Data Docked
DocsPricing
Contact
Sign inGet free API keyGet key
Data Docked

Maritime data API — real-time & historical AIS, port intelligence, vessel particulars.

API status

Products

  • Vessel Location
  • Vessel Particulars
  • Port Analytics
  • Historical Data
  • Route Planner
  • All APIs

Use Cases

  • Fleet Management
  • Supply Chain
  • Compliance
  • Insurance
  • Trading
  • All use cases

Developers

  • API Reference
  • Quickstart
  • Best Practices
  • Integrations
  • API Status
  • FAQ

Learn

  • Glossary
  • Learn
  • AIS Data Explained
  • AIS Message Types
  • MMSI Explained
  • IMO Numbers

Company

  • About
  • Pricing
  • Credit Calculator
  • Blog
  • App Store
  • Contact

© 2026 Data Docked · VAT EE102956214

TermsPrivacySecurityCookies

Data Processing Agreement

Effective date: 1 January 2025

A separate /subprocessors page lists our current sub-processors, their purposes, and regions.

This Data Processing Agreement ("DPA") forms part of the agreement between Data Docked OÜ (VAT EE102956214, registered in Estonia) ("Data Docked", "we", "us") and the Customer ("Controller"). It governs the processing of personal data by Data Docked on behalf of the Customer, in accordance with the EU General Data Protection Regulation (GDPR).

1. Scope

This DPA applies where the Customer is a data controller and Data Docked processes personal data on the Customer's behalf. Examples of personal data processed include: user email addresses stored in Customer accounts, and billing information passed to Stripe for payment processing. Data Docked does not process large volumes of end-user personal data in delivering the maritime API service itself; AIS data concerns vessels, not individuals.

2. Data Docked as processor

Data Docked processes personal data solely on documented instructions from the Customer, as set out in the main service agreement and this DPA. Data Docked does not sell, rent, or use Customer personal data for its own commercial purposes. Staff with access to personal data are bound by confidentiality obligations.

3. Security measures

Data Docked implements appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or destruction, including:

  • Encryption in transit using TLS 1.2 or higher.
  • Encryption at rest within our cloud environment.
  • Role-based access controls and least-privilege principles.
  • Annual internal security review of measures and sub-processors.

Further details are available on our security infrastructure page.

4. Sub-processors

The current list of sub-processors is maintained at /subprocessors. The Customer consents to the use of those sub-processors. Data Docked will provide at least 30 days' notice of any intended changes to sub-processors, published at /api-changes. The Customer may object within that period; if no resolution is reached, either party may terminate the agreement.

5. Data subject rights

Data Docked will assist the Customer in responding to data subject rights requests (access, rectification, erasure, restriction, portability) within 5 business days of receiving a request forwarded by the Customer. The Customer remains responsible for determining whether a request is valid and communicating the outcome to the data subject.

6. Breach notification

Data Docked will notify the Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer data. The notification will include: the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address it.

7. Retention and deletion

Upon termination of the service agreement, Data Docked will, at the Customer's written request, delete or return all personal data within 30 days, unless applicable law requires retention. Backups may be purged on their normal rotation schedule.

8. Governing law

This DPA is governed by the laws of Estonia and the European Union, in particular the GDPR (Regulation (EU) 2016/679). Any disputes arising under this DPA shall be subject to the jurisdiction of Estonian courts, unless mandatory local law provides otherwise.

9. Contact

For data protection queries or to exercise your rights under this DPA, contact us at [email protected]. Please include “Data Protection” in the subject line.