Data Processing Addendum

Effective date: 2026-05-18 · Version: 1.0

How this DPA becomes binding.This Data Processing Addendum (“DPA”) supplements the Terms of Servicebetween you (the “Customer”) and Oceancode (“Spanlens”, “Processor”). It is automatically incorporated into your contract when you create an organization or access the service, provided your processing of personal data is subject to the GDPR, UK GDPR, or another applicable data-protection law that requires a written processor contract. If you require a countersigned copy of this DPA for your records, email support@spanlens.io from your account address and we will return an executed PDF within 5 business days.

1. Parties

2. Definitions

Capitalized terms not defined here have the meaning given to them in the GDPR (Regulation (EU) 2016/679). For the avoidance of doubt:

3. Scope and roles

For the purpose of this DPA, the Customer is the Controller of Customer Personal Data and Spanlens is the Processor. Where the Customer is itself a Processor acting on behalf of one of its own clients, the Customer warrants that it has the legal authority to enter into this DPA on that client's behalf and that all instructions it gives to Spanlens are consistent with that client's instructions to the Customer.

4. Details of the processing

5. Processing only on documented instructions

Spanlens will process Customer Personal Data only on documented instructions from the Customer, including with regard to transfers of personal data to a third country or international organisation, unless required to do so by EU or Member State law to which Spanlens is subject. The Customer's documented instructions include this DPA, the Terms of Service, the Service documentation, and any reasonable supplementary written instructions from the Customer that are consistent with the foregoing.

Spanlens will immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data-protection law.

6. Personnel confidentiality

Spanlens ensures that persons authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access to Customer Personal Data is restricted on a need-to-know basis to the smallest possible number of personnel; as of the effective date of this DPA, this is limited to the proprietor of Oceancode.

7. Security of processing (Art. 32)

Spanlens implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

8. Use of subprocessors

The Customer gives Spanlens general written authorization to engage the subprocessors listed at spanlens.io/subprocessors. Spanlens will:

9. Assistance with data-subject rights

Taking into account the nature of the processing, Spanlens assists the Customer by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Customer's obligation to respond to requests from data subjects exercising their rights under GDPR Chapter III (Arts. 15–22).

The dashboard provides self-service tools that allow the Customer to export, rectify, and erase Personal Data within its organization without Spanlens involvement. Where additional assistance is required, the Customer may contact support@spanlens.io; Spanlens will respond without undue delay and in any event within 30 days.

10. Assistance with Arts. 32–36

Spanlens assists the Customer in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR, including security of processing, notification of personal data breaches, communication of personal data breaches to the data subject, data protection impact assessments, and prior consultation , taking into account the nature of processing and the information available to Spanlens.

11. Personal data breach notification

Spanlens will notify the Customer without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will, to the extent information is available at that time, describe:

Where information cannot be provided at the same time, it may be provided in phases without further undue delay.

12. Return or deletion of data

At the Customer's choice, on termination of the Service, Spanlens will delete or return all Customer Personal Data and delete existing copies, unless EU or Member State law or Korean law requires storage of the Customer Personal Data. The standard self-service deletion flow erases account-level data within the retention windows described in the Privacy Policy. The Customer may request immediate erasure by email; Spanlens will complete erasure within 30 days unless a longer period is required by law.

13. Audit rights

Spanlens will make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Art. 28 of the GDPR and allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.

In recognition that Spanlens is a small operator and that on-site audits impose significant operational cost, the parties agree that audit rights are satisfied in the first instance by:

The Customer may request an on-site audit only where a written security questionnaire is insufficient to address a documented concern; such audits will be scheduled at a mutually agreed time, conducted by a mutually agreed auditor bound by confidentiality, and limited in scope to what is necessary to address the concern. The Customer bears its own audit costs and Spanlens may recover reasonable internal costs for audits in excess of one per 24-month period.

14. International data transfers

Where Customer Personal Data is transferred from the EEA, the United Kingdom, or Switzerland to a country that has not received an adequacy decision from the European Commission or equivalent body, the parties agree that:

15. Liability

Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. Nothing in this DPA limits or excludes any liability that cannot be limited or excluded under applicable law (including direct liability of a Processor to a data subject under GDPR Art. 82(2)).

16. Term and termination

This DPA takes effect on the effective date stated at the top of this page and continues for as long as Spanlens processes Customer Personal Data. Termination of the underlying Terms of Service automatically terminates this DPA, except that Sections 11 (breach notification), 12 (return / deletion), and 13 (audit) survive to the extent necessary to give effect to the parties' respective obligations.

17. Governing law and jurisdiction

To the extent compatible with the Standard Contractual Clauses (where they apply), this DPA is governed by the laws of the Republic of Korea. The exclusive jurisdiction provisions of the Terms of Service apply. The Standard Contractual Clauses themselves are governed by the law and subject to the supervisory authority of the EU Member State chosen pursuant to Clause 17 and Clause 18 of the SCCs as completed in Annex A.

Annex A, Completion of the Standard Contractual Clauses

The following completions apply where the SCCs are incorporated under Section 14 of this DPA.

18. Changes to this DPA

Spanlens may revise this DPA from time to time to reflect changes in the Service, in applicable law, or in industry best practice. Material changes will be notified to the Customer by email to the account's billing address at least 30 days before taking effect. The effective date at the top of this page will always reflect the current version. Prior versions are available on request.

19. Contact

Questions about this DPA, requests for a countersigned copy, security questionnaire submissions, and audit requests should be directed to support@spanlens.iowith subject line beginning “DPA: …”.


Last updated: 2026-05-18. Previous versions are available on request. See also our Privacy Policy, Terms of Service, and Subprocessors list.