Privacy Policy

Last updated: 31 July 2026

This Privacy Policy explains how Cleanwake (“we”, “us”) collects, uses and protects personal data when you use our maritime fleet-intelligence platform (the “Service”). We act as a data processor for the vessel and operational data your organisation enters, and as a data controller for the account data we need to run the Service. We comply with the EU General Data Protection Regulation (GDPR).

Who we are

Cleanwake is a maritime software service operated from Rotterdam, the Netherlands. For any privacy question or to exercise your rights, contact us at teamcleanwake@gmail.com.

What data we collect

  • Account data: name, work email, organisation name, hashed password, role.
  • Operational data you enter: vessels, voyages, noon reports, fuel and emissions data.
  • Sign-up and sign-in context: IP address, approximate country, browser and device type, and the page you arrived from — used to secure accounts, detect fraud and keep an audit trail.
  • Organisation information derived from your work-email domain, used to understand and support the businesses that sign up.
  • On our public marketing website only: a Google Ads tag that measures advertising performance (see “Cookies, analytics and advertising” below).
  • We do not sell personal data, we do not use your account or operational data for advertising, and we do not use hidden tracking or device fingerprinting.

Why we use it (legal bases)

  • To provide the Service under our contract with your organisation.
  • To secure accounts and prevent abuse (legitimate interest).
  • To measure the performance of our advertising on our public website (your consent, where consent is required by law).
  • To meet legal and regulatory obligations.

Where data is stored

Data is hosted on infrastructure in the EU (eu-west-1). Operational submissions are archived to encrypted object storage for audit purposes. Access is restricted and tenant-isolated, so one organisation can never see another’s data.

Cookies, analytics and advertising

The logged-in application keeps only what is needed to sign you in and run the Service; it does not run advertising trackers. Our public marketing website (the pages outside your account) uses:

  • Privacy-friendly, cookieless visit analytics (Umami), where enabled — it measures page views without cookies and without tracking you across other sites.
  • A Google Ads tag (gtag.js), provided by Google Ireland Limited, that measures whether our advertising leads to actions such as a sign-up (conversion measurement) and may enable remarketing. It can set cookies in your browser for this purpose, and shares data with Google as an independent controller for its own advertising services.

You can refuse or remove these advertising cookies through your browser settings and via Google’s Ads settings at adssettings.google.com. Where the law requires your consent before such cookies are set, we rely on that consent, and you can withdraw it at any time. Google’s handling of the data is governed by its own privacy policy.

Sub-processors

We use a small number of vetted providers to run the Service (cloud hosting, error monitoring, and — where enabled — email delivery) and, on our public website, Google (Google Ads) for advertising measurement. A current list is available on request at the contact address above.

Retention

We keep operational and regulatory records for as long as your organisation’s account is active, and afterwards only as long as required to meet maritime regulatory obligations (e.g. EU MRV / IMO DCS). Account data is deleted on request after the contract ends, subject to those obligations.

Your rights

Under the GDPR you can request access, correction, deletion, restriction, or a copy of your personal data, and you can object to certain processing. To exercise these rights, contact us at the address above. You also have the right to lodge a complaint with your national data protection authority.

Security

We protect data with encryption in transit, hashed passwords, row-level tenant isolation, HTTP security headers and access controls. No system is perfectly secure, but we work to industry standards and patch known issues promptly.

Changes

We may update this policy; material changes will be communicated to account administrators. Continued use after an update constitutes acceptance.

See also our Terms of Service.