Privacy Policy
Last updated: 7 June 2026
This Privacy Policy explains how Magnor Vessels LLC ("Magnor Vessels", "we", "us", "our") collects, uses, and protects personal data when you use our superyacht regulatory-compliance platform and related websites (the "Service"). We are a United States company, and we offer the Service to customers and crew in the United States, the European Economic Area (EEA), and the United Kingdom. We are committed to handling personal data responsibly and in accordance with applicable data-protection laws — including the EU General Data Protection Regulation (GDPR), the UK GDPR, and US federal and state privacy laws such as the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA").
1. Who we are
Magnor Vessels LLC provides a web platform that helps superyacht owners, operators, and management companies manage regulatory compliance — including statutory certificates, crew records and certifications, rest hours, drills, planned maintenance, surveys and audits, documents, and live vessel position, together with an AI compliance assistant.
Magnor Vessels LLC is a limited liability company formed in the State of Wyoming, United States.
Because we offer the Service to individuals in the EEA and the UK, the GDPR and UK GDPR apply to that processing under their extraterritorial scope (Article 3(2)). For the purposes of those laws, Magnor Vessels LLC is the controller of account and billing data, and a processor of the content our customers upload (see section 3).
For privacy questions or to exercise your rights, contact privacy@magnorvessels.com. For general enquiries, use hello@magnorvessels.com. If a Data Protection Officer is appointed, their contact details will be published here.
2. EU and UK representatives
Because we are established outside the EEA and the UK but offer services to individuals there, we are required to designate representatives under Article 27 of the GDPR and the UK GDPR. You may contact the relevant representative on data-protection matters as an alternative to contacting us directly:
- EU representative (Article 27 GDPR): available on request from legal@magnorvessels.com.
- UK representative (Article 27 UK GDPR): available on request from legal@magnorvessels.com.
We expect to appoint these representatives through a specialist provider before offering the Service to EEA/UK individuals at scale.
3. Scope and our role (controller vs processor)
This policy covers personal data we process through our platform and websites. It is important to understand the difference between the two roles we play, because they determine who is responsible for the data:
- Where we are the controller. For account data (the details of the people who log in and use the platform) and billing data, we decide why and how the data is processed, so we act as the controller.
- Where we are the processor. For the content our customers upload — including vessel records, crew personal data, certificate details, rest-hour logs, documents, and maintenance and audit records — the customer (the yacht owner, operator, or management company) is the controller, and we act as a processor on their behalf. We process that content only on the customer's documented instructions, under our Data Processing Agreement (DPA).
If you are a crew member or other individual whose data has been uploaded by a customer, please direct requests about that data to the customer who controls it; we will support them in responding. This policy primarily describes the data for which we are the controller.
4. What personal data we collect
Depending on how you interact with us, we may process the following categories of personal data:
- Account data (we are controller): your name, email address, authentication credentials (managed through our authentication provider, Clerk), and your role within an organisation.
- Customer content (we are processor): vessel records and, where uploaded by the customer, crew personal data such as names, roles, certificate details, STCW and MLC documents, rest-hour logs, uploaded documents and files, and maintenance and audit records.
- Vessel position data: AIS data, which is publicly broadcast and tied to a vessel's MMSI number.
- Billing data (we are controller): information needed to manage your subscription, processed through our payment provider, Stripe. We do not store full payment card numbers.
- Technical data: your IP address, device and browser information, usage logs, and error reports.
Under the CCPA, these correspond broadly to the categories of identifiers, commercial information, internet/network activity, geolocation data (vessel position), and professional or employment-related information (crew records).
5. How and why we use personal data (GDPR legal bases)
We use personal data for the purposes set out below. For each purpose we identify the legal basis under Article 6 of the GDPR on which we rely where the GDPR/UK GDPR applies:
- To provide and operate the platform — creating and managing accounts, delivering compliance features, and making the service available per vessel. Legal basis: performance of a contract.
- To process payments and manage subscriptions — billing, invoicing, and preventing non-payment. Legal basis: performance of a contract, and legal obligation for tax and accounting records.
- To secure, maintain, and improve the service — monitoring for errors and abuse, debugging, and developing new features. Legal basis: legitimate interests in keeping our platform reliable and secure, balanced against your rights.
- To communicate with you — sending service and transactional messages (for example, security notices and account updates) via our email provider, Resend. Legal basis: performance of a contract and legitimate interests. Where we send optional marketing, we rely on your consent, which you can withdraw at any time.
- To provide AI compliance assistant features — processing your queries and relevant records to generate responses. Legal basis: performance of a contract; where we act as processor on customer content, on the customer's instructions under the DPA.
- To comply with our legal obligations — responding to lawful requests and meeting regulatory and accounting duties. Legal basis: legal obligation.
6. Crew data and special-category information
Some customer content may reveal information about individuals — for example, certificates, qualifications, and rest-hour records can indicate aspects of a crew member's professional history, working time, and, in some cases, health or fitness. Where a customer uploads this content, the customer is the controller and is responsible for establishing a lawful basis for processing it (including, where relevant, an appropriate condition for processing special-category data) and for providing any required notices to the individuals concerned. We process such content only as a processor, on the customer's instructions and under our Data Processing Agreement.
7. Sub-processors
We use carefully selected third-party providers to help us deliver the service. These currently include Clerk (authentication), Neon (database hosting), Railway (API hosting), Netlify (web hosting), Cloudflare R2 (file storage), Resend (transactional email), Stripe (payments), Anthropic (AI assistant features), Sentry (error monitoring), and AISStream (AIS position data). Each is bound by appropriate contractual data-protection obligations. An up-to-date list is maintained on our sub-processors page.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
8. International data transfers
We are based in the United States, and our sub-processors operate data centres in the United States and the European Union. When personal data of individuals in the EEA or the UK is transferred to the United States or another country that has not received an adequacy decision, we rely on appropriate safeguards — in particular the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary measures where required. Where we or a relevant sub-processor is certified, we may also rely on the EU-US Data Privacy Framework and its UK Extension. You may contact us for more information about, or a copy of, the relevant safeguards.
9. How long we keep data
We keep personal data only for as long as necessary for the purposes described in this policy, or for as long as required to meet legal, accounting, or reporting obligations. Indicative retention periods are:
- Account data: for the duration of your account and then deleted or anonymised within approximately 12 months of closure.
- Customer content: for the term of the customer's subscription and then deleted or returned in line with our Data Processing Agreement, within approximately 30–90 days.
- Billing and tax records: as required by applicable US tax and accounting law, typically up to 7 years.
- Technical data and logs: approximately 12 months.
When personal data is no longer needed, we securely delete or anonymise it.
10. How we protect data
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or misuse, including encryption in transit, access controls, tenant isolation, and monitoring. Our payment provider, Stripe, is PCI-DSS compliant. You can read more about our approach on our Security page. No method of transmission or storage is completely secure, but we work continuously to safeguard the data entrusted to us.
11. Your rights under the GDPR and UK GDPR
If you are in the EEA or the UK, you have the following rights in relation to your personal data, subject to applicable law:
- Access — to obtain a copy of the personal data we hold about you.
- Rectification — to have inaccurate or incomplete data corrected.
- Erasure — to ask us to delete your personal data in certain circumstances.
- Restriction — to ask us to limit how we process your data.
- Portability — to receive your data in a structured, commonly used, machine-readable format.
- Objection — to object to processing based on our legitimate interests.
- Withdraw consent — where we rely on consent, to withdraw it at any time without affecting prior processing.
- Lodge a complaint — EEA residents may complain to their local data-protection authority; UK residents may complain to the Information Commissioner's Office (ICO). You may also contact our EU/UK representative (section 2).
Logged-in users can export a JSON bundle of their personal data and request account deletion from Account → Privacy (the export and deletion tools fulfil GDPR Articles 15 and 17). For other requests, contact privacy@magnorvessels.com.
12. Your rights under US state privacy laws
If you are a resident of California or another US state with a comprehensive privacy law (for example Colorado, Connecticut, Virginia, Texas, Oregon, and a growing number of others), you may have the following rights, subject to that law and its exceptions:
- Right to know / access — the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients.
- Right to delete — to request deletion of personal information we collected from you.
- Right to correct — to correct inaccurate personal information.
- Right to opt out — of the "sale" or "sharing" of personal information and of targeted advertising. We do not sell or share personal information, so no opt-out is required, but you may still contact us.
- Right to limit sensitive personal information — we do not use sensitive personal information for purposes that would require an opt-out under the CCPA.
- Non-discrimination — we will not discriminate against you for exercising any of these rights.
To exercise these rights, contact privacy@magnorvessels.com. You may use an authorised agent to submit a request on your behalf. We will verify your request and respond within the timeframes required by applicable law, and where a request is denied you may appeal by replying to our response.
Note: where personal data was uploaded by a customer (and we act only as a processor / "service provider"), we will refer your request to, or assist, the customer who controls that data.
13. Cookies
We use cookies and similar technologies to operate our website, keep you signed in, and understand how the service is used. You can find details of the cookies we use, and how to manage your preferences, in our Cookie Policy.
14. Children
Our service is intended for maritime professionals and is not directed at children. We do not knowingly collect personal data from children (under 13 in the US, or under 16 in the EEA/UK). If you believe a child has provided us with personal data, please contact privacy@magnorvessels.com so we can take appropriate action.
15. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you through the service or by email. We encourage you to review this page periodically.
16. Contact us
If you have any questions about this Privacy Policy or how we handle personal data, please contact us at privacy@magnorvessels.com for privacy matters, or hello@magnorvessels.com for general enquiries.