GDPR Article 28 terms for Dive Centers using the Diving Experience Manager (DEM)
This Data Processing Agreement ("DPA") forms part of, and is entered into together with, the Business Terms between MBAR Millibar Technologies UG (haftungsbeschränkt) ("MBAR", "Processor", "we", "us") and the organization that has accepted the Business Terms (the "Dive Center", "Controller", "you"). It reflects the requirements of Art. 28 of Regulation (EU) 2016/679 ("GDPR") for the processing of personal data that MBAR carries out on the Dive Center's behalf through the Diving Experience Manager ("DEM").
This DPA applies only to processing where the Dive Center acts as controller and MBAR acts as processor, as described in Section 1 of our Privacy Policy. It does not apply to processing where MBAR acts as controller in its own right (for example for individual Millibar accounts or platform security), which remains governed by the Privacy Policy alone.
The subject matter of this DPA is the processing of personal data by MBAR on behalf of the Dive Center through DEM. Processing is carried out for the duration of the Business Terms between MBAR and the Dive Center, and ceases upon termination, subject to Section 11 (Deletion or Return of Data).
MBAR processes personal data as necessary to provide DEM's administrative, communication, and operational features to the Dive Center, including: managing customer and diver records; check-in and check-out workflows; collecting and storing forms, waivers, declarations, and signed documents configured by the Dive Center; recording certifications and dive activity; managing bookings and equipment; and sending related communications on the Dive Center's behalf. MBAR does not process this data for any purpose of its own.
Depending on how the Dive Center configures and uses DEM, processing may include:
Customers, divers, and guests of the Dive Center, and, where the Dive Center configures DEM to record them, the Dive Center's own staff or team members.
MBAR will process personal data only on the Dive Center's documented instructions, which are given by the Dive Center's configuration and use of DEM (for example, which forms it enables, what data fields it collects, and which features it activates), unless MBAR is required to process the data otherwise by EU or member state law to which MBAR is subject — in which case MBAR will inform the Dive Center of that legal requirement before processing, unless the law prohibits this on important grounds of public interest.
If MBAR considers an instruction to infringe the GDPR or other applicable data protection provisions, it will inform the Dive Center without undue delay.
MBAR ensures that persons authorized to process the personal data (including its own personnel and any subprocessors) have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to what is necessary to provide DEM.
MBAR implements the technical and organizational measures ("TOMs") described on our Security page, which forms part of this DPA by reference, including: hosting infrastructure aligned with ISO 27001 standards, encrypted data transmission (TLS), hashed password storage, restricted access controls, two-factor authentication for infrastructure access, web application firewalls, multi-facility backups, continuous vulnerability monitoring, and regular code review. Health and medical data is stored with access restricted to authorized personnel and kept separate from general account data, as described in our Privacy Policy.
MBAR may update these measures from time to time, provided the updated measures do not materially reduce the overall level of protection.
The Dive Center authorizes MBAR to engage the subprocessors listed in our Privacy Policy (Section 6, Service Providers and International Transfers), each bound by a data processing agreement imposing data protection obligations equivalent to those in this DPA. MBAR will inform the Dive Center of any intended addition or replacement of a subprocessor, giving the Dive Center a reasonable opportunity to object on legitimate data protection grounds before the change takes effect. An up-to-date list of subprocessors may be requested at privacy@millibar.io.
Note on third-party diving-agency integrations: where a Dive Center configures an integration with a third-party diving or sport-association federation (for example, to register members for a federation membership card), MBAR transmits data to that federation at the Dive Center's own instruction and configuration. Such federations act as independent recipients of the data for their own registration purposes, not as MBAR subprocessors, and are not covered by this DPA. The Dive Center is responsible for its own relationship with any such federation.
Taking into account the nature of the processing, MBAR will assist the Dive Center, insofar as possible and by appropriate technical and organizational measures, in responding to requests from data subjects seeking to exercise their rights under Chapter III of the GDPR (access, rectification, erasure, restriction, portability, and objection). Where a data subject contacts MBAR directly about data processed on a Dive Center's behalf, MBAR will forward the request to the Dive Center without undue delay.
MBAR will notify the Dive Center without undue delay after becoming aware of a personal data breach affecting personal data processed on the Dive Center's behalf, and will provide the information reasonably available to it to allow the Dive Center to meet any of its own notification obligations under Art. 33 and 34 GDPR.
Upon termination of the Business Terms, and at the Dive Center's choice, MBAR will delete or return all personal data processed on the Dive Center's behalf, and delete existing copies, unless EU or member state law requires storage of the data. This mirrors the retention approach described in our Business Terms and Privacy Policy for account deletion.
MBAR will make available to the Dive Center all information reasonably necessary to demonstrate compliance with the obligations in this DPA, and will allow for and contribute to audits, including inspections, conducted by the Dive Center or an auditor mandated by the Dive Center, subject to reasonable advance notice, confidentiality, and scheduling that avoids undue disruption to MBAR's operations and other customers.
Where a subprocessor listed under Section 8 is located outside the European Economic Area, the transfer is covered by Standard Contractual Clauses (SCCs) or another valid transfer mechanism under Art. 46 GDPR, as described for each subprocessor in our Privacy Policy.
Latest update: 31 August 2026
For questions about this DPA, please contact us at
privacy@millibar.io.
Note: This document has been prepared in good faith to reflect current practices. It is
recommended that it receives legal review before being treated as final.
2026 © Millibar Technologies - All Rights Reserved