This Privacy Policy explains how Charter Logic Suite (‘we’, ‘us’, ‘our’) collects, uses, stores, and protects personal data when you use our platform at charterlogicsuite.com. We comply with the EU General Data Protection Regulation (GDPR), the Pakistan Personal Data Protection Act 2023 (PDPA), and applicable UAE Federal Decree No. 45 of 2021 on Personal Data Protection.
Section 1
For EU users: we process your data as a Data Controller under GDPR Article 4(7). Our EU representative for GDPR purposes (per Article 27) will be appointed prior to active marketing in the EU. Contact privacy@charterlogicsuite.com for EU-specific enquiries in the interim.
Section 2
Documents in Arabic, Greek, Spanish, Chinese, French, and other languages are auto-detected and translated to English for processing. Original language content is retained alongside translations.
If you operate a white-label portal, we process: your branding assets (logo, colours), custom domain configuration, and your clients' data on your behalf. You act as Data Controller for your clients; CLS acts as Data Processor.
Documents you upload (Statements of Facts, charterparties, invoices) are processed by our AI pipeline. The content is sent to the following third-party processors:
| Processor | Purpose | Data Sent | Retention |
|---|---|---|---|
| Google Document AI | OCR — text extraction | Document image bytes | Not retained after processing |
| Amazon Textract | Table extraction | Document image bytes | Not retained after processing |
| OpenRouter AI | Maritime AI reasoning | Extracted text (not raw images) | Not retained for model training |
| Supabase | Database and file storage | All structured data and files | 90 days for files; indefinite for audit results |
Zero-Training Commitment
We use OpenRouter's API which does not use your data for model training. Your document content is never used to train or improve the AI models.
Section 3
| Processing Activity | Legal Basis |
|---|---|
| Creating and managing your account | Performance of contract (GDPR Art. 6(1)(b)) |
| Processing audit jobs | Performance of contract (GDPR Art. 6(1)(b)) |
| Sending service emails (receipts, alerts) | Performance of contract (GDPR Art. 6(1)(b)) |
| Improving the platform (aggregated analytics) | Legitimate interests (GDPR Art. 6(1)(f)) |
| Security monitoring (IP logging) | Legitimate interests (GDPR Art. 6(1)(f)) |
| Marketing emails (if opted in) | Consent (GDPR Art. 6(1)(a)) |
| Compliance with legal obligations | Legal obligation (GDPR Art. 6(1)(c)) |
Section 4
We do not sell, rent, or trade your personal data.
We share data only with the following categories of recipients:
Section 5
Section 6
Depending on your jurisdiction, you have the following rights:
| Right | Description | How to Exercise |
|---|---|---|
| Access | Request a copy of all personal data we hold about you. | Email privacy@charterlogicsuite.com — response within 30 days. |
| Rectification | Correct inaccurate or incomplete personal data. | Update directly in Account Settings, or email us. |
| Erasure | Request deletion of your personal data. | Account Settings > Delete Account, or email us. |
| Portability | Receive your data in a machine-readable format. | Email privacy@charterlogicsuite.com — JSON export. |
| Object | Object to processing based on legitimate interests. | Email privacy@charterlogicsuite.com. |
| Withdraw Consent | Withdraw consent for marketing emails. | Unsubscribe link in any email, or Account Settings. |
Section 7
| Cookie | Type | Purpose | Expiry |
|---|---|---|---|
| sb-auth-token | Essential | Supabase authentication session token. | 30 days |
| cls_preferences | Functional | UI preferences (sidebar state, date format). | 12 months |
| paddle_marketing | Marketing (opt-in) | Paddle affiliate tracking (referral links only). | 90 days |
| _vercel_insights | Analytics (opt-in) | Anonymised page view analytics (no personal data). | 30 days |
We do not use third-party advertising cookies. We do not use fingerprinting or cross-site tracking.
Section 8
Charter Logic Suite is a professional B2B platform intended exclusively for maritime industry professionals. We do not knowingly collect data from persons under the age of 18. If we become aware that a user under 18 has registered, we will delete the account immediately.
Section 9
Our infrastructure is primarily US-based (Supabase on AWS, Vercel). For EU users, this constitutes an international data transfer. We rely on the EU-US Data Privacy Framework and Standard Contractual Clauses (SCCs) to ensure adequate protection. For users in Pakistan: we comply with the Pakistan Personal Data Protection Act 2023. Your data is processed in the US under appropriate transfer safeguards.
Section 10
We may update this Privacy Policy to reflect changes to our platform, legal requirements, or data practices. We will notify you by email at least 14 days before any material changes take effect. The current version is always available at charterlogicsuite.com/privacy.
Section 11
If you are not satisfied with our response to a privacy complaint, you may contact your national supervisory authority (e.g., ICO in the UK, CNIL in France).