← Back to portflow.tech
⚖️

GDPR & Compliance

GDPR Readiness Statement · March 24, 2026 · Document Version: 1.0

PortFlow is a maritime logistics SaaS platform designed for agencias portuarias throughout the Caribbean and Latin America. Many of our customers operate internationally and work with shipping companies that fall under European Union data protection requirements.

This statement outlines PortFlow's commitment to GDPR compliance and explains how we protect the personal data of users, crew members, and other individuals referenced in maritime operations.

"We treat your data like it's our own. This is our core principle."

1. GDPR Compliance Overview

1.1 What is GDPR?

The General Data Protection Regulation (GDPR) is the EU's comprehensive data protection law that applies to:

  • · Any organization processing personal data of EU residents
  • · Organizations anywhere in the world (not just EU companies)
  • · Violations can result in fines up to €20 million or 4% of global revenue

1.2 Why Does This Matter for Maritime Agencies?

Maritime agencies often work with European shipping companies, EU-citizen crew members, EU-based vessel owners, European customers and partners, and EU regulatory authorities. This data falls under GDPR protection, even if your agency is located outside the EU.

2. Data Controller vs. Data Processor

Your Role: Data Controller

  • · You decide what data to collect
  • · You decide how to use that data
  • · You are responsible for the legal basis for processing
  • · You are responsible for data subject rights requests
  • · You own your data

PortFlow's Role: Data Processor

  • · We process data according to your instructions
  • · We implement security measures you require
  • · We help you comply with GDPR
  • · We delete data when you request it
  • · We are your data security provider

3. Data Processing Agreement (DPA)

3.1 DPA Availability

PortFlow provides a comprehensive Data Processing Agreement that includes:

Definition of personal data and processing scope
Security and confidentiality obligations
Your rights to audit PortFlow's security
List of sub-processors (Neon, Vercel, Anthropic, Zoho)
Data breach notification procedures
Assistance with data subject rights requests
Assistance with impact assessments (DPIA)
Instructions for data deletion and return

Status

DPA is available upon request and will be finalized by Q2 2026.

To request a DPA, email privacy@portflow.tech with your organization name, data protection officer contact, and intended use cases.

3.2 Sub-Processors

Sub-ProcessorFunctionLocation
Neon PostgresDatabase storageUS (default); EU available
VercelApplication hostingGlobal
Anthropic ClaudeChatbot AIUS
Zoho CRMSupport / CRMUS

You will be notified of any sub-processor changes and have the right to object.

4. Data Residency & International Transfers

Default Configuration

Database: Neon Postgres on AWS us-east-1 (Northern Virginia, USA). Application servers: Vercel Global Edge Network.

EU Data Residency Option

Available Now

For organizations requiring GDPR adequacy compliance, we can configure your environment to keep data within EU/EEA boundaries.

  • · Database: Neon Postgres on AWS eu-west-1 (Ireland)
  • · Application: Vercel EU infrastructure
  • · Setup time: 5–10 business days
  • · Requires separate Data Processing Agreement

Contact: sales@portflow.tech

Legal Basis for Transfers

For default US-based configuration: Standard Contractual Clauses (SCCs) approved by the EU Commission. PortFlow implements encryption making data unreadable, contractual restrictions on government access, and transparency procedures.

5. Data Subject Rights Under GDPR

Art. 15

Right to Access

30 calendar days

Request a copy of all personal data we hold, including how it's processed, who we share it with, and retention periods.

Art. 16

Right to Rectification

10 business days

Correction of inaccurate or incomplete data (e.g., vessel name, crew member information).

Art. 17

Right to Erasure

30 days

Deletion of personal data, including crew information. Limited by maritime legal requirements (7-year retention for some data).

Art. 18

Right to Restrict Processing

10 business days

Limit how we process your data while you resolve a dispute or verify accuracy.

Art. 20

Right to Data Portability

30 days

Export your data in portable, machine-readable format (CSV, JSON) suitable for transfer to another service provider.

Art. 21

Right to Object

Immediate

Object to marketing communications or analytics. Honored immediately.

Art. 22

Automated Decision-Making

N/A

PortFlow does NOT use automated decision-making to determine access to services or restrict features. Humans make all important decisions.

To exercise any right, email privacy@portflow.tech with proof of identity.

6. Maritime-Specific Data Considerations

Crew Member Personal Data

Maritime operations involve names, passport numbers, visas, medical information, certifications, salary, and next-of-kin contacts. This is personal data covered by GDPR if crew are EU residents.

Your agency controls this data (controller). PortFlow provides secure storage (processor). Crew members retain GDPR rights including access and deletion.

Vessel Owner & Company Data

Company names and details are NOT personal data. Individual names, email addresses, and phone numbers within companies ARE personal data under GDPR. PortFlow separates personal and non-personal data where possible.

Port Authority Data

Cargo declarations, crew lists, customs information submitted to port authorities may require specific handling. PortFlow helps you organize data for submission and does not retain submission copies beyond 30 days.

7. Compliance Roadmap

Q2 2026Planned
  • · Data Processing Agreement finalized and available
  • · EU data residency infrastructure deployed
  • · GDPR readiness self-assessment completed
Q1 2027Planned
  • · Independent GDPR compliance audit scheduled
  • · Verification of lawful basis, data subject rights, data protection measures, sub-processor compliance, and cross-border transfer mechanisms
Q2 2027Planned
  • · GDPR audit results published
  • · Audit certificates issued
  • · Remediation of any findings completed

8. Data Breaches & Notifications

Our Commitment

  • · Notify you within 24 hours of discovery
  • · Provide details: what data, when, how many affected
  • · Explain what we're doing to fix it
  • · Advise steps you should take

Your GDPR Obligations

  • · Notify EU data subjects within 72 hours
  • · Notify relevant data protection authority
  • · (We'll assist, but you're responsible for notification)

Our Philosophy

"We treat your data like it's our own."

·We encrypt it the way we'd want our data encrypted
·We retain it only as long as necessary
·We delete it when you ask
·We protect your crew members' privacy
·We respond quickly to requests
·We respect the trust you place in us

Contact & Support

Response timeline: Acknowledgment within 2 business days · Preliminary response within 15 days · Final response within 30 days

PortFlow © 2026 · All Rights Reserved · Document Version 1.0