Legal
Privacy Policy
Last updated: July 24, 2026
Vessia is an online administration for inland shipping. This policy explains which personal data we process on this website (vessia.app) and in the app (app.vessia.app), why we do so and which rights you have.
01Who is responsible
Vessia is a product of Digitura, registered with the Dutch Chamber of Commerce under number 96508647 (VAT number NL005213731B50). Digitura is the controller for your account data and for the use of the website and the app. You can reach us at [email protected].
When you record data about others in your administration, such as charterers, contacts or crew, you are the controller for that data and Vessia only processes it on your behalf.
02Which data we process
We only process data that is needed to make Vessia work:
- Account data: your email address, your password (stored encrypted) or your external login, and an optional display name.
- Company profile: company name, address, Chamber of Commerce and VAT numbers, IBAN and the contact details you enter for your documents and invoices.
- Your administration: vessels, trips, time charters, charterers and their contacts, invoices, surveys and the documents you upload.
- Mileage records: vehicles, car trips and the odometer photos you upload.
- Sent emails: for every invoice or document email we keep a delivery record with sender, recipients, subject, content and attachments.
- Technical data: security logs in which IP addresses and browser characteristics only appear encrypted (hashed).
03What we use it for
We use your data for:
- Providing the service: storing your administration, completing documents and sending emails (performance of the contract).
- Your subscription and its billing through Stripe (performance of the contract and legal obligation).
- Security and abuse prevention (legitimate interest).
- Service emails, such as email verification, payment reminders and a notice when your trial is about to end (performance of the contract).
- Anonymised visitor statistics for the website (legitimate interest).
We show no ads, sell no data and do no profiling.
04Odometer photos and location
When you read an odometer straight from a photo, we only process the photo during recognition and do not store it. When you create draft car trips from photos, we keep the photos until you confirm or discard the drafts; after that we delete them.
Odometer recognition runs on our own servers; no photo is sent to an external AI service. If a photo contains GPS coordinates, we only send rounded coordinates to the Dutch PDOK location service to look up a place name. You can switch this off.
05Who we share data with
We only share data with parties that are needed to provide the service:
- Stripe, for payments and subscriptions.
- Amazon Web Services (EU region Stockholm), for document storage (S3) and the delivery of service and invoice emails (SES).
- The PDOK location service, which only receives rounded GPS coordinates (see above).
Visitor statistics run on our own server; no data goes to external analytics companies. Beyond this, we only share data when the law requires it.
06How long we keep data
We keep your data for as long as your account exists. When you delete your account or a vessel, we erase or anonymise the associated data immediately, including that vessel’s sent emails. Two exceptions: subscription and payment records are kept for the legally required (fiscal) retention period, and on a vessel that still has other members after you leave, email delivery records remain for their administration, decoupled from your name.
07Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction, objection and data portability. The most important rights are built into the app itself:
- Export all your data as a machine-readable file from your privacy settings (once per 24 hours).
- Delete your account and your data yourself from the same settings.
For other requests, email [email protected]. If you disagree with how we handle your data, you can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
08Security
We protect your data with, among other things:
- Encrypted connections (TLS) and encrypted password storage.
- Passkeys and two-factor authentication with recovery codes.
- Session management: you can see where you are signed in and revoke sessions.
- An extra confirmation step for sensitive actions, such as deleting your account.
- Roles per vessel, so everyone only sees what their work requires.
- Audit logging in which IP addresses and browser characteristics only appear hashed.
09Cookies
The app only uses strictly necessary cookies: to keep you signed in and to protect forms. There are no tracking or marketing cookies. Preferences such as theme and language are stored locally in your browser.
This website sets no tracking cookies. Visitor statistics are measured anonymously with a self-hosted analytics service.
10Changes and contact
If this policy changes in an important way, we will let you know through the app or by email. For privacy questions, contact [email protected].