Data processing addendum
Last updated August 19, 2026 · Version 2026-08-19.2
What this is. This Data Processing Addendum (“DPA”) sets out how Zeil Software LLC (“Zeil”) handles personal information that a sailing club puts into its Zeil workspace. The club decides what is collected and why, so the club is the controller and Zeil is its processor. This DPA supplements the Zeil Terms of Service or other agreement between the parties (the “Agreement”) and controls over it for the subject matter covered here.
Who the parties are. This DPA is entered into by Zeil and the club that executes it (the “Club”). A Club executes it by clicking to accept it, or by accepting other terms that state that accepting them executes this DPA, or by signing a countersigned copy. Section 13 sets out those routes.
Version. This text carries the version identifier shown at the top of this page, in the form YYYY-MM-DD.n. That identifier changes whenever any word of this DPA changes, so no two different texts ever answer to the same identifier, and the version a Club executed always names the exact wording that Club agreed to.
1. Definitions
- Personal Data means information relating to an identified or identifiable natural person contained in Club Data (as defined in the Agreement) that Zeil processes on the Club’s behalf.
- Processing means any operation performed on Personal Data: collection, storage, use, disclosure, deletion, and so on.
- Data Protection Laws means privacy and data-protection laws applicable to the parties’ processing of Personal Data under the Agreement, including US state privacy laws and, where applicable, the Children’s Online Privacy Protection Act (COPPA).
- Subprocessor means a third party engaged by Zeil to process Personal Data.
- Security Incident means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by Zeil.
2. Roles and scope
2.1 The Club is the controller (or “business” under laws using that term) of Personal Data in its workspace; Zeil is the Club’s processor (or “service provider”). Each party will comply with Data Protection Laws applicable to it in that role.
2.2 Details of processing are set out in Annex 1: subject matter, duration, nature and purposes, and the categories of data subjects and data.
2.3 Zeil acts as a controller only for the limited data described in its Privacy Policy (for example global account identities, billing records, and marketing contacts). That processing is outside this DPA.
3. Club instructions
3.1 Zeil will process Personal Data only on the Club’s documented instructions, which are: (a) to provide, secure, and support the services per the Agreement and documentation; (b) the Club’s and its authorized users’ configurations and actions in the product; and (c) other written instructions the parties agree to. Zeil will inform the Club if, in its opinion, an instruction violates Data Protection Laws.
3.2 Service-provider commitments. Zeil will not: sell or share Personal Data; retain, use, or disclose it for any purpose other than performing the services, or as permitted by law; retain, use, or disclose it outside the direct business relationship with the Club; or combine it with personal information from other sources except as permitted for service providers. Zeil certifies that it understands and will comply with these restrictions.
3.3 The Club is responsible for the lawfulness of the Personal Data it submits, including providing notices to members and obtaining any required consents (including verifiable parental consent for minors in junior programs, as set out in the Agreement).
4. Confidentiality
Zeil ensures that the people it authorizes to process Personal Data, including its personnel and agents, are bound by confidentiality obligations.
5. Security
5.1 Zeil will implement and maintain appropriate technical and organizational measures to protect Personal Data, no less protective than those summarized in Annex 2.
5.2 Zeil may update the Annex 2 measures from time to time, provided the overall security of the services is not materially reduced during a subscription term.
6. Subprocessors
6.1 The Club provides general authorization for the Subprocessors listed in Annex 3, published and kept current at zeilapp.com/subprocessors, and for replacements and additions made under this Section.
6.2 Change notice. Zeil will give the Club at least 30 days’ advance notice, by email to Club administrators or on the subprocessors page or both, before authorizing a new Subprocessor to process Personal Data.
6.3 Objection. If the Club reasonably objects on data-protection grounds within the notice period, the parties will discuss in good faith. If Zeil cannot reasonably accommodate the objection, the Club may terminate the affected services on notice and receive a pro-rata refund of prepaid unused fees. Continued use after the notice period constitutes approval.
6.4 Zeil will impose data-protection obligations on Subprocessors that are materially no less protective than this DPA, and remains responsible for their performance.
7. Assistance
7.1 Data subject and consumer requests. Taking into account the nature of the processing, Zeil will assist the Club by appropriate technical and organizational measures (self-service profile editing, export, deletion flows) in fulfilling the Club’s obligation to respond to member requests to access, correct, delete, or port Personal Data. If a member contacts Zeil directly about Club workspace data, Zeil will, where the member’s club is identifiable, direct the request to the Club without undue delay, and will not respond substantively except as required by law.
7.2 Zeil will provide reasonable assistance with the Club’s data-protection assessments and regulator consultations relating to the services, to the extent required by Data Protection Laws and taking into account the information available to Zeil.
8. Security incident notification
8.1 Zeil will notify the Club without undue delay, and in any event within 72 hours, after confirming a Security Incident affecting the Club’s Personal Data.
8.2 The notice will describe, to the extent known: the nature of the incident, the categories and approximate volumes of data and data subjects affected, likely consequences, and measures taken or proposed. Zeil will provide timely updates as the investigation proceeds and will reasonably cooperate with the Club’s legal notification obligations. State breach-notification laws are the Club’s obligations for its member data where the Club is the data owner; Zeil’s notice under this Section is designed to let the Club meet its own deadlines.
8.3 Zeil’s notification of, or response to, a Security Incident is not an acknowledgment of fault or liability.
9. Audits and information
9.1 On the Club’s written request, no more than once per 12 months absent a Security Incident affecting the Club, Zeil will make available information reasonably necessary to demonstrate compliance with this DPA: security summaries and completed security questionnaires, together with penetration-test summaries and third-party audit reports when and if Zeil obtains them. Zeil does not hold a SOC 2 attestation and does not have a penetration test to share.
9.2 If the information in 9.1 is insufficient to meet a requirement of Data Protection Laws, the Club may conduct an audit, itself or through an independent auditor bound to confidentiality and not a Zeil competitor. The audit is limited in scope, duration, and frequency, on at least 30 days’ notice, during business hours, without access to other clubs’ data, and at the Club’s expense. Zeil may charge reasonable costs for support exceeding one business day.
10. Deletion and return
10.1 During the term, the Club can export Club Data (including Personal Data) under the Agreement’s no-lock-in export right. Individual users export their own account and activity data from their profile at any time; a full club-level export is a service Zeil performs on the Club’s request, delivered in a commonly used machine-readable format within 10 business days.
10.2 On termination or expiry, Zeil will (a) keep export available for 60 days; then (b) delete Personal Data from production systems within 90 days after the export window closes; and (c) allow backups containing Personal Data to age out of rotation within approximately 35 further days. Zeil may retain data it must keep under applicable law (for example billing and audit records), protected under this DPA and deleted when the requirement ends.
10.3 On the Club’s written request, Zeil will confirm deletion in writing.
11. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. Nothing in this DPA expands them.
12. International provisions
Zeil is a United States company serving US clubs, and Service data is hosted in Canada as stated in Annex 3. If the Club requires processing subject to the GDPR or UK GDPR, the parties will execute appropriate transfer mechanisms (for example EU Standard Contractual Clauses and the UK Addendum) before such processing begins. Write to legal@zeilapp.com with the subject “DPA”.
13. Term, precedence, and execution
This DPA is effective while Zeil processes Personal Data for the Club, survives termination of the Agreement until deletion under Section 10 completes, and terminates automatically thereafter.
Execution by click-through. The Club may execute this DPA by checking a box or clicking a button presented with it, or presented with other terms that state that accepting them executes this DPA. That click has the same legal effect as a signature. The version executed is the version published on this page on the date of acceptance, and Zeil records that version, the accepting person’s name and email, and the date and time. The Club may request a copy of its own execution record at legal@zeilapp.com.
Execution by signature. A Club whose board requires a signed document can request a countersigned copy of this same text at legal@zeilapp.com with the subject “DPA”. Signatures may be electronic.
Annex 1: details of processing
| Subject matter | Provision of sailing-club management services: membership, reservations, crew, credentials, weather and Sail Brief advisories, announcements. |
|---|---|
| Duration | Term of the Agreement plus the deletion period in Section 10. |
| Nature and purposes | Hosting, storage, display, transmission, generation of advisories from Club-configured inputs, backup, support. |
| Categories of data subjects | Club members, skippers, crew, volunteers, staff, administrators; emergency contacts of members; junior program participants only as roster records entered by adult administrators (child-facing accounts require the consent flow per the Agreement). |
| Categories of Personal Data | Identification and contact data (name, email, phone, avatar); emergency contact details; sailing certifications, endorsements, and eligibility records; membership role and status; reservation and crew history; announcements and messages; usage logs. No payment card numbers: card and bank details are entered on Stripe’s own pages and held by Stripe, and do not reach Zeil’s systems. No government IDs. |
| Sensitive data | None intended. Clubs are instructed not to submit special-category data beyond voluntary emergency-contact and safety notes. |
Annex 2: security measures
| Tenant isolation | Multi-tenant architecture with row-level security enforced at the PostgreSQL database layer. Every club-scoped query is bound to the club’s context, and the subdomain resolves to a club on every request. |
|---|---|
| Encryption in transit | TLS 1.2+ for all connections to the application and the API. |
| Access control | Role-based access within club workspaces (admin and member); least-privilege production access limited to named administrators. |
| Application security | Server-side authorization on every mutation; database-level constraints (for example exclusion constraints preventing conflicting writes); rate limiting; audit logging; continuous integration with automated end-to-end tests. |
| Backups and recovery | Nightly automated database backups retained on the hosting infrastructure for 30 days, and a documented restore runbook covering dump selection, integrity checks, cutover, and post-restore verification. |
| Availability and monitoring | Health checks, uptime monitoring, and error reporting. |
| Vendor management | Written terms with all Subprocessors (Annex 3), and data-processing terms with subprocessors handling Personal Data. |
| Personnel | Confidentiality obligations, and security review of automation with human approval gates for irreversible actions. |
| Data minimization | AI Sail Brief prompts include only reservation-relevant metadata, and weather lookups transmit coordinates only. |
Annex 3: approved subprocessors
These are the third parties that process Personal Data on Zeil’s behalf. The current list, together with the third parties that are named in the Privacy Policy but are not Subprocessors, is published at zeilapp.com/subprocessors. Changes are notified under Section 6.2.
| Subprocessor | Function | Location |
|---|---|---|
| OVH SAS | Cloud infrastructure hosting, database, and backups. All Service data is held here. | Canada (Montreal region) |
| Anthropic, PBC | AI generation of Sail Briefs. Receives only the brief inputs described in the Privacy Policy, and does not train on data submitted through its API under its commercial terms. | United States |
| Resend, Inc. | Transactional email delivery. Receives recipient addresses and full message content. | United States |
| Stripe, Inc. | Payment processing, in two roles: Zeil’s processor for the Club’s subscription to Zeil, and the Club’s own processor where the Club collects payments from its members and guests on the Club’s own Stripe account. | United States |
| Functional Software, Inc. (Sentry) | Application error reporting. Names and emails are not attached to reports and session replay is disabled; reports can carry technical context and, at the transport level, an IP address. | United States |
| Open-Meteo | Weather and tide forecast API. Receives club coordinates and a date range only, and ordinarily no Personal Data. | Switzerland |
Contact
Email: legal@zeilapp.com with the subject “DPA”.
Zeil Software LLC · 500 Paterson Plank Rd # 31479, Union City, NJ 07087, USA