All Legal & Policies

Legal

Data Processing Agreement

Published , Last updated

This Data Processing Agreement ("DPA") forms part of the Terms of Use between AWP Marine Consultancy LTD ("we," "our," "us") and the customer ("you"). It sets out how we process personal data on your behalf under UK GDPR and EU GDPR.

This agreement is under review and is published so customers can read it ahead of that review concluding. Tell us at support@awpmarine.com if anything here does not work for you.

Definitions

Controller, processor, personal data, processing, personal data breach and supervisory authority carry the meanings given to them in UK GDPR.

UK GDPR means the retained EU General Data Protection Regulation as it forms part of the law of England and Wales, Scotland and Northern Ireland, together with the Data Protection Act 2018. EU GDPR means Regulation (EU) 2016/679. Data protection law means whichever of these applies to the processing in question.

Subprocessor means a third party we engage to process personal data on your behalf.

When We Are a Processor, and When We Are Not

We do two different kinds of work, and the law treats them differently. This DPA covers only the first.

We act as your processor when we:

  • Hold your organisation's contacts, users and their accounts
  • Store documents you upload to the platform
  • Pass messages between you and the inspectors assigned to your work

We act as a controller in our own right when we:

  • Conduct an inspection and decide what is observed, recorded and reported
  • Retain reports and supporting material as evidence of work performed
  • Issue invoices and keep accounting records, which UK law requires us to do
  • Assess travel risk and look up vessel data to plan and carry out our work

Where we act as a controller, our Privacy Policy governs instead of this DPA. Where the same record serves both purposes, this DPA applies to our handling of it on your behalf, and our own obligations as a controller continue alongside.

Your Responsibilities

As controller of the personal data we process for you, you are responsible for:

  • Having a lawful basis for the processing you instruct
  • Giving the people whose data you upload the information they are entitled to
  • Making sure your instructions, and the data you put into the platform, comply with data protection law
  • Keeping your users' accounts and access rights current, and removing people who should no longer have access

We are not responsible for deciding whether your processing is lawful, and we do not review the content of what you upload.

Processing Details

Subject matter: provision of the platform described in the Terms of Use.

Duration: for as long as your account exists, plus any retention period set out in section 10.

Nature and purpose: hosting, storage, transmission and coordination of inspection work.

Types of personal data: names, email addresses, telephone numbers, job titles, profile pictures, authentication credentials, session and device information, and any personal data contained in documents you upload.

Categories of data subject: your staff and representatives, inspectors assigned to your work, and individuals named in inspection material, which may include vessel crew.

Our Instructions From You

We process personal data only on your documented instructions, including in relation to transfers outside the UK or EEA, unless we are required to do otherwise by law. Where the law requires it, we will tell you before processing unless the law forbids us from doing so.

Your instructions consist of the Terms of Use, this DPA, and your use of the platform's features.

We will tell you if, in our opinion, an instruction infringes data protection law. We may decline to act on an instruction that would put us in breach.

Confidentiality

Everyone we authorise to process personal data is bound by a duty of confidence, whether by contract of employment, engagement terms, or a written undertaking. We limit access to those who need it to do their work.

Security

We implement appropriate technical and organisational measures under Article 32, including:

  • Passwords stored using a one-way hashing function, and support for passkeys
  • Encryption in transit using HTTPS/TLS, and encryption at rest
  • Role-based access control, with access limited to what each role needs
  • Logging of access and administrative action
  • Backups held in a separate protected vault, with restoration tested
  • Multi-factor authentication available on accounts

We review these measures as the platform changes. We may update them, provided the level of protection does not fall.

Subprocessors

You give us general written authorisation to engage subprocessors. The current list is published at Subprocessors, which serves as the register for the purposes of this DPA.

We will give you at least 30 days' notice before a new subprocessor begins processing, by email or through the platform. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative. If we cannot, you may terminate the affected services without penalty, and we will refund any fees paid for services not delivered.

We impose data protection obligations on each subprocessor no less protective than those in this DPA, and we remain liable to you for their performance.

Inspectors are engaged around the world. An individual inspector engaged under our terms acts under our authority as personnel rather than as a subprocessor, and is bound by the confidentiality duty in section 6. A company we subcontract inspection work to is a subprocessor, and is covered by this section like any other.

We do not publish the names of those companies, because our agreements with them are confidential, and the published list covers the technology services behind the platform rather than the firms we work with. We will identify the subcontractors involved in your work on request, in writing and under confidentiality. Your right to notice and to object under this section applies to them exactly as it does to a named subprocessor.

Helping You Meet Your Obligations

Data subject rights. The platform lets people update their name, profile picture and telephone number, manage their passkeys, and view and revoke their sessions. Where a request reaches us instead of you, we will pass it on rather than answer it, unless you tell us otherwise. We will help you respond, taking into account what the platform makes available.

Personal data breaches. We will notify you without undue delay, and in any event within 48 hours of becoming aware of a breach affecting your personal data. Our notice will describe what happened, the categories and approximate number of records involved, the likely consequences, and the steps taken.

Impact assessments. We will provide reasonable assistance with data protection impact assessments and prior consultation with a supervisory authority, so far as they relate to our processing on your behalf.

Deletion and Return

On request during the term, or on termination, we will delete or return the personal data we process on your behalf, and delete existing copies.

We will keep records where the law requires it, or where they are evidence of work performed. In practice this means:

  • Accounting records, including invoices and expenses, kept for six years under UK law
  • Inspection reports and supporting material, kept as the record of an inspection we carried out and as evidence in the event of a dispute or claim

Anything retained under this section stays subject to the security and confidentiality terms above, and we process it for no other purpose. Individual account deletion is described at Delete Your Account.

International Transfers

Most personal data is processed in the UK and EU. Some subprocessors process in the United States, and AI processing may take place in other regions, as set out in the Subprocessors list.

Our inspectors and subcontractors work worldwide, including in countries with no UK or EU adequacy decision. They access personal data through the platform to carry out the work you commission, under the confidentiality and access controls in sections 6 and 7.

Where personal data leaves the UK or EEA, whether to a subprocessor or to our own personnel, we rely on the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum, and on transfer risk assessments where required. Those terms are incorporated into this DPA and take precedence over it if they conflict.

Audits

We will make available the information reasonably needed to demonstrate compliance with this DPA.

You may request that information once in any twelve-month period, in writing, and we will respond within 30 days. Where that is genuinely insufficient, you may audit us on site with at least 30 days' notice, during business hours, in a manner that does not disrupt our work, and at your cost. You may appoint an independent auditor who is not a competitor of ours, subject to confidentiality.

If a supervisory authority requires an audit, this section does not limit it.

California

Where the California Consumer Privacy Act applies to personal information you provide, we act as a service provider. We do not sell or share it, we do not retain, use or disclose it for any purpose other than performing the services in the Terms of Use, and we do not combine it with personal information obtained elsewhere except as that Act permits. We will tell you if we can no longer meet these obligations.

Liability, Term and Precedence

Liability under this DPA is subject to the limitations in the Terms of Use.

This DPA takes effect when you accept the Terms of Use and continues while we process personal data on your behalf. If any part of it conflicts with the Terms of Use, this DPA governs in respect of personal data.

This DPA is the agreement we work to. Where you require your own data processing terms, we will consider them, and any we accept must be signed by us to take effect; until then this DPA applies. Where signed terms and this DPA cover the same point, the signed terms govern.

This DPA is governed by the law of England and Wales, and subject to the jurisdiction set out in the Terms of Use.

Changes to This Agreement

We may update this DPA as the platform or the law changes, provided the change does not reduce the protection it gives you. We will give at least 30 days' notice of a material change, by email or through the platform, and the current version is always published here.

Contact

For anything under this agreement, email support@awpmarine.com. For security matters, email security@awpmarine.com.