Data Processing Agreement
Last updated: August 2026
Status of this document
Stated plainly: this is a first, in-house draft written to describe actual processing accurately, not yet reviewed by a lawyer. Where a limitation in the current implementation exists (see Section 8 in particular), it is stated here rather than promised away.
1. Parties and roles
This Data Processing Agreement ("DPA") forms part of the Terms of Service between [Legal Entity Name] ("Processor", "we") and the Customer ("Controller"). For personal data the Customer submits to the Service, the Customer is the controller and we are the processor, processing personal data only on the Customer's documented instructions (given by using the Service's features as designed).
2. Subject matter, duration, and nature of processing
Subject matter: provision of the RegNavigo Service. Duration: for as long as the Customer's account is active, plus any post-termination period described in Section 8. Nature and purpose: hosting, storage, retrieval, and AI-assisted analysis of Customer Data as described in the Terms of Service and the Service itself.
3. Categories of data subjects and personal data
Data subjects: the Customer's platform users (and, incidentally, any individual named in free text a user submits — e.g., in a chat question, task, or support ticket). Categories of personal data: account data (name, email), vessel-to-user assignments, free-text content submitted to chat/tasks/tickets, and vessel registry fields that may incidentally name an organization or individual (owner/PI-club fields). See Annex 1 below for the full breakdown by system.
4. Processor obligations
- Process personal data only on the Controller's documented instructions.
- Ensure personnel with access are bound by confidentiality obligations.
- Implement the security measures described in Annex 3.
- Engage sub-processors only as permitted under Section 5.
- Assist the Controller in responding to data subject requests, per docs/compliance/data-subject-request-procedure.md in our repository.
- Assist the Controller with breach notification, per docs/compliance/breach-response-policy.md.
- Make available the information necessary to demonstrate compliance with this DPA.
5. Sub-processors
The Controller generally authorizes the engagement of the sub-processors listed in Annex 2 below. We will notify the Customer of any intended change adding or replacing a sub-processor, giving the Customer a reasonable opportunity to object on reasonable grounds before the change takes effect.
6. International transfers
Where a sub-processor processes personal data outside the EEA, an appropriate transfer mechanism (such as Standard Contractual Clauses, or reliance on an adequacy decision) applies. Current status: the specific region(s) in use depend on how this product is deployed (see docs/compliance/gdpr-legal-documents-plan.md, "Data residency"), and a full, per-vendor International Transfer Assessment has not yet been completed — see docs/compliance/international-transfer-assessment.md for its current, partial status. Do not treat this section as a completed transfer-mechanism confirmation.
7. Security measures
Described in full in Annex 3 below (tenant isolation, access control, authentication, encryption, audit logging). Notably, two known gaps are disclosed rather than hidden: two configuration secrets are stored in plaintext (mitigated by database-level encryption at rest, not field-level encryption), and no backup/disaster- recovery policy is currently documented for this deployment.
8. Deletion or return of data on termination — current limitations
This section states what actually happens today, not an aspirational commitment.
- Chat history is retained indefinitely as an audit trail and is not automatically deleted on termination.
- Deleting an uploaded document removes its database record but does not remove the underlying file from storage.
- User account "deletion" is a soft-delete (email address anonymized; name/history retained), not full erasure.
- No function currently exists to fully delete a Customer's entire account and data on termination. Until one is built, full data return/deletion at contract end is handled as a manual, individually-arranged operation, not an automated guarantee.
We are treating closing this gap as a priority — see docs/compliance/data-retention-deletion-policy.md — but a Customer relying on prompt post-termination erasure should confirm the current status with us directly rather than assuming this section describes a finished capability.
9. Audits
On reasonable notice, we will make available the information necessary to demonstrate compliance with this DPA, and will permit and contribute to audits conducted by the Controller or an auditor mandated by the Controller, subject to reasonable confidentiality and scheduling terms.
10. Liability and governing law
Liability under this DPA is governed by the limitation of liability terms in the Terms of Service. This DPA is governed by the laws of Cyprus.
Annex 1 — Categories of processing
See docs/compliance/ropa.md in our repository for the full table (processing activity, personal data, data subject, purpose, retention, recipient) built directly from the product's data model.
Annex 2 — Sub-processors
- Anthropic — chat answer generation (Messages API).
- Voyage AI (part of MongoDB, Inc.) — embeddings for semantic search.
- VesselAPI — vessel particulars/AIS position lookup (vessel identifiers only).
- Email relay (deployment-configured) — transactional email delivery.
- Vercel Blob and/or AWS S3 (deployment-dependent) — file storage.
- Vercel and/or AWS (deployment-dependent) — application and database hosting.
Full detail per provider (data received, location) is in docs/compliance/subprocessor-list.md and on /privacy.
Annex 3 — Technical and organisational measures
See docs/compliance/technical-organisational-measures.md in our repository for the full description of tenant isolation, access control, authentication, encryption, audit logging, and the disclosed gaps (plaintext secrets mitigated by encryption at rest; no documented backup policy).
See also the Customer Agreement, Terms of Service, and Privacy & third-party AI processing — or see all legal documents.