Legal
Data processing agreement
Effective 2026-06-23
This Data Processing Agreement (“DPA”) governs the processing of personal data that Vessel Hunter (“Vessel Hunter”, “we”, “us”) carries out on your behalf when you use the Vessel Hunter platform. It forms part of, and is incorporated into, our Terms of Service (the “Terms”). By accepting the Terms or using the platform you agree to this DPA. Where it conflicts with the Terms on the subject of personal-data processing, this DPA prevails. We will sign a counterpart copy on your letterhead on request.
This DPA applies to Customer Personal Data: personal data that you, or the users you authorise, upload, enter, or otherwise provide for processing in your Vessel Hunter workspace (for example account and login details of your users, and the contacts, notes, lists and records you create or import). It does not cover the maritime intelligence we compile from public and third-party sources and surface in the product; for that data Vessel Hunter acts as an independent controller, as described in our Privacy Policy and in section 6 of the Terms.
1. Definitions
“GDPR” means Regulation (EU) 2016/679, and, where applicable, the UK GDPR and Data Protection Act 2018. “Controller”, “Processor”, “Sub-processor”, “Data Subject”, “Processing”, and “Personal Data Breach” have the meanings given in the GDPR. “SCCs” means the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914. “Applicable Data Protection Law” means all data-protection and privacy laws that apply to the processing under this DPA, including the GDPR.
2. Roles & instructions
For Customer Personal Data you are the controller and Vessel Hunter is the processor. We process Customer Personal Data only on your documented instructions, including as to international transfers, unless required to do otherwise by EU or member-state law (in which case we will inform you first, unless that law prohibits it). Your instructions are set out in the Terms, this DPA, and your configuration and use of the platform. We will inform you if, in our opinion, an instruction infringes Applicable Data Protection Law. We do not sell Customer Personal Data and do not use it for our own purposes, including to build or train models, except to provide, secure and maintain the platform.
3. Details of the processing
The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are set out in Annex A. The processing lasts for as long as we provide the platform to you and until Customer Personal Data is returned or deleted under section 12.
4. Our obligations as processor
In line with Article 28(3) GDPR, we will:
- process Customer Personal Data only on your documented instructions (section 2);
- ensure that personnel authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality (section 5);
- implement and maintain the technical and organisational measures in Annex B (Article 32);
- engage sub-processors only on the terms in section 7 (Article 28(2) and (4));
- taking into account the nature of the processing, assist you by appropriate measures to respond to data-subject requests (section 9);
- assist you in ensuring compliance with your obligations under Articles 32–36 (security, breach notification, data-protection impact assessments and prior consultation), taking into account the information available to us (section 10);
- delete or return Customer Personal Data at the end of the service (section 12); and
- make available the information needed to demonstrate compliance with Article 28 and allow for and contribute to audits (section 11).
5. Confidentiality
Access to Customer Personal Data is limited to personnel who need it to provide, secure or support the platform, on a least-privilege basis. Those individuals are bound by confidentiality obligations, whether contractual or statutory.
6. Security
We implement appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, having regard to the state of the art, the costs of implementation, and the nature, scope and purposes of the processing. The current measures are described in Annex B. We may update them over time provided the level of protection is not reduced.
7. Sub-processors
You give general authorisation for us to engage the sub-processors listed in Annex C, by category, to help us provide the platform. We impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, by way of a written contract, and we remain fully liable to you for each sub-processor’s performance. A current list of named sub-processors and their locations is available to customers on request, under NDA. We will give you at least 30 days’ notice before adding or replacing a sub-processor; if you have a reasonable, data-protection-based objection you may raise it within that period and we will work with you in good faith, which may include offering an alternative or, failing that, allowing you to terminate the affected service.
8. International transfers
The primary application and database hosting for the platform is provided within the European Economic Area, in a data centre in Germany. Customer Personal Data is therefore stored within the EEA, and no Chapter V transfer mechanism is required for the core data store.
Some sub-processors (Annex C) operate outside the EEA, including in the United States. Where a sub-processor processes Customer Personal Data outside the EEA in a country without an adequacy decision, that transfer relies on the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914), which are incorporated into this DPA by reference and are deemed entered into between the parties for any such transfer, together with supplementary measures including encryption in transit. Where a US sub-processor is certified under the EU–US Data Privacy Framework, we may rely on that framework instead. We do not transfer Customer Personal Data outside the EEA other than to sub-processors covered by an Article 46 safeguard.
9. Data-subject requests
If we receive a request from a data subject relating to Customer Personal Data, we will not respond directly (except to confirm that the request concerns you) and will forward it to you without undue delay. Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to fulfil your obligation to respond to requests to exercise rights of access, rectification, erasure, restriction, portability and objection. Account holders can also export or delete workspace data directly in the product.
10. Personal data breaches & assistance
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We will assist you in meeting your obligations under Articles 32–36 GDPR, including breach notification to authorities and data subjects, data-protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to us.
11. Audits & records
We will make available to you the information necessary to demonstrate compliance with Article 28 and this DPA, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. To respect the confidentiality and security of other customers, audits take place on reasonable prior notice (at least 30 days, except where a supervisory authority or a breach requires sooner), no more than once per year unless required by an authority or following a breach, during business hours, subject to confidentiality, and in a manner that does not disrupt our operations. We may satisfy an audit request by providing current documentation of our controls or relevant third-party certifications or reports where available.
12. Return & deletion
On termination of the service, or at your request, we will, at your choice, return Customer Personal Data to you or delete it, and delete existing copies, unless EU or member-state law requires us to keep it. We make export available for a reasonable period after termination; after that we delete Customer Personal Data within 30 days. Data held in routine backups is deleted on the ordinary backup-rotation cycle.
13. Liability
Each party’s liability under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Terms.
14. Term, governing law & changes
This DPA takes effect when you accept the Terms and continues for as long as we process Customer Personal Data on your behalf. It is governed by the laws of the Netherlands, and disputes are subject to the exclusive jurisdiction of the competent Dutch court, consistent with the Terms. We review this DPA periodically and will post material changes here with an updated effective date.
Annex A — Details of the processing
Subject matter
Provision of the Vessel Hunter platform (maritime intelligence, vessel dossiers, lists and watchlists, contact and CRM records, and related features) to you under the Terms.
Duration
For the term of the Terms and until Customer Personal Data is returned or deleted under section 12.
Nature & purpose
Hosting, storage, organisation, retrieval, display and deletion of Customer Personal Data as necessary to provide, secure, support and bill the platform features you use.
Types of personal data
- your authorised users: name, business email, role, hashed credentials, and usage, log and audit data;
- personal data within the content you upload or enter: typically business contacts you store (name, job title, employer, business contact details) and your notes and records about them.
You agree not to upload special categories of personal data (Article 9 GDPR) for processing in the platform unless separately agreed in writing.
Categories of data subjects
- your personnel and other authorised users; and
- the business contacts and prospects you choose to store in your workspace.
Annex B — Technical & organisational measures
We maintain, at a minimum, the following measures (Article 32):
- Encryption in transit: all traffic to the platform is served over TLS with HTTP Strict Transport Security enforced at the edge.
- Access control: least-privilege access for personnel; administrative access is key-based and individually attributed; application database access is role-scoped.
- Tenant isolation: customer workspaces are logically separated and isolated at the database level through row-level security policies.
- Network security: the database and application are not exposed to the public internet; only the TLS edge is reachable. A host firewall, brute-force protection and edge rate-limiting and security headers are in place.
- Logging & monitoring: changes to customer-facing data are recorded in an audit log; access and application events are logged.
- Backups & resilience: automated database backups run on a regular schedule with rolling retention to support restoration.
- Personnel & vendors: personnel are bound by confidentiality; sub-processors are subject to due diligence and written data-protection terms.
- Secure development: dependency and vulnerability management, and an incident-response process for security events.
Annex C — Sub-processors
We use a small set of vetted sub-processors, by category. The named list, with each provider’s identity and location, is available to customers on request under NDA.
- Cloud hosting & database — application, database and backups; located within the EEA (Germany).
- Payment & subscription processing — billing name, email and payment metadata.
- Transactional email — delivery of account and notification emails.
- AIS / vessel data — vessel identifiers only; no Customer Personal Data is sent.
- In-product support assistant — processes the support messages your users send, to generate replies.
- Product & website analytics — consent-gated; pseudonymous usage data only.
Sub-processors located outside the EEA are covered by the safeguards in section 8.
Request a signed copy
Email contact@vesselhunter.io with your company name and we will share a counterpart for signature within one business day. Vessel Hunter, De Wijper 16, 4726 TG Heerle, The Netherlands, KvK 80638090.
Questions? Get in touch.