NoonBridge

Data Processing Addendum

Last updated: 5 July 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between the customer (“Customer”) and Bobook Limited, operating NoonBridge (“NoonBridge”), where NoonBridge processes personal data on behalf of the Customer in connection with the NoonBridge service.

This DPA is intended to support GDPR and similar data protection requirements. If there is a conflict between this DPA and the main agreement, this DPA controls only in relation to the processing of personal data.


1. Parties and roles

For customer noon reports, sample reports, uploaded files, extracted report data, and related service data that contain personal data:

For NoonBridge’s own website visitors, commercial contacts, billing contacts, and general business administration, NoonBridge may act as an independent controller as described in the Privacy Policy.


2. Processing instructions

NoonBridge will process personal data only:

If NoonBridge believes an instruction violates applicable data protection law, it will inform the Customer where legally permitted.


3. Details of processing

Subject matter

Processing of vessel noon reports, sample reports, report emails, attachments, extracted data, validation alerts, dashboards, exports, and related customer service data.

Duration

For the duration of the customer relationship, pilot, snapshot review, or other agreed service period, plus any retention period needed for export, deletion, backup, legal, security, accounting, or dispute purposes.

Nature and purpose

Receiving, storing, parsing, extracting, normalizing, validating, displaying, exporting, supporting, securing, troubleshooting, and deleting customer report data.

Categories of data subjects

Data subjects may include:

Categories of personal data

Personal data may include:

Noon reports are primarily operational data, but may include personal data depending on customer content.

Special categories of personal data

NoonBridge does not intentionally require special categories of personal data. The Customer should not submit special category data unless necessary and lawfully permitted.


4. Confidentiality

NoonBridge will ensure that persons authorised to process customer personal data are subject to appropriate confidentiality obligations.

Access to customer report data will be limited to personnel and service providers who need access to provide, support, secure, or maintain the service.


5. Security measures

NoonBridge will implement reasonable technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.

Measures may include, as appropriate:

NoonBridge’s current security posture is also described in the Security and Confidentiality Statement.


6. Sub-processors

The Customer gives NoonBridge general authorisation to use sub-processors where reasonably necessary to provide the service, including hosting, storage, email, analytics, support, OCR, parsing, automation, AI, monitoring, and security providers.

NoonBridge will require sub-processors to process personal data only for authorised purposes and to apply appropriate confidentiality and security obligations.

NoonBridge should maintain a list of material sub-processors and provide it to customers upon request.

If a customer has a reasonable objection to a new material sub-processor, the customer may notify NoonBridge in writing. NoonBridge will work in good faith to address the objection, which may include providing additional information, offering a workaround where commercially reasonable, or allowing termination of the affected service where required.


7. International transfers

Where personal data is transferred outside the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with applicable transfer restrictions, NoonBridge will use appropriate safeguards where required by law. These may include adequacy decisions, standard contractual clauses, transfer risk assessments, or other lawful transfer mechanisms.


8. Data subject requests

NoonBridge will reasonably assist the Customer in responding to data subject requests where the Customer cannot reasonably fulfil the request without NoonBridge’s assistance.

If NoonBridge receives a data subject request relating to personal data processed on behalf of the Customer, NoonBridge may refer the request to the Customer unless legally required to respond directly.


9. Personal data breach

NoonBridge will notify the Customer without undue delay after becoming aware of a personal data breach affecting customer personal data.

The notice will include available information reasonably needed by the Customer to assess the breach and meet its legal obligations, taking into account the nature of the breach and information available to NoonBridge.

NoonBridge will take reasonable steps to investigate, contain, and remediate the breach.


10. Assistance with compliance

Taking into account the nature of processing and information available to NoonBridge, NoonBridge will provide reasonable assistance to the Customer with:

Assistance may be subject to reasonable fees if it requires substantial time, unless caused by NoonBridge’s breach of this DPA.


11. Return or deletion of data

Upon termination of the service or upon written request, NoonBridge will delete or return customer personal data, unless retention is required by law, contract, backup, security, accounting, or legitimate dispute resolution needs.

Backup copies may remain for a limited period until overwritten or deleted according to normal backup cycles.


12. Audit and information rights

NoonBridge will make available information reasonably necessary to demonstrate compliance with this DPA.

Where required by applicable law, and subject to reasonable confidentiality, security, scope, timing, and cost controls, NoonBridge will allow audits or inspections by the Customer or an independent auditor agreed by the parties.

Audits must not compromise the security, confidentiality, or availability of NoonBridge systems or other customers’ data.


13. No public model training

Unless expressly agreed in writing, NoonBridge will not use customer report data to train public or general-purpose AI models.

If third-party AI, OCR, or automation providers are used, NoonBridge will use reasonable efforts to select settings, terms, or providers that restrict unauthorised training or secondary use of customer report data.


14. Contact

NoonBridge / Bobook Limited
Registered office: Venture Hub, 136 Capel Street, Dublin 1, Dublin, D01 T2C9, Ireland
Company number: 785764
Email: privacy@noonbridge.net