This Data Processing Addendum (“DPA”) is incorporated into and subject to the master subscription or services agreement between the customer (“Customer”) and Marivue, Inc. (“Marivue”) (the “Agreement”). It reflects the parties’ agreement on the processing of Personal Data in accordance with applicable Data Protection Laws, including the EU and UK GDPR.
1. Definitions
Terms such as “Controller,” “Processor,” “Data Subject,” “Personal Data,” “Processing,” and “Personal Data Breach” have the meanings given in applicable Data Protection Laws. “Customer Personal Data” means Personal Data processed by Marivue on the Customer’s behalf under the Agreement.
2. Roles & scope
For Customer Personal Data, the Customer is the Controller and Marivue is the Processor. Where the Customer acts as a processor for a third-party controller, Marivue acts as a sub-processor. Each party will comply with its obligations under applicable Data Protection Laws. The subject matter, nature, and purpose of processing are described in Annex I.
3. Processing instructions
Marivue will process Customer Personal Data only on the Customer’s documented instructions, including as set out in the Agreement and this DPA, unless required otherwise by law (in which case Marivue will, where permitted, inform the Customer). Marivue’s platform integrates with the Customer’s TOS on a read-only, least-privilege basis and does not write back to the Customer’s system of record. Marivue will inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.
4. Confidentiality
Marivue ensures that persons authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and process such data only as necessary to perform under the Agreement.
5. Security measures
Taking into account the state of the art, costs, and the nature, scope, context, and purposes of processing, Marivue implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Annex II.
6. Subprocessors
The Customer provides general authorization for Marivue to engage subprocessors to support the services. A current list is maintained in Annex III. Marivue imposes data protection obligations on each subprocessor that are no less protective than those in this DPA and remains responsible for their performance. Marivue will give the Customer reasonable prior notice of any intended addition or replacement of a subprocessor, allowing the Customer to object on reasonable data-protection grounds.
7. Data subject requests
Taking into account the nature of the processing, Marivue will assist the Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights. If Marivue receives such a request directly, it will, where lawful, redirect the Data Subject to the Customer.
8. Personal data breach notification
Marivue will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to assist the Customer in meeting its notification obligations.
9. Audits
Marivue will make available information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, on reasonable prior notice and subject to confidentiality. Marivue may satisfy audit requests by providing third-party certifications, attestations, or audit reports where available.
10. International transfers
Where Marivue transfers Customer Personal Data outside the EEA, UK, or other restricted jurisdiction, it does so under an appropriate transfer mechanism, including the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated by reference where applicable.
11. Return & deletion
Upon termination or expiry of the Agreement, Marivue will, at the Customer’s choice, delete or return Customer Personal Data and delete existing copies, unless retention is required by law.
Annex I — Details of processing
| Subject matter | Provision of the Marivue maritime port intelligence platform. |
|---|---|
| Duration | For the term of the Agreement plus any agreed retention period. |
| Nature & purpose | Read-only ingestion, normalization, analysis, and presentation of operational data to deliver predictive intelligence and alerts. |
| Categories of data subjects | Customer’s authorized users; and, where present in operational records, terminal staff, drivers, and other operational personnel. |
| Types of personal data | Account and contact identifiers (name, work email, role); and limited identifiers that may appear in operational data (e.g. user IDs, driver or appointment references). The platform is not intended to process special-category data. |
Annex II — Technical & organizational measures
- Encryption — TLS for data in transit and AES-256 for data at rest; optional customer-managed keys.
- Access control — least-privilege, role-based access; SSO/ SAML and MFA for administrative access; periodic access reviews.
- Integration security — read-only, scoped credentials to the Customer’s TOS; no write-back to the system of record.
- Network security — segmentation, firewalls, and per-tenant logical isolation; optional private-VPC or on-premise deployment.
- Resilience — backups, monitoring, and documented incident response and business continuity processes.
- Secure development — code review, dependency and vulnerability management, and testing throughout the lifecycle.
See our Security page for further detail. Measures evolve as the product matures; Marivue will not materially reduce the overall level of security during the term.
Annex III — Subprocessors
Marivue engages the following categories of subprocessors. A current, itemized list is available on request and will be maintained as the product becomes generally available.
| Category | Purpose | Location |
|---|---|---|
| Cloud infrastructure & hosting | Compute, storage, and database hosting for the platform | Customer-selected region |
| Observability & monitoring | Application logging, metrics, and error tracking | EEA / US |
| Communications | Transactional email and notifications | EEA / US |