Subprocessors
Last updated: EFFECTIVE_DATE
This page lists the third-party subprocessors that Mareel Waters uses to provide its services. It exists to satisfy our transparency obligations under Article 28(2) and 28(4) of the General Data Protection Regulation (GDPR) and to support the general written authorisation of subprocessors recorded in our Data Processing Agreement (DPA).
A Subprocessor is a third-party Processor engaged by us (the operator of Mareel Waters) to process Personal Data on behalf of a Customer who is acting as a Controller. We engage a small number of subprocessors to operate the payment, transactional email, and edge-delivery functions of the service. The core service itself is Self-hosted on our own server, so the list below is deliberately short.
This page should be read together with our Privacy Policy and our DPA:
- The Privacy Policy describes what Personal Data we process, why, and on what legal basis, including for our own purposes as a Controller (for example, account administration and first-party analytics).
- The DPA governs our processing of Personal Data on behalf of Customers who use the API to process Personal Data and who are themselves Controllers or Processors. The DPA contains the contractual terms that bind us as a Processor, including the general written authorisation that permits us to engage the subprocessors named here.
Where there is any conflict between this page and the DPA on the subject of subprocessing, the DPA prevails as between us and a Customer who has entered into it.
What this list covers
In normal operation, API requests sent to the Mareel Waters API contain coordinates and times and do not contain Personal Data. The subprocessors below are therefore relevant primarily to:
- Account and billing data (for example, your account email and the payment details you provide directly to our payment processor); and
- Edge delivery of all traffic to and from the service, which necessarily transits our content-delivery and security edge.
Outputs of the API consist of modelled tide and forecast values and are not Personal Data.
Current subprocessors
The following subprocessors are engaged as of the date at the top of this page.
Stripe
- Name: Stripe (the Stripe group of entities, including its US and Irish/EU operating entities).
- Service: Payment processing and subscription billing.
- Processing activity: Processes payment and subscription data when you purchase or manage a paid Plan. This includes the payment card or other payment instrument details that you enter directly with Stripe, your billing identifiers, and transaction records. We do not store card numbers or the primary account number (PAN); these are collected and held by Stripe, not by us. We receive only limited billing metadata needed to operate your subscription (for example, subscription status and the billing email associated with your Account).
- Region: United States and Ireland / European Union.
- Transfer safeguard: For any transfer of Personal Data outside the European Economic Area, Standard Contractual Clauses (SCCs) apply, together with the EU-US Data Privacy Framework (DPF) where and to the extent Stripe is certified under it.
Resend
- Name: Resend.
- Service: Transactional email delivery.
- Processing activity: Sends operational and transactional emails relating to your Account, such as email verification, password resets, security notifications, and billing-related notices. For this purpose, Resend processes the recipient email address and the contents of the message. Tokens we send by email (for example, verification or reset links) are stored by us in hashed form. We do not use Resend for marketing email broadcasts.
- Region: United States.
- Transfer safeguard: Standard Contractual Clauses (SCCs), together with the EU-US Data Privacy Framework (DPF) where and to the extent Resend is certified under it.
Cloudflare
- Name: Cloudflare.
- Service: Content delivery network (CDN), edge network, web application firewall (WAF), bot management, and secure tunnel.
- Processing activity: Acts as the public Edge for the service. All traffic to and from Mareel Waters passes through Cloudflare, which provides caching and content delivery, TLS termination at the edge, firewall and bot-management protection, and a secure tunnel back to our self-hosted origin server. In performing these functions, Cloudflare processes connection metadata such as IP addresses and request headers for routing, security, and abuse-prevention purposes. Cloudflare is our edge and security layer only; it does not host the application or its database.
- Region: Global (Cloudflare operates a worldwide edge network).
- Transfer safeguard: Standard Contractual Clauses (SCCs), together with the EU-US Data Privacy Framework (DPF) where and to the extent Cloudflare is certified under it.
Self-hosting and no third-party analytics
The core Mareel Waters service is Self-hosted. We run the web application, the developer portal, the admin interface, the API, and the database on our own server. We do not use a third-party cloud hosting Processor for the application itself. Cloudflare provides only the public Edge (CDN, WAF, bot management, and tunnel) in front of that self-hosted origin.
We do not use Google Analytics or any other third-party analytics Processor. Our first-party web and marketing analytics are cookieless and run on our own infrastructure: they use a sessionStorage visitor identifier, a daily-salted hash of the visitor IP address (we do not store raw IP addresses), and a derived user-agent family for bot tagging. Because we operate this analytics ourselves, no additional analytics subprocessor is engaged.
For completeness, our API Usage Events (which record the Endpoint, HTTP status, timestamp, request latitude and longitude, and cost) do not contain IP addresses or user-agent data, and they are processed on our self-hosted infrastructure rather than by any subprocessor.
Changes to this list and how to object
We may add, replace, or remove subprocessors as the service evolves. The general written authorisation in our DPA permits us to engage subprocessors of the kind listed above, subject to the notice and objection rights described here.
How we notify you of changes. We maintain this page as the authoritative, current list of subprocessors. Before we add a new subprocessor or replace an existing one in a way that affects the processing of Personal Data on behalf of Customers, we will provide advance notice. Notice is given by updating this page (including the "Last updated" date at the top) Notice is given by updating this page (including the "Last updated" date). Where you have asked us in writing to notify you of subprocessor changes, we will use reasonable efforts to email you at the address associated with your Account; this is a best-effort courtesy and the authoritative notice is the update to this page.
Your right to object. If you are a Customer bound by our DPA and you have a reasonable, good-faith objection to a new or replacement subprocessor on data-protection grounds, you may object by notifying us in writing at [email protected] within the objection period stated in the DPA. We will work with you in good faith to address the objection, which may include explaining the safeguards in place or, where a reasonable alternative is available, making such an alternative available to you. Where we cannot reasonably resolve a legitimate objection, the resolution mechanism (including any right of termination) is governed by the DPA.
This notice and objection process operates within, and is subject to, the terms of the DPA. Nothing on this page replaces or limits the contractual rights and obligations set out there.
Related pages
Contact
For questions about this list or any subprocessor, contact us at [email protected]. For contractual or objection matters under the DPA, contact [email protected]. Our data-protection point of contact is [email protected].
Mareel Waters is operated by LEGAL_ENTITY, REGISTERED_ADDRESS (organisation number ORG_NUMBER, VAT number VAT_NUMBER).
---
This page provides general information and is not legal advice. It should be read together with our Privacy Policy and DPA, which govern in the event of any conflict.
Last updated: EFFECTIVE_DATE