Data Processing Agreement (DPA)

Last updated: Pending legal configuration

This is a structural legal template. Professional legal review is required before commercial launch. Jurisdiction-specific details, legal entity information, and registered addresses must be confirmed by qualified counsel.

This Data Processing Agreement forms part of the Terms of Service and applies where Y Marine OS processes personal data on behalf of an Organization.

1. Controller and Processor Roles

The Organization is the data controller. Y Marine OS is the data processor. We process personal data only on the documented instructions of the Organization.

2. Processing Instructions

We process personal data for the purpose of providing the Y Marine OS Platform, including yacht management, technical operations, maintenance, charter operations, and intelligence features. The Organization instructs us by configuring roles, assignments, and entitlements within the Platform.

3. Confidentiality

Our personnel and subprocessors are bound by confidentiality obligations. Access to personal data is limited to authorized personnel with a need-to-know basis.

4. Security Measures

We implement technical and organizational measures including: role-based access control, tenant isolation, audit logging, signed integrations, domain separation, and temporary support access controls. See our Security page for details.

5. Subprocessors

We engage subprocessors to provide the Platform. A current list is maintained in our Subprocessors page. We provide notice of changes to subprocessor lists.

6. International Transfers

Pending legal configuration: Transfer mechanisms (e.g., Standard Contractual Clauses) must be confirmed by qualified counsel.

7. Data Subject Requests

We assist the Organization with data subject requests where technically and legally possible. The Organization is responsible for responding to data subject requests within applicable legal timeframes.

8. Incident Notification

We will notify the Organization of a personal data breach without undue delay after becoming aware of it, providing sufficient information for the Organization to meet its own notification obligations.

9. Deletion and Return

Upon termination, we will delete or return personal data at the Organization's choice, subject to legal retention obligations. See our Data Retention and Data Deletion policies.

10. Audit Cooperation

We will cooperate with reasonable audits conducted by the Organization or an independent auditor, subject to confidentiality and security requirements.

11. Processing Schedule (Annex)

Pending legal configuration: The following annexes must be completed before commercial launch:

  • Annex A — Processing Categories: Categories of personal data processed.
  • Annex B — Data Subjects: Categories of data subjects (crew, guests, users, contractors).
  • Annex C — Purposes: Detailed processing purposes per category.
  • Annex D — Retention: Retention periods per data category.
  • Annex E — Subprocessors: Current subprocessor list with functions and locations.
  • Annex F — Technical and Organizational Measures: Detailed security measures.

12. Contact

Pending legal configuration: DPA contact information must be confirmed before commercial launch.