DockOptima Back to home

Data Processing Agreement

Last updated: 29 September 2026

This Data Processing Agreement ("DPA") forms part of the agreement between the customer organisation using DockOptima ("Customer", the Data Controller) and DockOptima ("DockOptima", the Data Processor). It governs the processing of personal data under the UK GDPR and the EU GDPR, in particular Article 28. It takes effect on the date the Customer first creates a DockOptima account, or on the date of a separately signed copy.

1. Roles and scope

The Customer determines the purposes and means of processing personal data entered into the platform and is the Controller. DockOptima processes that personal data only on the Customer's documented instructions, which include use of the platform's features and any written instructions the Customer gives. DockOptima will inform the Customer if, in its opinion, an instruction infringes applicable data protection law.

2. Subject matter, duration, nature and purpose

  • Subject matter: provision of dock scheduling, carrier booking and yard management software.
  • Duration: for the term of the Customer's subscription, plus the deletion period in section 9.
  • Nature and purpose: hosting, storage, transmission, display and analysis of appointment, gate and yard data, and delivery of related notifications.

3. Categories of data subjects and personal data

  • Data subjects: Customer employees and users; carrier staff and contacts; drivers attending site; individuals named in delivery paperwork.
  • Personal data: name, work email, telephone number, job role, company, user account credentials (hashed), driver name, vehicle registration (VRM), arrival and departure timestamps, site check-in records, uploaded delivery documents, messages exchanged in the platform, and technical data such as IP address and user agent.
  • Special category data: none is requested or required. The Customer must not upload special category data into free-text or document fields.

4. Processor obligations

  • Process personal data only on documented instructions from the Customer.
  • Ensure that personnel authorised to process personal data are bound by confidentiality.
  • Implement the technical and organisational measures set out in section 5.
  • Assist the Customer with data subject requests, data protection impact assessments and consultations with supervisory authorities.
  • Make available all information necessary to demonstrate compliance with Article 28.

5. Security measures (Article 32)

  • Tenant isolation: row-level security in the database scopes every record to a single organisation.
  • Encryption: TLS 1.3 in transit; AES-256 at rest, including backups and uploaded documents.
  • Access control: role-based permissions enforced server-side; least-privilege administrative access.
  • Auditability: changes to facilities, docks, appointments and gate events are recorded in an audit trail.
  • Certified infrastructure: hosting providers audited to ISO/IEC 27001:2022, SOC 1 and SOC 2 Type II.
  • Resilience: automated encrypted daily backups with point-in-time restore.
  • Payments: card data handled solely by Stripe (PCI-DSS Level 1); DockOptima never stores card numbers.

6. Sub-processors

The Customer grants general authorisation for DockOptima to engage sub-processors, each bound by written terms no less protective than this DPA. Current categories:

  • Cloud application hosting and edge delivery — serving the web application (UK/EEA regions).
  • Managed database, authentication and file storage — accounts, appointments, gate events, uploaded documents (EU region).
  • Transactional email provider — booking confirmations, status updates, invitations, password resets.
  • Payment processor (Stripe) — subscription billing and card processing.
  • AI provider — optional yard insight summaries; data is not used to train models.

A current named list is available at contact@dockoptima.com. DockOptima will give reasonable prior notice of any new or replacement sub-processor, and the Customer may object on reasonable data protection grounds.

7. International transfers

Personal data is stored and processed in the United Kingdom and the European Economic Area. DockOptima will not transfer personal data outside the UK/EEA without first putting an approved transfer mechanism in place (UK IDTA, or EU Standard Contractual Clauses with the UK Addendum) and updating this DPA.

8. Personal data breaches

DockOptima will notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting the Customer's data, providing the nature of the breach, categories and approximate volume of records affected, likely consequences and remedial measures taken.

9. Return and deletion of data

On termination or expiry, the Customer may export its data from the platform. On written request, DockOptima will delete all Customer personal data within 30 days, except where retention is required by law. Backups containing deleted data expire on the standard backup rotation.

10. Data subject rights

DockOptima will promptly forward any data subject request it receives directly to the Customer and will assist the Customer in responding, including through the platform's export and deletion tools.

11. Audit

DockOptima will provide the Customer with information reasonably required to demonstrate compliance, including infrastructure certifications and completed security questionnaires. On no more than one occasion per year, and on 30 days' written notice, the Customer may conduct a remote audit at its own cost, subject to confidentiality.

12. AI processing

Where the Customer enables AI insight features, operational data included in prompts is processed only to generate that output. It is not retained for model training and is not used to train third-party models.

13. Liability and governing law

Liability under this DPA is subject to the limitations in the main agreement between the parties. This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

14. Signed copies

To request a countersigned PDF of this DPA for your records, email contact@dockoptima.com with your organisation's legal name and registered address.

This document reflects DockOptima's standard processing terms and is not legal advice. Customers with bespoke requirements should contact us to agree amendments.