Legal

Privacy Notice

Last updated: 7 August 2026

This Privacy Notice explains how Georgios Zografos, a sole trader established in the Republic of Cyprus, trading as "Full Ahead AI Ship Manager", collects and uses personal data when you visit our website or use the Full Ahead AI Ship Manager platform (the "Service").

1. Who we are and our role

We are the data controller for personal data about account holders, users and website visitors, and we decide why and how it is processed. Where you upload personal data about your own crew or third parties into the Service, you act as controller for that content and we act as your processor, processing it on your instructions to provide the Service.

Contact: hello@fullahead.app.

2. What we collect, why, and on what legal basis

  • Account data (name, email, organisation name, password hash, role) — to create and administer your account and provide the Service. Legal basis: performance of a contract.
  • Fleet content (vessels, equipment, maintenance jobs, certificates, evidence documents and any personal data you place in them) — to deliver the Service. Legal basis: performance of a contract; for third-party data you upload, your own legal basis as controller.
  • Support communications (messages, attachments) — to answer your requests. Legal basis: contract and legitimate interests in supporting customers.
  • Usage and telemetry (pages viewed, feature usage, audit log entries, timestamps) — to secure, debug and improve the Service. Legal basis: legitimate interests.
  • Device and technical data (IP address, browser and device identifiers, error reports) — for security, fraud prevention and reliability. Legal basis: legitimate interests and legal obligation.
  • Marketing preferences — to send product updates where you have asked for them. Legal basis: consent, withdrawable at any time.

AI features: prompts and the fleet data needed to answer them are sent to our AI provider to generate regulatory summaries and insights. We do not use your fleet content to train publicly available models.

3. Who we share data with

  • Service providers and subprocessors — hosting, database, email delivery, AI inference, error monitoring and support tooling, under written data-processing terms.
  • Paddle.com, our Merchant of Record, for the sale of subscriptions, subscription management, payments, tax compliance and invoicing.
  • Professional advisers — legal, accounting and audit, where necessary.
  • Authorities — where required by law or to establish, exercise or defend legal claims.
  • A successor — in a merger, acquisition or sale of the business.

We do not sell personal data.

4. International transfers

We are based in Cyprus (EU). Some of our providers process data outside the EEA. Where that happens, we rely on an adequacy decision of the European Commission or on Standard Contractual Clauses together with appropriate supplementary measures. You can request details of the safeguards used.

5. Retention

We keep account and fleet data for as long as your account is active, and for 30 days after termination to allow export, after which it is deleted or anonymised. Audit log and security records may be kept for up to 12 months. Records required for tax and accounting are kept for the period required by Cypriot law (generally six years).

6. Your rights

Under the EU GDPR you have the right to access your personal data, to rectification, to erasure, to restriction of processing, to data portability, to object to processing based on legitimate interests, and to withdraw consent at any time without affecting prior processing.

Contact hello@fullahead.app to exercise any of these rights; we respond within one month. You may also complain to the Office of the Commissioner for Personal Data Protection in Cyprus, or to the supervisory authority where you live or work.

7. Security

We apply appropriate technical and organisational measures, including encryption in transit, encryption at rest for stored data, row-level access controls that isolate each organisation's data, role-based permissions, audit logging and least-privilege access for administrators. No system is perfectly secure, but we will notify you and the relevant authority of a personal data breach where legally required.

8. Cookies and local storage

We use strictly necessary cookies and browser storage to keep you signed in, to remember preferences, and to cache your fleet data for offline use at sea. These are required for the Service to work. We do not use advertising cookies. If we introduce analytics or marketing cookies, we will ask for your consent first and you will be able to change your choice at any time. You can also clear cookies and site data in your browser settings, though this will sign you out and remove offline data.

9. Children

The Service is intended for business use and is not directed to children under 16.

10. Changes

We may update this notice. Material changes will be announced in the app or by email before they take effect.