
- Stripe, Inc. (United States) — payment processing and billing, if and when paid plans are enabled.
- Google LLC (United States) — account sign-in (Google OAuth).
- Functional Software, Inc. d/b/a Sentry (United States) — error and performance monitoring; error reports can include technical context from our servers and browsers, which may incidentally contain personal data.
- Atlassian Pty Ltd and its affiliates (Jira Service Management support desk) — support requests you submit through the support portal.
- Slack Technologies, LLC (United States) — internal notification of in-product feedback you submit, which includes your user ID, the page path, and your message.
- Anthropic, PBC (United States) — AI model provider for the Vector assistant, reached through the Cloudflare AI Gateway.
5. security
Our measures include: TLS 1.2+ for data in transit; AES-256 encryption at rest by the underlying storage platform; least-privilege access with scoped credentials; per-product database isolation; runtime secrets held in managed secret stores and never in source control; optional TOTP two-factor sign-in; and an audit log of selected account and data mutations. Details are on the Trust & Security page. We do not currently hold a SOC 2 report or other third-party certification.
6. personal-data breaches
We will notify you without undue delay after becoming aware of a personal-data breach affecting your customer data and provide the information reasonably available to help you meet your own notification duties. Report suspected incidents to security@wentzel.ai.
7. return & deletion
After termination, on your written request we will provide an export of your customer data and will delete it within a reasonable period, unless the law requires us to retain it. We do not currently run an automated retention or purge schedule, and there is no self-serve export endpoint. Backups and logs age out in the ordinary course.
8. audits & information
On reasonable written request we will provide information needed to show compliance with this DPA, such as our security documentation. Because no independent audit report currently exists, any on-site or further audit must be agreed in advance, limited in scope and frequency, and carried out at your cost under confidentiality.
9. international transfers
We and our sub-processors process data in the United States. Where law requires a transfer mechanism for personal data moved from the EEA, UK, or Switzerland, we will work with you to put an appropriate mechanism in place.
10. liability, order of precedence & contact
Liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms on the processing of personal data, this DPA prevails. Questions: contact@wentzel.ai.