Dive Shop Manager Back to the site

Data processing agreement

Version 1.0 · 13.09.2026

This agreement applies automatically when you open a centre. You do not have to sign anything separately — but you may, and we will counter-sign. Write to privacy@diveshopmanager.com.

1. Who is who

You — the dive centre — are the controller for everything you enter about your guests and your staff. You decide what is collected and why.

We — Aquatics Global Holdings LLC — are the processor. We hold that data for you and act only on your instructions.

For your own account, your billing data and this website we are the controller; that is covered by the privacy notice, not by this agreement.

2. What we process, and why

Subject matterOperating a dive centre: planning dives, guests, courses, staff, equipment, rentals, sales
DurationFor as long as your account exists
Nature and purposeStoring, organising, computing and displaying the data you enter, so that the service works
Data subjectsYour guests, your staff, your partners' contacts
Types of dataIdentification and contact data, date of birth, certifications and dive history, equipment sizes, emergency contacts, working time, sales records
Special categoriesYes — data concerning health: the dive medical statement

The special category is deliberately small. The system stores three facts about a medical statement: that it was signed and when, whether any answer was yes, and what a physician said. Which question was answered yes is never asked for and never stored. Each statement carries its own deletion date.

3. Our obligations

4. Sub-processors

You give general authorisation for the sub-processors below. We will announce any change at least 30 days in advance in the product. If you object on reasonable data protection grounds, you may terminate for the remaining period without penalty.

WhoWhat forWhere
Vercel Inc.Hosting, delivery, server logsUSA
Neon Inc.DatabaseUSA (us-east-1)
Resend, Inc.The three access emailsUSA

Resend, Inc. (United States) sends the three access emails — password reset, password changed, invitation. It receives the recipient address, subject and message text, and reports back whether the message arrived. It is bound by a data processing agreement with the Standard Contractual Clauses. Open and click tracking is switched off.

5. Transfers out of the EU

We are established in the United States and the data is stored there. For that transfer the parties adopt the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), Module Two: controller to processor, which are incorporated into this agreement by reference and are available at eur-lex.europa.eu.

Clause 7 (docking)applies
Clause 9 (sub-processors)Option 2, general authorisation, 30 days' notice
Clause 11 (redress)the optional independent dispute body is not used
Clause 17 (governing law)The law of the Republic of Cyprus — the Member State where our Article 27 representative is established
Clause 18 (forum)the courts of that Member State
Annexes I, II, IIIclauses 2, 4 and Annex II of this agreement

Where the clauses and this agreement disagree, the clauses win.

6. Audits

You may satisfy yourself that we keep to this agreement. In the first instance we answer in writing and provide what we have. Where that is not enough, an on-site or remote audit may take place once per year, with 30 days' notice, at your cost, by you or an auditor who is not our competitor and who is bound to confidentiality.

Annex II — Technical and organisational measures

Not a catalogue of good intentions. This is what is in the product, and most of it can be checked from outside.

Separation between dive centres

Two independent walls. Every query is limited to one centre in the application, and the database enforces the same limit again by itself (row-level security). The application connects with an account that cannot bypass that rule, never as the database owner — and a health endpoint fails loudly if it ever does.

Access

The interface to other systems

Read only. It cannot write, and it never returns dates of birth, equipment sizes or anything concerning health. A revoked or expired key gets the same answer as an invented one: not found.

Deletion

Medical statements carry their own deletion date and a nightly job acts on it, independently of the rest of the guest record. Deleting a centre removes everything belonging to it.

Availability and integrity

What we do not do