Skip to content
VesselCall

Information for E-mail Recipients

Updated:

You received this e-mail because a maritime service company in Türkiye wants to reach your company. Public ship registers list your company as responsible for a vessel approaching a port where the sender offers its services. The e-mail was sent through VesselCall, in that company's name. You can stop all further e-mails sent through VesselCall with one click, at any time.

1. Why did I receive this e-mail?

  • VesselCall's customers are maritime service companies in Türkiye, such as ship chandlers, ship agents and technical service firms.
  • Our system uses AIS position data to detect commercial vessels approaching the Turkish ports our customer has selected.
  • Using the vessel's IMO number, it identifies the company listed in public ship registers (such as Equasis) as the vessel's ship manager, commercial manager, ISM manager or registered owner.
  • An e-mail introducing our customer's services is then sent to a business e-mail address that this company publishes on its own website or on other public web pages.

The e-mail is sent in our customer's name and from our customer's own domain, so your replies go directly to them. That is why our brand does not appear in the body of the e-mail; the unsubscribe and privacy notice links at the bottom are operated by us. The sender's name and contact details are at the bottom of the e-mail; senders based in Türkiye also show their trade name and MERSİS number (Turkish central trade registry number) there.

To keep e-mails rare and relevant, we apply default limits: the same sender does not e-mail about the same vessel twice within 7 days and sends at most 3 e-mails about it in 90 days, and it sends at most 1 e-mail to the same company within 3 days. No e-mails are sent about vessels or to companies that appear on sanctions lists (for example the US OFAC, UK and EU lists).

2. Your right to object, and how to stop these e-mails

You have the right to object, at any time and free of charge, to the use of your data for direct marketing, which includes sending you introduction e-mails. You do not need to give a reason. If you object, we stop using your data for this purpose.

To object or opt out:

  • Open the unsubscribe link at the bottom of the e-mail and confirm with one click on the page that opens. Many e-mail programs also show an "Unsubscribe" option next to the sender's name; it works the same way.
  • Or write to info@vesselcall.com.

What happens next:

  • Your request is processed immediately, and any e-mails already queued for your address are canceled.
  • We add a one-way hash of your address to our global suppression list. A hash is a fixed code derived from your address that we use only to recognize it. From then on, no e-mail is sent to that address through VesselCall on behalf of any of our customers, even if the address is found again in a public source later.
  • If you want all addresses at your company's domain to be excluded, just write to info@vesselcall.com.

Why do we ask you to confirm? Some corporate security systems open links in e-mails automatically. The confirmation button makes sure that an automatic scan does not unsubscribe you by mistake.

You can also object, on grounds relating to your particular situation, to other processing based on our legitimate interests (Art. 21(1) GDPR) by writing to info@vesselcall.com.

3. Who is responsible for your data?

  • The business contact database (finding companies and business e-mail addresses, verifying them, and keeping opt-out lists): the controller is VesselCall ("VesselCall", "we", "us"), Türkiye, info@vesselcall.com.
  • Sending the e-mail: the sender is our customer. Our customer is responsible for the content of the e-mail and for its obligations as a sender under Turkish Law No. 6563 on the Regulation of Electronic Commerce. VesselCall sends the e-mail on the customer's behalf, as its processor and intermediary service provider.
  • Your replies: replies go directly to the sender's own mailbox, and the sender handles them under its own responsibility.

4. Where does the data come from?

  • Public ship registers (such as Equasis): vessel identity (IMO number, name, type, flag), company name, IMO company number, address, and the company's role for the vessel.
  • The company's official website and other publicly accessible web pages: business e-mail addresses. We find these pages with search engines and AI-assisted research. We never use an address found through AI-assisted research automatically unless we have confirmed that it really appears on the source page.
  • AIS position data: only to detect the vessel's position and its approach to the port. This data relates to the vessel, not to you.
  • Corrections suggested by our customers: we check them before use.
  • Delivery feedback: if an e-mail to an address bounces permanently, we mark the address as invalid and stop using it.

For each address we store the address (URL) of the page where we found it and the date. You can ask us for this information.

5. What data do we hold?

  • Company data: name, IMO company number, address, country, website.
  • Vessel data: the vessels concerned and your company's role for them.
  • Business contact details: mainly the e-mail address and, where available, a department label (for example operations or purchasing).
  • Source data: the page where the address was found, and the date.
  • Verification data: a check that the address's domain accepts e-mail (MX record), and bounce records.
  • Sending records: date, sending customer, vessel and port concerned, content of the e-mail sent and delivery status.
  • Opt-out and objection records, and consent records for countries that require prior consent.
  • Your correspondence with us.

General addresses (such as info@ or ops@) are often not personal data. An address that contains a person's name is personal data. This notice applies in both cases.

E-mails sent through VesselCall currently contain no tracking pixels, and we do not track opens or clicks.

6. Why do we use the data, and on what legal basis?

Our purposes:

  • sending e-mails on behalf of our customers that introduce maritime services related to vessels calling at Turkish ports,
  • keeping an accurate and current business contact database and avoiding e-mails to the wrong recipient,
  • applying opt-out and objection requests,
  • checking vessels and companies against sanctions lists,
  • meeting statutory record-keeping duties and protecting our rights in legal claims,
  • preventing abuse and keeping our sending infrastructure secure.

Our legal bases under the GDPR, where it applies:

  • Legitimate interests (Art. 6(1)(f) GDPR). Our interest, and our customers' interest, in offering maritime services to the companies responsible for vessels arriving in Türkiye, and in keeping an accurate business contact database. Recital 47 GDPR recognizes that processing for direct marketing may be regarded as a legitimate interest. We balance these interests with your rights through these safeguards: we only use addresses published for business contact, the content relates to your business role, frequency limits apply, every e-mail has a one-click opt-out, opt-outs go on a global suppression list, and we do not track you.
  • Consent (Art. 6(1)(a) GDPR). Where the rules of the recipient's country require prior consent for business e-mail (for example Germany and Greece), an e-mail is only sent if a valid consent record exists. You can withdraw your consent at any time; this does not affect processing that took place before the withdrawal.
  • Record keeping and legal claims. Keeping the records that Turkish law requires us to keep, and establishing or defending legal claims, are also based on our legitimate interests (Art. 6(1)(f) GDPR).

Because of sanctions, we do not send any e-mails to some countries.

For recipients in Türkiye: under Turkish Law No. 6563, commercial electronic messages may be sent to merchants and tradespeople without prior consent (Art. 6(2)). Once you use your right to refuse, no further messages may be sent to you without your consent. Under Türkiye's Personal Data Protection Law (KVKK), we rely on legitimate interests (Art. 5(2)(f)) and, where you published the address yourself for business contact, on the fact that you made it public (Art. 5(2)(d)). In that case we use it only in line with that purpose, for business contact.

7. Who can see the data?

  • The customer who sent you the e-mail: in its own records it sees your business e-mail address, the vessel and port the e-mail was about, the delivery status, and whether you have opted out.
  • Our service providers: our hosting provider (data center in Finland, EU) and the AI service providers we use to research company contact information. This research uses company information such as company name, IMO company number, address and country. Only template text is sent for translation, never your data.
  • Public authorities: where required by law.

We do not sell or rent our business contact database, and we do not hand it over to our customers in bulk.

8. Is the data transferred outside the EU or Türkiye?

VesselCall is based in Türkiye, and our servers are in Finland (EU). AI service providers may be located outside Türkiye and the EU, for example in the United States. For these transfers we use the standard contract mechanism under KVKK Art. 9 and, where the GDPR applies, appropriate safeguards under Chapter V GDPR, such as standard contractual clauses. You can request a copy of the safeguards at info@vesselcall.com.

9. How long do we keep the data?

  • Business contact details: as long as they are current and needed for the service. We re-check them regularly, stop using addresses that bounce, and delete them on request.
  • Sending records, content archive and opt-out records: at least 3 years, as required by Art. 13(2) of the Turkish Regulation on Commercial Communication and Commercial Electronic Messages.
  • Consent records: 3 years after the consent ends.
  • The hash on our global suppression list: no fixed end date, because deleting it would make it possible to e-mail you again.

If you ask us to delete your data, we delete your contact record and keep only the hash of your address on the suppression list. Records we must keep by law (for example the record of e-mails already sent) are kept until that period ends and are not used for any other purpose.

10. What are your rights?

Where the GDPR applies, you have the right to:

  • access your data and receive a copy,
  • have inaccurate data corrected,
  • have your data erased,
  • restrict the processing,
  • object to the processing (see section 2),
  • receive your data in a portable format, where applicable,
  • withdraw consent at any time, where processing is based on consent.

Under Turkish law (KVKK Art. 11) you have similar rights, including the right to learn whether and how your data is processed, to whom it has been transferred, and to claim compensation for damage caused by unlawful processing.

To use your rights, write to info@vesselcall.com. We respond within 30 days, free of charge, in writing or electronically. We may ask for information to confirm that the address belongs to you. Our Personal Data Notice explains the formal application procedure under Turkish law.

You can also lodge a complaint with a supervisory authority, in particular in the EU country where you live or work, or with the Turkish Personal Data Protection Board (KVKK Art. 14). The European Data Protection Board lists the EU supervisory authorities.

11. Do we make automated decisions about you?

Our system automatically decides which company receives an e-mail, based on vessel, port and ship register data and the rules described on this page. This selection has no legal effect on you and does not affect you in a similarly significant way. We do not profile individuals.

12. How to contact us

VesselCall, Türkiye, info@vesselcall.com. For all of our privacy practices, see our Privacy Policy.

This text is for information purposes and may be updated as our services or the law change.