Version: 1.0 Effective date: [DD Month 2026 — set on publication] Document status: Beta release
The controller of personal data processed through CrewMag is:
Arturs Stols, a natural person residing in Latvia, operating the Service as an individual (not as a registered company).
Contact for all data protection matters: support@crewmag.net
No Data Protection Officer has been appointed, as the Service does not meet the criteria requiring one under Article 37 GDPR.
We process only the data you enter into the Service yourself:
Account data
Profile and CV data
We do not collect date of birth, financial data, identity document numbers, or certificate registration numbers.
Certificate records. For each certificate you add, we store only the certificate name, its expiry date, and the country where it was issued. We do not store certificate numbers, scanned copies, or any assessment details.
Special categories of data. Some certificates common in the maritime industry — such as a medical fitness certificate — may indirectly indicate that you have been assessed as fit for service. Where such a record constitutes data concerning health under Article 9 GDPR, we process it on the basis of your explicit consent (Article 9(2)(a)), given by voluntarily entering that certificate into your CV.
Entering a medical certificate is optional. You may withdraw this consent at any time by deleting the certificate record from your CV; the record is then removed. If you publish a CV containing such a certificate, that information becomes publicly visible along with the rest of the CV (see section 5).
We do not collect diagnoses, medical findings, treatment information, or any other health details, and no field in the Service asks for them.
Some technical data (such as IP addresses and connection logs) is processed automatically by our infrastructure providers as part of delivering the Service — see section 6.
We process your data on the basis of Article 6(1)(b) GDPR — performance of a contract. Creating an account and using CrewMag forms an agreement between you and the Operator, and the processing described here is necessary to provide the Service you asked for.
The single exception is certificate data that may qualify as health data, which relies on explicit consent under Article 9(2)(a) as described in section 2.
Apart from that exception, we do not rely on consent (Article 6(1)(a)) as the basis for the core functionality of the Service. This means the processing described in this Policy is not something you can withdraw consent for while continuing to use the Service — instead, you can stop using the Service and delete your account at any time (see section 7).
We do not use your data for advertising, profiling, automated decision-making, or to build any kind of behavioural profile. We do not sell or rent your data to anyone.
By default, everything you enter is private and visible only to you.
A CV is made public only by your own explicit action in the dashboard. When you publish a CV:
You choose what to publish. If you do not wish your phone number, photograph, nationality or visa status to be publicly visible, do not include that information in a CV you intend to publish, or do not publish the CV at all.
You can unpublish a CV at any time. Unpublishing stops future public access but cannot recall copies already made by third parties, and cached versions may remain available briefly outside our control.
We use the following service providers (processors):
Supabase — database, authentication, file storage. Project data, including uploaded profile photographs, is hosted in a Supabase region located in Sweden (European Union / EEA). Supabase also handles authentication and delivers account-related emails (such as confirmation and password reset messages).
Supabase Inc. is a company established in the United States. Where support or administrative access could involve access to data from outside the EEA, this is governed by Supabase's data processing agreement and the appropriate safeguards under Chapter V GDPR (standard contractual clauses).
[HOSTING PROVIDER] — hosting of the CrewMag web application itself.
[TO BE COMPLETED] The hosting provider for the application must be named here, with its hosting region, before this Policy is published. If the provider is established outside the EEA, a transfer-safeguards paragraph equivalent to the Supabase one above must be added.
PDF documents are generated by the Service's own infrastructure. No separate third-party PDF service receives your data.
We do not use analytics, advertising networks, or any other third-party tracking services.
We keep your data for as long as your account exists. There is no automatic expiry or inactivity-based deletion.
You can request deletion of your account from within the Service at any time. When you do:
Erasure covers your profile, all CVs and related records, your uploaded photograph in storage, and your authentication account. Data is not retained in anonymised form — it is removed.
If you cancel the deletion request within the 30-day period, normal access is restored. Previously published CVs remain unpublished until you publish them again.
Under the GDPR you have the right to:
How to exercise these rights: send a request to support@crewmag.net from the email address associated with your account.
The Service does not currently include an automated data export function. Access and portability requests are fulfilled manually: we will extract your data and provide it to you in a machine-readable format. We will respond within one month of receiving your request, as required by Article 12(3) GDPR. If a request is complex, this period may be extended, and we will inform you if that happens.
Right to complain. If you believe your data has been handled unlawfully, you may lodge a complaint with the Latvian supervisory authority, the Data State Inspectorate (Datu valsts inspekcija), or with the supervisory authority in your country of residence within the EU.
CrewMag uses only strictly necessary cookies required for authentication and session management. These are set by Supabase Auth to keep you logged in.
We do not use analytics cookies, advertising cookies, or any other tracking technology. Because only strictly necessary cookies are used, no cookie consent banner is required.
If tracking or analytics is introduced in the future, this Policy will be updated to a new version and a separate cookie notice and consent mechanism will be implemented before any such technology is activated.
The Service is not intended for persons under 18 years of age. We do not knowingly process data of minors and do not collect date of birth.
If you believe a minor has registered an account, contact support@crewmag.net and the account will be reviewed and removed.
Access to your data is restricted so that each user can only read and modify their own records, enforced at database level. Data in transit is encrypted. Uploaded images are validated before storage.
No system can be guaranteed fully secure. We do not claim that a breach is impossible. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority and, where required, affected users, in accordance with Articles 33 and 34 GDPR.
This Policy is versioned. Each version carries a version number and an effective date.
If we change how data is processed — for example, by adding a new processor or introducing analytics — we will publish a new version before the change takes effect and notify registered users of material changes by email or through the Service.
Data protection questions and requests: support@crewmag.net
CrewMag Privacy Policy, Version 1.0.