Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the agreement between the Customer and FRANCISCO GARRIDO PAULO - UNIPESSOAL LDA (“MYACHT”) governing the provision of the MYACHT platform. It reflects the parties’ obligations under the EU General Data Protection Regulation (“GDPR”), Regulation (EU) 2016/679.
Version 1.0 · Effective date: 8 July 2026
1. Definitions
Capitalised terms have the meanings given below. Terms not defined here have the meanings given in the GDPR.
- “Customer” means the entity that has entered into a subscription agreement with MYACHT for the use of the Service.
- “Customer Personal Data” means Personal Data uploaded to, generated within, or processed by the Service on behalf of the Customer.
- “Service” means the MYACHT yacht operations and maintenance platform, comprising the mobile applications and backend infrastructure operated by MYACHT.
- “Sub-processor” means any third party engaged by MYACHT to process Customer Personal Data. The current list is maintained at myachtsystems.com/sub-processors.
2. Roles of the parties
For Customer Personal Data processed by MYACHT under the subscription agreement, the Customer is the Controller and MYACHT is the Processor. Where the Customer is acting on behalf of another Controller (for example, a yacht owner or management company acting on behalf of a vessel), the Customer represents that it has the authority to instruct MYACHT on that Controller’s behalf.
3. Subject matter, duration, and purpose
Subject matter: processing of Customer Personal Data as necessary to provide the Service.
Duration: for the term of the subscription agreement, plus any post-termination period required to return or delete Customer Personal Data.
Purpose: to enable Customer’s use of the Service for vessel operations, maintenance, compliance, crew management, and related functions.
Nature of processing: storage, retrieval, organisation, transmission, backup, deletion.
Categories of data subjects: Customer’s personnel, crew members, contractors, visitors, and any other natural persons whose data the Customer uploads to the Service.
Categories of Personal Data: identification data, contact data, professional qualifications and certificates, work-rest hours, sea-time records, and (where the Customer configures it) references to medical fitness certificates as special-category data under GDPR Article 9. Full detail in Privacy Policy §2.
4. Customer instructions
MYACHT will process Customer Personal Data only on documented instructions from the Customer, including with regard to transfers of Personal Data to a third country. The subscription agreement, this DPA, and the Customer’s use of the Service constitute the Customer’s complete instructions.
If applicable law requires MYACHT to process Customer Personal Data otherwise, MYACHT will inform the Customer before processing unless that law prohibits such notice on grounds of public interest.
5. Confidentiality
MYACHT ensures that persons authorised to process Customer Personal Data are bound by written confidentiality obligations or are under an appropriate statutory obligation of confidentiality.
6. Security
MYACHT implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption in transit (TLS 1.2 or higher) and at rest
- Hashed and salted password storage; no plaintext access
- Role-based access control within Customer accounts
- Least-privilege access for MYACHT operational personnel
- Regular dependency updates and security patching
- Sub-processor due diligence and contractual obligations
- Audit logging of administrative and privileged access to the production environment
Detail of the security posture is published at myachtsystems.com/security.
7. Sub-processors
The Customer generally authorises MYACHT to engage Sub-processors for the provision of the Service, subject to the terms of this section.
The current list of Sub-processors is maintained at myachtsystems.com/sub-processors. MYACHT will give the Customer notice of any intended addition or replacement of a Sub-processor no less than thirty (30) days before the change takes effect, by updating that page and (where the Customer has requested notification) by email.
If the Customer reasonably objects to a proposed Sub-processor on data-protection grounds, the parties will discuss the objection in good faith. If the objection cannot be resolved, either party may terminate the affected part of the Service, without penalty for the Customer.
MYACHT remains liable for the acts and omissions of its Sub-processors as if they were MYACHT’s own.
8. International transfers
MYACHT primarily hosts Customer Personal Data in the European Union (Fly.io EU regions). Where a Sub-processor requires access from outside the EEA, MYACHT relies on:
- The Standard Contractual Clauses adopted by the European Commission (Decision (EU) 2021/914), where applicable
- The EU–US Data Privacy Framework where the recipient is certified
- Any other transfer mechanism recognised as providing adequate safeguards under GDPR Chapter V
9. Assistance to the Customer
Taking into account the nature of the processing and the information available to MYACHT, MYACHT will assist the Customer:
- In responding to requests from data subjects exercising rights under Articles 15–22 GDPR
- In complying with obligations under Articles 32–36 GDPR (security, breach notification, data protection impact assessments, and consultation with supervisory authorities)
Where a data subject sends a request directly to MYACHT, MYACHT will forward the request to the Customer without undue delay and will not respond to the request itself, unless authorised by the Customer.
10. Personal Data breach notification
MYACHT will notify the Customer without undue delay and, where feasible, within seventy-two (72) hours after becoming aware of a Personal Data breach affecting Customer Personal Data. The notification will include, to the extent then known:
- The nature of the breach
- The categories and approximate number of data subjects
- The categories and approximate volume of Personal Data records
- The likely consequences of the breach
- Measures taken or proposed to address the breach
MYACHT will provide the Customer with reasonable cooperation and assistance in the Customer’s notification to its supervisory authority and to affected data subjects, where applicable.
11. Deletion and return of Customer Personal Data
Upon termination or expiry of the subscription agreement, MYACHT will, at the Customer’s choice, delete or return Customer Personal Data, and delete existing copies, unless applicable law requires storage. The Customer may export its Personal Data at any time during the term via the Service’s export functions.
Backup copies containing Customer Personal Data are retained for up to thirty (30) days after the primary deletion and are then overwritten by the standard backup rotation.
12. Audit
MYACHT will make available to the Customer information necessary to demonstrate compliance with the obligations laid down in this DPA and Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.
The Customer will give MYACHT reasonable prior notice of any audit and conduct it in a manner that does not disrupt the Service. The parties will agree in good faith on the timing, scope, and allocation of costs.
13. Liability
The parties’ liability under this DPA is subject to the limitation and exclusion of liability provisions of the underlying subscription agreement or Terms of Service.
14. Order of precedence
If there is any conflict between this DPA and the subscription agreement, this DPA prevails with respect to the parties’ data-protection obligations. All other provisions of the subscription agreement remain in full force and effect.
15. Governing law
This DPA is governed by the laws of Portugal, without regard to conflict-of-laws principles. The courts of Lisbon, Portugal, have exclusive jurisdiction over any dispute arising out of or in connection with this DPA.
16. Contact
FRANCISCO GARRIDO PAULO - UNIPESSOAL LDA
NIPC: 519391845
Avenida da República, nº 13, Apt. CB
2775-273 Parede, Portugal
Email: privacy@myachtsystems.com
Related: Privacy Policy · Sub-processors · Cookie Policy · Terms of Service