Privacy Policy
How we handle personal data — under KVKK and the GDPR.
This policy explains what personal data The Maritime (“we”) processes, why, on what legal basis, with whom we share it, and the rights you have. It is written to align with the Turkish Personal Data Protection Law No. 6698 (KVKK) and, for visitors in the European Economic Area, the GDPR.
1. Who is responsible (data controller)
The data controller is The Maritime A.Ş. (İstanbul, Türkiye), reachable at privacy@themaritime.net. For KVKK purposes this is the “veri sorumlusu”; for the GDPR, the “controller”. Data-protection requests should be sent to that address.
2. What we collect
- Account data you give us when you register — name and email.
- Usage data — pages viewed and searches performed, to operate and improve the service.
- Technical & security data — your IP address and basic request metadata (user-agent, timestamp), processed by our anti-abuse / rate-limiting layer to count page views per address and to block sources that attempt to bulk-scrape the site. IP addresses are personal data and are treated as such.
- Cookies — an essential, signed session cookie to keep you logged in and remember preferences.
3. Maritime data about third parties
The platform aggregates maritime information about vessels, companies and organisations from public, official and licensed sources. Where such information relates to an identifiable natural person (for example a named owner or company representative), it is personal data. We process it on the basis of our legitimate interest in maritime transparency, safety and sanctions-compliance research, balanced against the rights of the individuals concerned. We do not knowingly list private pleasure craft or purely private individuals. If you are named and wish to see, correct or object to that processing, contact us at the address above — see “Your rights” and our takedown process.
4. Why we process it and our legal basis
- To provide your account and the service — performance of a contract (KVKK Art. 5/2-c; GDPR Art. 6(1)(b)).
- Security, anti-abuse and IP-based rate limiting — our legitimate interests (KVKK Art. 5/2-f; GDPR Art. 6(1)(f)).
- Aggregating maritime/third-party data — legitimate interests, as above.
- Any marketing email — only with your explicit consent, which you can withdraw at any time.
5. Who we share it with (processors / sub-processors)
We do not sell personal data. We use service providers who process data on our behalf under contract: cloud hosting (Vercel, Railway), managed database (Neon), and — for features that use it, server-side only — AI inference providers. Each acts as our processor (KVKK “veri işleyen” / GDPR processor).
6. International transfers
Some providers process data outside Türkiye and the EEA. Where that happens we rely on an appropriate transfer mechanism (e.g. the provider’s standard contractual clauses and, for KVKK, the applicable transfer conditions / explicit consent where required).
7. How long we keep it
- Account data — while your account is active, then deleted or anonymised within a reasonable period.
- Security / IP logs — kept only as long as needed for abuse-prevention (short-lived; auto-blocks lapse after 24 hours) and then purged.
- Aggregated maritime records — retained as part of the dataset, subject to correction / removal requests.
8. Data security
Access tokens are scoped and signed; passwords are hashed; the internal data API is reachable only server-side behind an internal key. We apply least-privilege access and industry-standard safeguards.
9. Your rights
Under KVKK Art. 11 and the GDPR you may ask us to confirm whether we process your data and to access it; to correct inaccurate data or complete incomplete data; to delete or anonymise it; to restrict or object to processing; and, under the GDPR, to receive it in a portable form. You may also lodge a complaint with the Turkish Personal Data Protection Authority (KVKK Kurumu) or, in the EEA, your local supervisory authority. To exercise any right, email privacy@themaritime.net; we respond within the statutory time limits.
10. Changes and contact
We may update this policy; material changes will be posted here. Questions or requests: privacy@themaritime.net.

