# SEA Fleet — Privacy & subprocessors (0₺ transparency)

**Product:** SEA Fleet (B2B) · **Operator:** VoxDuru  
**Contact:** info@voxduru.com · security: info@voxduru.com  
**Updated:** 2026-08-16

## Data we process (typical pilot)

| Category | Examples | Purpose |
|----------|----------|---------|
| Account | email, name, org role | Auth, invites, license |
| Fleet ops | vessels, certificates, WO, NC, inspections, photos | Product function |
| Device | sync queue, offline drafts | Offline-first ops |
| Telemetry (minimal) | auth/error logs | Reliability |

No consumer App Store listing. Tenants are contracted companies.

## Subprocessors

| Vendor | Role | Notes |
|--------|------|-------|
| **Supabase** (project `nirkjzbkddpzzscjkeoz`) | Auth, Postgres, RLS, storage | Free tier; EU-capable cloud |
| **Hosting (Vercel / voxduru.com)** | Public site + Trust Center + Shore demo | TLS (Vercel) |
| **Email SMTP (configured for OTP)** | Magic-link / OTP delivery | Transactional only |

No ad networks. No sale of personal data.

## Retention (product policy pointer)

Class/PMS history retention target ≥5 years — see `BACKUP_RETENTION.md`.  
Tenant offboarding: contractual SoW; export on request during pilot.

## Rights / KVKK–GDPR posture (honest)

We design for data minimization, org-scoped RLS, and contractual B2B processing.  
**We do not claim** a paid ISO 27001 / SOC 2 audit certificate.

## Security contact

Report vulnerabilities: `info@voxduru.com` subject `SEA Fleet security`.
