01Who is responsible for your data
Digi Creative SIA, trading as MicroShipowner, is the controller of the personal data described on this page. We are registered in Latvia under Reg. No. LV41203061418, at Krasta 8C, Iecava, LV-3913.
For anything on this page — including a request to see, correct or delete your data — write to welcome@maritimedao.com. A person reads that address.
We have not appointed a Data Protection Officer. Our processing does not meet the criteria in Article 37 of the GDPR that would require one.
02What we collect, and why
We collect three kinds of personal data, and nothing else.
When you ask for a pilot
The form on our home page asks for your company, your name, your email address, an optional telephone number, the vessel name or IMO number, the flag, the GT band and how many ships you run, plus anything you choose to write in the message field.
We use it to prepare and quote a baseline inspection and to reply to you. The lawful basis is Article 6(1)(b) of the GDPR — steps taken at your request before entering into a contract. We do not add you to a mailing list, and we do not pass the request to anyone else.
When you use the system on board or ashore
Accounts are issued by name to the people who need one — typically the Master, the Chief Engineer and the Designated Person Ashore. For those accounts we hold a username, a hashed password, a role, and the record of what that person filed, signed or acknowledged.
A safety management system is only evidence if entries are attributable to a person, so this data is inseparable from the service. The lawful basis is Article 6(1)(b) — performance of our contract with your company — and, for the records your flag state or the ISM Code requires you to keep, Article 6(1)(c), compliance with a legal obligation.
Crew records entered by your company — crew lists, contracts of employment, rest hours, certificates and their expiry dates — are processed by us on your company's behalf. For that data your company is the controller and we are the processor, under a written agreement.
When you simply visit the site
Our web server keeps a short technical log of requests: IP address, time, the page requested, and the browser's user-agent string. We use it to keep the site available and to investigate abuse. The lawful basis is Article 6(1)(f), our legitimate interest in operating a secure service.
This site sets no advertising or analytics cookies. There is no tracking pixel, no advertising network and no visitor analytics. The only cookie the site can set is the session cookie that keeps you signed in after you use the login page, and it is strictly necessary for that purpose.
03Who else sees it
We do not sell personal data and we do not share it for anyone else's marketing.
We disclose data to a public authority only where the law requires it — for example a flag state, a Port State Control officer or a court acting within its powers.
04Where it is kept
Personal data is stored inside the European Economic Area.
The one routine exception is Google Fonts, described above. Where any transfer outside the EEA becomes necessary, we rely on an adequacy decision or on the European Commission's standard contractual clauses, and we will say so here.
05How long we keep it
06Your rights
Under the GDPR you may ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or provide it in a portable form. You may object to processing we carry out on the basis of legitimate interest.
Two honest limits. Where a record forms part of a safety management system or a statutory record, we may be unable to delete it while the retention obligation runs — we will tell you which obligation and when it ends. And where your employer is the controller of the data, we will pass your request to them rather than act on it ourselves.
We answer within one month. There is no charge.
If you think we have handled your data badly, you can complain to the Latvian supervisory authority, Datu valsts inspekcija, Elijas iela 17, Riga, LV-1050 — www.dvi.gov.lv. We would rather you told us first.
07Security
Passwords are stored hashed, never in readable form. Access to records follows the role a person holds: crew see their vessel, shore staff see the fleet, inspectors get a scoped read-only view, and every inspector read is logged. Records in the register are append-only and hash-chained, so an entry cannot be altered after the fact without breaking the chain.
No system is perfect. If a breach is likely to result in a risk to your rights, we will notify Datu valsts inspekcija within 72 hours and tell you directly where the risk is high.
08Changes to this notice
If we change how we handle personal data, we will publish the new version here with a new version number and date, and — where the change matters to you — tell you by email before it takes effect.
MicroShipowner