Privacy Policy
We take your privacy seriously. This policy explains what we collect, why we collect it, and what your rights are.
Last updated: April 2026
1. Who we are
This privacy policy applies to the website and services of:
Lorrendraaier BV
Postbus 196
4870AD Etten-Leur
the Netherlands
Email: contact@lorrendraaier.nl
Telephone: +31 76 50 32 797
Chamber of Commerce (KvK): 66646162
2. What data we collect and why
We collect only the personal data that is necessary for the services we provide. This is called the principle of data minimisation. We do not collect data for data’s sake. Below is an overview of the categories of data we may process, the purpose, and the legal basis under GDPR Article 6.
| Category of data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Name, email address, telephone number | Responding to enquiries; managing the client relationship | Art. 6(1)(b) – performance of a contract or pre-contractual steps |
| Vessel ownership documents and purchase contracts containing personal data | Carrying out registration procedures; proof of ownership; compliance with flag state requirements | Art. 6(1)(b) – performance of a contract; Art. 6(1)(c) – legal obligation |
| Identity documents (e.g. passport copies), where required | Verification of identity as required by the shipping register or flag state authority | Art. 6(1)(c) – legal obligation; Art. 6(1)(b) – contractual necessity. We only request identity documents when strictly required by the relevant authority and when no less intrusive means of verification is available. |
| Financial and billing information | Invoicing; financial administration; VAT compliance | Art. 6(1)(c) – legal obligation (tax and accounting legislation) |
| Website usage data (via cookies and analytics) | Understanding how visitors use the website; improving content and navigation | Art. 6(1)(a) – consent (via cookie banner) |
| IP address and browser/device information | Website security; fraud prevention; technical functionality | Art. 6(1)(f) – legitimate interest (website security and operation) |
Privacy by Design. We apply the principle of privacy by design and by default. We collect only what is necessary for the specific purpose. We do not process personal data beyond what is needed for that purpose.Lorrendraaier is the data controller for the personal data described in this policy. This means we determine the purpose and means of processing your personal data. If you have any questions about how we handle your data, please contact us at the details above.
3. How long we keep your data
We do not keep your data for longer than necessary. The retention period depends on the type of data and the purpose for which it was collected.
| Type of data | Retention period | Reason |
|---|---|---|
| Client and registration files | 7 years after the end of the client relationship | Dutch tax and accounting obligations (Belastingdienst) |
| Financial records and invoices | 7 years | Legal obligation under Dutch tax law |
| Identity documents (passport copies) | Only for as long as required by the flag state authority or legal obligation; deleted promptly once the obligation is fulfilled | Minimisation principle; legal obligation |
| Contact form data and enquiries | 2 years, or until the purpose is fulfilled | Legitimate interest in maintaining records of correspondence |
| Website analytics data | As set by the analytics provider; typically 14 months | Consent; legitimate interest in website improvement |
When the retention period expires, data is securely deleted or anonymised. We document these retention periods and review them periodically.
4. How we keep your data secure
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or disclosure. These measures include:
- Encryption of data in transit (HTTPS / TLS)
- Secure, access-controlled storage for digital files
- Restricted access, only those who need the data to carry out their work can access it
- Secure deletion of data once retention periods expire
- Regular review of our security measures
We do not sell, share, or otherwise commercially exploit your personal data. Ever.
5. Who has access to your data
Your data is handled internally by Lorrendraaier. In the course of carrying out a registration, we may need to share data with third parties. We only do this where it is strictly necessary and where the recipient provides sufficient guarantees of appropriate data protection. Recipients may include:
- Flag state authorities and shipping registers – to process the registration application. This is an inherent necessity of the service.
- Specialist partners (e.g. maritime lawyers, tax advisors) – only where you have been informed and agreed, or where it is strictly necessary for the service.
- IT service providers – for hosting, email, and system management. These parties act as data processors under a data processing agreement (DPA) and may not use your data for their own purposes.
We do not share your data with third parties for marketing or advertising purposes. We do not share your data with parties outside the European Economic Area (EEA) unless the transfer is governed by appropriate safeguards under GDPR Chapter V (such as Standard Contractual Clauses).
6. Cookies
Our website uses cookies. A cookie is a small text file stored on your device when you visit a website. We use the following categories of cookies:
| Category | Purpose | Consent required? |
|---|---|---|
| Necessary | Essential for the website to function (e.g. session cookies, security cookies) | No – these are always active |
| Analytics | Understanding how visitors use the website (e.g. Google Analytics or similar) | Yes – only placed after consent |
| Functional | Remembering preferences (e.g. language, cookie consent status) | No – or yes, depending on the specific cookie |
You can change or withdraw your cookie preferences at any time by clicking the “View Preferences” button in the cookie banner on this website. You can also manage or delete cookies via your browser settings. Please note that disabling certain cookies may affect the functionality of the website.
7. Your rights under GDPR
Under the General Data Protection Regulation, you have the following rights with regard to your personal data. We are required to inform you of these rights and to facilitate their exercise.
How to exercise your rights. To exercise any of the above rights, please contact us at [contact@lorrendraaier.nl]. We will respond to your request within one month. In complex cases, we may extend this by a further two months, in which case we will inform you. We will not charge a fee for handling your request unless it is manifestly unfounded or excessive.
8. What happens if there is a data breach
Despite our security measures, a data breach can never be entirely ruled out. In the event of a breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours of becoming aware of the breach, where required under GDPR Article 33.
- Notify you directly if the breach is likely to result in a high risk to your rights and freedoms, as required under GDPR Article 34, without undue delay.
We maintain an internal data breach register in which all (suspected) breaches are documented, regardless of whether notification to the supervisory authority is required.
9. Data Protection Impact Assessment
Where we introduce new processing activities that are likely to result in a high risk to the rights and freedoms of individuals – for example, large-scale processing of sensitive personal data – we carry out a Data Protection Impact Assessment (DPIA) as required by GDPR Article 35. The outcomes of such assessments are used to implement appropriate safeguards before the processing begins.
10. Complaints
If you have a concern about how we handle your personal data, we would like to hear from you first so that we can try to resolve it. Please contact us at [contact@lorrendraaier.nl].
You also have the right to lodge a complaint directly with the Dutch supervisory authority:
Autoriteit Persoonsgegevens
Bezuidenhoutseweg 30
2594 AV Den Haag
Website: www.autoriteitpersoonsgegevens.nl
11. Changes to this policy
We may update this privacy policy from time to time. The date at the top of this page indicates when the policy was last revised. Where changes are significant, we will make reasonable efforts to inform you, for example, via a notice on the website. We encourage you to review this page periodically.