1. Definitions
1.1 ‘Confidential Information’ means all non-public information disclosed by or on behalf of a Disclosing Party to a Receiving Party, whether before or after the Effective Date and whether disclosed orally, visually, electronically, physically, digitally, by inspection, through access to systems or facilities, through samples, through plant tours, through collaboration portals, or in any other form. Confidential Information includes information marked confidential, proprietary, restricted, CUI, export controlled, trade secret, limited distribution, or with similar markings, and also includes information that a reasonable aerospace supplier, manufacturer, repair provider, engineer, quality professional, export-control professional, or business person would understand to be confidential from the nature of the information or the circumstances of disclosure.
1.2 Confidential Information includes, without limitation, engineering drawings, CAD models, solid models, layouts, sketches, dimensional data, specifications, bills of material, routings, work instructions, inspection plans, first article inspection records, PPAP or equivalent production-readiness data, process sheets, tooling designs, gage designs, fixtures, manufacturing methods, special-process information, test plans, test reports, qualification data, material data, chemical or metallurgical information, supplier lists, pricing, margin data, customer information, forecasts, demand signals, source-inspection information, audit reports, corrective actions, nonconformance records, risk assessments, software, source code, object code, databases, passwords, cybersecurity information, facility information, and information concerning the existence, scope, timing, status, or outcome of negotiations between the Parties.
1.3 For aerospace and FAA-regulated work, Confidential Information specifically includes PMA data, STC data, TSO data, FAA correspondence, FAA submissions, FAA approvals, design approvals, design data, type design data, airworthiness data, Instructions for Continued Airworthiness, Continued Operational Safety information, conformity records, delegation-of-authority information, supplier-control records, traceability records, serialization data, installation data, repair or overhaul information, service difficulty information, failure analysis information, and information used to determine conformity or airworthiness of any product, article, part, component, subassembly, appliance, or assembly.
1.4 ‘Disclosing Party’ means the Party disclosing Confidential Information. ‘Receiving Party’ means the Party receiving Confidential Information. ‘Representatives’ means a Party’s directors, officers, employees, contractors, consultants, advisors, attorneys, accountants, insurers, auditors, affiliates, parent companies, subsidiaries, suppliers, subcontractors, laboratories, special processors, freight forwarders, cloud-service providers, information-technology providers, brokers, and agents who receive or access Confidential Information. ‘Trade Secret’ has the meaning provided under applicable federal and state law, including the Defend Trade Secrets Act, 18 U.S.C. 1836 et seq., and applicable Massachusetts trade-secret law.
1.5 The Parties intend these definitions to be interpreted broadly because aerospace confidential information is frequently embedded in ordinary operational materials. An inspection checklist can reveal a critical characteristic; a fixture drawing can reveal a proprietary manufacturing method; an email to the FAA can reveal certification strategy; and a supplier quote can reveal volume assumptions, margin structure, or customer identity. The label on the document is helpful, but the absence of a label does not remove protection when the information is confidential by nature.
5. Markings, Handling Instructions, and Oral Disclosures
5.1 Confidential Information may be marked with legends such as Confidential, Proprietary, ACD Proprietary, ITAR Controlled, EAR Controlled, CUI, Export Controlled, Limited Distribution, or similar notices. The Receiving Party shall not remove, obscure, alter, or disregard any such legends. If the Receiving Party believes a marking is unclear or overbroad, it shall request clarification rather than treating the information as unrestricted.
5.2 Oral or visual disclosures are protected if identified as confidential at the time of disclosure or if the nature and circumstances of the disclosure reasonably indicate confidentiality. Examples include information disclosed during a plant tour, design review, source inspection, FAA conformity meeting, supplier corrective-action meeting, or teleconference in which drawings, test results, or commercial terms are discussed.
5.3 The Receiving Party shall follow any additional written handling instructions provided by the Disclosing Party, including restrictions on copying, printing, forwarding, cloud storage, foreign-person access, supplier disclosure, or destruction. If handling instructions conflict with the Receiving Party’s normal internal procedures, the stricter instruction shall apply unless the Parties agree otherwise in writing.
6. Reverse Engineering, Competitive Use, and Derivative Work
6.1 The Receiving Party shall not reverse engineer, decompile, disassemble, chemically analyze, metallurgically analyze, measure, scan, digitize, model, reproduce, benchmark, or otherwise attempt to derive the composition, design, source code, process, manufacturing method, tolerances, tooling approach, approval basis, or know-how embodied in any product, sample, software, drawing, data package, or process disclosed by the Disclosing Party, except to the limited extent expressly authorized in writing or required to perform the Project.
6.2 The Receiving Party shall not use Confidential Information to create, improve, certify, qualify, approve, sell, or support any competing or substitute product, article, repair, overhaul method, PMA application, STC application, TSO article, engineering package, or manufacturing process. This restriction applies whether the Receiving Party acts alone or through an affiliate, customer, supplier, consultant, or other third party.
6.3 If the Receiving Party develops improvements, modifications, derivative works, analyses, compilations, or notes that incorporate, are based on, or could not reasonably have been created without the Disclosing Party’s Confidential Information, those materials shall be treated as Confidential Information of the Disclosing Party. A manufacturability analysis derived from ACD drawings, a cost model based on ACD volumes, or a corrective-action plan based on ACD nonconformance records shall remain subject to this Agreement.
7. FAA, PMA, STC, TSO, Airworthiness, and Continued Operational Safety Information
7.1 The Parties acknowledge that certain Confidential Information may relate to civil aviation products and articles subject to FAA oversight, including production approvals, PMA, STC, TSO authorizations, design data, approved data, accepted data, conformity inspections, quality systems, marking requirements, continued operational safety, service difficulty information, and reporting of failures, malfunctions, and defects. FAA regulations in 14 CFR Part 21 include requirements relevant to production approvals, PMA holders, quality systems, and access to design data necessary to determine conformity and airworthiness.
7.2 The Receiving Party shall not use FAA-related Confidential Information to make, support, or imply any regulatory approval, airworthiness determination, conformity determination, source approval, supplier approval, PMA, STC, TSO authorization, repair approval, or customer approval unless expressly authorized in writing by the Disclosing Party and permitted by applicable law. The Receiving Party shall not represent that it has authority to act for ACD before the FAA or any customer unless ACD expressly grants that authority in writing.
7.3 The Receiving Party shall preserve the integrity, traceability, and context of FAA-related Confidential Information. The Receiving Party shall not separate a drawing from its revision level, remove limitations from an approval document, use an obsolete specification without confirmation, or omit related quality or conformity requirements. In aerospace, a data item can become misleading if removed from its approval basis, revision history, part applicability, or configuration context.
7.4 Nothing in this Agreement prohibits a Party from complying with lawful FAA, National Transportation Safety Board, Department of Transportation, Department of Defense, Department of Justice, court, or other governmental requirements. When legally permitted, the Party receiving the request shall give prompt written notice to the other Party, cooperate in seeking confidential treatment, and disclose only the minimum information reasonably required.
9. Export Control, Sanctions, and Foreign-Person Access
9.1 The Parties shall comply with all applicable U.S. export-control, re-export, sanctions, and import laws and regulations, including the International Traffic in Arms Regulations (ITAR), 22 CFR Parts 120 through 130; the Export Administration Regulations (EAR), 15 CFR Parts 730 through 774; and sanctions regulations administered by the U.S. Department of the Treasury Office of Foreign Assets Control (OFAC).
9.2 The Receiving Party shall not export, re-export, transfer, release, disclose, provide access to, or otherwise make available any export-controlled Confidential Information to any foreign person, foreign entity, foreign government, embargoed country, sanctioned party, restricted party, or prohibited end user except in compliance with applicable law and after obtaining all required authorizations. A release can occur by email, cloud access, visual inspection, verbal disclosure, plant tour, screen sharing, or access by a foreign-person employee in the United States.
9.3 Before disclosing technical data to any supplier, affiliate, contractor, or employee who may be a foreign person, the Receiving Party shall determine whether the information is subject to ITAR, EAR, or other controls, identify any license, license-exception, or exemption requirements, and maintain records of the basis for access. If classification is uncertain, the Receiving Party shall stop and request written guidance from the Disclosing Party rather than assuming the data is uncontrolled.
11. Cybersecurity, Data Security, and Incident Reporting
11.1 The Receiving Party shall implement and maintain reasonable administrative, technical, and physical safeguards designed to protect Confidential Information against unauthorized access, acquisition, use, disclosure, alteration, loss, destruction, or compromise. Safeguards shall be appropriate to the type of information, the size and complexity of the Receiving Party, and the reasonably foreseeable risks associated with aerospace technical data, export-controlled data, CUI, personal information, and trade secrets.
11.2 Minimum safeguards shall include, where appropriate, access control, unique user accounts, strong authentication, least-privilege permissions, secure transmission, secure storage, malware protection, vulnerability management, patch management, backup controls, logging, employee training, secure disposal, and procedures for responding to suspected incidents. The Receiving Party shall not knowingly upload Confidential Information to public artificial-intelligence tools, public code repositories, open collaboration spaces, or uncontrolled cloud services.
11.3 The Receiving Party shall notify the Disclosing Party without unreasonable delay, and in any event within seventy-two (72) hours after discovery, of any actual or reasonably suspected unauthorized access, acquisition, disclosure, loss, misuse, ransomware event, compromise, or security incident involving Confidential Information. The notice shall describe, to the extent known, the information affected, the date and nature of the incident, the systems involved, containment actions, corrective actions, and whether any regulatory or customer notice may be required.
11.4 Where Confidential Information includes personal information of Massachusetts residents, the Receiving Party shall comply with applicable Massachusetts data-security and breach-notification requirements, including M.G.L. c. 93H and 201 CMR 17.00. Supplier files may contain contact information, employee data, visitor records, or other personal information in addition to technical data, and therefore data-security obligations should not be viewed as separate from the NDA.
13. Government Rights, Proprietary Legends, and Technical Data Restrictions
13.1 Confidential Information may include technical data, software, drawings, processes, or documentation developed at private expense and subject to restrictions on use, disclosure, reproduction, release, performance, display, or distribution. The Receiving Party shall preserve all proprietary legends, restrictive notices, export-control legends, CUI markings, government-rights legends, and data-rights markings.
13.2 Nothing in this Agreement grants the Receiving Party, any customer, any prime contractor, or any government entity unlimited rights, government-purpose rights, license rights, manufacturing rights, repair rights, source-approval rights, or ownership rights in the Disclosing Party’s Confidential Information, technical data, software, know-how, trade secrets, inventions, or intellectual property. Any such rights must be granted, if at all, in a separate written agreement signed by an authorized representative of the Disclosing Party.
13.3 The Receiving Party shall not remove an ACD proprietary legend from a drawing before forwarding it to a supplier, include ACD technical data in a government submission without authorization, or characterize ACD private-expense data as unrestricted. Technical data rights can be lost or disputed when legends are omitted, altered, or ignored during supplier or customer submissions.
14. Cross-Border Manufacturing, Out-of-State Performance, and Foreign-Law Compliance
14.1 The Receiving Party acknowledges that Confidential Information may be used, accessed, reviewed, stored, transmitted, or processed in connection with parts, articles, assemblies, subassemblies, tooling, fixtures, test equipment, inspection equipment, software, quality records, certification records, or supplier activities performed outside the Commonwealth of Massachusetts or outside the United States. Such out-of-state or foreign performance does not reduce, waive, limit, or replace the Receiving Party’s obligations under this Agreement. The Receiving Party shall remain responsible for protecting Confidential Information regardless of where the information is accessed, where the work is performed, where the part is manufactured, where the supplier is located, where the server is hosted, or where the personnel reviewing the information are physically located.
14.2 The Parties intend that this Agreement shall apply to all Confidential Information disclosed under the Project, including information used in connection with manufacturing, processing, testing, inspection, repair, overhaul, packaging, shipping, quality review, supplier management, regulatory support, or customer support outside Massachusetts or outside the United States. The fact that a part is machined in another state, heat treated in another country, inspected by a foreign laboratory, supported by an offshore engineering team, or stored in a cloud environment hosted outside Massachusetts shall not make the information unrestricted or remove duties of confidentiality, limited use, no reverse engineering, export compliance, cybersecurity, supplier flow-down, return, destruction, and incident reporting.
14.3 The Receiving Party shall comply with all mandatory laws, regulations, ordinances, orders, and governmental requirements applicable in each jurisdiction where Confidential Information is accessed or where Project-related work is performed. Such laws may include local employment law, privacy law, cybersecurity law, customs law, import law, tax law, environmental law, occupational safety law, anti-corruption law, sanctions law, aviation-safety law, and manufacturing or product-compliance law. Compliance with local law does not authorize use or disclosure beyond the scope permitted by this Agreement.
14.4 For FAA-regulated work, the Receiving Party shall not treat foreign manufacture or out-of-state manufacture as a reason to disregard FAA-related obligations, configuration-control requirements, conformity requirements, approved-data requirements, quality-system requirements, traceability requirements, or continued-operational-safety obligations. If Confidential Information relates to FAA-approved articles, PMA parts, STC data, TSO articles, Instructions for Continued Airworthiness, conformity records, airworthiness data, failure analysis, service difficulty information, or quality-system records, the Receiving Party shall preserve the technical context, revision level, proprietary markings, approval basis, and configuration status of such information.
14.5 The Receiving Party shall not manufacture, release, ship, mark, certify, approve, or represent any part, article, component, or assembly as FAA-approved, ACD-approved, customer-approved, PMA-approved, STC-approved, TSO-authorized, or airworthy unless expressly authorized in writing by ACD and permitted by applicable law.
14.6 The Receiving Party shall not export, re-export, transfer, release, disclose, or provide access to Confidential Information to any foreign person, foreign entity, foreign government, overseas supplier, offshore engineering resource, foreign affiliate, foreign subcontractor, foreign laboratory, foreign cloud-service provider, or other non-U.S. recipient unless such access is authorized in writing by the Disclosing Party and is made in full compliance with applicable export-control, sanctions, import, and re-export laws. Before disclosure, the Receiving Party shall determine whether the information is subject to ITAR, EAR, sanctions restrictions, customer restrictions, government-contract restrictions, or other dissemination controls.
14.7 Unless the Disclosing Party gives prior written authorization, the Receiving Party shall not transmit Confidential Information to, store Confidential Information in, or permit access to Confidential Information from any location outside the United States. This restriction includes access by foreign affiliates, foreign parent companies, foreign subsidiaries, offshore IT support personnel, overseas engineering teams, overseas quotation teams, overseas procurement personnel, foreign cloud administrators, foreign data centers, and foreign subcontractors. For example, the Receiving Party may not send an ACD drawing to an overseas machine shop for quoting, upload ACD technical data to a foreign-hosted collaboration platform, allow offshore IT personnel to administer a folder containing ACD drawings, or permit a foreign-person employee to view controlled technical data during a screen-sharing session unless required written authorization and export-control approvals are in place.
14.8 Before disclosing Confidential Information to any out-of-state or foreign supplier, subcontractor, consultant, laboratory, special processor, broker, freight forwarder, affiliate, or service provider, the Receiving Party shall ensure that the third party is bound by written obligations no less protective than this Agreement. The Receiving Party remains fully responsible for any breach, misuse, unauthorized export, unauthorized re-export, unauthorized foreign-person access, or unauthorized disclosure by such third party.
14.9 If the Receiving Party believes that the law of any jurisdiction outside Massachusetts or outside the United States conflicts with this Agreement, prevents compliance with this Agreement, requires disclosure of Confidential Information, restricts return or destruction of Confidential Information, requires local retention of Confidential Information, requires access by a governmental authority, or otherwise affects protection of Confidential Information, the Receiving Party shall promptly notify the Disclosing Party in writing before taking action, unless legally prohibited from doing so. The Parties shall cooperate in good faith to implement lawful protective measures such as redaction, encryption, restricted access, local-counsel review, protective order, confidential-treatment request, export license, amended handling instruction, or termination of the affected disclosure.
14.10 If Project-related parts, samples, tooling, inspection equipment, prototypes, failed parts, test articles, documents, or electronic media are shipped across state or national borders, the Receiving Party shall comply with all applicable import, export, customs, sanctions, tariff, country-of-origin, marking, packaging, recordkeeping, and shipping-document requirements. The Receiving Party shall not identify ACD as manufacturer, importer, exporter, regulatory approval holder, PMA holder, design authority, source approver, or responsible party in any customs, regulatory, shipping, or customer document unless expressly authorized in writing by ACD.
14.11 The Receiving Party acknowledges that unauthorized use or disclosure of Confidential Information outside Massachusetts or outside the United States may cause harm that is difficult or impossible to remedy solely through monetary damages. The Disclosing Party may seek injunctive relief, specific performance, protective orders, preservation orders, seizure where legally available, or other equitable relief in Massachusetts or in any jurisdiction where Confidential Information is located, where unauthorized disclosure occurred, where the Receiving Party or its Representatives are located, where a supplier is located, or where relief is necessary to prevent imminent harm.
17. No Warranty; No Obligation to Proceed
17.1 All Confidential Information is provided ‘as is’ without representation or warranty, express or implied, as to accuracy, completeness, merchantability, fitness for a particular purpose, noninfringement, regulatory sufficiency, or suitability for any use. The Receiving Party is responsible for its own engineering, quality, regulatory, export-control, and business evaluation of any information it receives.
17.2 Nothing in this Agreement obligates either Party to proceed with any transaction, purchase, sale, project, certification effort, supplier relationship, teaming arrangement, or other business activity. Any such obligation must be set forth in a separate written agreement, purchase order, statement of work, quality agreement, or other executed document.
17.3 An NDA opens discussion; it does not approve a supplier, certify a part, validate a drawing, authorize production, or guarantee a purchase order. In aerospace, operational teams should not treat receipt of data as permission to manufacture or release product without the separate approvals required by contract, quality system, and regulation.
18. Ownership and Intellectual Property
18.1 Each Disclosing Party retains all right, title, and interest in and to its Confidential Information, Trade Secrets, inventions, patents, copyrights, mask works, software, know-how, designs, processes, technical data, regulatory data, business information, and other intellectual property. No disclosure under this Agreement grants any license, covenant not to sue, ownership interest, shop right, manufacturing right, repair right, source approval, distribution right, or other right, whether by implication, estoppel, exhaustion, or otherwise.
18.2 The Receiving Party shall not file any patent, copyright, mask work, PMA, STC, TSO, source approval, supplier approval, or other application or registration based on or derived from the Disclosing Party’s Confidential Information without the Disclosing Party’s prior written consent.
18.3 If the Parties jointly develop intellectual property, inventions, data, or work product, ownership and use rights shall be governed by a separate written agreement. Absent such agreement, this NDA does not transfer pre-existing intellectual property or authorize either Party to commercialize the other Party’s confidential contributions.
25. Dispute Resolution, Governing Law, Venue, and Cross-Border Relief
25.1 Before filing suit, the Parties shall attempt in good faith to resolve disputes through executive-level discussions, except that either Party may immediately seek injunctive, equitable, protective, or emergency relief to prevent or remedy threatened or actual unauthorized use, disclosure, export, re-export, foreign-person access, loss, destruction, or misuse of Confidential Information.
25.2 This Agreement shall be governed by and construed in accordance with the laws of the Commonwealth of Massachusetts and applicable federal law, without regard to conflicts-of-law principles. The Parties select Massachusetts law because ACD resides in Massachusetts, ACD’s Confidential Information is being disclosed from or on behalf of a Massachusetts business, and the Parties desire a predictable contractual standard for confidentiality, trade-secret protection, remedies, and interpretation. Applicable federal law, including aviation-safety law, FAA requirements, export-control law, sanctions law, and federal trade-secret law, may independently apply regardless of the governing law selected for this Agreement.
25.3 Nothing in this Agreement shall be interpreted to require either Party to violate mandatory law applicable in the jurisdiction where work is performed, where a part is manufactured, where a supplier is located, where data is stored, where an individual accesses information, or where a governmental authority has lawful jurisdiction. If mandatory local law applies, the Receiving Party shall comply with that law while preserving the confidentiality, limited-use, proprietary-rights, export-control, cybersecurity, supplier-flow-down, and incident-reporting obligations of this Agreement to the maximum extent legally permitted.
25.4 Subject to Section 25.5, the state and federal courts located in Massachusetts shall have exclusive jurisdiction and venue over disputes arising out of or relating to this Agreement, and each Party consents to such jurisdiction and venue. Each Party waives objections based on inconvenient forum, lack of personal jurisdiction, or improper venue to the maximum extent permitted by law.
25.5 Notwithstanding Section 25.4, the Disclosing Party may seek temporary, preliminary, emergency, injunctive, protective, preservation, or equitable relief in any court or tribunal of competent jurisdiction where Confidential Information is located, where unauthorized disclosure occurred or is threatened, where a supplier or foreign recipient is located, where evidence is located, where assets are located, or where relief is necessary to prevent imminent or irreparable harm. Seeking such relief outside Massachusetts shall not be deemed a waiver of Massachusetts governing law, Massachusetts venue for non-emergency proceedings, or any other right under this Agreement.
25.6 If the Counterparty is organized outside the United States or does not maintain a regular place of business in the United States, the Counterparty shall, upon ACD’s request, identify a U.S. agent for service of process or otherwise agree to a commercially reasonable method of service permitted by applicable law. The Counterparty shall ensure that its foreign affiliates, suppliers, subcontractors, and Representatives who receive Confidential Information are contractually bound to cooperate with preservation, return, destruction, audit, and injunctive-relief obligations.
25.7 Nothing in this Agreement limits either Party’s obligation to comply with lawful requirements of the FAA, NTSB, DOT, DoD, BIS, DDTC, OFAC, customs authorities, courts, law-enforcement agencies, aviation authorities, or other governmental authorities having jurisdiction. When legally permitted, the Party receiving such request shall provide prompt notice to the other Party, seek confidential treatment, and limit disclosure to the minimum information legally required.