Diving.Voyage Legal
Data Processing Addendum
GDPR-style processing terms between Webase Global and a Diving.Software business customer.
Scope and instructions
This DPA forms part of the Diving.Software agreement where a business Controller instructs Webase Global as Processor to handle organization-scoped data. We process it only to provide, secure and support the contracted service under authorised actions and documented requests. Independent controller purposes follow the Privacy Notice.
Controller duties
The Controller selects lawful purposes and bases, provides notices, obtains valid consents, limits data, configures access and retention, responds to individuals and ensures instructions are lawful. Sensitive data must not be used for unrelated marketing or profiling.
Security and confidentiality
- Personnel and authorised contractors are bound by appropriate confidentiality duties.
- Logical tenant isolation and role-based access.
- Secure authentication, sessions and request controls.
- Encryption in transit and provider-managed encryption at rest where available.
- Separated environments, databases and credentials.
- Restricted document routes, upload validation, logs and backups.
- Verified payment events and restricted health-data access.
Subprocessors and transfers
The Controller gives general authorisation for the published subprocessors. We give notice of material additions where required and consider documented data-protection objections.
Restricted transfers use an adequacy decision, current Standard Contractual Clauses or another lawful safeguard.
Requests, instructions and incidents
We reasonably assist with individual-rights requests, impact assessments and consultations. Requests for Controller data are directed to the Controller unless law requires otherwise. We inform the Controller if, in our reasonable view, an instruction infringes applicable data-protection law and may pause that instruction while it is reviewed.
We notify the Controller without undue delay after confirming a breach affecting its data and provide available facts in phases if needed. Subprocessors are bound to data-protection obligations no less protective than the relevant obligations in this DPA.
Deletion and audit
At termination or lawful instruction, data is exported and deleted under the agreement and retention rules, except mandatory records and protected rolling backups.
We provide information reasonably needed to demonstrate compliance. Proportionate audits must protect other tenants, security and confidentiality.
Processing description
- Subjects: customers, divers, participants, guardians, emergency contacts, staff and business contacts.
- Data: identity, contact, bookings, credentials, documents, equipment, communications, payment references and audit data.
- Special data: health, accessibility, insurance and incidents where enabled.
- Duration: agreement term plus applicable retention and deletion periods.