Record of Processing Activities (RoPA)¶
UK GDPR Art 30. Controls PRIV-01. Status: designed — seeded from
readiness/data-inventory-and-retention.md, pending counsel confirmation of
lawful basis. [counsel required] on the lawful-basis column.
Controller: Partile (entity details — Tier 2 / restricted, not stored here).
Production hosting is now Google Cloud in europe-west2; there is still no real
user data. Pre-launch seed data is fictional/mock traveler data tagged
users.is_seed = true and is tracked separately from real-user processing.
Geography (2026-07-04, Data Sourcing Map canon): launch scope is US + Europe (12 seed airports incl. LHR/CDG/AMS/FRA/MAD). EU operation brings EU GDPR alongside UK GDPR into scope (representative/lead-authority analysis OPEN — counsel), and EU border-rule content (ETIAS/EES) enters the product's informational scope — that is curated reference content, not personal-data processing, but the distinction is recorded here deliberately.
Policy: policies/privacy-and-retention-policy.md. Field-level inventory →
readiness/data-inventory-and-retention.md. Processor detail →
subprocessors.md.
| # | Processing activity | Data subjects | Data categories | Purpose | Lawful basis (provisional) | Recipients / processors | Retention (target) | Transfers |
|---|---|---|---|---|---|---|---|---|
| 1 | Account creation & authentication | Travelers | LinkedIn sub, email, name, picture |
Identity, login | Contract | LinkedIn (source); Google Cloud production host | Life of account + grace | TBD (Art 44-49) |
| 2 | Session management | Travelers | Hashed session token, timestamps | Secure access | Contract | Google Cloud production host | 30d after expiry/revoke | — |
| 3 | Flight presence intake | Travelers | Boarding-pass-derived airport, optional terminal/gate, departure/window times, verification level; no raw pass payload/PNR/name/ticket/seat retained | Co-location matching | Consent (proximity) | Google Cloud production host | 7d after presence expiry | — |
| 4 | Match generation & connect requests | Travelers | User pair, verified place/time context, relevance ranking state, request note, request/accept/decline state | Core professional matching and connect workflow | Legitimate interest / contract | Google Cloud production host | 30d after terminal status; request-note retention pending | — |
| 5 | Messaging | Travelers | Message body, sender, timestamps | Matched communication | Contract | Google Cloud production host | 90d after last activity (TBD) | — |
| 6 | Trust & safety | Travelers | Block pairs; report reason/details/status | Abuse handling, safety | Legitimate interest (safety) | Google Cloud production host; future moderation | Block: life of account; report: 180d after resolve (TBD) | — |
| 7 | Analytics / ML (planned) | Travelers | Tiered events (see ML taxonomy) | Product improvement, recommender training | Consent (T1/T2) | Google Cloud production host; future warehouse | TBD | TBD |
| 8 | Persistent professional connections | Travelers | Accepted connection pair, request-note metadata, timestamps, conversation link, minimized counterpart profile fields; no raw boarding-pass payload | Durable professional network contact beyond the trip window (GET /connections) |
Contract / legitimate interest [counsel required] | Google Cloud production host | Persists beyond trip window; hard-delete on account erasure; independent duration TBD per C28 | — |
| 9 | Profile enrichment for matching (deferred) | Travelers | PDL/ZoomInfo enrichment attributes, if later enabled, used only as internal matching signals | Rank the verified airport/window directory and generate match rationale | Legitimate interest (provisional per C26) | PDL; ZoomInfo; cloud host | Deferred; no broker processing today; future retention TBD | TBD |
| 10 | Professional profile management | Travelers | LinkedIn display fields plus self-authored headline, summary, and intent tags | Let travelers present professional context and improve matching/card relevance | Contract / legitimate interest [counsel required] | Google Cloud production host | Life of account; hard-delete on account erasure | — |
| 11 | AI rationale and profile interview (key-gated) | Travelers | Rationale: minimized display name/headline/intent tags plus cached rationale sentence; interview: bounded role/content turns and advisory suggested summary. No email, raw identifiers, raw boarding-pass data, secrets, or broker enrichment | Generate match rationale and help users deepen their own professional profile | Legitimate interest / contract [counsel required per C27] | Anthropic (Claude API, when key is set); Google Cloud production host | Rationale cache expires with the pair/window input TTL; interview endpoint is stateless and does not auto-write profile summaries; account-linked source data erased with account | TBD |
| 12 | Pre-launch seed testing | Fictional/mock travelers only | Mock accounts, profiles, presences, messages, connection requests, and rationales tagged through users.is_seed = true; no real PII |
Production-like testing before GA | Not personal data if fictional; keep segregated [counsel to confirm posture] | Google Cloud production host | Purge before GA and before real users | — |
| 13 | Trip-history persistence (STUB — forthcoming, NOT built) | Travelers | Past flights/presences retained beyond the current trip window — a movement profile (stateful-boarding-pass roadmap) | Trip history, arrival briefs, and longitudinal product features | OPEN — no lawful basis assigned; [counsel required per C29]. Lawful basis + retention + DSAR treatment must be settled BEFORE this becomes user-facing | Google Cloud production host | OPEN — no retention class defined yet; must land in retention-schedule.md before build |
TBD |
Processor/subprocessor detail → subprocessors.md. Field-level inventory →
readiness/data-inventory-and-retention.md. Retention mechanics →
retention-schedule.md.