Privacy Policy — CharterFlow CRM

Effective: 2 August 2026 · Operator: SUDO Technology LTD, s. Poprusevtsi 17, 5084 s. Poprusevtsi, Bulgaria, company no. (ЕИК) 205812687, VAT BG205812687 ("we", "us") · Contact: kalpetkoff@gmail.com

CharterFlow CRM is a business application for yacht-charter brokerages ("workspaces"). This policy explains what personal data we process, in which role, and what rights you have.

1. Two roles — controller and processor

We are the controller for data about the people who use CharterFlow CRM: account holders and workspace members (§2).

We are a processor for the business records a workspace stores in CharterFlow CRM about its own clients and charter guests (§3). For that data, the brokerage operating the workspace is the controller, and our processing is governed by the Data Processing Agreement (see dpa.md). If you are a charter client or guest whose details appear in a workspace, please direct requests to the brokerage you dealt with; we support them in responding.

2. Data we control (your CharterFlow CRM account)

3. Data we process for workspaces (their CRM records)

Workspaces store, at their discretion: client contact details, leads and correspondence context, quotations, bookings, payment records (amounts and status — not card numbers), uploaded documents, and charter guest details, which may include identity-document data (passport numbers, dates of birth, nationality) required for charter manifests. Protections built into the Service for this data include: strict per-workspace isolation enforced in the database; role-based access; masking of sensitive guest fields with audited reveal; audit trails on changes; encrypted transport and at-rest storage via our subprocessors.

Optional AI assistance: if a workspace explicitly enables it, text the broker submits (e.g. an inquiry email) is sent to Anthropic to extract fields or draft a reply. Output is advisory and reviewed by the broker before anything is saved or sent. Prompt content is not used to train models under Anthropic's commercial API terms. AI is off by default.

4. Subprocessors and transfers

We use the vendors listed in subprocessors.md (database/auth/storage, hosting, billing, email, optional AI, maps). Where processing occurs outside the EEA/UK, transfers rely on adequacy decisions or Standard Contractual Clauses with the vendor. We do not sell personal data and use no third-party advertising or analytics trackers in the application.

5. Cookies and website analytics

The application (charterflow.app) uses strictly necessary cookies only (authentication session, workspace selection). No advertising or cross-site tracking cookies.

Our marketing website (charterflowcrm.com) sets no cookies by default. With your consent — requested via the cookie banner and changeable at any time via "Cookie settings" in the footer — it measures visits using: (a) Google Analytics 4 (Google Ireland Ltd. / Google LLC), which sets analytics cookies (e.g. _ga) and processes usage data with IP anonymization; data may be transferred to the United States under the EU–U.S. Data Privacy Framework and Standard Contractual Clauses; and (b) cookieless, aggregated statistics from our hosting provider (Vercel Web Analytics). We use these for aggregated insight only — no advertising audiences, no cross-site profiles. If you decline, neither runs; your choice is stored locally in your browser (localStorage, not a cookie). Details: the Cookie Notice at charterflowcrm.com/cookies.

6. Your rights

Under the GDPR (and equivalent laws) you may request access, rectification, erasure, restriction, portability, or object to processing — contact kalpetkoff@gmail.com. You may lodge a complaint with your supervisory authority. For records controlled by a brokerage (§3), we will refer your request to them and assist their response.

7. Security and breach notification

Measures include workspace isolation enforced at the database layer, role-based permissions, audited access to sensitive fields, secret-free logging, encrypted transport, and provider-managed encryption at rest. We notify affected controllers without undue delay after becoming aware of a personal-data breach, as the DPA describes.

8. Changes

We will post updates here and notify workspace owners of material changes.