Privacy notice

Online ADN Safety Adviser processes business personal data and case information only for clear, necessary purposes. This notice explains what data is processed, why, with whom it may be shared and how long it is retained.

Last updated: 28 August 2026

1. Controller

The controller is schipperhuren.nl, trading as Online ADN Safety Adviser, Dutch Chamber of Commerce (KvK) 75954109. Privacy enquiries can be sent to advies@adnveiligheidsadviseur.nl.

The service is intended for business users. Business contact data can nevertheless be personal data when it identifies an individual.

2. Data we process

  • Account and identification data such as business email address, name, organisation and authentication data.
  • Case data you provide, such as the question, messages, documents, photographs, necessary vessel or company information and feedback.
  • Invoice and payment references needed to link payments and administration to the correct pseudonymous case. Full card or bank details are not stored in the case portal.
  • Technical and security data needed for authentication, abuse prevention, error handling and operational security.
  • Email and notification status such as delivery status, timestamp and provider reference without unnecessary substantive case information.
  • Newsletter address and preferences if you separately subscribe to a newsletter.

3. Purposes and legal bases

  • Taking steps before entering into a contract and performing the contract, including intake, assessment, case management, communication, feedback, release and payment.
  • Compliance with legal, tax and administrative obligations.
  • Legitimate interests in security, fraud prevention, quality assurance, audit trails, dispute handling and the establishment, exercise or defence of legal claims.
  • Consent where a processing activity specifically relies on consent, such as a voluntary newsletter subscription. Consent can be withdrawn for the future.

4. Data minimisation and confidentiality

Each request receives a pseudonymous case number in the format ADN-2026-XXXXX. Vessel name, ENI and other identifying operational information are processed only when needed for the assessment or formal record.

Substantive case information stays in the secure case environment as far as possible. Ordinary notification emails deliberately do not contain detailed situation descriptions, UN data, documents or advice text.

5. Recipients and service providers

Specialised service providers may process data for the technical and administrative delivery of the service. These currently include Supabase for database, storage and authentication, Vercel for hosting and runtime, Stripe for payments and invoicing, Resend for transactional email, Cloudflare Turnstile for abuse prevention and Google when you voluntarily choose Google sign-in.

Where necessary, data may also be disclosed to accountants, insurers, professional advisers, competent authorities or other parties when a legal duty or a specific legal interest requires it.

Appropriate contractual and technical safeguards are used with service providers. Where processing occurs outside the EEA, recognised transfer mechanisms and appropriate safeguards are used where required, such as an adequacy decision, applicable certification or Standard Contractual Clauses.

6. Retention

  • Account and profile data: while the business account is needed. Following a valid account-deletion request, operational profile and sign-in data are removed unless a legal duty or legal claim still requires particular information.
  • Cancelled or uncommissioned requests without financial processing: normally no more than 12 months after closure unless a specific obligation requires longer retention.
  • Completed cases, including accepted scope, relevant correspondence, feedback, release records and final advice versions: normally 7 years after case closure.
  • Financial administration, invoice data and necessary payment references: at least 7 years under Dutch tax-record requirements; a longer statutory period is applied only where it is relevant to the specific record.
  • Technical security and error logs: only for as long as needed for operational security and incident investigation; where an infrastructure provider controls the period, the shortest appropriate provider setting is used.
  • If there is a dispute, incident, insurance matter, investigation or possible legal claim, only the information necessary for that purpose may be retained longer until the specific need ends. Dutch limitation periods for damage claims can in certain cases extend to 20 years and for specific environmental damage or particular hazards to 30 years; these are not default retention periods for every case.
  • Newsletter data: until unsubscribe. A minimal suppression record may then be kept to avoid sending to an unsubscribed address again.
  • Deleted data may remain temporarily in routine protected backups until overwritten through the normal backup cycle; it is not restored for normal business use.

7. Security

The case portal uses protected routes, access controls, Row Level Security where applicable, separated server secrets, protected document access and data minimisation in notifications and payment metadata. No safeguard can remove every risk, so controls are reviewed and adjusted periodically.

8. Cookies and local storage

The application uses technically necessary storage for authentication, sessions, language preferences and security. The current release does not configure advertising trackers or behavioural marketing profiles. External security or login providers may use their own technical cookies or storage where needed for their operation.

9. Google sign-in and automated decisions

If you choose Google sign-in, the authentication service receives the information needed for that sign-in. Email/password and a secure email link remain alternatives.

Substantive ADN advice is not determined solely by automated decision-making producing legal or similarly significant effects. Payment and security providers may apply their own automated fraud or security checks under their terms.

10. Your rights

Requests can be sent to advies@adnveiligheidsadviseur.nl. For an existing case, preferably mention only the case number. Identity verification may be required first to protect the person concerned.

  • Access to and a copy of your personal data.
  • Rectification of inaccurate or incomplete data.
  • Erasure where there is no legal or other valid ground for continued retention.
  • Restriction of processing and, where applicable, objection to processing based on legitimate interests.
  • Data portability for processing to which that right applies.
  • Withdrawal of consent for future processing where consent is the legal basis.

11. Complaint and changes

You may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). This notice may be updated when the service, law or technical setup changes. The current version is published on this website.

Company and contact details

schipperhuren.nl — Online ADN Safety Adviser

Privacy contact: advies@adnveiligheidsadviseur.nl

Dutch Chamber of Commerce (KvK): 75954109

VAT ID: NL003028871B47

Lodge a complaint with the supervisory authority: Autoriteit Persoonsgegevens