Nordic Stars
NavigationRace ControlDebrief PlayerAnalyticsReportsPricingDocsBlog
Open app

Legal

Data Processing Agreement

Goose Yard Sailing AB · Last updated: 16 August 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Goose Yard Sailing AB, org. nr. 559489-8594 (“Goose Yard”, the Processor) and the Customer (the Controller), and governs the processing of personal data contained in Customer Data under Article 28 GDPR.

1. Roles and scope

  • The Customer is the controller of personal data in its telemetry, tracking data, events and organisation content; Goose Yard processes it only on the Customer’s behalf.
  • Goose Yard is an independent controller for account and billing data (see the Privacy Policy), which is outside this DPA.

2. Subject matter, nature and purpose

On the Customer’s documented instructions, Goose Yard will:

  • receive, validate, store and index telemetry — uploaded recordings and the live stream from Race Control;
  • derive analytics from them (rollups, race detection, performance series) and serve them back in the debrief player;
  • retrieve fleet tracking data from the race tracking provider the Customer connects, using the Customer’s own credentials — configuring an event for capture in the app constitutes the documented instruction;
  • store video metadata (fingerprints, alignment) — video bytes are never uploaded;
  • host organisation content such as polars, targets and notes.

Duration: the term of the agreement plus the 30-day post-termination export window, after which personal data is deleted per section 7.

3. Data subjects and categories

  • Data subjects: the Customer’s crew, staff and invited users; competitors and other participants appearing in official race tracking feeds.
  • Categories: identifiers (names, emails of invited users; boat and sail numbers, competitor names in provider feeds); location and performance data (GPS traces, speeds, headings, timestamps); video metadata.
  • Special categories (Art. 9): none intended or required. The Customer must not submit special-category data.

4. Customer obligations

The Customer warrants that it:

  • has a valid legal basis for the personal data it submits;
  • provides any required privacy notices to its crew and users (GDPR Arts. 13–14);
  • is entitled to use the race-tracking credentials and data it connects;
  • issues lawful, documented instructions (use of the app is such an instruction);
  • conducts DPIAs where its use requires them, with our reasonable assistance.

5. Processor obligations

  • Instructions only. We process personal data only on documented instructions from the Customer, including regarding international transfers, unless required by EU or member-state law (in which case we inform the Customer unless prohibited).
  • Confidentiality. Persons authorised to process the data are bound by confidentiality obligations.
  • Security (Art. 32). We implement the technical and organisational measures in Annex B.
  • Assistance. We assist the Customer, insofar as possible, with data-subject requests (Arts. 12–23) and with Arts. 32–36 obligations. We notify the Customer promptly of requests received directly and do not respond to them without authorisation unless legally required.
  • Breach notification. We notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting Customer Data, including the nature, likely consequences and measures taken.

6. Subprocessors

The Customer grants general authorisation for the subprocessors in Annex A. We will give at least 30 days’ notice (email or in-Service) before adding or replacing a subprocessor; the Customer may object on reasonable data-protection grounds within 14 days, and if no resolution is found may terminate the affected service. We impose data-protection obligations on subprocessors equivalent to this DPA and remain liable for their performance.

7. Deletion and return

Upon termination, Customer Data remains available for export for 30 days (in-app reads, and on request to support). After the window we delete personal data in Customer Data, unless EU or Swedish law requires retention (e.g. bookkeeping). De-identified, aggregated data may be retained. Written confirmation of deletion is available on request to privacy@nordicstars.ai.

8. Audits

We make available the information reasonably necessary to demonstrate compliance with Article 28. The Customer may audit at most once per year, on at least 30 days’ written notice, at its own cost (unless the audit reveals material non-compliance), under confidentiality, and without disrupting the Service. We may satisfy audit requests in the first instance with our security documentation and the current third-party attestations of our cloud providers (e.g. Google Cloud’s ISO 27001 / SOC 2 reports).

9. International transfers

Primary processing occurs in the EU (Google Cloud europe-north1, Finland). Where a subprocessor entails transfers outside the EU/EEA, we rely on adequacy decisions (including the EU-US Data Privacy Framework) or EU Standard Contractual Clauses (Art. 46(2)(c)), with supplementary measures where needed.

10. Liability and governing law

Liability under this DPA is subject to the limitations in the Terms of Service. This DPA is governed by the laws of Sweden. Where this DPA conflicts with the Terms regarding personal data, this DPA prevails; the GDPR prevails over both.

Annex A — Authorised subprocessors

ProviderPurposeLocationSafeguards
Google Cloud Platform (incl. Google Cloud Identity Platform)Infrastructure, database, storage, sign-inEU — europe-north1 (Finland)ISO 27001, SOC 2; EU data residency
StripePayment processing, invoicing, taxEU primary; USPCI DSS Level 1; SCCs; EU-US DPF
Twilio SendGridTransactional email deliveryEU primary; USSOC 2; SCCs; EU-US DPF

Race tracking providers (currently GEORACING) act as data sources under the Customer’s own provider relationship, not as our subprocessors.

Annex B — Technical and organisational measures

  • Encryption in transit (TLS 1.3) and at rest (AES-256, Google Cloud default encryption).
  • Per-organisation tenant isolation enforced at the application and database layer.
  • Role-based access control on least privilege; administrative operations additionally require recent re-authentication.
  • Credentials and secrets held in a managed secret store; provider keys encrypted and write-only (never displayed after entry).
  • Audit logging of administrative actions; security logs retained 12 months.
  • Segregated production environment; all changes reviewed (automated and human gates) before deployment.
  • Documented incident response with the 48-hour customer notification in section 5.
  • EU data residency (europe-north1) for service data.

Contact

Privacy: privacy@nordicstars.ai · Legal: legal@nordicstars.ai

Terms of ServicePrivacy PolicyCookie PolicyData Processing AgreementService Level AgreementAcceptable Use Policy
Nordic Stars

Race plans and weather routing in the browser, Race Control on a tablet aboard, the debrief player with your video and the fleet on one clock, and analytics and reports from the boat’s own telemetry.

Product

NavigationRace ControlDebrief PlayerData AnalyticsPerformance Reports

Resources

DocumentationGetting startedBlog

Account

PricingOpen the appSupport

Legal

Terms of ServicePrivacy PolicyCookie PolicyData Processing AgreementService Level AgreementAcceptable Use

© 2026 Goose Yard Sailing AB · Nordic Stars