BerthRight

Data Export and Deletion Policy

Version 1.0

Effective Date: August 24, 2026

Last Updated: August 24, 2026

1. Purpose and Scope

This Policy describes how Marina Operators (“Customer,” “you”) who use the BerthRight platform can export their data, what happens to that data after a subscription ends, and how BerthRight handles requests related to End User (boater) personal data. Berth Right MGMT LLC, a Florida limited liability company doing business as BerthRight (“BerthRight,” “we,” “us”) acts as a data processor / service provider on behalf of Customer, who is the data controller for data about Customer’s boaters and Customer’s own business (“End Users”). This Policy should be read together with the DPA, which is the controlling document for data protection terms between BerthRight and Customer.

2. Customer Data vs. BerthRight Business Records

  • “Customer Data” means data that Customer or its End Users input into, or that is generated through Customer’s use of, the Service — including but not limited to boater/customer records, vessel records, slip and storage assignments, reservations, waitlist entries, invoices and billing records, payment and transaction history, messages (email/SMS) and consent records, documents and attachments, and reports generated from the foregoing.
  • “BerthRight Business Records” means records BerthRight generates in the ordinary course of running its own business relationship with Customer — most importantly, BerthRight’s own invoices to Customer for BerthRight’s subscription fees, and BerthRight’s internal accounting, tax, and financial records related to that relationship. BerthRight Business Records are not Customer Data, are owned and retained by BerthRight for its own legal and accounting purposes, and are not subject to the export and deletion timelines in this Policy.

3. Data Export

Customer may request a full export of its own Customer Data at any time during an active subscription by writing to info@berthright.app; exports are delivered within ten (10) business days. Self-service export from the BerthRight admin console is in development and this Policy will be updated when it is available.

3.1 What Is Included

CategoryIncluded
Customers/boatersContact records, boater profiles
VesselsVessel records and specifications
ReservationsSlip reservations, transient dockage, storage, service, haul & launch, waitlist records
InvoicesAll invoices issued through the Service
Payments/transactionsTransaction history as reflected in BerthRight’s own database (see Section 8 regarding Stripe’s separately-retained records)
Messages and consentEmail and SMS message logs and consent/opt-in records
Documents/attachmentsFiles uploaded to or generated by the Service and associated with a Customer record

3.2 Format

Exports are provided in structured, machine-readable, non-proprietary formats: CSV, JSON, or a standard SQL/PostgreSQL dump, as applicable to the data type. BerthRight does not limit exports to PDF-only or proprietary formats.

4. Post-Termination Export Window

Upon termination or expiration of Customer’s subscription (for any reason), Customer’s right to request an export remains available for 30 days following the effective date of termination (the “Export Window”). During the Export Window, Customer may continue to request exports of Customer Data in the formats described in Section 3.

If Customer needs assistance completing an export, Customer may contact support@berthright.app before the Export Window closes. BerthRight will provide reasonable assistance consistent with the Support and SLA Policy’s support scope.

5. Deletion Timeline

StageTiming
Export Window closes30 days after termination
Deletion from production systemsWithin 30 days after the Export Window closes
Deletion from backups (full rotation)In line with our infrastructure provider’s backup retention configuration, following the Export Window

In other words: Customer Data is deleted from BerthRight’s live production database within 30 days of the Export Window closing, and is fully purged as encrypted backups roll off their normal retention cycle, in line with our infrastructure provider’s backup retention configuration.

6. What Is Retained, and Why

Notwithstanding Section 5, BerthRight may retain the following beyond the deletion timeline:

  1. BerthRight Business Records (Section 2) — retained per BerthRight’s own accounting/tax retention practices, independent of Customer Data deletion.
  2. Aggregated, de-identified data — data that has been stripped of identifying information and aggregated such that it no longer identifies Customer, an End User, or a specific marina, which BerthRight may retain and use for product analytics and improvement.
  3. Legal hold — data subject to a litigation hold, subpoena, government investigation, or other legal process requiring preservation.
  4. Tax/accounting retention requirements — data BerthRight is independently required to retain to comply with applicable tax, accounting, or financial recordkeeping law.
  5. Data Customer has instructed BerthRight to retain — where Customer has affirmatively requested longer retention in writing (see Section 7).

7. Public-Sector Retention Carve-Out

Some Customers are municipal, county, or port-authority-owned marinas subject to public-records retention laws that require records to be kept longer than the default deletion timeline in Section 5. Where Customer notifies BerthRight in writing that Customer is subject to such a requirement and specifies the applicable retention period, BerthRight will retain the relevant Customer Data for that longer period instead of deleting it per Section 5, and will delete it once that retention obligation has lapsed and Customer confirms deletion is appropriate.

8. End User (Boater) Data Subject Requests

BerthRight is a processor / service provider, not a controller, with respect to End User personal data. Accordingly:

  • The Marina Operator (Customer) is the controller and is responsible for receiving and deciding how to respond to requests from its own End Users (boaters) to access, correct, export, or delete their personal data.
  • BerthRight does not respond directly to End Users who contact BerthRight with such a request; BerthRight will refer the End User to their marina (Customer) and, if authorized by Customer, may notify Customer that the request was received.
  • BerthRight assists Customer in fulfilling End User data subject requests through the Service’s own tooling — Customer can look up, correct, or delete a specific End User’s record through the admin console — and through the support channels described in the Support and SLA Policy for anything the admin console doesn’t cover.
  • The specific terms governing BerthRight’s obligations as processor, including response timeframes for assisting Customer, are set out in the DPA and control over this Policy in the event of conflict.

9. Data Held by Subprocessors

BerthRight uses subprocessors to deliver parts of the Service, and some of those subprocessors independently retain certain records for their own regulatory or operational purposes, separate from BerthRight’s own systems:

  • Stripe retains payment and transaction records for its own regulatory, compliance, and fraud-prevention purposes, independent of BerthRight’s deletion timeline.
  • The SMS provider (Twilio) retains consent (opt-in/opt-out) and delivery records for a period required for A2P 10DLC compliance and carrier requirements.

BerthRight cannot compel a subprocessor to delete records that subprocessor is independently required by law or regulation to retain. Where Customer or an End User has a specific need to understand a subprocessor’s own retention practices, BerthRight can direct Customer to the relevant subprocessor’s public data retention or privacy documentation, but cannot make retention commitments on that subprocessor’s behalf.

10. Certification of Deletion

Upon written request following completion of the deletion timeline in Section 5, BerthRight will provide Customer a written certification confirming that Customer Data has been deleted from BerthRight’s production systems and has rotated out of BerthRight’s backups, subject to the retention exceptions in Sections 6, 7, and 9.

11. Offboarding Checklist (For Marina Operators)

Use this checklist when planning to end a BerthRight subscription:

  1. Before cancelling: Request a full export of all Customer Data categories (Section 3.1) in CSV/JSON/SQL format by writing to info@berthright.app (Section 3); store the export securely.
  2. Confirm public-records status: If Customer is a municipal, county, or port-authority-owned entity subject to public-records retention law, notify support@berthright.app in writing with the applicable retention period (Section 7).
  3. Flag any legal hold: If any data is subject to litigation hold or similar legal process, notify support@berthright.app in writing before termination takes effect.
  4. Terminate the subscription per the Terms of Service / MSA cancellation terms (month-to-month, no lock-in, cancel anytime).
  5. Use the 30-day Export Window to complete or re-run any exports; contact support if bulk-export assistance is needed.
  6. Reconcile billing: Confirm final BerthRight invoice; note this invoice is a BerthRight Business Record and is retained independently of Customer Data deletion.
  7. Request a Certification of Deletion, in writing, any time after the deletion timeline (Section 5) has completed.
  8. Notify End Users, if appropriate, of the change in service and where their data now resides (Customer’s responsibility as controller).

12. Changes to This Policy

BerthRight may update this Policy from time to time. Material changes that shorten the Export Window or accelerate deletion timelines will be communicated to active Customers at least 30 days before taking effect.