This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Goose Yard Sailing AB, org. nr. 559489-8594 (“Goose Yard”, the Processor) and the Customer (the Controller), and governs the processing of personal data contained in Customer Data under Article 28 GDPR.
1. Roles and scope
- The Customer is the controller of personal data in its telemetry, tracking data, events and organisation content; Goose Yard processes it only on the Customer’s behalf.
- Goose Yard is an independent controller for account and billing data (see the Privacy Policy), which is outside this DPA.
2. Subject matter, nature and purpose
On the Customer’s documented instructions, Goose Yard will:
- receive, validate, store and index telemetry — uploaded recordings and the live stream from Race Control;
- derive analytics from them (rollups, race detection, performance series) and serve them back in the debrief player;
- retrieve fleet tracking data from the race tracking provider the Customer connects, using the Customer’s own credentials — configuring an event for capture in the app constitutes the documented instruction;
- store video metadata (fingerprints, alignment) — video bytes are never uploaded;
- host organisation content such as polars, targets and notes.
Duration: the term of the agreement plus the 30-day post-termination export window, after which personal data is deleted per section 7.
3. Data subjects and categories
- Data subjects: the Customer’s crew, staff and invited users; competitors and other participants appearing in official race tracking feeds.
- Categories: identifiers (names, emails of invited users; boat and sail numbers, competitor names in provider feeds); location and performance data (GPS traces, speeds, headings, timestamps); video metadata.
- Special categories (Art. 9): none intended or required. The Customer must not submit special-category data.
4. Customer obligations
The Customer warrants that it:
- has a valid legal basis for the personal data it submits;
- provides any required privacy notices to its crew and users (GDPR Arts. 13–14);
- is entitled to use the race-tracking credentials and data it connects;
- issues lawful, documented instructions (use of the app is such an instruction);
- conducts DPIAs where its use requires them, with our reasonable assistance.
5. Processor obligations
- Instructions only. We process personal data only on documented instructions from the Customer, including regarding international transfers, unless required by EU or member-state law (in which case we inform the Customer unless prohibited).
- Confidentiality. Persons authorised to process the data are bound by confidentiality obligations.
- Security (Art. 32). We implement the technical and organisational measures in Annex B.
- Assistance. We assist the Customer, insofar as possible, with data-subject requests (Arts. 12–23) and with Arts. 32–36 obligations. We notify the Customer promptly of requests received directly and do not respond to them without authorisation unless legally required.
- Breach notification. We notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting Customer Data, including the nature, likely consequences and measures taken.
6. Subprocessors
The Customer grants general authorisation for the subprocessors in Annex A. We will give at least 30 days’ notice (email or in-Service) before adding or replacing a subprocessor; the Customer may object on reasonable data-protection grounds within 14 days, and if no resolution is found may terminate the affected service. We impose data-protection obligations on subprocessors equivalent to this DPA and remain liable for their performance.
7. Deletion and return
Upon termination, Customer Data remains available for export for 30 days (in-app reads, and on request to support). After the window we delete personal data in Customer Data, unless EU or Swedish law requires retention (e.g. bookkeeping). De-identified, aggregated data may be retained. Written confirmation of deletion is available on request to privacy@nordicstars.ai.
8. Audits
We make available the information reasonably necessary to demonstrate compliance with Article 28. The Customer may audit at most once per year, on at least 30 days’ written notice, at its own cost (unless the audit reveals material non-compliance), under confidentiality, and without disrupting the Service. We may satisfy audit requests in the first instance with our security documentation and the current third-party attestations of our cloud providers (e.g. Google Cloud’s ISO 27001 / SOC 2 reports).
9. International transfers
Primary processing occurs in the EU (Google Cloud europe-north1, Finland). Where a subprocessor entails transfers outside the EU/EEA, we rely on adequacy decisions (including the EU-US Data Privacy Framework) or EU Standard Contractual Clauses (Art. 46(2)(c)), with supplementary measures where needed.
10. Liability and governing law
Liability under this DPA is subject to the limitations in the Terms of Service. This DPA is governed by the laws of Sweden. Where this DPA conflicts with the Terms regarding personal data, this DPA prevails; the GDPR prevails over both.
Annex A — Authorised subprocessors
| Provider | Purpose | Location | Safeguards |
|---|---|---|---|
| Google Cloud Platform (incl. Google Cloud Identity Platform) | Infrastructure, database, storage, sign-in | EU — europe-north1 (Finland) | ISO 27001, SOC 2; EU data residency |
| Stripe | Payment processing, invoicing, tax | EU primary; US | PCI DSS Level 1; SCCs; EU-US DPF |
| Twilio SendGrid | Transactional email delivery | EU primary; US | SOC 2; SCCs; EU-US DPF |
Race tracking providers (currently GEORACING) act as data sources under the Customer’s own provider relationship, not as our subprocessors.
Annex B — Technical and organisational measures
- Encryption in transit (TLS 1.3) and at rest (AES-256, Google Cloud default encryption).
- Per-organisation tenant isolation enforced at the application and database layer.
- Role-based access control on least privilege; administrative operations additionally require recent re-authentication.
- Credentials and secrets held in a managed secret store; provider keys encrypted and write-only (never displayed after entry).
- Audit logging of administrative actions; security logs retained 12 months.
- Segregated production environment; all changes reviewed (automated and human gates) before deployment.
- Documented incident response with the 48-hour customer notification in section 5.
- EU data residency (europe-north1) for service data.
Contact
Privacy: privacy@nordicstars.ai · Legal: legal@nordicstars.ai