Data Processing Agreement (DPA)
Last updated: EFFECTIVE_DATE
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the agreement between you ("Customer", "you") and LEGAL_ENTITY ("Mareel Waters", "we", "us"), comprising our Terms of Service and any order or subscription you place through your Account (together, the "Agreement"). This DPA records the terms on which we process Personal Data on your behalf and supplements the privacy commitments set out in our Privacy Policy.
Defined terms used but not defined here have the meaning given in the Agreement. "GDPR" means Regulation (EU) 2016/679. "Controller", "Processor", "Subprocessor", "Personal Data", "Data Subject", "processing" and "supervisory authority" have the meanings given in the GDPR.
This is general information and not legal advice. Where Customer transmits Personal Data through the API, you remain responsible for assessing whether this DPA meets your own legal and contractual requirements.
1. Roles and when this DPA applies
We act in two distinct roles, and it is important to keep them separate.
Mareel Waters as Controller. We are the Controller for the Personal Data we collect and use to operate the service, establish and bill your Account, and secure the API. This includes your Account email, your hashed password, your hashed API Keys, your Plan and subscription status, Usage Events (Endpoint, HTTP status, timestamp, request latitude and longitude and computed cost, with no IP address and no user-agent stored), and our cookieless first-party web and marketing analytics (a sessionStorage visitor identifier, a daily-salted hash of IP, and a derived user-agent family, with no raw IP or raw user-agent retained). Our processing of this data in our role as Controller is governed by our Privacy Policy, not by this DPA. This DPA does not apply to that data.
Ordinary API calls are generally not Personal Data. A standard request to the API consists of coordinates (latitude and longitude) and times, and the Output consists of modelled tide values (and, when the forecast/water-state API is live, modelled marine forecast values). Coordinates and times sent to the API are generally not Personal Data, so processing on the Customer's behalf typically does not arise and a data processing agreement is typically not required for ordinary use of the API.
Mareel Waters as Processor. Where you choose to transmit Personal Data through the API, or otherwise route Personal Data to us within the Output you request (for example, by associating coordinates with an identified or identifiable Data Subject and submitting that combination through your account), you act as the Controller (or as a Processor for your own customer) and we act as your Processor in respect of that Customer-supplied Personal Data only ("Customer Personal Data"). This DPA applies to, and only to, our processing of Customer Personal Data in that Processor role.
You are responsible for ensuring you have a lawful basis to transmit any Customer Personal Data to us and for the lawfulness of the instructions you give. You must not send special categories of Personal Data, or data relating to criminal convictions and offences, through the API unless we have agreed this in writing in advance.
2. Subject-matter, duration, nature and purpose (Art. 28(3) chapeau)
This section describes our processing of Customer Personal Data as required by Article 28(3) GDPR.
- Subject-matter. Processing of Customer Personal Data transmitted by you through the API in order to provide the API, generate and return the Output, and operate, secure and support the service in accordance with the Agreement.
- Duration. For the term of the Agreement, plus the limited retention and deletion periods described in section 9. Usage Events are retained for our standard operational and billing period as set out in our Privacy Policy.
- Nature of the processing. Receiving requests at the Edge (Cloudflare) and at our self-hosted servers, computing the requested Output, logging Usage Events, transmitting the Output back to you over TLS, and the related storage, hosting, security and support operations necessary to deliver the service.
- Purpose of the processing. To provide the contracted API and Output to you, to meter Usage against your Plan, to secure the service, and to provide support, in each case on your instructions and in accordance with the Agreement.
- Types of Personal Data. Only such Personal Data as you choose to include in your API requests. By design the API requires coordinates and times, which are generally not Personal Data; any further Personal Data within Customer Personal Data is determined and controlled by you. You must minimise the Personal Data you transmit.
- Categories of Data Subjects. Determined and controlled by you, being any individuals whose Personal Data you elect to transmit through the API.
3. Processing only on documented instructions (Art. 28(3)(a))
We will process Customer Personal Data only on your documented instructions, including with regard to transfers of Customer Personal Data to a third country or an international organisation, unless required to do so by Union or Member State law to which we are subject. Where such a legal requirement applies, we will inform you of that legal requirement before processing, unless that law prohibits informing you on important grounds of public interest.
Your documented instructions are: (a) this DPA; (b) the Agreement, including the Documentation; and (c) your configuration and use of the API and your Account, including the contents of the requests you submit. Any additional instructions must be agreed in writing and may be subject to a reasonable adjustment to fees if they require work outside the scope of the Agreement.
We will not sell Customer Personal Data and will not process it for our own purposes, for profiling, or for advertising. We do not use Customer Personal Data to train models.
4. Confidentiality of authorised persons (Art. 28(3)(b))
We will ensure that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. We will limit access to Customer Personal Data to personnel who need access to perform the Agreement, and we will ensure those persons are informed of the confidential nature of the data and are bound by confidentiality obligations that survive the end of their engagement.
5. Security measures (Arts. 28(3)(c) and 32)
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to Data Subjects, we implement reasonable technical and organisational measures to ensure a level of security appropriate to the risk. These measures include, as applicable to the data concerned:
- Passwords stored using bcrypt hashing; we do not store Account passwords in plaintext.
- API Keys stored as SHA-256 hashes; we do not store the plaintext key after issuance.
- Emailed tokens stored in hashed form.
- Encryption of data in transit using TLS.
- No card or primary account number (PAN) data stored by us; card payments are handled by our payment Subprocessor (see section 6 and the Subprocessors page).
- For our cookieless web and marketing analytics only, IP addresses are reduced to a daily-salted hash and user-agent strings are reduced to a derived family; Usage Events store neither IP nor user-agent.
- Access controls limiting access to Personal Data to authorised personnel, and use of Cloudflare at the Edge for CDN, WAF and bot-management protections.
We make no representation that these measures constitute, and we do not claim, any specific certification or formal attestation (for example SOC 2, ISO 27001 or PCI DSS), encryption-at-rest specifics, or any uptime or availability guarantee, except as may be expressly stated in writing in the Agreement. We may update our security measures from time to time provided that the updated measures do not materially reduce the overall level of security.
6. Subprocessors (Art. 28(3)(d))
General authorisation. You give us a general written authorisation to engage Subprocessors to process Customer Personal Data, subject to this section. Our current Subprocessors are listed on our Subprocessors page, which currently includes Stripe (payments), Resend (transactional email), and Cloudflare (CDN, edge, WAF, bot-management and tunnel). Hosting is self-hosted on our own server, with Cloudflare acting as the public edge. We do not use Google Analytics or any third-party analytics processor.
Flow-down of obligations. Where we engage a Subprocessor to carry out processing activities on your behalf, we will do so by way of a written contract that imposes on the Subprocessor data protection obligations that are, in substance, equivalent to those set out in this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures so that the processing meets the requirements of the GDPR. Where a Subprocessor fails to fulfil its data protection obligations, we remain fully liable to you for the performance of that Subprocessor's obligations.
Notice of changes and right to object. We will give you reasonable prior notice of any intended addition or replacement of a Subprocessor that processes Customer Personal Data, for example by updating the Subprocessors page and, where you have subscribed to a notification mechanism, by notifying you through it. You may object on reasonable data-protection grounds within the notice period. If you object, we will work with you in good faith to address the objection. If we cannot reasonably resolve it, you may terminate the affected part of the service in accordance with the Agreement as your sole remedy.
7. Assistance with Data Subject rights (Art. 28(3)(e))
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests from Data Subjects exercising their rights under Chapter III of the GDPR (including access, rectification, erasure, restriction, data portability, and objection).
Because we hold Customer Personal Data only as transmitted by you and largely within the requests and Output you control, you are generally best placed to identify and act on the relevant data. If we receive a request from a Data Subject that relates to Customer Personal Data, we will not respond directly except on your documented instructions or as required by law, and we will promptly inform you of the request. Where reasonable assistance requires significant effort beyond providing the relevant access and tooling, we may charge a reasonable fee.
8. Assistance with breach, DPIA and prior consultation (Arts. 33-36 and 28(3)(f))
Taking into account the nature of the processing and the information available to us, we will assist you in ensuring compliance with your obligations under Articles 32 to 36 GDPR, namely:
- Personal data breach (Arts. 33-34). We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide you with the information reasonably available to us to enable you to meet your own notification obligations to a supervisory authority and, where applicable, to Data Subjects. Our notification is not an acknowledgement of fault or liability.
- Data protection impact assessment (Art. 35). We will provide reasonable assistance and the information reasonably available to us to support any DPIA you are required to carry out in respect of processing of Customer Personal Data through the service.
- Prior consultation (Art. 36). We will provide reasonable assistance in connection with any prior consultation you are required to undertake with a supervisory authority.
You should report any suspected security concern to us at [email protected], and we will route breach-related matters to [email protected] and [email protected].
9. Deletion or return of Personal Data (Art. 28(3)(g))
At your choice, we will delete or return all Customer Personal Data to you after the end of the provision of services relating to processing, and delete existing copies, unless Union or Member State law requires storage of the Personal Data.
In practice, because Customer Personal Data is largely contained within the requests and Output you control, much of it is transient. On termination or expiry of the Agreement, and on your written request, we will delete or return Customer Personal Data within a reasonable period, save that we may retain Personal Data to the extent and for as long as required by applicable law, in which case we will continue to protect it under this DPA and process it only as necessary for the retention purpose. Standard retention periods for Usage Events and other operational data we hold as Controller are described in our Privacy Policy.
10. Audit, demonstration of compliance, and infringing instructions (Art. 28(3)(h))
Demonstration and audit. We will make available to you the information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by you or another auditor mandated by you. To the extent permitted by Article 28, we may satisfy an audit request by providing relevant documentation and written responses. Any on-site audit must be conducted on reasonable prior written notice, no more than once in any twelve-month period (save where required by a supervisory authority or following a personal data breach), during business hours, subject to confidentiality undertakings, and in a manner that does not unreasonably disrupt our operations or compromise the security or confidentiality of other customers' data. You will bear your own costs and any reasonable costs we incur in supporting an audit beyond providing standard documentation.
Duty to flag infringing instructions. We will immediately inform you if, in our opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions. We may suspend performance of the affected instruction until it is confirmed, amended or withdrawn, without being in breach of the Agreement.
11. International transfers and Standard Contractual Clauses
We process and host Customer Personal Data primarily within the EU on our self-hosted infrastructure, with Cloudflare acting as the edge. Some of our Subprocessors may process Personal Data outside the European Economic Area.
Where our processing of Customer Personal Data on your behalf involves a transfer of Personal Data to a country outside the EEA that is not the subject of an adequacy decision, the parties agree that the European Commission's Standard Contractual Clauses (SCCs) for the transfer of personal data to third countries (Commission Implementing Decision (EU) 2021/914) are incorporated into this DPA by reference and apply to that transfer, with:
- Module Two (Controller to Processor) applying where you act as Controller and we act as Processor; and
- Module Three (Processor to Processor) applying where you act as Processor and we act as your Subprocessor.
For the purposes of the SCCs: the data exporter is the Customer; the data importer is LEGAL_ENTITY; the optional docking clause does not apply unless agreed; in Clause 9 the general written authorisation option applies, consistent with section 6; in Clause 11 the optional independent dispute resolution body does not apply unless agreed; in Clause 17 the governing law is the law of Sweden; in Clause 18 the competent courts are the courts of the courts of Sweden, with Stockholm District Court (Stockholms tingsratt) as court of first instance; the supervisory authority is that of the courts of Sweden, with Stockholm District Court (Stockholms tingsratt) as court of first instance or as otherwise determined under the SCCs. Annex I (parties, description of transfer and competent supervisory authority) is populated by sections 1, 2 and this section 11; Annex II (technical and organisational measures) is populated by section 5; and Annex III (subprocessors) is populated by our Subprocessors page. Where the United Kingdom GDPR applies, the UK International Data Transfer Addendum to the SCCs is incorporated and applies to the relevant transfer.
Transfer impact assessment and onward transfers. In connection with any such transfer, the parties will, where required, carry out a transfer impact assessment to evaluate whether the laws and practices of the destination country provide an essentially equivalent level of protection and whether supplementary measures are needed. We will provide the information reasonably available to us to support your assessment. Any onward transfer by us or a Subprocessor will be made only in accordance with the SCCs and subject to equivalent safeguards. If the SCCs are amended, replaced or invalidated, the parties will work in good faith to implement a valid transfer mechanism.
12. General
This DPA applies for as long as we process Customer Personal Data on your behalf. In the event of a conflict between this DPA and the rest of the Agreement on the subject of the processing of Customer Personal Data, this DPA prevails; in the event of a conflict between this DPA and the incorporated SCCs, the SCCs prevail to the extent of the conflict. Except as modified by this DPA, the Agreement remains in full force and effect, including its provisions on limitation of liability, which apply to this DPA and to the SCCs to the extent permitted by law. This DPA is governed by Sweden and the courts of the courts of Sweden, with Stockholm District Court (Stockholms tingsratt) as court of first instance have jurisdiction, save where the SCCs require otherwise.
13. Executing or requesting a signed copy, and contact
This DPA is incorporated into the Agreement and applies automatically, without signature, when you transmit Customer Personal Data through the API while the Agreement is in force. If your organisation requires a separately signed copy, or a copy of the incorporated SCCs with the Annexes completed, contact us at [email protected] and we will provide one for execution. Please include your Account email, your legal entity details, and the role split that applies to your use.
For any question about this DPA, our role as Controller or Processor, Subprocessors, international transfers, or Data Subject requests, contact us at [email protected] (privacy matters: [email protected]; data protection contact: [email protected]).
Related pages
This is general information and not legal advice.
Last updated: EFFECTIVE_DATE