Purpose, Scope and Interpretation
1.1 Purpose
This Data Processing Agreement ("DPA") forms part of the agreement between Lite Blue Services Ltd., trading as Revert ("Revert", "Processor", "we", "us" or "our") and the User identified in the applicable Order, subscription or other agreement ("User", "Controller", "you" or "your") governing access to and use of the Platform (the "Terms of Use").
This DPA applies only where, and to the extent that, Revert processes Personal Data on behalf of the User as a processor within the meaning of the UK GDPR or, where applicable, the EU GDPR.
1.2 Scope
This DPA governs the processing of Personal Data carried out by Revert solely on the User's documented instructions for the purpose of providing the Services.
This DPA does not apply where Revert acts as an independent controller, including where Revert determines the purposes and means of processing Personal Data for its own legitimate business purposes, such as:
(a) administering user accounts and subscriptions;
(b) providing User support;
(c) billing, payment processing and account administration;
(d) maintaining the security, integrity and availability of the Platform;
(e) complying with legal or regulatory obligations;
(f) preventing fraud, abuse or unauthorised use of the Services;
(g) generating aggregated or anonymised analytics;
(h) facilitating business introductions, networking or lead generation through the Platform; or
(i) any other processing described in Revert's Privacy Policy or otherwise carried out by Revert in its capacity as an independent controller.
1.3 Order of precedence
In the event of any conflict between this DPA and the Terms of Use solely in relation to the processing of Personal Data where Revert acts as a processor, this DPA shall prevail to the extent of that conflict. In all other respects, the Terms of Use shall continue to apply.
1.4 Applicable data protection law
This DPA is intended to satisfy the requirements of Article 28 of the UK GDPR and, where applicable, Article 28 of the EU GDPR. Where both regimes apply, references in this DPA to the GDPR shall be construed accordingly.
Definitions
2.1 Defined terms
In this DPA, unless the context otherwise requires:
"Applicable Data Protection Law" means all applicable laws and regulations relating to the processing of Personal Data, including, where applicable, the UK GDPR, the EU GDPR, the Data Protection Act 2018 and any legislation implementing or supplementing them, as amended or replaced from time to time.
"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing", "Special Category Data", "Sub-processor" and "Supervisory Authority" shall have the meanings given to them under Applicable Data Protection Law.
"User Content" means any Personal Data processed by Revert on behalf of the User in connection with the Services and to which this DPA applies.
"EU GDPR" means Regulation (EU) 2016/679 (General Data Protection Regulation), as it forms part of the law of the European Union and as amended from time to time.
"Restricted Transfer" means a transfer of Personal Data to a country or recipient that requires appropriate safeguards under Applicable Data Protection Law.
"Services" means the services provided by Revert under the Terms of Use.
"UK GDPR" means the General Data Protection Regulation as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, together with the Data Protection Act 2018, as amended from time to time.
2.2 Interpretation
Unless otherwise defined in this DPA, capitalised terms shall have the meanings given to them in the Terms of Use.
References to legislation include any amendment, replacement, consolidation or re-enactment of that legislation.
Headings are for convenience only and do not affect interpretation.
References to the singular include the plural and vice versa.
Roles of the Parties
3.1 User as Controller
For the purposes of the processing activities governed by this DPA, the User acts as the Controller and appoints Revert to process User Content on the User's behalf and in accordance with the User's documented instructions, this DPA and the Terms of Use.
The User is responsible for ensuring that it has all necessary rights, permissions and lawful bases required under Applicable Data Protection Law to disclose User Content to Revert and to instruct Revert to process such Personal Data in accordance with this DPA.
3.2 Revert as Processor
Where this DPA applies, Revert shall process User Content solely:
(a) on the User's documented instructions, including those contained in the Terms of Use, this DPA and the User's authorised use of the Services;
(b) as necessary to provide the Services;
(c) as required to comply with Applicable Data Protection Law; or
(d) as otherwise permitted by this DPA.
Where Revert is required by Applicable Data Protection Law to process User Content other than on the User's instructions, Revert shall, unless prohibited by law, inform the User before carrying out such processing.
3.3 Independent controller activities
The parties acknowledge and agree that this DPA applies only to processing activities for which Revert acts as a Processor.
Nothing in this DPA shall apply where Revert acts as an independent Controller, including where Revert processes Personal Data for its own purposes in connection with:
(a) administering user accounts, subscriptions and access to the Platform;
(b) User support and service communications;
(c) billing, invoicing, payment administration and financial record-keeping;
(d) maintaining, securing, monitoring, troubleshooting and improving the Platform or Services;
(e) fraud prevention, cybersecurity, abuse detection and incident response;
(f) complying with legal, regulatory, law enforcement or judicial obligations;
(g) maintaining audit logs, security logs and business records;
(h) generating aggregated, anonymised or statistical information that does not identify any individual or User;
(i) facilitating introductions, networking, lead generation or communications between users of the Platform;
(j) protecting Revert's legal rights, enforcing the Terms of Use or defending legal claims; or
(k) any other processing carried out by Revert in its capacity as an independent Controller and described in the Privacy Policy or the Terms of Use.
3.4 User instructions
The User instructs Revert to process User Content only as necessary to provide the Services requested by the User, including hosting, storage, retrieval, transmission, AI-assisted analysis, API processing, MCP functionality, User support and other processing reasonably necessary for the operation of the Services, subject always to this DPA and the Terms of Use.
3.5 User responsibility
The User remains solely responsible for:
(a) determining the purposes and lawful bases for its processing of User Content;
(b) complying with its obligations as Controller under Applicable Data Protection Law;
(c) the accuracy, quality and lawfulness of User Content submitted to the Services;
(d) the legality of the User's instructions to Revert; and
(e) responding to Data Subject requests relating to the User's own processing activities, except to the extent Revert is required to provide assistance under this DPA.
Details of Processing
The subject matter, duration, nature and purpose of the processing, the categories of Data Subjects, the categories of User Content and any other information required by Article 28(3) UK GDPR or EU GDPR are set out in Annex A to this DPA.
The parties may update Annex A from time to time where reasonably necessary to reflect changes to the Services or the processing activities carried out under this DPA, provided that such updates do not materially reduce the level of protection afforded to User Content.
User Instructions
Revert shall process User Content only on the User's documented instructions unless otherwise required by Applicable Data Protection Law.
The User's documented instructions include:
(a) this DPA;
(b) the Terms of Use;
(c) the User's authorised configuration and use of the Services; and
(d) any additional written instructions agreed between the parties.
If Revert reasonably believes that an instruction infringes Applicable Data Protection Law, Revert may suspend the relevant processing and shall notify the User without undue delay unless prohibited by law.
Confidentiality
Revert shall ensure that all persons authorised to process User Content are subject to appropriate contractual or statutory duties of confidentiality and receive appropriate training regarding the protection of Personal Data.
This clause supplements, and does not replace, the confidentiality obligations contained in the Terms of Use.
Security Measures
Revert shall implement and maintain appropriate technical and organisational measures designed to protect User Content against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, User Content, taking into account the nature of the processing, the state of the art, implementation costs and the risks to Data Subjects.
A summary of Revert's technical and organisational measures is set out in Annex B.
Revert may modify or update its security measures from time to time, provided that such modifications do not materially reduce the overall level of protection afforded to User Content.
Sub-processors
The User authorises Revert to appoint Sub-processors to assist in providing the Services.
Revert shall ensure that each Sub-processor is bound by written contractual obligations that provide a level of protection for User Content substantially equivalent to those set out in this DPA.
Revert remains responsible for the performance of its Sub-processors to the extent required by Applicable Data Protection Law.
Upon reasonable written request from the Customer, Revert will provide information regarding the categories of Sub-processors it engages and, where appropriate and subject to appropriate confidentiality obligations, the identity of relevant Sub-processors.
Where required by Applicable Data Protection Law, Revert will provide reasonable prior notice of the appointment or replacement of a Sub-processor, allowing the Customer an opportunity to raise reasonable objections on data protection grounds.
International Transfers
Where the processing of User Content involves a Restricted Transfer, Revert shall ensure that appropriate safeguards are implemented in accordance with Applicable Data Protection Law.
Such safeguards may include adequacy regulations, Standard Contractual Clauses, the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or any other lawful transfer mechanism recognised under Applicable Data Protection Law.
Assistance to the User
Taking into account the nature of the processing and the information available to Revert, Revert shall provide reasonable assistance to the User, upon written request and at the User's expense where appropriate, to enable the User to comply with its obligations under Applicable Data Protection Law relating to:
(a) responding to requests from Data Subjects;
(b) data protection impact assessments;
(c) prior consultation with a Supervisory Authority where required; and
(d) demonstrating compliance with Applicable Data Protection Law.
Where Revert receives a request directly from a Data Subject relating to User Content, Revert shall, unless prohibited by law, promptly notify the User and shall not respond to the request except on the User's documented instructions or where required by Applicable Data Protection Law.
Personal Data Breaches
Revert shall notify the User without undue delay after becoming aware of a Personal Data Breach affecting User Content.
Such notification shall, where reasonably practicable, include:
(a) the nature of the Personal Data Breach;
(b) the categories of User Content affected;
(c) the measures taken or proposed to address the Personal Data Breach; and
(d) any information reasonably available to assist the User in complying with its obligations under Applicable Data Protection Law.
Audits and Information
Revert shall make available to the User such information as is reasonably necessary to demonstrate compliance with this DPA.
Where such information is insufficient, the User may request a reasonable audit of Revert's compliance with this DPA, subject to:
(a) at least thirty (30) days' prior written notice;
(b) the audit taking place during normal business hours;
(c) the audit not unreasonably interfering with Revert's business operations or the confidentiality obligations owed to other Users;
(d) the parties agreeing appropriate confidentiality arrangements before any audit; and
(e) the User bearing its own costs and reimbursing Revert's reasonable costs incurred in supporting the audit, unless the audit identifies a material breach of this DPA.
No more than one audit may be conducted during any twelve (12) month period unless required by a Supervisory Authority or Applicable Data Protection Law.
Return or Deletion of User Content
Upon termination or expiry of the Services, Revert shall, at the User's written request, delete or return User Content, unless Applicable Data Protection Law requires continued retention.
Nothing in this clause shall require Revert to delete Personal Data contained in routine backup systems before the normal expiry of applicable backup retention periods, provided such data remains protected in accordance with this DPA.
Liability
The liability of each party arising out of or in connection with this DPA shall be subject to the exclusions and limitations of liability set out in the Terms of Use, except to the extent such limitations are prohibited by Applicable Data Protection Law.
Term and Survival
This DPA shall commence on the date the User first uses the Services in a manner that results in Revert acting as a Processor on behalf of the User and shall remain in force for so long as Revert processes User Content on the User's behalf.
Clauses which by their nature are intended to survive termination, including those relating to confidentiality, security, international transfers, liability and return or deletion of User Content, shall survive termination of this DPA for so long as Revert retains User Content.
ANNEX A
Description of Processing
Subject Matter
The processing of User Content by Revert in connection with the provision of the Services under the Terms of Use.
Duration
For the duration of the User's use of the Services and thereafter only for so long as necessary to comply with this DPA, the Terms of Use or Applicable Data Protection Law.
Nature of the Processing
Processing may include, where applicable: collection; recording; organisation; structuring; storage; hosting; retrieval; consultation; transmission; sharing on the User's documented instructions; AI-assisted analysis; document analysis; API processing; MCP processing; matching and workflow automation; adaptation; pseudonymisation; backup; deletion; and destruction.
Purpose of the Processing
To enable Revert to provide the Services requested by the User, including:
-
hosting and operating the Platform;
-
facilitating communication between Authorised Users;
-
processing User documents and data submitted to the Services;
-
providing AI-assisted functionality requested by the User;
-
enabling API and MCP integrations;
-
storing User data;
-
providing User support;
-
maintaining system resilience, security and business continuity; and
-
carrying out other processing activities necessary for the provision of the Services in accordance with the Terms of Use.
Categories of Data Subjects
Depending upon how the User uses the Services, Data Subjects may include: the User's employees; Authorised Users; directors; officers; contractors; consultants; Users; suppliers; brokers; traders; counterparties; vessel owners; ship managers; charterers; port agents; service providers; business contacts; and other individuals whose Personal Data the User submits to the Services.
Categories of User Content
Depending upon the User's use of the Services, User Content may include: names; business contact details; company information; job titles; email addresses; telephone numbers; correspondence; messages; uploaded documents; RFQs; quotations; commercial information; vessel information; operational information; API requests; AI prompts; AI outputs containing Personal Data; metadata; usage logs; authentication information; and any other Personal Data submitted by or on behalf of the User.
Special Category Data
The User shall not intentionally submit Special Category Data to the Services unless:
(a) such processing is necessary for the User's legitimate use of the Services;
(b) the User has an appropriate lawful basis under Applicable Data Protection Law; and
(c) Revert has agreed in writing to process such data where required by Applicable Data Protection Law.
ANNEX B
Technical and Organisational Measures
Revert maintains technical and organisational measures appropriate to the risks presented by the processing of User Content. Such measures include, where appropriate:
Governance
-
documented security policies and procedures;
-
personnel confidentiality obligations;
-
security awareness and privacy training;
-
access to User Content limited on a least-privilege basis.
Access Controls
-
user authentication mechanisms;
-
role-based access controls where appropriate;
-
management of privileged access;
-
periodic review of access permissions.
Encryption
-
encryption of Personal Data in transit using industry-standard protocols where appropriate;
-
encryption of Personal Data at rest where appropriate.
System Security
-
firewalls and network security controls;
-
monitoring and logging of security events;
-
malware protection;
-
vulnerability management;
-
security patch management.
Operational Security
-
secure software development and deployment practices;
-
backup and recovery procedures;
-
disaster recovery and business continuity planning;
-
change management processes.
Incident Management
-
procedures for identifying, managing and investigating security incidents;
-
procedures for notifying Users of Personal Data Breaches where required by this DPA.
Sub-processors
Revert conducts appropriate due diligence before appointing Sub-processors and requires Sub-processors to implement appropriate technical and organisational measures consistent with the requirements of this DPA.
Ongoing Review
Revert reviews and updates its technical and organisational measures periodically to reflect changes in technology, applicable security risks, legal requirements and the Services, provided that such changes do not materially reduce the level of protection afforded to User Content.
