Last updated: August 7, 2026
Data Processing
Addendum
This Data Processing Addendum ("DPA") forms part of the Oceanir Software as a Service Agreement and is incorporated by reference. It reflects the parties' agreement with regard to the processing of Personal Data under the GDPR, the UK GDPR, the Swiss FADP, the CCPA as amended by the CPRA, and other applicable data protection laws. It applies to every Customer, including customers who sign up without an Order Form, and takes effect as described in Section 17.
Download
This DPA is available as a signed addendum for enterprise customers. Contact sales to execute a counter-signed copy. A counter-signed addendum prevails over this page for the processing it covers (Section 17.2).
1. Definitions
"Agreement" means the Oceanir Software as a Service Agreement, together with any Order Form, terms of service, or online terms under which Oceanir provides the Services to Customer.
"Customer" means the entity or individual that has entered into the Agreement with Oceanir, whether by executing an Order Form or by accepting the Agreement online and using the Services. Where an individual opens or administers an account on behalf of an organization, Customer means that organization and the individual accepts this DPA on its behalf. Customer includes Customer's authorized users and affiliates permitted to use the Services under the Agreement.
"Controller" means the entity that determines the purposes and means of processing Personal Data. "Processor" means an entity that processes Personal Data on behalf of a Controller. "data subject", "processing" and "supervisory authority" have the meanings given in the GDPR.
"Data Protection Law" means all privacy and data protection laws applicable to the processing under this DPA, including Regulation (EU) 2016/679 (the "GDPR"), the UK General Data Protection Regulation and the UK Data Protection Act 2018 (together the "UK GDPR"), the Swiss Federal Act on Data Protection (the "FADP"), the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (the "CCPA"), and other applicable United States state privacy laws.
"Personal Data" means any information relating to an identified or identifiable natural person processed by Oceanir on behalf of the Customer pursuant to the Agreement.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed by Oceanir or a Sub-processor.
"Services" means the Oceanir products, applications and application programming interfaces made available to Customer under the Agreement.
"Sub-processor" means a third party engaged by Oceanir to process Personal Data in connection with providing the Services.
"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0, in force 21 March 2022.
2. Roles and Scope
2.1 Default allocation. Except as set out in Sections 2.2 and 2.3, Customer is the Controller of Personal Data submitted to the Services and Oceanir is the Processor. Oceanir processes that Personal Data only on documented instructions from Customer, including with regard to transfers of Personal Data to a third country, unless required to do so by applicable law.
2.2 Customer acting as a Processor. Where Customer submits Personal Data on behalf of, and on the documented instructions of, a third party that determines the purposes and means of the processing, Customer is a Processor and Oceanir is a Sub-processor in respect of that Personal Data. This applies, for example, where a government, law enforcement, or business account supplies imagery belonging to its own agency, client, or constituent. In that case Customer warrants that (a) it has the authority of the relevant Controller to appoint Oceanir as a Sub-processor; (b) it has given that Controller any notice, and obtained any consent or authorization, required by Data Protection Law; and (c) the terms of this DPA satisfy the flow-down obligations Customer owes that Controller under Article 28(4) GDPR or the equivalent provision of Data Protection Law. References in this DPA to Customer's instructions include instructions Customer passes through from that Controller.
2.3 Oceanir as an independent Controller. Oceanir acts as an independent Controller, and not as Customer's Processor, in respect of account registration and administration, authentication and identity data for Customer's authorized users, billing and payment records, service usage and telemetry data used to operate the Services, security monitoring, fraud and abuse prevention, and compliance with Oceanir's own legal obligations. Oceanir's processing in that capacity is described in the Privacy Policy and is governed by that policy and by applicable law rather than by Customer's instructions under this DPA.
2.4 Scope of processing. The subject matter and duration of the processing, the nature and purpose of the processing, the types of Personal Data and the categories of data subjects are set out in Annex I.B in Section 18. Annex I.B applies in full to every Customer, including Customers who have no Order Form. Where an Order Form describes the processing in more detail, the Order Form supplements Annex I.B and controls for that Customer to the extent of any inconsistency.
3. Customer Obligations and Warranties
Customer warrants and undertakes that:
- It has obtained and will maintain all rights, consents, permissions and lawful bases required to submit Personal Data to the Services, and for Oceanir and its Sub-processors to process that Personal Data as described in this DPA, including images and other visual media that depict identifiable individuals.
- It has provided all notices to data subjects required by Data Protection Law in respect of the processing described in this DPA.
- It will not submit special categories of personal data within the meaning of Article 9 GDPR, or personal data relating to criminal convictions and offences within the meaning of Article 10 GDPR, unless it has obtained the data subject's explicit consent (or another condition in Article 9(2) applies) and has notified Oceanir in writing in advance.
- It is solely responsible for the accuracy, quality and legality of the Personal Data it submits, and for the lawfulness of the means by which it acquired that Personal Data.
- Its instructions to Oceanir will comply with Data Protection Law and with Section 5.
Oceanir has no obligation to review or verify the Personal Data Customer submits, and no obligation to determine whether Customer has a lawful basis for submitting it.
4. Processing Instructions
Oceanir will process Personal Data only on Customer's documented instructions, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do so by law to which Oceanir is subject. Where a legal requirement obliges Oceanir to process Personal Data other than on Customer's instructions, Oceanir will inform Customer of that requirement before processing, unless the law prohibits the disclosure on important grounds of public interest.
The Agreement, this DPA, Customer's configuration of the Services, and the requests Customer submits through the Services or the API together constitute Customer's complete documented instructions.
Unlawful instructions. Oceanir will promptly inform Customer if, in Oceanir's opinion, an instruction infringes the GDPR or other Data Protection Law. Oceanir may suspend performance of the affected instruction, without liability, until Customer withdraws it, amends it, or confirms it in writing with an explanation of its lawfulness. Any suspension is limited to the affected processing and does not relieve either party of its other obligations under the Agreement.
Government requests. Oceanir will challenge any government or law enforcement request for Personal Data that it reasonably believes is unlawful or overly broad, and will notify Customer of the request unless legally prohibited from doing so.
5. Purpose Limitation
The Services estimate the geographic origin of visual media. Oceanir analyzes scenes, not people.
Oceanir does not perform, and Customer will not instruct Oceanir to perform, any of the following:
- Face recognition or facial comparison.
- Biometric identification, biometric templating, or biometric categorisation of a natural person.
- Processing whose purpose is to determine where a specific identified or identifiable individual is, or has been, including by locating, tracking or monitoring that individual.
Where an image depicts an identifiable individual, that individual's presence is incidental to the estimate of where the media was captured. Oceanir does not process that individual's likeness in order to identify them or to establish their whereabouts.
Any instruction inconsistent with this Section is outside the scope of this DPA and the Agreement, and Oceanir may refuse or suspend it under Section 4 without liability.
6. Confidentiality of Personnel
Oceanir ensures that each person authorized to process Personal Data is bound by a written duty of confidentiality that survives the end of their engagement, or is under an appropriate statutory obligation of confidentiality. Access to Personal Data is restricted to personnel with a documented business need, and those personnel receive data protection and security training appropriate to their role.
7. Security Measures
Oceanir implements and maintains appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include:
- Encryption of Personal Data in transit using TLS 1.2 or higher
- Encryption of Personal Data at rest in databases and file storage
- Role-based access controls with least-privilege provisioning
- Audit logging of administrative and API access to Personal Data
- Regular security assessments and vulnerability remediation
- Incident response procedures with documented notification timelines
- Employee access controls and background screening where permitted by applicable law
Personnel confidentiality obligations are set out separately in Section 6. The measures in this Section, together with Section 6, are incorporated into Annex II in Section 18 and serve as the technical and organisational measures for the purposes of the Standard Contractual Clauses.
Current security documentation, including SOC 2 Type II reports (when available), is available upon request under NDA.
8. Sub-processors
8.1 Sub-processors that process Customer Personal Data. Oceanir engages the following categories of sub-processor to process Personal Data submitted to the Services on Customer's behalf:
- Cloud infrastructure: Railway (compute, database hosting), US-region
- AI inference: Third-party model inference providers used to analyse submitted media. Oceanir uses more than one provider for redundancy and may route between them. Processing location is determined by the provider; Oceanir does not currently guarantee a specific processing region for inference.
- Maps and geospatial: Mapbox (map rendering, geocoding, and reference imagery lookups performed on Oceanir's instructions)
8.2 Oceanir's own vendors. The following vendors support Oceanir's own operations. They process the account, billing and telemetry data for which Oceanir is an independent Controller under Section 2.3, and they are not engaged to process Personal Data that Customer submits to the Services:
- Payment processing: Stripe (PCI DSS Level 1), for billing, invoicing and payment records
- Email delivery: Resend, for transactional and account email
- Analytics: PostHog (self-hosted or US-region cloud), for product usage analytics
8.3 Independent controllers. Google Maps Platform is used for base map imagery and street-level reference imagery. Google acts as an independent controller for that processing under its own terms, and is not a Sub-processor of Customer Personal Data under this DPA.
Oceanir maintains a current list of sub-processors and will update it within five (5) business days of any addition or replacement. Oceanir will give Customer at least thirty (30) days advance notice before engaging a sub-processor in a category not listed above. Routing between providers already listed, for redundancy, failover, or capacity, does not require advance notice. Oceanir imposes on every sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to Customer for their performance.
Customer may object to a new sub-processor by notifying Oceanir within fifteen (15) days of receiving notice. Oceanir will use reasonable efforts to address Customer's concerns; where a timely objection is reasonable and cannot be resolved, Oceanir will not onboard that sub-processor for Customer's data, or Customer may terminate the affected portion of the Services with a pro-rated refund.
8.4 General authorisation. Sections 8.1 to 8.3 constitute Customer's general written authorisation to engage Sub-processors for the purposes of Clause 9 of the Standard Contractual Clauses (Option 2) and Article 28(2) GDPR. Where the CCPA applies, each Sub-processor is engaged as a Service Provider or Contractor under a written contract meeting the requirements of the CCPA.
9. Data Subject Rights
Taking into account the nature of the processing, Oceanir will assist Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling Customer's obligation to respond to requests to exercise data subject rights under Chapter III of the GDPR and equivalent provisions of Data Protection Law, including requests for access, rectification, erasure, restriction, data portability, and objection.
That assistance includes making Personal Data held in Customer's account available to Customer within ten (10) business days of a written request, and permanently deleting specified Personal Data within thirty (30) days of Customer's written instruction, in each case where technically feasible and subject to Section 13.
Oceanir will notify Customer without undue delay if it receives a request from a data subject directly, and will direct the data subject to submit the request to Customer. Oceanir will not respond to such a request itself except on Customer's documented instruction or where required by law.
10. Assistance with Articles 32 to 36
Taking into account the nature of the processing and the information available to Oceanir, Oceanir will provide reasonable assistance to Customer in ensuring compliance with Customer's obligations under Articles 32 to 36 GDPR, or the equivalent provisions of Data Protection Law. That assistance covers:
- Security of processing (Article 32), including by making available the information in Section 7 and Annex II.
- Notification of a Personal Data Breach to a supervisory authority and communication of a breach to data subjects (Articles 33 and 34), as set out in Section 11.
- Data protection impact assessments (Article 35), including by providing information about the Services reasonably necessary for Customer to complete an assessment.
- Prior consultation with a supervisory authority (Article 36), including by providing information the authority reasonably requires.
Where the assistance Customer requests is unusually extensive or repetitive, Oceanir may charge a reasonable fee, and will notify Customer of the fee before any charge is incurred.
11. Personal Data Breach Notification
Oceanir will notify Customer of a Personal Data Breach affecting Customer Personal Data without undue delay, and in any event within twenty-four (24) hours after becoming aware of it. The twenty-four hour commitment is set deliberately inside the seventy-two hour deadline that Customer, as Controller, has for notifying its own supervisory authority under Article 33 GDPR.
The initial notification will contain the information available to Oceanir at the time. Oceanir will provide the following in phases as the information becomes available, and will supplement its notification without undue delay:
- A description of the nature of the breach, to the extent then known
- The categories and approximate number of data subjects and Personal Data records concerned, where Oceanir is able to determine them
- The likely consequences of the breach, to the extent they can be assessed
- The measures taken or proposed to address the breach and mitigate its possible adverse effects
Oceanir will also provide the name and contact details of a point of contact from whom further information can be obtained. Oceanir will cooperate reasonably with Customer in investigating and mitigating the breach, and will provide information Customer reasonably requires for its own notifications to a supervisory authority or to data subjects. Notification under this Section is not an acknowledgement of fault or liability.
12. Data Retention
Oceanir retains Personal Data only for as long as necessary to provide the Services or as required by applicable law. The following periods apply while the Agreement is in force:
- Submitted media. Images, video frames and other visual media submitted to the Services are retained for thirty (30) days from submission and are then permanently deleted.
- Request metadata. Request metadata (timestamps, request identifiers, depth tier, credit consumption, and the IP address of the API client) is retained for ninety (90) days for billing, rate limiting, security and abuse prevention.
- Account data. Account and billing records are retained for the duration of the Agreement, and afterwards only as described in Section 13 or for the period required by tax and accounting law.
Oceanir may retain aggregated, de-identified usage metrics that cannot be linked to Customer or to any data subject. Deletion from encrypted backups occurs as those backups expire on their ordinary schedule; backups are encrypted, access-controlled, and accessed only for disaster recovery.
13. Return and Deletion of Personal Data
On termination or expiry of the Agreement, and at any other time on Customer's written request, Oceanir will, at Customer's election, either return the Personal Data to Customer in a commonly used machine-readable format or delete it, and will procure that each Sub-processor does the same.
Customer must communicate its election within thirty (30) days of termination or expiry. Oceanir will complete the return or the deletion within thirty (30) days of receiving the election. If Customer makes no election within that period, Oceanir will delete the Personal Data.
Oceanir may retain Personal Data to the extent retention is required by applicable law. Where that applies, Oceanir will limit the retention to what the law requires, will continue to protect the data in accordance with this DPA, and will delete it once the legal requirement ends. Deletion from encrypted backups occurs as those backups expire on their ordinary schedule.
This Section governs return and deletion on termination. It does not shorten or override the in-life retention periods in Section 12, which continue to apply while the Agreement is in force.
14. International Data Transfers
14.1 Application. Where Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country that is not covered by an adequacy decision applicable to that transfer, the transfer is governed by the mechanisms in this Section. Where an adequacy decision covers a transfer, that decision governs and the clauses below do not apply to it.
14.2 EU Standard Contractual Clauses. The parties incorporate the Standard Contractual Clauses set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 into this DPA by reference, on the following basis:
- Module Two (Controller to Processor) applies where Customer is a Controller under Section 2.1.
- Module Three (Processor to Processor) applies where Customer is a Processor under Section 2.2.
- Customer is the data exporter. Oceanir LLC is the data importer. Where Section 2.2 applies, Customer enters into the Clauses as the Controller's processor and on the Controller's behalf, consistent with the warranty in Section 2.2.
- Clause 7 (docking clause) does not apply.
- Clause 9 (use of sub-processors): Option 2, general written authorisation, applies. Oceanir has Customer's general written authorisation under Section 8.4 and will give notice of changes as set out in Section 8, with a period of thirty (30) days advance notice for a Sub-processor in a category not already listed.
- Clause 11 (redress): the optional language on an independent dispute resolution body does not apply.
- Clause 13 and Annex I.C: the competent supervisory authority is determined as set out in Annex I.C in Section 18.
- Clause 17 (governing law): Option 1 applies. The Clauses are governed by the law of Ireland.
- Clause 18(b) (choice of forum and jurisdiction): disputes arising from the Clauses will be resolved before the courts of Ireland.
- Annexes: Annex I.A, Annex I.B, Annex I.C and Annex II of the Clauses are populated by Section 18 of this DPA.
14.3 Execution and deemed acceptance. By entering into the Agreement, or by using the Services, each party is deemed to have signed the Standard Contractual Clauses and their Annexes, on the date the Agreement takes effect or the date of first use of the Services, whichever is earlier. Where the parties execute a separate counter-signed data processing addendum or a separate set of Standard Contractual Clauses, those executed documents prevail over this Section for the transfers they cover.
14.4 United Kingdom. For transfers subject to the UK GDPR, the parties incorporate the UK Addendum. Table 1 of the UK Addendum is completed with the party details in Annex I.A. Table 2 selects the Standard Contractual Clauses incorporated under Section 14.2, together with the Modules and elections stated there. Table 3 is completed by Section 18. In Table 4, neither party may end the UK Addendum when the Approved Addendum changes. References in the Clauses to the GDPR are read as references to the UK GDPR, references to a supervisory authority are read as references to the Information Commissioner, and the governing law and forum for UK transfers are the law and courts of England and Wales.
14.5 Switzerland. For transfers subject to the FADP, the Standard Contractual Clauses apply with the following amendments:
- The competent supervisory authority under Clause 13 and Annex I.C is the Swiss Federal Data Protection and Information Commissioner (FDPIC). Where a transfer is subject to both the FADP and the GDPR, the FDPIC and the authority identified in Annex I.C each act in respect of the transfers within their remit.
- References to the GDPR are read as references to the FADP.
- References to a Member State and to EU Member State law do not prevent data subjects in Switzerland from bringing proceedings in their place of habitual residence under Clause 18(c).
- The Clauses also protect the data of legal entities to the extent the FADP so requires.
14.6 Relationship to the Agreement's governing law. The governing law and forum provisions of the Agreement, including any provision selecting the law of the State of Florida or a Florida forum, do not apply to the Standard Contractual Clauses, the UK Addendum, or the Swiss amendments. Those instruments are governed by the law and subject to the forum stated in Sections 14.2 and 14.4, as amended for Swiss transfers by Section 14.5. If there is a conflict between the Standard Contractual Clauses and this DPA or the Agreement, the Standard Contractual Clauses prevail. Nothing in this DPA or the Agreement limits or varies a data subject's third-party beneficiary rights under Clause 3 of the Clauses.
14.7 Hosting. Oceanir's infrastructure is currently hosted in US-region data centers. The processing location for model inference is determined by the relevant provider, as stated in Section 8.1. EU-specific data residency is available for enterprise customers upon request.
15. CCPA and CPRA Terms
This Section applies to Personal Information, as that term is defined in the CCPA, that Oceanir processes on Customer's behalf. For the purposes of the CCPA, Customer is a Business and Oceanir is a Service Provider. Personal Information is disclosed to Oceanir only for the limited and specified business purpose of providing the Services described in the Agreement and Annex I.B.
Oceanir will not:
- Sell or share Personal Information, as "sell" and "share" are defined in the CCPA.
- Retain, use or disclose Personal Information for any purpose other than performing the Services specified in the Agreement, including for any commercial purpose other than those Services.
- Retain, use or disclose Personal Information outside the direct business relationship between Oceanir and Customer.
- Combine Personal Information received from or on behalf of Customer with Personal Information it receives from or on behalf of another person, or that it collects from its own interaction with a consumer, except where the CCPA permits a Service Provider to do so.
Oceanir certifies that it understands the restrictions in this Section and will comply with them. Oceanir will provide the same level of privacy protection as the CCPA requires of a Business, will assist Customer in responding to verifiable consumer requests, and grants Customer the right to take reasonable and appropriate steps to help ensure that Oceanir uses Personal Information in a manner consistent with Customer's obligations under the CCPA.
Oceanir will notify Customer promptly, and in any event without undue delay, if it determines that it can no longer meet its obligations as a Service Provider under the CCPA. On receiving that notice, Customer may take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Information.
Oceanir does not use Personal Information for cross-context behavioural advertising, and does not sell or share it. Any Sub-processor engaged under Section 8.1 is engaged as a Service Provider or Contractor under a written contract that imposes the same restrictions.
16. Audit Rights and Compliance Information
Oceanir will make available to Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and in this DPA, and will allow for and contribute to audits, including inspections, conducted by Customer or by an auditor mandated by Customer, in accordance with this Section.
- Written summary. Customer may request, no more than once per calendar year, a written summary of Oceanir's security controls and practices relevant to the processing of Customer Personal Data. Oceanir will provide the summary within ten (10) business days of the request, and will also make available its then-current security documentation, including any SOC 2 Type II report when one is available, under a non-disclosure agreement.
- Third-party audit. If Customer has a specific, documented security concern that the summary and documentation do not resolve, Customer may request an audit of Oceanir's relevant security practices, conducted by a mutually agreed independent third-party auditor at Customer's expense. The audit will be scheduled on at least thirty (30) days advance notice, will take place during normal business hours, will be limited in scope to systems and records relevant to the processing of Customer Personal Data, and will not unreasonably interfere with Oceanir's operations.
- Confidentiality. The auditor must enter into a non-disclosure agreement with Oceanir before the audit begins. Audit findings, and any information disclosed in the course of the audit, are Confidential Information under the Agreement.
- Limits. Nothing in this Section requires Oceanir to disclose information that would compromise the security or confidentiality of another customer's data, or that Oceanir is prohibited by law or by a binding obligation of confidentiality from disclosing.
Where the Standard Contractual Clauses apply, this Section describes the manner in which the audit rights under Clause 8.9 of the Clauses are exercised, and does not limit those rights.
17. Term, Acceptance, Precedence and Governing Law
17.1 Acceptance. This DPA is a standing offer by Oceanir to every Customer. It takes effect and binds both parties on the earlier of Customer's acceptance of the Agreement and Customer's first use of the Services. No signature is required. A person who accepts the Agreement or uses the Services on behalf of an organization does so on that organization's behalf and warrants that they have authority to bind it.
17.2 Executed addendum prevails. If the parties have executed a separate written data processing addendum, or a separate set of Standard Contractual Clauses, that executed document prevails over this page for the processing it covers. This page continues to apply to the extent the executed document is silent.
17.3 Precedence. On matters concerning the processing of Personal Data, this DPA prevails over any conflicting term of the Agreement. The Standard Contractual Clauses prevail over this DPA as stated in Section 14.6. In all other respects the Agreement continues unchanged.
17.4 Term. This DPA takes effect as described in Section 17.1 and continues for the term of the Agreement, plus the period required to complete the return or deletion of Personal Data under Section 13.
17.5 Survival. Sections 1 (Definitions), 3 (Customer Obligations and Warranties), 5 (Purpose Limitation), 6 (Confidentiality of Personnel), 11 (Personal Data Breach Notification), 12 (Data Retention), 13 (Return and Deletion), 14 (International Data Transfers), 15 (CCPA and CPRA Terms), 16 (Audit Rights and Compliance Information), 18 (Annexes) and this Section 17 survive termination or expiry of the Agreement, in each case for as long as Oceanir retains any Customer Personal Data or for the period required by Data Protection Law, whichever is longer.
17.6 Governing law. This DPA is governed by the law that governs the Agreement, which is the law of the State of Florida, United States, without regard to its conflict of laws rules. That choice of law does not extend to the Standard Contractual Clauses, the UK Addendum, or the Swiss amendments, which are governed as stated in Section 14.
17.7 Severability and changes. If any provision of this DPA is held invalid or unenforceable, the remainder continues in full effect. Oceanir may update this DPA to reflect changes in Data Protection Law, in the Services, or in its sub-processors, and will publish the updated version with a new "Last updated" date. A change that materially reduces Customer's protections takes effect thirty (30) days after publication.
18. Annexes: Description of Processing and Security Measures
The annexes below populate Annex I and Annex II of the Standard Contractual Clauses, complete Table 3 of the UK Addendum, and constitute the description of processing required by Article 28(3) GDPR. They apply to every Customer, including Customers who have no Order Form. Where an Order Form describes the processing differently, the Order Form controls for that Customer.
Annex I.A. List of parties
Data exporter: Customer, being the entity or individual identified in the Agreement or in the Oceanir account through which the Services are used, at the address and contact details held in that account or stated in the Order Form. Role: Controller under Section 2.1, or Processor under Section 2.2. Activities relevant to the transfer: submitting visual media and associated metadata to the Services in order to obtain an estimate of geographic origin, and administering the account. Contact person: the account administrator, or the data protection contact named by Customer. Signature and date: as described in Section 14.3.
Data importer: Oceanir LLC, a Florida limited liability company, 6449 NW 104th Court, Doral, FL 33178, United States. Role: Processor under Section 2.1, or Sub-processor under Section 2.2. Activities relevant to the transfer: providing the Services described in Annex I.B, including hosting, automated analysis of submitted media, storage for the retention periods in Section 12, security monitoring, and support. Contact person: Privacy and Security, [email protected]. Signature and date: as described in Section 14.3.
Annex I.B. Description of transfer
- Categories of data subjects: individuals who appear incidentally in visual media submitted to the Services; individuals whose property, vehicle or surroundings appear in that media; and Customer's authorized users who administer the account and use the Services.
- Categories of personal data: (i) visual media submitted by Customer, including photographs, video frames and screenshots, which may incidentally depict individuals or identifiers such as vehicles, signage or premises, together with any personal data Customer includes in filenames, captions or request parameters; (ii) request metadata, being timestamps, request identifiers, depth tier, credit consumption and the IP address of the API client; (iii) account data for Customer's authorized users, being name, email address, authentication data and billing records.
- Sensitive data: the Services do not require special category data. Customer must not submit special category data or criminal offence data except as permitted by Section 3. The restrictions in Section 5 and the measures in Annex II apply to any personal data that is nonetheless present in submitted media.
- Frequency of the transfer: continuous, for the duration of the Agreement, on each request Customer submits to the Services.
- Nature and purpose of the processing: automated analysis of submitted visual media to estimate the geographic location at which it was captured, together with the hosting, transmission, storage, logging, security monitoring, abuse prevention, billing and support that are incidental to providing the Services. Processing is limited by Section 5.
- Subject matter and duration: the subject matter is the provision of the Services under the Agreement. The duration is the term of the Agreement, plus the retention periods in Section 12 and the return or deletion period in Section 13.
- Retention periods: submitted media, thirty (30) days from submission; request metadata, ninety (90) days; account and billing data, the term of the Agreement plus the periods stated in Section 12.
- Transfers to sub-processors: to the sub-processors listed in Section 8.1, for the purposes described in that Section and for the retention periods stated above.
Annex I.C. Competent supervisory authority
The competent supervisory authority is identified in accordance with Clause 13 of the Standard Contractual Clauses, by reference to the establishment of the data exporter and not by reference to the choice of law in Clause 17:
- Where the data exporter is established in an EEA Member State, the supervisory authority of that Member State.
- Where the data exporter is not established in an EEA Member State but has appointed a representative under Article 27(1) GDPR, the supervisory authority of the Member State in which that representative is established.
- Where the data exporter is not established in an EEA Member State and is not required to appoint a representative under Article 27(2) GDPR, the supervisory authority of the Member State in which the data subjects whose personal data is transferred are located.
- For transfers subject to the UK GDPR, the competent authority is the Information Commissioner's Office of the United Kingdom.
- For transfers subject to the FADP, the competent authority is the Swiss Federal Data Protection and Information Commissioner.
Annex II. Technical and organisational measures
The measures set out in Section 6 (Confidentiality of Personnel), Section 7 (Security Measures), Section 11 (Personal Data Breach Notification), Section 12 (Data Retention) and Section 13 (Return and Deletion of Personal Data) are incorporated into this Annex II in full. Mapped to Article 32 GDPR, they are:
- Encryption: TLS 1.2 or higher for data in transit, and encryption at rest for databases and file storage.
- Confidentiality: role-based access control on the least-privilege principle, and written confidentiality obligations on all personnel with access to Personal Data.
- Integrity and availability: encrypted, access-controlled backups used only for disaster recovery, as described in Section 12, and monitoring of production systems.
- Resilience and restoration: documented incident response procedures with defined escalation paths and the notification timelines in Section 11.
- Testing and evaluation: regular security assessments and timely vulnerability remediation.
- Logging: audit logging of administrative and API access to Personal Data.
- Data minimisation and retention: the retention limits in Section 12 and the return and deletion process in Section 13.
- Measures for transfers to sub-processors: contractual data protection obligations no less protective than this DPA, as required by Section 8.
For transfers under Module Three of the Standard Contractual Clauses, these are the measures the data importer applies, and they are the measures to be imposed on any onward sub-processor.
19. Contact
For any questions about this DPA or to request a counter-signed copy:
Privacy & Security
Oceanir LLC
Email: [email protected]
Web: oceanir.ai/security
This DPA is incorporated into and forms part of the Oceanir SaaS Agreement and Privacy Policy.