GDPR Readiness Statement · Updated August 19, 2026 · Document Version: 1.1
PortFlow is a maritime operations platform for port agencies. Many of the agencies that use it work with shipping companies, vessel owners and crew who fall under European Union data protection rules, even when the agency itself operates entirely outside the EU.
This statement describes how personal data is actually handled inside the product today: who processes it, where it sits, what is encrypted, what can be exported and what cannot.
PortFlow is a data processor for the agencies that use it, and a data controller for its own account holders and waitlist contacts. It holds no GDPR certification and has not been independently audited. Nothing below is a forecast; anything not stated here has not been verified.
The General Data Protection Regulation (Regulation (EU) 2016/679) applies to:
Maritime agencies routinely handle data about European shipping companies, EU citizen crew, EU based vessel owners and European counterparties. That data is covered by GDPR even when your agency sits entirely outside the EU. It does not follow that any particular software makes you compliant: the obligations stay with your agency, and no software vendor can take them over.
PortFlow has no signed or published Data Processing Agreement. The list below is the scope a DPA would need to cover. None of it is in force until one is executed:
Status: in preparation
Nothing is signed. We will not send you a document that does not exist yet.
If your organisation needs a DPA, email support@portflow.tech with your organisation name, your data protection contact and the processing you intend, and we will work through the scope with you.
| Sub-Processor | Function | Processing region |
|---|---|---|
| Neon Postgres | Application database | United States (default region) |
| Vercel | Hosting for the application and this site | Global edge network |
| Anthropic | Assistant on this site, and an internal review of new signups | United States |
| Resend | Transactional and waitlist email delivery | United States |
| Upstash Redis | Rate limiting and budget counters on this site | United States (default region) |
| Zoho Mail | Hosted mailboxes for support and general correspondence | United States |
| Vercel Analytics | Traffic measurement, this site only | Global edge network |
The last two run only on the public marketing site, never inside the application. Regions reflect the current default configuration and are not contractual. This list is maintained on this page; a contractual right to be notified of changes and to object only exists once a DPA is signed.
Application database: Neon Postgres in the United States. Application and marketing site: Vercel edge network. Crew identity fields are encrypted inside the application before they ever reach the database.
Neon and Vercel both offer EU regions, so an EU resident deployment is technically possible. PortFlow has not provisioned one, has not tested one, and no customer runs on one today. Treat it as a scoping conversation, not a product feature.
To scope it, contact info@portflow.tech
In the default configuration, personal data is processed in the United States. Those transfers currently rest on the Standard Contractual Clauses and data processing terms of each provider listed above. PortFlow has no SCCs of its own signed with customers, because no DPA has been executed yet. The technical measures actually in place are TLS in transit, provider encryption at rest, and application level AES-256-GCM on crew passport number, nationality, date of birth and gender marker before they are written to the database.
Who to contact depends on the data. Personal data your agency loads into PortFlow, such as crew and client contacts, is yours as controller: a crew member exercises these rights against your agency, and PortFlow assists you in answering. Personal data PortFlow holds about its own account holders and waitlist contacts is ours as controller, and those requests come to us.
A copy of the personal data held, the purposes of processing, the recipients and the criteria used to set retention.
Correction of inaccurate or incomplete records, including crew details and identity document data.
Deletion of personal data. Two things survive: disbursement account evidence carrying a retention date or a legal hold set by your agency, and audit log entries, which are kept as a tamper evidence record of who did what.
Processing limited while accuracy is verified or a dispute is resolved.
Exports are per module, in CSV or XLSX: audit log, invoices, payments, quotations, vessels, port services, provisions, water supply and client account statements. There is no one click export of a whole account; a full extract is assembled by hand on request.
An objection to direct marketing stops that processing on receipt. No third party analytics runs on the marketing site or in the application. Vercel Analytics runs on the marketing site only, first party, aggregated and cookieless, so there is no tracking profile to object to.
No automated decision grants, denies or restricts access to PortFlow. A Claude model does classify new signups for internal lead triage, using company name, email domain, approximate location from IP, phone and ports operated. It runs after the account already exists and cannot block or reverse a signup.
One month is the statutory deadline in Art. 12(3), extendable by two further months for complex requests with notice to the person. PortFlow does not publish a faster service level it has not measured. To exercise a right against PortFlow as controller, email support@portflow.tech; we will ask you to confirm your identity before acting.
What PortFlow stores about a crew member: name, identity document type and number, nationality, date of birth, gender marker, rank, vessel assignment, and STCW certificate types with their expiry dates, including the validity of a medical certificate. It does not store salary, medical records or next of kin details.
Passport number, nationality, date of birth and gender marker are encrypted with AES-256-GCM at the application layer, with a blind index so search still works without decrypting the column. That sits on top of the encryption at rest the database provider already applies.
Your agency controls this data. PortFlow stores and processes it. If the crew member is in the EU, their GDPR rights are exercised against your agency.
A company name or registration number is not personal data. The name, email address and phone number of a person at that company is. Both live inside PortFlow client records, so treat a client record as containing personal data rather than assuming it is purely commercial.
PortFlow generates the IMO FAL paperwork from the port call and tracks the pre-arrival submission deadline for you, in the port's own local time, so it stays correct across a daylight saving change. Which forms a given call needs is shown in the product.
Generated documents are stored against the port call, content, PDF and XML together, and stay for as long as that port call exists. Deleting the port call deletes them. There is no automatic purge after a fixed number of days.
PortFlow does not transmit anything to a port authority, to customs or to immigration. Preparing and submitting the declaration stays with your agency, through whatever channel the port requires.
A compliance page is worth less than nothing if a buyer can knock a claim down. So here is the other half:
We acknowledge in writing and respond within one month, the statutory limit in Art. 12(3). Complex requests can be extended by two further months, and we tell you if that happens.
Privacy & data requests: support@portflow.tech
Security reports: security@portflow.tech
General: info@portflow.tech
PortFlow © 2026 · All Rights Reserved · Document Version 1.1