Legal
Privacy Policy
This policy explains how Omnivessel LLC collects, uses, shares and protects personal data in connection with the OmniVessel Vessel Inspection Suite (VIS). We are committed to processing personal data lawfully, fairly and transparently, in line with the EU General Data Protection Regulation (GDPR) and equivalent data-protection laws.
Effective 4 July 2026 · Applies to OmniVessel Vessel Inspection Suite (VIS)
01Introduction
Omnivessel LLC (“Omnivessel”, “we”, “us”), a company registered in Georgia, develops, owns and operates the OmniVessel Vessel Inspection Suite, a software-as-a-service platform used by shipmanagement companies to run their vessel-inspection programmes.
This policy applies to personal data we process through the Platform, our website and our support channels. It should be read together with our Terms of Use.
02Controller & processor roles
The Platform is a B2B service, so two distinct relationships apply:
- For personal data that a customer (a shipmanagement company) submits to run its inspection programme - such as records about its office staff and crew - the customer is the data controller and Omnivessel acts as a data processor, processing that data on the customer’s documented instructions.
- For data we determine the purpose of ourselves - such as account administration, billing, security, and improving the Platform - Omnivessel acts as the data controller.
Where we act as a processor, our processing is also governed by a data processing agreement (DPA) with the customer. If you are an individual whose data was entered by your employer, please direct data-subject requests to your employer as controller in the first instance; we will support them in responding.
03Data we process
Account & identity data
Name, work email address, role (admin, office, crew or office staff), organisation and vessel assignment, hashed credentials, two-factor and trusted-device information, and account preferences.
Operational data
Vessel and fleet details (including IMO numbers), inspection checklists and answers, comments, scheduling data, key performance indicators, reports, evidence attachments you upload, and support tickets and messages.
Technical & security data
Authentication and session information, audit-log entries (an append-only, hash-chained record of significant actions), and limited technical metadata needed to operate and secure the service.
We ask that customers avoid entering special categories of personal data into free-text fields unless strictly necessary and lawful.
04Purposes & legal bases
Under the GDPR, we rely on the following legal bases:
- Contract (Art. 6(1)(b)) - to provide the Platform, administer accounts, and deliver support.
- Legitimate interests (Art. 6(1)(f)) - to secure the Platform, prevent abuse, maintain audit logs, and improve and develop the service, balanced against your rights.
- Legal obligation (Art. 6(1)(c)) - to comply with applicable law, including retention and tax requirements.
- Consent (Art. 6(1)(a)) - where we ask for it, for example enabling the optional AI assistant. Consent can be withdrawn at any time.
Where Omnivessel acts as a processor, the legal basis for the underlying processing is determined by the customer as controller.
05AI assistant
The Platform includes an optional AI assistant. It is off by default and requires explicit data-processing consent before it can be enabled, plus a per-vessel opt-in for crew use. When enabled, relevant context is sent to an AI provider solely to generate responses, through server-side calls with guardrails and context isolation; the provider identity is managed by us and never exposed to customer users.
If you do not enable the assistant, no data is sent to any AI provider. You can withdraw consent and disable the assistant at any time.
07Subprocessors
We use a small number of trusted subprocessors to run the Platform. The current categories are:
- Cloud database & authentication - hosting of the application database and user authentication.
- Application hosting - hosting and delivery of the web application.
- Email delivery - transactional emails such as one-time codes, inspection notifications and temporary passwords.
- Mapping & vessel data - fleet-map rendering and vessel-position / IMO lookup (only when those features are used).
- AI provider - only where the AI assistant is enabled by the customer.
Each subprocessor is bound by appropriate data-protection terms. A current list of specific subprocessors is available on request at info@omnivessel.io.
08International transfers
The Platform’s primary infrastructure is hosted in the European Union (EU-West region). Where personal data is transferred outside the European Economic Area - for example to a subprocessor - we rely on an appropriate transfer mechanism, such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where needed.
09Data retention
We retain personal data for as long as needed to provide the Platform and for legitimate, lawful purposes thereafter. Unless a longer or shorter period is set out in our agreement with the relevant customer, we retain Customer Data for a minimum of three (3) years, or for the duration of the customer’s subscription if longer. After the applicable retention period, or on termination, Customer Data is made available for export for a limited period and then deleted or anonymised, except where longer retention is required by law. Audit logs are retained as an integrity record for a period consistent with their security purpose and the retention terms above.
10Security
We implement technical and organisational measures appropriate to the risk, including:
- encryption of data in transit;
- row-level access controls and a privileged, server-only access path for administrative operations;
- two-factor authentication, single active session per account, and strong-password enforcement;
- an immutable, hash-chained audit log and a strict content-security policy;
- least-privilege handling of secrets and service keys.
No system can be guaranteed perfectly secure, but we work to protect personal data and to respond promptly to incidents. We will notify affected controllers of a personal-data breach without undue delay as required by the GDPR.
11Your GDPR rights
Subject to conditions and exemptions under applicable law, you have the right to:
- access the personal data we hold about you;
- request correction of inaccurate or incomplete data;
- request erasure (“right to be forgotten”);
- restrict or object to certain processing;
- data portability;
- withdraw consent where processing is based on consent; and
- lodge a complaint with your local data-protection supervisory authority.
Where we process your data on behalf of your employer (as processor), we will forward your request to the relevant controller and assist them in responding. To exercise your rights, contact us at info@omnivessel.io.
12Children
The Platform is a professional tool intended for use by adults in a work context. It is not directed to children and we do not knowingly process children’s personal data.
13Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, notify you through the Platform. We encourage you to review this page periodically.
14Contact
For privacy questions or to exercise your rights, contact the data controller, Omnivessel LLC:
- Email: info@omnivessel.io
- Telephone: +995 555 965 050
- Web: www.omnivessel.io
© 2026 Omnivessel LLC. All rights reserved. The OmniVessel Vessel Inspection Suite is developed, owned and copyrighted by Omnivessel LLC.