Data Processing Addendum
MarineClaims Pro — claims assessment and marine asset survey platform
Effective 1 July 2026 · Version 3.0
This Data Processing Addendum (“DPA”) forms part of the MarineClaims Pro Terms of Service between Sustainable Transport Advisory Pty Ltd (“STA”, “Processor” where acting as such) and the customer entity using MCP (“Customer”, “Controller” / APP entity where acting as such).
Related: Privacy Policy · Subprocessors · Security Overview · Acceptable Use Policy
1. Purpose and order of precedence
This DPA sets out the parties’ responsibilities when STA processes Personal Information / Personal Data contained in Customer Content on the Customer’s behalf to provide MCP.
If this DPA conflicts with the Terms on data-processing topics, this DPA prevails. The Privacy Policy describes STA’s practices for account and website data where STA determines purposes.
2. Definitions
In this DPA:
- Customer Content means claims, surveys, inspections, reports, documents, images, directories, messages and other content submitted to MCP by or for the Customer (including Portal Users).
- Personal Information has the meaning in the Privacy Act 1988 (Cth).
- Personal Data has the meaning in UK GDPR where UK law applies.
- Processing means any operation on Personal Information / Personal Data (collection, storage, use, disclosure, deletion, etc.).
- Subprocessor means a third party engaged by STA to Process Customer Content on STA’s behalf to deliver MCP.
- Applicable Data Law means the Privacy Act and APPs, and where applicable UK GDPR / Data Protection Act 2018, and any similar law expressly agreed in writing.
Other capitalised terms have the meaning in the Terms.
3. Roles
3.1 For Customer Content, the Customer determines the purposes and means of Processing (APP entity / Controller). STA Processes Customer Content as a service provider / Processor on documented instructions.
3.2 For STA account data, billing contacts, product analytics about MCP usage, and similar platform data, STA typically acts as APP entity / Controller — see Privacy Policy.
3.3 Each party will comply with Applicable Data Law in its respective role.
4. Customer instructions and responsibilities
4.1 The Customer instructs STA to Process Customer Content to:
- provide, maintain, secure and support MCP;
- follow configuration and in-product settings chosen by the Customer;
- comply with law and the Agreement suite.
4.2 The Customer warrants that its instructions are lawful and that it has provided all notices and obtained all consents required to upload Personal Information / Personal Data into MCP and to share it with invitees.
4.3 The Customer should only include sensitive personal information when it is necessary for a legitimate claim or survey purpose and lawful, and should apply need-to-know sharing inside MCP.
4.4 If STA reasonably believes an instruction breaches Applicable Data Law, STA will notify the Customer and may pause that Processing until clarified.
5. STA processor obligations
STA will:
- Process Customer Content only on documented instructions (including this DPA and the Terms), unless required by law (in which case STA will notify the Customer unless legally prohibited);
- Ensure persons authorised to Process Customer Content are bound by confidentiality;
- Implement appropriate technical and organisational measures — see Security Overview;
- Assist the Customer, insofar as possible and taking into account the nature of Processing, with requests from individuals and with privacy assessments reasonably required;
- Notify the Customer without undue delay after becoming aware of a Personal Information / Personal Data breach affecting Customer Content, and provide information reasonably available to help the Customer meet notification duties (including Australia’s Notifiable Data Breaches scheme and, where applicable, UK controller duties);
- At termination or on written request, delete or return Customer Content within commercially reasonable timeframes (target 30 days for primary systems; backups retained according to the managed database provider’s backup cycle), unless law requires retention or the Customer keeps an active archive feature;
- Make available information reasonably necessary to demonstrate compliance with this DPA; and
- Not sell Customer Content.
Audit rights: upon reasonable written notice, no more than once per year (unless a confirmed breach), STA will provide security summary information it maintains. On-site audits only if required by mandatory law or a signed enterprise Order.
6. Subprocessors
6.1 The Customer authorises STA to engage Subprocessors to deliver MCP. A current list is at Subprocessors.
6.2 STA will impose written data-protection obligations on Subprocessors that are materially no less protective than this DPA regarding Customer Content.
6.3 STA remains responsible to the Customer for Subprocessor Processing of Customer Content as required by Applicable Data Law.
6.4 STA will update Subprocessors when material Subprocessors change and, where feasible, notify account owners by email before a material new Subprocessor begins Processing Customer Content. If the Customer reasonably objects on data-protection grounds, the parties will discuss alternatives in good faith; if unresolved, the Customer may terminate the affected subscription for convenience before the change takes effect (prepaid unused fees handled per Terms).
7. International transfers (Australia — APP 8)
STA will take steps required under APP 8 before disclosing Personal Information overseas, including using contractual protections and assessing recipients where required.
MCP application compute and managed databases (Postgres and Redis) run on DigitalOcean in Sydney, Australia. Claim files, photos, PDFs and signatures may be stored with Cloudflare R2 (United States provider; storage location not locked to Australia). Other Subprocessors may Process information outside Australia — see Subprocessors.
8. Duration
This DPA starts on the effective date of the Customer’s MCP agreement and continues until STA ceases Processing Customer Content.
9. Liability
Liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where prohibited by Applicable Data Law.
10. Governing law
This DPA follows the governing law in the Terms (Victoria, Australia), except that the UK Schedule applies additional UK terms where UK GDPR governs the Processing.
Schedule A — Description of Processing
| Item | Description |
|---|---|
| Subject matter | Hosting and Processing Customer Content in MCP |
| Duration | Term of the subscription + deletion/return period |
| Nature and purpose | Storage, retrieval, transmission, display, backup, support, security, and workflow features for marine claims, surveys, inspections and related portals |
| Types of Personal Information / Personal Data | Names, contact details, claim and vessel-related identifiers, insured/claimant details, inspection notes, documents, images, user account identifiers within Customer Content — as submitted by Customer |
| Categories of individuals | Customer staff; insurers; claimants/policy holders; vessel owners; witnesses; other persons whose details Customer elects to store |
| Frequency | Continuous during use of MCP |
Schedule B — UK GDPR Schedule (UK customers / UK Personal Data)
B1. Application. This Schedule applies where UK GDPR applies to STA’s Processing of Personal Data in Customer Content for the Customer.
B2. Roles. Customer is Controller; STA is Processor.
B3. Article 28 terms. Without limiting the DPA body:
- STA Processes only on documented instructions (including regarding international transfers);
- STA ensures confidentiality of Processing staff;
- STA implements appropriate security measures (UK GDPR Art 32) — see Security Overview;
- STA respects Subprocessor conditions (general authorisation with notice via Subprocessors);
- STA assists with data subject rights, security, breach notification, and DPIAs where reasonable given the nature of Processing;
- STA deletes or returns Personal Data at the end of services as set out above;
- STA will inform the Customer if, in its opinion, an instruction infringes UK GDPR.
B4. International transfers. Where STA transfers UK Personal Data to a third country, STA will do so under a lawful transfer mechanism (adequacy regulations, the UK International Data Transfer Agreement / Addendum, or another valid mechanism under UK GDPR) and will document the mechanism used for the relevant Subprocessors listed at Subprocessors.
B5. Breach notice. STA will notify the Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Content, with facts reasonably available (nature, categories, approximate numbers, likely consequences, measures taken).
B6. Conflict. For UK GDPR Processing topics, this Schedule prevails over conflicting DPA body text; it does not change Victoria governing law of the commercial Terms unless an Order says otherwise.
Contact — The STA Team
support@sta-au.com · info@sta-au.com
Sustainable Transport Advisory Pty Ltd, ABN 75 657 423 222, Newport VIC 3015
— The STA Team
