Version 1.0 · September 5, 2026
This Addendum forms part of the Terms of Service between ArcNautical (the Processor) and the customer entity accepting those Terms (the Controller). It applies whenever ArcNautical processes personal data on the Controller's behalf and to which the GDPR, the UK GDPR, or the Swiss FADP applies.
This is our standard form, not an ultimatum. If your organisation requires its own data processing agreement, send it and we will review and sign, provided the technical facts in Annexes I to III are carried across accurately. What we cannot do is sign a document that misdescribes where the data actually sits.
Controller, Processor, Personal Data, Processing, Data Subject, Sub-processor and Personal Data Breach have the meanings given in the GDPR. Applicable Data Protection Law means Regulation (EU) 2016/679, the UK GDPR and Data Protection Act 2018, the Swiss FADP, and India's Digital Personal Data Protection Act 2023, each as applicable.
ArcNautical acts in two different capacities, and conflating them would misdescribe what actually happens. A data protection officer reviewing this will ask, so it is set out up front:
The Controller is not responsible for our processing under role 2, and we are not the Controller of anything under role 1.
ArcNautical processes Personal Data only on the Controller's documented instructions, including as to international transfers, unless required otherwise by Union or Member State law — in which case we inform the Controller before processing, unless that law forbids it on important grounds of public interest.
The Terms of Service, this Addendum, and the Controller's use of the platform and API constitute the Controller's complete documented instructions. We will tell the Controller if, in our opinion, an instruction infringes Applicable Data Protection Law.
We do not sell Personal Data, do not use it for advertising, do not disclose it for any purpose other than performing the service, and do not use it to train machine learning models. No customer Personal Data is transmitted to any third-party artificial intelligence or large language model service; the screening and scoring engines are deterministic.
Every person authorised to process Personal Data is bound by an obligation of confidentiality that survives termination of their engagement, and has access only to the data their role requires. Production database and host access is limited to the founder.
We implement and maintain the technical and organisational measures set out in Annex II, taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as required by Article 32. We may update those measures provided the level of protection is not reduced.
The Controller gives general written authorisation for ArcNautical to engage the Sub-processors listed in Annex III, and to appoint others on the terms below.
ArcNautical processes Personal Data in India, which is not the subject of an adequacy decision. Where the Controller is established in the EEA, the UK or Switzerland, the transfer is made under:
| Clause | Election |
|---|---|
| Parties | Data exporter: the Controller. Data importer: ArcNautical. |
| Clause 7 (docking) | Applies. |
| Clause 9 (sub-processors) | Option 2, general written authorisation, with the 30-day notice period in section 5 above. |
| Clause 11 (redress) | The optional independent dispute resolution body does not apply. |
| Clause 17 (governing law) | The law of the EU Member State in which the data exporter is established. |
| Clause 18(b) (forum) | The courts of that same Member State. |
| Annex I.A / I.B | Annex I of this Addendum. |
| Annex I.C (supervisory authority) | The authority of the Member State in which the data exporter is established. |
| Annex II | Annex II of this Addendum. |
Where this Addendum and the Clauses conflict, the Clauses prevail.
We have assessed the legal environment of the destination country as required by Clause 14. In summary:
The full assessment is available on request.
If we receive a legally binding request from a public authority for Personal Data we process for the Controller, we will:
We do not grant any authority direct or unrestricted access to Personal Data, and we hold no encryption key or back door provided for that purpose.
We notify the Controller without undue delay and in any event within 72 hours of becoming aware of a Personal Data Breach affecting Personal Data processed for the Controller. The notification describes, to the extent known, the nature of the breach and the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. Information not available at the time is supplied in phases as it becomes available, without further undue delay.
Our notification is not an admission of fault or liability.
On termination or expiry, at the Controller's election, we delete or return all Personal Data processed for the Controller and delete existing copies, within 30 days, unless Union, Member State or Indian law requires storage.
One deliberate exception. Screening records and their evidence are retained for ten years, because sanctions screening records are subject to a ten-year recordkeeping requirement under 31 CFR 501.601 as amended effective 12 March 2025, and destroying them on request would remove the Controller's own ability to answer a regulator. On termination we will export them to the Controller in full. If the Controller nonetheless directs deletion, we will comply and record the instruction.
We make available to the Controller the information necessary to demonstrate compliance with Article 28 and this Addendum, and we allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates. In practice this means:
An on-site inspection is available on reasonable notice, no more than once per twelve months, and at the Controller's cost, except following a Personal Data Breach affecting the Controller, when it is at ours. We may require an auditor who is not our competitor to sign a reasonable confidentiality undertaking.
Each party's liability under this Addendum is subject to the limitations and exclusions of liability in the Terms of Service, except that nothing limits either party's liability to a Data Subject under the third-party beneficiary provisions of the Standard Contractual Clauses. In the event of conflict, the Standard Contractual Clauses prevail over this Addendum, and this Addendum prevails over the Terms of Service in respect of the processing of Personal Data.
This Addendum is incorporated into the Terms of Service and takes effect when the Controller accepts those Terms. A countersigned copy is available on request from [email protected]; we will return it executed within two business days.
Data exporter / Controller: the customer entity accepting the Terms of Service. Contact details as given at account registration. Role: Controller.
Data importer / Processor: ArcNautical, maritime intelligence platform, arcnautical.com. Contact: [email protected]. Role: Processor.
| Categories of Data Subject | The Controller's employees, contractors and authorised users of the platform and API. Where the Controller submits them, named individuals appearing in vessel ownership, management or commercial counterparty records. |
|---|---|
| Categories of Personal Data | Name; business email address; company name and role; hashed authentication credentials; session and API key identifiers; IP address and request metadata; product usage events; the content of support correspondence; and any personal data the Controller chooses to place in free-text fields such as customer references, fleet names, and cargo descriptions. |
| Special category data | None. The platform neither requests nor requires special category data, and the Controller is instructed not to submit it. |
| Frequency | Continuous, for the duration of the agreement. |
| Nature and purpose | Hosting and operating a maritime sanctions screening, vessel risk and voyage risk platform: authenticating users, executing screenings the Controller requests, storing the resulting records as the Controller's audit evidence, delivering notifications and webhooks, metering usage, and providing support. |
| Retention | As set out in section 4 of the Trust & Security page. In summary: account data for the life of the account; screening records and evidence for ten years; voyage assessments 30 days; position history 90 days; session tokens 7 days. |
| Sub-processor transfers | Subject matter, nature and duration as set out in Annex III. |
The supervisory authority of the EU Member State in which the data exporter is established. Where the data exporter is not established in the EEA but falls within the GDPR under Article 3(2), the authority of the Member State in which its Article 27 representative is established.
These are the Article 32 measures the importer applies. They are the same measures described on the Trust & Security page and are contractual here.
| Measure | Implementation |
|---|---|
| Pseudonymisation and encryption | TLS on all external traffic, with HSTS. Passwords hashed with scrypt (N=16384) and per-user random salts. API keys stored as SHA-256 hashes and never recoverable in plaintext. Off-site backups encrypted with AES-256 (GnuPG symmetric, SHA-512 key derivation) under a key held by the importer, not the storage provider. At-rest encryption of managed disks by the hosting provider. |
| Confidentiality | Per-customer scoping enforced on every database query; no cross-tenant read path exists in the API. Scoped API keys with separate test and live environments holding independent quota, idempotency and webhook namespaces. Production access limited to the founder, by SSH public key only, with password authentication disabled. |
| Integrity | Webhook payloads signed with HMAC-SHA256 over a timestamped payload, enabling origin verification and replay rejection. Idempotency keys on every mutating endpoint. Screening results stored exactly as returned and replayed byte-for-byte on retrieval. |
| Availability and resilience | Daily database backup, encrypted and pushed to off-site infrastructure in a different country from the primary region; fourteen restore points retained; recovery point objective 24 hours. Every backup is decrypted and integrity-verified by the job that creates it, and the upload is refused if the round-trip fails. |
| Restoring availability | Documented single-command restore procedure from any retained encrypted backup. Restore integrity is verified automatically on every backup run rather than at a periodic drill. |
| Testing and evaluation | Automated regression suite gating every deployment, including a labelled goldset of screening outcomes that blocks release on regression. Nightly independent health probes across all upstream data sources, delivered as a digest whose absence is itself an alarm. |
| Resilience against abuse | Per-key rate limiting; global and per-customer concurrency ceilings on expensive scoring work; metered quota with reserve-and-refund so failed calls do not consume allowance; web application firewall and DDoS mitigation at the CDN edge. |
| Data minimisation | Registration collects email, company name and password only. Session replay masks all text inputs, including email, password and vessel identifier fields, at capture. |
| Sub-processor governance | Written contracts imposing equivalent obligations; published list; 30 days notice of change with a right to object. |
| Accountability and logging | Every authenticated API request is recorded durably with method, path, status, error code, source address, user agent and the key used, retained 365 days, and exposed to the Controller at GET /api/v1/access-log. Refusals are recorded alongside successes, and the source address is read only from the edge-set header, never from caller-supplied X-Forwarded-For. |
| Access control and accountability | Individual named logins for each colleague rather than a shared credential, invited under a single-use 14-day invitation. Role-based restriction of team management and API key issuance to administrators. Removal of a member destroys their sessions and cached credentials immediately. An account audit trail records who minted or revoked a key and who invited, promoted or removed a member, with the acting identity retained even after that person is removed, for 730 days. |
| Credential lifecycle | API keys may carry an expiry and can be rotated with a configurable grace window, so a compromised credential is replaced without interrupting the Controller's integration. Any key may be restricted to Controller-nominated IP addresses or CIDR ranges, enforced on every request. Resolved-credential caches are cleared on revocation, rotation and restriction changes so a withdrawal takes effect immediately rather than at cache expiry. |
| Incident management | Automated alerting on application errors, failed scheduled jobs and upstream degradation. Controller notification within 72 hours of awareness of a Personal Data Breach. |
Measures not implemented, stated so the Controller can assess residual risk rather than discover it later: no SOC 2 or ISO 27001 certification; no third-party penetration test; no customer-managed encryption keys; no private networking or IP allowlisting; no formally exercised disaster recovery drill beyond the automated restore verification above; no multi-region failover.
Current as of the version date above. The authoritative list is maintained on the Trust & Security page.
| Entity | Processing | Location |
|---|---|---|
| Microsoft Corporation (Azure) | Application hosting, database, cache, object storage, error-tracking VM, mail relay | India |
| Cloudflare, Inc. | DNS, CDN, TLS termination, web application firewall, one edge worker | Global edge |
| PostHog, Inc. | Product analytics, error diagnostics, input-masked session replay | United States |
| GitHub, Inc. | Storage of off-site database backups, encrypted under a key held by ArcNautical | United States |
| Zoho Corporation | Transactional and account email delivery, support mailboxes | India |
Sentry (error tracking) and ntfy (operational alerting) are self-hosted on ArcNautical infrastructure and are therefore not Sub-processors.
Related: Trust & Security · Service Level Agreement · Privacy Policy · Terms of Service