Legal

Privacy Policy

This policy explains how Omnivessel LLC collects, uses, shares and protects personal data in connection with the OmniVessel Vessel Inspection Suite (VIS). We are committed to processing personal data lawfully, fairly and transparently, in line with the EU General Data Protection Regulation (GDPR) and equivalent data-protection laws.

Effective 4 July 2026 · Applies to OmniVessel Vessel Inspection Suite (VIS)

01Introduction

Omnivessel LLC (“Omnivessel”, “we”, “us”), a company registered in Georgia, develops, owns and operates the OmniVessel Vessel Inspection Suite, a software-as-a-service platform used by shipmanagement companies to run their vessel-inspection programmes.

This policy applies to personal data we process through the Platform, our website and our support channels. It should be read together with our Terms of Use.

02Controller & processor roles

The Platform is a B2B service, so two distinct relationships apply:

  • For personal data that a customer (a shipmanagement company) submits to run its inspection programme - such as records about its office staff and crew - the customer is the data controller and Omnivessel acts as a data processor, processing that data on the customer’s documented instructions.
  • For data we determine the purpose of ourselves - such as account administration, billing, security, and improving the Platform - Omnivessel acts as the data controller.

Where we act as a processor, our processing is also governed by a data processing agreement (DPA) with the customer. If you are an individual whose data was entered by your employer, please direct data-subject requests to your employer as controller in the first instance; we will support them in responding.

03Data we process

Account & identity data

Name, work email address, role (admin, office, crew or office staff), organisation and vessel assignment, hashed credentials, two-factor and trusted-device information, and account preferences.

Operational data

Vessel and fleet details (including IMO numbers), inspection checklists and answers, comments, scheduling data, key performance indicators, reports, evidence attachments you upload, and support tickets and messages.

Technical & security data

Authentication and session information, audit-log entries (an append-only, hash-chained record of significant actions), and limited technical metadata needed to operate and secure the service.

We ask that customers avoid entering special categories of personal data into free-text fields unless strictly necessary and lawful.

04Purposes & legal bases

Under the GDPR, we rely on the following legal bases:

  • Contract (Art. 6(1)(b)) - to provide the Platform, administer accounts, and deliver support.
  • Legitimate interests (Art. 6(1)(f)) - to secure the Platform, prevent abuse, maintain audit logs, and improve and develop the service, balanced against your rights.
  • Legal obligation (Art. 6(1)(c)) - to comply with applicable law, including retention and tax requirements.
  • Consent (Art. 6(1)(a)) - where we ask for it, for example enabling the optional AI assistant. Consent can be withdrawn at any time.

Where Omnivessel acts as a processor, the legal basis for the underlying processing is determined by the customer as controller.

05AI assistant

The Platform includes an optional AI assistant. It is off by default and requires explicit data-processing consent before it can be enabled, plus a per-vessel opt-in for crew use. When enabled, relevant context is sent to an AI provider solely to generate responses, through server-side calls with guardrails and context isolation; the provider identity is managed by us and never exposed to customer users.

If you do not enable the assistant, no data is sent to any AI provider. You can withdraw consent and disable the assistant at any time.

06Cookies & sessions

The Platform uses only cookies that are strictly necessary to operate the service - primarily to keep you logged in, to record two-factor clearance, and to remember devices you choose to trust. Single active sessions are enforced on our servers, not through a cookie. Your interface theme preference is stored separately in your browser’s local storage, not in a cookie, and is never sent to our servers. We do not use advertising cookies or third-party behavioural tracking. For the full list, see our Cookie Notice.

07Subprocessors

We use a small number of trusted subprocessors to run the Platform. The current categories are:

  • Cloud database & authentication - hosting of the application database and user authentication.
  • Application hosting - hosting and delivery of the web application.
  • Email delivery - transactional emails such as one-time codes, inspection notifications and temporary passwords.
  • Mapping & vessel data - fleet-map rendering and vessel-position / IMO lookup (only when those features are used).
  • AI provider - only where the AI assistant is enabled by the customer.

Each subprocessor is bound by appropriate data-protection terms. A current list of specific subprocessors is available on request at info@omnivessel.io.

08International transfers

The Platform’s primary infrastructure is hosted in the European Union (EU-West region). Where personal data is transferred outside the European Economic Area - for example to a subprocessor - we rely on an appropriate transfer mechanism, such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where needed.

09Data retention

We retain personal data for as long as needed to provide the Platform and for legitimate, lawful purposes thereafter. Unless a longer or shorter period is set out in our agreement with the relevant customer, we retain Customer Data for a minimum of three (3) years, or for the duration of the customer’s subscription if longer. After the applicable retention period, or on termination, Customer Data is made available for export for a limited period and then deleted or anonymised, except where longer retention is required by law. Audit logs are retained as an integrity record for a period consistent with their security purpose and the retention terms above.

10Security

We implement technical and organisational measures appropriate to the risk, including:

  • encryption of data in transit;
  • row-level access controls and a privileged, server-only access path for administrative operations;
  • two-factor authentication, single active session per account, and strong-password enforcement;
  • an immutable, hash-chained audit log and a strict content-security policy;
  • least-privilege handling of secrets and service keys.

No system can be guaranteed perfectly secure, but we work to protect personal data and to respond promptly to incidents. We will notify affected controllers of a personal-data breach without undue delay as required by the GDPR.

11Your GDPR rights

Subject to conditions and exemptions under applicable law, you have the right to:

  • access the personal data we hold about you;
  • request correction of inaccurate or incomplete data;
  • request erasure (“right to be forgotten”);
  • restrict or object to certain processing;
  • data portability;
  • withdraw consent where processing is based on consent; and
  • lodge a complaint with your local data-protection supervisory authority.

Where we process your data on behalf of your employer (as processor), we will forward your request to the relevant controller and assist them in responding. To exercise your rights, contact us at info@omnivessel.io.

12Children

The Platform is a professional tool intended for use by adults in a work context. It is not directed to children and we do not knowingly process children’s personal data.

13Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, notify you through the Platform. We encourage you to review this page periodically.

14Contact

For privacy questions or to exercise your rights, contact the data controller, Omnivessel LLC:

© 2026 Omnivessel LLC. All rights reserved. The OmniVessel Vessel Inspection Suite is developed, owned and copyrighted by Omnivessel LLC.