Legal
Privacy Policy
How the Yacht Workers Council ("YWC", "we", "us", "our") collects, uses, discloses and protects your personal and sensitive data across the Professional Registry and Digital Passport, and the rights you have under GDPR.
YACHT WORKERS COUNCIL PROFESSIONAL REGISTRY AND DIGITAL PASSPORT PRIVACY POLICY
Introduction
The Yacht Workers Council (the "YWC," "we," "us," or "our"), with our registered office at 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF, operates the Professional Registry and Digital Passport services (the "Services"). For the purposes of the General Data Protection Regulation (GDPR), the YWC is the Data Controller of your personal data. We are committed to protecting the privacy and security of the personal and sensitive data of yacht workers who use our Services. This Privacy Policy describes how we collect, use, disclose, and protect your information when you use the Professional Registry and Digital Passport.
1. Information we collect
We collect information necessary to operate, maintain, and verify the professional credentials associated with your Digital Passport and entry in the Professional Registry. This includes:
- Identifiers and Contact Data: Your name, email address, physical address, phone number, date of birth, and unique registry identification number.
- Special Categories of Personal Data (Sensitive Data):
- Verification Data: Passport/ID (securely stored) and certification documents.
- Employment Data: Sea service records, vessel history, and roles held.
- Compliance Data: Certificate validity and training records.
- Optional Data: References, endorsements, and professional notes.
- Processing this data is necessary for the purposes of carrying out the obligations and exercising specific rights of the data controller in the field of employment and social security law (Article 9(2)(b) of the GDPR).
- Account and Usage Data: Information related to your registration, preferences, and details necessary to help you sign in and upload files across devices. We collect performance data and crash analytics to improve service reliability and for troubleshooting.
All user data collected pseudonymously, or data that can reasonably be re-associated with an individual, must be disclosed.
2. How we use your information and our lawful basis for processing
We use the information collected exclusively for the following purposes, based on the corresponding lawful grounds under GDPR:
- Service Delivery and Account Management: To maintain the Professional Registry, create and issue your Digital Passport, and verify your professional status and credentials. Lawful Basis: Performance of a contract with you.
- Security and Protection: To detect and block threats, spam filtering, virus detection, malware protection, and prevent abuse of our services. We process your content to allow for file search within your individual account. Lawful Basis: Legitimate interests (ensuring the security and integrity of the Services).
- Communication: To inform you of service changes and user-to-user activity. Lawful Basis: Legitimate interests (managing our relationship with you and informing you about essential service updates).
We do not use your content for advertising purposes.
4. International data transfers
Your personal data may be transferred to, and stored at, a destination outside the European Economic Area (EEA) and the UK. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy. Where we transfer your data outside the EEA or UK, we ensure a similar degree of protection is afforded to it by implementing at least one of the following safeguards:
- We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission.
- Where we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe (Standard Contractual Clauses).
5. Data security and storage
To ensure your information is as safe as possible with YWC we have:
Coded the YWC Application in Strong Coding Frameworks:
Strong Coding Frameworks enhance security with stronger default password hashing (increased bcrypt rounds), refined encryption techniques, and streamlined, secure configuration. It offers improved protection against SQL injection, cross-site request forgery (CSRF), and cross-site scripting (XSS), alongside a simplified structure for faster, more secure application development.
Key Security and Architectural Benefits
- Enhanced Password Security: Strong Coding Frameworks upgrades its encryption techniques, including higher bcrypt rounds for password hashing.
- Streamlined Configuration: The number of configuration files is significantly reduced, decreasing the attack surface and potential for configuration errors.
- Improved Authentication/Authorisation: The framework continues to provide robust tools for verifying identity and controlling user actions.
- Modernised Structure: New applications are much more streamlined, reducing bloat and focusing on essential security features.
- Database Security Improvements: Includes improved support for modern database security configurations (MariaDB/MySQL).
Core Security Features Carried Forward
- CSRF Protection: Automatically generates tokens to prevent forgery attempts.
- Input Validation: Robust built-in mechanisms to sanitise data.
- Secure Routing: Improved speed and secure handling of application routes.
- Graceful Encryption Key Rotation: Enables secure, seamless rotation of encryption keys without downtime.
- Performance: Enhanced speed due to better routing and optimisation.
- Simplified Maintenance: A cleaner codebase makes maintenance easier.
- Health Routing: Dedicated routes for monitoring application health.
Hosted with Cloudways:
Key Security Features:
- Dedicated Firewalls: Servers use OS-level firewalls and Imunify360 to filter malicious traffic and block brute-force attacks.
- Automatic Backups: Automated backups are managed, ensuring data safety.
- SSL & Security: SSL and secure patching, along with Malware Protection add-ons.
- Managed Environment: Cloudways handles server-level security.
Used Reliable 3rd Party Solutions and minimise data risks:
We use Google Cloud Services GDPR and Google Cloud which maintain alignment to GDPR and provides safe solutions which enhance the YWC service. We use Tesseract OCR to process images captured by users and Google Vision API to process pdf. Added by users. Both activities are delivered on a scan, send and delete protocol meaning there is minimal data storage with the provider awaiting the confirmation the files have been received, which takes microseconds. Security maintained by Google Cloud and services are in the link.
Google Analytics & Ads
We use Google Analytics (GA4) and Google Ads provided by Google Ireland Limited.
- Data Purpose: Data is collected to analyse website traffic, user behaviour, and to deliver personalised advertisements based on your interests.
- Data Points: Collected data may include truncated IP addresses, unique device identifiers, and on-site interactions (e.g., button clicks, page views).
- Legal Basis: We process this data only with your explicit prior consent (Art. 6(1)(a) GDPR).
- Opt-Out: Users can withdraw consent at any time via our Cookie Settings or by using the Google Analytics Opt-out Browser Add-on: https://tools.google.com/dlpage/gaoptout
- Third-Party Link: Refer to Google's Privacy & Terms for details on how they process your data: https://policies.google.com/technologies/partner-sites
Your Devices:
We cannot control the risk users expose themselves to within their environments; it is suggested that all users maintain dual factor authentication on all devices.
6. Data retention
We retain your personal data only for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
- To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data, and whether we can achieve those purposes through other means, and the applicable legal requirements.
- Since your Digital Passport and entry in the Professional Registry are continuous professional credentials, we will generally retain your core professional data for the duration of your registration with the YWC, and for a period thereafter as required by law or our legitimate interests in record keeping. You may request data deletion at any time, subject to legal limitations.
7. Your rights and choices
Under GDPR, you have enhanced rights regarding your personal data:
- Right to Access (Rectification): You can review and update your professional and contact information within your YWC account. You also have the right to request a copy of the personal data we hold about you.
- Right to Erasure (Data Deletion / Right to be Forgotten): We provide a way for users to request that their data is deleted. We will comply with this request within 14 working days unless we have a legal obligation to retain the data.
- Right to Data Portability: You have the right to request that your personal data be transferred to you or to a third party in a structured, commonly used, machine-readable format.
- Right to Restriction of Processing: You have the right to ask us to suspend the processing of your personal data in certain scenarios (e.g., if you contest its accuracy).
- Right to Object: You have the right to object to the processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground.
- Right to Withdraw Consent: Where we are relying on consent to process your personal data (such as for certain sharing purposes), you have the right to withdraw that consent at any time.
Where data collection is marked as "Optional," you have the ability to opt into or opt out of that collection, and you can use the Service without providing it.
8. Changes to this privacy policy
We reserve the right to modify this Privacy Policy. We will inform you of service changes, which may include policy updates. When we make material changes, we will provide you with notice through the Services or by email before the change becomes effective. We encourage you to review our policy periodically.
9. Contact us and supervisory authority
If you have questions or concerns about this Privacy Policy or our data handling practices, please contact the Yacht Workers Council at:
- Registered Address: 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF
- Data Protection Officer (DPO): Captain James Alexander Battey
You also have the right to lodge a complaint with a supervisory authority, particularly in the Member State of your habitual residence, place of work, or where the infringement of the GDPR is alleged to have occurred.