Template — requires legal review before publication. This page is a general website template. It is not legal advice and does not guarantee compliance with the law of any country. Have it reviewed by a qualified lawyer for the jurisdictions in which SeafarerFit operates.
Placeholders in [square brackets] must be completed before publication.
This policy describes how SeafarerFit protects personal data internally. It complements the Privacy Policy.
Principles
- Lawfulness, fairness and transparency
- Purpose limitation — data is used only for the purpose collected
- Data minimisation — health information is not collected unless genuinely necessary
- Accuracy, storage limitation, integrity and confidentiality
- Accountability
Health information
Calculators and questionnaires are processed client-side. Health values are never placed in URLs, analytics events, public REST endpoints or logs.
Access control
Staff roles (Administrator, Medical Content Editor, Directory Manager, Content Editor, Reviewer) receive only the permissions they need. Messages and tracker data are accessible to administrators only.
Security measures
HTTPS, password hashing, nonces/CSRF protection, input validation and output escaping, prepared database queries, rate limiting, security headers, encryption of tracker data, audit logs, backups and timely updates.
Breach response
[DESCRIBE INCIDENT RESPONSE AND NOTIFICATION TIMELINES REQUIRED IN EACH JURISDICTION.]
Responsible person
[NAME / ROLE], with oversight by the Platform Administrator, V.K. SINGH.