Data Processing Agreement
Last updated: July 16, 2026
Last Updated: July 16, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between WaterTight Ltd ("Processor", "WaterTight", "we", "us") and the customer entity that has subscribed to the WaterTight platform ("Controller", "Customer", "you").
It applies where WaterTight processes Personal Data on behalf of the Customer in connection with the WaterTight software-as-a-service platform, mobile applications, APIs, and related services (the "Services").
This DPA is designed to meet the requirements of the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and the Data Protection Act 2018.
Where the Customer is established in the UK, EEA, or processes Personal Data of individuals in those jurisdictions, the Standard Contractual Clauses and UK International Data Transfer Addendum described in Section 10 are incorporated into and form part of this DPA.
1. Definitions
In this DPA:
- Applicable Data Protection Law means UK GDPR, EU GDPR (where applicable), the Data Protection Act 2018, and any national implementing legislation.
- Personal Data, Data Subject, Processing, Controller, Processor, Subprocessor, and Supervisory Authority have the meanings given in Applicable Data Protection Law.
- Customer Personal Data means Personal Data processed by WaterTight on behalf of the Customer under the Services.
- SCCs means the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679, as set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (Controller to Processor).
- UK Addendum means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office under section 119A of the Data Protection Act 2018 (Version B1.0, as amended).
Capitalised terms not defined here have the meanings given in the main subscription or terms agreement between the parties.
2. Roles of the parties
2.1 The Customer is the Controller of Customer Personal Data.
2.2 WaterTight is the Processor of Customer Personal Data, except where WaterTight determines the purposes and means of processing (for example, direct account administration, website analytics, or billing contact details), in which case WaterTight acts as an independent Controller for that limited processing.
2.3 The Customer shall ensure it has a lawful basis under Applicable Data Protection Law to provide Customer Personal Data to WaterTight and to instruct Processing.
2.4 The Customer is responsible for the accuracy, quality, and legality of Customer Personal Data and the means by which it acquired such data.
3. Subject matter, duration, and nature of processing
| Item | Details |
|---|---|
| Subject matter | Provision of the WaterTight vessel management, crew management, safety, compliance, maintenance, and related operational software platform. |
| Duration | For the term of the Customer's subscription to the Services, plus any period required to return or delete data under this DPA and Applicable Data Protection Law. |
| Nature and purpose | Hosting, storage, organisation, retrieval, display, export, backup, security monitoring, support, and other processing necessary to provide the Services as configured by the Customer. |
| Categories of Data Subjects | Seafarers and other crew; company employees and contractors; masters, officers, superintendents, DPAs, HR staff, and other authorised users of the Customer account. |
| Types of Personal Data | Identity and contact data; employment and rank data; vessel assignment data; certificates and training records; medical fitness certificates and related health information; safety and incident records; work/rest hours; contracts and payroll-related data; communications; technical and usage logs; and other data uploaded or generated through the Services. |
| Special category data | May include health data contained in medical fitness certificates and related documents uploaded or managed through the Services. |
4. Processor obligations
WaterTight shall:
4.1 Process Customer Personal Data only on documented instructions from the Customer, including as set out in the Services configuration, this DPA, and Applicable Data Protection Law, unless required to process by law (in which case WaterTight shall inform the Customer of that legal requirement before processing, unless prohibited by law).
4.2 Ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations.
4.3 Implement appropriate technical and organisational measures to protect Customer Personal Data, as described in Annex II.
4.4 Not engage another processor (Subprocessor) without the Customer's general written authorisation as set out in Section 5.
4.5 Taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as possible, with the fulfilment of the Customer's obligations to respond to Data Subject requests.
4.6 Assist the Customer in ensuring compliance with Articles 32 to 36 of the GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of processing and information available to WaterTight.
4.7 At the Customer's choice, delete or return all Customer Personal Data after the end of provision of the Services, subject to Section 8 and legal retention requirements.
4.8 Make available to the Customer information necessary to demonstrate compliance with this DPA and allow for audits as described in Section 9.
4.9 Inform the Customer if, in WaterTight's opinion, an instruction infringes Applicable Data Protection Law.
5. Subprocessors
5.1 The Customer provides general written authorisation for WaterTight to engage Subprocessors to support delivery of the Services.
5.2 WaterTight shall impose data protection obligations on Subprocessors that are no less protective than those in this DPA.
5.3 WaterTight shall remain fully liable to the Customer for the performance of a Subprocessor's obligations.
5.4 WaterTight shall inform the Customer of intended changes concerning the addition or replacement of Subprocessors by updating Annex III and, where practicable, by notice to the account administrator or via the WaterTight website. The Customer may object on reasonable data-protection grounds within 30 days of notice. If the parties cannot resolve the objection, the Customer may terminate the affected Services.
5.5 The current list of Subprocessors is set out in Annex III.
6. Security of processing
6.1 WaterTight shall implement technical and organisational measures appropriate to the risk, including those listed in Annex II.
6.2 Further security information is published at https://watertight.app/trust/security.
7. Personal data breaches
7.1 WaterTight shall notify the Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data.
7.2 The notification shall, to the extent known, describe the nature of the breach, likely consequences, measures taken or proposed, and a contact point for further information.
7.3 WaterTight shall cooperate with the Customer and take reasonable steps to assist in investigating, mitigating, and remediating the breach.
8. Return and deletion of data
8.1 On termination or expiry of the Services, the Customer may export Customer Personal Data using available export features in the platform.
8.2 Following termination, WaterTight shall delete Customer Personal Data from active systems within 90 days, unless Applicable Data Protection Law requires retention or the Customer requests an earlier deletion schedule in writing.
8.3 Backups containing Customer Personal Data shall be overwritten or deleted in accordance with WaterTight's backup retention cycle, normally within 90 days after deletion from active systems.
8.4 WaterTight may retain minimal records where required by law (for example billing, tax, or dispute records) or in anonymised form for service improvement and security analytics.
9. Audits and information
9.1 WaterTight shall make available on request reasonable information necessary to demonstrate compliance with this DPA.
9.2 The Customer may conduct audits no more than once per year on reasonable notice, during business hours, without disrupting operations, and subject to confidentiality obligations. WaterTight may satisfy audit requests by providing current third-party certifications, security summaries, or completed security questionnaires where appropriate.
10. International transfers and Standard Contractual Clauses
10.1 General
Where Customer Personal Data is transferred to a country outside the UK or EEA that does not benefit from an adequacy decision, the parties agree that appropriate safeguards are provided as set out in this Section 10.
10.2 Incorporation of EU Standard Contractual Clauses
The SCCs (Module Two: Controller to Processor) are incorporated into this DPA by reference and form part of it. In the event of conflict between this DPA and the SCCs, the SCCs prevail to the extent of the conflict with respect to an international transfer subject to EU GDPR.
The parties complete the SCCs using the details in Annex I, Annex II, and Annex III to this DPA.
Where Module Two requires option selections:
- Clause 7 (Docking clause): not used
- Clause 9 (Use of subprocessors): Option 2 (general written authorisation) applies, as set out in Section 5
- Clause 11 (Redress): the optional language is not used
- Clause 13 (Supervision): the supervisory authority is as stated in Annex I.C
- Clause 17 (Governing law): the law of Ireland (for transfers subject to EU GDPR)
- Clause 18 (Choice of forum and jurisdiction): the courts of Ireland (for transfers subject to EU GDPR)
10.3 UK International Data Transfer Addendum
For transfers subject to UK GDPR, the UK Addendum is incorporated into this DPA by reference and forms part of it, with the following Part 2 elections:
- Table 1: parties and key contact details as in Annex I
- Table 2: the approved EU SCCs are the SCCs referenced in Section 10.2, Module Two
- Table 3: Annex II of the SCCs is Annex II to this DPA; Annex III of the SCCs is Annex III to this DPA
- Table 4: the parties may end the UK Addendum in accordance with its terms; WaterTight may propose changes as permitted by the UK Addendum with notice to the Customer
10.4 Supplementary measures
WaterTight applies supplementary technical and organisational measures described in Annex II, including encryption in transit and at rest for sensitive fields, tenant isolation, access controls, and EU-region hosting for production workloads.
11. Data subject rights
11.1 WaterTight shall promptly notify the Customer if it receives a request from a Data Subject relating to Customer Personal Data, unless prohibited by law.
11.2 WaterTight shall not respond directly to the Data Subject except on the Customer's instructions or as required by law.
11.3 The Customer is responsible for responding to Data Subject requests. WaterTight shall provide reasonable assistance through platform features (including export and deletion tools) and support channels.
12. Order of precedence, term, and contact
12.1 This DPA supplements the main agreement between the parties. If there is a conflict regarding the processing of Customer Personal Data, this DPA prevails.
12.2 This DPA remains in effect for as long as WaterTight processes Customer Personal Data on behalf of the Customer.
12.3 Privacy-related enquiries: hello@watertight.app
12.4 WaterTight Ltd, United Kingdom (registered office address available on request).
Annex I — Parties and transfer description (SCC Annex I)
A. List of parties
Data exporter (Controller)
- Name: The Customer entity that has subscribed to the Services
- Address: As provided in the Customer account or order form
- Contact: The Customer's designated account administrator
- Role: Controller
Data importer (Processor)
- Name: WaterTight Ltd
- Address: United Kingdom (full registered office address available on request via hello@watertight.app)
- Contact: hello@watertight.app
- Role: Processor
B. Description of transfer
See Section 3 of this DPA.
Transfers may occur because WaterTight and its Subprocessors operate infrastructure and support services that may process or access Customer Personal Data from or in countries outside the UK/EEA, including where support, monitoring, or Subprocessor systems are located outside those jurisdictions.
Frequency: Continuous for the duration of the Services.
Retention: As set out in Sections 8 and Annex II.
C. Competent supervisory authority
For transfers subject to EU GDPR: the supervisory authority of the EU member state in which the Customer is established, or, if the Customer is not established in the EU but falls within the scope of EU GDPR under Article 3(2), the supervisory authority of the EU member state indicated by the Customer (default: Ireland — Data Protection Commission).
For transfers subject to UK GDPR: the UK Information Commissioner's Office (ICO).
Annex II — Technical and organisational measures (SCC Annex II)
WaterTight maintains a security programme appropriate to the nature of the Services, including:
| Area | Measures |
|---|---|
| Governance | Access control policies, least-privilege administration, and security review as the platform evolves. |
| Encryption | TLS/HTTPS for data in transit; authenticated encryption (AES-256-GCM) for designated sensitive crew profile fields at rest. |
| Authentication | Password hashing (bcrypt); multi-factor authentication options (TOTP, email OTP, WebAuthn passkeys, backup codes). |
| Tenant isolation | Strict company-level data scoping; no cross-tenant access in application logic. |
| Authorisation | Rank- and permission-based access controls across vessel and fleet modules. |
| Hosting | Production workloads hosted on Google Cloud Platform, primarily in the EU (europe-west1, Belgium). |
| Backups | Encrypted database backups with controlled retention and restore procedures. |
| Logging | Administrative and security-relevant event logging to support investigation and audit. |
| Development | Secure deployment practices, dependency management, and change control for production releases. |
| Incident response | Procedures to detect, contain, and notify Customers of relevant security incidents. |
| Personnel | Confidentiality obligations for personnel with access to production systems. |
| Subprocessors | Contractual data protection requirements and due diligence for infrastructure and service providers. |
Further detail: https://watertight.app/trust/security
Annex III — Authorised subprocessors (SCC Annex III)
The Customer authorises WaterTight to use the following categories of Subprocessors. Specific entities may be updated from time to time in line with Section 5.
| Subprocessor | Purpose | Location / transfer notes |
|---|---|---|
| Google Cloud Platform (Google LLC) | Cloud hosting, storage, backups, logging, and related infrastructure | Primary production region: EU (Belgium). Google may process support/monitoring data globally under Google's DPA and SCCs. |
| Stripe, Inc. | Subscription billing and payment processing | United States and other locations per Stripe's DPA and SCCs. Card data handled by Stripe; WaterTight does not store full card numbers. |
| Email delivery provider | Transactional email (account, security, notifications) | Provider and location may vary; transfers safeguarded by processor terms and SCCs where applicable. |
| TrueLayer | Open banking connectivity (where enabled) | UK / EEA; governed by TrueLayer terms and applicable transfer safeguards. |
| Xero Limited | Accounting and payroll integration (where enabled) | New Zealand / global per Xero's DPA and transfer mechanisms. |
| Google Analytics | Website and product analytics (marketing site; consent-based) | United States per Google's terms; used for pseudonymous analytics where consent is given. |
The Customer may request the current Subprocessor list at hello@watertight.app.