Privacy policy
What this site records, what you send us when you ask for a quotation, why each is held, and how long it lasts.
Draft — not legal advice. This page was drafted for review and has not been approved by counsel. It must be reviewed before this site is opened to search engines.
Who we are, and who controls the data
ShipCertify is a Seaway Group company. The controller for the personal data collected through this site is the operating entity, Ekinek Tarım Gıda ve Denizcilik Ltd Şti, registered at the Karşıyaka tax office under tax number 329 120 5309: it runs the quote form, it decides why the data are collected and what is done with them, and it answers for them. There is a United Kingdom registered office at Office 7408, 58 Peregrine Road, Hainault, Ilford, Essex IG6 3SZ, and a written request may be sent there instead — it reaches the same people and is answered on the same clock. Anything arising from this page goes to compliance@shipcertify.com, or to info@shipcertify.com if you would rather use the general mailbox; whichever route it arrives by, it is acknowledged within five working days.
What the quote form collects
What you type into the quote form, and nothing else about you. About the vessel: its name and IMO number, and where you give them its flag, type and gross tonnage. About the call: the port and UN/LOCODE, whether the vessel will be at a berth, at anchorage, in a shipyard or in dry dock, the ETA and ETD, and how urgent the work is. About the work: the service lines you need, whether parts are required, equipment makes, models and serial numbers, the due date of an expiring certificate, and anything you write in the free-text field. About you: your name, company, email address, telephone number and which channel you would rather we reply on. If you give us the ship’s agent’s name and contact details we hold those too, and use them only to arrange the attendance — if you are that agent and did not give us your details yourself, the rights below apply to you in the same way. We build no visitor profile, we do not fingerprint your browser, and we set no advertising cookie.
IP addresses, the access log and the rate limiter
An IP address is personal data, and this site processes one in two places. The nginx access log records the address that made each request, the time, the page requested, the response code and the browser’s user-agent string; without that log a server cannot be diagnosed when it fails or defended when it is attacked. It is rotated every night, compressed the following day, and deleted ten days after it is written — long enough to trace an incident back through a week of traffic, short enough that no address sits on the server beyond that. Nothing is copied off the server, and no address in it is joined to an enquiry, to a name, or to any other log. The quote form counts submissions separately — at most five in ten minutes from one address, and three in an hour from one email address — so that a script cannot flood the coordinators’ mailbox; those counters sit in the memory of the running process, are never written to disk, and are gone when the window closes or the service restarts. The address is not truncated, it is not stored alongside your enquiry, and it is not used to identify you or to build a profile. The form also carries a hidden field that must stay empty and the time the page was rendered, both of which exist only to reject automated posts.
Why we may hold it
For a quote request the lawful basis is the steps taken at your request before entering into a contract, and our legitimate interest in answering a business enquiry; your explicit consent is recorded at the point of submission as well, which is why the box is never pre-ticked. For the access log and the rate limiter the basis is legitimate interest alone — keeping the site available and keeping automated submissions out of the coordinators’ mailbox — and you are not asked to consent to it, because it cannot be switched off and still serve a page. A contact who asks for a quotation is not added to a mailing list, a newsletter or an automated reminder schedule: the only email that follows is about the enquiry you raised and any order that comes out of it. We do not sell or rent a contact detail, and we do not pass one to another company for that company’s own marketing. If we ever offer certificate expiry reminders they will be asked for separately, in plain words, recorded with the date the consent was given, and stopped by a single reply.
Who else touches it
These are the only third parties that touch it.
Namecheap Private Email, which carries the notification to us and the acknowledgement to you.
Our own server, hosted with IONOS in London, which serves this site.
There is no analytics provider, no tag manager, and no third-party script on any page of this site.
How long we keep it
A quote request and the correspondence that follows it live in the coordinators’ email, and nowhere else on this site. An enquiry that never becomes an order is deleted twenty-four months after the last message in the thread — long enough for the same vessel to call twice and for you to ask us to quote against the earlier scope, short enough that nothing is held on the chance that it may one day be useful. Where an order is placed, the correspondence becomes part of the job record and is kept for ten years from the end of the financial year in which the work was invoiced, because the commercial books and the documents supporting them have to be kept that long. A submission the rate limiter refuses is never stored at all. If you ask us to erase an enquiry before its period ends we do it within thirty days and confirm it in writing, unless an order was placed and the record has to be kept to satisfy tax or accounting law — in which case we tell you so, and tell you the date it goes.
Where it goes, and who else may read it
The server is in London. Coordinators work from six service bases — İstanbul, İzmir and İskenderun in Türkiye, Varna in Bulgaria, Constanța in Romania, and London — so an enquiry may be read outside the United Kingdom and the EEA, and in particular in Türkiye. Türkiye is covered by neither a European Commission adequacy decision nor United Kingdom adequacy regulations, so a transfer there rests on a safeguard rather than on adequacy: the standard contractual clauses, in the European Commission’s form for data falling under EU GDPR and with the United Kingdom addendum for data falling under UK GDPR, supported by a transfer risk assessment that the operations director accountable for compliance reviews once a year. Where a port has no ShipCertify base, an attendance may be delivered through a partner company; if your enquiry is passed to one, the vessel, the port, the scope and a contact for the ship go with it, because nobody can attend without them — and nothing else goes with it. No partner is sent an enquiry before a written agreement is signed that confines them to that attendance, imposes the same safeguards on any onward transfer, forbids any other use of the contact details, and requires the data to be returned or destroyed when the job closes. A copy of the safeguards relied on for a particular transfer is supplied on request to compliance@shipcertify.com within thirty days, with commercial terms redacted.
Turkish Law No. 6698 (KVKK)
Because the operating entity is established in Türkiye, Law No. 6698 on the Protection of Personal Data applies to this processing alongside UK GDPR and EU GDPR; the three overlap but they are not one regime, and a right under one is not automatically a right under another. Under Article 11 you may learn whether your personal data are processed, request information if they are, learn the purpose and whether they are used in line with it, know the third parties in Türkiye and abroad to whom they are transferred, have incomplete or inaccurate data corrected and that correction notified to those third parties, request erasure or destruction under Article 7 and notification of that as well, object to a result reached about you by exclusively automated analysis, and claim compensation for damage caused by unlawful processing. An application is made to us first, in writing — to compliance@shipcertify.com, or to the registered office address in the contact section below — and is answered within thirty days at the latest. If it is refused, answered inadequately, or not answered in time, a complaint may be made to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu), the decision-making organ of the Personal Data Protection Authority — within thirty days of learning our answer, and in any event within sixty days of the date of the application. Which of the three regimes leads for a given request follows from the controller named at the top of this page.
Representatives in the EU and the UK
Article 27 of the EU GDPR requires a controller established outside the Union that offers services to people in the Union to designate a representative there in writing, and the UK GDPR imposes the same duty for the United Kingdom. Neither duty falls on us, and the reason is where we work from. We have service bases in Varna, in Bulgaria, and in Constanța, in Romania — establishments in the Union — and a registered office and a service base in London. Processing carried out in the context of those establishments is caught by Article 3(1) of each regulation, the ground that applies to a controller established in the territory, while Article 27 addresses only the controller caught instead by Article 3(2). So there is no representative to name and none is needed: a request from the Union or from the United Kingdom is handled by us directly, at the contact below, on the periods set out above.
The customer portal is a separate system
portal.shipcertify.com is a different application on a different host name, with its own database, its own credentials, its own legal basis and its own privacy notice; this notice does not cover it and its notice does not cover this site. A quote request submitted here is never written to it — the public site has no route into that database at all. Asking for a quotation therefore does not create a portal account. If you are given portal access, that is a separate step, with its own terms and its own consent, and you would be told about it at the time.
How it is protected
The site is served only over TLS, on a certificate that renews automatically, and plain HTTP is redirected to it. The public application is deployed with no database connection string and no portal credential, so a compromise of this web server reaches no customer records: there are none on it. It does hold one signed-session secret, used for a single administrative sign-in by which our own staff manage the photographs on this site; that sign-in touches no enquiry. A quote request goes to the role mailboxes that have to answer it and is not circulated beyond the coordinators and documentation staff working on it. Those mailboxes are opened only through named individual accounts — there is no shared password and no generic login — access is granted by an operations director, two-factor authentication is enforced on every account that can reach them, the list of who holds access is reviewed every six months, and an account is closed on the day the person leaves. A personal data breach affecting this site would be reported to the competent supervisory authority without undue delay and, where feasible, within seventy-two hours of our becoming aware of it, where the breach is likely to result in a risk to you, and to you directly where that risk is high. Which authority is competent follows from the controller named at the top of this page.
No automated decision-making
There is no profiling on this site, and no automated decision that produces a legal effect for you or similarly significantly affects you. Every quotation is priced by a person and every attendance is planned by a person. The only automated control is the rate limiter described above: it counts submissions from an address over a short window and decides nothing about you, only whether the next submission inside that window is accepted. A submission it refuses can be sent again once the window closes, or given to the hotline straight away. Before a quotation is given, the vessel, its ownership and the counterparty raising the order are screened against sanctions lists, as the sanctions notice on this site sets out. That check can produce a refusal to quote. The list match is automated; the decision is not — a person reviews every match and every refusal, and no refusal is issued by a machine.
Your rights, and how to use them
Under UK and EU GDPR you may ask for a copy of what we hold about you, have it corrected, ask for it to be erased, ask us to restrict or stop processing it, ask for it in a portable form, and withdraw a consent you gave — withdrawal does not make what came before it unlawful. Write to the contact below and we will answer within one month of receiving the request, and tell you inside that month if the request is complex enough to need longer. We may ask you to confirm your identity first; what you send for that is used for nothing else, and for a request under UK or EU GDPR there is no charge unless the request is manifestly unfounded or excessive. Under Law No. 6698 a fee within the tariff set by the Board may be charged. If you are not satisfied you may complain to the Information Commissioner’s Office in the United Kingdom, to the supervisory authority of your own country in the EEA, or by the Turkish route set out above.
Contacting us
Data protection requests go to compliance@shipcertify.com; general enquiries to info@shipcertify.com. The compliance mailbox is read by the documentation staff every working day and answered under the authority of the operations director accountable for compliance, who holds that responsibility as part of the role. A request is acknowledged within five working days and answered inside the periods set out above. A written application — including an application under Law No. 6698, which has to be made in writing — may be sent to the United Kingdom registered office at Office 7408, 58 Peregrine Road, Hainault, Ilford, Essex IG6 3SZ, marked for the attention of the operations director accountable for compliance. No data protection officer is designated under Article 37 of the GDPR: we are not a public authority, this site’s processing involves no regular and systematic monitoring of people on a large scale, and it involves no special category data at all, so the appointment is not required — the accountability sits with the role named above rather than being left unowned. The telephone numbers for each base, and the 24/7 hotline, are on the contact page.
Last updated: