Data processing agreement
Last updated 27 September 2026. Part of the terms of service, and applies automatically with no separate signature.
Parties: the Customer (the controller) and Adryn Ltd, company 17308893 (the processor).
1. Subject, duration, nature and purpose
- Subject: providing VesselOverview to the Customer.
- Duration: the subscription, plus the return-and-delete period in clause 9.
- Nature: storing, hosting, displaying and backing up data the Customer's users enter.
- Purpose: running the vessel's day-to-day operations, as the Customer chooses to use the Service.
2. Data subjects and personal data
Data subjects: the Customer's crew, officers and shore staff who use the Service, and other crew, guests and contacts the Customer records.
Personal data: names, email addresses, roles and departments, cabin and berth assignments, watch and duty assignments, entries in operational logs, vessel contact details, and any other free text users enter.
Special category data: none is intended. The Customer must not enter health or other special category data unless it has a lawful basis for doing so.
3. Adryn's obligations
Adryn will:
- process the personal data only on the Customer's documented instructions, unless the law requires otherwise. These terms and the Customer's use of the Service are those instructions. Where the law requires otherwise, Adryn will tell the Customer first if the law allows;
- ensure everyone authorised to process it is bound by confidentiality;
- apply the security measures in clause 5;
- use sub-processors only under clause 6;
- help the Customer answer requests from people exercising their data protection rights, taking account of the nature of the processing;
- help the Customer with security, breach notification, data protection impact assessments and consultation with the Information Commissioner's Office;
- return or delete the data at the end, under clause 9;
- make available the information needed to show compliance, and allow reasonable audits, normally by written questionnaire, at most once a year unless there has been a breach.
4. Personal data breaches
Adryn will notify the Customer without undue delay, and in any case within 48 hours of becoming aware of a breach affecting the Customer's personal data. The notice will say what is known and what is being done about it.
5. Security measures
- Data is stored in a managed Postgres database in Frankfurt (EU), and application requests are processed in Frankfurt.
- Each vessel is separated from every other by row-level security enforced inside the database. The account that serves requests cannot bypass it.
- Connections are encrypted in transit, and the database provider encrypts data at rest.
- Sign-in uses single-use email links that expire after 60 minutes, with no passwords. Sessions end after at most 180 days. Removing a user from a vessel ends their access to it immediately.
- Only named Adryn operators can access Customer Data, and only to support and run the Service. Changes they make are recorded under their own names in the vessel's change log.
- Backups are taken daily and kept for 7 days.
6. Sub-processors
The Customer authorises the sub-processors below. Adryn will give at least 30 days' notice of a new sub-processor, by email to the administrator. The Customer may object on reasonable data protection grounds. If the objection cannot be resolved, the Customer may cancel without penalty. Adryn remains responsible for its sub-processors.
| Sub-processor | Service | Where |
|---|---|---|
| Supabase | Database hosting | Frankfurt, Germany |
| Vercel | Application hosting | Frankfurt, Germany |
| Resend | Sign-in emails | Ireland |
| Stripe | Payments (billing contact only, not crew data) | UK / EU |
7. International transfers
Customer Data is stored and processed in the EU, which the UK recognises as adequate. Where a sub-processor may access data from outside the UK or EU, the transfer is protected by the safeguards in that provider's own data processing terms. Those are the UK International Data Transfer Addendum, or the UK Extension to the EU-US Data Privacy Framework.
8. The Customer's obligations
The Customer confirms that it has a lawful basis for the personal data it enters, and that it has told its crew and other people concerned that it uses the Service.
9. Return and deletion
At the end of the subscription, and on request within 30 days, Adryn will send a copy of the Customer's data in CSV or JSON. There is no self-service export in the product yet, so this is done by request. Adryn then deletes the data. Backup copies expire within 7 days. Data that Adryn must keep by law, such as invoices, is kept only for that purpose.
10. Precedence
If this agreement conflicts with the terms of service on the protection of personal data, this agreement prevails.
Questions: support@adryn.co.