Privacy Policy
This Privacy Policy explains how personal data is processed in the 360 Crewing platform: the web application, the 360crewing Android and iOS applications, and the websites 360crewing.com and 360crewing.ru (together, the “Service”).
1. Who we are
The Service is operated by Kuraga Investment AS, a company registered in Estonia, Pronksi tn 5-5, Tallinn 10124, Estonia (“we”, “us”, “360 Crewing”).
For any question about this policy or about your personal data, write to hello@360crewing.com.
2. Our two roles: controller and processor
360 Crewing is a business-to-business platform. Crewing companies, ship managers and manning agents (“Customers”) subscribe to the Service and use it to manage their own crew records. This means our role differs depending on whose data is involved.
| Data | Our role | What that means |
|---|---|---|
| Seafarer and crew records held inside a Customer’s workspace | Processor | The Customer is the data controller. They decide what is collected, why, and for how long. We process this data only on their documented instructions, under a data processing agreement. |
| User accounts, sign-in data, support correspondence, product analytics | Controller | We decide the purposes and means, and this policy describes them. |
| Website visitors (360crewing.com / 360crewing.ru), demo requests | Controller | We decide the purposes and means, and this policy describes them. |
If you are a seafarer and your records are held in 360 Crewing by a crewing company, that company is the controller of your data. Address requests about your crew record to your employer or manning agent first. If you cannot reach them, contact us at hello@360crewing.com and we will assist them in responding.
3. What data we process
3.1 User account data (we are controller)
- Email address and a securely hashed password.
- Name, job role and permissions, office and group assignment within the Customer’s workspace.
- Interface language and account settings.
- Technical sign-in records: session and authentication tokens, timestamps.
- Correspondence you send us by email.
3.2 Crew records (the Customer is controller, we are processor)
Depending on how a Customer configures the Service, crew records may include:
- Identity: full name, date and place of birth, nationality, photograph.
- Contact details: postal addresses, phone numbers, email addresses, nearest airport or railway station.
- Identity and travel documents: passports, seaman’s books, visas, national identity documents, including numbers, issue and expiry dates and scanned copies.
- Professional qualifications: rank, certificates of competency, STCW and training certificates, education records, skills.
- Sea service history: vessels, positions, tours of duty, joinings and sign-offs, flights and travel arrangements.
- Health data: medical certificates and their validity, fitness-for-duty status. This is a special category of personal data (see section 5).
- Next of kin and relatives: names, relationship, contact details.
- Financial details: bank account and payment details, employment contracts, wage scales, payslips and allotments.
- Free-text notes recorded by the Customer’s staff, and an activity log of changes.
We do not decide which of these fields a Customer fills in. We provide the tools; the Customer decides what to record and is responsible for having a lawful basis to do so.
3.3 Product analytics (we are controller)
We use Amplitude to understand how the Service is used, so we can improve it. Analytics are configured to be pseudonymous:
- We identify users by an internal random identifier (UUID). We do not send names or email addresses to Amplitude.
- We record events such as screens viewed and actions taken, together with context: workspace identifier, user role and permissions, office and group, interface language, platform (web / Android / iOS), application version.
- Amplitude receives standard technical data with each request, including IP address, device and browser type, and derives an approximate region from it.
- Our Amplitude project is hosted in Amplitude’s EU region.
- Analytics are disabled in development and preview environments.
Analytics data is cleared from the device identifier when you sign out. If you would prefer that we exclude your account from product analytics, write to hello@360crewing.com.
3.4 Push notifications (mobile app)
If you allow notifications, the app registers a device token with Google Firebase Cloud Messaging so we can deliver alerts about your work (for example, expiring documents or assignment changes). The token identifies a device installation, not a person by name. You can revoke notification permission at any time in your device settings.
3.5 Website and demo requests
If you submit the demo request form, we process the contact details and company information you provide, in order to contact you about 360 Crewing.
4. Why we process data, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the Service to a Customer under their subscription, including hosting crew records on their behalf | Performance of a contract with the Customer (Art. 6(1)(b)); for seafarer records, the Customer’s own basis as controller |
| Creating and securing user accounts, authentication, access control | Performance of a contract (Art. 6(1)(b)) |
| Security, abuse prevention, audit logs, backups | Legitimate interests in operating a secure service (Art. 6(1)(f)); legal obligation where applicable (Art. 6(1)(c)) |
| Product analytics and service improvement | Legitimate interests in understanding and improving our product (Art. 6(1)(f)), using pseudonymous data |
| Push notifications about your work in the Service | Performance of a contract (Art. 6(1)(b)); device-level permission is granted by you |
| Responding to demo requests and support enquiries | Steps prior to entering a contract and legitimate interests (Art. 6(1)(b) and (f)) |
5. Health data and other special categories
Crew records include medical certificates and fitness-for-duty information, which is a special category of personal data under Article 9 of the GDPR. This data is recorded by the Customer, as controller, in order to meet obligations in the field of employment law and maritime safety regulation — in particular the Maritime Labour Convention 2006 and the STCW Convention, which require operators to verify that seafarers hold valid medical certificates. The Customer is responsible for establishing the applicable condition under Article 9(2), typically Article 9(2)(b).
We apply the same technical and organisational safeguards to this data as to the rest of the crew record, and we access it only as needed to operate and support the Service.
6. Who we share data with
We do not sell personal data and we do not use it for advertising. We share it only with:
- The Customer whose workspace the data belongs to, and the users they authorise.
- Sub-processors who help us run the Service, under contract and only for that purpose:
| Sub-processor | Purpose | Processing location |
|---|---|---|
| Amplitude, Inc. | Product analytics (pseudonymous) | European Union |
| Google Ireland Ltd. / Google LLC (Firebase Cloud Messaging) | Delivery of push notifications to mobile devices | European Union and United States |
| Hosting and infrastructure providers | Application hosting, databases, file storage, backups | See section 7 |
We may also disclose data where we are legally required to do so, or where necessary to establish, exercise or defend legal claims.
7. Where data is stored
360 Crewing operates two separate infrastructure environments:
-
European environment — serving workspaces on
360crewing.com. Application servers, databases, uploaded documents and backups are located in the European Union. -
Russian environment — serving workspaces on
360crewing.ru. Personal data of individuals in the Russian Federation is recorded, systematised, accumulated, stored, amended and retrieved using databases located in the Russian Federation, in accordance with Article 18(5) of Federal Law No. 152-FZ.
A Customer’s workspace lives in one environment only; crew records are not copied between the two. Where a transfer outside the EEA is unavoidable — for example, push notification delivery through Google’s global infrastructure — it is carried out under the European Commission’s Standard Contractual Clauses or another transfer mechanism recognised under Chapter V of the GDPR.
8. How long we keep data
- Crew records. Retention is determined by the Customer as controller, based on their own legal obligations — for instance, maritime and employment law record-keeping duties. We keep the data for as long as the Customer’s subscription is active and they instruct us to. When a subscription ends, we delete or return the workspace data in accordance with our agreement with that Customer.
- User account data. Kept while the account is active, and deleted after the account is closed, subject to any retention required by law.
- Product analytics. Retained in pseudonymous form according to our Amplitude project settings.
- Backups. Deleted data may persist in encrypted backups for a limited period before being overwritten in the ordinary backup cycle.
9. How we protect data
- All traffic between the applications and our servers is encrypted with TLS (HTTPS).
- Each Customer’s workspace is isolated; users can only reach data in workspaces they are authorised for.
- Access within a workspace is limited by role and by granular permissions set by the Customer’s administrators.
- Passwords are stored only as salted hashes; we cannot read them.
- Changes to crew records are recorded in an activity log.
- Our own staff access production data only when needed to operate or support the Service.
10. Your rights
If you are in the EEA, the GDPR gives you the right to:
- Access the personal data held about you and receive a copy.
- Have inaccurate data corrected and incomplete data completed.
- Have data erased, where one of the grounds in Article 17 applies.
- Restrict processing, in the circumstances set out in Article 18.
- Receive data you provided in a portable format, and have it transmitted to another controller.
- Object to processing carried out on the basis of legitimate interests, including product analytics.
- Withdraw consent at any time, where processing is based on consent.
To exercise these rights in relation to data we control, write to hello@360crewing.com. We respond within one month, and will tell you if we need longer because a request is complex.
For crew records, please address your request to the crewing company that holds them. If you send it to us, we will forward it to that company without undue delay and support them in answering it.
You also have the right to lodge a complaint with a supervisory authority. In Estonia, this is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee. You may also complain to the authority where you live or work.
11. Deleting your account and data
To request deletion of your 360 Crewing user account and the personal data associated with it, send a request from your registered email address to hello@360crewing.com with the subject “Account deletion”.
What happens next:
- We verify that the request comes from the account holder.
- We confirm receipt within 5 working days and complete the deletion within 30 days.
- We delete your account, sign-in credentials, account settings and the analytics identifier linked to your account.
- Crew records inside a Customer’s workspace belong to that Customer, not to us. If your request concerns those records, we forward it to the Customer, who decides on it as controller. We cannot delete a Customer’s business records on our own initiative.
- We may retain the minimum data required by law — for example, accounting records — and residual copies in encrypted backups until those backups are overwritten in the ordinary cycle.
Deleting part of your data without closing your account
You can also ask us to delete specific personal data and keep your account open. To do so:
- Write to hello@360crewing.com from your registered email address, with the subject “Data deletion”.
- Name the data you want removed — for example your phone number, your postal address, a document you uploaded, or your product analytics history.
- We verify that the request comes from the account holder.
- We confirm receipt within 5 working days and complete the deletion within 30 days.
What we can delete this way: contact details and optional profile fields on your user account, uploaded files you added yourself, and your product analytics history. What we keep: the identifiers and sign-in data needed to keep your account working, data a Customer holds as controller in their own workspace (their decision, not ours — we forward the request to them), records we must retain by law, and residual copies in encrypted backups until those backups are overwritten in the ordinary cycle.
12. Children
The Service is a professional tool for maritime crewing operations. It is not directed at children and is not intended for use by anyone under 18. We do not knowingly collect data from children.
13. Cookies and similar technologies
The web application uses storage on your device for functional purposes only: keeping you signed in, remembering your selected workspace and your interface language. The mobile application stores the same information locally on your device. We do not use advertising cookies or third-party tracking pixels, and the Android and iOS applications do not use the device advertising identifier.
14. Changes to this policy
We may update this policy as the Service changes. The current version is always published at this address, with the date of the last update at the top. If a change materially affects how we handle your data, we will notify Customers by email or through the Service before it takes effect.
15. Contact
Kuraga Investment AS
Pronksi tn 5-5, Tallinn 10124, Estonia
hello@360crewing.com