Data Processing Addendum
Last updated: Oct 4, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between The Schoeller Group LLC ("Processor") and an organisation customer on a Team, API or Enterprise plan ("Customer") whenever Voydar processes personal data on the Customer's behalf, for example member accounts managed by the Customer or a private AIS feed. It applies automatically; a signed copy is available on request at privacy@voydar.com.
1. Roles and scope
Customer is the controller and The Schoeller Group LLC is the processor of Customer Personal Data: personal data Voydar processes for Customer under the agreement. The Schoeller Group LLC processes it only to provide the Service, on Customer's documented instructions (the agreement, this DPA and Customer's use of the Service's features), unless the law requires otherwise, in which case we will tell Customer first where allowed. Details of the processing are in Annex 1 below.
2. Confidentiality
Everyone authorised to process Customer Personal Data is bound by confidentiality obligations.
3. Security
The Schoeller Group LLC maintains appropriate technical and organisational measures, including: encryption in transit (TLS); row-level security isolating each account's data; least-privilege database roles; multi-factor authentication and audit logging for administrative access; encrypted backups; and vulnerability management under our security policy.
4. Sub-processors
Customer authorises the sub-processors listed on our sub-processors page. We impose data protection obligations on each that are no less protective than this DPA and remain responsible for them. We give at least 30 days' notice of a new sub-processor by updating that page and emailing account owners; Customer may object on reasonable data-protection grounds, and if we can't resolve the objection, Customer may terminate the affected service and receive a refund of prepaid fees for it.
5. Assistance and data subject requests
Taking into account the nature of the processing, we help Customer respond to data subject requests and meet its obligations on security, breach notification, impact assessments and prior consultation. We forward any request we receive directly about Customer Personal Data to Customer.
6. Personal data breaches
We notify Customer without undue delay, and where feasible within 72 hours, after becoming aware of a breach affecting Customer Personal Data, with the information Customer reasonably needs to meet its own obligations.
7. Deletion and return
On termination, Customer can export its data through the Service; we then delete Customer Personal Data (private feed positions are deleted on their schedule of at most 90 days, and deleted data leaves encrypted backups as they expire), unless the law requires us to keep it.
8. Audits
We make available the information reasonably necessary to demonstrate compliance with this DPA, including written answers to security questionnaires once a year. Any on-site audit requires reasonable notice, is limited to once a year, and is at Customer's cost.
9. International transfers
Customer Personal Data is processed in the United States. For transfers from the EEA, the EU Standard Contractual Clauses (Commission Decision 2021/914, Module Two, or Module Three where Customer is itself a processor) are incorporated by reference, with Customer as data exporter and The Schoeller Group LLC as data importer; Clause 7 (docking) applies; Clause 9 option 2 (general authorisation) applies with the notice period above; Clause 11's optional language does not apply; Clauses 17 and 18 select the law and courts of Ireland. For transfers from the UK, the UK International Data Transfer Addendum applies, and from Switzerland, the SCCs as adapted for Swiss law.
10. US state privacy laws
Where the CCPA/CPRA or a similar US state law applies, The Schoeller Group LLC is a service provider (or processor): it will not sell or share Customer Personal Data, retain, use or disclose it for any purpose other than providing the Service, or combine it with other data except as those laws allow, and it certifies that it understands these restrictions.
11. Liability and order of precedence
Each party's liability under this DPA is subject to the limitations of liability in the agreement. If this DPA conflicts with the agreement, this DPA prevails for the processing of Customer Personal Data; the Standard Contractual Clauses prevail over both.
12. Annex 1: Details of processing
- Subject matter and duration: providing the Service for the term of the agreement.
- Nature and purpose: hosting, storing, displaying and transmitting data in the Service as the Customer directs.
- Data subjects: Customer's members and users; people whose data appears in a Customer's private AIS feed, if any.
- Personal data: names and email addresses of members, account and usage records, API keys metadata, and private AIS feed data (vessel identifiers and positions), which may relate to identifiable people.
- Special categories: none intended.