Privacy Policy
Effective 4 October 2026
This policy explains what personal data IMO RISK processes, why, who helps us process it, how long we keep it, and your rights under the EU General Data Protection Regulation (GDPR) and Czech Act No. 110/2019 Coll. on personal data processing.
1. Controller
The controller of your personal data is Pavel Havlíček, IČO 07501668, Záhřebská 562/41, Vinohrady, 120 00 Praha 2, Czech Republic. For any privacy question or request, contact pa.havlicek@gmail.com. We have not appointed a data protection officer, as we are not required to.
2. Personal data we process
| Category | Data | Source |
|---|---|---|
| Account | Name, e-mail address, profile picture URL and Google account identifier; role, plan and quota settings | Google, when you sign in |
| Usage | Vessel descriptions and IMO numbers you search, which dossiers you requested and when, query counts and refunds | You, when using the Service |
| Billing | Name, e-mail, billing country/address and VAT ID if given, purchased products, amounts, invoices, subscription status. Card details are handled by Stripe and never reach us. | You, via Stripe checkout |
| Enquiries | Name, work e-mail, company, expected volume and your message | You, via the contact-sales form or e-mail |
| Technical | IP address, browser information and request logs; sign-in session tokens | Your device, automatically |
| Third parties in dossiers | Names and roles of people publicly associated with vessels or companies (e.g. company officers, crew in news reports) | Public sources — see section 6 |
3. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating your account, running searches and assessments, keeping your history, applying quotas | Performance of a contract — Art. 6(1)(b) |
| Taking payments, issuing invoices, keeping accounting and tax records | Contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) |
| Answering Enterprise and other enquiries | Steps prior to a contract — Art. 6(1)(b); legitimate interest — Art. 6(1)(f) |
| Security, abuse and fraud prevention, technical logs, monitoring service quality and costs | Legitimate interest in operating a secure, reliable service — Art. 6(1)(f) |
| Service messages (e.g. changes to these documents, billing notices) | Contract — Art. 6(1)(b) |
| Defending legal claims | Legitimate interest — Art. 6(1)(f) |
4. What we do not do
- We do not sell your personal data or use it for advertising.
- We do not send marketing e-mails unless you ask for them.
- We do not use analytics or advertising cookies (see the Cookie Policy).
- We do not make automated decisions about you that have legal or similarly significant effects. AI is used to research vessels, not to assess users.
- We do not use your searches to train AI models, and our AI providers receive the vessel query text and public web content needed to run it — not your name or e-mail.
5. Service providers and international transfers
We use the following providers, who process data on our behalf (processors) or, where stated, as independent controllers:
| Provider | Role | Location |
|---|---|---|
| LANGTAIL.COM s.r.o. (Macaly), Prague | Application hosting, build platform, e-mail delivery, and gateway to AI and web-search services | EU |
| Convex, Inc. | Database and backend; our deployment is hosted in the EU (Ireland) | EU data storage; US company |
| AI model and web-search providers reached through Macaly’s gateway (e.g. OpenRouter, Inc., Anthropic PBC, Google LLC) | Processing vessel query text and fetched public web pages to produce Outputs | USA |
| Stripe Payments Europe, Ltd. | Payment processing and invoicing; independent controller for fraud prevention and its legal obligations | Ireland (EU); transfers to Stripe, Inc. (USA) |
| Google Ireland Limited | Sign-in with Google; independent controller for your Google account | Ireland (EU); transfers to the USA |
Where personal data is transferred outside the European Economic Area, the transfer relies on an adequacy decision (including the EU–US Data Privacy Framework for certified recipients) or on the European Commission’s Standard Contractual Clauses. You can request more information about these safeguards at pa.havlicek@gmail.com.
We may also disclose data where required by law, for example to tax authorities or courts.
6. People mentioned in vessel dossiers
Dossiers are compiled from publicly available sources such as ship registries, port state control databases, official sanctions lists, and maritime and general news. They can contain names and roles of individuals — for example directors of ship-owning companies, persons on sanctions lists, or people named in news about incidents.
We process this information as controller on the basis of our and our users’ legitimate interest in maritime risk due diligence and sanctions compliance (Art. 6(1)(f) GDPR), and, for sanctions lists, in supporting compliance with legal obligations. We collect only what appears in the cited sources, show the source for every fact, and do not build profiles of individuals beyond the vessel context. Dossiers are stored as dated records of what the sources said at the time.
If you are mentioned in a dossier, you have the rights described in section 9, including the right to object. Write to pa.havlicek@gmail.com; we will review the request and correct, restrict or remove information where your interests prevail.
7. How long we keep data
| Data | Retention |
|---|---|
| Account, settings and search history | Until you delete your account, then removed within 30 days (backups up to 30 further days) |
| Invoices and accounting records | 10 years from the end of the tax year, as required by Czech VAT and accounting law |
| Vessel dossiers | Kept as permanent point-in-time research records; after account deletion they are no longer linked to you |
| Enquiries (contact sales) | Up to 2 years after our last contact, unless a contract follows |
| Technical logs | Short periods set by our hosting providers, typically up to 30 days |
| Usage and cost logs | Up to 2 years, then deleted or anonymised |
8. Security
Data is transmitted over encrypted connections (HTTPS) and stored with our providers using access controls. Administrative access is limited to authorised administrators. Payment card data is processed exclusively by Stripe, which is PCI-DSS certified.
9. Your rights
Under the GDPR you have the right to:
- access your personal data and receive a copy;
- have inaccurate data corrected;
- have data erased (“right to be forgotten”), subject to legal retention duties such as invoices;
- restrict processing;
- data portability for data you provided to us under a contract;
- object to processing based on legitimate interest;
- withdraw any consent you have given, without affecting earlier processing.
To exercise your rights or delete your account, e-mail pa.havlicek@gmail.com from the address linked to your account. We respond within one month (extendable by two months for complex requests).
You may also lodge a complaint with the supervisory authority: Úřad pro ochranu osobních údajů (Office for Personal Data Protection), Pplk. Sochora 27, 170 00 Praha 7, Czech Republic, https://uoou.gov.cz, or with the authority in your EU country of residence or work.
10. Children
The Service is intended for professionals and not directed at anyone under 18. We do not knowingly process children’s data.
11. Changes to this policy
We may update this policy. Material changes will be announced to registered users by e-mail or in the app before they take effect. The current version is always published here.