Data Processing Agreement
Version 1.0 · effective 6/15/2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between
DocksBase and the marina or organisation using the Service ("Customer"). It applies
where DocksBase processes personal data on the Customer's behalf.
1. Roles
The Customer is the controller and DocksBase is the processor in respect of
personal data that the Customer or its boaters submit to the Service ("Customer
Personal Data").
2. Subject matter and duration
The subject matter is the provision of the DocksBase service. Processing continues
for the duration of the Customer's use of the Service and until deletion or return
of Customer Personal Data as set out below.
3. Nature and purpose
DocksBase processes Customer Personal Data to provide marina management and booking
functionality — including reservations, berth allocation, invoicing and payments —
in accordance with the Customer's documented instructions.
4. Categories of data and data subjects
- Data subjects: the Customer's boaters, their crew, and the Customer's staff.
- Data: identification and contact details, billing and address details, vessel
details, booking and stay information, and related correspondence.
5. Processor obligations
DocksBase shall: (a) process Customer Personal Data only on the Customer's
documented instructions; (b) ensure persons authorised to process the data are
bound by confidentiality; (c) implement appropriate technical and organisational
security measures; and (d) assist the Customer, taking into account the nature of
processing, with data subject requests and with security, breach notification and
impact assessments.
6. Sub-processors
The Customer authorises DocksBase to engage sub-processors to provide the Service,
including payment processing (Stripe) and hosting and infrastructure providers.
DocksBase imposes data protection obligations on its sub-processors and remains
responsible for their performance. DocksBase will inform the Customer of intended
changes to sub-processors and give the Customer the opportunity to object.
7. Security
DocksBase maintains appropriate measures to protect Customer Personal Data against
accidental or unlawful destruction, loss, alteration, and unauthorised disclosure
or access, including encryption in transit, access controls and logging.
8. Personal data breaches
DocksBase will notify the Customer without undue delay after becoming aware of a
personal data breach affecting Customer Personal Data and will provide information
reasonably required for the Customer to meet its notification obligations.
9. Data subject requests
DocksBase will, taking into account the nature of the processing, assist the
Customer by appropriate measures to respond to requests from data subjects.
10. Deletion and return
On termination of the Service, DocksBase will delete or return Customer Personal
Data at the Customer's choice, save where retention is required by law.
11. International transfers
Where DocksBase transfers Customer Personal Data outside Switzerland or the EEA, it
relies on an appropriate transfer mechanism such as an adequacy decision or
standard contractual clauses.
12. Audits
DocksBase will make available information reasonably necessary to demonstrate
compliance with this DPA and allow for and contribute to audits, subject to
reasonable confidentiality and security conditions.
13. Governing law
This DPA is governed by the law of Switzerland and, where applicable, the data
protection law that applies to the Customer's processing.
Contact: david.sajosi@gmail.com.