Skip to content
CRALOG CRALOG
Find an ASP Become an ASP Academy Authorisations About Contact
Login
home Home search Find an ASP verified_user Become an ASP school Academy verified Authorisations info About mail Contact login Login

Privacy Policy

How CRALOG A/S processes personal data.

Document PP-01 | Version: October 2026

Academy, Software, Online purchasing, Certification, Authorisation and ASP Services

This Privacy Policy explains how CRALOG A/S processes personal data across its Academy, Software, online store, certification, authorisation and service activities. It is separate from the General Terms and Conditions.

1. Introduction

This Privacy Policy applies to Academy delegates, candidates, certified personnel, technicians, CRALOG Software users, business customers using the online purchasing functions, clients, suppliers, vessel contacts, employer and Authorised Service Provider contacts, website visitors and other persons whose personal data CRALOG receives or processes in connection with its activities.

Personal data may be provided directly by the person or through an employer, client, Authorised Service Provider, booking party, funding body, vessel or other relevant organisation. CRALOG processes personal data only for specified purposes and on an applicable lawful basis.

Where a person is asked to acknowledge this Privacy Policy, the acknowledgement confirms that the person has received and read the Policy. The acknowledgement does not constitute consent where another lawful basis applies and does not limit the person’s data-protection rights.

2. Data controller

CRALOG A/S, CVR no. 33156715, Knoten 7, DK-9900 Frederikshavn, Denmark, is the data controller for the personal data processing purposes determined by CRALOG and described in this Policy. Contact: info@cralog.com | +45 702 709 20.

Where CRALOG processes personal data solely on documented instructions from another data controller under a separate data-processing agreement, CRALOG acts as a data processor, and the respective roles and responsibilities are governed by that agreement.

3. Purposes of processing

  • administer accounts, enquiries, quotations, contracts, online orders, payments, invoicing, support and customer relationships;
  • administer Academy bookings, attendance, e-learning, training, assessment, reassessment and certification;
  • verify identity, prerequisites, practical experience, competence, certification and authorisation status;
  • issue and verify certificates, identification, authorisations, QR references, inspection records, reports and Statements of Fitness;
  • operate, secure, troubleshoot, maintain and improve CRALOG Software, websites and digital services;
  • administer employers, clients, Authorised Service Providers, vessel contacts, certified personnel, access rights and employment orders;
  • perform ASP services and document inspection, maintenance, examination, testing, overhaul, repair, traceability and work history;
  • meet contractual, quality, audit, accreditation, certification, statutory, regulatory, flag State, Recognized Organization, classification society, SOLAS, IMO and ISO requirements;
  • protect maritime safety, HSE, impartiality, system integrity and correct use of CRALOG authorisation;
  • prevent and investigate misuse, fraud, falsification, security incidents, complaints and non-conformities; and
  • establish, exercise or defend legal claims and respond to competent authorities and courts.

4. Categories of personal data

  • identity and contact data, including name, address, email, telephone, date of birth and nationality where relevant;
  • employer, job title, organisation, client, vessel and Authorised Service Provider information;
  • booking, attendance, order, payment, invoicing and customer-service records;
  • certificates, training, competence, authorisation, scope, validity, e-learning activity and progress, course completion, test results, assessment and reassessment records;
  • prerequisite and practical-experience evidence, including reports, logs, Statements of Fitness, photographs and videos;
  • signature, portrait/photo, identification and verification records;
  • inspection history, reports, checklists, equipment and vessel-related work records;
  • passport, visa, invitation-letter and travel information where specifically necessary;
  • health, accessibility, dietary or other special-requirement information where specifically necessary for safety, course participation, accommodation or catering;
  • account details, permissions, login, IP address, device/browser, security logs and system activity;
  • correspondence, support, complaints, incidents, conflicts of interest and non-conformity records; and
  • photos or recordings from Academy or service activities where relevant.

CRALOG does not use personal data for behavioural advertising, external marketing profiling or third-party advertising tracking. Payment-card data may be processed by CRALOG’s payment service provider; CRALOG processes only the transaction information needed for order, accounting, fraud and support purposes unless otherwise stated.

5. Legal bases

Contract and pre-contract steps: processing necessary to enter into or perform a contract with the individual, or to take steps requested by the individual before entering into a contract, including relevant enquiries, bookings, orders and requested services. Where the contract is with an employer, Authorised Service Provider or other organisation, related processing of delegate, user or personnel data is generally based on CRALOG’s and the organisation’s legitimate interests, legal obligations or another applicable lawful basis.

Legal obligations: processing necessary for accounting, documentation, safety, certification, authorisation, inspection, traceability or other applicable statutory and regulatory requirements.

Legitimate interests: operating and securing CRALOG’s business, Academy, Software and services; administering professionally sponsored training and assessment; working with educational, assessment and technical service providers; documenting competence, certification, authorisation and inspection history; verifying personnel and deliverables; quality assurance; communicating expiry, renewal and requirement changes; preventing misuse; handling complaints and incidents; and establishing, exercising or defending legal claims.

Consent: used where specifically requested and appropriate, including certain external publication of photos, videos, testimonials or marketing communications. Consent may be withdrawn at any time without affecting earlier lawful processing.

Special-category data: where CRALOG processes health or other special-category personal data, CRALOG will rely on explicit consent or another applicable condition under data-protection law. Such data will be collected only where necessary and handled with appropriate restrictions.

Vital interests or public-interest grounds: used only where applicable, for example in an emergency or where an applicable legal framework provides such a basis.

6. Sources of personal data

CRALOG receives personal data directly from the person; from an employer, client, booking party, funding body, Authorised Service Provider, vessel, colleague or representative; through CRALOG Software and online systems; from educational and training providers, instructors, assessors and learning platforms; and from certificates, reports, public registers, Maritime Administrations, Recognized Organizations, classification societies, certification bodies and other legitimate sources.

Where another party supplies personal data, that party must ensure it is entitled to do so and must provide any required privacy information to the affected person.

7. Recipients and access

CRALOG discloses or makes personal data accessible only where necessary for the relevant purpose and where an applicable lawful basis exists. Recipients may include:

  • authorised CRALOG personnel, administrators, instructors, assessors and support providers;
  • MARTEC, as CRALOG’s educational and assessment provider, for e-learning, training, attendance, assessment, reassessment, competence verification, quality assurance and related documentation;
  • learning-platform providers used for course delivery, including the Rise platform used by MARTEC;
  • the relevant employer, client, booking party, funding body, paying party and Authorised Service Provider;
  • vessel owners, operators, managers and shipboard personnel where verification or service performance requires it;
  • Maritime Administrations, flag States, Recognized Organizations, classification societies, certification, accreditation and audit bodies;
  • competent authorities, law enforcement, courts and professional advisers where justified;
  • hosting, infrastructure, payment, communications, security, maintenance and other service providers working for CRALOG; and
  • other recipients where the person directs CRALOG to disclose data or disclosure is otherwise lawful.

CRALOG may provide MARTEC with relevant identity and contact information, including name and email address; employer and booking information; previous certificates; prerequisite and practical-experience documentation; attendance and course information; photographs, videos and other assessment material; and information necessary for assessment, reassessment, certification and compliance with applicable SOLAS and ISO 23678 requirements.

MARTEC uses the delegate’s email address to provide access to e-learning through the Rise platform. The platform may process account, login, course activity, progress, completion and assessment-related information for delivery and administration of the e-learning.

Verification information disclosed to relevant parties may include name, employer, photo, signature, certification or authorisation status, scope, validity, identification, QR reference, report or Statement of Fitness status and related work records. Access is limited according to role, purpose and applicable requirements. Limited certificate verification is publicly available without login. The public verification result displays only the certified person’s name, photo and whether the relevant certificate is currently valid. No other personal data are made publicly available through this verification service.

A recipient may act as CRALOG’s data processor or as an independent data controller, depending on the recipient’s function and legal responsibilities. Where a recipient acts as an independent data controller, its own privacy information applies to its processing.

8. Storage location and international transfers

CRALOG Software and website data are hosted on CRALOG-controlled servers at Hetzner in two separate locations in Germany. CRALOG’s primary and backup hosting is within the EU/EEA.

Personal data used for e-learning, training and assessment may also be processed in systems used by MARTEC and through the Rise learning platform. The relevant provider determines or documents the applicable hosting locations and any international transfers for its services.

Authorised users, recipients and service providers may access relevant information from other countries. Where processing involves a transfer of personal data outside the EU/EEA, CRALOG or the relevant responsible recipient will use an applicable legal transfer mechanism and safeguards, such as an adequacy decision, standard contractual clauses and supplementary measures where required.

Information about relevant transfer safeguards may be requested from CRALOG. Where another recipient acts as an independent data controller, information about its transfers and safeguards may also be available in that recipient’s privacy information.

9. Retention

CRALOG retains personal data only as long as necessary for the purpose and applicable legal, accounting, contractual, certification, authorisation, safety, quality, traceability, audit and claims requirements.

Training, assessment, certification, authorisation, inspection, Statements of Fitness, reports and competence records may be retained for extended periods to document validity, history, the acting organisation and person, and work performed. Financial records are retained for the period required by accounting and tax law. Passport and visa records are deleted when the specific purpose and required retention end. Security and activity logs are retained according to operational, security and investigation needs.

When data are no longer required, CRALOG deletes or anonymises them, unless continued retention is permitted or required. A deletion request does not override a lawful retention duty or CRALOG’s need to establish, exercise or defend legal claims.

Personal data processed by MARTEC or another recipient may be retained according to that recipient’s legal responsibilities and documented retention requirements. Where the recipient acts as CRALOG’s data processor, deletion or return is governed by CRALOG’s instructions and the applicable data-processing agreement. Where the recipient acts as an independent data controller, its own retention rules and privacy information apply.

10. Security

CRALOG uses appropriate technical and organisational measures, including access controls, role-based permissions, authentication, logging, backups, monitoring, secure administration and incident procedures. Measures are reviewed and adjusted based on risk and system needs.

Users must protect credentials, devices, identification and verification material and must report suspected unauthorised access, loss or security incidents immediately. No system can be guaranteed completely secure, but CRALOG works to prevent, detect and respond to unauthorised processing.

CRALOG requires service providers processing personal data on its behalf to implement appropriate technical and organisational security measures. Where personal data are disclosed to an independent data controller, that recipient is responsible for the security of its own processing in accordance with applicable data-protection law.

11. Cookies, websites and online purchasing

CRALOG may use technically necessary cookies, session technologies and server logs for login, security, shopping-cart, checkout, language, load balancing and core functionality. These technologies do not require consent where they are strictly necessary under applicable law.

If CRALOG introduces non-essential analytics, marketing cookies or similar technologies, CRALOG will provide the required information and obtain consent before use. Cookie choices can be managed through the available interface where applicable.

Third-party learning platforms, including the Rise platform used by MARTEC, may use cookies, session technologies and technical logs required for login, security, course delivery and progress tracking. Where MARTEC or the platform provider determines the use of such technologies, the relevant provider’s own cookie and privacy information applies.

12. Photos, video and Academy activities

CRALOG may process photos and recordings for internal training, assessment, competence documentation, quality assurance, safety, incident review, certification and authorisation where an applicable lawful basis exists.

Photos, videos and recordings submitted for training, assessment, reassessment or competence verification may be made available to MARTEC and relevant instructors or assessors where necessary for those purposes. Such material is not used for external marketing or publication unless a separate lawful basis applies.

External publication on websites, social media or in branding, testimonials or marketing requires a separate lawful basis and, where consent is used, a freely given choice. Refusal or withdrawal of promotional consent does not affect course participation, assessment or certification. Withdrawal stops new use where reasonably possible but may not require the recall of material already lawfully distributed or published.

13. Automated decisions and marketing

CRALOG does not make decisions producing legal or similarly significant effects solely by automated processing unless CRALOG provides specific information and the safeguards required by law.

CRALOG may send service communications about accounts, orders, courses, certificates, expiry, renewal, reassessment, authorisation, safety, requirements and system changes where necessary for the relationship. Promotional electronic marketing is sent only where permitted, and recipients may opt out at any time.

14. Your rights

You may have the right to:

  • access your personal data and receive information about the processing;
  • have inaccurate or incomplete personal data corrected;
  • request erasure where the legal conditions are met;
  • request restriction of processing where the legal conditions are met;
  • object to processing based on legitimate interests, including an absolute right to object to direct marketing;
  • receive eligible personal data in a portable format where the data are processed by automated means based on consent or contract;
  • withdraw consent at any time, without affecting processing carried out before the withdrawal; and
  • submit a complaint to the Danish Data Protection Agency at www.datatilsynet.dk.

These rights are not absolute. CRALOG may need to retain or process records for legal, regulatory, contractual, certification, authorisation, safety, traceability, audit or claims purposes. CRALOG may request information necessary to verify your identity and will respond within the period required by law.

Requests concerning processing for which CRALOG is the data controller should be sent to info@cralog.com. Where MARTEC or another recipient acts as an independent data controller, requests concerning that recipient’s own processing should normally be directed to the relevant recipient. CRALOG will provide reasonable assistance in identifying the appropriate contact where necessary.

15. Children

CRALOG’s services, Software accounts, Academy activities, certification and professional training are not offered to children or persons under the age of 18. CRALOG does not knowingly collect personal data relating to children. If CRALOG becomes aware that such data have been submitted without a valid purpose, CRALOG will delete them unless retention is required by law.

16. Changes to this Policy

CRALOG may update this Policy to reflect changes in services, systems, law, requirements or processing. The current version and effective date will be made available through CRALOG’s website or systems. Material changes will be communicated where required. Earlier processing remains governed by the law and information applicable at that time.

17. Contact and complaints

Questions, requests or concerns about CRALOG’s processing of personal data may be sent to CRALOG A/S, Knoten 7, DK-9900 Frederikshavn, Denmark, by email to info@cralog.com or by telephone at +45 702 709 20.

A complaint may also be submitted to the Danish Data Protection Agency (Datatilsynet). Contact information and guidance are available at www.datatilsynet.dk.

Where a question or request concerns processing for which MARTEC or another recipient is an independent data controller, CRALOG will provide reasonable assistance in identifying the relevant recipient’s privacy information or contact point.

CRALOG CRALOG

CRALOG A/S
Knoten 7
DK-9900 Frederikshavn
Denmark

VAT: DK33156715

Company

About CRALOG Contact Verify a technician Brand Assets

Legal

Privacy Policy General Terms and Conditions Security & Hosting

Partners

MARTEC Training Center Enjoy Nordjylland
© 2026 CRALOG A/S. All rights reserved.