diving.software

Diving ecosystem

Diving.Management Complete diving industry ecosystem Diving.Voyage Platform for divers worldwide Diving.Shopping Diving equipment shopping marketplace Diving.Software Dive business management software
  • Features
  • About Us
  • Pricing
  • Compare
  • FAQ
  • Contact
  • Sign In
  • Get Started
Menu
Features About Us Pricing Compare FAQ Contact
Legal Center Diving.Software
Overview 01Platform Terms 02Privacy Notice 03Data Processing Addendum 04Cookie Notice 05Subprocessors 06Payments & Stripe Connect 07Booking Terms 08Cancellations & Refunds 09Electronic Records & Safety Data
Need help?Contact Webase Global
Legal documents
Overview Platform TermsPrivacy NoticeData Processing AddendumCookie NoticeSubprocessorsPayments & Stripe ConnectBooking TermsCancellations & RefundsElectronic Records & Safety Data

Diving.Software Legal

Data Processing Addendum

The controller-to-processor terms that apply to organization-scoped data.

Effective 14 September 2026 Version 1.0

This DPA forms part of the agreement between the business customer (“Controller”) and the Platform Provider (“Processor”) for Diving.Software. It applies where the Processor handles personal data on the Controller's behalf. Capitalised data-protection terms have the meanings given by applicable law, including the GDPR where it applies.

1. Instructions and scope

The Processor will process personal data only to provide, secure, support and improve the contracted service under documented instructions in the agreement, product settings and authorised use. It will notify the Controller if an instruction appears unlawful, unless prohibited. Processing for the Processor's independent controller purposes is governed by the Privacy Notice and is outside this DPA.

2. Controller obligations

The Controller determines lawful purposes and bases, gives required notices, obtains valid consents where relied upon, limits data to what is necessary, configures retention and access, responds to individuals and ensures instructions are lawful. The Controller must not upload unlawful data or use sensitive information for unrelated profiling or marketing.

3. Confidentiality and personnel

The Processor ensures that authorised personnel are bound by confidentiality, receive appropriate security/privacy training and access data only as necessary for their role.

4. Security

The Processor will maintain measures appropriate to risk, including:

  • logical tenant isolation using organization UUID scope;
  • role-based access and least privilege;
  • authentication, session and CSRF controls;
  • encryption in transit and provider-managed encryption at rest where available;
  • secret management and separation of environments/credentials;
  • authorised file routes, safe filenames and upload validation;
  • logging/audit of critical changes and payment events;
  • verified and idempotent webhooks;
  • vulnerability/dependency maintenance, backups and recovery procedures;
  • restricted access and handling for health, waiver and minor data;
  • incident response and periodic control review.

The Processor may update controls while maintaining an equivalent or stronger protection level.

5. Subprocessors

The Controller grants general authorisation for subprocessors in the Provider Schedule. The Processor will give advance notice of a new subprocessor where required, allowing a reasonable objection based on documented data-protection grounds. The Processor will impose materially equivalent obligations and remains responsible for subprocessor performance to the extent required by law.

6. International transfers

Restricted transfers will use an applicable adequacy decision, the then-current EU Standard Contractual Clauses or another lawful safeguard. Where SCCs are required, the appropriate controller-to-processor module is incorporated, this DPA and its schedules complete the annexes, the competent supervisory authority and governing law follow the Controller's establishment where required, and conflicting commercial clauses yield to the SCCs. The parties will cooperate on transfer-impact assessment and supplementary measures.

7. Individual requests

Taking account of the processing, the Processor will provide reasonable technical and organisational assistance for access, correction, deletion, restriction, portability, objection and automated-decision requests. If the Processor receives a request concerning Controller data, it will direct it to the Controller and not respond substantively unless authorised or legally required.

8. Breach notification

The Processor will notify the Controller without undue delay after confirming a personal-data breach affecting Controller data and provide available information on nature, categories, likely consequences, measures and contact. Information may be supplied in phases. The Controller remains responsible for authority and individual notifications unless law assigns otherwise.

9. Assessments and consultation

The Processor will reasonably assist with security, data-protection impact assessments and prior consultation, considering the nature of processing and information available. Additional bespoke work may be charged at agreed rates unless caused by the Processor's breach.

10. Return and deletion

At termination or written instruction, the Processor will return/export and delete Controller data according to the Platform Terms and Retention Schedule, unless law requires retention. Residual backups remain protected, are not restored for ordinary use and expire on schedule.

11. Audit

The Processor will provide information reasonably necessary to demonstrate compliance, such as current security summaries, subprocessor information and independent reports where available. If that is insufficient, the Controller may conduct one proportionate audit per year on reasonable notice, during business hours, without compromising other tenants, security or confidentiality. More frequent audits are allowed after a material incident or regulator request. The Controller bears ordinary audit costs unless material non-compliance is found.

12. Liability and precedence

Liability follows the Platform Terms except where mandatory data-protection law or the SCCs require otherwise. If this DPA conflicts with the Platform Terms on processing, this DPA controls; SCCs control over both for covered transfers.

Annex I — Processing description

  • Subject matter: hosting and operation of dive-business customer, booking, document, payment and operational workflows.
  • Duration: agreement term plus the deletion/retention period.
  • Nature: collection, recording, organisation, storage, retrieval, consultation, transmission, reconciliation, restriction, export, deletion and support.
  • Purposes: provide the configured Software service under Controller instructions.
  • Data subjects: customers/divers, participants, guardians, emergency contacts, staff, contractors, business contacts and persons in communications/incidents.
  • Personal data: identity/contact, account IDs, booking/service, certifications/experience, documents/signatures, equipment, communications, payment references, technical/audit data and business records.
  • Special data: health/medical, accessibility, insurance and incident information where the Controller uses those features.
  • Frequency: continuous during use of the service.
  • Controller instructions: the agreement, authorised settings/actions and documented support requests.

Annex II — Subprocessors and transfers

The Provider Schedule in `00-legal-and-booking-schedules.md` is incorporated and must be published with legal entity, location and safeguard fields completed.

Annex III — Security contacts

Processor security/privacy contact: the address in the Platform Identity Schedule. Controller contact: the verified administrative or privacy contact in the organization account.

Diving.Software

Diving.Software is the all-in-one operating system built for dive businesses. It is part of Diving.Management, the hub behind connected solutions for the global diving industry.

Product

Features About Us Pricing FAQ Contact

Compare

DiveShop360 Dive Admin HALIBLU AquaDivePro Rezdy

Ecosystem

Diving.Management Diving.Voyage Diving.Shopping Diving.Software

Legal

Legal Center Platform Terms Privacy Notice Cookie Notice

© 2026 Diving.Software | All rights reserved. Part of the Diving.Management ecosystem.