Data Processing Agreement

Version 1.0 — 31 May 2026

This Data Processing Agreement ("DPA") forms part of the ReefDesk Terms of Service between ReefDesk ("Processor") and the customer ("Controller"). It governs the processing of Personal Data by ReefDesk on behalf of the Controller in the course of providing the Service, in compliance with Article 28 of Regulation (EU) 2016/679 (GDPR).

Customers who require a signed counterpart can request one at legal@reefdesk.io. Otherwise, by using the Service, the Controller accepts the terms of this DPA.

1. Subject matter & duration

ReefDesk processes Personal Data on behalf of the Controller solely to provide the Service for the duration of the underlying subscription, plus the 90-day post-termination retention period.

2. Nature & purpose of processing

3. Categories of data subjects & data

Data subjectsPersonal data categories
Guests of the resortIdentity, contact, dates of stay, room number, payments, dive certification level, dive medical declarations (special-category data)
Resort staffIdentity, role, login history, audit-log entries

4. Controller instructions

ReefDesk processes Personal Data only on documented instructions from the Controller, which include the Service configuration and these terms. Any additional instruction must be made in writing.

5. Confidentiality

Personnel authorised to process Personal Data are bound by confidentiality obligations.

6. Security measures (Article 32)

7. Sub-processors

The Controller authorises the following sub-processors:

Sub-processorPurposeLocation
Hetzner Cloud GmbHApplication hostingGermany / Finland (EEA)
Resend (Plus Five Five, Inc.)Transactional emailUSA (SCCs in place)
hCaptcha (Intuition Machines Inc.)Bot protection on signupUSA (SCCs in place)
Stripe Payments Europe Ltd.Payment processing (when applicable)Ireland (EEA)

ReefDesk notifies the Controller of any addition or replacement of sub-processors at least 30 days before the change. The Controller may object on reasonable grounds and, if not resolved, terminate the affected portion of the Service.

8. International data transfers

Transfers to sub-processors outside the EEA are governed by the European Commission's Standard Contractual Clauses (Decision 2021/914), Module 3 (processor-to-processor).

9. Data subject requests

The Controller is responsible for responding to data-subject requests. ReefDesk provides the necessary tools (export, anonymisation, audit) through the in-app Audit & GDPR tab and, on reasonable request, assists with additional cases at no extra cost where the volume is reasonable.

10. Breach notification

ReefDesk notifies the Controller without undue delay and in any event within 72 hours of becoming aware of a Personal Data Breach affecting the Controller's data, providing the information required by Article 33(3) GDPR.

11. Audit rights

Once per year, and at the Controller's expense, the Controller may request a written audit of ReefDesk's compliance, satisfied by sharing the most recent third-party security report or a structured questionnaire response.

12. Deletion / return of data

On termination, the Controller can export the full tenant data via the in-app Audit & GDPR export for 30 days. All Personal Data is then irreversibly deleted within 90 days, except where retention is required by law (e.g. invoicing).

13. Liability & governing law

The liability cap of the Terms of Service applies to this DPA. French law applies; disputes are resolved by the courts of Paris.

Request a signed countersignature →