Privacy Policy

Effective date: 1 June 2025

Creative Nook SRL ("we", "us", "our") operates the MarineDocsAI platform. This Privacy Policy explains what personal data we collect, how we use it, and your rights under the General Data Protection Regulation (GDPR) and applicable Romanian law.

1. Data Controller

The data controller responsible for your personal data is Creative Nook SRL, incorporated in Romania. You can reach us at [email protected].

2. Data We Collect

We collect the following categories of personal data:

  • Account data — name, email address, company name, and hashed password when you register.
  • Fleet & vessel data — vessel names, IMO numbers, flag states, class societies, and equipment records you enter or that are extracted from uploaded documents.
  • Uploaded documents — certificates, survey reports, manuals, and images you submit for AI processing. These may contain vessel or crew-related information.
  • Usage data — pages visited, features used, and interaction timestamps, collected via server logs and application telemetry.
  • Payment data — billing email and transaction IDs. Full card details are processed by Stripe and never stored by us.

3. How We Use Your Data

PurposeLegal basis
Provide and operate the ServiceContract performance (Art. 6(1)(b))
Process AI document extractionContract performance (Art. 6(1)(b))
Send service and billing emailsContract performance (Art. 6(1)(b))
Improve the platform and fix bugsLegitimate interest (Art. 6(1)(f))
Comply with legal obligationsLegal obligation (Art. 6(1)(c))
Send product updates (opt-in only)Consent (Art. 6(1)(a))

4. AI Processing of Documents

Documents you upload are sent to Anthropic's API for AI-assisted extraction and analysis. Anthropic processes data as a sub-processor under our instructions and does not use your documents to train its models. Anthropic's data processing agreement is in place. Documents are stored in encrypted object storage hosted within the EU and are not shared with any other third parties.

5. Data Sharing

We share personal data only with:

  • Anthropic — AI processing of uploaded documents (sub-processor);
  • Stripe — payment processing (independent controller for payment data);
  • Infrastructure providers — self-hosted EU servers for storage and compute.

We do not sell your personal data. We do not share it with advertisers or data brokers.

6. Data Retention

  • Account data is retained for the duration of your account plus 12 months after deletion.
  • Uploaded documents and extracted records are retained for 3 years to support compliance audit trails, unless you request earlier deletion.
  • Payment records are retained for 7 years as required by Romanian accounting law.
  • Usage logs are retained for 90 days.

7. International Transfers

All data is stored and processed within the EU. Anthropic is a US-based company; transfers to Anthropic are covered by Standard Contractual Clauses (SCCs) approved by the European Commission.

8. Your Rights

Under GDPR you have the right to:

  • Access — request a copy of the personal data we hold about you;
  • Rectification — ask us to correct inaccurate data;
  • Erasure — ask us to delete your data ("right to be forgotten");
  • Restriction — ask us to limit how we process your data;
  • Portability — receive your data in a machine-readable format;
  • Objection — object to processing based on legitimate interests;
  • Withdraw consent — where processing is based on consent.

To exercise any right, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Romanian National Supervisory Authority (ANSPDCP) at dataprotection.ro.

9. Cookies & Tracking

MarineDocsAI does not use third-party advertising cookies. We use a session cookie strictly necessary for authentication and a localStorage token for keeping you signed in to the Fleet Dashboard. No consent banner is required for these strictly necessary cookies under ePrivacy rules.

10. Security

We implement appropriate technical and organisational measures to protect your data, including encryption in transit (TLS), hashed passwords (bcrypt), and access controls limiting who can read stored documents. In the event of a data breach affecting your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR Art. 33–34.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you by email and update the effective date above. Material changes will be communicated at least 14 days in advance.

12. Contact

Creative Nook SRL
Email: [email protected]