RootCause Simulator
Back to home

Version 1.0

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the service agreement between [COMPANY NAME] ("Processor") and the enterprise customer ("Controller") and governs the processing of personal data in connection with the HFACS RCA Trainer platform.

DPA Version

1.0

Effective

[EFFECTIVE DATE]

Framework

GDPR / CCPA

Parties to this Agreement

Controller

The enterprise customer

Identified in the master service agreement or order form

Processor

[COMPANY NAME]

[COMPANY ADDRESS]

RootCauseSim@gmail.com

1. Definitions

For the purposes of this DPA:

  • "Personal Data" means any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller in connection with the Service.
  • "Processing" has the meaning given in applicable Data Protection Law and includes any operation performed on Personal Data.
  • "Data Protection Law" means the EU General Data Protection Regulation (GDPR) 2016/679, the UK GDPR, the California Consumer Privacy Act (CCPA), and any equivalent national legislation, as applicable to the parties.
  • "Service" means the RootCause Simulator platform and associated features provided by the Processor.
  • "Sub-Processor" means any third-party processor engaged by the Processor to assist in processing Personal Data.
  • "Security Incident" means any confirmed or reasonably suspected unauthorised access, disclosure, alteration, or destruction of Personal Data.

2. Scope and Purpose of Processing

The Processor will process Personal Data only as described below and only on the documented instructions of the Controller:

CategoryData TypesPurpose
Account DataEmail address, hashed credentialAuthentication and account management
Training DataModule progress, quiz responses, reflection entries, badges, certification recordsDelivery of personalised HFACS training curriculum and certification tracking
Scenario NarrativesUser-authored practice scenario textStorage, export, and optional AI-assisted feedback generation
Security LogsTruncated IP address (first three octets), login timestamps, failed login countsAccount lockout protection, fraud prevention, audit trail
Consent RecordsTimestamp and policy version at time of consentCompliance recordkeeping

3. Processor Obligations

The Processor agrees to:

  • Process Personal Data only on documented instructions from the Controller, unless required to do so by applicable law.
  • Ensure that all personnel with access to Personal Data are bound by appropriate confidentiality obligations.
  • Implement and maintain the technical and organisational security measures described in Section 6.
  • Notify the Controller promptly (and in any event within 72 hours of becoming aware) of any confirmed or suspected Security Incident affecting Personal Data.
  • Assist the Controller in responding to Data Subject rights requests, at the Controller's reasonable expense.
  • At the Controller's election upon termination of the service relationship, delete or return all Personal Data within 30 days.
  • Make available all information reasonably necessary to demonstrate compliance with this DPA, and cooperate with audits on reasonable prior written notice.

4. Controller Obligations

The Controller agrees to:

  • Ensure it has a lawful basis for processing Personal Data before instructing the Processor.
  • Ensure that Personal Data provided to the Processor does not include sensitive special-category data (health, biometric, criminal record data) unless expressly agreed in writing.
  • Instruct users not to enter personally identifiable information about real individuals in scenario narratives, as described in the platform's Terms of Service.
  • Provide any consents, notices, or disclosures required by applicable Data Protection Law to Data Subjects whose data is processed under this DPA.

5. Sub-Processors

The Controller hereby grants general authorisation to the Processor to engage the following Sub-Processors. The Processor will notify the Controller of any proposed changes to Sub-Processors with at least 14 days' notice, giving the Controller the opportunity to object on reasonable data protection grounds.

Supabase, Inc.

Privacy Policy
ServiceDatabase, authentication, file storage, and API infrastructure
LocationUnited States (AWS us-east-1 — N. Virginia)
Transfer mechanismStandard Contractual Clauses (SCCs) where applicable

OpenAI, L.L.C.

Privacy Policy
ServiceAI-assisted narrative analysis (invoked only when the Controller's users explicitly use the AI feedback feature)
LocationUnited States
Transfer mechanismStandard Contractual Clauses (SCCs) where applicable. Only practice narrative text is transmitted — no account identifiers.

Note on international transfers: Personal Data may be transferred to and processed in the United States. Where the Controller is established in the EEA or UK, such transfers are made pursuant to Standard Contractual Clauses adopted by the European Commission and, where applicable, the UK International Data Transfer Addendum.

6. Technical and Organisational Security Measures

The Processor currently implements the following security measures:

Encryption in transit

TLS 1.2+ on all connections

Encryption at rest

AES-256 at infrastructure level (Supabase/AWS)

Access control

Row-level security policies; principle of least privilege

Authentication

Hashed credentials; account lockout after repeated failures

Audit logging

Append-only logs for admin actions and sensitive operations

Input sanitisation

DOMPurify on all rich-text content; URL allowlisting

Security headers

CSP, HSTS, X-Frame-Options, X-Content-Type-Options on all responses

Admin privilege control

Server-side metadata; user cannot self-elevate

The platform is in active development. An independent penetration test by a credentialed third party is planned prior to general availability. The Processor will provide a summary of findings to enterprise customers upon request.

7. Data Subject Rights

Where a Data Subject submits a request to the Processor to exercise rights under applicable Data Protection Law (access, rectification, erasure, portability, restriction, or objection), the Processor will:

  • Notify the Controller within 5 business days of receiving the request.
  • Not respond to the Data Subject directly on the Controller's behalf unless instructed to do so.
  • Provide reasonable technical assistance to enable the Controller to fulfil the request within the statutory timeframe.

Account deletion can be initiated by the user via the Settings page. Upon confirmed deletion, Personal Data is removed within 30 days, subject to the retention obligations in Section 8.

8. Data Retention and Deletion

Data CategoryRetention Period
Account and training dataDuration of active account; deleted within 30 days of account closure
Consent records and security logs3 years (compliance and fraud prevention)
AI narrative text transmitted to OpenAINot retained by Processor after API response; governed by OpenAI's own retention policy
Certification recordsDuration of active account, or as extended by written agreement

9. Incident Notification

In the event of a confirmed Security Incident involving Personal Data, the Processor will:

  • Notify the Controller without undue delay and within 72 hours of becoming aware.
  • Provide, to the extent known at the time of notification: the nature of the incident; categories and approximate number of Data Subjects affected; categories and approximate volume of records involved; likely consequences; measures taken or proposed to address the incident.
  • Cooperate with the Controller in meeting any regulatory notification obligations.

Security incidents should be reported to: RootCauseSim@gmail.com

10. Liability and Indemnification

Each party's liability under this DPA is subject to the limitations and exclusions set out in the master service agreement between the parties. To the extent permitted by applicable law, neither party shall be liable to the other for indirect, consequential, or punitive damages arising from a breach of this DPA.

11. Term and Termination

This DPA is effective from the date the parties execute the master service agreement and continues until termination of that agreement. Obligations relating to Personal Data processed prior to termination survive for the duration of the applicable retention periods set out in Section 8.

12. Governing Law

This DPA is governed by the same law as the master service agreement unless otherwise required by applicable Data Protection Law.

13. Entire Agreement

This DPA, together with the master service agreement and any executed order form, constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior agreements and understandings relating to data processing.

14. Contact and Execution

To request a countersigned copy of this DPA or to raise data protection queries:

[COMPANY NAME]

[COMPANY ADDRESS]

RootCauseSim@gmail.com