NERMO

Legal

Privacy policy.

How personal data is processed across the NERMO platform and this website.

1. Who we are

The NERMO platform — the Client Portal, the Vendor Portal, the NERMO API and MCP surface, and the public website at nermo.io including its registration forms — is operated by:

Vinterstrom OÜ (operating as NERMO)
Registry code: 17505744
Registered address: Tornimäe tn 5, 10145, Tallinn linn, Harju maakond, Estonia
Email: privacy@nermo.io

Vinterstrom OÜ is the controller of the personal data described in this policy, except where stated otherwise.

NERMO is a business-to-business maritime procurement intermediary: it routes orders between vessel operators and port-local suppliers. Our users are businesses and the individuals who act for them. We do not offer services to consumers or children.

2. Scope

This policy covers personal data processed through:

  • the Client Portal (vessel owners, fleet managers, superintendents, captains and their staff);
  • the Vendor Portal (port-local suppliers and their staff);
  • the NERMO API and MCP surface (programmatic and AI-agent access on behalf of clients);
  • the public website, including the “Request Access” (client) and “Apply as Vendor” registration forms;
  • related operational communications.

It does not cover the internal privacy practices of vendors or client organisations, who are independent controllers of their own data.

3. Summary table

The table below is a plain-language summary; Sections 4–9 are the full description and prevail over the table.

CategoryTypical dataPurposeLegal basis (Art. 6 GDPR)Retention
Portal user accountsName, work email, phone, role, login and session recordsProvide and secure portal/API accessLegitimate interest (operating the service for your employer); contract where you are the contracting partyAccount life + a post-closure period
Client application (registration form)Company details, contact name/role/email/phone, beneficial owner / director names (DOB, nationality optional). Vessel identities and billing details are not collected on the form: they are entered later, in the Client Portal, when the first vessel is addedVet and onboard the client; sanctions/KYC screening; billing setup (at the first vessel add)Legal obligation / legitimate interest (screening); pre-contractual steps (Art. 6(1)(b))Declined applications: identifying personal data purged 90 days after decision; approved: account life
Vendor application (registration form)Company details, legal identifiers, contact details, beneficial owner / director names, terms acceptanceVet and onboard the vendor; sanctions/KYC screeningLegal obligation / legitimate interest (screening); pre-contractual stepsSame as client applications
Vendor KYC and bankingUBO/director identification, compliance documents, bank account details (IBAN/SWIFT)KYC, payee verification, payment of rebates and ordersLegal obligation / legitimate interest; contractRelationship life + statutory record-keeping period
Procurement recordsRFQs, quotes, orders, invoices, delivery records naming individual signatories/contactsOperate the procurement service; accountingContract; legal obligation (accounting/tax)Statutory accounting period
Crew-related data (where a client records it)Dietary/allergen requirements, crew counts, nationality where processedProvision planning (galley/menu features); complianceContract / legitimate interestClient-controlled + a scheduled retention window
Sanctions screening recordsNames screened, list-match results, adjudication decisionsSanctions complianceLegal obligation / legitimate interestCompliance record period
API / MCP service accountsService-account identifiers, the authorising organisation and administrator, usage and audit logsProgrammatic access, security, auditContract; legitimate interestAccount life + audit retention
Audit logActor identity, action, timestamp, affected records (sensitive values excluded)Tamper-evident record of all system changes; regulatory evidenceLegal obligation; legitimate interestDefined audit retention period
Support and business contact dataContact details, call/email contentAnswering enquiries, onboarding outreach, collections follow-upLegitimate interest; consent where requiredScheduled retention window
Website / cookiesSession and security data; with your consent on the public website: analytics and advertising cookie data (pseudonymous identifiers, page paths with campaign parameters)Operate the site and forms; abuse prevention; with consent: usage measurement and ad-campaign measurementLegitimate interest (operation/security); consent (analytics/advertising, Art. 6(1)(a))Session-bound / short-lived; analytics cookies 12 months; see Section 13

4. Where your data is stored

Personal data processed on the NERMO platform is stored in the European Union: a single EU-located database and EU-located object storage. Authentication is handled by an identity provider that NERMO self-hosts in the EU — your login credentials are not processed by a third-party identity service. Limited, safeguarded exceptions are described in Section 8 (international transfers). Consent-based website analytics involves a transfer described in Section 8; it runs only on the public website and only after you opt in.

5. What we process, and why

5.1 Portal users (Client Portal, Vendor Portal, Staff)

If you hold a portal account, we process: your name, work email address, phone number where provided, your role and permissions within your organisation, and authentication data (managed by our self-hosted identity provider — password hashes and, where enabled, MFA/passkey/SSO artefacts), plus login and session security records.

Purposes and bases: providing and securing access to the platform. Where you personally are our contracting counterparty, the basis is performance of a contract (Art. 6(1)(b)). Where — as is usual — you act for a client or vendor organisation, the basis is our legitimate interest (Art. 6(1)(f)) in performing our contract with your organisation and keeping the platform secure.

5.2 Client-side data (vessel operators)

Client organisations and their users cause us to process:

  • Vessel data: vessel names, IMO numbers, types, flags, ports of call and delivery schedules (ETAs). Vessel data is company data, but in context it can relate to identifiable individuals (e.g. the master of a named vessel at a known port) and vessel movements are treated as sensitive in context — see Section 5.6.
  • Procurement records: requisitions, RFQs, quotes, orders, delivery confirmations and invoices, which may name individual contacts, signatories, masters or pursers.
  • Crew-related data, where a client chooses to record it: crew counts and budgets, and galley/provisioning data such as dietary and allergen requirements used for menu and provisioning planning. NERMO’s provisioning features are designed around dishes and products, not crew member profiles; however, where a client records dietary or allergen information in a way that relates to identifiable crew members, that data may reveal health information or religious beliefs.
  • Crew nationality data, where processed (e.g. for compliance or provisioning purposes): treated as sensitive in context and stored with column-level encryption — see Section 10.
  • Billing data: billing entity, billing contact name and email, billing address, VAT number, contract currency, invoices and payment records.

Purposes and bases: operating the procurement service and subscription billing (contract, Art. 6(1)(b), with the legitimate-interest overlay for individuals acting for the client as in 5.1); accounting and tax record-keeping (legal obligation, Art. 6(1)(c)); sanctions screening of vessels and counterparties (Section 6).

5.3 Vendor-side data (port-local suppliers)

Vendor organisations and their users cause us to process:

  • Company and KYC identification: legal entity details, registration and VAT numbers, and the names and roles of beneficial owners and directors (with date of birth and nationality where provided), collected for know-your-counterparty vetting and sanctions screening.
  • Compliance documents: certifications and supporting documents a vendor provides during onboarding and thereafter.
  • Banking details: bank account information (IBAN/SWIFT) and payee-verification records, used so that clients can pay vendors and NERMO can administer rebates. Banking details are stored with column-level encryption (Section 10).
  • Catalog and quoting data: product catalogues, price lists, port coverage, quotes and order history. This is primarily business data but may include the names and contact details of vendor staff.

Purposes and bases: vendor vetting, KYC and sanctions screening (legal obligation and/or legitimate interest — Section 6); operating the marketplace relationship, quoting, orders and rebate settlement (contract / legitimate interest); statutory record-keeping (legal obligation).

5.4 Website applicants (registration forms)

The public “Request Access” and “Apply as Vendor” forms collect the application data listed in Section 3 (company details; the primary contact’s name, role, email and phone; beneficial owner / director names, with date of birth and nationality optional; for vendors, legal identifiers and supplier-terms acceptance — a client’s vessel identities and billing details are entered later, in the Client Portal, when the first vessel is added). We also record your acceptance of the applicable terms and the application’s progress, and we operate anti-abuse controls on the forms (rate limits and a CAPTCHA challenge — see Section 13 on cookies).

Applications are processed through an automated onboarding workflow with sanctions/KYC screening (Section 6). You can check your application’s status with your application reference; the status endpoint deliberately returns only a coarse status and never screening detail.

Purposes and bases: taking steps prior to entering into a contract (Art. 6(1)(b)); screening (Section 6); abuse prevention on a public form (legitimate interest).

Declined or expired applications: identifying personal data collected in the application (including beneficial-owner records and the application snapshot) is purged 90 days after the decision; a minimal record of the decision and the screening event log is retained as a compliance record.

5.5 API and MCP callers

Programmatic access — including AI procurement agents acting for a client over the MCP surface — is authenticated via OAuth service accounts or delegated user authorisation. We process: service-account identifiers, the authorising organisation and administrator, token and credential metadata, permission scopes, and request/usage logs (including idempotency keys and correlation identifiers). Every action taken through the API or MCP surface is attributed and audit-logged the same way as portal actions.

Purposes and bases: providing the contracted service (contract / legitimate interest); security, abuse prevention and auditability (legitimate interest; legal obligation for the audit record).

5.6 Data that is sensitive in context

Some data we process is not “special category” data under Art. 9 GDPR on its face, but is sensitive in the maritime context, and we treat it accordingly:

  • Crew nationality data — subject to flag-state and port-state data-protection expectations; stored encrypted at column level.
  • Vessel ports of call, ETAs and delivery schedules — can reveal information about identifiable individuals on board and are commercially and security-sensitive. (NERMO does not ingest live vessel-position/AIS data; if that changes, this policy must be updated first.)
  • Beneficial-ownership data — encrypted at column level and disclosed only as needed for screening and legal compliance.

Where genuinely special-category data arises (e.g. dietary data revealing religion or health — Section 5.2), we apply Art. 9 safeguards.

6. Sanctions and KYC screening; automated decision-making

As a maritime procurement intermediary, NERMO is required to screen its counterparties. Personal data — including the names of beneficial owners, directors and contact persons — is screened against applicable sanctions and watchlists (including OFAC, EU and UK consolidated lists) at onboarding and on an ongoing basis, and vessel identity/ownership data is screened in the same way when a vessel is added and on an ongoing basis after that. KYC checks are performed on vendors (including payee-name verification of banking details).

How screening decisions work: screening is automated-first, with human review of every hit, screening error or ambiguous result. A clear (no-match) result allows an application to proceed automatically. A hit or a screening error is escalated to a NERMO compliance reviewer, who decides before any account is opened. Where an automated result is ambiguous (a possible match needing list review), a vendor account is not opened until a compliance reviewer has adjudicated it; a client account may be opened first, and while no screening provider is engaged a NERMO compliance reviewer completes the list review against the public consolidated lists within one business day and deactivates the account on a confirmed match. A confirmed match on a vessel is confined to that vessel: the vessel is declined and can no longer be used to order, you are told so with a reason drawn from a fixed vocabulary of service reasons rather than screening detail, and your account and your other vessels stay open. Only a confirmed match on the client itself or on a related party (an owner, controller, beneficial owner or director) deactivates the account. No application is declined, and no vessel is declined, without human involvement.

Legal basis: compliance with legal obligations to which we are subject (Art. 6(1)(c)) and/or our legitimate interest in complying with sanctions regimes applicable to the transactions we route and to our payment-facilitation role (Art. 6(1)(f)).

Screening records (who was screened, against what, the result, and any human adjudication) are retained as compliance records even where an application is declined (Section 9).

7. Recipients and subprocessors

We do not sell personal data. We share personal data only with:

  • Your counterparties, as the service requires: when an RFQ is routed, a vendor sees the vessel, port and line details needed to decide whether and how to quote — but not the client organisation’s identity, which (together with the delivery contact and port-agent details needed to fulfil and invoice) is disclosed only to the winning vendor at award. The client sees the vendor’s quoting identity and prices. Prices and commercial terms are transparent between the parties by design.
  • Payment and screening providers acting in regulated roles: where the optional pre-funded payment facilitation is used, payment data is processed by our payment provider; sanctions/KYC screening providers process counterparty data as part of their own regulated function.
  • Service providers (subprocessors) that support the platform, under data-processing terms.
  • Public authorities where required by law (e.g. sanctions authorities, courts, regulators).

Current subprocessors, by category:

  • Transactional email delivery (EU sending domain): recipient email addresses and the content of the notification email we send you about your RFQs, orders, deliveries and billing.
  • Business email hosting (EU data residency): correspondence you send to, or receive from, our published @nermo.io addresses — including anything you attach.
  • Text-embedding computation (US): product-name text strings only, for product-catalogue matching. No personal data is sent: payloads are bare product-naming strings — no names, emails, crew data, supplier identities, prices, vessel or port context, or tenant identifiers (test-enforced).
  • Consent-based website analytics (Google — Google Ireland Limited; Google LLC, US): with your consent on the public website only, pseudonymous analytics identifiers and page-usage data (paths and campaign parameters — no form content, tokens, or references). Consent-gated behind a per-purpose banner; Google acts as processor for analytics measurement and as an independent controller for advertising uses you separately consent to. Transfer: see Section 8.

A named subprocessor list is available to clients and vendors on request via privacy@nermo.io and under our data-processing terms.

Infrastructure providers: the platform runs on EU-region managed infrastructure (cloud hosting and database, object storage, workflow orchestration, observability). Plaintext personal data is stored only in the EU; the workflow-orchestration service processes only minimised identifiers and payloads encrypted under keys held by NERMO in the EU (see Section 8).

We will update this notice before any new provider processes personal data.

8. International transfers

Our posture is EU-only storage of personal data: the database, object storage and the self-hosted identity provider are located in the EU, and plaintext personal data stays in EU systems.

Limited transfers outside the EU/EEA can occur where a provider requires it:

  • Our workflow-orchestration provider is a US company operating an EU region. Workflow payloads are minimised (internal identifiers and status values only — personal data is designed not to cross this boundary, enforced by tooling) and additionally encrypted end-to-end under keys held by NERMO in the EU, so the provider handles ciphertext and minimised metadata. Because encrypted/pseudonymised data is still personal data, we treat this as a transfer and rely on Standard Contractual Clauses with the encryption and minimisation as supplementary measures.
  • The product-name embedding provider (Section 7) processes in the US, but receives no personal data.
  • Website analytics (with your consent): Google Analytics data is received by Google Ireland Limited, with Google LLC (United States) as recipient. The transfer relies on the EU-US Data Privacy Framework adequacy decision (Google LLC is DPF-certified), with the Standard Contractual Clauses incorporated in Google’s data-processing terms as fallback. This processing exists only on the public website, only after opt-in, and carries no client, vendor, or applicant record content.

9. Retention

Our approach: keep personal data only as long as the purpose requires, then delete it on a scheduled, automated basis (retention sweeps), subject to statutory retention duties.

  • Declined/expired applications: identifying personal data purged 90 days after the decision; the decision record and screening event log are retained as compliance records (Section 5.4).
  • Accounts and tenant data: retained for the life of the relationship; on termination, tenant data is deleted or returned; the per-category schedule is agreed in the client agreement and data-processing addendum.
  • Procurement, invoicing and payment records: retained for the statutory accounting/tax period.
  • Sanctions/KYC screening records: retained per applicable compliance regimes.
  • Audit log: every change in the platform is recorded in an append-only (write-once) audit log that cannot be modified or deleted by the application, with sensitive values excluded from log content by design; it exists to provide regulators and counterparties tamper-evident evidence.
  • Operational and infrastructure records (delivery/webhook queues, idempotency keys, staging data): pruned automatically on short windows (days to ~90 days).
  • Consent-based website analytics (public website only): the analytics cookies expire after 12 months and the advertising cookies after 3 months; the pseudonymous event data held at Google Analytics is retained for 14 months and then deleted automatically. Withdrawing consent deletes the cookies immediately (Section 13).

10. Security

Personal data is protected by layered controls: strict per-organisation isolation enforced at the database layer, so one client or vendor can never read another’s data; encryption in transit and at rest, with additional column-level encryption (keys held separately from the database) for the most sensitive fields — banking details, KYC documents, beneficial-ownership data, and crew-related personal records; role- and permission-based access control on every operation, for humans and machine clients alike; and a tamper-evident audit trail of every change. Access by NERMO staff is permission-gated and audited.

11. Your rights

Under the GDPR you have the right to: access your personal data; rectify inaccurate data; erasure (“right to be forgotten”); restriction of processing; data portability; object to processing based on legitimate interest, including any direct marketing; withdraw consent at any time where processing is based on consent; and not be subject to solely automated decisions with legal or similarly significant effects, subject to the exceptions in Art. 22 (see Section 6 — screening hits always receive human review, and you may contest a screening outcome and request human intervention).

To exercise your rights, contact privacy@nermo.io. We will respond within one month (extendable as GDPR permits). Note that we may be legally prevented from deleting or disclosing certain records (e.g. sanctions-screening and accounting records), and that where NERMO processes data as a processor for a client organisation, we may refer your request to that organisation as the controller.

12. Complaints

You may lodge a complaint with the Estonian supervisory authority:

Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate) — www.aki.ee, info@aki.ee.

You may also complain to the supervisory authority of your habitual residence or place of work within the EU.

13. Cookies

The NERMO portals use strictly necessary cookies (session/authentication, same-origin request protection) plus the optional first-party nermo_theme preference cookie (12 months, set only when you pick a theme, consent-exempt as a user-requested preference). The public registration forms use an anti-abuse CAPTCHA challenge, which may set a functional token for that purpose. The portals use no analytics or advertising cookies.

On the public website (nermo.io) only, we use Google Analytics measurement cookies and — as a separately consented purpose — Google advertising cookies, each only with your prior consent, collected through a consent banner with independent per-purpose toggles (rejecting is as easy as accepting). No request is made to Google before you opt in. These cookies are host-scoped to the website and never reach the portals or the API. You can change or withdraw your choice at any time via “Cookie preferences” in the site footer or on the application forms; withdrawal stops collection immediately and deletes the cookies. Withdrawal is forward-looking — for data already collected you can additionally use Google’s own deletion controls, or contact privacy@nermo.io; data already collected is in any case retained at Google Analytics for at most 14 months and then deleted automatically (Section 9). Full detail, including the cookie table and durations, is in the Cookie Notice. Google’s role and the associated transfer are described in Sections 7 and 8.

14. Changes to this policy

We may update this policy as the platform and the law evolve. Material changes will be notified to account holders via the portals or email before they take effect. Prior versions will be available on request.