Data Processing Addendum
Last updated: 2026-07-29 Effective: 2026-07-29
This Data Processing Addendum ("DPA") forms part of the Terms of Service between SeafloorSpeciesmapper LLC ("Processor", "we", "us") and the customer identified in the account ("Controller", "you"). It applies where you use the SeafloorSpeciesmapper platform ("Service") to process personal data covered by the EU General Data Protection Regulation ("GDPR"), the UK GDPR, or comparable data protection law. If any term of this DPA conflicts with the Terms of Service, this DPA prevails for the processing of personal data.
If you are a US-only customer processing no personal data of EU/UK residents, this DPA does not apply and you can skip it.
1. Definitions
Terms not defined here have the meanings given in the GDPR. "Personal Data" means any Customer Data that relates to an identified or identifiable natural person.
2. Subject matter and scope
2.1 Subject matter. We process Personal Data on your behalf solely to deliver the Service to you and to comply with your written instructions.
2.2 Duration. For as long as your subscription is active, plus the retention periods stated in our Privacy Policy.
2.3 Nature and purpose of processing. Storage of files, execution of scoring runs, generation of maps and reports, provision of an API and dashboard.
2.4 Categories of data subjects. Where present in your uploaded Customer Data: researchers, field surveyors, and (rarely) named observers.
2.5 Categories of Personal Data. Where present: names, professional affiliations, coordinates of survey activity, email addresses of collaborators added to a run.
3. Roles
You are the Controller of Personal Data you upload to the Service. We are the Processor. We do not determine the purposes or means of processing beyond what is necessary to deliver the Service.
4. Our obligations as Processor
We shall:
- Process Personal Data only on documented instructions from you, including your use of the Service itself and any support requests you submit.
- Ensure that persons authorised to process Personal Data are under an obligation of confidentiality.
- Implement appropriate technical and organisational measures (see Section 8 and the Security page).
- Assist you in responding to data subject requests, insofar as reasonably possible.
- Assist you with data protection impact assessments, insofar as reasonably possible.
- Notify you without undue delay after becoming aware of a Personal Data breach (see Section 9).
- On termination of the subscription, delete or return all Personal Data as directed, subject to legal retention obligations.
5. Sub-processors
5.1 Authorised sub-processors. You authorise our use of the sub-processors listed at seafloorspeciesmapper.com/legal/privacy.html, section 3. That list may change; we will provide 30 days' notice of any change via the dashboard and by email, during which you may object in writing.
5.2 Sub-processor obligations. We impose data-protection terms on every sub-processor that are at least as protective as those in this DPA.
5.3 Liability. We remain liable to you for the acts and omissions of our sub-processors.
6. International transfers
6.1 Default location. Personal Data is stored and processed in the United States.
6.2 Legal mechanism. Where required by applicable law, transfers rely on the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Modules 2 (Controller to Processor) and 3 (Processor to Processor), which are incorporated by reference into this DPA. Where required by UK law, we rely on the UK International Data Transfer Addendum to the SCCs.
6.3 EU / UK data residency option. Enterprise customers may request EU-West storage — contact [email protected]. This may affect pricing.
7. Data subject rights
We do not have direct relationships with your data subjects. On written request, we will provide reasonable assistance to help you respond to access, correction, deletion, and portability requests.
8. Security measures
We maintain the technical and organisational measures described on our Security page, currently including:
- TLS 1.3 encryption for data in transit.
- AES-256 encryption for data at rest.
- Argon2id password hashing.
- Multi-factor authentication for administrative access.
- Least-privilege access controls.
- Immutable audit logging of all administrative actions.
- Regular dependency updates and vulnerability scanning.
We may update these measures over time to maintain or improve security; we will not lower the level of protection.
9. Personal Data breach notification
We will notify you at your registered account email within 72 hours of becoming aware of a Personal Data breach affecting Personal Data processed on your behalf. The notification will describe:
- The nature of the breach and the categories and approximate number of data subjects and records concerned.
- The likely consequences.
- The measures taken or proposed to address the breach.
- Contact details for further information.
10. Audit rights
10.1 Documentation. We will make available to you all information necessary to demonstrate compliance with this DPA and the GDPR.
10.2 Audits. You may audit our compliance with this DPA no more than once per year, on 30 days' written notice, during business hours, and subject to a mutually agreed non-disclosure agreement. Where we hold a current independent audit report (e.g., SOC 2), delivery of that report satisfies your audit right for the period covered.
11. Termination
On termination of your subscription, we will delete Personal Data in accordance with the retention periods in the Privacy Policy. If you require earlier deletion, email [email protected]; we complete such requests within 30 days.
12. Governing law
This DPA is governed by the laws of the State of Wyoming, United States, except that the SCCs and UK IDTA are governed by their own choice-of-law provisions.
13. Contact
Data protection questions: [email protected] Legal address: 30 N Gould St, Suite R, Sheridan, WY 82801, United States