BerthRight

Data Processing Addendum

Version 1.0

Effective Date: August 24, 2026

Last Updated: August 24, 2026

Berth Right MGMT LLC — Marina Management Platform

Data Processing Addendum

This Data Processing Addendum (this “DPA”) is entered into by and between:

Berth Right MGMT LLC, a Florida limited liability company doing business as BerthRight, with a principal place of business at 741 West Ave, Ocean City, NJ 08226 (“BerthRight”); and

[Customer legal name], a [State] [entity type] with a principal place of business at [Customer address] (“Customer” or “Marina Operator”).

BerthRight and Customer are referred to individually as a “Party” and collectively as the “Parties.”

This DPA is incorporated into and forms part of the Master Services Agreement, Terms of Service, or other written or electronic agreement between the Parties governing Customer’s access to and use of the Services (the “Agreement”). Capitalized terms used but not defined in this DPA have the meanings given in the Agreement.

Recitals

A. Customer owns, operates, or manages one or more marina facilities and uses BerthRight’s white-label, multi-tenant marina management platform to manage slip reservations, transient dockage, storage, service work, haul and launch scheduling, waitlisting, billing and invoicing, point-of-sale transactions, email and SMS communications with its boater customers, reporting and analytics, (the “Services”).

B. In the course of providing the Services, BerthRight processes personal information relating to Customer’s boater customers, prospective customers, and staff.

C. Customer determines the purposes and means of that processing. BerthRight processes that personal information solely on Customer’s behalf and on Customer’s documented instructions.

D. The Parties wish to set forth the terms governing that processing, and to satisfy the contract requirements imposed on controllers and processors, and on businesses and service providers, by applicable United States privacy laws.

NOW, THEREFORE, in consideration of the mutual covenants set forth below and in the Agreement, the Parties agree as follows:

1. Definitions

1.1 “Applicable Privacy Law” means each United States federal, state, or local law, regulation, or binding regulatory guidance relating to privacy, data protection, data security, breach notification, or the processing of personal information that applies to a Party’s processing of Personal Information under the Agreement, including without limitation: the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act, and its implementing regulations; the Virginia Consumer Data Protection Act (Va. Code § 59.1-575 et seq., including the processor-contract requirements of Va. Code § 59.1-579); the New Jersey Data Privacy Act, effective January 15, 2025; and the comprehensive consumer privacy statutes of Colorado, Connecticut, Utah, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, Minnesota, Tennessee, Maryland, Indiana, Kentucky, Rhode Island, and Texas; together with applicable state data breach notification statutes and applicable state reasonable-security statutes, including Cal. Civ. Code § 1798.81.5.

1.2 “Business” has the meaning given in the CCPA. For purposes of this DPA, Customer is the Business with respect to Personal Information processed under the Agreement.

1.3 “Business Purpose” has the meaning given in the CCPA, and for purposes of this DPA means the specific purposes enumerated in Section 4.2.

1.4 “CCPA” means the California Consumer Privacy Act of 2018, Cal. Civ. Code § 1798.100 et seq., as amended by the California Privacy Rights Act of 2020, together with its implementing regulations at Cal. Code Regs. tit. 11 § 7000 et seq.

1.5 “Consumer” means a natural person who is a “ consumer,” “data subject,” or equivalent under Applicable Privacy Law, and for purposes of this DPA includes End Users and Authorized Users whose Personal Information is processed under the Agreement.

1.6 “Consumer Rights Request” means a request by or on behalf of a Consumer to exercise a right under Applicable Privacy Law, including a request to know, access, obtain a copy of, port, correct, delete, limit the use or disclosure of, opt out of the sale or sharing of, or opt out of targeted advertising or profiling using, that Consumer’s Personal Information, and a request to appeal the denial of any of the foregoing.

1.7 “Controller” means the natural or legal person that, alone or jointly with others, determines the purpose and means of processing Personal Information. For purposes of this DPA, Customer is the Controller with respect to Personal Information processed under the Agreement.

1.8 “Customer Data” has the meaning given in the Agreement, and includes all Personal Information contained within it.

1.9 “De-identified Data” means data that cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable natural person or a device linked to such a person, and that is processed in accordance with Section 4.6.

1.10 “End User” means a boater, slip holder, vessel owner, vessel operator, transient guest, storage customer, service customer, or other individual who is a customer or prospective customer of Customer and whose Personal Information is processed through the Services. End Users are Customer’s customers, not BerthRight’s customers.

1.11 “Personal Information” means information contained in Customer Data that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Consumer or household, and that constitutes “personal information,” “ personal data,” or an equivalent term under Applicable Privacy Law. “Personal Information,” “personal data,” and “Personal Data” are used interchangeably in this DPA and in the Agreement. Personal Information does not include De-identified Data or aggregate consumer information processed in accordance with Section 4.6.

1.12 “Processing” means any operation or set of operations performed on Personal Information, whether or not by automated means, including collection, use, storage, disclosure, analysis, deletion, modification, transmission, retention, and destruction. “Process,” “Processes,” and “ Processed” have corresponding meanings.

1.13 “Processor” means the natural or legal person that Processes Personal Information on behalf of a Controller. For purposes of this DPA, BerthRight is the Processor.

1.14 “Security Incident” means a confirmed breach of BerthRight’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, Personal Information in BerthRight’s possession or control. A Security Incident does not include: unsuccessful login attempts; pings, port scans, or other network reconnaissance that does not result in unauthorized access; denial-of-service attempts that do not result in unauthorized access to or acquisition of Personal Information; malware detected and blocked before execution; or an event affecting only data that has been rendered unusable, unreadable, or indecipherable through encryption where the encryption key was not compromised. An incident caused by, or confined to, Customer’s own credentials, configuration, or Authorized Users is addressed in Section 10.7.

1.15 “Sell,” “Sale,” “Share,” and “ Sharing” have the meanings given in the CCPA.

1.16 “Sensitive Personal Information” means “sensitive personal information” as defined in the CCPA and “sensitive data” as defined in the Virginia-model statutes, including without limitation government-issued identification numbers (Social Security, driver’s license, state identification card, passport); financial account numbers or payment card numbers in combination with any security or access code, password, or credentials permitting access to an account; precise geolocation; racial or ethnic origin; religious or philosophical beliefs; citizenship or immigration status; the contents of a Consumer’s mail, email, or text messages where BerthRight is not the intended recipient; genetic or biometric data processed for the purpose of uniquely identifying a natural person; personal information collected and analyzed concerning a Consumer’s health, sex life, or sexual orientation; and personal information of a known child.

1.17 “Service Provider” has the meaning given in the CCPA. For purposes of this DPA, BerthRight is the Service Provider.

1.18 “Subprocessor” means a third party engaged by BerthRight to Process Personal Information on BerthRight’s behalf in connection with the provision of the Services, including the entities listed in Annex I § 8 and published at https://berthright.app/subprocessors.

2. Roles, Scope, and the Bridging Clause

2.1 Roles of the Parties. With respect to Personal Information Processed under the Agreement, Customer is the Controller and Business, and BerthRight is the Processor and Service Provider. Customer determines the purposes and means of the Processing. BerthRight Processes Personal Information solely on Customer’s documented instructions as set forth in Section 3.

2.2 Scope. This DPA applies to all Processing of Personal Information by BerthRight on Customer’s behalf in connection with the Services. It does not apply to: (a) Personal Information that BerthRight Processes as a Controller in its own right, which is addressed in Section 2.5; (b) payment card data Processed by Stripe, Inc., which is addressed in Section 2.6; or (c) data that is not Personal Information.

2.3 Duration. This DPA takes effect on the effective date of the Agreement and continues for so long as BerthRight Processes Personal Information on Customer’s behalf, and thereafter as to any provision that by its nature is intended to survive (including Sections 6, 12, 14, and 15.4).

2.4 Bridging Clause — Equivalence of Terminology. The Parties acknowledge that Applicable Privacy Law uses different terminology to describe substantially equivalent roles and obligations. Accordingly, and to the maximum extent permitted by Applicable Privacy Law:

(a) each reference in this DPA to “Controller” is deemed also a reference to “Business” as defined in the CCPA, and each reference to “ Business” is deemed also a reference to “Controller”;

(b) each reference to “Processor” is deemed also a reference to “ Service Provider” as defined in the CCPA, and each reference to “Service Provider” is deemed also a reference to “Processor”;

(c) each reference to “Personal Information” is deemed also a reference to “personal data” as defined in the Virginia-model statutes;

(d) each reference to “Consumer” is deemed also a reference to “data subject,” “consumer,” or the equivalent term used in the applicable statute; and

(e) where an obligation in this DPA is expressed by reference to one statute but a substantially equivalent obligation exists under another Applicable Privacy Law, BerthRight’s performance of the obligation as stated in this DPA satisfies the equivalent obligation, provided that where two Applicable Privacy Laws impose obligations that differ in substance rather than in wording, BerthRight will comply with each as it applies.

(f) Nothing in this Section 2.4 (i) confers on either Party a status, role, or obligation under a statute that does not otherwise apply to it, (ii) waives any exemption available to either Party, or (iii) constitutes an admission that any particular Applicable Privacy Law applies to either Party or to any particular Processing.

2.5 BerthRight as Controller for Limited Purposes. BerthRight acts as an independent Controller, and not as a Processor, with respect to: (a) Personal Information of Customer’s billing and administrative contacts used for BerthRight’s own account administration, invoicing, contract management, support ticketing, and service communications; (b) Personal Information collected through BerthRight’s own marketing website, sales activities, and marketing communications directed to Customer as a business; and (c) system telemetry, security logs, and usage metrics to the extent BerthRight uses them for the purposes described in Section 4.6. BerthRight’s Processing in this capacity is governed by BerthRight’s own privacy policy published at https://berthright.app/privacy and not by this DPA.

2.6 Payment Card Data; Stripe Connect. Customer maintains its own Stripe account under Stripe Connect (Standard) and is the merchant of record for all transactions with End Users. Card data is captured exclusively through Stripe-hosted payment fields (Stripe Elements, Payment Element, Checkout, or the Stripe virtual terminal). BerthRight’s systems do not receive, transmit, or store full primary account numbers (“PAN”) or sensitive authentication data. BerthRight stores only Stripe-issued tokens and identifiers, card brand, the last four digits of the account number, and expiration date. With respect to cardholder data, Stripe, Inc. acts as an independent Controller and/or as Customer’s own processor under Customer’s direct agreement with Stripe, and not as BerthRight’s Subprocessor for that data. Customer’s relationship with Stripe, including Customer’s obligations under the Stripe Connected Account Agreement and under the Payment Card Industry Data Security Standard, is a matter between Customer and Stripe.

3. Processing Instructions

3.1 Documented Instructions. BerthRight will Process Personal Information only on Customer’s documented instructions, including with regard to transfers of Personal Information to a third country or an international organization, unless required to do otherwise by applicable law. Customer’s documented instructions consist of:

(a) the Agreement, including this DPA and its Annexes;

(b) Customer’s configuration and use of the Services, including the settings Customer selects, the workflows Customer enables, the data Customer and its Authorized Users and End Users submit, the communications Customer sends, and the integrations Customer activates; and

(c) any further written instruction Customer gives to BerthRight that the Parties agree in writing, which may be subject to additional fees if it requires effort materially beyond the scope of the Services.

3.2 Nature and Purpose of Processing. BerthRight Processes Personal Information for the purpose of providing, maintaining, securing, and supporting the Services to Customer. The nature of the Processing includes collection, recording, organization, structuring, storage, retrieval, consultation, use, transmission, disclosure to Subprocessors, restriction, erasure, and destruction, in each case as necessary to deliver the functionality described in Annex I § 6.

3.3 Type of Personal Information and Categories of Consumers. The types of Personal Information Processed and the categories of Consumers to whom it relates are set forth in Annex I.

3.4 Duration of Processing. BerthRight will Process Personal Information for the term of the Agreement and thereafter only as permitted by Section 12 (Return and Deletion).

3.5 Unlawful Instructions. BerthRight will immediately inform Customer if, in BerthRight’s reasonable opinion, an instruction from Customer infringes Applicable Privacy Law. BerthRight may suspend performance of the specific instruction, without liability, until the Parties resolve the matter. BerthRight is not obligated to, and does not, conduct a legal review of Customer’s instructions, and BerthRight’s failure to identify an unlawful instruction is not a breach of this Section.

3.6 Customer Responsibilities as Controller. Customer represents, warrants, and covenants that:

(a) it has provided all notices and obtained all consents, permissions, and rights necessary under Applicable Privacy Law for BerthRight and its Subprocessors to Process Personal Information as contemplated by the Agreement, including all consents required for email and SMS communications sent through the Services;

(b) its instructions to BerthRight comply with Applicable Privacy Law;

(c) it will maintain a publicly accessible privacy notice that accurately describes its collection and use of End User Personal Information and its use of service providers and processors;

(d) it is solely responsible for the accuracy, quality, and legality of Personal Information it and its Authorized Users and End Users submit to the Services, and for the means by which it acquired that Personal Information; and

(e) it will not submit, and will instruct its Authorized Users not to submit, Sensitive Personal Information to the Services except where the Services expressly provide a designated field for a specific data element and BerthRight has confirmed in writing that the field is intended for that purpose. This prohibition expressly includes health, medical, disability, accessibility, and mobility information, Social Security numbers, driver’s license and other government identification numbers, and full payment card numbers.

3.7 Instruction to Process Notwithstanding Prohibited Submission. If Customer or its Authorized Users nonetheless submit Sensitive Personal Information to the Services, BerthRight will Process it as Personal Information under this DPA and apply the security measures in Annex II to it, but BerthRight does not thereby assume the status of a controller, covered entity, business associate, or regulated processor of that data under any sectoral statute, and Customer remains responsible for the submission.

4. CCPA Service Provider Certification and Use Restrictions

4.1 Certification. BerthRight certifies that it understands the restrictions in this Section 4 and will comply with them. Specifically, BerthRight certifies that:

(a) BerthRight does not and will not Sell Personal Information, and does not and will not Share Personal Information, as those terms are defined in the CCPA;

(b) BerthRight does not receive Personal Information from Customer as consideration for the Services or for any other thing of value. BerthRight’s consideration under the Agreement consists solely of the Fees paid by Customer;

(c) BerthRight will not retain, use, or disclose Personal Information for any purpose other than the specific Business Purposes enumerated in Section 4.2, including will not retain, use, or disclose Personal Information for a commercial purpose other than those Business Purposes;

(d) BerthRight will not retain, use, or disclose Personal Information outside the direct business relationship between BerthRight and Customer;

(e) BerthRight will not combine Personal Information received from or on behalf of Customer with Personal Information it receives from or on behalf of any other person, or that it collects from its own interaction with a Consumer, except as expressly permitted by Section 4.6 or as otherwise permitted by the CCPA for a service provider; and

(f) BerthRight will comply with the obligations applicable to it under the CCPA, including by providing the same level of privacy protection as the CCPA requires of a business, and by implementing and maintaining reasonable security procedures and practices appropriate to the nature of the Personal Information, as required by Cal. Civ. Code § 1798.81.5.

4.2 Specified Business Purposes. BerthRight Processes Personal Information solely for the following specific Business Purposes, and for no other purpose:

(a) Slip and berth management — maintaining slip, berth, mooring, rack, and yard inventory; recording slip assignments; and matching vessels to berths based on vessel dimensions and draft;

(b) Reservation and dockage management — accepting, confirming, modifying, and cancelling seasonal, annual, and transient dockage reservations; recording arrival, departure, and stay history; and managing check-in and check-out;

(c) Waitlist management — maintaining waitlists for slips and services, recording waitlist position and priority, and notifying End Users of availability;

(d) Storage, service, and haul-and-launch management — scheduling and recording winter and dry storage, service work orders, haul-outs, launches, and related yard operations;

(e) Billing, invoicing, and payment facilitation — generating and delivering invoices and statements; recording amounts due, paid, and outstanding; storing Stripe tokens and payment-method metadata to enable Customer to charge End Users; processing refunds and credits at Customer’s direction; and dunning and collections communications sent at Customer’s direction;

(f) Point-of-sale transactions — recording retail, fuel, pumpout, and ancillary sales and associating them with an End User account or a walk-in transaction;

(g) Customer communications — composing, sending, delivering, and logging transactional and operational email and SMS messages to End Users at Customer’s direction, and recording consent, opt-in, and opt-out status;

(h) Account provisioning, authentication, and access management — creating, authenticating, and managing Authorized User and End User accounts, sessions, multi-factor authentication, and role assignments;

(i) Reporting and analytics for Customer — generating occupancy, revenue, utilization, aging, and operational reports for Customer’s own use within Customer’s tenant;

(k) Technical support, incident diagnosis, debugging, and error correction, including reproducing and resolving issues reported by Customer;

(l) Maintaining, securing, and ensuring the availability, integrity, and continuity of the Services, including backup, disaster recovery, capacity management, fraud and abuse detection and prevention, and detecting and responding to security incidents;

(m) Data migration, import, export, and onboarding at Customer’s direction; and

(n) Compliance with BerthRight’s legal obligations, including responding to lawful requests from public authorities and defending legal claims.

4.3 No Use for BerthRight’s Own Purposes. BerthRight will not use Personal Information for its own commercial purposes, including to market to End Users, to build or enrich profiles of End Users, to create or contribute to any data product, or to benchmark or advertise to other customers, except as expressly permitted by Section 4.6.

4.4 No Cross-Tenant Use. BerthRight will not use or disclose Personal Information belonging to one Customer’s tenant for the benefit of, or in the provision of Services to, any other customer, and will not combine Personal Information across tenants, except as expressly permitted by Section 4.6. Tenant isolation is enforced technically as described in Annex II § 4.

4.5 No AI or Machine Learning Processing. BerthRight does not use artificial intelligence or machine learning to process Personal Information, does not use Personal Information to train, fine-tune, or improve any model whether its own or a third party’s, and does not disclose Personal Information to any AI model provider. BerthRight will give Customer prior written notice and update this DPA and the subprocessor list before introducing any such processing.

(a) BerthRight will not use Personal Information to train, fine-tune, or otherwise improve any general-purpose or foundation model, and will not permit any Subprocessor or model provider to do so;

(c) BerthRight will contractually require any third-party model provider to process inputs and outputs solely to return the response, to refrain from training on them, and to apply zero-day or short-duration retention; and

(d) BerthRight will not use the Services’ AI functionality to make, or to substantially facilitate, any decision producing a legal or similarly significant effect concerning a Consumer.

4.6 De-identified and Aggregated Data. BerthRight may create and use De-identified Data and aggregate consumer information derived from Personal Information for the purposes of operating, securing, analyzing, maintaining, benchmarking, and improving the Services, provided that BerthRight: (a) takes reasonable measures to ensure the data cannot be associated with a Consumer, household, or Customer; (b) publicly commits to maintain and use the data only in de-identified form and not to attempt to reidentify it; (c) contractually obligates any recipient to comply with the foregoing; and (d) does not disclose De-identified Data in a form that identifies or is reasonably capable of identifying Customer or any individual marina without Customer’s prior written consent.

4.7 Notice of Inability to Comply. BerthRight will notify Customer in writing without undue delay if BerthRight determines that it can no longer meet its obligations under this DPA or under the CCPA. Upon receiving such a notice, or upon Customer’s reasonable belief that BerthRight is Processing Personal Information in an unauthorized manner, Customer may exercise the rights in Section 4.8.

4.8 Customer’s Right to Stop and Remediate. Customer has the right, upon written notice, to take reasonable and appropriate steps to stop and remediate BerthRight’s unauthorized use of Personal Information. Such steps may include: (a) directing BerthRight to cease the specific Processing at issue; (b) requiring BerthRight to provide a written explanation of the Processing and a remediation plan within ten (10) business days; (c) requiring BerthRight to delete or return the affected Personal Information; and (d) exercising the audit rights in Section 11. If BerthRight fails to cure a material unauthorized use within thirty (30) days of written notice, Customer may terminate the affected Services and this DPA without penalty and receive a pro-rata refund of prepaid, unused Fees.

5. Security

5.1 Security Measures. BerthRight will implement and maintain appropriate technical and organizational measures designed to protect Personal Information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and unauthorized access, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of the Processing, and the risk to Consumers. Those measures are described in Annex II, which is incorporated into this DPA by reference.

5.2 No Duplication. The measures in Annex II are the complete statement of BerthRight’s security obligations under this DPA. No other document, marketing material, security page, questionnaire response, or statement by BerthRight creates a contractual security obligation unless expressly incorporated by written amendment.

5.3 Changes to Security Measures. BerthRight may update the measures in Annex II from time to time, provided that no update will materially decrease the overall level of protection for Personal Information. BerthRight will notify Customer of any material change to Annex II at least thirty (30) days in advance by email to Customer’s designated notice contact.

5.4 Customer-Side Security. Customer is responsible for: configuring the Services appropriately for its risk profile; enabling and requiring multi-factor authentication for its Authorized Users; assigning and periodically reviewing roles and permissions on a least-privilege basis; promptly deprovisioning departed staff; safeguarding credentials and API keys; and securing the endpoints, networks, and devices from which its Authorized Users access the Services. BerthRight is not responsible for a Security Incident to the extent caused by Customer’s failure to perform these responsibilities.

6. Confidentiality of Personnel

6.1 Duty of Confidentiality. BerthRight will ensure that every natural person authorized to Process Personal Information on BerthRight’s behalf — including BerthRight’s sole member, any employee, any individual contractor, and any individual employed or engaged by a contracting entity — is subject to a duty of confidentiality with respect to that Personal Information. That duty will be imposed by written agreement or by a binding statutory or professional obligation of confidentiality, and will survive the termination of that person’s engagement with BerthRight.

6.2 Need to Know. BerthRight will limit access to Personal Information to those individuals who require access to perform the Services, and will grant that access on a least-privilege basis as described in Annex II § 5.

6.3 Training and Awareness. BerthRight will ensure that individuals authorized to Process Personal Information receive appropriate instruction on their confidentiality and data protection obligations, on the handling of Personal Information, and on the identification and escalation of suspected Security Incidents.

6.4 Contractor Personnel. BerthRight’s engagement of the offshore software development contractor identified in Annex I § 8 is subject to a written agreement that binds both the contracting entity and each individual performing services under it to obligations of confidentiality and data protection no less protective than those in this DPA. See Section 13 (International Transfers) for the additional safeguards applicable to that engagement.

7. Demonstrating Compliance

7.1 Information Sufficient to Demonstrate Compliance. BerthRight will make available to Customer, upon reasonable written request and no more than once per twelve (12)-month period (except as provided in Section 11.4), information reasonably necessary to demonstrate BerthRight’s compliance with its obligations under this DPA. That information will consist of the materials described in Section 11.2 (Tier One).

7.2 Records of Processing. BerthRight will maintain a written record of the Processing it carries out on Customer’s behalf, describing the categories of Processing, the categories of Personal Information, the Subprocessors engaged, and the security measures applied, and will make that record available to Customer on request.

7.3 Cooperation. BerthRight will cooperate reasonably with Customer, and with any regulator having jurisdiction over Customer, in connection with any inquiry, investigation, or assessment relating to the Processing of Personal Information under the Agreement.

8. Subprocessors

8.1 General Authorization. Customer grants BerthRight general written authorization to engage Subprocessors to Process Personal Information in connection with the Services, subject to this Section 8.

8.2 Current Subprocessors. The Subprocessors engaged by BerthRight as of the date of this DPA are listed in Annex I § 8 and are published, in current form, at https://berthright.app/subprocessors. The published list is the authoritative current list; Annex I § 8 states the list as of the date of this DPA.

8.3 Notice of New Subprocessors. BerthRight will provide Customer with at least thirty (30) days’ prior notice before a new Subprocessor begins Processing Personal Information. Notice will be given by both: (a) email to Customer’s designated notice contact of record; and (b) posting the addition to https://berthright.app/subprocessors. Customer is responsible for maintaining a current and monitored notice contact and for subscribing to change notifications at the address above.

8.4 Objection Right. Customer may object to a new Subprocessor on reasonable, documented data protection grounds by written notice to info@berthright.app within thirty (30) days of BerthRight’s notice. If Customer objects:

(a) the Parties will confer in good faith for up to fifteen (15) days to identify a commercially reasonable accommodation, which may include BerthRight making the Services available without the functionality that requires the new Subprocessor, applying additional safeguards, or delaying the transition;

(b) if the Parties cannot reach an accommodation, and if BerthRight cannot provide the Services without the objected-to Subprocessor, Customer may terminate the affected Services on written notice, and BerthRight will refund any prepaid, unused Fees for the terminated Services; and

(c) termination under this Section 8.4 is Customer’s sole and exclusive remedy for an objection to a new Subprocessor.

8.5 Emergency Replacement. If BerthRight must replace a Subprocessor on an emergency basis — including because the Subprocessor ceases operations, suffers a material security failure, materially breaches its agreement with BerthRight, or terminates service on short notice — BerthRight may engage a replacement Subprocessor before the thirty (30)-day notice period elapses, provided that BerthRight gives notice as soon as reasonably practicable and Customer’s objection right under Section 8.4 continues to apply after the fact.

8.6 Flow-Down. BerthRight will engage each Subprocessor under a written contract that imposes on the Subprocessor data protection obligations that are no less protective than those imposed on BerthRight under this DPA, including obligations of confidentiality, security, use limitation, deletion or return, and assistance, in each case to the extent applicable to the Processing the Subprocessor performs. Where a Subprocessor’s standard terms of service constitute that written contract, BerthRight will ensure that the Subprocessor’s data processing addendum or equivalent terms are in force.

8.7 BerthRight Remains Liable. BerthRight remains fully liable to Customer for the performance of each Subprocessor’s data protection obligations, and for the acts and omissions of each Subprocessor in connection with the Processing of Personal Information, to the same extent BerthRight would be liable for its own acts and omissions, subject to the limitations of liability in Section 14.

8.8 Subprocessor Documentation. On Customer’s written request, BerthRight will provide a copy of the data protection terms in effect between BerthRight and a Subprocessor, with commercial terms and other confidential information redacted, or will identify the publicly available location of those terms.

9. Assistance with Consumer Rights Requests

9.1 Customer Fields the Requests. As Controller and Business, Customer is responsible for receiving, verifying, evaluating, and responding to Consumer Rights Requests from its End Users and Authorized Users, including determining whether an exception or exemption applies, verifying the requester’s identity, honoring or denying the request within statutory deadlines, and handling appeals.

9.2 BerthRight Does Not Respond Directly. If BerthRight receives a Consumer Rights Request directly from an End User relating to Personal Information Processed on Customer’s behalf, BerthRight will not respond substantively. BerthRight will, without undue delay and in any event within five (5) business days: (a) inform the requester that BerthRight acts as a service provider and that the request should be directed to the marina; (b) where BerthRight can reasonably identify the relevant Customer, forward the request to Customer’s designated privacy contact or otherwise notify Customer; and (c) take no further action absent Customer’s written instruction. BerthRight may respond directly only where required by law or where Customer instructs it in writing to do so.

9.3 Self-Service Tooling. BerthRight will make available to Customer, as part of the Services and at no additional charge, functionality reasonably designed to enable Customer to respond to Consumer Rights Requests without BerthRight’s manual involvement, including the ability to:

(a) search for and retrieve the Personal Information associated with an identified End User;

(b) export that Personal Information in a structured, commonly used, machine-readable format — available today by request to BerthRight, with in-console self-service export in development;

(c) correct inaccurate Personal Information;

(d) delete or anonymize an End User record, subject to Customer’s own retention obligations and to Section 9.5; and

(e) record and change an End User’s email and SMS communication preferences and consent status.

9.4 Manual Assistance. To the extent Customer cannot fulfill a Consumer Rights Request through the self-service functionality, BerthRight will provide reasonable assistance, taking into account the nature of the Processing and the information available to BerthRight, to enable Customer to respond within the applicable statutory deadline. BerthRight will use commercially reasonable efforts to respond to a request for such assistance within five (5) business days, and in any event sufficiently in advance of Customer’s statutory deadline to allow Customer to respond, provided that Customer notifies BerthRight promptly and at least ten (10) business days before that deadline. BerthRight may charge its then-current professional services rate for assistance that is repetitive, excessive, or manifestly unfounded, or that requires effort materially beyond the scope described in Annex III.

9.5 Deletion and Retention Conflicts. BerthRight will effect a deletion instructed by Customer in accordance with Annex III. BerthRight is not responsible for determining whether a deletion request is subject to an exception under Applicable Privacy Law, whether Customer must retain the record under tax, accounting, maritime lien, insurance, or public-records law, or whether the record is subject to a legal hold. Those determinations are Customer’s. If Customer instructs deletion of a record that BerthRight is independently required to retain, BerthRight will inform Customer and retain only the minimum necessary.

9.6 Opt-Out Signals. Customer is responsible for honoring opt-out preference signals and universal opt-out mechanisms to the extent Applicable Privacy Law requires Customer to do so. BerthRight does not Sell or Share Personal Information and therefore does not process opt-out-of-sale or opt-out-of-sharing requests on its own account.

9.7 Detailed Procedure. The operational procedure for handling Consumer Rights Requests is set forth in Annex III.

10. Security Incident Notification

10.1 Notification to Customer. BerthRight will notify Customer of a Security Incident affecting Customer’s Personal Information without undue delay after confirming the Security Incident, and where feasible within seventy-two (72) hours of confirmation. Upon becoming aware of facts reasonably suggesting that a Security Incident may have occurred, BerthRight will investigate promptly and diligently and will not unreasonably delay confirmation.

10.2 Method of Notice. Notice under Section 10.1 will be given by email to Customer’s designated security/notice contact of record, followed by telephone contact if Customer does not acknowledge within twenty-four (24) hours. Customer is responsible for maintaining a current, monitored notice contact in its account settings and for notifying BerthRight of changes.

10.3 Content of Notice. BerthRight’s notice will include, to the extent known at the time of notice and updated as the investigation progresses:

(a) a description of the nature of the Security Incident, including the date or approximate date of occurrence and of discovery;

(b) the categories and approximate number of Consumers and records affected, and the categories of Personal Information involved;

(c) whether the affected Personal Information was encrypted, redacted, or otherwise rendered unusable, and whether any encryption key or credential was compromised;

(d) the likely consequences of the Security Incident;

(e) the measures BerthRight has taken or proposes to take to address the Security Incident and mitigate its effects;

(f) whether any Subprocessor was involved and, if so, which; and

(g) a point of contact at BerthRight for further information.

If BerthRight cannot provide all of the foregoing at the time of initial notice, it will provide what it has and supplement without undue delay as further information becomes available. A partial notice given promptly is preferred to a complete notice given late, and delay in obtaining full information is not a permissible reason to defer the initial notice.

10.4 Cooperation and Assistance. BerthRight will:

(a) take reasonable steps to contain, investigate, mitigate, and remediate the Security Incident;

(b) preserve relevant logs, records, and forensic evidence in accordance with its ordinary retention practices and any litigation hold;

(c) provide Customer with reasonable information and assistance to enable Customer to assess the incident, to determine its own notification obligations, to prepare and issue notifications to End Users and regulators, and to respond to regulator inquiries;

(d) provide a factual summary of any forensic investigation, provided that BerthRight is not required to disclose the full forensic report, information subject to the attorney-client privilege or work-product doctrine, or information whose disclosure would compromise the security of BerthRight’s other customers; and

(e) provide a written post-incident summary describing root cause and corrective actions within thirty (30) days after containment.

10.5 Customer Controls Notification to Individuals and Regulators; State-Sequencing Caveat. The Parties acknowledge that under applicable state breach notification statutes, a vendor that maintains personal information on behalf of an owner or licensee of that information is generally obligated to notify the owner or licensee — here, Customer — and that the owner or licensee is responsible for notifying affected individuals, state attorneys general, state police or other designated agencies, consumer reporting agencies, and any other required recipients. Accordingly:

(a) Customer determines whether, when, how, and to whom notification of a Security Incident is made to End Users, regulators, and any other third party, and Customer is solely responsible for the content, timing, and method of those notifications;

(b) BerthRight will not notify End Users, regulators, the press, or any other third party about a Security Incident affecting Customer’s Personal Information without Customer’s prior written consent, except where BerthRight is independently required by law to do so, in which case BerthRight will give Customer as much advance notice as is legally permissible and will coordinate with Customer to the extent practicable;

(c) Nothing in this DPA requires Customer to delay, sequence, or condition any notification in a manner that conflicts with Customer’s own legal obligations. The Parties specifically acknowledge that state statutes differ, and in some respects conflict, as to timing and sequence — for example, New Jersey requires the owner of the data to report a breach to the New Jersey Division of State Police in advance of notifying affected individuals; Maryland requires notice to the Attorney General before notifying individuals; and Rhode Island prohibits delaying notice to individuals in order to provide notice to a regulator. Customer will comply with the sequencing required by the statutes applicable to it, and BerthRight will not assert any provision of this DPA, including any consultation, review, or approval right, as a basis for Customer’s failure or delay in doing so;

(d) BerthRight may request, and Customer will consider in good faith, the opportunity to review any proposed notification that names or describes BerthRight, provided that such review will not delay Customer’s notification, and Customer may proceed without BerthRight’s input if BerthRight does not respond within twenty-four (24) hours; and

(e) Customer will not attribute a Security Incident to BerthRight in a public notification in a manner that is inaccurate or misleading.

10.6 No Admission. BerthRight’s notification of, or response to, a Security Incident is not an acknowledgment or admission of fault or liability.

10.7 Customer-Caused Incidents. An incident arising from compromise of Customer’s or an Authorized User’s credentials, from Customer’s configuration choices, from Customer’s own systems or endpoints, or from an integration Customer enabled with a third party is not a Security Incident for which BerthRight bears responsibility, provided that BerthRight will still notify Customer of any such incident of which it becomes aware and will provide reasonable assistance in investigating it. BerthRight may charge its then-current professional services rate for assistance under this Section 10.7 that is materially beyond routine support.

11. Audit and Compliance

11.1 Structure. BerthRight’s audit obligations are tiered. Customer will exercise its rights under this Section 11 beginning with Tier One, and may proceed to Tier Two only if the Tier One materials are insufficient to allow Customer to verify BerthRight’s compliance and Customer states in writing the specific respects in which they are insufficient.

11.2 Tier One — Documentation (available on request, no charge). On Customer’s written request, and no more than twice per twelve (12)-month period, BerthRight will provide:

(a) BerthRight’s then-current security documentation and the content of its public security page;

(b) a completed CAIQ-Lite or SIG-Lite questionnaire, or BerthRight’s completed responses to Customer’s own reasonable security questionnaire of comparable scope;

(c) a summary of the results of the most recent penetration test or vulnerability assessment performed on the Services, if any, with findings redacted to the extent necessary to protect the security of BerthRight’s other customers;

(d) the then-current Annex II and the then-current Subprocessor list;

(e) the third-party audit reports, certifications, or attestations that BerthRight’s Subprocessors make available to BerthRight and that BerthRight is permitted to share (including, where available, SOC 2 reports of Vercel, Supabase, Clerk, Stripe, and Cloudflare), or, where BerthRight is not permitted to share them, the location at which Customer may request them directly; and

(f) written responses to Customer’s reasonable follow-up questions about the foregoing.

11.3 Tier Two — Assessment (once per twelve months). If the Tier One materials are insufficient, Customer may, no more than once in any twelve (12)-month period, conduct or have conducted an assessment of BerthRight’s policies and technical and organizational measures relating to the Processing of Personal Information, subject to each of the following conditions:

(a) Customer gives at least thirty (30) days’ prior written notice, identifying the scope and the specific Tier One deficiencies that prompted the request;

(b) the assessment is conducted remotely, by videoconference, screen share, document review, and written interview, during BerthRight’s normal business hours, and in a manner that does not unreasonably disrupt BerthRight’s operations. On-site assessment is not available except as required under Section 11.4;

(c) the assessment is limited to systems, records, and personnel relevant to the Processing of Customer’s Personal Information, and does not extend to BerthRight’s source code, financial records, personnel files, other customers’ data or configurations, or any information whose disclosure would compromise the security or confidentiality of another customer;

(d) Customer and any assessor act under a written confidentiality agreement reasonably acceptable to BerthRight; if Customer engages a third-party assessor, that assessor must not be a competitor of BerthRight and must be reasonably acceptable to BerthRight;

(e) Customer bears its own costs and reimburses BerthRight’s reasonable costs, including BerthRight’s time at its then-current professional services rate [$___/hour], except where the assessment identifies a material breach by BerthRight of this DPA, in which case BerthRight bears its own costs;

(f) the assessment does not include penetration testing, vulnerability scanning, or any active technical testing of the Services without BerthRight’s separate prior written authorization, which BerthRight will not unreasonably withhold and which may be conditioned on scope, timing, and use of a non-production environment; and

(g) Customer provides BerthRight with a copy of the assessment report, which is BerthRight’s Confidential Information and Customer’s Confidential Information jointly, and BerthRight will respond within thirty (30) days to any material finding with a remediation plan.

11.4 Tier Three — Regulator-Mandated. Where a regulator or supervisory authority with jurisdiction over Customer requires an assessment, audit, or inspection of BerthRight’s Processing that exceeds the scope or frequency permitted by Sections 11.2 and 11.3, BerthRight will cooperate reasonably with that requirement, including by permitting an on-site inspection if the regulator specifically requires one, subject to reasonable confidentiality, scheduling, and security conditions and to Customer’s reimbursement of BerthRight’s reasonable costs. The frequency limits in Sections 11.2 and 11.3 do not apply to this Section 11.4 or following a Security Incident affecting Customer’s Personal Information.

11.5 CCPA Twelve-Month Right. For the avoidance of doubt, and notwithstanding the tiering above, Customer has the right to take reasonable and appropriate steps to help ensure that BerthRight uses Personal Information in a manner consistent with Customer’s obligations under the CCPA, including by exercising the rights in this Section 11 at least once in any twelve (12)-month period. Nothing in this Section 11 limits that right.

12. Return and Deletion of Personal Information

12.1 Export During the Term. Throughout the term of the Agreement, Customer may export its Customer Data, including Personal Information, at any time by request to BerthRight as described in the Data Export and Deletion Policy, in a structured, commonly used, machine-readable format. Self-service export functionality in the Services is in development.

12.2 Post-Termination Export Window. For thirty (30) days following the effective date of expiration or termination of the Agreement, BerthRight will maintain Customer’s Customer Data and will make it available for export, either through the export process described in Section 12.1 or, at BerthRight’s option, by providing a complete export file. If Customer requires assistance beyond a standard export, BerthRight will provide it at its then-current professional services rate.

12.3 Deletion. Following the export window, and in any event within ninety (90) days after expiration or termination of the Agreement, BerthRight will delete or return, at Customer’s election, all Personal Information in its possession or control, and will instruct its Subprocessors to do the same. The ninety (90)-day period is set to accommodate the rotation of encrypted backups; Personal Information residing in backup media will be deleted in the ordinary course of backup rotation and, pending deletion, will remain subject to the security measures in Annex II and to the confidentiality obligations in Section 6 and in the Agreement, and will not be accessed for any purpose other than backup integrity, disaster recovery, or legal compliance.

12.4 Certification. On Customer’s written request made within sixty (60) days after the deletion deadline, BerthRight will provide written certification that deletion has been completed in accordance with Section 12.3.

12.5 Exceptions to Deletion. BerthRight may retain Personal Information after the period in Section 12.3 to the extent, and only for so long as:

(a) required by applicable law, regulation, or a governmental or judicial order;

(b) subject to a legal hold issued in connection with pending or reasonably anticipated litigation, arbitration, investigation, or regulatory proceeding involving either Party, in which case BerthRight will notify Customer of the hold to the extent legally permitted, will retain only the Personal Information within the hold’s scope, and will delete it promptly upon release of the hold;

(c) required by Customer’s own records-retention obligations, where Customer instructs BerthRight in writing to retain specified Personal Information beyond the deletion deadline. This subsection is intended in particular to accommodate public-sector Customers — municipal, county, and authority-operated marinas — whose records may constitute public records subject to a state public-records retention schedule that requires retention for a period longer than ninety (90) days, and which may not lawfully permit destruction of those records on the schedule in Section 12.3. Where Customer so instructs, the Parties will agree in writing on the retention period, the scope of the retained data, the applicable fees, and the security measures that will continue to apply, and this DPA will remain in effect as to the retained Personal Information for the duration of the retention; and

(d) contained in De-identified Data or aggregate consumer information created and maintained in accordance with Section 4.6, or in routine system, security, and audit logs, which BerthRight may retain in accordance with its ordinary log retention schedule.

12.6 Deletion During the Term. Customer’s ability to delete individual records during the term is addressed in Section 9.3(d) and Annex III. Deletion of an individual record during the term follows the same backup-rotation timeline described in Section 12.3.

13. International Transfers and the Offshore Development Contractor

13.1 Data Residency. All Personal Information Processed under the Agreement is stored and Processed at rest in data centers located in the United States. Each of BerthRight’s infrastructure Subprocessors — Vercel, Supabase, Clerk, Stripe, Resend, the SMS provider, and Cloudflare — is configured to store Customer Data in United States regions.

13.2 The One Non-US Touchpoint. BerthRight discloses that it engages [Offshore development company name], located in [Country], as a contractor for software development, maintenance, and support engineering. Personnel of that contractor have scoped access to BerthRight’s production systems for the purpose of developing, maintaining, supporting, and debugging the Services. This is the only circumstance in which Personal Information Processed under the Agreement is accessed from outside the United States. Personal Information is not stored outside the United States.

13.3 Safeguards. BerthRight applies the following safeguards to the contractor engagement:

(a) Written agreement. The contractor is engaged under a written agreement containing confidentiality, data protection, information security, intellectual property assignment, and termination provisions, and imposing obligations no less protective than those in this DPA, as required by Section 8.6;

(b) Individual confidentiality undertakings. Each individual performing services with access to Personal Information is bound by a written duty of confidentiality that survives the end of that individual’s engagement, as required by Section 6.1;

(c) Scoped, least-privilege access. Contractor access to production systems is limited to what is necessary for a specific development or support task, is granted at the least privilege sufficient for that task, and is reviewed periodically;

(d) Individual credentials. Each individual with access holds individually issued, named credentials. Shared, generic, or team credentials are prohibited, and credentials are not transferable between individuals. Multi-factor authentication is enabled on those credentials, and BerthRight is completing verification that it is enforced on every such account;

(e) No bulk export. Contractor personnel are prohibited from exporting, downloading, copying, or otherwise extracting Personal Information in bulk from production systems, and from transferring Personal Information to personal devices, personal accounts, or unapproved storage. Non-production and development environments use synthetic or de-identified data;

(f) Logging. Access to production systems is logged, and logs are retained and reviewed as described in Annex II § 9;

(g) Prompt revocation. Access is revoked promptly upon the conclusion of the task, the individual’s removal from the engagement, or termination of the contractor relationship, in accordance with the offboarding procedure in Annex II § 12; and

(h) Subprocessor status. The contractor is identified as a Subprocessor in Annex I § 8 and on the public Subprocessor page, and Customer’s objection right under Section 8.4 applies to any change of contractor.

13.4 No Other Cross-Border Processing. Except as described in Section 13.2, BerthRight will not transfer Personal Information to, or access it from, a jurisdiction outside the United States, or engage a Subprocessor that does so, without first adding that Subprocessor to the list in accordance with Section 8.3 and identifying the jurisdiction.

14. Liability

14.1 Tie-In to the Agreement. Each Party’s liability arising out of or in connection with this DPA is subject to, and counts toward, the exclusions and limitations of liability set forth in the Agreement, including the exclusion of indirect and consequential damages and the aggregate liability cap. Liability under this DPA and liability under the Agreement do not create separate or cumulative caps; the caps in the Agreement apply to the Parties’ aggregate liability under the Agreement and this DPA taken together.

14.2 No Expansion by Precedence. The Parties acknowledge that this DPA takes precedence over the Agreement as to the Processing of Personal Information. That precedence does not displace, modify, or increase the limitations of liability in the Agreement, which govern notwithstanding any contrary implication arising from the order of precedence.

14.3 Allocation. Customer is responsible for its obligations as Controller and Business, and BerthRight is responsible for its obligations as Processor and Service Provider. Neither Party is liable for the other’s failure to perform its own role-based obligations under Applicable Privacy Law.

15. General

15.1 Order of Precedence. In the event of a conflict between this DPA and the Agreement, this DPA controls solely with respect to the Processing of Personal Information, subject to Section 14.2. In the event of a conflict between the body of this DPA and an Annex, the body controls, except that Annex II controls as to the description of security measures and Annex I controls as to the details of Processing.

15.2 Amendment. This DPA may be amended: (a) by written agreement of the Parties; (b) by BerthRight unilaterally, on thirty (30) days’ notice, solely to the extent necessary to comply with a change in Applicable Privacy Law, provided the amendment does not materially reduce the protections afforded to Personal Information; and (c) as to Annex II, in accordance with Section 5.3, and as to the Subprocessor list, in accordance with Section 8.3. If Customer reasonably objects to an amendment under clause (b), the Parties will confer in good faith, and if they cannot agree, Customer may terminate the affected Services without penalty.

15.3 Severability. If any provision of this DPA is held invalid or unenforceable, that provision will be modified to the minimum extent necessary to make it enforceable, and the remaining provisions will remain in full force.

15.4 Survival. Sections 4 (as to Personal Information retained), 6, 10 (as to incidents affecting retained Personal Information), 12, 13, 14, and this Section 15 survive termination of the Agreement and of this DPA.

15.5 Governing Law and Venue. This DPA is governed by the laws of the State of Florida, without regard to its conflict of laws principles, and the Parties submit to the exclusive jurisdiction and venue of the state and federal courts located in Palm Beach County, Florida, in each case as provided in and subject to the dispute resolution provisions of the Agreement. Nothing in this Section limits the application of Applicable Privacy Law of any other jurisdiction that applies of its own force.

15.6 Notices. Notices under this DPA are given as provided in the Agreement, and to BerthRight at info@berthright.app, Attn: Privacy, with a copy to the address on the signature page. Notices under Sections 8.3 (subprocessor changes), 8.4 (objections), and 10 (security incidents) may be given by email and are effective on transmission absent a bounce or delivery failure.

15.7 Counterparts and Electronic Signature. This DPA may be executed in counterparts and by electronic signature, each of which is an original and all of which together constitute one instrument.

15.8 Entire Agreement. This DPA, together with its Annexes and the Agreement, constitutes the entire agreement between the Parties concerning the Processing of Personal Information and supersedes all prior data processing terms between the Parties.

15.9 Execution Not Required for Effectiveness. For customers accessing the Services under BerthRight’s online Terms of Service, this DPA is incorporated by reference and is binding without signature. A Customer that requires a countersigned copy may request one at info@berthright.app.

Signatures

IN WITNESS WHEREOF, the Parties have caused this Data Processing Addendum to be executed by their duly authorized representatives.

BERTH RIGHT MGMT LLC
a Florida limited liability company

By: ______________________________

Name: Thomas J. Heist

Title: Manager / Sole Member

Date: ____________________________

Email for notices: info@berthright.app

Privacy contact: info@berthright.app

[Customer legal name]
a [State] [entity type]

By: ______________________________

Name: ____________________________

Title: ____________________________

Date: ____________________________

Email for notices: _________________

Security incident contact: __________

Privacy/DSR contact: _______________

Annex I — Details of Processing

1. The Parties

Controller / Business[Customer legal name], the Marina Operator. Contact: [Name, title, email]
Processor / Service ProviderBerth Right MGMT LLC, a Florida limited liability company. Contact: Thomas J. Heist, Manager / Sole Member, info@berthright.app, (609) 881-2656
Subject matterProvision of the BerthRight marina management platform
Nature of the relationshipController-to-processor; business-to-service-provider

2. Categories of Data Subjects / Consumers

BerthRight Processes Personal Information relating to the following categories of individuals:

(a) End Users — boaters, slip holders, vessel owners and operators, transient guests, storage customers, service customers, and their designated contacts, guests, and crew, who hold or seek a slip, mooring, rack, storage space, or service appointment at Customer’s facility;

(b) Prospective End Users — individuals who inquire, request a quote, submit a reservation request, or join a waitlist but do not become customers of Customer;

(c) Authorized Users — Customer’s owners, managers, dockmasters, harbormasters, service writers, yard staff, seasonal staff, bookkeepers, and other individuals authorized by Customer to access the Services; and

(d) Third-party contacts — vendors, contractors, emergency contacts, co-owners, and insurance or brokerage contacts whose details Customer or an End User records in connection with a vessel, reservation, or work order.

3. Categories of Personal Information

CategoryElements
Identifiers and contact dataFull name; email address; postal/mailing address; home, mobile, and work telephone numbers
Vessel dataVessel name; make; model; year; length, beam, and draft; hull identification number; state registration number and/or USCG documentation number; hailing port; engine and propulsion details; insurance carrier and policy identifiers where Customer collects them
Reservation and occupancy dataSlip, berth, mooring, rack, or yard space assignment; reservation and contract dates; arrival and departure records; stay and occupancy history; transient versus seasonal status; waitlist position and priority; check-in and check-out records
Service and storage dataWork orders; service requests and descriptions; haul, launch, and storage schedules; parts and labor records; yard location
Commercial and transactional dataInvoices and statements; line items; rates and rate plans applied; amounts billed, paid, credited, refunded, and outstanding; aging and collection status; point-of-sale transaction records including fuel, pumpout, and retail purchases
Payment method dataStripe tokens and identifiers; card brand; last four digits; expiration month and year; bank account last four where ACH is used. No full primary account number (PAN), CVV/CVC, magnetic stripe data, PIN, or other sensitive authentication data is received, transmitted, or stored by BerthRight (see DPA § 2.6)
Account and authentication dataAccount identifiers; usernames and email identifiers; hashed credentials and authentication factors managed by Clerk; multi-factor enrollment status; session and login events; password reset events; role and permission assignments
Communications dataContent of transactional and operational email and SMS messages sent through the Services; delivery, bounce, open, click, and failure metadata; inbound replies; consent, opt-in, opt-out, STOP/HELP, and preference records; timestamps and audit trail of consent capture
Technical and usage dataIP address; device type; browser and operating system; user agent; approximate location derived from IP; pages and features accessed; timestamps; referral data; error and diagnostic logs; audit log entries
Free-text dataNotes, comments, and descriptions entered by Authorized Users or End Users in open-text fields, which may contain any of the above and which are subject to the prohibition in DPA § 3.6(e)

4. Sensitive Data

BerthRight does not intentionally collect, and the Services are not designed to collect, Sensitive Personal Information or sensitive data as defined in DPA § 1.16.

BerthRight instructs Customer not to submit Sensitive Personal Information to the Services. That instruction expressly includes:

(a) health, medical, disability, accessibility, and mobility information about any individual, including notes about a person’s medical conditions, medications, treatments, physical or mental limitations, mobility devices, or need for health-related accommodation;

(b) Social Security numbers, taxpayer identification numbers, driver’s license numbers, state identification card numbers, passport numbers, and other government-issued identifiers;

(c) full payment card numbers, security codes, or PINs entered into any field of the Services (see DPA § 2.6 and the Acceptable Use Policy);

(d) financial account numbers in combination with any access credential;

(e) precise geolocation, racial or ethnic origin, religious or philosophical beliefs, citizenship or immigration status, union membership, sex life or sexual orientation, or genetic or biometric identifiers; and

(f) personal information of a known child under thirteen (13) years of age.

If Sensitive Personal Information is nonetheless submitted, DPA § 3.7 governs.

5. Frequency of Processing

Continuous and ongoing, for the duration of the Agreement. Processing occurs whenever an Authorized User or End User interacts with the Services, whenever a scheduled or automated process runs (including billing runs, dunning, reminders, waitlist notifications, and backups), and whenever BerthRight performs support, maintenance, or incident response.

6. Nature and Purpose of Processing

BerthRight Processes Personal Information to provide, maintain, secure, and support the Services, for the specific Business Purposes enumerated in DPA § 4.2(a)–(n), which are incorporated here by reference. The nature of the Processing includes collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, transmission, disclosure to Subprocessors, alignment, combination within the tenant, restriction, erasure, and destruction.

7. Duration of Processing

For the term of the Agreement, plus the export and deletion periods set forth in DPA § 12 (thirty (30)-day export window; deletion within ninety (90) days), subject to the exceptions in DPA § 12.5 (legal requirement, legal hold, public-records retention, de-identified data and logs).

8. Subprocessors

The current authoritative list is published at https://berthright.app/subprocessors. As of the date of this DPA, the Subprocessors are:

SubprocessorPurposePersonal Information ProcessedLocation
Vercel Inc.Application hosting, edge network, content deliveryAll platform data in transit; application and request logsUnited States
Supabase Inc.Managed PostgreSQL database, object storage, backupsAll Customer Data at restUnited States
Clerk Inc.Authentication, identity, session management, MFAAccount identifiers, credentials, authentication eventsUnited States
Stripe, Inc.Payment processing (Connect Standard)Payment and cardholder data. Stripe acts as an independent controller and/or as Customer’s own processor for cardholder data under Customer’s direct Stripe agreement — see DPA § 2.6United States
ResendTransactional email deliveryRecipient email address, name, message content, delivery metadataUnited States
Twilio Inc. or Telnyx LLCSMS / A2P 10DLC messagingMobile number, message content, consent records, delivery metadataUnited States
Cloudflare, Inc.Video streaming and media delivery, network securityMedia assets, request metadataUnited States
[Offshore development company name]Software development, maintenance, support engineeringScoped access to production systems for support and debugging — see DPA § 13[Country]

Annex II — Technical and Organizational Measures

1. Encryption in Transit

All data transmitted between Authorized Users, End Users, and the Services, and between the Services and BerthRight’s Subprocessors, is encrypted in transit using TLS 1.2 or higher with modern cipher suites. HTTPS is enforced across all application endpoints, and HTTP requests are redirected to HTTPS.

2. Encryption at Rest

Customer Data at rest is encrypted using AES-256 encryption, provided through Supabase’s managed PostgreSQL and storage infrastructure and the underlying AWS storage layer. Database backups and object storage are encrypted at rest.

3. Multi-Factor Authentication

(a) Multi-factor authentication is enabled on BerthRight’s administrative accounts across the systems in BerthRight’s stack, including Vercel, Supabase, Clerk, Stripe, Cloudflare, Resend, the SMS provider, the source code repository, the domain registrar, and the DNS provider. BerthRight is completing verification that multi-factor authentication is enforced on every such account.

(b) Multi-factor authentication is available to Customer’s Authorized Users through Clerk, and Customer may require it for its own staff. BerthRight recommends that Customer enable and require MFA for all Authorized Users, and in particular for any user with billing, export, or user-management permissions.

(c) Credentials are never shared between individuals. Each person with access holds individually issued, named credentials.

4. Tenant Isolation

(a) The Services are multi-tenant. Tenant isolation is enforced in the application layer: every query that reads or writes Customer Data is scoped to the marina tenant on whose behalf the request is made, so that a request made in the context of one tenant cannot return another tenant’s records. PostgreSQL Row-Level Security (“RLS”) is not in use today. BerthRight is planning database-enforced Row-Level Security as a defense-in-depth addition to, and not a replacement for, the application-layer scoping described here.

(b) Automated cross-tenant access tests are executed as part of BerthRight’s unit-test pipeline to verify that the application-layer tenant scoping prevents cross-tenant reads and writes.

(c) Tenant-branded subdomains and application routing do not, by themselves, constitute an isolation control, and BerthRight does not rely on them for isolation.

5. Access Control and Least Privilege

(a) Role-based access control governs Authorized User access within each tenant. Customer assigns roles to its own staff and is responsible for maintaining appropriate role assignments.

(b) Administrative access to production systems is limited to BerthRight’s sole member and to individually named personnel of the offshore development contractor, in each case on a least-privilege basis, scoped to the task requiring access.

(c) Contractor access is individually credentialed and never shared, scoped to the minimum necessary, and logged and monitored. Multi-factor authentication is enabled on contractor accounts, and BerthRight is completing verification that it is enforced on every such account. Contractor personnel are prohibited from bulk export of Personal Information and from transferring Personal Information to personal devices or accounts. See DPA § 13.3.

(d) Access rights are reviewed upon any change in personnel or in the scope of an engagement. BerthRight is instituting a recurring access review on at least a semi-annual cadence.

6. Secrets Management

(a) Application secrets, API keys, database credentials, and service keys are stored in Vercel encrypted environment variables (and in the equivalent encrypted secret stores of the relevant Subprocessor platforms), scoped by environment.

(b) Secrets are managed outside source control. Application secrets, API keys, and service credentials are held in the encrypted stores described in subsection (a) and are not committed to the repository. BerthRight is instituting scanning of the full repository history to verify this and to rotate any credential that scanning identifies.

(c) Automated secret scanning on the source code repository, covering both new commits and the full commit history, is being put in place to detect accidental commit of credentials.

(d) Key and credential rotation is performed upon (i) the departure of any individual with access, (ii) termination of the contractor engagement, (iii) suspected exposure, or (iv) a Security Incident. BerthRight is instituting a scheduled twelve (12)-month rotation cycle in addition to those events.

7. Secure Development

(a) Changes to the Services are made through version-controlled source code with a documented deployment pipeline, and are deployed through Vercel’s build and deployment infrastructure.

(b) Automated dependency scanning is enabled to identify known vulnerabilities in third-party libraries, and material vulnerabilities are remediated on a risk-prioritized basis.

(c) Non-production and development environments are provisioned with synthetic and seeded data rather than with production data. BerthRight is completing verification that no production Personal Information is present in any non-production environment.

(d) Code changes affecting authentication, authorization, tenant isolation, payment flows, or data export receive heightened review before deployment.

8. Application Security

(a) Authentication, session management, password policy, credential storage, and multi-factor authentication are provided by Clerk, a specialized identity provider. BerthRight does not store plaintext passwords and does not implement its own credential hashing.

(b) Input validation, parameterized database queries, and output encoding are used to mitigate injection and cross-site scripting.

(c) Platform-level DDoS mitigation is provided at the edge by Vercel and Cloudflare. Web application firewall capabilities are available on those platforms, and BerthRight is completing the configuration and verification of its rule set.

(d) Rate limiting is applied to authentication endpoints through Clerk, and to messaging send paths, to mitigate credential stuffing and abuse. BerthRight is completing verification of rate-limit coverage across the remaining application endpoints.

9. Logging and Monitoring

(a) Audit and change logging is maintained within the Services, including a record of administrative actions taken by BerthRight’s platform administrators, error and exception records, and change history on the records that carry it. BerthRight is completing a control-by-control verification of audit-log coverage across billing and invoice changes; refunds and credits; role and permission changes; user creation and deletion; data exports; record deletions and anonymizations; authentication events including failed logins and MFA changes; and administrative access to production systems, and will state the verified coverage in this Annex.

(b) Application and infrastructure logs are retained in line with the retention configuration of BerthRight’s infrastructure providers and are available to support incident investigation.

(c) Error and exception monitoring is in place with alerting to BerthRight’s sole member.

(d) Audit logs relating to a tenant are available to that tenant on request. Tenant-administrator access to those logs from within the Services is planned.

10. Backup, Resilience, and Recovery

(a) Customer Data is backed up automatically through Supabase’s managed backup infrastructure. Backups are encrypted at rest.

(b) Recovery Point Objective (RPO): twenty-four (24) hours. BerthRight’s objective is that no more than twenty-four (24) hours of data would be lost in a disaster recovery scenario.

(c) Recovery Time Objective (RTO): eight (8) hours. BerthRight’s objective is to restore Service availability within eight (8) hours of a declared disaster.

(d) Restore testing. BerthRight’s target is to perform a restore test at least annually, to verify that backups can be restored and that data integrity is preserved. Restore testing is being instituted.

11. Physical Security

BerthRight does not operate its own data centers. Physical and environmental security for the infrastructure hosting Customer Data is provided by BerthRight’s infrastructure Subprocessors (Vercel, Supabase and its underlying cloud provider, Clerk, Stripe, and Cloudflare), each of which maintains its own physical security program and third-party attestations. BerthRight has no physical office at which Customer Data is stored. Personal Information is not stored on removable media.

Endpoint devices used by BerthRight’s sole member to access production systems are protected by full-disk encryption, screen lock with automatic timeout, current operating system and security updates, and a password manager.

12. Personnel and Offboarding

(a) Every individual with access to Personal Information is bound by a written duty of confidentiality (DPA § 6.1).

(b) Offboarding and access revocation. Upon the departure of any individual with access, or upon conclusion of a contractor engagement or removal of an individual from it, BerthRight revokes all access — application accounts, infrastructure console accounts, source code repository access, and any issued keys or tokens — within twenty-four (24) hours, and rotates any credential that individual may have known. BerthRight is instituting a written offboarding checklist and a written record of each offboarding.

(c) Background screening of contractor personnel, where it is performed, is the responsibility of the contracting entity. BerthRight does not itself conduct background screening.

(d) Individuals with access receive instruction on confidentiality, data handling, and incident escalation (DPA § 6.3).

13. Written Information Security Program

BerthRight is formalizing a Written Information Security Program built to the standard of 201 CMR 17.00 and appropriate to its size, the nature of its business, and the sensitivity of the Personal Information it Processes. The program documents the measures in this Annex II, assigns responsibility for information security to BerthRight’s sole member, and will be reviewed at least annually and upon any material change to the Services or to BerthRight’s infrastructure.

14. Incident Response

BerthRight is documenting an incident response procedure covering detection, triage, containment, investigation, notification in accordance with DPA § 10, remediation, and post-incident review.

Annex III — Consumer Rights Request Handling

Purpose. This Annex describes the operational procedure by which BerthRight assists Customer with Consumer Rights Requests under DPA § 9. It is an operational document and does not expand BerthRight’s obligations beyond DPA § 9.

1. Who Does What

StepResponsible Party
Receiving the request from the End UserCustomer (Marina Operator)
Verifying the requester’s identityCustomer
Determining whether the request is valid, and whether an exception or exemption appliesCustomer
Locating and retrieving the dataCustomer, using the Services’ self-service tools; BerthRight assists where self-service is insufficient
Responding to the End UserCustomer
Handling appealsCustomer
Providing tooling, technical assistance, and dataBerthRight
Executing a deletion or anonymization that cannot be performed self-serviceBerthRight, on Customer’s written instruction

2. If BerthRight Receives a Request Directly

  1. BerthRight does not respond substantively and does not disclose, correct, or delete any Personal Information.
  2. Within five (5) business days, BerthRight replies to the requester stating that BerthRight provides software to the marina, that the marina controls the data, and that the request should be directed to the marina; BerthRight provides the marina’s name and public contact information where it can reasonably identify the marina.
  3. BerthRight notifies the relevant Customer’s designated privacy contact that a request was received and forwarded.
  4. BerthRight takes no further action absent Customer’s written instruction.
  5. BerthRight logs the request, the date, and the disposition.

3. Self-Service Capabilities (Customer-Initiated)

RightHow Customer Performs ItTypical Timeframe
Access / Know / CopySearch the End User record; use the record export function to generate a structured export of the End User’s dataImmediate
PortabilitySame export, in a structured, commonly used, machine-readable formatImmediate
CorrectionEdit the End User record fields directlyImmediate
DeletionUse the delete/anonymize function on the End User record, subject to open balances, active reservations, and Customer’s retention obligationsImmediate in the application; backups per DPA § 12.3
Opt out of email/SMSUpdate the End User’s communication preferences and consent status; STOP replies are processed automaticallyImmediate; STOP processed automatically

4. Requesting BerthRight’s Assistance

  1. Customer submits a written request to info@berthright.app with the subject line “DSR ASSISTANCE”, stating: the tenant/marina name; the type of right being exercised; the End User identifier (name plus email or account ID — not a Social Security number or other government identifier); the applicable statutory deadline; and what Customer has already attempted self-service.
  2. BerthRight acknowledges within two (2) business days.
  3. BerthRight uses commercially reasonable efforts to complete the assistance within five (5) business days, and in any event sufficiently in advance of Customer’s stated statutory deadline where Customer gave at least ten (10) business days’ notice (DPA § 9.4).
  4. BerthRight delivers responsive data to Customer only — never directly to the End User — through the Services or another secure channel. Personal Information is not sent as an unencrypted email attachment.
  5. BerthRight logs the assistance request, the action taken, and the completion date.

5. Deletion Mechanics

  1. Customer instructs deletion in writing or executes it in the application.
  2. BerthRight (or the application) deletes or anonymizes the End User record in the production database. Where a full delete would break referential integrity or destroy financial or occupancy records Customer must retain, the record is anonymized in place — identifiers (name, email, phone, postal address) are removed or irreversibly replaced, while the transactional and occupancy record is preserved keyed to an opaque identifier.
  3. Deletion propagates to Subprocessors that hold a copy of the affected data, and BerthRight instructs those Subprocessors accordingly. Note that message content and delivery metadata held by the email and SMS providers are subject to those providers’ own retention schedules, and that suppression-list entries (opt-out records) are deliberately retained because deleting them would cause a previously opted-out person to be messaged again — retention of a suppression record is a compliance requirement, not a failure to delete.
  4. Data in encrypted backups is deleted through ordinary backup rotation in accordance with DPA § 12.3, and pending rotation is not accessed for any purpose other than backup integrity, disaster recovery, or legal compliance.
  5. On request, BerthRight confirms deletion in writing to Customer.

6. Records

BerthRight maintains a log of Consumer Rights Request assistance, including date received, tenant, type of request, action taken, and completion date, and makes it available to Customer on request. The log does not retain the substance of the Personal Information disclosed.