Effective date: 6 October 2026 Version: 1.0
Language notice: This is an English translation provided for your convenience. The Turkish version is the binding text; in the event of any discrepancy between the two, the Turkish version prevails. See Veri İşleme Sözleşmesi.
This agreement governs the data processing relationship between the shipping company using Pelastra and Pelastra, pursuant to Article 12(2) of Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and Article 28 of the European Union General Data Protection Regulation (GDPR). It forms an integral part of the Terms of Service; in the event of a conflict between the two texts concerning personal data, this agreement applies.
1. Parties and roles
| Data controller ("Company") | The legal or natural person that holds a company account on Pelastra and uses the platform for its own personnel, vessels and operations |
| Data processor ("Pelastra") | Melih Can Akbulut — Soğanlık Yeni Mah. Atatürk Cad. No: 13 D: 5, 34880 Kartal / İstanbul — [email protected] |
1.1 The Company is the data controller of the data listed in Annex 1: the Company decides which data is processed, for what purpose, on what legal basis and for how long.
1.2 Pelastra processes this data only on behalf of the Company and on the Company's instructions. The Company's instructions are deemed to be given through the Terms of Service, this agreement and the actions taken on the platform by the Company's authorised users (creating records, uploading, sharing, deleting, granting permissions, changing settings).
1.3 Matters outside the scope of this agreement. With respect to the following data, Pelastra is a data controller in its own right and the Privacy Policy applies:
- The own account data of Company users and seafarers (name, e-mail, password, session),
- Profile, identity, document and bank information entered by seafarers themselves — when a seafarer accepts the Company's personnel invitation, this information is made available to the Company by Pelastra; from that moment, the Company also becomes a data controller when using the data it accesses for its own purposes,
- Audit, access and application logs kept for platform security,
- Billing and subscription records.
2. Subject matter, nature and duration of processing
2.1 Subject matter and purpose: Providing the Company with personnel, crew and rotation management, document and training tracking, safety management (ISM), planned maintenance, voyage reports, crew wages, procurement, commercial operations, and the related notification, reporting and offline synchronisation services.
2.2 Nature: Collection, recording, storage, organisation, classification, display to the Company's authorised users and to its personnel on board, sending to third parties by e-mail on the Company's instructions, reporting, export and deletion.
2.3 Duration: The period during which the Company account is open, plus the return and deletion period set out in §10.
2.4 The categories of data and of data subjects are set out in Annex 1.
3. Obligations of the Company
3.1 Legal basis: The Company undertakes that it has a valid legal basis under KVKK Art. 5 and Art. 6 (and, within the scope of the GDPR, Art. 6 and Art. 9) for all data it has Pelastra process. In particular, for:
- Health data (medical certificates uploaded by the company, injury records, sick leave dates),
- Identity and document numbers, wage and bank information,
- Appraisals, personnel record notes and "do not re-employ" records
the Company determines the legal basis and, where necessary, the Company obtains explicit consent.
3.2 Information notice: The Company itself informs each of its employees and other data subjects whose records it keeps on the platform, in accordance with KVKK Art. 10. This obligation is particularly important in the following cases and cannot be fulfilled by Pelastra:
- Employees for whom the Company has created a managed record that cannot sign in (if no e-mail address has been entered, Pelastra cannot reach the person at all),
- Records not shown to the person (appraisals, personnel record notes, "do not re-employ" record),
- Representatives of suppliers, agents, charterers and brokers, and persons named in cargo documents,
- Photographs taken on board that may show individuals.
Annex 4 contains a sample text that the Company may use as a basis for its own information notice.
3.3 Access management: The Company keeps the roles, vessel scopes and special permissions (identity, health, wage, appraisal) it grants to its users limited to what is necessary. The access of ship's officers to documents uploaded by the company for the crew of their own vessel (including medical certificates) derives from the rank in the crew list; the Company is responsible for ranks being entered correctly.
3.4 Retention periods: The Company decides how long data is retained and deletes records whose retention period has expired using the deletion tools on the platform. Pelastra does not delete Company data without the Company's instructions (except in the cases under §10 and account deletion).
3.5 Persons who delete their accounts: When a seafarer deletes their Pelastra account, the Company's data that constitutes employer records (crew lists, rotation, crew wages, safety, maintenance and procurement records, documents uploaded by the company) is not deleted; the person's identity in these records is anonymised or the name copy specified in Annex 1 remains. The Company is responsible for the legal basis for continuing to retain these records.
3.6 The Company does not upload to the platform any data that is unlawful or lacks a legal basis.
4. Obligations of Pelastra
4.1 Adherence to instructions: Pelastra processes Company data only in accordance with the instructions in §1.2; it does not use it for its own purposes, does not sell it and does not use it for advertising. If Pelastra considers that an instruction infringes the legislation, it informs the Company without delay.
4.2 Aggregated data: Pelastra may produce numerical statistics from Company data that do not identify any individual or the Company for the purpose of measuring the operation and capacity of the service. Company data is not shown to any other company and is not used for cross-company comparison.
4.3 Confidentiality: Pelastra ensures that persons who access Company data are subject to a confidentiality obligation. Pelastra personnel access Company data only in the event of a support request, a security investigation or a legal obligation, and only to the extent necessary.
4.4 Security: Pelastra implements and keeps up to date the technical and organisational measures in Annex 2, pursuant to KVKK Art. 12(1) and GDPR Art. 32.
4.5 Data subject requests: Pelastra forwards any request received directly by Pelastra concerning Company data to the Company within 5 business days; it does not respond to the request itself. To enable the Company to respond to requests, Pelastra provides the viewing, rectification, export and deletion tools on the platform and, where necessary, provides reasonable technical assistance.
4.6 Audit log: Pelastra records the actions of Company users (who did what, and when) and their access to health, bank and identity document data, and shows these records to the Company's administrator users. Retention periods are set out in Annex 2.
4.7 Assistance: Pelastra provides, to a reasonable extent, the information necessary for the Company's data protection impact assessments, correspondence with the Personal Data Protection Board (KVKK Board) and audit obligations.
5. Sub-processors
5.1 The Company grants general authorisation for the use of the sub-processors listed in Annex 3.
5.2 Pelastra informs the Company by e-mail and on the platform at least 30 days before adding a new sub-processor or replacing an existing one. The Company may object within this period on reasonable grounds; if the objection cannot be resolved, the Company has the right to terminate the relevant service with a refund of fees.
5.3 Pelastra enters into written agreements with sub-processors containing data protection obligations equivalent to those in this agreement and is liable to the Company for the performance of their obligations.
6. Transfers abroad
6.1 Company data is hosted on servers in Türkiye (İstanbul). Transfers to sub-processors shown in Annex 3 as established abroad are carried out by signing the standard contracts (processor to processor) announced by the Personal Data Protection Board (KVKK Board) and notifying the KVKK Board (KVKK Art. 9(4)); within the scope of the GDPR, the European Commission's standard contractual clauses apply.
6.2 E-mails that the Company sends through the platform on its own instructions to a recipient abroad (e.g. a ticket request to a travel agency abroad, a request for quotation to a supplier) are the Company's own transfers; the Company determines their legal basis.
7. Personal data breach
7.1 When Pelastra becomes aware of a breach affecting Company data, it informs the Company without delay and at the latest within 48 hours. The notification includes the nature of the breach, the categories and approximate numbers of data and data subjects affected, its likely consequences, and the measures taken or proposed. Where the information cannot be provided at once, it is provided in phases.
7.2 The obligation to notify the KVKK Board and the data subjects rests with the Company (KVKK Art. 12(5): 72 hours). Pelastra provides the information required for that notification.
8. Audit
8.1 Pelastra provides, upon the Company's written request, information demonstrating compliance with this agreement.
8.2 The Company may, no more than once a year and with 30 days' prior notice, have a compliance audit carried out by an auditor subject to a confidentiality obligation. The audit is planned so that it does not require access to other companies' data and does not disrupt the service; the Company bears its costs. These limitations do not apply in the event of a breach or a request from the KVKK Board.
9. Liability
The parties' liability arising from this agreement is subject to the limitations in the Terms of Service. However, administrative fines and compensation to data subjects caused by a party's own fault are borne by that party. Pursuant to KVKK Art. 12(2), the parties are jointly liable to data subjects for taking data security measures.
10. Termination of the agreement: return and deletion
10.1 After the Company account is closed, the Company may retrieve its data using the platform's export tools for 30 days.
10.2 At the end of this period, Pelastra deletes the Company data and the files stored on behalf of the Company. Copies in backups are deleted when the ordinary retention period of the backup expires and are not processed again during that period.
10.3 Records that the legislation obliges Pelastra to retain (e.g. invoices) are retained after this period as well and are used only for that obligation.
11. Amendments
Pelastra may update this agreement in the event of changes in legislation or in the scope of the service. Amendments that restrict the Company's rights are notified at least 30 days in advance.
Annex 1 — Data processed and categories of data subjects
Categories of data subjects: The Company's shore and seagoing personnel (including former and candidate personnel), the Company's platform users, persons for whom the Company has created managed records, representatives of suppliers / agents / charterers / brokers / counterparties, shipper and consignee individuals named in cargo documents, travelling personnel, survey participants.
| Area | Data | Special category / sensitive | Note |
|---|---|---|---|
| Personnel | Category, rank, title, department, hire / departure, employment periods, availability | — | |
| Managed record | First name, last name, e-mail, phone, nationality, body measurements, identity and document information (entered by the Company) | Identity numbers | The person cannot sign in; upon claiming, the profile passes to the person |
| Service history | Vessel, rank, dates, contract, reason for leaving, end-of-assignment appraisal | — | Wage is read from the Crew wages area |
| Crew and rotation | Vessel, assignment dates, ports, internal notes, crew list (FAL Form 5) | Identity and document numbers | |
| Pre-joining + travel | Checklist, the person's form declarations, ticket (flight, PNR, ticket no, fare, PDF), ticket requests and agency correspondence | — | In a ticket request, the passenger name is sent to the agency by e-mail |
| Leave | Type (annual, sick, course, unpaid), dates, note | Sick leave (no diagnosis) | |
| Appraisal | Monthly appraisal, competency assessment, personnel record notes, "do not re-employ" record | Sensitive | Not shown to the person; the "do not re-employ" record keeps a name copy |
| Company documents | Employment contract, training, insurance, medical certificate and document scans | Health | Ship's officers see the crew of their own vessel; access log 30 days; a name copy is kept |
| Safety | Work / rest hours and monthly acknowledgement, watch schedule, form submissions, incident reports, injury (body part, nature, severity, lost days, medical note), non-conformity, audit | Health (injury) | Anonymous near miss reports carry no identity |
| Maintenance, voyage, procurement, commercial | Identity and rank of the person performing the action; name, e-mail, phone and address of supplier / agent / counterparty representatives; shipper / consignee of cargo parcels | — | Requests for quotation are sent to suppliers by e-mail; incoming replies are stored |
| Crew wages | Wage agreement, monthly payslip and its items, advance / expense items and receipt photos, employment contract (SEA) and the identity / document numbers as at its issue, bank payment file, bank statement lines | Wage, IBAN | Not a statutory payroll |
| Survey | Identified responses and participation; anonymous responses (with vessel, department, rank group) | Opinion-based | Results only for groups of at least 5 people |
| File attachments | Attachments to quotations, orders, work orders, non-conformities and audits | Depends on content |
Annex 2 — Technical and organisational measures
- Hosting: In a data centre in Türkiye (İstanbul); database with separate schemas per module.
- Encryption in transit: All traffic over HTTPS/TLS.
- Authentication: bcrypt password hashing; short-lived access token; session refresh token in an HttpOnly cookie; all secret keys stored in the database as hashes.
- Authorisation: permission-based roles; scoping of roles to a list of vessels; separate permissions for identity, health, wage and appraisal data; segregation of duties setting (the person who creates a record cannot approve it); isolation of platform administration from company permissions.
- Files: in non-public storage; accessible only via short-lived signed links; type, content signature and size checks on upload; rejection of Office documents containing macros.
- Logging: action audit log (actor, action, IP, field changes) 5 years; health, bank and identity document access log 365 days; personnel document access log 30 days; application logs 14 days. Passwords, keys, identity / passport / seaman's book / visa numbers and IBANs are masked in logs.
- Offline use: data held on the device on board is encrypted; readable data is deleted on sign-out.
- Rate limiting and IP blocking, security headers, HTML sanitisation of user content.
- Backup: The database is backed up daily. Backups are kept encrypted with AES-256 on the hosting provider's server in Türkiye (Istanbul), are used only for restoration and are deleted automatically after 30 days.
- Breach response: §7.
Annex 3 — Sub-processors
| Sub-processor | Service | Location | Transfer safeguard |
|---|---|---|---|
| Natro — Çizgi Telekomünikasyon A.Ş. | Server and database hosting | Türkiye (İstanbul) | Domestic |
| Cloudflare, Inc. | File storage (R2), DNS and network | Eastern Europe (R2) / global | Standard contract (KVKK Art. 9(4)) |
| Brevo (Sendinblue SAS) | Sending and receiving e-mail | France (EU) | Standard contract (KVKK Art. 9(4)) |
Company data is not sent to artificial intelligence services. Incoming e-mails (quotations, ticket replies) are read using fixed rules, not artificial intelligence.
Annex 4 — Sample information notice for employees
This text is a sample; the Company must adapt it to its own processing purposes, legal bases and retention periods. It does not replace legal advice.
[Company name] — Personal Data Information Notice for Our Employees
As [Company name] (the "Company"), in our capacity as data controller, we process your personal data within the scope of the employment relationship we have established with you. We keep our records on the Pelastra platform; Pelastra processes this data only on our behalf and on our instructions.
- Data processed: identity and contact information; passport, seaman's book, certificate of competency, visa and certificate information and copies; assignment and rotation information; travel and ticket information; work and rest hours; leave records; performance appraisals; wage and bank information; medical certificates and occupational accident records; safety records.
- Purposes: establishment and performance of the employment contract; obligations arising from seafarer and labour legislation, MLC 2006, the ISM Code and flag state rules; crew and visa procedures; occupational health and safety; payment of wages; preparation for inspections.
- Legal bases: KVKK Art. 5(2)(a) (expressly provided for by law), Art. 5(2)(c) (performance of a contract), Art. 5(2)(ç) (legal obligation), Art. 5(2)(f) (legitimate interest); for health data, Art. 6(3).
- Transfers: the officers of the vessel on which you serve (limited to the necessary documents); port and immigration authorities, the flag state, the classification society, the P&I insurer, the travel agency, your bank; the Ministry of Transport and Infrastructure (seafarer registry query); our service provider Pelastra and its sub-processors.
- Retention: [Periods to be determined by the Company].
- Your rights: You may submit requests regarding your rights under KVKK Art. 11 to [company contact address].