Skip to main content

Legal — Breach notification policy

Breach notification policy.

Last updated: 2026-07-29.

1. Controller and processor

Provenship is processor for customer-uploaded operational data (voyages, bunker delivery notes, vessel particulars); where a personal data breach affects those records, the customer is controller and notifies their lead supervisory authority. Provenship assists per GDPR Art. 33(2). Provenship is controller for tenant-relationship data (billing contacts, breach register, DSAR audit log) and notifies the competent supervisory authority directly for breaches in that scope.

2. Supervisory authority within 72 hours (Art. 33)

When Provenship becomes aware of a personal data breach for which it is controller, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours per Art. 33(1). Where notification cannot be made within 72 hours, it is accompanied by the reasons for the delay. The 72-hour clock starts at the moment we become aware of the breach, not at notification submission.

3. Data subjects when high risk (Art. 34)

Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, Provenship communicates the breach to the affected data subjects without undue delay, in clear and plain language per Art. 12(1) GDPR, containing the elements required by Art. 34(2): nature of the breach, name and contact of the Data Protection Officer, likely consequences, and the measures taken or proposed.

4. Sub-processor cascade (Art. 33(2))

Provenship's sub-processors (Amazon Web Services / Bedrock, Amazon SES, BoldSign for signed verifier statements, Airwallex for invoicing) notify Provenship of any personal data breach without undue delay per Art. 33(2). Provenship in turn notifies affected customer-controllers within 24 hours of confirmed sub-processor breach so that the customer can meet its Art. 33(1) 72-hour obligation to its own supervisory authority.

5. Internal breach register (Art. 33(5))

Provenship maintains an internal breach register documenting facts, effects, and remedial actions for every reported breach. The register is retained 7 years per ADR-022 (Firehose to S3 Object Lock, WORM) and is protected as audit-trail data under Art. 32.

6. How to report a suspected breach to Provenship

Email security [at] provenship.com. Out of hours, the address routes to an on-call inbox monitored 24/7. Include the affected tenant, time of detection, scope summary, and any containment already in place.

7. Data Protection Officer

Reach the DPO at dpo [at] provenship.com. Complaints may also be filed with your national supervisory authority.