Section 8

International Data Transfers

AeroVance operates a global aerospace and defense engineering network. As part of our operations, personal and technical data may be transferred to, processed in, or accessed from jurisdictions outside the European Economic Area (EEA), the United Kingdom, and California. This section outlines how we ensure those transfers meet rigorous legal and security standards.

8.1 Why We Transfer Data Internationally

Our engineering teams, manufacturing facilities, launch operations, and defense partners span multiple countries. Cross-border data flows are essential for:

8.2 Legal Frameworks & Safeguards

AeroVance does not transfer data to jurisdictions with inadequate privacy protections unless appropriate safeguards are in place. We rely on the following mechanisms under GDPR, CCPA, and applicable defense export controls:

Safeguard Mechanism Applicable To Implementation Status
EU Standard Contractual Clauses (2021/914) EEA to Third Countries Active & Executed with all processors
UK International Data Transfer Addendum UK to Third Countries Active & Integrated into SCCs
US-EU Data Privacy Framework US-based Cloud & Analytics Services Certified & Compliant
Binding Corporate Rules (BCRs) Intra-Group Transfers Approved by EDPB (2024)
Adequacy Decisions Switzerland, Japan, Canada (commercial) Monitored & Updated Quarterly
⚠️ Defense & ITAR/EAR Note: Certain technical data and contractor information are subject to US export controls (ITAR/EAR) and may be restricted from transfer to specific jurisdictions regardless of adequacy status. Additional contractual and technical restrictions apply to cleared personnel data.

8.3 Data Flow Architecture

All international transfers are governed by our Data Protection Impact Assessment (DPIA) register and cross-border transfer mapping. Key principles include:

  1. Data Minimization: Only data strictly necessary for the contractual or operational purpose is transferred.
  2. Encryption in Transit & At Rest: AES-256 encryption with key management hosted within our primary jurisdiction.
  3. Access Logging & Audit: All cross-border access events are logged, monitored, and subject to annual third-party audit.
  4. Subprocessor Transparency: Any changes to international subprocessors are notified to data subjects/controllers within 30 days.

8.4 Recipient Locations

As of the last update, AeroVance processes and stores data in the following jurisdictions:

8.5 Your Rights & Enforcement

If you are concerned about an international transfer of your personal data, or if a jurisdiction's legal environment changes (e.g., new surveillance laws or export control updates), you may:

Questions about cross-border data handling?
Our DPO team maintains full transparency logs and is available for vendor inquiries, audit requests, and regulatory correspondence.

Contact Data Protection Office

Last updated: November 2025 | Policy Version 8.2.1 | In accordance with GDPR Art. 44-49, CCPA §1798.185, and ISO 27001:2022 controls.