Version 1.0
Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the service agreement between [COMPANY NAME] ("Processor") and the enterprise customer ("Controller") and governs the processing of personal data in connection with the HFACS RCA Trainer platform.
DPA Version
1.0
Effective
[EFFECTIVE DATE]
Framework
GDPR / CCPA
Parties to this Agreement
Controller
The enterprise customer
Identified in the master service agreement or order form
1. Definitions
For the purposes of this DPA:
- "Personal Data" means any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller in connection with the Service.
- "Processing" has the meaning given in applicable Data Protection Law and includes any operation performed on Personal Data.
- "Data Protection Law" means the EU General Data Protection Regulation (GDPR) 2016/679, the UK GDPR, the California Consumer Privacy Act (CCPA), and any equivalent national legislation, as applicable to the parties.
- "Service" means the RootCause Simulator platform and associated features provided by the Processor.
- "Sub-Processor" means any third-party processor engaged by the Processor to assist in processing Personal Data.
- "Security Incident" means any confirmed or reasonably suspected unauthorised access, disclosure, alteration, or destruction of Personal Data.
2. Scope and Purpose of Processing
The Processor will process Personal Data only as described below and only on the documented instructions of the Controller:
| Category | Data Types | Purpose |
|---|---|---|
| Account Data | Email address, hashed credential | Authentication and account management |
| Training Data | Module progress, quiz responses, reflection entries, badges, certification records | Delivery of personalised HFACS training curriculum and certification tracking |
| Scenario Narratives | User-authored practice scenario text | Storage, export, and optional AI-assisted feedback generation |
| Security Logs | Truncated IP address (first three octets), login timestamps, failed login counts | Account lockout protection, fraud prevention, audit trail |
| Consent Records | Timestamp and policy version at time of consent | Compliance recordkeeping |
3. Processor Obligations
The Processor agrees to:
- Process Personal Data only on documented instructions from the Controller, unless required to do so by applicable law.
- Ensure that all personnel with access to Personal Data are bound by appropriate confidentiality obligations.
- Implement and maintain the technical and organisational security measures described in Section 6.
- Notify the Controller promptly (and in any event within 72 hours of becoming aware) of any confirmed or suspected Security Incident affecting Personal Data.
- Assist the Controller in responding to Data Subject rights requests, at the Controller's reasonable expense.
- At the Controller's election upon termination of the service relationship, delete or return all Personal Data within 30 days.
- Make available all information reasonably necessary to demonstrate compliance with this DPA, and cooperate with audits on reasonable prior written notice.
4. Controller Obligations
The Controller agrees to:
- Ensure it has a lawful basis for processing Personal Data before instructing the Processor.
- Ensure that Personal Data provided to the Processor does not include sensitive special-category data (health, biometric, criminal record data) unless expressly agreed in writing.
- Instruct users not to enter personally identifiable information about real individuals in scenario narratives, as described in the platform's Terms of Service.
- Provide any consents, notices, or disclosures required by applicable Data Protection Law to Data Subjects whose data is processed under this DPA.
5. Sub-Processors
The Controller hereby grants general authorisation to the Processor to engage the following Sub-Processors. The Processor will notify the Controller of any proposed changes to Sub-Processors with at least 14 days' notice, giving the Controller the opportunity to object on reasonable data protection grounds.
Supabase, Inc.
Privacy PolicyOpenAI, L.L.C.
Privacy PolicyNote on international transfers: Personal Data may be transferred to and processed in the United States. Where the Controller is established in the EEA or UK, such transfers are made pursuant to Standard Contractual Clauses adopted by the European Commission and, where applicable, the UK International Data Transfer Addendum.
6. Technical and Organisational Security Measures
The Processor currently implements the following security measures:
Encryption in transit
TLS 1.2+ on all connections
Encryption at rest
AES-256 at infrastructure level (Supabase/AWS)
Access control
Row-level security policies; principle of least privilege
Authentication
Hashed credentials; account lockout after repeated failures
Audit logging
Append-only logs for admin actions and sensitive operations
Input sanitisation
DOMPurify on all rich-text content; URL allowlisting
Security headers
CSP, HSTS, X-Frame-Options, X-Content-Type-Options on all responses
Admin privilege control
Server-side metadata; user cannot self-elevate
The platform is in active development. An independent penetration test by a credentialed third party is planned prior to general availability. The Processor will provide a summary of findings to enterprise customers upon request.
7. Data Subject Rights
Where a Data Subject submits a request to the Processor to exercise rights under applicable Data Protection Law (access, rectification, erasure, portability, restriction, or objection), the Processor will:
- Notify the Controller within 5 business days of receiving the request.
- Not respond to the Data Subject directly on the Controller's behalf unless instructed to do so.
- Provide reasonable technical assistance to enable the Controller to fulfil the request within the statutory timeframe.
Account deletion can be initiated by the user via the Settings page. Upon confirmed deletion, Personal Data is removed within 30 days, subject to the retention obligations in Section 8.
8. Data Retention and Deletion
| Data Category | Retention Period |
|---|---|
| Account and training data | Duration of active account; deleted within 30 days of account closure |
| Consent records and security logs | 3 years (compliance and fraud prevention) |
| AI narrative text transmitted to OpenAI | Not retained by Processor after API response; governed by OpenAI's own retention policy |
| Certification records | Duration of active account, or as extended by written agreement |
9. Incident Notification
In the event of a confirmed Security Incident involving Personal Data, the Processor will:
- Notify the Controller without undue delay and within 72 hours of becoming aware.
- Provide, to the extent known at the time of notification: the nature of the incident; categories and approximate number of Data Subjects affected; categories and approximate volume of records involved; likely consequences; measures taken or proposed to address the incident.
- Cooperate with the Controller in meeting any regulatory notification obligations.
Security incidents should be reported to: RootCauseSim@gmail.com
10. Liability and Indemnification
Each party's liability under this DPA is subject to the limitations and exclusions set out in the master service agreement between the parties. To the extent permitted by applicable law, neither party shall be liable to the other for indirect, consequential, or punitive damages arising from a breach of this DPA.
11. Term and Termination
This DPA is effective from the date the parties execute the master service agreement and continues until termination of that agreement. Obligations relating to Personal Data processed prior to termination survive for the duration of the applicable retention periods set out in Section 8.
12. Governing Law
This DPA is governed by the same law as the master service agreement unless otherwise required by applicable Data Protection Law.
13. Entire Agreement
This DPA, together with the master service agreement and any executed order form, constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior agreements and understandings relating to data processing.
14. Contact and Execution
To request a countersigned copy of this DPA or to raise data protection queries: