Effective date: 1 September 2026 Last updated: 1 September 2026 Version: 1.0
Language notice: This is an English translation provided for your convenience. The Turkish version is the binding text; in the event of any discrepancy between the two, the Turkish version prevails. See Gizlilik Politikası.
This policy explains how personal data is processed on the Pelastra platform (pelastra.com and api.pelastra.com). It has been prepared under Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and the European Union General Data Protection Regulation (GDPR).
1. Data controller
| Trade name | Melih Can Akbulut |
| Address | Soğanlık Yeni Mah. Atatürk Cad. No: 13 D: 5, 34880 Kartal / İstanbul, Türkiye |
| Tax office | Yakacık Tax Office |
| MERSİS no | — (sole proprietorship; not registered with the trade registry) |
| [email protected] | |
| Registered electronic mail (KEP) | — (none; applications are accepted by e-mail or post) |
| VERBİS registration | Not registered — the exemption conditions in Board Decision No. 2018/88 are met (reassessed annually) |
We act as the data controller under the GDPR. We have no representative established in the European Union. If we begin systematically offering services to users established in the EU, a representative will be appointed under GDPR Article 27.
2. What data we process
Pelastra is a platform connecting seafarers and maritime companies. The data processed depends on your user type (seafarer / company staff) and which features you use. A significant portion of the fields below is optional — you can use your account without filling them in; only the related features will not work.
2.1 Identity and contact data
| Data | Required | Source |
|---|---|---|
| First name, last name | Required | From you |
| E-mail address | Required | From you or your Google account |
| Phone number | Optional | From you |
| Password (only an irreversible hash is stored) | Not applicable with Google sign-in | From you |
| Preferred language | Automatic | Your selection at registration |
When you sign in with Google, Google sends us only your e-mail address and name; your password never reaches us.
2.2 Seafarer profile data (optional)
Date of birth, gender, nationality, country/province/district of residence, marital status, military service status, height, weight, shoe size, coverall/clothing size, profile photo, "about me" text, current rank.
Body and size information is requested in the industry for the supply of work clothing and safety equipment. You are not obliged to enter it.
2.3 Professional and document data (optional)
- Sea service / experience: company name, vessel name, IMO, vessel type, tonnage, rank, trading area, service dates, duties performed
- Education: school, department, graduation details
- Documents: passport (colour, issuing country, validity), seaman's book (rank, qualification, STCW section, GMDSS, flag country, validity), visa (country, number, type, validity), STCW certificates
- Document files you upload: scanned copies of the documents above
- Foreign languages and skills
- Job preferences: desired rank, vessel type, contract type, region
2.4 Special categories of personal data — health data
The following data is special category / sensitive data within the meaning of KVKK Article 6 and GDPR Article 9, and is processed solely on the basis of your explicit consent:
- Medical examination records — document name, date of issue and date of expiry
For the medical report, only information about the document itself (its name and dates) is kept; no medical content such as illness, diagnosis, treatment or examination results is processed.
Filling in these fields is entirely optional. Not filling them in does not prevent the use of your account or of other features. You may withdraw your consent at any time; upon withdrawal this data is deleted.
Separate consent in share links: If you wish to include the health section when sharing your profile with an employer via a link, the system asks for your separate and explicit approval. If you do not give it, health fields are not generated at all in the shared content. The moment your approval is given is recorded.
2.5 Third-party data — references
If you add a reference to your profile, that person's first name, last name, company, position and phone number are processed. That person may not be a user of our platform.
⚠️ Your responsibility: Before adding someone as a reference, it is your obligation to obtain their knowledge and consent and to inform them that this information will be processed on Pelastra. When you create a share link, the reference's information including the phone number is shown unmasked to whoever opens the link; you are warned about this when creating the link. A person who learns that they have been added as a reference may write to [email protected] to request the deletion of their record; we fulfil such requests within 30 days.
2.6 Communication and community data
- Messaging: message content in direct and group chats, participant information, read status
- Social: friend requests, friendships, users you have blocked
- Community: channel memberships, posts, comments, likes, bookmarks, images you upload
- Notifications and your notification preferences
- Activity feed: your visible actions on the platform (publishing a post, forming a friendship, etc.)
Your messages are not end-to-end encrypted. We do not routinely read their content; however, we may access them in the event of an abuse report, a legal obligation or a security investigation.
2.7 Data relating to company users
For company accounts we process: company profile, fleet/vessel records, vessel certificates, crew lists, rotation plans, staff memberships and invitations. Company staff's name, surname, e-mail and role are visible to company administrators.
2.8 Technical data and logs
| Record | Content | Purpose | Retention |
|---|---|---|---|
| Command audit record | User id, module, operation, IP address, result, duration, trace id | Security, error analysis, abuse detection | 30 days |
| Share access record | IP address and browser information (User-Agent) of the person opening the link, operation type, time | To show you who viewed your profile, and to detect abuse | 30 days |
| Activity records | Action type, object, time | Activity feed | 30 days |
| Notifications | Notification content | Notification history | Read notifications 30 days; unread ones are retained regardless of age |
| Server/application logs | Error and performance records | Keeping the system running | at most 30 days |
Passwords, tokens and API keys are masked in logs (***). This is enforced at code level; it is not left to operator discretion.
2.9 Payment data
We store subscription status, plan tier and billing period information relating to paid plans. Your card details never reach our servers and are not stored by us; payment is collected by the licensed payment institution iyzico — iyzi Ödeme ve Elektronik Para Hizmetleri A.Ş. (Türkiye) on its own infrastructure.
This section applies once the payment infrastructure goes live. As of 1 September 2026 no fees are collected on the platform.
3. Purposes and legal bases of processing
| Purpose | Data category | KVKK basis | GDPR basis |
|---|---|---|---|
| Account creation, authentication, session management | Identity, contact | Art. 5/2-c — establishment and performance of a contract | Art. 6/1-b — contract |
| Creating the seafarer profile and presenting it to employers | Profile, professional, document | Art. 5/2-c — performance of a contract | Art. 6/1-b — contract |
| Processing and sharing of health data | Medical report (document name + dates) | Art. 6/2 — explicit consent | Art. 9/2-a — explicit consent |
| Transfer of data to service providers abroad | See §5 below | Art. 9 — explicit consent / standard contract | Chapter V |
| AI-assisted professional summary generation | Profile, professional | Art. 5/1 — explicit consent (your choice to use the feature) | Art. 6/1-a — consent |
| Messaging, community and social features | Communication, community | Art. 5/2-c — performance of a contract | Art. 6/1-b — contract |
| Sending notifications (including certificate expiry warnings) | Contact, document dates | Art. 5/2-f — legitimate interest | Art. 6/1-f — legitimate interest |
| Platform security, abuse detection, audit logging | Technical, IP | Art. 5/2-f — legitimate interest | Art. 6/1-f — legitimate interest |
| Compliance with legal obligations, responding to official requests | All | Art. 5/2-ç — legal obligation | Art. 6/1-c — legal obligation |
| Providing paid plans and billing | Subscription, identity | Art. 5/2-c and 5/2-ç | Art. 6/1-b and 6/1-c |
Legitimate interest assessment: We rely on legitimate interest for security records and notifications. In this assessment, protecting the platform against abuse and preventing professional harm to a seafarer whose certificate is expiring were weighed against your privacy expectations; limiting records to 30 days and making notification categories individually switchable off were adopted as balancing measures. You may request the details of this assessment from [email protected].
4. Use of artificial intelligence
There are three separate AI features on the platform. The difference between them is whether your personal data enters the processing:
| Feature | Is your personal data used | Explanation |
|---|---|---|
| Professional summary generation | Yes | Professional information in your profile (rank, experience, certificates) is sent to Anthropic PBC's API in the United States for text generation |
| Profile quality advisor, career analysis | No (on our servers only) | Rule-based computation; no data leaves our systems |
| Regulatory analysis and news summaries | No | Only publicly available official regulatory documents are analysed; no user data is sent |
What you should know about the professional summary feature:
- Using the feature is entirely optional. Your profile data is not sent to Anthropic unless you use it.
- The generated text is shown to you and submitted for your approval before publication. Text you do not approve is not written to your profile.
- AI can make mistakes. The generated summary is not a professional document; verifying its accuracy is your responsibility.
- Anthropic's undertaking not to use API data for model training, and its current terms: the Commercial Terms and Data Processing Addendum at anthropic.com/legal
The AI does not make an automated decision producing legal effects concerning you or similarly significantly affecting you (GDPR Art. 22). Hiring decisions are made by the employer, not on the platform.
5. Transfers of data
5.1 To whom we transfer
At your direction:
- Employers / company users: the people you give a share link to see only the sections you have selected. A section you have not selected is not generated at all in the response.
- Other users: your community posts, the public part of your profile, and the people you message.
To our service providers (as data processors): see the table below.
To competent authorities: to the extent legally required, upon a duly made request.
We do not sell or rent data to any third party for advertising purposes.
5.2 Transfers abroad
Our servers and main database are located in Türkiye (İstanbul). Your personal data is hosted domestically; the transfers below relate only to service providers we use for specific platform functions. Transfers within the scope of KVKK Article 9 and GDPR Chapter V:
| Recipient | Country | Data transferred | Purpose | Safeguard |
|---|---|---|---|---|
| Anthropic PBC | USA | Professional profile data (if you use the feature) | Professional summary generation | Based on your explicit consent (KVKK Art. 9/6-a). Anthropic undertakes not to use data sent via the API for model training |
| Cloudflare, Inc. (R2) | Eastern Europe (Cloudflare EEUR region) | Document files you upload | Document storage | Based on your explicit consent (KVKK Art. 9/6-a) |
| Cloudflare, Inc. (DNS/CDN) | Global | IP address, request metadata | Network security, availability | Based on your explicit consent (KVKK Art. 9/6-a) |
| Google LLC | USA | E-mail, name (only with Google sign-in) | Authentication | Only if you choose Google sign-in; based on that choice (KVKK Art. 9/6-a) |
| Brevo (Sendinblue SAS) | France (European Union) | E-mail address, content of e-mails sent | E-mail delivery | Based on your explicit consent (KVKK Art. 9/6-a) |
| Natro — Çizgi Telekomünikasyon A.Ş. data centre, İstanbul | Türkiye (İstanbul) | All platform data | Server hosting | Domestic — no transfer abroad |
Document files are kept in storage that is closed to public access and can be read only through short-lived signed links; once a link expires the file cannot be accessed.
6. Retention periods
| Data | Period |
|---|---|
| Account and profile data | For as long as your account is active |
| After account deletion | Permanently deleted within 30 days |
| Health data | For as long as your consent continues; deleted immediately upon withdrawal |
| Uploaded document files | Until you delete them or your account is deleted |
| Command audit records (including IP) | 30 days — deleted automatically |
| Share access records (IP, User-Agent) | 30 days — deleted automatically |
| Activity records | 30 days — deleted automatically |
| Notifications | Read: 30 days; unread: retained |
| Messages and community content | Until you delete them or your account is deleted |
| Invoices and financial records | 10 years as required by tax legislation |
Deletion is performed by automated scheduled jobs; it does not depend on manual intervention.
7. Your rights
Under KVKK Article 11
To learn whether your personal data is processed; to request information if it has been processed; to learn the purpose of processing and whether the data is used in accordance with that purpose; to know the third parties to whom it is transferred domestically or abroad; to request rectification if it is incomplete or incorrect; to request erasure or destruction; to request that rectification and erasure be notified to the third parties to whom the data was transferred; to object to a result arising against you through analysis exclusively by automated systems; to claim compensation if you suffer damage due to unlawful processing.
Additional rights under the GDPR
Access (Art. 15), rectification (Art. 16), erasure / right to be forgotten (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21), withdrawal of consent (Art. 7/3), not to be subject to automated decision-making (Art. 22).
How to exercise your rights
Directly on the platform:
- You can edit and delete your profile data and documents at any time from your account settings.
- You can revoke or delete your share links. Deletion genuinely terminates access via the link. However, files already downloaded cannot be recalled.
- You can switch off notification categories individually.
- You can delete your account yourself from your account settings. Upon your deletion request your account is immediately closed to access and your data is permanently deleted after 30 days. Within that period you can reverse your request using the link in the e-mail sent to you.
- You can download all of your personal data in a single file (machine-readable JSON) — the portability right under GDPR Article 20.
By application: you can apply in writing to [email protected] or to the postal address above. Your application must allow us to verify your identity. Your request is concluded free of charge within 30 days at the latest (KVKK Art. 13; under GDPR Art. 12 one month, extendable to two months for complex requests).
Right to complain:
- Türkiye: Personal Data Protection Authority — kvkk.gov.tr
- EU: the data protection authority in your country
8. Data security
- All traffic is encrypted with HTTPS/TLS.
- Passwords are irreversibly hashed with bcrypt; plain-text passwords are never stored anywhere.
- Share link tokens are stored in the database as hashes, not in plain text.
- Uploaded documents are kept in non-public storage and served only via short-lived signed links.
- Authorisation is permission-based; company data and platform administration privileges are two mutually isolated axes.
- Sensitive fields are automatically masked in logs.
- A system-wide command audit record (who did what, and when) is kept.
⚠️ Profile photos are served publicly; anyone who knows the link can view them. Do not upload sensitive images such as scans of identity documents as your profile photo — use the document upload feature; those files are kept in protected storage.
No system is 100% secure. In the event of a breach affecting your personal data, we will notify the Personal Data Protection Board as soon as possible and within no more than 72 hours under the KVKK, the competent supervisory authority under GDPR Article 33, and — where there is a high risk — you directly.
9. Children's data
Pelastra is not directed at persons under the age of 18. Accounts of users we learn to be under 18 are closed and their data deleted. If you believe your child has provided us with data, write to [email protected].
10. Cookies
The use of cookies and similar technologies is explained in a separate document: Cookie Policy.
11. Changes to this policy
When we update the policy we change the "last updated" date on this page. For significant changes (a new processing purpose, a new recipient abroad, an extension of a retention period) we inform you in advance by e-mail or in-platform notification. If processing based on consent is being expanded, your consent is obtained again.
Previous versions are archived at pelastra.com/privacy/arsiv.
12. Contact
For any question about this policy or your personal data: [email protected]