Data Processing Agreement

Version 1.2 — Effective date: 14 September 2026

This DPA is incorporated into the Marine Inspect Terms & Conditions and governs how we process personal data on your behalf as your data processor (UK GDPR Art. 28).

This Data Processing Agreement ("DPA") is incorporated into the Terms & Conditions between Near Max Ltd ("Processor") and the individual or entity using Marine Inspect ("Controller"). By accepting the Terms & Conditions, you also accept this DPA. It governs the processing of personal data by the Processor on behalf of the Controller, as required by UK GDPR Article 28.


1. Definitions

Term Meaning
UK GDPR UK General Data Protection Regulation (retained EU law as amended by the Data Protection Act 2018)
Personal Data Any information relating to an identified or identifiable natural person
Controller The user or entity that determines the purposes and means of processing (the surveyor, surveying firm or organisation, such as a Certifying Authority, using Marine Inspect)
Processor Near Max Ltd, trading as Marine Inspect, which processes personal data on behalf of the Controller
Sub-processor Any third party appointed by the Processor to process personal data on behalf of the Controller
Processing Any operation performed on personal data, including collection, storage, retrieval, transmission, and deletion
Service The Marine Inspect web portal and mobile application

Certifying Authority, Coding Survey and Documentation of Compliance have the meanings given in the Terms & Conditions.


2. Subject Matter, Duration, Nature and Purpose

Subject matter: The Processor provides a marine survey management platform. In using this platform, the Controller may enter, store, and process personal data belonging to third parties — in particular, vessel owners and clients.

Duration: This DPA remains in force for the term of the Controller's account with Marine Inspect and expires upon account deletion or termination, subject to any applicable retention obligations under clause 8.

Nature and purpose of processing: The Processor will process personal data only to provide the Service to the Controller and for the purposes listed below. This includes:

  • Storing survey data, photographs, voice notes, and inspection records entered by the Controller
  • Making stored data accessible to the Controller through the web portal and mobile application
  • Transmitting selected survey content to AI processing services to generate draft report text, as directed by the Controller
  • Generating and storing PDF reports incorporating the submitted data
  • Providing backup and recovery capabilities
  • Sending survey content to the Certifying Authority the Controller selects, and giving that authority access to it
  • Collecting the vessel owner's declaration on the Controller's behalf, including evidence of the owner's electronic signature
  • Hosting an organisation's roster and scrutiny records
  • Opening records when needed to investigate and fix an operational issue
  • Creating anonymised data from the Controller's data. The Controller authorises this. Once anonymised, the data is no longer personal data, and the Processor may use it in its own products and services as clause 9.5 of the Terms & Conditions sets out.

Instructions: The Processor shall process personal data only on the documented instructions of the Controller. The Controller's use of the Service (including what data they enter and what reports they generate) constitutes such instructions.


3. Types of Personal Data and Categories of Data Subjects

The personal data processed under this DPA may include:

Types of personal data:

  • Names and contact details (address, telephone number, email address)
  • Vessel details that may be linked to identifiable individuals
  • Photographs, which may incidentally capture persons
  • Location data (GPS coordinates recorded during inspections)
  • Survey observations, defect notes, and inspection findings that may reference identifiable individuals
  • Evidence of an electronic signature (typed name, the email address a form was sent to, IP address, time)
  • Any other information the Controller chooses to enter into the Service

Categories of data subjects:

  • Vessel owners and registered keepers
  • Third parties mentioned in survey notes or defect records
  • Incidental data subjects captured in survey photographs
  • Surveyors listed on a Certifying Authority's roster
  • Staff of an organisation using the Service

The types and categories of data processed depend entirely on what the Controller enters into the Service. The Processor does not determine, verify, or limit what personal data the Controller submits.


4. Obligations of the Processor

The Processor shall:

4.1 Process personal data only on documented instructions from the Controller (as described in clause 2) and shall inform the Controller if any instruction infringes UK GDPR or other applicable data protection law, unless prohibited from doing so by law.

4.2 Ensure that persons authorised to process personal data are bound by appropriate confidentiality obligations.

4.3 Implement and maintain appropriate technical and organisational security measures to protect personal data against accidental or unlawful destruction, loss, alteration, or unauthorised disclosure — in accordance with UK GDPR Article 32. Current measures include:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256 via AWS)
  • Access controls and authentication (Clerk identity management)
  • Activity logging and monitoring
  • Regular security reviews

4.4 Assist the Controller, to the extent technically feasible, in fulfilling the Controller's obligations to respond to data subject requests under Chapter III of UK GDPR. The Controller may export their data at any time via the Settings page, and account closure (including removal of the Controller's personal account data) is available via the Settings page or by contacting support@marine-inspect.co.uk.

4.5 Assist the Controller in ensuring compliance with security obligations (Art. 32), data breach notification (Arts. 33–34), data protection impact assessments (Art. 35), and prior consultation (Art. 36).

4.6 On account deletion, delete or retain personal data as described in clause 8, unless storage is required by UK law or is otherwise permitted under this DPA.

4.7 Make available to the Controller all information necessary to demonstrate compliance with this DPA and permit audits, including inspections, conducted by the Controller or an auditor mandated by the Controller. Such audits must be requested in writing with at least 30 days' notice, conducted during business hours, and carried out in a manner that minimises disruption to the Processor's business.

4.8 Notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, to the extent permitted by law.


5. Sub-processors

The Controller grants the Processor general authorisation to engage sub-processors. The Processor's current sub-processors are:

Sub-processor Role Location Legal basis for transfer
Amazon Web Services (AWS) Cloud infrastructure, database, and file storage UK (eu-west-2, London) No transfer outside UK
Anthropic, PBC AI-assisted report text generation USA UK IDTA / SCCs
Clerk, Inc. User authentication and identity management USA UK IDTA / SCCs
Stripe, Inc. Payment processing USA UK IDTA / SCCs
PostHog, Inc. Product analytics and usage tracking Germany, EU (Frankfurt) UK IDTA / SCCs
Functional Software, Inc. (Sentry) Crash reporting for the mobile application Germany, EU UK IDTA / SCCs

UK IDTA = UK International Data Transfer Agreement. SCCs = Standard Contractual Clauses.

The Processor shall:

  • Impose data protection obligations on each sub-processor no less protective than those in this DPA
  • Remain liable to the Controller for the acts and omissions of sub-processors

The Processor will notify the Controller of any intended changes to sub-processors (additions or replacements) by publishing an updated version of this DPA and by bumping the Terms & Conditions version, which will trigger the in-app re-acceptance flow. The Controller has the right to terminate their account within 14 days of such notice if they object to the change.


6. International Data Transfers

Survey and account data are stored in AWS eu-west-2 (London) and do not leave the UK under normal operation. However, survey content submitted for AI-assisted report generation is transmitted to Anthropic (USA). This transfer is covered by appropriate safeguards (UK IDTA or SCCs). By generating reports within the Service, the Controller instructs the Processor to make this transfer. Usage analytics events are also transmitted to PostHog, Inc. (Germany, EU) for product analytics. This transfer is covered by UK IDTA. PostHog receives interaction events linked to the user's account. It does not receive survey content or personal data belonging to the Controller's clients. Crash reports from the mobile application are sent to Sentry and stored in the EU. They carry no account identity.


7. Controller's Obligations

The Controller acknowledges and agrees that:

7.1 The Controller is the Data Controller for personal data belonging to their clients, vessel owners, and other third parties entered into the Service.

7.2 The Controller must have a valid lawful basis under UK GDPR Art. 6 (and Art. 9 where special category data is involved) before entering any personal data into the Service.

7.3 The Controller is responsible for providing appropriate privacy notices to their clients, informing them that their data may be processed using Marine Inspect. This includes telling them that a survey may be sent to a Certifying Authority for certification, and that data may be used in anonymised form.

7.4 The Controller is responsible for responding to data subject access requests, erasure requests, and other rights requests from their own clients. The Processor will assist as described in clause 4.4.

7.5 The Controller must not enter special category data (as defined in UK GDPR Art. 9) into the Service unless they have a lawful basis to do so and have complied with all applicable requirements.


8. Data Handling on Account Closure

Upon account deletion:

8.1 The Processor will promptly delete the following personal data associated with the account:

  • Account authentication data (held by Clerk, Inc.)
  • Professional profile data (company name, address, contact details, qualifications, logo, signature)
  • Billing and credit records
  • Support correspondence (issue reports and messages)
  • Report generation audit records
  • Questions asked of Beacon, the guidance assistant

8.2 Survey and inspection records will be retained by the Processor for 7 years from the date of each survey, with owner contact details and survey location removed. Coding Surveys with an approved Documentation of Compliance are retained whole for the same period, because a Certifying Authority may rely on them. This retention is necessary for professional liability purposes, potential legal proceedings, and compliance with applicable law, and is based on the Processor's legal obligations and legitimate interests under UK GDPR Art. 17(3)(b) and (e). These records cannot be deleted on request. Clause 8.8 applies to Coding Surveys sent to a Certifying Authority.

8.3 In the event of planned discontinuation of the Service, the Processor will give the Controller not less than 90 days' written notice. During this period the Controller's data export function will remain operational. The Controller is solely responsible for exporting and independently retaining their own professional records before service termination. The Processor accepts no liability for any loss arising from the Controller's failure to do so. Following expiry of the notice period, the Processor will carry out the deletions and retention described in clauses 8.1, 8.2 and 8.8 above.

8.4 The following categories are subject to statutory retention periods and will be retained notwithstanding account closure:

  • Financial and transaction records: 7 years (Companies Act 2006)
  • Terms and DPA acceptance records: 6 years after account closure

8.5 The Controller may export all their data at any time before account closure using the export function in the Settings page.

8.6 Account deletion can be initiated at any time through the Settings page or by emailing support@marine-inspect.co.uk. Deletion is irreversible.

8.7 Report verification records are generated by the Processor as part of its own verification infrastructure and are not survey content subject to this DPA. When the Controller approves a report, the Processor writes a verification record containing: the Controller's professional name, the vessel name and type, the survey date, cryptographic hashes of the survey and report, the approval timestamp, and the Controller's email address (used as a second-factor identity check in the public verification system). This record is held under Near Max Ltd's own data controllership — the Controller is not the data controller for these records. For a Documentation of Compliance the record also holds the vessel's area category and use type, the Certifying Authority named on it, the certification recommendation and the number of deficiencies. Where a Certifying Authority approves a later version, the record notes which version superseded it and when. Verification records persist after account closure for 7 years from the date of report approval and are not subject to deletion on account closure or erasure request. Full details are set out in the Privacy Policy §7.

8.8 Where the Controller has sent a Coding Survey to a Certifying Authority through the Service, and has not withdrawn it, the survey, its reports, its submission history and the Controller's professional details and signature as they appear on them are kept whole for that authority after the Controller's account closes. The authority is responsible for its own record. The Processor holds these records for the authority until the authority's agreement with the Processor ends, then returns them to the authority and deletes them.


9. Contact

For DPA queries, data subject assistance requests, or to request an audit:

Near Max Ltd (trading as Marine Inspect) Company No. 09222812, England and Wales Email: support@marine-inspect.co.uk


10. Governing Law

This DPA is governed by the laws of England and Wales. Any disputes arising under or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of England and Wales.


11. Changes to This DPA

Near Max Ltd may update this DPA from time to time. Material changes will be communicated by bumping the Terms & Conditions version, which triggers the in-app re-acceptance flow for all users. The current version is always available at marine-inspect.co.uk/dpa.

Questions about this DPA? Contact us at support@marine-inspect.co.uk