Data Processing Addendum
This is the legal contract that governs how we handle your data on your behalf. Plain language wherever possible.
Lawful basis
We process your data on the basis of contract (delivering the service you signed up for). For AI features (voice transcription, marine-life identification, logbook insights) we additionally rely on your explicit consent — toggleable per feature in your account settings.
What data we process
- Account: email, display name, certification level, agency.
- Dive logs: every field you enter or import (depth, time, site, buddies, notes, gas mix, gear).
- Photos: only when you upload them; encrypted at rest.
- Audio: only when you voice-log on Cloud tier; deleted within 24 hours of transcription.
Retention
- Sync events: 30 days, then pruned.
- Account / billing / data-access events: 12 months minimum.
- Voice audio: deleted within 24 hours of transcription.
- Photos: retained until you delete them or your account.
Your rights
You can submit a GDPR data-subject-rights request from your account screen — access, rectification, portability, deletion. We respond within 30 days. Founder reads each one personally at v1 scale.
Breach notification
We commit to a 72-hour breach notification window per GDPR Article 33. The incident-response runbook is published at docs/runbooks/incident-response.md.
Data residency
All data lives in the EU. Application hosting: Railway eu-west (Amsterdam). Photo and export storage: Cloudflare R2 EU Jurisdiction. Email: Resend EU region. Error monitoring: Sentry EU. Authentication: self-hosted Zitadel on Railway eu-west (Amsterdam) — no separate authentication sub-processor. AI providers may be US-based (Anthropic (Claude Vision)) under DPF + SCC; the EU-sovereign Mistral (Pixtral) fallback is on the roadmap. Voice transcription: Speechmatics EU. Payments: Stripe EU. iOS billing: Apple. Android billing: Google Play Billing.
Sub-processors
Every service we use to run Scubra Dive Log is listed below. Two columns matter: where the service runs (region) and what it does (purpose). The “status” column distinguishes services we currently use from those we are prepared to use as fallbacks.
| Service | Region | Purpose | Data | Status |
|---|---|---|---|---|
| Railway | eu-west (Amsterdam) | Application hosting (incl. self-hosted authentication service) | account, auth metadata, sync metadata | Active |
| Cloudflare R2 | EU Jurisdiction | Photo + export storage | photos, export bundles | Active |
| Anthropic (Claude Vision) | US (DPF + SCC) | Marine-life identification (Cloud-tier opt-in) | photos when consented | Active |
| Mistral (Pixtral) | EU | EU-sovereign Vision API fallback | photos when consented | Planned (not active) |
| Speechmatics | EU | Cloud voice transcription (Cloud-tier opt-in) | audio when consented | Active |
| Stripe | EU | Web subscription billing | billing | Active |
| Apple | global | iOS in-app purchase (StoreKit) | billing | Active |
| Google Play Billing | global | Android in-app purchase | billing | Active |
| Resend | EU | Transactional email | email address | Active |
| Sentry | EU | Error monitoring | error stack traces (PII redacted) | Active |
Last updated: 4 May 2026