Data Processing Agreement
Last updated: 27 August 2026
Handover is operated by Helmwise (Pty) Ltd.
1. Introduction
This Data Processing Agreement (“DPA”) governs how Helmwise (Pty) Ltd (“Helmwise”, “we”, “us”) processes personal data on behalf of the data controller (the vessel or organisation using Handover). This DPA supplements our Terms of Service and Privacy Policy and forms part of the agreement between Helmwise and the controller.
Where there is any conflict between this DPA and the Terms of Service or Privacy Policy, this DPA shall take precedence in relation to data processing matters.
2. Definitions
- Controller — the customer (vessel administrator or organisation) that determines the purposes and means of processing personal data through the Handover service.
- Processor — Helmwise (Pty) Ltd, which processes personal data on behalf of the controller.
- Data Subject — crew members, users, and any individual whose personal data is processed through the Handover service.
- Personal Data — any information relating to an identified or identifiable natural person, including names, email addresses, voice recordings, uploaded images or screenshots, and capture content.
- Processing — any operation performed on personal data, including collection, storage, transcription, classification, image and document analysis, report generation, and deletion.
- Sub-processor — a third-party service provider engaged by Helmwise to process personal data on behalf of the controller.
3. Scope and Purpose
Helmwise processes personal data solely to provide the Handover service. This includes voice-to-text transcription, AI classification of captures, AI-assisted document and image extraction for library workflows, storage of photo attachments on ordinary captures, handover report generation, and transactional email delivery. In the current library image-import workflows, user-submitted images are processed transiently to extract structured details and are not retained by Helmwise as standalone stored image files after extraction. Where the optional WhatsApp Capture feature is enabled, Helmwise also processes inbound WhatsApp messages (text, voice notes, or images) sent from phone numbers a user has connected, in order to create captures. We do not process personal data for any purpose beyond what is strictly necessary to deliver the service.
The categories of personal data processed include account information (name, email, role), capture content (voice transcriptions, text notes), stored photo attachments, uploaded documents and images that a user submits for extraction, vessel and rotation data, pseudonymous product analytics, and handover report content.
4. Controller Obligations
The controller is responsible for:
- Determining what personal data is captured and processed through the Handover service.
- Ensuring a valid legal basis exists for all processing activities (such as consent, legitimate interest, or contractual necessity).
- Informing data subjects about the processing of their personal data, including the involvement of Helmwise as a processor.
- Ensuring that any instructions given to Helmwise regarding processing comply with applicable data protection laws.
- Ensuring users have the authority, consent, or other lawful basis needed before submitting personal data about crew, guests, suppliers, or other third parties, including through WhatsApp messages, voice notes, images, and uploaded documents.
5. Processor Obligations
Helmwise undertakes to:
- Process personal data only on the documented instructions of the controller, unless required by law to do otherwise.
- Implement appropriate technical and organisational security measures to protect personal data against unauthorised access, loss, or destruction.
- Ensure that all personnel with access to personal data are bound by confidentiality obligations.
- Assist the controller in fulfilling its obligations to respond to data subject requests (access, rectification, erasure, portability).
- Assist the controller with data protection impact assessments and prior consultations with supervisory authorities where required.
- Make available to the controller all information necessary to demonstrate compliance with this DPA.
6. Sub-processors
Helmwise uses the following sub-processors to deliver the Handover service. Each sub-processor has been assessed for adequate data protection practices.
| Name | Purpose | Location |
|---|---|---|
| Supabase (Supabase Inc.) | Database, authentication, file storage | AWS (US/EU) |
| Deepgram (Deepgram Inc.) | Voice-to-text transcription | US |
| OpenAI (OpenAI LLC) | Voice-to-text transcription, text classification, summaries, document structure extraction, image understanding for optional WhatsApp Capture, and transient image-based OCR/import workflows | US |
| Resend (Resend Inc.) | Transactional email delivery | US |
| Twilio (Twilio Inc.) | WhatsApp message transport, inbound and outbound (optional WhatsApp Capture feature) | US |
| Vercel (Vercel Inc.) | Web application hosting | Global edge |
| PostHog (PostHog Inc.) | Pseudonymous signed-in product analytics and anonymous pre-signup analytics | US |
Helmwise will notify the controller by email before engaging any new sub-processor. The controller may object to a new sub-processor within 30 days of notification. If no objection is raised within that period, the sub-processor is deemed approved.
The optional WhatsApp Capture feature relies on the WhatsApp messaging network, which is operated by Meta Platforms, Inc. Meta is not a Helmwise sub-processor: where data subjects use WhatsApp, their relationship with WhatsApp and Meta is governed by Meta's own terms and privacy policy. Helmwise receives only the messages a connected user chooses to send to the Handover WhatsApp number, via Twilio.
7. Crew Privacy Commitment
Crew privacy is a founding principle of Handover. Helmwise limits the use of crew identity to providing, securing, supporting, and improving the service, and commits to the following:
- No individual performance tracking or profiling of crew members.
- Signed-in product activity may be linked to a stable, pseudonymous account identifier. Analytics are not used to score individual crew performance or productivity.
- Vessel administrators see crew names only for the purpose of handover coordination and operational continuity.
- Crew data is never sold, shared with third parties for marketing, or used for purposes unrelated to the Handover service.
8. Data Security
Helmwise implements and maintains appropriate technical and organisational measures to ensure the security of personal data, including:
- Encryption in transit via TLS for all data transmitted between clients, servers, and sub-processors.
- Encryption at rest for all data stored in Supabase (AWS infrastructure).
- Row-level security policies ensuring data isolation per vessel — crew can only access data belonging to their own vessel.
- Access controls limiting personnel access to personal data on a need-to-know basis.
- Regular security reviews of infrastructure, sub-processors, and access controls.
9. Data Breach Notification
In the event of a personal data breach, Helmwise will notify the controller without undue delay and in any event within 72 hours of becoming aware of the breach. The notification will include:
- The nature of the breach, including the categories and approximate number of data subjects affected.
- The categories of personal data affected.
- The measures taken or proposed to address the breach, including measures to mitigate its effects.
- Recommended actions the controller should take to protect affected data subjects.
Helmwise will cooperate with the controller and provide all reasonable assistance in investigating and remediating the breach.
10. Data Subject Rights
Helmwise will assist the controller in responding to requests from data subjects exercising their rights under applicable data protection laws, including the right of access, rectification, erasure, restriction of processing, data portability, and objection.
Helmwise will respond to controller requests for assistance within 30 days. Where a data subject contacts Helmwise directly, we will promptly redirect the request to the relevant controller.
11. Data Retention and Deletion
- Personal data is retained for as long as the controller's account remains active and the service is in use.
- Voice recordings are ephemeral — audio files are processed for transcription and immediately deleted. Raw audio is never retained.
- Photo attachments are retained with their captures. Archiving a capture retains its photos. Removing a photo or permanently deleting its capture removes it from normal product access; eligible unreferenced files are then handled by protected storage cleanup, subject to shared-file checks, backup rotation, and any manual review required for older files.
- Upon account closure or controller request, personal data associated with the controller's account will be deleted from active Handover systems within 30 days, except where retention is required or permitted by applicable law, billing records, security logs, backup rotation, or the establishment, exercise, or defence of legal claims.
- Where relevant, Helmwise will instruct or request deletion by applicable sub-processors in accordance with their data processing terms and retention schedules.
- Deletion from active Handover systems will be confirmed to the controller in writing upon completion.
12. International Transfers
Personal data may be processed outside of the Republic of South Africa by sub-processors listed in Section 6. Helmwise ensures that appropriate safeguards are maintained for all international transfers, including contractual obligations with sub-processors that provide an adequate level of data protection.
By using the Handover service, the controller acknowledges and consents to these international transfers as necessary for the provision of the service.
13. Term and Termination
This DPA is effective for the duration of the controller's use of the Handover service and remains in force for as long as Helmwise processes personal data on behalf of the controller.
The obligations in this DPA survive termination of the service agreement for any personal data still held by Helmwise. Upon termination, all personal data will be deleted in accordance with the retention policy set out in Section 11.
For questions about this DPA, contact our Information Officer, Charl Dettmer, at hello@thehandover.app.
Governing Law
This DPA is governed by the laws of the Republic of South Africa, including the Protection of Personal Information Act, 2013 (POPIA). Any disputes arising from this DPA shall be subject to the exclusive jurisdiction of the South African courts.