Privacy policy

Version 2026-07-02

1. Who we are KeelTruth.com is operated by the project operator (contact us via the Feedback form on the site). This policy explains how we process personal data under the EU General Data Protection Regulation (GDPR). 2. What we process - Account data: email, password hash, public nickname, profile fields you enter, locale preferences. - Content you publish: Marketplace listings, ratings, protocols, tips submissions. - Identity document data (optional): passport or national ID number, document type, citizenship, place of birth — only when you or a guest enter them for crew lists or profile defaults. Numbers are stored encrypted. - Crew list data: names, dates of birth, sex, residence, embarkation details for charter manifests. - Technical data: session cookies, CSRF tokens, consent records, server logs. - Analytics (only with consent): usage via Google Analytics / Microsoft Clarity. 3. Purposes and legal bases (GDPR Art. 6) - Providing the service (account, protocols, Marketplace, crew lists): contract (Art. 6(1)(b)). - Identity document data in your profile or crew lists: your explicit consent (Art. 6(1)(a)); you may withdraw consent at any time. - Guest invite forms: consent of the data subject (Art. 6(1)(a)). The skipper who sends the invite must have a lawful reason to collect guest data for the charter; KeelTruth provides the tool only. - Cookie analytics: consent (Art. 6(1)(a)). - Security, fraud prevention, legal obligations: legitimate interest or legal duty (Art. 6(1)(f)/(c)). Passport numbers are personal data but not special-category data under Art. 9 unless you upload biometric scans (we do not). 4. Who receives data We do not sell personal data. We do not show your email or passport details to other users. Charter companies receive crew list exports only from you (the skipper). Hosting and email providers act as processors under contract. 5. Retention - Account data: until you delete your account or ask for erasure. - Crew lists and identity fields: until you delete them, or automatically within 90 days after the disembarkation date on the list (whichever is sooner). - Consent audit logs: as required for accountability (typically up to 3 years). - Server logs: limited retention for security. 6. Your rights Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Contact us via Feedback. You may lodge a complaint with the competent supervisory authority in your EU Member State under GDPR Art. 77. 7. Security HTTPS, access controls, encrypted storage for document numbers, CSRF protection on forms. 8. International transfers If analytics providers process data outside the EEA, we rely on appropriate safeguards (e.g. EU Standard Contractual Clauses) where required. 9. Changes We publish policy version dates. Material changes may require renewed consent for identity data processing.