Data Processing Agreement (DPA)
Last updated: Pending legal configuration
This is a structural legal template. Professional legal review is required before commercial launch. Jurisdiction-specific details, legal entity information, and registered addresses must be confirmed by qualified counsel.
This Data Processing Agreement forms part of the Terms of Service and applies where Y Marine OS processes personal data on behalf of an Organization.
1. Controller and Processor Roles
The Organization is the data controller. Y Marine OS is the data processor. We process personal data only on the documented instructions of the Organization.
2. Processing Instructions
We process personal data for the purpose of providing the Y Marine OS Platform, including yacht management, technical operations, maintenance, charter operations, and intelligence features. The Organization instructs us by configuring roles, assignments, and entitlements within the Platform.
3. Confidentiality
Our personnel and subprocessors are bound by confidentiality obligations. Access to personal data is limited to authorized personnel with a need-to-know basis.
4. Security Measures
We implement technical and organizational measures including: role-based access control, tenant isolation, audit logging, signed integrations, domain separation, and temporary support access controls. See our Security page for details.
5. Subprocessors
We engage subprocessors to provide the Platform. A current list is maintained in our Subprocessors page. We provide notice of changes to subprocessor lists.
6. International Transfers
Pending legal configuration: Transfer mechanisms (e.g., Standard Contractual Clauses) must be confirmed by qualified counsel.
7. Data Subject Requests
We assist the Organization with data subject requests where technically and legally possible. The Organization is responsible for responding to data subject requests within applicable legal timeframes.
8. Incident Notification
We will notify the Organization of a personal data breach without undue delay after becoming aware of it, providing sufficient information for the Organization to meet its own notification obligations.
9. Deletion and Return
Upon termination, we will delete or return personal data at the Organization's choice, subject to legal retention obligations. See our Data Retention and Data Deletion policies.
10. Audit Cooperation
We will cooperate with reasonable audits conducted by the Organization or an independent auditor, subject to confidentiality and security requirements.
11. Processing Schedule (Annex)
Pending legal configuration: The following annexes must be completed before commercial launch:
- Annex A — Processing Categories: Categories of personal data processed.
- Annex B — Data Subjects: Categories of data subjects (crew, guests, users, contractors).
- Annex C — Purposes: Detailed processing purposes per category.
- Annex D — Retention: Retention periods per data category.
- Annex E — Subprocessors: Current subprocessor list with functions and locations.
- Annex F — Technical and Organizational Measures: Detailed security measures.
12. Contact
Pending legal configuration: DPA contact information must be confirmed before commercial launch.