Πολιτική απορρήτου
Τι συλλέγουμε όταν χρησιμοποιείτε τον ιστότοπο αυτόν, για ποιον λόγο και ποιος άλλος έχει πρόσβαση σε αυτά.
Σχέδιο — δεν αποτελεί νομική συμβουλή. Η παρούσα σελίδα συντάχθηκε προς έλεγχο και δεν έχει εγκριθεί από νομικό σύμβουλο. Πρέπει να ελεγχθεί προτού ο ιστότοπος αυτός ανοίξει στις μηχανές αναζήτησης.
Ποιοι είμαστε
Η ShipCertify είναι εταιρεία του Seaway Group. Η νομική οντότητα, η καταστατική έδρα και ο αριθμός μητρώου της εκκρεμούν και θα αναφερθούν εδώ πριν από τη δημοσίευση. Ερωτήματα: info@shipcertify.com.
Τι συλλέγουμε
Μόνο ό,τι συμπληρώνετε στη φόρμα αιτήματος προσφοράς: όνομα πλοίου και αριθμό IMO, λιμάνι και ημερομηνίες, το αντικείμενο των εργασιών που χρειάζεστε, καθώς και το ονοματεπώνυμό σας, την εταιρεία, το email και το τηλέφωνό σας. Δεν δημιουργούμε προφίλ επισκέπτη, δεν καταγράφουμε ψηφιακό αποτύπωμα του προγράμματος περιήγησής σας και δεν εγκαθιστούμε διαφημιστικά cookies.
IP addresses, the access log and the rate limiter
An IP address is personal data, and this site processes one in two places. The nginx access log records the address that made each request, the time, the page requested, the response code and the browser’s user-agent string; without that log a server cannot be diagnosed when it fails or defended when it is attacked. It is rotated every night, compressed the following day, and deleted ten days after it is written — long enough to trace an incident back through a week of traffic, short enough that no address sits on the server beyond that. Nothing is copied off the server, and no address in it is joined to an enquiry, to a name, or to any other log. The quote form counts submissions separately — at most five in ten minutes from one address, and three in an hour from one email address — so that a script cannot flood the coordinators’ mailbox; those counters sit in the memory of the running process, are never written to disk, and are gone when the window closes or the service restarts. The address is not truncated, it is not stored alongside your enquiry, and it is not used to identify you or to build a profile. The form also carries a hidden field that must stay empty and the time the page was rendered, both of which exist only to reject automated posts.
Γιατί μπορεί να τα χρησιμοποιήσουμε
Για ένα αίτημα προσφοράς, η νόμιμη βάση είναι οι ενέργειες που πραγματοποιούνται κατόπιν αιτήματός σας πριν από τη σύναψη σύμβασης, καθώς και το έννομο συμφέρον μας να απαντήσουμε σε επιχειρηματικό αίτημα. Κατά την υποβολή καταγράφεται επίσης η ρητή συγκατάθεσή σας — γι' αυτό το πεδίο επιλογής δεν είναι ποτέ προεπιλεγμένο.
Ποιος άλλος έχει πρόσβαση
Αυτοί είναι οι μόνοι εκτελούντες την επεξεργασία, οι μόνοι τρίτοι που έρχονται σε επαφή με τα δεδομένα αυτά.
Namecheap Private Email, που μεταφέρει την ειδοποίηση σε εμάς και την επιβεβαίωση παραλαβής σε εσάς.
Ο δικός μας διακομιστής, που φιλοξενείται στην IONOS στο Λονδίνο και εξυπηρετεί τον παρόντα ιστότοπο.
Δεν υπάρχει πάροχος αναλυτικών στοιχείων, ούτε σύστημα διαχείρισης ετικετών (tag manager), ούτε σενάριο τρίτου μέρους σε καμία σελίδα του παρόντος ιστοτόπου.
Για πόσο διάστημα τα διατηρούμε
Ένα αίτημα προσφοράς παραμένει στο ηλεκτρονικό ταχυδρομείο των συντονιστών μας, υπό τον συνήθη χρόνο διατήρησης της εμπορικής μας αλληλογραφίας. Ο ιστότοπος αυτός δεν διαθέτει βάση δεδομένων — η υποβολή σας δεν καταχωρείται σε κάποια εδώ.
Πού διαβιβάζονται
Ο διακομιστής μας βρίσκεται στο Λονδίνο. Οι συντονιστές μας εργάζονται από βάσεις εξυπηρέτησης στην Τουρκία, τη Βουλγαρία, τη Ρουμανία και το Ηνωμένο Βασίλειο, οπότε ένα αίτημα μπορεί να αναγνωστεί εκτός του Ηνωμένου Βασιλείου και του ΕΟΧ. Οι διαβιβάσεις προς το εξωτερικό πραγματοποιούνται με τις κατάλληλες εγγυήσεις για την εκάστοτε χώρα.
Turkish Law No. 6698 (KVKK)
Because the operating entity is established in Türkiye, Law No. 6698 on the Protection of Personal Data applies to this processing alongside UK GDPR and EU GDPR; the three overlap but they are not one regime, and a right under one is not automatically a right under another. Under Article 11 you may learn whether your personal data are processed, request information if they are, learn the purpose and whether they are used in line with it, know the third parties in Türkiye and abroad to whom they are transferred, have incomplete or inaccurate data corrected and that correction notified to those third parties, request erasure or destruction under Article 7 and notification of that as well, object to a result reached about you by exclusively automated analysis, and claim compensation for damage caused by unlawful processing. An application is made to us first, in writing — to compliance@shipcertify.com, or to the registered office address in the contact section below — and is answered within thirty days at the latest. If it is refused, answered inadequately, or not answered in time, a complaint may be made to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu), the decision-making organ of the Personal Data Protection Authority — within thirty days of learning our answer, and in any event within sixty days of the date of the application. Which of the three regimes leads for a given request follows from the controller named at the top of this page.
Representatives in the EU and the UK
Article 27 of the EU GDPR requires a controller established outside the Union that offers services to people in the Union to designate a representative there in writing, and the UK GDPR imposes the same duty for the United Kingdom. Neither duty falls on us, and the reason is where we work from. We have service bases in Varna, in Bulgaria, and in Constanța, in Romania — establishments in the Union — and a registered office and a service base in London. Processing carried out in the context of those establishments is caught by Article 3(1) of each regulation, the ground that applies to a controller established in the territory, while Article 27 addresses only the controller caught instead by Article 3(2). So there is no representative to name and none is needed: a request from the Union or from the United Kingdom is handled by us directly, at the contact below, on the periods set out above.
The customer portal is a separate system
portal.shipcertify.com is a different application on a different host name, with its own database, its own credentials, its own legal basis and its own privacy notice; this notice does not cover it and its notice does not cover this site. A quote request submitted here is never written to it — the public site has no route into that database at all. Asking for a quotation therefore does not create a portal account. If you are given portal access, that is a separate step, with its own terms and its own consent, and you would be told about it at the time.
How it is protected
The site is served only over TLS, on a certificate that renews automatically, and plain HTTP is redirected to it. The public application is deployed with no database connection string and no portal credential, so a compromise of this web server reaches no customer records: there are none on it. It does hold one signed-session secret, used for a single administrative sign-in by which our own staff manage the photographs on this site; that sign-in touches no enquiry. A quote request goes to the role mailboxes that have to answer it and is not circulated beyond the coordinators and documentation staff working on it. Those mailboxes are opened only through named individual accounts — there is no shared password and no generic login — access is granted by an operations director, two-factor authentication is enforced on every account that can reach them, the list of who holds access is reviewed every six months, and an account is closed on the day the person leaves. A personal data breach affecting this site would be reported to the competent supervisory authority without undue delay and, where feasible, within seventy-two hours of our becoming aware of it, where the breach is likely to result in a risk to you, and to you directly where that risk is high. Which authority is competent follows from the controller named at the top of this page.
No automated decision-making
There is no profiling on this site, and no automated decision that produces a legal effect for you or similarly significantly affects you. Every quotation is priced by a person and every attendance is planned by a person. The only automated control is the rate limiter described above: it counts submissions from an address over a short window and decides nothing about you, only whether the next submission inside that window is accepted. A submission it refuses can be sent again once the window closes, or given to the hotline straight away.
Τα δικαιώματά σας
Μπορείτε να ζητήσετε να μάθετε ποια δεδομένα σας διατηρούμε, να αιτηθείτε τη διόρθωση ή τη διαγραφή τους, να αντιταχθείτε στην επεξεργασία τους ή να ανακαλέσετε τη συγκατάθεσή σας. Γράψτε στο info@shipcertify.com και θα σας απαντήσουμε. Εάν δεν μείνετε ικανοποιημένοι, μπορείτε να υποβάλετε καταγγελία στην εθνική αρχή προστασίας δεδομένων της χώρας σας.
Επικοινωνία μαζί μας
info@shipcertify.com ή τα τηλέφωνα των γραφείων που αναφέρονται στη σελίδα επικοινωνίας. Ο ονομαστικά υπεύθυνος επικοινωνίας για θέματα προστασίας προσωπικών δεδομένων θα αναφερθεί εδώ με την έγκριση.
Τελευταία ενημέρωση: