Global SAR Hub Logo

PRIVACY POLICY

ARTICLE 1 – PREAMBLE

The purpose of this Privacy Policy (hereinafter the “Policy”) is to inform the user of the CH16 mobile application (hereinafter the “User” and the “Application”), in a clear, complete and transparent manner, in accordance with Articles 12 to 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter the “GDPR”) and French Act No. 78-17 of 6 January 1978, as amended, on data processing, files and individual liberties, of the conditions under which their personal data is processed by GLOBAL SAR HUB.

This Policy forms an integral part of the Terms of Use and Sale of the Application and is expressly appended thereto by reference. Any term not defined in this Policy retains the meaning given to it in the Terms of Use and Sale.

ARTICLE 2 – IDENTITY OF THE DATA CONTROLLER

The controller of the personal data collected and processed within the framework of the Application is:

Corporate name: GLOBAL SAR HUB.

Form: simplified joint-stock company (société par actions simplifiée) with share capital of EUR 100.

Registered office: 60 rue François 1er, 75008 Paris, France.

Registration: Paris Trade and Companies Register No. 928 618 776 – SIRET No. 928 618 776 00019.

Legal representative: Ms Sarah LE COQ ZARANTONELLO, President.

Dedicated contact address: contact@globalsarhub.com.

GLOBAL SAR HUB is not required, in light of the criteria laid down in Article 37 of the GDPR, to appoint a data protection officer. Any request or complaint relating to the protection of personal data may be addressed to the dedicated contact point referred to above.

ARTICLE 3 – GUIDING PRINCIPLES

The processing of personal data carried out within the framework of the Application is based on the following guiding principles:

3.1. Minimisation. Only the data strictly necessary to provide the features is processed, in accordance with Article 5(1)(c) of the GDPR.

3.2. Non-retention by the Publisher. The Publisher has made the architectural choice not to retain any personal data relating to the User in its own databases. The data entered by the User into the Application is, depending on the feature concerned, either stored exclusively and locally on the User’s device, or transmitted to specifically identified third parties without retention by the Publisher.

3.3. No account creation. Use of the Application does not require the creation of any user account with the Publisher. Any identification of the User for the purpose of managing the Paid Plans is carried out exclusively by the Stores and their technical service provider.

3.4. Transparency. The User is informed, in clear and accessible terms, of the nature, purpose and arrangements of each processing operation.

3.5. Security. The Publisher implements appropriate technical and organisational measures to ensure the security of processing.

ARTICLE 4 – DATA PROCESSED, PURPOSES AND ARRANGEMENTS

The Publisher sets out below, by category of processing, the nature of the data processed, the purpose pursued, the place of storage and the treatment of the data.

4.1 Vessel configuration data

Upon first opening the Application, the User is invited to enter the name of their vessel, the MMSI number and the vessel type. This information is stored exclusively and locally in the device’s memory (local application storage). It is at no time transmitted to the Publisher, to its servers or to any third party, except where the User uses the Passage Plan feature (Article 4.4).

Deletion of the Application results in the definitive and irreversible erasure of this data. The User acknowledges that they will not be able to claim its restoration.

4.2 Geolocation data

Subject to the prior authorisation granted by the User by means of their device’s system dialog box, the Application accesses the geolocation data provided by the GNSS chip (GPS, GALILEO, GLONASS or equivalent) integrated into the device.

This data is processed locally on the device for the sole purposes of:

(i) identifying in real time the SRR in which the User is located and presenting them with the competent RCC;

(ii) powering the Man Overboard Mode feature, by locally recording a position at the time of its activation;

(iii) allowing the User to trace a Passage Plan.

Geolocation data is at no time transmitted to the Publisher, to its servers or to any third party, subject to the information voluntarily entered by the User within the framework of a Passage Plan. The User may revoke at any time, from their device settings, the geolocation access authorisation, it being specified that such revocation will render certain features inoperative.

4.3 Data entered for the generation of a Text Message

When the User generates a Text Message (MAYDAY, PAN PAN or MOB), the information they enter (in particular relating to the vessel, the crew, the nature of the situation) is processed exclusively and locally on the device to produce the corresponding visual or audio aid. No data is transmitted to the Publisher or to any third party by reason of this feature. The Application does not issue any message.

4.4 Data transmitted within the framework of a Passage Plan

When the User activates the Passage Plan feature and validates the transmission, the Application sends by email, through the SMTP servers operated by the Publisher with the provider LWS, a host established in France, an email to the email addresses of the RCCs whose SRR will be crossed by the route entered.

The email comprises the information voluntarily entered by the User, which may include, without limitation: vessel identification, crew composition, safety equipment, planned ports of call and their dates, means of propulsion, shore contacts.

Upon completion of the transmission, the Publisher retains no copy of the email content in its databases. Technical traceability of the transmissions may, however, be retained for operational management and evidentiary purposes, for a period not exceeding thirteen (13) months, in the form of connection logs devoid of the substantial content of the Passage Plans.

The recipient RCCs become, upon receipt of the email, autonomous data controllers for the data they decide to retain, archive or use, within the framework of their public service missions and in accordance with the applicable international conventions and the national law applicable to them. The Publisher exercises no control over the processing of data by the recipient RCCs.

4.5 Technical data and identifiers

The Application processes the following technical data:

(i) a technical installation identifier, generated locally, enabling the provision of the features;

(ii) information relating to the device (model, operating system version, language settings);

(iii) a push notification token (push token) issued by the Apple Push Notification Service (Apple Inc.) or Firebase Cloud Messaging (Google LLC) where the User consents to receiving notifications;

(iv) a pseudonymous identifier (“anonymous identifier”) generated by the RevenueCat platform for the purpose of managing subscription status, which does not enable the Publisher to directly identify the User.

4.6 Statistical and traffic data

The Publisher collects, through the RevenueCat platform and the audience measurement tools associated with the Stores, aggregated and anonymised indicators relating to the traffic of the Application, the number of Users, the geographical distribution of downloads and the subscription rate to the Paid Plans. This data enables neither the direct nor the indirect identification of Users.

4.7 Advertising data

In the free version, the Application displays an advertising banner operated by Google AdMob (Google LLC). On this basis, advertising trackers (cookies, advertising identifiers such as the IDFA on iOS and the Advertising ID on Android) may be placed on the User’s device, under the conditions referred to in Article 10.

Subscription to a Paid Plan results in the removal of advertising banners and, consequently, of the associated advertising trackers.

ARTICLE 5 – LEGAL BASES FOR PROCESSING

In accordance with Article 6 of the GDPR, the legal bases on which each processing operation relies are as follows:

ARTICLE 6 – RECIPIENTS OF THE DATA

The recipients of the personal data processed within the framework of the Application are strictly the following:

6.1. The Publisher and its authorised personnel, within the limits of their respective duties and exclusively for operational, security and support purposes.

6.2. The rescue coordination centres (RCCs) that are recipients of the emails transmitted within the framework of a Passage Plan, becoming autonomous data controllers upon receipt.

6.3. The Publisher’s technical processors, acting on its behalf and in accordance with Article 28 of the GDPR, under the conditions specified in Article 7 below.

6.4. The competent administrative or judicial authorities, by reason of a legal obligation, a court decision or a lawful requisition.

Personal data is neither sold, rented nor transferred to third parties for commercial prospecting purposes, in any form whatsoever.

ARTICLE 7 – PROCESSORS AND THIRD-PARTY DATA CONTROLLERS

The scope of intervention of technical third parties varies according to the operations concerned. In accordance with the doctrine of the European Data Protection Board (Guidelines 07/2020 on the concepts of controller and processor), a distinction must be drawn between processors acting on behalf of the Publisher on documented instructions, and third parties acting as autonomous data controllers for their own purposes.

7.1 Processors within the meaning of Article 28 of the GDPR

The following technical third parties act on behalf of the Publisher, on documented instructions and under an obligation of confidentiality and security:

7.2 Third parties acting as autonomous data controllers

The following technical third parties process personal data as autonomous data controllers for their own purposes, which are defined in their respective privacy policies. The Publisher exercises no control over this processing and does not assume the status of joint controller:

Each third party implements security measures consistent with the state of the art and publishes its own privacy policy, accessible from its respective website. The User is invited to consult them for the processing operations for which such third parties act as autonomous data controllers.

ARTICLE 8 – RETENTION PERIODS

The retention periods for personal data are set as follows:

8.1. Vessel configuration data and any other data entered into the Application: stored exclusively on the User’s device, until uninstallation of the Application or reset at the User’s initiative.

8.2. Geolocation data: processed in volatile memory, not retained.

8.3. Content of Passage Plan emails: not retained by the Publisher after transmission. Retention by the recipient RCCs is governed by their own policies.

8.4. Technical logs of Passage Plan email transmissions (metadata): thirteen (13) months from their creation.

8.5. Push notification tokens: for the duration of actual use of the Application and for as long as the User has not revoked their consent.

8.6. RevenueCat pseudonymous identifiers: for the duration of the subscription cycle and in accordance with RevenueCat’s retention policy.

8.7. Data retained as evidence of consent to trackers: six (6) months from its collection, in accordance with the recommendation of the French Data Protection Authority (CNIL).

8.8. Data retained for the purpose of legal defence: duration of the applicable statutory limitation period.

ARTICLE 9 – TRANSFERS OUTSIDE THE EUROPEAN UNION

Certain processing operations involve a transfer of personal data outside the European Union and the European Economic Area, in particular to the United States of America as a result of the use of Apple Inc., Google LLC and RevenueCat, Inc.

These transfers are governed in accordance with Chapter V of the GDPR, by the cumulative or alternative implementation of the following safeguards:

(i) an adequacy decision of the European Commission (in particular the EU-United States adequacy decision of 10 July 2023 relating to the Data Privacy Framework), for adhering organisations and for as long as that decision remains in force;

(ii) the standard contractual clauses adopted by the European Commission by Implementing Decision (EU) 2021/914 of 4 June 2021;

(iii) the implementation of appropriate supplementary technical and organisational measures.

The User may obtain, upon written request sent to contact@globalsarhub.com, further information on the safeguards in force as well as a copy of the applicable standard contractual clauses.

ARTICLE 10 – TRACKERS, COOKIES AND CONSENT MANAGEMENT

10.1. In accordance with Article 82 of French Act No. 78-17 of 6 January 1978, as amended, and the guidelines of the French Data Protection Authority (CNIL) of 17 September 2020, the Application presents to the User residing in the European Economic Area or the United Kingdom, upon first opening and upon any substantial modification, a consent management platform (CMP), enabling the free, informed, specific and unambiguous collection of their consent to the placing and reading of advertising trackers.

10.2. The User may accept, refuse or customise their choices. Refusal is as simple and accessible as acceptance. The trackers strictly necessary for the operation of the Application are not subject to prior consent.

10.3. The User may change their choices at any time from the Application’s settings menu.

10.4. The trackers liable to be placed for advertising purposes mainly emanate from the Google AdMob advertising network (Google LLC). The details of the categories, purposes and lifespans are set out in the CMP interface.

ARTICLE 11 – APPLE APP TRACKING TRANSPARENCY (iOS)

On devices running the iOS operating system, the Application implements, in accordance with Apple Inc.’s requirements, the App Tracking Transparency framework. A system dialog box is presented to the User asking them to authorise or refuse tracking by the Application by means of the IDFA advertising identifier.

The User’s refusal affects neither access to the Application nor access to the free features. Its sole consequence is to prevent the IDFA identifier from being made available to the advertising network, which may then display non-personalised advertising.

ARTICLE 12 – RIGHTS OF THE DATA SUBJECT

In accordance with Articles 12 to 22 of the GDPR, the User has, at any time, the following rights over their personal data:

12.1. Right of access (Article 15 GDPR): to obtain confirmation that data concerning them is being processed and, where applicable, a copy of such data.

12.2. Right to rectification (Article 16 GDPR): to obtain the rectification of inaccurate or incomplete data.

12.3. Right to erasure (Article 17 GDPR): to obtain the erasure of data in the cases provided for by the GDPR.

12.4. Right to restriction of processing (Article 18 GDPR): to obtain the restriction of processing in the cases provided for by the GDPR.

12.5. Right to portability (Article 20 GDPR): to receive the data provided in a structured, commonly used and machine-readable format.

12.6. Right to object (Article 21 GDPR): to object, on grounds relating to their particular situation, to processing based on the legitimate interest of the Publisher.

12.7. Right to withdraw consent (Article 7(3) GDPR): to withdraw their consent at any time, without such withdrawal affecting the lawfulness of prior processing.

12.8. Right to define post-mortem directives (Article 85 of the Act of 6 January 1978, as amended): to organise the fate of data after death.

The User may exercise their rights electronically at the address contact@globalsarhub.com or by post to the address of the Publisher’s registered office. The Publisher undertakes to provide a response within a period of one (1) month from receipt of the request, which may be extended by two (2) months in the event of complexity or a large number of requests.

The User is informed that, as a result of the principle of non-retention, certain rights may become devoid of purpose vis-à-vis the Publisher. The rights relating to the data retained by the Stores, by RevenueCat, by the advertising network or by the RCCs receiving the Passage Plans must be exercised directly with the entities concerned.

The User further has the right to lodge a complaint with a supervisory authority, and in particular, for French residents, with the French Data Protection Authority (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris cedex 07, website www.cnil.fr.

ARTICLE 13 – SECURITY OF PROCESSING

13.1. The Publisher implements appropriate technical and organisational measures, having regard to the nature, scope, context and purposes of the processing, to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR.

13.2. These measures include in particular: the encryption of application flows (TLS), the design of the system around a principle of non-retention of data by the Publisher, the restriction of access to authorised personnel, the traceability of sensitive operations, and the application of security updates published by the editors of third-party components.

13.3. In the event of a personal data breach likely to give rise to a risk to the rights and freedoms of natural persons, the Publisher notifies the competent supervisory authority within a period of seventy-two (72) hours and, where the risk is high, informs the data subjects, in accordance with Articles 33 and 34 of the GDPR.

ARTICLE 14 – AUTOMATED DECISION-MAKING AND PROFILING

In accordance with the information obligation provided for in Article 13(2)(f) of the GDPR and Article 22 of the same Regulation, the Publisher informs the User that the provision of the Application does not involve any decision based solely on automated processing, including profiling, producing legal effects concerning them or similarly significantly affecting them.

The processing operations carried out by the Application are based on deterministic rules (in particular geolocation, SRR identification, generation of Text Messages) that do not carry out any evaluation of the User’s personal characteristics, any behavioural prediction or any segmentation for decision-making purposes.

The advertising processing operations carried out by third-party networks (in particular Google AdMob) may, where the User consents, involve advertising targeting. Such targeting does not produce legal effects or similarly significantly affect the User within the meaning of Article 22 of the GDPR. The User may object to it at any time via the consent management platform described in Article 10.

ARTICLE 15 – MINORS

15.1. The Application is rated 4 years and over on the Stores. Its content does not specifically target minors and does not encourage any risky behaviour.

15.2. In accordance with Article 8 of the GDPR and Article 7-1 of French Act No. 78-17 of 6 January 1978, as amended, where processing is based on the consent of the data subject and that person is resident in France, such consent may validly be given as from the age of fifteen (15). Below this age, consent is given jointly by the minor and by the holder(s) of parental authority. In other Member States of the European Union, the age from which a minor may validly consent alone is that set by the national legislation, up to a maximum of sixteen (16).

15.3. The Publisher does not knowingly collect any personal data relating to a minor under the age of fifteen (15) without the prior consent of the holder(s) of parental authority. Subscription to a Paid Plan is subject to the prior authorisation of the legal representative for any User who has not reached the age of majority in their country of residence.

15.4. The holder(s) of parental authority of a minor who has used the Application may request, under the conditions of Article 12, the exercise of any GDPR right on behalf of that minor.

15.5. If the Publisher becomes aware that personal data relating to a minor has been processed in breach of these provisions, it will erase it without delay and take the appropriate technical and organisational measures to prevent the situation from recurring.

ARTICLE 16 – MODIFICATIONS TO THIS POLICY

16.1. The Publisher reserves the right to modify this Policy at any time, in particular to take account of legislative, regulatory, case-law, technical or operational developments.

16.2. Any substantial modification is brought to the User’s attention by in-app notification and, where applicable, by the collection of a new consent where such collection is required.

16.3. The date of last update appearing at the head of this Policy evidences the applicable version. Earlier versions are retained by the Publisher for evidentiary purposes only.

ARTICLE 17 – CONTACT AND COMPLAINT

For any question relating to this Policy or to exercise the rights referred to in Article 12, the User may contact the Publisher:

By email: contact@globalsarhub.com.

By post: GLOBAL SAR HUB – CH16 Personal Data Compliance – 60 rue François 1er, 75008 Paris, France.

Failing a satisfactory response, the User may lodge a complaint with the competent supervisory authority, in particular the French Data Protection Authority (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris cedex 07, www.cnil.fr.

ARTICLE 18 – LEGAL NOTICE

In accordance with Article 6-III of French Act No. 2004-575 of 21 June 2004 on confidence in the digital economy:

Publisher: GLOBAL SAR HUB, SAS with share capital of EUR 100, Paris Trade and Companies Register No. 928 618 776, SIRET No. 928 618 776 00019, APE Code 6201Z, intra-Community VAT number FR 44 928 618 776, registered office 60 rue François 1er, 75008 Paris, France.

Publication director: Ms Sarah LE COQ ZARANTONELLO.

Contact: contact@globalsarhub.com.

Hosting of the Publisher’s website and of the SMTP servers: LIGNE WEB SERVICES (LWS), SAS with share capital of EUR 500,000, Paris Trade and Companies Register No. B 851 993 683, SIRET No. 851 993 683 00024, APE Code 6311Z, intra-Community VAT FR 21 851 993 683, Paris establishment 10 rue Penthièvre, 75008 Paris, France.

© 2026 GLOBAL SAR HUB – All rights reserved.

CH16 is a registered trademark of GLOBAL SAR HUB.