Privacy Policy
1. Who we are
STSscreen is operated by the STSscreen operating company (legal name to be published upon completion of company registration), registered address to be published upon completion of company registration. Our representative in the European Union under Art. 27 GDPR is to be published upon appointment; details available on request via support@stsscreen.com.
Contact for anything in this policy: support@stsscreen.com.
2. What this policy covers
The STSscreen service at stsscreen.com and its email channel (documents sent to sts@in.stsscreen.com). STSscreen generates a ship-to-ship counterpart screening report from two documents you provide: a Q88 and a Class Survey Status Report (CSSR). There are no user accounts.
3. What we process, why, and on what legal basis
Documents you provide (Q88 and CSSR, as .pdf, .doc or .docx). These contain vessel technical and commercial data and may incidentally contain personal data of named individuals, for example a listed contact person. The service does not seek out or use such personal data: no screening logic reads it, contact details are stripped from the report at rendering, and any incidental personal data inside the documents is deleted with them on the schedule in Appendix A of the Terms. Before you pay, your documents are classified and validated locally on our infrastructure; they are sent to our AI processing provider only after payment is confirmed and the screening runs, transiently and under a data processing agreement. Purpose: classifying the documents and generating your screening report. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). Retention: deleted as soon as your report is generated; ceilings in Appendix A.
Email data (email channel only): your sending address, message subject, and attachments. Purpose: running the screening you requested, sending the payment link and the report, replying when classification fails. Legal basis: contract performance. Retention: the email session record, including your address, expires automatically within 49 hours; attachments per Appendix A.
Payment data: payments are processed by our payment processor on its own hosted checkout. We receive payment status and a payment reference; we never receive or store card numbers. Purpose: charging the EUR 2.50 fee (VAT included), releasing holds when a screening is canceled, and fraud prevention. Legal basis: contract performance; legitimate interests (fraud prevention); legal obligation (tax and accounting records). Retention: transaction records are kept as long as applicable tax law requires; the specific period is available on request via support@stsscreen.com.
Technical data: your IP address is used transiently for rate limiting and abuse prevention (stored only as hashed keys that expire with their short windows), and standard hosting logs exist at our infrastructure providers. Our own application logs carry technical identifiers (session and payment references, status codes), never your email address, document names, or document contents. Our hosting provider retains runtime logs for approximately one day. Legal basis: legitimate interests.
Generated report and session metadata: the report PDF, a session identifier, a customer-visible reference, and timestamps. Purpose: delivering your report and handling support. Legal basis: contract performance. Retention: the report is available for 24 hours and then deleted; session records expire within 24 hours (web) or 49 hours (email).
Support correspondence: emails you send to support@stsscreen.com. Legal basis: legitimate interests (handling your request). Retention: ordinary business correspondence, deletable on request absent a legal obligation.
4. Cookies
The service sets no cookies and runs no analytics or third-party scripts: there is no cookie use, no tracking, and nothing to consent to on this site. Our payment processor's hosted checkout, which you are redirected to for payment, sets its own cookies on its own domain under its own privacy policy.
5. Recipients of data
We share data only with service providers acting on our instructions, by category: a payment processor (checkout and card handling), cloud hosting and file storage providers, an AI document-processing provider (receives documents only after payment, as described above), a transactional email delivery provider, and a DNS and mail routing provider. Each receives only what its role requires, under a data processing agreement. We do not sell or share data for advertising, and we disclose data to authorities only where legally required.
6. International transfers
The controller is established in the United States, and some providers process data there. EU customer data is handled under this policy's rules regardless of location; transfers rely on the EU-US Data Privacy Framework where a provider is certified, and otherwise on Standard Contractual Clauses. You can request details of the safeguards via support@stsscreen.com.
7. How long we keep things
The service is built to keep as little as possible for as short as possible: uploaded files are deleted as soon as your report is generated, the report is available for 24 hours and then deleted, and every session record expires automatically (24 hours web, 49 hours email). Nothing customer-related is retained indefinitely. The full retention ladder, including the email channel's windows and the abandonment ceilings, is Appendix A of the Terms and forms part of this policy.
8. Automated processing
Screening reports are generated automatically, including AI-assisted document processing after payment. The report assesses vessels and documents, not people; no decision with legal or similarly significant effects on an individual is made.
9. Your rights
You have the rights of access, rectification, erasure, restriction, portability, and objection under the GDPR. Because the service deletes data automatically within hours, the data may already be gone by the time we receive a request. To exercise any of these rights, email support@stsscreen.com. You also have the right to lodge a complaint with a data protection authority at any time; in Greece that is the Hellenic Data Protection Authority (dpa.gr), or you may contact the authority of your own EU country.
10. Security
Transport encryption throughout, payment handling delegated entirely to the payment processor's hosted checkout, no accounts and no credential storage, and the deletion-first design described above. File and session storage run on established managed cloud infrastructure under those providers' security programs.
11. Minors
The service is a professional maritime tool and is not directed at minors, and we do not knowingly process minors' personal data.
12. Changes
Material changes will be posted on this page with a new effective date.
Effective date: to be published at launch.