Data Processing Agreement
Version 1.1 — Effective date: 15 March 2026
This DPA is incorporated into the Marine Inspect Terms & Conditions and governs how we process personal data on your behalf as your data processor (UK GDPR Art. 28).
This Data Processing Agreement ("DPA") is incorporated into the Terms & Conditions between Near Max Ltd ("Processor") and the individual or entity using Marine Inspect ("Controller"). By accepting the Terms & Conditions, you also accept this DPA. It governs the processing of personal data by the Processor on behalf of the Controller, as required by UK GDPR Article 28.
1. Definitions
| Term | Meaning |
|---|---|
| UK GDPR | UK General Data Protection Regulation (retained EU law as amended by the Data Protection Act 2018) |
| Personal Data | Any information relating to an identified or identifiable natural person |
| Controller | The user or entity that determines the purposes and means of processing (i.e., the marine surveyor using Marine Inspect) |
| Processor | Near Max Ltd, trading as Marine Inspect, which processes personal data on behalf of the Controller |
| Sub-processor | Any third party appointed by the Processor to process personal data on behalf of the Controller |
| Processing | Any operation performed on personal data, including collection, storage, retrieval, transmission, and deletion |
| Service | The Marine Inspect web portal and mobile application |
2. Subject Matter, Duration, Nature and Purpose
Subject matter: The Processor provides a marine survey management platform. In using this platform, the Controller may enter, store, and process personal data belonging to third parties — in particular, vessel owners and clients.
Duration: This DPA remains in force for the term of the Controller's account with Marine Inspect and expires upon account deletion or termination, subject to any applicable retention obligations under clause 8.
Nature and purpose of processing: The Processor will process personal data solely to provide the Service to the Controller. This includes:
- Storing survey data, photographs, voice notes, and inspection records entered by the Controller
- Making stored data accessible to the Controller through the web portal and mobile application
- Transmitting selected survey content to AI processing services to generate draft report text, as directed by the Controller
- Generating and storing PDF reports incorporating the submitted data
- Providing backup and recovery capabilities
Instructions: The Processor shall process personal data only on the documented instructions of the Controller. The Controller's use of the Service (including what data they enter and what reports they generate) constitutes such instructions.
3. Types of Personal Data and Categories of Data Subjects
The personal data processed under this DPA may include:
Types of personal data:
- Names and contact details (address, telephone number, email address)
- Vessel details that may be linked to identifiable individuals
- Photographs, which may incidentally capture persons
- Location data (GPS coordinates recorded during inspections)
- Survey observations, defect notes, and inspection findings that may reference identifiable individuals
- Any other information the Controller chooses to enter into the Service
Categories of data subjects:
- Vessel owners and registered keepers
- Third parties mentioned in survey notes or defect records
- Incidental data subjects captured in survey photographs
The types and categories of data processed depend entirely on what the Controller enters into the Service. The Processor does not determine, verify, or limit what personal data the Controller submits.
4. Obligations of the Processor
The Processor shall:
4.1 Process personal data only on documented instructions from the Controller (as described in clause 2) and shall inform the Controller if any instruction infringes UK GDPR or other applicable data protection law, unless prohibited from doing so by law.
4.2 Ensure that persons authorised to process personal data are bound by appropriate confidentiality obligations.
4.3 Implement and maintain appropriate technical and organisational security measures to protect personal data against accidental or unlawful destruction, loss, alteration, or unauthorised disclosure — in accordance with UK GDPR Article 32. Current measures include:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256 via AWS)
- Access controls and authentication (Clerk identity management)
- Activity logging and monitoring
- Regular security reviews
4.4 Assist the Controller, to the extent technically feasible, in fulfilling the Controller's obligations to respond to data subject requests under Chapter III of UK GDPR. The Controller may export their data at any time via the Settings page, and account closure (including removal of the Controller's personal account data) is available via the Settings page or by contacting support@marine-inspect.co.uk.
4.5 Assist the Controller in ensuring compliance with security obligations (Art. 32), data breach notification (Arts. 33–34), data protection impact assessments (Art. 35), and prior consultation (Art. 36).
4.6 On account deletion, delete or anonymise personal data as described in clause 8, unless storage is required by UK law or is otherwise permitted under this DPA.
4.7 Make available to the Controller all information necessary to demonstrate compliance with this DPA and permit audits, including inspections, conducted by the Controller or an auditor mandated by the Controller. Such audits must be requested in writing with at least 30 days' notice, conducted during business hours, and carried out in a manner that minimises disruption to the Processor's business.
4.8 Notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, to the extent permitted by law.
5. Sub-processors
The Controller grants the Processor general authorisation to engage sub-processors. The Processor's current sub-processors are:
| Sub-processor | Role | Location | Legal basis for transfer |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, database, and file storage | UK (eu-west-2, London) | No transfer outside UK |
| Anthropic, PBC | AI-assisted report text generation | USA | UK IDTA / SCCs |
| Clerk, Inc. | User authentication and identity management | USA | UK IDTA / SCCs |
| Stripe, Inc. | Payment processing | USA | UK IDTA / SCCs |
| PostHog, Inc. | Product analytics and usage tracking | Germany, EU (Frankfurt) | UK IDTA / SCCs |
UK IDTA = UK International Data Transfer Agreement. SCCs = Standard Contractual Clauses.
The Processor shall:
- Impose data protection obligations on each sub-processor no less protective than those in this DPA
- Remain liable to the Controller for the acts and omissions of sub-processors
The Processor will notify the Controller of any intended changes to sub-processors (additions or replacements) by publishing an updated version of this DPA and by bumping the Terms & Conditions version, which will trigger the in-app re-acceptance flow. The Controller has the right to terminate their account within 14 days of such notice if they object to the change.
6. International Data Transfers
Survey and account data are stored in AWS eu-west-2 (London) and do not leave the UK under normal operation. However, survey content submitted for AI-assisted report generation is transmitted to Anthropic (USA). This transfer is covered by appropriate safeguards (UK IDTA or SCCs). By generating reports within the Service, the Controller instructs the Processor to make this transfer. Usage analytics events are also transmitted to PostHog, Inc. (Germany, EU) for product analytics. This transfer is covered by UK IDTA. PostHog processes only anonymised interaction events; it does not receive survey content or personal data belonging to the Controller's clients.
7. Controller's Obligations
The Controller acknowledges and agrees that:
7.1 The Controller is the Data Controller for personal data belonging to their clients, vessel owners, and other third parties entered into the Service.
7.2 The Controller must have a valid lawful basis under UK GDPR Art. 6 (and Art. 9 where special category data is involved) before entering any personal data into the Service.
7.3 The Controller is responsible for providing appropriate privacy notices to their clients, informing them that their data may be processed using Marine Inspect.
7.4 The Controller is responsible for responding to data subject access requests, erasure requests, and other rights requests from their own clients. The Processor will assist as described in clause 4.4.
7.5 The Controller must not enter special category data (as defined in UK GDPR Art. 9) into the Service unless they have a lawful basis to do so and have complied with all applicable requirements.
8. Data Handling on Account Closure
Upon account deletion:
8.1 The Processor will promptly delete the following personal data associated with the account:
- Account authentication data (held by Clerk, Inc.)
- Professional profile data (company name, address, contact details, qualifications, logo, signature)
- Billing and credit records
- Support correspondence (issue reports and messages)
- Report generation audit records
8.2 Survey and inspection records will be retained by the Processor in anonymised form (with all personally identifiable fields removed from the survey record, including owner contact details, surveyor profile data, and account identifiers) for a period of 7 years from the date of each survey. Such retained records cannot be linked back to the Controller or any identifiable individual. This retention is necessary for professional liability purposes, potential legal proceedings, and compliance with applicable law, and is based on the Processor's legal obligations and legitimate interests under UK GDPR Art. 17(3)(b) and (e). Anonymised survey records cannot be deleted on request.
8.3 In the event of planned discontinuation of the Service, the Processor will give the Controller not less than 90 days' written notice. During this period the Controller's data export function will remain operational. The Controller is solely responsible for exporting and independently retaining their own professional records before service termination. The Processor accepts no liability for any loss arising from the Controller's failure to do so. Following expiry of the notice period, the Processor will carry out the deletions and anonymisation described in clauses 8.1 and 8.2 above.
8.4 The following categories are subject to statutory retention periods and will be retained notwithstanding account closure:
- Financial and transaction records: 7 years (Companies Act 2006)
- Terms and DPA acceptance records: 6 years after account closure
8.5 The Controller may export all their data at any time before account closure using the export function in the Settings page.
8.6 Account deletion can be initiated at any time through the Settings page or by emailing support@marine-inspect.co.uk. Deletion is irreversible.
8.7 Report verification records are generated by the Processor as part of its own verification infrastructure and are not survey content subject to this DPA. When the Controller approves a report, the Processor writes a verification record containing: the Controller's professional name, the vessel name and type, the survey date, cryptographic hashes of the survey and report, the approval timestamp, and the Controller's email address (used as a second-factor identity check in the public verification system). This record is held under Near Max Ltd's own data controllership — the Controller is not the data controller for these records. Verification records persist after account closure for 7 years from the date of report approval and are not subject to deletion on account closure or erasure request. Full details are set out in the Privacy Policy §7.
9. Contact
For DPA queries, data subject assistance requests, or to request an audit:
Near Max Ltd (trading as Marine Inspect) Company No. 09222812, England and Wales Email: support@marine-inspect.co.uk
10. Governing Law
This DPA is governed by the laws of England and Wales. Any disputes arising under or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of England and Wales.
11. Changes to This DPA
Near Max Ltd may update this DPA from time to time. Material changes will be communicated by bumping the Terms & Conditions version, which triggers the in-app re-acceptance flow for all users. The current version is always available at marine-inspect.co.uk/dpa.
Questions about this DPA? Contact us at support@marine-inspect.co.uk
