Data Processing Addendum

Version 1.0 · September 5, 2026

This Addendum forms part of the Terms of Service between ArcNautical (the Processor) and the customer entity accepting those Terms (the Controller). It applies whenever ArcNautical processes personal data on the Controller's behalf and to which the GDPR, the UK GDPR, or the Swiss FADP applies.

This is our standard form, not an ultimatum. If your organisation requires its own data processing agreement, send it and we will review and sign, provided the technical facts in Annexes I to III are carried across accurately. What we cannot do is sign a document that misdescribes where the data actually sits.

1. Definitions and roles

Controller, Processor, Personal Data, Processing, Data Subject, Sub-processor and Personal Data Breach have the meanings given in the GDPR. Applicable Data Protection Law means Regulation (EU) 2016/679, the UK GDPR and Data Protection Act 2018, the Swiss FADP, and India's Digital Personal Data Protection Act 2023, each as applicable.

1.1 Two distinct roles, stated plainly

ArcNautical acts in two different capacities, and conflating them would misdescribe what actually happens. A data protection officer reviewing this will ask, so it is set out up front:

  1. As Processor — for everything the Controller gives us or generates in the platform: account and user records, the vessel and fleet lists the Controller submits, cargo and voyage details, customer references, API usage and audit logs. We process these only on the Controller's instructions. This is the subject of this Addendum.
  2. As independent Controller — for the reference corpus we compile from public and official sources in order to operate the screening engine: sanctions designations, corporate registry and beneficial-ownership records, port state control inspection results, and casualty and detention data. Some of those records name individuals, so they are personal data. We determine the sources, the methodology and the retention for that corpus; the Controller does not instruct us on it, and we could not accept an instruction to alter a sanctions record. Our lawful basis is legitimate interests under Article 6(1)(f) — the prevention of sanctions evasion and financial crime — and, where relevant, the substantial public interest basis in Article 9(2)(g) read with the Member State law implementing restrictive measures.

The Controller is not responsible for our processing under role 2, and we are not the Controller of anything under role 1.

2. Scope and instructions

ArcNautical processes Personal Data only on the Controller's documented instructions, including as to international transfers, unless required otherwise by Union or Member State law — in which case we inform the Controller before processing, unless that law forbids it on important grounds of public interest.

The Terms of Service, this Addendum, and the Controller's use of the platform and API constitute the Controller's complete documented instructions. We will tell the Controller if, in our opinion, an instruction infringes Applicable Data Protection Law.

We do not sell Personal Data, do not use it for advertising, do not disclose it for any purpose other than performing the service, and do not use it to train machine learning models. No customer Personal Data is transmitted to any third-party artificial intelligence or large language model service; the screening and scoring engines are deterministic.

3. Confidentiality

Every person authorised to process Personal Data is bound by an obligation of confidentiality that survives termination of their engagement, and has access only to the data their role requires. Production database and host access is limited to the founder.

4. Security

We implement and maintain the technical and organisational measures set out in Annex II, taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as required by Article 32. We may update those measures provided the level of protection is not reduced.

5. Sub-processors

The Controller gives general written authorisation for ArcNautical to engage the Sub-processors listed in Annex III, and to appoint others on the terms below.

6. International transfers

ArcNautical processes Personal Data in India, which is not the subject of an adequacy decision. Where the Controller is established in the EEA, the UK or Switzerland, the transfer is made under:

6.1 How the Clauses are completed

ClauseElection
PartiesData exporter: the Controller. Data importer: ArcNautical.
Clause 7 (docking)Applies.
Clause 9 (sub-processors)Option 2, general written authorisation, with the 30-day notice period in section 5 above.
Clause 11 (redress)The optional independent dispute resolution body does not apply.
Clause 17 (governing law)The law of the EU Member State in which the data exporter is established.
Clause 18(b) (forum)The courts of that same Member State.
Annex I.A / I.BAnnex I of this Addendum.
Annex I.C (supervisory authority)The authority of the Member State in which the data exporter is established.
Annex IIAnnex II of this Addendum.

Where this Addendum and the Clauses conflict, the Clauses prevail.

6.2 Transfer impact assessment, in summary

We have assessed the legal environment of the destination country as required by Clause 14. In summary:

The full assessment is available on request.

7. Government and law enforcement requests

If we receive a legally binding request from a public authority for Personal Data we process for the Controller, we will:

We do not grant any authority direct or unrestricted access to Personal Data, and we hold no encryption key or back door provided for that purpose.

8. Assistance to the Controller

9. Personal Data Breach

We notify the Controller without undue delay and in any event within 72 hours of becoming aware of a Personal Data Breach affecting Personal Data processed for the Controller. The notification describes, to the extent known, the nature of the breach and the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. Information not available at the time is supplied in phases as it becomes available, without further undue delay.

Our notification is not an admission of fault or liability.

10. Deletion and return

On termination or expiry, at the Controller's election, we delete or return all Personal Data processed for the Controller and delete existing copies, within 30 days, unless Union, Member State or Indian law requires storage.

One deliberate exception. Screening records and their evidence are retained for ten years, because sanctions screening records are subject to a ten-year recordkeeping requirement under 31 CFR 501.601 as amended effective 12 March 2025, and destroying them on request would remove the Controller's own ability to answer a regulator. On termination we will export them to the Controller in full. If the Controller nonetheless directs deletion, we will comply and record the instruction.

11. Audit

We make available to the Controller the information necessary to demonstrate compliance with Article 28 and this Addendum, and we allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates. In practice this means:

An on-site inspection is available on reasonable notice, no more than once per twelve months, and at the Controller's cost, except following a Personal Data Breach affecting the Controller, when it is at ours. We may require an auditor who is not our competitor to sign a reasonable confidentiality undertaking.

12. Liability and precedence

Each party's liability under this Addendum is subject to the limitations and exclusions of liability in the Terms of Service, except that nothing limits either party's liability to a Data Subject under the third-party beneficiary provisions of the Standard Contractual Clauses. In the event of conflict, the Standard Contractual Clauses prevail over this Addendum, and this Addendum prevails over the Terms of Service in respect of the processing of Personal Data.

13. Acceptance

This Addendum is incorporated into the Terms of Service and takes effect when the Controller accepts those Terms. A countersigned copy is available on request from [email protected]; we will return it executed within two business days.


Annex I — Description of the processing

A. Parties

Data exporter / Controller: the customer entity accepting the Terms of Service. Contact details as given at account registration. Role: Controller.

Data importer / Processor: ArcNautical, maritime intelligence platform, arcnautical.com. Contact: [email protected]. Role: Processor.

B. Description of the transfer

Categories of Data SubjectThe Controller's employees, contractors and authorised users of the platform and API. Where the Controller submits them, named individuals appearing in vessel ownership, management or commercial counterparty records.
Categories of Personal DataName; business email address; company name and role; hashed authentication credentials; session and API key identifiers; IP address and request metadata; product usage events; the content of support correspondence; and any personal data the Controller chooses to place in free-text fields such as customer references, fleet names, and cargo descriptions.
Special category dataNone. The platform neither requests nor requires special category data, and the Controller is instructed not to submit it.
FrequencyContinuous, for the duration of the agreement.
Nature and purposeHosting and operating a maritime sanctions screening, vessel risk and voyage risk platform: authenticating users, executing screenings the Controller requests, storing the resulting records as the Controller's audit evidence, delivering notifications and webhooks, metering usage, and providing support.
RetentionAs set out in section 4 of the Trust & Security page. In summary: account data for the life of the account; screening records and evidence for ten years; voyage assessments 30 days; position history 90 days; session tokens 7 days.
Sub-processor transfersSubject matter, nature and duration as set out in Annex III.

C. Competent supervisory authority

The supervisory authority of the EU Member State in which the data exporter is established. Where the data exporter is not established in the EEA but falls within the GDPR under Article 3(2), the authority of the Member State in which its Article 27 representative is established.

Annex II — Technical and organisational measures

These are the Article 32 measures the importer applies. They are the same measures described on the Trust & Security page and are contractual here.

MeasureImplementation
Pseudonymisation and encryptionTLS on all external traffic, with HSTS. Passwords hashed with scrypt (N=16384) and per-user random salts. API keys stored as SHA-256 hashes and never recoverable in plaintext. Off-site backups encrypted with AES-256 (GnuPG symmetric, SHA-512 key derivation) under a key held by the importer, not the storage provider. At-rest encryption of managed disks by the hosting provider.
ConfidentialityPer-customer scoping enforced on every database query; no cross-tenant read path exists in the API. Scoped API keys with separate test and live environments holding independent quota, idempotency and webhook namespaces. Production access limited to the founder, by SSH public key only, with password authentication disabled.
IntegrityWebhook payloads signed with HMAC-SHA256 over a timestamped payload, enabling origin verification and replay rejection. Idempotency keys on every mutating endpoint. Screening results stored exactly as returned and replayed byte-for-byte on retrieval.
Availability and resilienceDaily database backup, encrypted and pushed to off-site infrastructure in a different country from the primary region; fourteen restore points retained; recovery point objective 24 hours. Every backup is decrypted and integrity-verified by the job that creates it, and the upload is refused if the round-trip fails.
Restoring availabilityDocumented single-command restore procedure from any retained encrypted backup. Restore integrity is verified automatically on every backup run rather than at a periodic drill.
Testing and evaluationAutomated regression suite gating every deployment, including a labelled goldset of screening outcomes that blocks release on regression. Nightly independent health probes across all upstream data sources, delivered as a digest whose absence is itself an alarm.
Resilience against abusePer-key rate limiting; global and per-customer concurrency ceilings on expensive scoring work; metered quota with reserve-and-refund so failed calls do not consume allowance; web application firewall and DDoS mitigation at the CDN edge.
Data minimisationRegistration collects email, company name and password only. Session replay masks all text inputs, including email, password and vessel identifier fields, at capture.
Sub-processor governanceWritten contracts imposing equivalent obligations; published list; 30 days notice of change with a right to object.
Accountability and loggingEvery authenticated API request is recorded durably with method, path, status, error code, source address, user agent and the key used, retained 365 days, and exposed to the Controller at GET /api/v1/access-log. Refusals are recorded alongside successes, and the source address is read only from the edge-set header, never from caller-supplied X-Forwarded-For.
Access control and accountabilityIndividual named logins for each colleague rather than a shared credential, invited under a single-use 14-day invitation. Role-based restriction of team management and API key issuance to administrators. Removal of a member destroys their sessions and cached credentials immediately. An account audit trail records who minted or revoked a key and who invited, promoted or removed a member, with the acting identity retained even after that person is removed, for 730 days.
Credential lifecycleAPI keys may carry an expiry and can be rotated with a configurable grace window, so a compromised credential is replaced without interrupting the Controller's integration. Any key may be restricted to Controller-nominated IP addresses or CIDR ranges, enforced on every request. Resolved-credential caches are cleared on revocation, rotation and restriction changes so a withdrawal takes effect immediately rather than at cache expiry.
Incident managementAutomated alerting on application errors, failed scheduled jobs and upstream degradation. Controller notification within 72 hours of awareness of a Personal Data Breach.

Measures not implemented, stated so the Controller can assess residual risk rather than discover it later: no SOC 2 or ISO 27001 certification; no third-party penetration test; no customer-managed encryption keys; no private networking or IP allowlisting; no formally exercised disaster recovery drill beyond the automated restore verification above; no multi-region failover.

Annex III — Authorised Sub-processors

Current as of the version date above. The authoritative list is maintained on the Trust & Security page.

EntityProcessingLocation
Microsoft Corporation (Azure)Application hosting, database, cache, object storage, error-tracking VM, mail relayIndia
Cloudflare, Inc.DNS, CDN, TLS termination, web application firewall, one edge workerGlobal edge
PostHog, Inc.Product analytics, error diagnostics, input-masked session replayUnited States
GitHub, Inc.Storage of off-site database backups, encrypted under a key held by ArcNauticalUnited States
Zoho CorporationTransactional and account email delivery, support mailboxesIndia

Sentry (error tracking) and ntfy (operational alerting) are self-hosted on ArcNautical infrastructure and are therefore not Sub-processors.

Related: Trust & Security · Service Level Agreement · Privacy Policy · Terms of Service