Our privacy policy explains how we process data across all services and websites we operate. This is quite a long document but it outlines, in detail, exactly what data we process, how long we retain it for and more.
Summary
Who We Are
Oceans HQ Ltd ("we", "us", "our") is a limited company registered in England & Wales (registration number 8486423) with a registered at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. We operate a number of services including OHQ Cloud, Vessel HQ, Seafarer HQ, Frontier, Atlas and others. This privacy policy covers how we will use, collect and process any data provided to us.
How we process your data
Throughout your interactions with us we will collect only the data that we require in order to provide you with the service that you are requesting. The key information that we process is shown below for your information.
IP Addresses
When you access any of our services we will store a record of your IP address along with details of your request in our logs. This information is stored and used by our system team to ensure the integrity of our services.
Data Retention: This information is stored in rotating logs, which are kept for between 6 and 24 months.
Authorisation & Session Data
Whenever you login to one of our services we will use at least two cookies that will identify your session to our services. This is necessary to provide our service to you.
The browser_id
cookie is a permanent cookie that uniquely identifies your browser to us and allows us to ensure that previous sessions from that browser are invalidated when logging in again. This is only used for the purposes of invalidating these sessions as well as allowing us to notify you when new sessions are created in new browsers.
The user_session
cookie is, initially, a session-only cookie that contains a unique token that identifies your specific session. This data is not stored on our end and is only stored in a hashed form. If you choose to persist your login session, this cookie will be converted to a more permanent cookie with an expiry time at some point in the future. The actual time will depend on the service you are using.
In addition to these cookies, we also store IP addresses & user agents with your session. This allows us to look for anomalies in its use to help us protect your account and our systems.
Data Retention: This data is stored until such time as the associated user account is deleted.
Your Name
When you sign up, we need to know your first & last name so that you can be identified. We will use your name to address you and it may be stored in various systems that you use (for example: our helpdesk). This is necessary to provide our service to you.
Your name may be shared with other people that share access to an account you are part of. For example, if you have an OHQ Cloud account, your name will be shared with other members of that account.
Data Retention: Your name will be retained until your user account is deleted. In some cases, your name may be kept with your billing records where we have a legal obligation to store this information.
Email Addresses
We will store your e-mail address for the purposes of managing your account with us. This will be used for transactional e-mails that relate directly to your account or services. This information is required in order to ensure you are informed about your account and can take appropriate actions in various situations.
We may also use your e-mail address to send you messages about our services which may include notifications about newly launched features, improvements to the service, upcoming maintenance as well as ways to help you make the most of your service. If you would rather not receive these messages, please let us know or click the unsubscribe link in these e-mails.
We will not send you any other marketing messages unless you subscribe to our newsletter which you can do through our website when signing up or through one of our applications. When you do this, you will be providing consent enabling us to use your email address for this purpose. You may withdraw this consent at any time by unsubscribing from the messages or contacting us.
If you are using a service that allows multiple users to have access to the same account, your e-mail address may be shared with the other users on this account.
Data Retention: Your email address will be kept until such time as all accounts associated with it are deleted from our systems.
Outgoing Emails
If we send you transactional e-mails, these will be passed through one of our mail servers and stored for a period of time to assist with debugging delivery problems and ensuring messages are appropriately delivered to their destinations. This is necessary to provide our service to you.
The information stored includes the contents of the message sent, the e-mail addresses of the recipients and any other headers.
Data Retention: The contents of messages are stored for a period of 30 days from the date the message is received by our mail system. The meta data for any messages is kept for 60 days from this date.
Incoming Emails
If you send us e-mails, these may be passed through our mail servers. If some cases, these messages will be consumed by one of our services or applications, for example, tickets sent to your OHQ Cloud account or updates to correspondence submitted to one of our applications. This is necessary to provide our service to you.
Data Retention: Our mail servers will store the contents of messages for 30 days and the meta data for 60 days. If the message has been consumed by one of our applications or services, the data will be retained for as long as you decide.
Passwords
We never store your own passwords on our services. Passwords are stored by Auth0.com in a hashed format using an industry standard hashing algorithm. As a good security practice, we recommend the following with regards to choosing your password:
Data Retention: Our mail servers will store the contents of messages for 30 days and the meta data for 60 days. If the message has been consumed by one of our applications or services, the data will be retained for as long as you decide.
Phone Numbers
We may ask for your phone number which will be used to contact you by phone in the event of a support request or billing query. This is necessary to provide our service to you.
Data Retention: Your phone number will be kept until such time as you delete your account or manually remove your number from it.
Company Name and Postal Address
We require your postal address in order to provide you with an invoice for your services. This information is collected as a legal obligation and will be stored on our systems along with invoices for a minimum period of 7 years.
We may wish to send you items by post (for example t-shirts, mugs, stickers etc...). To do this, you will need to provide your address to us again and consent to us using it for the purposes of sending you items by post. We may store your address on file to allow us to send you items in the future. You may opt to have this address removed from our records at any time by contacting us.
Payment Cards
We do not store full payment card details on our own servers. We work with external PCI-compliant payment processors (Stripe) who store these details. We also store the country that the card was registered in and the IP address country that the card was added from as a legal obligation to ensure that the correct VAT rate is charged for your payments.
Data Retention: We will instruct our payment processors to delete any stored card details when you cancel your account.
Data added by you and stored in your accounts
When you use our services you might upload or generate personal information relating to your own customers and users. You will remain the data controller for all such data that is stored within our systems and are responsible for ensuring you have an appropriate lawful basis & notices in place to allow us to store this data on your behalf.
If you use an Oceans HQ service which allows you to upload, store or process any personal data, you are responsible for ensuring that you are compliant with appropriate laws & regulations (for example the General Data Protection Regulation) for this data.
We do not recommend customers store any personal data in areas of our systems that are not designed for the purposes of storing this information.
Data Retention: Data stored in the services you have with us will be kept until such time as you delete the data yourselves or you cancel your account. Upon cancellation of an account, we may keep the data for up to 30 days at which point it will be purged from our databases.
Analytics
We use AppSignal to help us track code errors and bugs generated by users of our services.
Data Retention: We will instruct AppSignal to delete any stored data when you cancel your account.
Your OHQ Cloud Account
Our services use our single sign on service, Auth0. You can manage many aspects of your data for your user account across all services by logging in to any of our Services and editing your account. This is necessary to provide our service to you.
Data Retention: OHQ Cloud accounts are kept for as long as they are associated with another service or are linked with another service using Auth0. Accounts which are not linked to any services will be deleted after 6 months of inactivity.
Support by Email
If you contact us by e-mail or through one of our websites, you will be sharing your contact details (e-mail address and/or phone number) with us for the purposes of responding to your query. This is necessary to provide our service to you.
Data Retention: We retain all support requests (including name & contact details) that we receive for the purposes of auditing and training of staff.
Emails directly to/from our employees
If you communicate with our employees directly by e-mail (i.e. not using our normal support channels), we may retain your name & e-mail address in the mailboxes of the employee(s) that you communicate with. This is necessary to provide our service to you.
Data Retention: Employee e-mails are kept indefinitely. Any e-mails that contain sensitive data that are delivered by accident will be removed immediately.
Call logs and audio recordings
If you choose to phone us, we will store a log of your call which may include your telephone number if it was sent to us. We also record calls for the purposes of auditing any requests that might be made by you to us over the phone.
Data Retention: We retain call recordings for 60 days from the date of the call then they are automatically deleted. Call logs are kept for a minimum period of 1 year.
Backups
We store backups of data stored by us for use in disaster recovery. Backup data is encrypted and stored off site in a secure data centre. This is necessary to provide our service to you.
Data Retention: Backup data is stored for a period of 12 weeks.
Job Applications
If you apply for a job with us, we will store the personal data that you submit for the purposes of considering your application.
Data Retention: Job application data will only be kept until the position has been filled unless you ask us to keep your information on record for considering for a future position.
Our Servers
We own and operate our own servers which are located in the European Union. The physical data centres have numerous physical security measures including biometric security, full CCTV coverage as well as 24/7 manned security.
Transfer of Data to Group Companies
We may share and/or transfer your data with other companies within our group for the purposes of administration and company structuring.
Transfer of Data on Product or Service Acquisition
If one of our services is acquired by another company or entity, we may share your information with the acquiring company so that they may continue to provide you with the services that you have elected to receive. You will be notified by e-mail in the event that such an acquisition occurs.
3rd Party Processors
In some cases, we may use third parties to provide storage or computing services. We maintain a list of third parties that process data on our behalf.
Category | Personal Data |
---|---|
Professional services | We may share your details with processional service companies such as accountants or accounting software. |
Payment service providers | We may share your details with company who provide us with payment services for taking payments from credit/debit cards. |
Technical service providers | We may share your details with providers we use to provide computing services. |
E-Mail marketing software | We may share your details with e-mail marketing software providers to allow us to send e-mails to customers. |
Communication services | We may share your details with companies who provide us with communication services such as a live chat or e-mail providers. |
We will not share your data with third parties for the purposes of any marketing without your consent unless otherwise specified in this privacy notice.
Some of our applications allow users to configure integrations with third party services. When using any of these integrations, you share your data with the organisations who operate these services. You should review their own privacy information with regard to how they will treat this information once it has been provided.
Correcting your personal data
It is important to us that the information we store is up to date and accurate. You may update your details at any time through our various websites & applications.
Removal of your personal data
In some cases, you may be able to request that we remove your personal data from our systems. As with correcting your data, you can often delete your data yourselves through our websites & applications. In other cases, though, please feel free to contact us using the information below.
Your rights
You have a lot of rights, including right to request access to and rectification or erasure of your personal data or restriction of processing of it. You also have the right to object to our processing of your data in some situations, as well as the right to data portability.
Notification of data breaches
Upon discovering any data breaches, we will notify any affected individuals as soon as its practical following our data breach notification policy. This policy dictates that in the event of a data breach concerning personal data, the affected parties will be notified by e-mail to the main e-mail address we store with your account.
Electronic storage of data
No method of electronic storage can be 100% secure, however, we have sophisticated and detailed security & development policies that govern our systems & applications to help ensure your data is as secure as it can be.
Changes to our Privacy Policy
We may need to make changes to this privacy policy from time to time. All changes will be published to our websites and we recommend reviewing it to stay up to date. If we make any changes that we feel may affect your privacy rights, we will notify you by e-mail or by displaying the information within the our services or applications.
Our Lawful Basis for processing data
Under the General Data Protection Regulation, unless we have otherwise specified above, we will be processing your data as a legitimate interest. These interests include staff training, ensuring the security of our systems and to allow us to operate our business in an efficient manner.
Where our processing is based on consent, you may withdraw consent at any time.
Where our processing is necessary for us to perform our contract with you, or to take steps to enter into a contract with you, we will not be able to enter into a contract with you or deliver our services to you if you do not give us the data in question.
Disclosure of information to Law Enforcement Agencies
We may disclose your information if we are requested to by any law enforcement agency where we believe we are required to comply with the request under any applicable laws.
Data Protection Authority
You may have the right to lodge a complaint with your local data protection authority or the Information Commissioner's Office (ICO) in the United Kingdom (our authority). The ICO can be contacted at: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Other information can be found on their website at ico.gov.uk.
Contacting us
If you have any questions about our privacy policy or any other aspects of our services, you may contact us by e-mail on [email protected] or calling us on +44 (0)3300 881002.
Capture, process and analyse your Maritime Administration's data while ensuring compliance with international regulations.
© 2024 Oceans HQ Ltd. All rights reserved. Registered in England and Wales under 08486423.
Registered Office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. VAT Registration: GB168617573