Data Processing Agreement
Version 1.0 — 31 May 2026
This Data Processing Agreement ("DPA") forms part of the ReefDesk Terms of Service between ReefDesk ("Processor") and the customer ("Controller"). It governs the processing of Personal Data by ReefDesk on behalf of the Controller in the course of providing the Service, in compliance with Article 28 of Regulation (EU) 2016/679 (GDPR).
Customers who require a signed counterpart can request one at legal@reefdesk.io. Otherwise, by using the Service, the Controller accepts the terms of this DPA.
1. Subject matter & duration
ReefDesk processes Personal Data on behalf of the Controller solely to provide the Service for the duration of the underlying subscription, plus the 90-day post-termination retention period.
2. Nature & purpose of processing
- Reservation and room-assignment management
- Dive scheduling and certification logging
- Guest billing and invoice generation
- Operational reporting and audit logging
3. Categories of data subjects & data
| Data subjects | Personal data categories |
|---|---|
| Guests of the resort | Identity, contact, dates of stay, room number, payments, dive certification level, dive medical declarations (special-category data) |
| Resort staff | Identity, role, login history, audit-log entries |
4. Controller instructions
ReefDesk processes Personal Data only on documented instructions from the Controller, which include the Service configuration and these terms. Any additional instruction must be made in writing.
5. Confidentiality
Personnel authorised to process Personal Data are bound by confidentiality obligations.
6. Security measures (Article 32)
- Per-tenant database isolation (separate database per customer).
- Encryption in transit (TLS 1.2+).
- Encrypted backups at rest.
- Passwords hashed with bcrypt (cost ≥ 12).
- Audit log of all authentication events and privileged actions, retained ≥ 12 months.
- Rate-limited authentication and lead-capture endpoints.
- Least-privilege production access for ReefDesk staff, logged and reviewed quarterly.
- Disaster recovery: daily backups, 7-day retention minimum, RTO ≤ 24 h, RPO ≤ 24 h.
7. Sub-processors
The Controller authorises the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Cloud GmbH | Application hosting | Germany / Finland (EEA) |
| Resend (Plus Five Five, Inc.) | Transactional email | USA (SCCs in place) |
| hCaptcha (Intuition Machines Inc.) | Bot protection on signup | USA (SCCs in place) |
| Stripe Payments Europe Ltd. | Payment processing (when applicable) | Ireland (EEA) |
ReefDesk notifies the Controller of any addition or replacement of sub-processors at least 30 days before the change. The Controller may object on reasonable grounds and, if not resolved, terminate the affected portion of the Service.
8. International data transfers
Transfers to sub-processors outside the EEA are governed by the European Commission's Standard Contractual Clauses (Decision 2021/914), Module 3 (processor-to-processor).
9. Data subject requests
The Controller is responsible for responding to data-subject requests. ReefDesk provides the necessary tools (export, anonymisation, audit) through the in-app Audit & GDPR tab and, on reasonable request, assists with additional cases at no extra cost where the volume is reasonable.
10. Breach notification
ReefDesk notifies the Controller without undue delay and in any event within 72 hours of becoming aware of a Personal Data Breach affecting the Controller's data, providing the information required by Article 33(3) GDPR.
11. Audit rights
Once per year, and at the Controller's expense, the Controller may request a written audit of ReefDesk's compliance, satisfied by sharing the most recent third-party security report or a structured questionnaire response.
12. Deletion / return of data
On termination, the Controller can export the full tenant data via the in-app Audit & GDPR export for 30 days. All Personal Data is then irreversibly deleted within 90 days, except where retention is required by law (e.g. invoicing).
13. Liability & governing law
The liability cap of the Terms of Service applies to this DPA. French law applies; disputes are resolved by the courts of Paris.