Privacy Policy

Arctic Digital SL — Sea Fleet Manager

Last updated: 2026-09-14

This policy covers two different relationships, and they carry different obligations — see section 2. If you are a seafarer whose records are held in Sea Fleet Manager ("SFM"), your relationship is with your employer, not with us; section 9 explains how to exercise your rights.

1. Who we are

Arctic Digital, S.L.U. ("Arctic Digital", "we") is a single-member limited company registered in Spain, CIF B88803044 (VAT number ESB88803044), with its registered office at Calle Besós 11, 08338 Premià de Dalt (Barcelona), Spain, registered at the Registro Mercantil de Barcelona, hoja B-657806.

We develop and operate Sea Fleet Manager ("SFM"), a maritime fleet compliance platform used by shipowners and managers to hold vessel and crew certification, hours of rest, planned maintenance, inspections and incident records.

Questions about this policy, or about personal data we hold, go to privacy@arcticdigital.eu.

We have not appointed a Data Protection Officer. Our processing does not meet the thresholds in Article 37(1) GDPR that would require one. If that changes, this policy will change with it.

2. Two different roles, and why the distinction matters

This policy covers both, and they carry different obligations.

As a controller, we decide why and how personal data is processed. This applies to visitors to our website, people who contact us, and the individuals at our customers and suppliers we deal with commercially. Part A covers this.

As a processor, we handle personal data on a customer's documented instructions and for no purpose of our own. Everything inside a customer's SFM tenant — crew records, certificates, hours of rest, incident reports — falls here. The customer, normally the shipowner or manager, is the controller of that data. Part B covers this.

If you are a seafarer whose records are held in SFM, your relationship is with your employer, not with us. Section 9 explains how to exercise your rights.

Part A

Where Arctic Digital is the controller

3. What we process, why, and on what basis

DataPurposeLegal basis (Art. 6 GDPR)
Name, employer, job title, email, telephoneResponding to enquiries; managing the commercial relationshipContract (6(1)(b)), or legitimate interests (6(1)(f)) before a contract exists
Account identifiers and authentication data for named administratorsGranting and securing access to SFMContract (6(1)(b))
Correspondence, including email we receive and retainKeeping a record of what was agreed and whenLegitimate interests (6(1)(f))
Billing details, invoices, tax recordsInvoicing and statutory accountingLegal obligation (6(1)(c))
Server and application logs, including IP addressSecurity, abuse prevention, diagnosing faultsLegitimate interests (6(1)(f))

Where we rely on legitimate interests, the interest is operating and securing a business-to-business service. We have assessed that this does not override the rights of the individuals concerned, who are acting in a professional capacity.

We do not sell personal data, we do not use it for advertising, and we do not make automated decisions producing legal or similarly significant effects.

4. How long we keep it

DataRetention
Enquiries that do not become customers24 months from last contact
Customer relationship recordsDuration of the contract plus 6 years
Invoices and accounting records6 years (Spanish commercial and tax law)
Security and application logs12 months
Part B

Where Arctic Digital is a processor

5. What sits in SFM

Customers use SFM to hold records about their seafarers and vessels. Depending on how a customer configures it, that can include:

  • identity and contact details, date and place of birth, nationality
  • passport and seafarer's book numbers and expiry dates
  • certificates of competency, endorsements, flag state recognitions and training certificates
  • medical fitness certificates and their validity dates
  • records of hours of work and hours of rest
  • employment agreements and engagement records
  • records of incidents, near misses and occupational injuries

Medical fitness certificates are health data and therefore a special category under Article 9 GDPR. Records concerning incidents and injuries may also be. We apply the additional controls in section 8 to them.

Incident and injury records may name individuals other than the customer's own crew, for example a surveyor or contractor injured aboard.

6. What we do with it, and what we do not

We process customer data only:

  • on the customer's documented instructions, as set out in the data processing agreement between us;
  • to make the service work — storing, indexing, generating documents, sending expiry notifications the customer has configured;
  • to keep it secure and to diagnose faults; and
  • where EU or Spanish law requires it of us, in which case we tell the customer first unless the law forbids it.

We do not use customer data for our own purposes, to train models of our own, or to build products.

Where SFM uses automated extraction to read uploaded documents, the output is presented to a human for review before it is committed to a record. No compliance record is created from extraction alone.

Two third-party AI services are used, and processing here is not self-hosted. Voyage AI, Inc. generates vector embeddings from chunked document text so that a document's content can be searched by meaning — the underlying text leaves our infrastructure for that purpose. Anthropic, PBC provides the language model behind the AI agent, which is given retrieved document excerpts together with live vessel data (certificates, maintenance jobs, crew manifest) to answer a user's question, and separately performs the extraction step when a customer uploads a scanned, hand-filled hours-of-rest record.

Model training. No customer data is used to train any third-party model. Anthropic's commercial terms provide that API inputs and outputs are never used for model training, and our agreement incorporates Anthropic's Data Processing Addendum including Standard Contractual Clauses Modules 2 and 3. Google commits that Workspace customer data is not used to train generative AI models outside Workspace without permission. API logs are retained by Anthropic for 7 days by default for abuse monitoring.

7. Sub-processors

We engage the following. Each is bound by a written contract meeting Article 28 GDPR, and each is permitted to process customer data only to deliver the function named.

Sub-processorFunctionProcessing location
Vercel Inc.Application hosting and content deliveryFrankfurt, Germany (eu-central-1)
Supabase Inc.Database, authentication, file storageIreland (eu-west-1)
Railway Corp.Document generation — Gotenberg PDF/DOCX renderingSingapore
Anthropic PBCDocument content extractionUnited States (multi-region)
MongoDB, Inc. (Voyage AI)Text embeddings for document searchUnited States
Google Ireland LimitedNotification email; mailbox access for the archive toolGlobal, including the United States

We give customers advance notice of any change to this list, so that they have the opportunity to object.

Transfers outside the EEA. Where a sub-processor processes data outside the European Economic Area, the transfer is made under the European Commission's Standard Contractual Clauses together with any supplementary measures required following an assessment of the destination country.

8. Security

  • Encryption in transit (TLS) and at rest.
  • Tenant isolation enforced in the database itself through row-level security, so a query cannot reach another customer's records.
  • Named accounts, least-privilege roles, and no shared logins.
  • Access to production data restricted to personnel who need it, and logged.
  • Backups taken regularly and their restoration tested.
  • Special category data is subject to narrower access and is not included in diagnostic exports.

We notify the customer without undue delay on becoming aware of a personal data breach affecting their data, with the information they need to meet their own obligations under Articles 33 and 34.

9. Retention and deletion of customer data

The customer decides how long their records are kept, subject to the retention periods maritime law imposes on them — records of hours of rest and certain crew records must be retained for defined periods under MLC 2006 and flag state rules, and a shipowner cannot delete them at will.

On termination, we delete or return customer data within 30 days, at the customer's choice, except where we are required by law to keep it.

10. Internal processing activity: mailbox archive

Where a customer asks us to, we extract and index documents from a mailbox they control, so that certificates and compliance records held only in email are brought into a structured archive. This is carried out on that customer's instructions, under the same terms as any other processing in Part B, with read-only access and no modification of the source mailbox.

Common

Common provisions

11. Your rights

Under the GDPR you may request access to your personal data, its correction or erasure, restriction of processing, portability, and you may object to processing based on legitimate interests. Where processing rests on consent, you may withdraw it at any time without affecting what was done beforehand.

If your data is in SFM because you work for one of our customers, that employer is the controller and decides these questions. Send your request to them. If you send it to us, we will pass it on promptly and support them in answering it, but we cannot grant it ourselves.

You may lodge a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (www.aepd.es), or with the authority in your country of residence or work.

12. Cookies and similar technologies

seafleetmanager.com uses only cookies strictly necessary to operate the service — maintaining your session and protecting against cross-site request forgery. These require no consent under Article 22.2 of Spanish Law 34/2002 (LSSI).

We use no advertising cookies and no third-party analytics.

13. Changes

We will post any change here and update the date at the top. Where a change materially affects how we handle personal data, we will tell affected customers directly rather than rely on them noticing.

14. Contact

Arctic Digital, S.L.U.
Calle Besós 11
08338 Premià de Dalt (Barcelona)
Spain

CIF: B88803044 (VAT: ESB88803044)
Email: privacy@arcticdigital.eu

Registered at the Registro Mercantil de Barcelona, hoja B-657806, folio 1, EUID ES8005.000749279.

This page is prepared as a working document and is not a substitute for legal advice.