Skip to content
VesselCall

Privacy Policy

Updated:

This Privacy Policy explains which personal data VesselCall processes about website visitors, people who request a demo, customer users and recipients of e-mails sent through VesselCall, why we process it and how long we keep it. We do not use analytics or advertising cookies on our website. For questions or requests, write to info@vesselcall.com.

1. Who we are

The controller for the processing described in this policy is the following company ("VesselCall", "we", "us"):

  • Legal name: VesselCall
  • Address: Türkiye
  • MERSİS number (Turkish central trade registry number): to be published once company registration is completed
  • E-mail: info@vesselcall.com

VesselCall offers two products to maritime service companies in Türkiye: Outreach, which sends introduction e-mails on behalf of our customers to the managers of commercial vessels approaching Turkish ports, and Data, which reports port calls and vessel information. Our website is vesselcall.com and our customer platform is app.vesselcall.com.

2. Our roles

  • As controller: for website visits, demo and contact requests, customer accounts, and the business contact database we compile from public sources.
  • As processor and intermediary service provider: when we send introduction e-mails on behalf of our customers. The customer is the sender of these e-mails. The customer is responsible for their content and for its obligations as a sender under Turkish Law No. 6563 on the Regulation of Electronic Commerce.

3. What personal data do we process?

3.1 Website visitors

  • Server logs: IP address, browser information (user agent), time of the request and the page requested. We keep these logs for security, error detection and abuse prevention, and delete them after 14 days.
  • Theme preference: If you choose light or dark mode, your choice is stored in your browser's local storage (localStorage) and is not sent to us. See our Cookie Policy.

There is no analytics, advertising or social media tracking on our website. Fonts and other files are served from our own server, so your browser does not contact third-party servers when it loads our pages.

3.2 Demo and contact requests

Through the form we collect your name, company, e-mail address, phone number (optional), ports of interest and your message. We use this information to answer your request, schedule a demo and continue the B2B sales conversation about your request. Providing the information is voluntary, but without your contact details we cannot answer you.

3.3 Customer platform users

Platform accounts are opened by the VesselCall team after a demo. To provide the service we process:

  • Account and company data: name, business e-mail address, phone, user role; the company's trade name, MERSİS number, tax and billing details.
  • Login and security records: login times, IP address, failed login attempts, two-factor authentication setting and audit records of administrative actions.
  • Service content: introduction templates and their translations, sender identity and domain settings, port selections, detection and sending logs, opt-out, exclusion and consent records.
  • Payment and invoice records: amount, date and status of payments, bank transfer records and invoices. Card payments are made on PayTR's payment page; we never see or store card details.
  • Contract records: which version of the Terms of Use and other documents was accepted, when, and from which IP address.
  • Support correspondence.

3.4 E-mail recipients

For introduction e-mails sent on behalf of our customers, we compile a business contact database from public sources: vessel and company roles from public ship registers (such as Equasis), and business e-mail addresses from company websites and other public web pages. For each address we store the address (URL) of the page where we found it and the date. VesselCall is the controller of this database. Recipients can find full details in our information for e-mail recipients.

4. Purposes and legal bases

Purpose Data Legal basis
Delivering the website securely, preventing attacks and abuse Server logs KVKK Art. 5(2)(f) (legitimate interests); GDPR Art. 6(1)(f)
Answering your demo or contact request Form data, correspondence KVKK Art. 5(2)(c) (entering into a contract), 5(2)(f); GDPR Art. 6(1)(b), 6(1)(f)
Following up on your request with B2B sales communication Form data, correspondence KVKK Art. 5(2)(f); GDPR Art. 6(1)(f)
Opening your platform account, providing the service and support Account, content and sending records KVKK Art. 5(2)(c); GDPR Art. 6(1)(b)
Account and infrastructure security Login and security records KVKK Art. 5(2)(f); GDPR Art. 6(1)(f)
Payments, invoicing and accounting Payment and invoice records KVKK Art. 5(2)(c), 5(2)(ç) (legal obligation); GDPR Art. 6(1)(b), 6(1)(f)
Statutory record keeping and proof in legal claims Commercial message records, contract and invoice records KVKK Art. 5(2)(ç), 5(2)(e); GDPR Art. 6(1)(f)
Building the business contact database and sending introduction e-mails for our customers Data listed in section 3.4 KVKK Art. 5(2)(f); GDPR Art. 6(1)(f), and Art. 6(1)(a) in countries that require prior consent

KVKK is Türkiye's Personal Data Protection Law No. 6698. The GDPR (EU General Data Protection Regulation) applies only where its scope covers the processing. For retention duties that arise under Turkish law, our basis under the GDPR is our legitimate interest in meeting those duties (Art. 6(1)(f)).

You can object to processing based on legitimate interests on grounds relating to your particular situation. Your right to object to direct marketing is absolute: if you object, we stop using your data for that purpose.

5. Who receives personal data?

We do not sell or rent personal data. We share it only with the following recipients, and only as far as necessary:

  • Hosting provider: our servers are in a data center in Finland, in the European Union. We plan to move the service to a data center in Türkiye later.
  • PayTR (payment institution, Türkiye): to process card payments. Card details are entered directly on PayTR's page.
  • AI service providers: to translate template text and to research publicly available company contact information. Only template text is sent for translation, never recipient personal data. Information typed directly into a template (for example a name in the text) becomes part of the translated text. Research uses company information such as company name, IMO company number, address and country. These providers may be located outside Türkiye and the EU, for example in the United States.
  • E-mail delivery: e-mails are sent through our own infrastructure; we do not use a separate e-mail delivery service.
  • Our customers: for an e-mail sent on a customer's behalf, the recipient address, the vessel concerned and the delivery status are visible in that customer's records. We do not provide bulk exports of our business contact database.
  • Public authorities: where required by law (for example the Turkish Ministry of Trade, the Turkish Personal Data Protection Board, courts or tax authorities).
  • Professional advisers: where necessary, legal and accounting advisers bound by confidentiality.

6. International transfers

Because our servers are in Finland and some providers are outside Türkiye, personal data is transferred abroad. For these transfers we use the standard contract mechanism announced by the Turkish Personal Data Protection Board under KVKK Art. 9. Where the GDPR applies to a transfer, we rely on appropriate safeguards under Chapter V GDPR, such as the European Commission's standard contractual clauses. To receive more information or a copy of the safeguards, write to info@vesselcall.com.

7. How long do we keep data?

Data Retention period
Website server logs 14 days
Demo and contact requests 2 years after the last contact
Customer account data For the term of the contract, then for statutory retention periods (for example 10 years for commercial books and records under Art. 82 of the Turkish Commercial Code No. 6102; 5 years for tax records under Art. 253 of the Tax Procedure Law No. 213)
Platform login and audit records 24 months
Customer content after account closure (templates, settings) Deleted or anonymized within 30 days, except records under statutory retention and opt-out lists
Commercial message records (detections, sent e-mails, content archive, opt-out records) At least 3 years (Art. 13(2) of the Turkish Regulation on Commercial Communication and Commercial Electronic Messages)
Consent records 3 years after the consent ends (same Regulation, Art. 13(2))
Entry on the global suppression list (one-way hash of the address) No fixed end date; needed so that the address is never e-mailed again
Business contact database As long as the information is current and needed for the service; we re-check it regularly, stop using invalid addresses and delete data on request

When a retention period ends, we delete, destroy or anonymize the data. If a dispute or official investigation is ongoing, we may keep the relevant records until it is resolved.

8. How do we protect data?

We use technical and organizational measures to protect personal data. For example, all connections are encrypted (HTTPS), passwords are stored as hashes, two-factor authentication is available, secret keys are stored encrypted, customer data is kept separate, access is limited to authorized persons and administrative actions are logged. If a personal data breach occurs, we make the notifications required by law.

9. Your rights

Under KVKK Art. 11 you can ask us whether we process your personal data, request information about it, learn the purpose of processing and whether data is used for that purpose, know the third parties it has been transferred to, request correction, deletion or destruction, request that these actions be notified to third parties who received the data, object to a result against you that arises solely from automated analysis, and claim compensation for damage caused by unlawful processing.

Where the GDPR applies, you also have the rights of access, rectification, erasure, restriction of processing, objection and data portability, the right to withdraw consent at any time where processing is based on consent, and the right to lodge a complaint with a supervisory authority, in particular in the EU country where you live or work. The European Data Protection Board lists the supervisory authorities.

To exercise your rights, write to info@vesselcall.com or send a letter to Türkiye. We respond within 30 days, free of charge as a rule, in writing or electronically. Our Personal Data Notice explains the formal application procedure under Turkish law and your right to complain to the Turkish Personal Data Protection Board.

10. Automated decision-making

We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. Outreach automatically selects which company receives an introduction e-mail, based on vessel, port and ship register data; this selection does not profile individuals.

11. Changes to this policy

We may update this policy when our services or the law change. The current version is always published on this page, and we inform our customers separately about material changes.

12. Contact

For privacy questions and requests: VesselCall, Türkiye, info@vesselcall.com.

This text is for information purposes and may be updated as our services or the law change.