Data Processing Addendum
Last Updated: July 3, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Dive Connect, LLC("DiveConnect," "Processor") and the customer using DiveConnect.ai ("Customer," "Controller"). It applies where DiveConnect processes personal data of the Customer's own end-customers ("Customer Personal Data") on the Customer's behalf, and reflects the requirements of applicable data-protection laws, including the EU and UK GDPR and the CCPA/CPRA.
1. Roles of the Parties
For Customer Personal Data, the Customer is the controller (or a processor acting for its own customer) and DiveConnect is the processor (or subprocessor). DiveConnect processes Customer Personal Data only to provide the Service and only on the Customer's documented instructions, including as set out in the Terms of Service and this DPA. For clarity, DiveConnect is an independent controller of account and usage data it collects about the Customer itself, as described in the Privacy Policy.
2. Customer Instructions & Compliance
The Customer is responsible for the accuracy and legality of Customer Personal Data and for having a lawful basis to provide it. The Customer instructs DiveConnect to process Customer Personal Data to operate the Service. DiveConnect will inform the Customer if, in its opinion, an instruction infringes applicable data-protection law.
3. Confidentiality
DiveConnect ensures that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations.
4. Security
DiveConnect implements and maintains appropriate technical and organizational measures to protect Customer Personal Data, as described in Annex II below.
5. Subprocessors
The Customer authorizes DiveConnect to engage the subprocessors listed in Annex III and in our Privacy Policy. DiveConnect imposes data-protection obligations on each subprocessor that are no less protective than those in this DPA, and remains responsible for its subprocessors' performance. DiveConnect will give the Customer notice of intended changes to subprocessors and a reasonable opportunity to object on data-protection grounds.
6. Data-Subject Requests
Taking into account the nature of the processing, DiveConnect will assist the Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects to exercise their rights. If DiveConnect receives such a request directly, it will advise the data subject to contact the Customer.
7. Personal-Data Breaches
DiveConnect will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, and will provide information reasonably available to it to help the Customer meet its own notification obligations.
8. Assistance & Audits
DiveConnect will assist the Customer, taking into account the nature of processing and the information available, with data-protection impact assessments and prior consultations, and will make available information reasonably necessary to demonstrate compliance with this DPA.
9. International Transfers
Where processing involves transferring Customer Personal Data out of the EEA, UK, or Switzerland to a country without an adequacy decision, the parties rely on the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, which are incorporated by reference and completed by the details in the Annexes.
10. Return & Deletion
On termination of the Service, DiveConnect will, at the Customer's choice, delete or return Customer Personal Data and delete existing copies, except to the extent applicable law requires storage. The Customer may export its data before termination and for a limited period afterward.
11. Liability & Precedence
Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. If there is a conflict between this DPA and the Terms of Service regarding the processing of Customer Personal Data, this DPA controls; where the SCCs apply, the SCCs control over both.
Annex I — Description of Processing
- Subject matter & duration: processing of Customer Personal Data for the term of the Service.
- Nature & purpose: hosting, storing, and processing Customer Personal Data to provide the dashboard, storefront, booking, retail/rental, communication, and related features the Customer uses.
- Types of personal data: end-customer contact details (such as name, email, phone), booking and purchase records, and any other data the Customer chooses to enter.
- Categories of data subjects: the Customer's customers, prospects, and contacts.
Annex II — Security Measures
- Encryption of data in transit (TLS) and encryption at rest for stored data.
- Role-based access controls and least-privilege access to production systems.
- Authentication managed via Supabase; administrative access restricted and logged.
- Network isolation and managed hosting through Vercel and Supabase.
- Error and performance monitoring (Sentry) to detect and respond to issues.
- Regular backups and documented incident-response practices.
Annex III — Subprocessors
- Supabase — database, authentication, and file storage.
- Vercel — application hosting.
- Stripe — payment and payout processing (Stripe Connect).
- Resend — transactional and account email.
- Sentry — error and performance monitoring.
- AI providers (Anthropic, OpenAI, ElevenLabs, Replicate) — only where the Customer submits content to AI features. The Customer should not enter end-customer personal data into AI prompts.
Contact
Dive Connect, LLC
7901 4TH ST N STE 27295, St Petersburg, FL 33702, USA
Data protection: privacy@diveconnect.io
