VesselMark
TermsPrivacyDPASubprocessorsContact

Data Processing Addendum

Version 1.0 — August 6, 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Stratiback LLC, a Louisiana limited liability company (“we”, “us”, the “Processor”) and the organization that has agreed to those terms (“you”, the “Controller”). Where this DPA and the Terms conflict on the handling of personal data, this DPA wins.

1. Roles

You are the controller of the personal data you put into VesselMark. We are the processor, and we process that data only to provide the service and only on your documented instructions — which are the Terms, this DPA, and your use of the product’s features. If we believe an instruction breaks applicable data protection law, we will tell you rather than act on it.

2. What we process

Subject matter and duration: provision of the VesselMark service, for as long as your account exists, plus the retention periods in section 8.

Nature and purpose: hosting, storing, organizing and displaying the compliance records you create, sending the account and reminder emails the product generates, and taking payment.

Categories of personal data: the names, work email addresses and roles of the users you invite; the IP address used at registration and at sign-in, kept for abuse prevention; the billing contact address; and any personal data you choose to place inside your own records — control narratives, risk entries, audit findings, evidence documents. What ends up in that last category is your decision, not ours.

Categories of data subjects: your personnel and any individual you reference in your own compliance records.

Special categories: the product is not designed for special category data as defined by GDPR Article 9, and you should not place it in the workspace.

3. Confidentiality

Access to customer data is limited to personnel who need it to operate or support the service, under a duty of confidentiality. Platform administrators cannot read the contents of your workspace through the admin console; reaching workspace data requires explicit impersonation, which is written to your own audit trail where you can see it.

4. Security

We maintain the measures described in the Privacy Policy and the security section of our site, including: enforced multi-factor authentication for every user; database-level tenant isolation so one organization’s rows cannot be read by another; encryption in transit and at rest; write-once storage for evidence files; an append-only audit trail; and least-privilege database roles separating the running application from schema ownership. We may change specific measures over time, but not in a way that materially reduces overall protection.

5. Subprocessors

You give general authorization for us to engage the subprocessors listed on our Subprocessors page. We impose data protection obligations on each of them no less protective than those in this DPA, and we remain responsible to you for their performance. We will update that page before adding a new subprocessor, and on request we will notify you by email in advance so you have a reasonable opportunity to object.

Note that hosting, the database and evidence storage are run on our own hardware, so the list is short and your workspace content is not sent to any of them.

6. Assisting you with data subject rights

The product is built so you can answer most requests yourself: you can read, export and correct workspace records, and export your full audit pack, without our involvement. If a data subject contacts us directly about your data, we will refer them to you rather than respond on your behalf. Where you still need help, we will provide reasonable assistance taking into account the nature of the processing.

7. Personal data breach

If we become aware of a personal data breach affecting your data, we will notify you without undue delay, with the information we have at the time, and update you as we learn more. We will not delay notification in order to complete an investigation first. We will assist you with your own notification obligations.

8. Deletion and return — please read

You can export your data at any time, including after a trial or subscription ends, while your account remains readable. On written request following termination we will delete your workspace data, subject to the following, which is a real technical constraint and not a preference:

Evidence files are held in write-once storage under a one-year compliance retention lock and cannot be deleted by anyone — including us — until that lock expires. This is the property that makes the evidence trail worth anything to an auditor, and it is the reason the product can claim its records are tamper-evident. If you need us to erase your account before that period is up, we will delete everything we are able to delete and tell you precisely what remains and when it expires. Consider this before uploading anything you may need erased on demand.

We may also retain data where law requires it, and retain backups on the ordinary rotation until they age out.

9. Audits and information

On reasonable written request, and no more than once in any twelve-month period, we will provide the information reasonably necessary to demonstrate compliance with this DPA, and respond to a security questionnaire. Where that is genuinely insufficient for your regulator or your own auditor, we will agree an on-site or remote audit on reasonable notice, during business hours, without unreasonable disruption, subject to confidentiality and at your cost.

10. International transfers

We store and process customer data in the United States, on infrastructure we operate. Our subprocessors are also United States entities. If you are transferring personal data from the UK, EEA or Switzerland, contact us before you do so — we will put an appropriate transfer mechanism in place with you rather than leave the position ambiguous.

11. Term

This DPA takes effect when you accept the Terms and continues for as long as we process personal data for you. Sections that by their nature should survive termination — confidentiality, deletion, and audit obligations relating to the period of processing — do so.

12. Contact

Data protection questions, subprocessor objections, audit requests and deletion requests all go through the contact form, which reaches us directly.

Compliance management software. Not legal advice. Regulatory readiness is the operator's responsibility.