Data Processing Agreement
Last updated: 23/08/2026
1. Purpose & Scope
This Data Processing Agreement ("DPA") describes how DockSpare ([LEGAL ENTITY NAME PENDING INCORPORATION], "we", "Processor") handles personal data in connection with the DockSpare Platform, for the benefit of Suppliers and other business users ("Customer", "Controller") who may themselves have data-protection obligations toward their own customers. It supplements our Privacy Policy and forms part of our Terms of Service where applicable law (such as the EU/UK GDPR) requires a DPA between us.
2. Roles of the Parties
For most personal data on the Platform — a Customer's own account details, and the Yacht Users they transact with — DockSpare acts as an independent Controller, determining the purposes and means of processing needed to operate the marketplace (see our Privacy Policy). Where a Customer uploads personal data of their own staff or sub-contractors into the Platform for their own purposes beyond that (for example, in free-text listing fields), DockSpare acts as a Processor with respect to that specific data, processing it only on the Customer's documented instructions.
3. Subject Matter & Duration
The subject matter of processing is the operation of the DockSpare marketplace platform as described in our Terms of Service. This DPA applies for as long as DockSpare processes personal data on the Customer's behalf, and terminates automatically when the underlying account relationship ends and any retention period in Section 10 has elapsed.
4. Categories of Data & Data Subjects
| Data Subjects | Categories of Data |
|---|---|
| Yacht Users & crew | Name, email, vessel details, delivery locations, order history |
| Supplier staff/contacts | Name, email, company role, contact details |
| Anyone named in free-text fields | Whatever a user includes in listings, messages, or notes — no special categories of data should be entered here |
5. Sub-processors
DockSpare uses the following sub-processors to operate the Platform. We will update this list if it changes.
| Sub-processor | Purpose |
|---|---|
| Supabase | Database, authentication, and file storage (Postgres + Auth) |
| Netlify | Static site hosting and deployment |
| Cloudflare (Turnstile) | Bot/abuse protection on registration and login |
| OpenStreetMap Nominatim | One-time geocoding of a Supplier's port/country into map coordinates at signup |
6. Security Measures
DockSpare implements technical and organizational measures appropriate to the risk, including: database-level row security policies restricting each record to its authorized parties, hashed password storage via Supabase Auth, HTTPS in transit, and security-focused HTTP headers (see _headers in the site's deployment configuration). See our Security & Vulnerability Disclosure Policy for how to report a concern.
7. Confidentiality
DockSpare treats personal data it processes as confidential and limits access to personnel who need it to operate the Platform, bound by confidentiality obligations.
8. Assistance with Data Subject Rights
Where DockSpare acts as a Processor for a Customer under Section 2, we will provide reasonable assistance to that Customer in responding to data subject requests (access, correction, deletion) relating to data we process on their behalf, to the extent this is within our control.
9. Data Breach Notification
If we become aware of a personal data breach affecting data we process as a Processor under this DPA, we will notify the affected Customer without undue delay after becoming aware of it, with the information available to us at the time.
10. Data Return & Deletion
Consistent with our Terms of Service's archive-rather-than-delete approach, account and transaction data is archived (not immediately erased) when an account or relationship ends, so in-progress Orders can be resolved and legal/accounting obligations met. Data is not retained beyond what's necessary for these purposes.
11. Audits
On reasonable request and subject to confidentiality, DockSpare will make available information reasonably necessary to demonstrate compliance with this DPA.
12. Contact
Questions about this DPA, or requests for a signed/countersigned version, can be sent to privacy@dockspare.example.