Privacy Policy — CharterFlow CRM
Effective: 2 August 2026 · Operator: SUDO Technology LTD, s. Poprusevtsi 17, 5084 s. Poprusevtsi, Bulgaria, company no. (ЕИК) 205812687, VAT BG205812687 ("we", "us") · Contact: kalpetkoff@gmail.com
CharterFlow CRM is a business application for yacht-charter brokerages ("workspaces"). This policy explains what personal data we process, in which role, and what rights you have.
1. Two roles — controller and processor
We are the controller for data about the people who use CharterFlow CRM: account holders and workspace members (§2).
We are a processor for the business records a workspace stores in
CharterFlow CRM about its own clients and charter guests (§3). For that data,
the brokerage operating the workspace is the controller, and our processing
is governed by the Data Processing Agreement (see dpa.md). If you are a
charter client or guest whose details appear in a workspace, please direct
requests to the brokerage you dealt with; we support them in responding.
2. Data we control (your CharterFlow CRM account)
- What: name, email address, password (stored as a salted hash by our authentication provider), workspace membership and role, sign-in metadata, billing contact and subscription state (payment card details are entered only on Stripe-hosted pages and never reach us).
- Why / legal basis: to provide the Service (contract, GDPR art. 6(1)(b)); security logging and abuse prevention (legitimate interest, art. 6(1)(f)); billing and tax records (legal obligation, art. 6(1)(c)).
- How long: for the life of the account; deleted or anonymized after account closure except where retention is legally required (e.g. invoices).
3. Data we process for workspaces (their CRM records)
Workspaces store, at their discretion: client contact details, leads and correspondence context, quotations, bookings, payment records (amounts and status — not card numbers), uploaded documents, and charter guest details, which may include identity-document data (passport numbers, dates of birth, nationality) required for charter manifests. Protections built into the Service for this data include: strict per-workspace isolation enforced in the database; role-based access; masking of sensitive guest fields with audited reveal; audit trails on changes; encrypted transport and at-rest storage via our subprocessors.
Optional AI assistance: if a workspace explicitly enables it, text the broker submits (e.g. an inquiry email) is sent to Anthropic to extract fields or draft a reply. Output is advisory and reviewed by the broker before anything is saved or sent. Prompt content is not used to train models under Anthropic's commercial API terms. AI is off by default.
4. Subprocessors and transfers
We use the vendors listed in subprocessors.md (database/auth/storage,
hosting, billing, email, optional AI, maps). Where processing occurs outside
the EEA/UK, transfers rely on adequacy decisions or Standard Contractual
Clauses with the vendor. We do not sell personal data and use no third-party
advertising or analytics trackers in the application.
5. Cookies and website analytics
The application (charterflow.app) uses strictly necessary cookies only (authentication session, workspace selection). No advertising or cross-site tracking cookies.
Our marketing website (charterflowcrm.com) sets no cookies by default.
With your consent — requested via the cookie banner and changeable at any
time via "Cookie settings" in the footer — it measures visits using:
(a) Google Analytics 4 (Google Ireland Ltd. / Google LLC), which sets
analytics cookies (e.g. _ga) and processes usage data with IP
anonymization; data may be transferred to the United States under the
EU–U.S. Data Privacy Framework and Standard Contractual Clauses; and
(b) cookieless, aggregated statistics from our hosting provider (Vercel
Web Analytics). We use these for aggregated insight only — no advertising
audiences, no cross-site profiles. If you decline, neither runs; your
choice is stored locally in your browser (localStorage, not a cookie).
Details: the Cookie Notice at charterflowcrm.com/cookies.
6. Your rights
Under the GDPR (and equivalent laws) you may request access, rectification, erasure, restriction, portability, or object to processing — contact kalpetkoff@gmail.com. You may lodge a complaint with your supervisory authority. For records controlled by a brokerage (§3), we will refer your request to them and assist their response.
7. Security and breach notification
Measures include workspace isolation enforced at the database layer, role-based permissions, audited access to sensitive fields, secret-free logging, encrypted transport, and provider-managed encryption at rest. We notify affected controllers without undue delay after becoming aware of a personal-data breach, as the DPA describes.
8. Changes
We will post updates here and notify workspace owners of material changes.