Legal
Privacy Policy
Processing of personal data in connection with the Nautech Services.
Effective date: 22 September 2026.
1. Controller and scope
Nautech Ltd. (“Nautech”, “we”), registered office 8230 Balatonfüred, Társasház utca 6. D. lház. 2. em. 5. ajtó, Hungary; company registration 19‑09‑523489; tax number 32146826‑2‑19, is the controller of the personal data processed in connection with Nautech Cloud and the Nautech mobile applications (together, the “Services”), including data transmitted to Nautech Cloud by the Nautech Core device (core, core PRO and core PRO+), within the meaning of Regulation (EU) 2016/679 (the “GDPR”) and Act CXII of 2011 (the “Infotv.”). You can reach us at mail@nautech.cloud, +36 30 178 3858 or +39 334 1420282. This notice forms part of the terms on which the Services are provided.
Nautech is a wholly owned subsidiary of Networker Ltd., which operates Nautech Cloud on our behalf as a processor. Any request concerning your personal data may be sent to mail@nautech.cloud, marked “Privacy”.
2. Personal data we process
| Category | Examples | Purpose |
|---|---|---|
| Account and contact | Name, email address, authentication details, telephone, language, organisation or fleet name | Creating and securing the account; service and support communications |
| Vessel and device | Vessel name, Nautech Core serial and hardware identifier, firmware, configuration, connected onboard devices | Provisioning the device; presenting the correct information; support and updates |
| Location | GNSS/GPS coordinates, speed, heading and timestamps | Real‑time monitoring, geofence and movement alerts, historical tracks, chart overlay |
| Onboard telemetry | Operational data from onboard systems over serial and Ethernet interfaces (for example NMEA 2000, with NMEA 0183 bridged over N2K): propulsion, power, tanks, environment, compass, digital switching | Real‑time dashboard, alerts, historical database |
| Camera recordings | Live imagery from connected cameras, Nautech‑supplied or your own; short clips of 30 to 60 seconds recorded on demand or on an alert | Remote supervision and an evidential record of events, as configured by you |
| Alerts and events | Threshold events, acknowledgements | Notifying you and authorised crew; operational history |
| Devices and security | For each device signed in to your account: software version, IP address and time of last login | Account security; managing active sessions and detecting unauthorised access |
| Support | Correspondence, call notes, installation particulars | Support and performance of the contract |
We do not process special categories of personal data under Article 9 GDPR, such as health, religious or biometric data, and we ask that you not provide any. A person you invite to a vessel or fleet may access the data shared with the role you assign.
3. Location data
The Nautech Core device has a GNSS receiver and a cellular modem for 4G, 5G and subsequent generations. When a device is registered to an account and connected, we process the vessel’s position and movement. Precise location is necessary to provide the Services, namely real‑time monitoring, geofencing, theft and drift alerts, historical tracks and chart overlay, and is processed to perform our contract with you under Article 6(1)(b) GDPR. We do not use location for advertising and we do not sell it.
4. Camera recordings
Where cameras are connected to the system, whether supplied by Nautech or your own, authorised users may view live imagery in the Nautech mobile applications or Nautech Cloud. The Services also record short clips of 30 to 60 seconds, either on your instruction or automatically when an alert is triggered. Clips are stored only in Nautech Cloud, hosted by Hetzner within the European Union, and are erased automatically after 30 days. A clip may contain images of identifiable persons. We process clips you initiate to perform our contract under Article 6(1)(b) GDPR, and alert‑triggered clips on the basis of our legitimate interest in recording evidence of the event and protecting the vessel under Article 6(1)(f) GDPR. You are responsible for operating cameras lawfully, including informing crew and guests where required, not directing cameras at the private spaces of third parties, and observing local surveillance rules. We do not use recordings for marketing.
5. Legal bases for processing
We process personal data on the following legal bases under Article 6 GDPR:
- Performance of a contract, Article 6(1)(b) — to provide the accounts, cloud history, alerts, remote supervision, telemetry shown to authorised users, integration with onboard systems, and the camera clips you initiate.
- Legitimate interests, Article 6(1)(f) — to secure the Services and prevent fraud and abuse, to keep the Services available, and to record alert‑triggered clips, balanced against your rights and freedoms.
- Legal obligation, Article 6(1)(c) — to comply with legal obligations to which we are subject, including lawful requests from competent authorities.
- Consent, Article 6(1)(a) — where you opt in to a newsletter or other marketing communications, and for any non‑essential cookies we may introduce. You may withdraw consent at any time, without affecting the lawfulness of prior processing.
We do not carry out automated decision‑making that produces legal or similarly significant effects concerning you under Article 22 GDPR. Alerts are threshold rules that you configure and do not constitute profiling.
6. Recipients and processors
We do not sell or rent your personal data, and we do not disclose it for the direct‑marketing purposes of others. We share it only as necessary to provide the Services, with:
- Persons you authorise — owners, skippers, crew and service partners you invite, according to the roles you assign.
- Networker Ltd., our parent company — operates Nautech Cloud on our behalf as our processor, within the European Union.
- Hetzner Online GmbH, Germany — cloud hosting.
- whereverSIM GmbH, Germany — cellular connectivity, where the optional “globalSIM” is fitted. Otherwise you use your own SIM and mobile operator, who is then your own provider and not our processor.
- Google LLC, United States — Android application distribution (Google Play) and push‑notification messaging through Firebase Cloud Messaging, which delivers notifications on both Android and iOS. Only a device token and the notification content are processed, not your account.
- Apple Inc., United States — iOS application distribution (App Store) and delivery of push notifications to iOS devices.
- Microsoft, Microsoft 365 — hosts our email mailboxes for correspondence to our addresses.
- Amazon Web Services, Amazon SES (Frankfurt region, EU) — sends certain service and notification emails on our behalf.
- Competent authorities, courts and emergency services, where disclosure is required by law or necessary to protect a person’s vital interests; and professional advisers bound by confidentiality.
Each processor acts under a data‑processing agreement pursuant to Article 28 GDPR. We may disclose aggregated or anonymised information that does not identify you.
7. International transfers
We store and process personal data within the European Economic Area (the “EEA”). Email is handled within the EU: Microsoft 365 (Exchange Online, set to the European Union / EFTA data region) and Amazon SES (Frankfurt). The only processing outside the EEA is the delivery of push notifications by Google (Firebase Cloud Messaging) and Apple in the United States, limited to a device token and the notification content; that transfer relies on the EU–US Data Privacy Framework, where the recipient is certified under it, and on the European Commission’s Standard Contractual Clauses. We make no other transfer outside the EEA.
8. Retention
We retain personal data only for as long as necessary for the purpose for which it was collected, after which it is erased or irreversibly anonymised:
- Account data — for the lifetime of the account, then erased or anonymised within a reasonable period after closure, unless a longer period is required by law.
- Camera clips — 30 days, then erased automatically.
- Historical telemetry and tracks — for the lifetime of the account, so that long‑term trends support monitoring and predictive‑maintenance analysis; then erased or anonymised within a reasonable period after closure.
- Support records — up to 5 years after the last communication, in line with the general limitation period for legal claims.
- Security logs — up to 12 months, retained longer only while an incident is being investigated.
Anonymised or aggregated data that no longer identifies you may be retained without a time limit for analysis and product improvement, including long‑term degradation and predictive‑maintenance models.
9. Your rights
Subject to the conditions in the GDPR, you have the rights of access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18) and data portability (Article 20); the right to object, on grounds relating to your particular situation, to processing based on legitimate interests, and an absolute right to object to direct marketing (Article 21); and the right to withdraw consent at any time. To exercise these rights, contact mail@nautech.cloud. We may need to verify your identity and will respond within one month, subject to any extension permitted by the GDPR. Certain vessel records may be retained for safety investigations, warranty or legal claims; where immediate erasure is not possible, we will explain why and restrict processing where appropriate.
10. Security
We apply technical and organisational measures appropriate to a connected‑vessel product: encryption in transit by TLS, including the cellular link to Nautech Cloud; role‑based access control; password hashing; restricted staff access; cryptographic keys held in the device’s secure element; and periodic review. Networker operates an ISO/IEC 27001‑certified information security management system covering the Microsoft 365 environment used for the Services. The Nautech Core device writes to its own local database first, so data is not lost in the absence of connectivity. Where a personal‑data breach is likely to result in a high risk to your rights, we notify the supervisory authority and, where required, you, under Articles 33 and 34 GDPR.
No electronic service is entirely secure, and radio, cellular and internet links may be interrupted at sea. This is an operational limitation of the Services and not a warranty of uninterrupted monitoring. You remain responsible for onboard safety, watch‑keeping, the COLREGs and applicable navigation rules; the Services are a remote‑supervision aid and not a substitute for seamanship.
11. Cookies
This page operates without advertising or analytics cookies; the hosting platform may set a strictly necessary session or security cookie. Nautech Cloud and the Nautech mobile applications use essential cookies or equivalent local storage to keep you signed in, which is necessary to provide the service you request. Should we introduce optional analytics or marketing cookies in future, we will obtain your consent first and list them here.
12. Children
The Services are intended for vessel owners, skippers, shipyards and fleet operators, and are not directed at children. We do not knowingly process the personal data of persons under 16 years of age. If you believe a minor has provided us with personal data, please contact us and we will erase it.
13. Changes to this policy
We may update this policy where the Services, the applicable law or our processors change. We will notify material changes through the Nautech mobile applications or by email, and update the effective date above.
14. Complaints and contact
For any question or complaint, contact us at mail@nautech.cloud. You have the right to lodge a complaint with the Hungarian supervisory authority, the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), 1055 Budapest, Falk Miksa utca 9–11., Hungary; naih.hu; ugyfelszolgalat@naih.hu; +36 1 391 1400; or with the supervisory authority of your habitual residence or place of work, and to an effective judicial remedy before the competent court.