Data Processing Addendum

This Data Processing Addendum (“DPA”) forms part of the agreement between the Customer and FRANCISCO GARRIDO PAULO - UNIPESSOAL LDA (“MYACHT”) governing the provision of the MYACHT platform. It reflects the parties’ obligations under the EU General Data Protection Regulation (“GDPR”), Regulation (EU) 2016/679.

Version 1.0 · Effective date: 8 July 2026

1. Definitions

Capitalised terms have the meanings given below. Terms not defined here have the meanings given in the GDPR.

2. Roles of the parties

For Customer Personal Data processed by MYACHT under the subscription agreement, the Customer is the Controller and MYACHT is the Processor. Where the Customer is acting on behalf of another Controller (for example, a yacht owner or management company acting on behalf of a vessel), the Customer represents that it has the authority to instruct MYACHT on that Controller’s behalf.

3. Subject matter, duration, and purpose

Subject matter: processing of Customer Personal Data as necessary to provide the Service.

Duration: for the term of the subscription agreement, plus any post-termination period required to return or delete Customer Personal Data.

Purpose: to enable Customer’s use of the Service for vessel operations, maintenance, compliance, crew management, and related functions.

Nature of processing: storage, retrieval, organisation, transmission, backup, deletion.

Categories of data subjects: Customer’s personnel, crew members, contractors, visitors, and any other natural persons whose data the Customer uploads to the Service.

Categories of Personal Data: identification data, contact data, professional qualifications and certificates, work-rest hours, sea-time records, and (where the Customer configures it) references to medical fitness certificates as special-category data under GDPR Article 9. Full detail in Privacy Policy §2.

4. Customer instructions

MYACHT will process Customer Personal Data only on documented instructions from the Customer, including with regard to transfers of Personal Data to a third country. The subscription agreement, this DPA, and the Customer’s use of the Service constitute the Customer’s complete instructions.

If applicable law requires MYACHT to process Customer Personal Data otherwise, MYACHT will inform the Customer before processing unless that law prohibits such notice on grounds of public interest.

5. Confidentiality

MYACHT ensures that persons authorised to process Customer Personal Data are bound by written confidentiality obligations or are under an appropriate statutory obligation of confidentiality.

6. Security

MYACHT implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

Detail of the security posture is published at myachtsystems.com/security.

7. Sub-processors

The Customer generally authorises MYACHT to engage Sub-processors for the provision of the Service, subject to the terms of this section.

The current list of Sub-processors is maintained at myachtsystems.com/sub-processors. MYACHT will give the Customer notice of any intended addition or replacement of a Sub-processor no less than thirty (30) days before the change takes effect, by updating that page and (where the Customer has requested notification) by email.

If the Customer reasonably objects to a proposed Sub-processor on data-protection grounds, the parties will discuss the objection in good faith. If the objection cannot be resolved, either party may terminate the affected part of the Service, without penalty for the Customer.

MYACHT remains liable for the acts and omissions of its Sub-processors as if they were MYACHT’s own.

8. International transfers

MYACHT primarily hosts Customer Personal Data in the European Union (Fly.io EU regions). Where a Sub-processor requires access from outside the EEA, MYACHT relies on:

9. Assistance to the Customer

Taking into account the nature of the processing and the information available to MYACHT, MYACHT will assist the Customer:

Where a data subject sends a request directly to MYACHT, MYACHT will forward the request to the Customer without undue delay and will not respond to the request itself, unless authorised by the Customer.

10. Personal Data breach notification

MYACHT will notify the Customer without undue delay and, where feasible, within seventy-two (72) hours after becoming aware of a Personal Data breach affecting Customer Personal Data. The notification will include, to the extent then known:

MYACHT will provide the Customer with reasonable cooperation and assistance in the Customer’s notification to its supervisory authority and to affected data subjects, where applicable.

11. Deletion and return of Customer Personal Data

Upon termination or expiry of the subscription agreement, MYACHT will, at the Customer’s choice, delete or return Customer Personal Data, and delete existing copies, unless applicable law requires storage. The Customer may export its Personal Data at any time during the term via the Service’s export functions.

Backup copies containing Customer Personal Data are retained for up to thirty (30) days after the primary deletion and are then overwritten by the standard backup rotation.

12. Audit

MYACHT will make available to the Customer information necessary to demonstrate compliance with the obligations laid down in this DPA and Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.

The Customer will give MYACHT reasonable prior notice of any audit and conduct it in a manner that does not disrupt the Service. The parties will agree in good faith on the timing, scope, and allocation of costs.

13. Liability

The parties’ liability under this DPA is subject to the limitation and exclusion of liability provisions of the underlying subscription agreement or Terms of Service.

14. Order of precedence

If there is any conflict between this DPA and the subscription agreement, this DPA prevails with respect to the parties’ data-protection obligations. All other provisions of the subscription agreement remain in full force and effect.

15. Governing law

This DPA is governed by the laws of Portugal, without regard to conflict-of-laws principles. The courts of Lisbon, Portugal, have exclusive jurisdiction over any dispute arising out of or in connection with this DPA.

16. Contact

FRANCISCO GARRIDO PAULO - UNIPESSOAL LDA
NIPC: 519391845
Avenida da República, nº 13, Apt. CB
2775-273 Parede, Portugal
Email: privacy@myachtsystems.com

Related: Privacy Policy · Sub-processors · Cookie Policy · Terms of Service