Blue Stratum — Naviora
Legal

Privacy Policy

Last updated: 22 June 2026 ·  Effective: 22 June 2026

This Privacy Policy explains how Blue Stratum Ltd ("Blue Stratum", "we", "us", "our") collects, uses, stores, and shares your personal data when you use the Naviora platform and visit our website (collectively, the "Services"). It applies to all users including platform administrators, organization managers, and maritime training candidates.

We are committed to processing your personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the UK Data Protection Act 2018, and where applicable the EU GDPR. Please read this policy carefully. By using our Services you acknowledge you have read it.

1. Who we are

Blue Stratum Ltd is the data controller for personal data processed through the Naviora platform.

Company name
Blue Stratum Ltd
Registered in
England & Wales
ICO Registration
Pending
Data Protection contact
privacy@bluestratum.com

Where an organization subscribes to Naviora and administers candidates under their account, that organization acts as an additional data controller (or processor, depending on the relationship) for data relating to their candidates. A separate Data Processing Agreement (DPA) is available upon request.

2. Data we collect

2.1 Data you provide directly

  • Account data: name, work email address, job title, organization name.
  • Contact / demo requests: name, work email, organization, role, message, and your GDPR consent timestamps.
  • Candidate profiles: name, seafarer ID, nationality, qualifications, certificate numbers.
  • Assessment records: session dates, scores, evaluator notes, competency ratings, simulator performance data.
  • Certificates: digital certificate metadata including issue date, expiry, and issuing authority.

2.2 Data collected automatically

  • Usage data: pages visited, features used, session duration, button clicks.
  • Technical data: IP address, browser type and version, operating system, time zone, referring URL.
  • Log data: server access logs, error logs, API request logs (retained for security and debugging).

2.3 Data from third parties

  • Simulator performance data received via direct simulator integrations (Kongsberg, Wärtsilä/Transas, etc.) during assessment sessions.
  • Single sign-on (SSO/SAML) identity data from your organization's identity provider where configured.

3. How we use your data

We only process your data for specific, documented purposes with a valid legal basis.

PurposeLegal Basis (GDPR Art. 6)Retention
Respond to demo / contact requestsArt. 6(1)(a) — ConsentUntil withdrawn or 2 years after last contact
Provide and maintain the platformArt. 6(1)(b) — Contract performanceDuration of contract + 30 days
Conduct and record assessmentsArt. 6(1)(b) — Contract performance7 years (regulatory compliance)
Issue and verify digital certificatesArt. 6(1)(c) — Legal obligation10 years
Platform security and fraud preventionArt. 6(1)(f) — Legitimate interests90 days (logs) / ongoing (security data)
Product analytics and improvementArt. 6(1)(f) — Legitimate interests25 months (anonymised after 90 days)
Marketing communications (with consent)Art. 6(1)(a) — ConsentUntil consent withdrawn
Legal compliance and regulatory reportingArt. 6(1)(c) — Legal obligationAs required by applicable law

We will not use your data for automated decision-making or profiling that produces legal or similarly significant effects without your explicit consent.

4. Who we share data with

We do not sell your personal data. We share it only in the following circumstances:

  • Infrastructure providers: hosting, database, and storage services (currently Replit Inc., subject to a DPA) processing data on our behalf.
  • Email service providers: transactional email delivery (e.g. for account notifications and certificate issuance), under a DPA.
  • Your organization: where you are a candidate, your assessment results, competency records, and certificates are accessible to your organization's administrators within the platform.
  • Flag state / regulatory authorities: where legally required and at the direction of the subscribing organization (e.g. certificate verification).
  • Legal / law enforcement: where required by applicable law, court order, or to protect the rights and safety of our users.
  • Business transfers: in connection with a merger, acquisition, or sale of all or substantially all of our assets, subject to standard confidentiality obligations.

5. International transfers

Our primary data processing takes place within the UK and the European Economic Area (EEA). Where data is transferred outside the UK/EEA (for example, to infrastructure providers with US-based data centres), we rely on:

  • UK adequacy regulations for transfers to countries with an adequacy decision.
  • UK International Data Transfer Agreements (IDTAs) or EU Standard Contractual Clauses (SCCs) with appropriate supplementary measures.

A copy of the applicable transfer mechanism can be requested by emailing privacy@bluestratum.com.

6. Retention periods

We retain personal data for no longer than is necessary for the purposes for which it was collected. The specific periods are shown in the table in Section 3. Where legal obligations require us to retain data for a defined period (e.g. maritime certification records for 10 years), we apply that period. After expiry, data is securely deleted or anonymised.

If you withdraw consent for demo / marketing purposes, we will stop processing within 14 days and delete the relevant data within 30 days unless retention is required by law.

7. Your rights

Under UK/EU GDPR you have the following rights regarding your personal data:

Right of access
Request a copy of the personal data we hold about you (Subject Access Request).
Right to rectification
Require inaccurate or incomplete data to be corrected.
Right to erasure
Request deletion of your data where there is no compelling reason to continue processing.
Right to restriction
Ask us to pause processing while accuracy or legitimacy is verified.
Right to portability
Receive your data in a structured, machine-readable format.
Right to object
Object to processing based on legitimate interests or for direct marketing (absolute right).
Withdraw consent
Where processing is consent-based, withdraw at any time without affecting prior lawful processing.
Automated decisions
Not be subject to solely automated decisions that significantly affect you, without human review.

To exercise any of these rights, email us at privacy@bluestratum.com with the subject line "Data Subject Request — [Your Name]". We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).

8. Cookies

We use cookies and similar tracking technologies on our website. The table below summarises the types in use:

PurposeLegal Basis (GDPR Art. 6)Retention
Strictly necessaryArt. 6(1)(b) — Contract / legitimate interestsSession / 1 year
Functional (preferences)Art. 6(1)(a) — Consent1 year
Analytics (anonymised)Art. 6(1)(a) — Consent25 months
Marketing / targetingArt. 6(1)(a) — ConsentAs set by provider

You can control cookie preferences via the cookie banner displayed on your first visit, and update your preferences at any time by clicking "Cookie Settings" in the footer. Withdrawing consent for non-essential cookies does not affect the functionality of the core platform.

9. Children

The Naviora platform is not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data relating to a child under 18, please contact us immediately so we can delete it.

10. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in law, our practices, or our Services. We will notify registered users of material changes by email or prominent notice within the platform at least 14 days before the change takes effect. The "Last updated" date at the top of this page reflects the most recent revision.

Continued use of the Services after the effective date of a change constitutes acceptance of the updated policy. If you do not agree to a change, you should discontinue use and contact us to exercise your data rights.

11. Contact & data protection enquiries

For any questions, subject access requests, or concerns about this policy or our data practices, please contact our data protection team:

Response time
We aim to respond to all requests within 5 business days.
Supervisory authority
Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF — ico.org.uk/concerns