Legal

Privacy Policy

Last updated: April 28, 2026 · Compliant with GDPR & LGPD (Lei 13.709/2018)

OCL Maritime LLC (“we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our maritime operations platform.

1. Data Controller

OCL Maritime LLC is the data controller for personal data processed through our Service. For EU residents, we act as the controller under GDPR. For Brazilian residents, we act as the controller under LGPD.

Contact: privacy@oclmaritime.com

2. Information We Collect

Account data: Name, email address, company name, role, and authentication credentials provided during registration.

Operational data: Vessel information, port call records, demurrage calculations, cargo manifests, crew records, documents, and other maritime operational data you enter into the platform.

Usage data: Log files, IP addresses, browser type, pages visited, features used, and timestamps. Collected automatically when you interact with the Service.

Payment data: Billing information processed by our payment provider. We do not store full payment card numbers.

Cookies: Essential cookies required for authentication and session management. Analytics cookies (only with your consent) to improve the Service.

3. Legal Basis for Processing (GDPR)

We process personal data under the following legal bases:

  • Contract performance: Processing necessary to provide the Service you subscribed to.
  • Legitimate interests: Security, fraud prevention, service improvement, and analytics.
  • Consent: Analytics cookies and marketing communications.
  • Legal obligation: Compliance with applicable laws.

4. Legal Basis for Processing (LGPD — Brasil)

For Brazilian users, we process personal data based on: (a) execution of a contract or preliminary procedures at the request of the data subject; (b) legitimate interests of the controller; (c) consent for optional processing; and (d) compliance with legal obligations.

5. How We Use Your Information

We use collected information to: (a) provide, operate, and maintain the Service; (b) process transactions and manage subscriptions; (c) send transactional communications (account notifications, invoices); (d) improve and personalize the Service; (e) ensure security and prevent fraud; (f) comply with legal obligations.

We do not sell your personal data to third parties. We do not use your operational maritime data to train AI models for third-party benefit.

6. Data Sharing and Third Parties

We share data only with:

  • Supabase: Database and authentication infrastructure.
  • Resend: Transactional email delivery.
  • OpenAI: AI document analysis (data processed per OpenAI’s API data policy — not used for model training).
  • AISStream.io: AIS vessel tracking data provider.
  • Payment processors: For subscription billing.

All third-party processors are contractually bound to protect your data and use it only for specified purposes.

7. Data Retention

We retain personal data for as long as your account is active or as needed to provide the Service. After account termination, we retain data for 30 days to allow export, then delete it unless required to retain it by law.

Anonymized and aggregated analytics data may be retained indefinitely.

8. International Data Transfers

The Service is operated from the United States. Data may be transferred to and processed in countries outside your jurisdiction. For EU/EEA users, transfers are covered by Standard Contractual Clauses or other adequacy mechanisms. For Brazilian users, transfers comply with LGPD Chapter V requirements.

9. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Right to access your personal data
  • Right to rectify inaccurate data
  • Right to erasure (“right to be forgotten”)
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent at any time (GDPR Art. 7)
  • Right to lodge a complaint with a supervisory authority (GDPR) or ANPD (LGPD)

To exercise your rights, contact: privacy@oclmaritime.com. We will respond within 30 days.

10. Cookies

Essential cookies: Required for authentication, session management, and core functionality. Cannot be disabled.

Analytics cookies: Used to understand how users interact with the Service. Only set with your explicit consent (via the cookie banner).

You can manage cookie preferences through the cookie banner shown upon first visit, or through your browser settings.

11. Security

We implement industry-standard security measures including: TLS encryption in transit, encryption at rest for sensitive data, access controls and audit logs, and regular security assessments. However, no method of transmission over the Internet is 100% secure.

12. Children’s Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from minors.

13. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes via email or prominent notice in the Service. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

14. Contact

For privacy-related inquiries or to exercise your rights:

Email: privacy@oclmaritime.com

OCL Maritime LLC · Wyoming, USA

Resumen en español

Esta política explica cómo OCL Maritime maneja tus datos personales. En resumen:

  • Recopilamos datos de cuenta, operativos y de uso para brindar el servicio.
  • No vendemos tus datos a terceros.
  • Compartimos datos solo con proveedores técnicos necesarios (base de datos, email, IA, AIS).
  • Podés solicitar acceso, corrección, eliminación o portabilidad de tus datos.
  • Usamos cookies esenciales siempre y cookies analíticas solo con tu consentimiento.
  • Para ejercer tus derechos: privacy@oclmaritime.com