This statement describes which personal data SeaData processes, why, for how long and with whom. SeaData is a business platform: the data we process almost always relates to someone acting in a professional capacity.
SeaData has no data protection officer; this is not required for an organisation of this size. Questions about your data can be sent to the email address above.
| Data | Purpose | Legal basis |
|---|---|---|
| Email address | Login, account verification, messages about your account | Performance of the contract |
| Password (stored hashed) | Securing access to your account | Performance of the contract |
| Name, company or vessel name, role, country, telephone | Contacting you and establishing that use is professional | Performance of the contract |
| Type of use, sailing area, remarks | Understanding how the platform is used | Legitimate interest |
| API key | Giving your onboard software access | Performance of the contract |
| IP address at registration | Preventing abuse and mass registration | Legitimate interest |
| Requested positions (lat/lon with timestamp) | Calculating the requested data and detecting misuse of your key | Performance of the contract and legitimate interest |
| Usage data: number of calls, time, duration | Keeping the platform running and reliable | Legitimate interest |
When your onboard software requests data, we pass the requested position to the external sources that provide the calculation. No name, email address or key is sent along: those sources see a position, not who is behind it.
We do store the requested positions on our side, linked to your account. This is necessary to detect whether your key is being used by several vessels at once.
SeaData automatically checks whether consecutive positions from your key are physically achievable. If a position jumps further than a vessel could sail in that time, this indicates shared use of the key and the request may be refused.
This check is automated, but we do not base a decision affecting your account solely on it. If your access is restricted you may contest this at mail@seadata.online and a human will review the case. You have this right under Article 22 GDPR.
| Data | Retention |
|---|---|
| Account data | As long as your account exists. After 12 months without use we may terminate the account; you will be notified first. |
| Usage data (calls, duration) | 90 days, then deleted automatically |
| Requested positions | As long as your account exists. We are working towards a shorter period and will update this statement once it is in place. |
If you want your data removed sooner, request deletion of your account. We will then erase everything we are not legally required to keep.
We do not sell your data and do not use it for advertising. We share it only where necessary to operate the platform:
You have the right to access, correct or delete your data, to restrict processing, to object to processing based on legitimate interest, and to receive your data in a commonly used format.
Send your request to mail@seadata.online. We respond within one month. If you disagree with the outcome you may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Passwords are stored hashed and are not readable by us. Traffic to the platform runs over a secure connection. Your API key grants access to your account: treat it like a password and do not share it.
We update this statement when the way we process data changes. The version and date are shown at the bottom. For significant changes we will notify you at your account's email address.