Privacy notice
Last updated 22 September 2026. Founding-period version — a legally reviewed version replaces this before public launch.
This notice explains what personal data Laiva collects, why, where it is held and what rights you have. It is written to meet the UK GDPR and the EU GDPR, in plain language — crew and captains should be able to understand it without a lawyer.
1. Who is responsible for your data
Laiva (laiva.io), operated during its founding period by its founders in the United Kingdom and Italy is the data controller: we decide what is collected and why. The registered entity, address and a data-protection contact will be published here before public launch. Privacy requests: privacy@laiva.io.
2. What we collect and why
Crew. Through your conversation with Finn: first name, email and/or WhatsApp number, current role and department, vessel sizes and types, sea time, tickets and the flag state that issued them, the country of your passport and which visas you hold, preferred rotation, programme and regions, availability, salary band and discretion setting. Through the documents view: the certificates, sea-service records, medical certificates and CV you choose to upload; a CV is shared with a vessel only as part of an introduction you have said yes to. We use this to build your profile, verify it, match you to briefs, and run introductions you have said yes to. Legal bases: taking steps at your request before a contract and performing it (representation and placement), consent (uploading documents, each introduction, marketing), and legitimate interests (running and improving the platform, keeping a record of introductions).
Passport country and visas are recorded because they decide where you can legally join a vessel. They are treated as facts about eligibility, never as ethnicity or origin, and are never used for anything else.
Medical certificates (ENG1 or equivalent) are health data. We process them only with your explicit consent, which you give when you upload one, and only to confirm that the certificate is valid and when it expires. We record validity and expiry — nothing about its contents.
We do not ask for, and ask you not to provide, ethnicity, religion, sexual orientation, political opinions or health information beyond the medical certificate above. If something like this is volunteered in conversation it is not used for matching and is removed on request.
Vessels and management companies. Through Isla: your WhatsApp number or email, your name if you give it, the vessel and position you are hiring for, and your responses to shortlisted candidates. Legal bases: performing a contract and legitimate interests.
Everyone. Conversations with the agents are logged in full so the Laiva team can review them; standard technical data (IP address, browser, pages viewed) for security and to keep the service working; and waitlist sign-ups.
3. AI agents and automated processing
Profiles are built and briefs are structured with the help of AI agents, and shortlists are ranked by a matching engine that combines fixed rules (role, vessel size, verification status) with AI-generated scoring and written reasons. No decision with legal or similarly significant effect on you is made solely by automated means: every verification, shortlist and introduction is reviewed by a person at Laiva, and no vessel learns who you are until you have said yes yourself. Our AI providers process data under contracts that prohibit using it to train their models. Private notes the Laiva team keeps on a profile are never given to the matching engine.
4. Who sees what
Your profile is private by default and visible only to the Laiva team. A vessel sees an anonymised summary of your profile in a shortlist — role, tickets, sea time, vessel range, rotation, availability and verification status, with your first name only. Your full name, contact details and documents are never shown to a vessel. Contact details move only when a vessel has said yes and you have said yes to that specific introduction. Documents are seen only by the verification team. Vessel briefs are visible only to that vessel and the Laiva team. We do not sell personal data and do not share it with advertisers.
We use processors to run the platform: database and file storage (Supabase, EU — Ireland), hosting (Vercel), AI models (Anthropic), WhatsApp messaging (Twilio, on Meta’s WhatsApp Business platform) and email delivery (Resend, EU). Each processes data on our instructions under a data-processing agreement. Details on the Your data page.
5. Where data is held and international transfers
Your profile, documents, briefs and conversation logs are stored in the European Union (Ireland). Some processors — the AI models and the WhatsApp channel — are operated by US companies and may process data outside the UK and EEA; those transfers are covered by the EU–US Data Privacy Framework and UK extension where the provider is certified, and otherwise by Standard Contractual Clauses or the UK International Data Transfer Agreement.
6. How long we keep it
Crew profiles: for as long as your profile is active, then deleted or anonymised within 12 months of your last contact. Uploaded documents: until you remove them, or until your profile is deleted — whichever comes first. Introduction records (who said yes to whom, and when): 3 years from the introduction, so both sides have a record of what was agreed. Agent conversation logs: 24 months, then deleted. Waitlist entries: until you join or ask to be removed. Technical logs: 90 days. When you ask us to delete your profile, we delete profile and documents within 30 days and keep only the minimum introduction record we need to honour placement agreements.
7. Your rights
You can ask for a copy of your data, have it corrected, have it deleted, restrict or object to its processing, and receive it in a portable format. Where processing is based on consent you can withdraw it at any time — remove a document, switch discretion on, or decline an introduction. To exercise any right, write to privacy@laiva.io; we respond within one month. You can also complain to the UK Information Commissioner’s Office or, in the EU, to the supervisory authority where you live (in Italy, the Garante per la protezione dei dati personali).
8. Cookies and browser storage
Laiva uses only strictly necessary storage: a session identifier in your browser so that your conversation with Finn resumes if you close the tab, and a sign-in cookie for the Laiva team console. No advertising or cross-site tracking cookies. If we add analytics we will ask for consent first.
9. Security
Data is encrypted in transit and at rest. Documents are stored in a private bucket and are only ever reached through short-lived signed links. Access to the team console is password-protected and restricted to the Laiva team. Full detail on the Your data page.
10. Changes to this notice
We will update this notice as the platform develops and will tell account holders about material changes. The date at the top shows the current version; the version you accepted is recorded on your profile.
Questions or requests about your data: privacy@laiva.io