We at Enesel Group (the "Group") respect your privacy and are aware that we expected to handle all personal data responsibly. We have, therefore, developed this Policy to clearly describe what types of information we gather, how this information is used, with whom it is shared and why, and to ensure that the Company complies fully with the EU General Data Protection Regulation (Regulation (EU) 2016/679) (the "General Data Protection Regulation" or "GDPR").

This privacy notice is provided in a layered format so you can click through to the specific areas set out below. Please also use the Glossary to understand the meaning of some of the terms used in this privacy notice.

1.1 Purpose of This Privacy Notice

This privacy notice explains how the Enesel group of companies (the “Group”, “we”, “us” or “our”) collects and processes personal data, whether through this website, through our business dealings with you, or in the course of our employment and recruitment activities.

This privacy notice supplements any other privacy or fair processing notices we may provide on specific occasions and is not intended to override them.

1.2 Applicable Data Protection Laws

The Group operates across multiple jurisdictions. The data protection laws applicable to the processing of your personal data depend on which Group entity is responsible for that processing:

  • For Enesel Group Limited (UK) and Enesel Partners Limited: the UK General Data Protection Regulation (the “UK GDPR”) as retained under the European Union (Withdrawal) Act 2018 and as amended by the Data Protection Act 2018 (the “DPA 2018”)
  • For Group entities established in the EU/EEA: Regulation (EU) 2016/679, the General Data Protection Regulation (the “EU GDPR”), together with applicable national implementing legislation
  • For Group entities outside the UK and EU/EEA: the applicable local data protection legislation in the relevant jurisdiction (see the entity table at section 1.4 below)

Where this notice refers to “data protection laws” or “applicable data protection legislation”, it means whichever of the above regimes applies to the relevant processing activity.

1.3 Data Controllers

Each Group entity that determines the purposes and means of processing your personal data acts as an independent data controller in respect of that processing. The identity of the controller will depend on the context in which your personal data is collected — for example, which entity you contract with, are employed by, or interact with.

Where two or more Group entities jointly determine the purposes and means of processing (for example, shared client due diligence), they will act as joint controllers and will have arrangements in place to allocate their respective responsibilities.

1.4 Group Entities and Contact Details

If you have any questions about this privacy notice or wish to exercise your rights, please contact the relevant entity using the details below:

Entity

Email

Address

Regime

Enesel S.A.

privacy-wet@eneselgroup.com

Kolonaki International Center, 23A Vasilissis Sofias Avenue, Athens 106-74, Greece

EU GDPR

Enesel Dry S.A.

privacy-dry@eneselgroup.com

Kolonaki International Center, 23A Vasilissis Sofias Avenue, Athens 106-74, Greece

EU GDPR

Enesel Group Limited

compliance@eneselgroup.com

5 Hanover Square, London W1S 1HE, United Kingdom

UK GDPR / DPA 2018

Enesel Partners Limited

compliance@eneselpartners.com

5 Hanover Square, London W1S 1HE, United Kingdom

UK GDPR / DPA 2018

Enesel ApS

compliance@eneselgroup.com

Kalkbraenderiloebskaj 4, 2100 Copenhagen Ø, Denmark

EU GDPR

Enesel Bulk Logistics DMCC

compliance@eneselgroup.com

Office No. 3701, JBC 5, Cluster W, Jumeirah Lakes Towers, UAE

UAE PDPL / DIFC DP Law (as applicable)

Enesel Bulk Logistics Pte Ltd

compliance@eneselgroup.com

8 Cross Street, #05-01, Manulife Tower, Singapore 048424

PDPA 2012

Enesel Bulk Logistics Pte Ltd (Germany Branch)

compliance@eneselgroup.com

Willy-Brandt Allee 31b, 23554 Lübeck, Germany

EU GDPR / BDSG

Enesel Bulk Logistics SpA

compliance@eneselgroup.com

Alonso Monroy 3020, Office 102, Vitacura, 7630483 Santiago, Chile

Chilean Data Protection Law (Law 19,628)

 

Note: Enesel Bulk Logistics Pte Ltd (Germany Branch) is a branch establishment of Enesel Bulk Logistics Pte Ltd (Singapore). It is not a separate legal entity, but is subject to EU GDPR by virtue of its establishment in the EU. References to it as a separate entry in this table are for contact and regulatory purposes only.

1.5 Changes to This Privacy Notice

We may update this privacy notice from time to time. Where changes are material, we will take reasonable steps to bring them to your attention. The date at the top of this notice indicates when it was last updated.

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.

1.6 Third-Party Links

This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices. We encourage you to read the privacy notice of every website you visit.

“Personal data” means any information relating to an identified or identifiable natural person. It does not include data from which identity has been irreversibly removed (anonymous data).

We may collect, use, store and transfer the following categories of personal data about you:

  • Identity Data: first name, last name, maiden name, username or similar identifier, title, date of birth, gender, nationality, marital status, passport or national ID details
  • Contact Data: postal address, email address, telephone numbers
  • Financial Data: bank account details, payment card details, tax identification numbers, national insurance or social security numbers, source of funds and wealth
  • Employment Data: employment history, qualifications, references, right-to-work documentation, seafarer certifications (where applicable)
  • Transaction Data: details about payments to and from you, details of contracts and services
  • Technical Data: IP address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website
  • Communications Data: the content and metadata of correspondence with us by email, post, telephone or other means
2.1 Special Categories of Personal Data

We may also process special categories of personal data about you, including information about your health, racial or ethnic origin, religious beliefs, trade union membership, or (in limited circumstances) biometric data. We will only process special category data where we have a lawful basis to do so under applicable data protection laws — for example, where processing is necessary for the purposes of carrying out our obligations in the field of employment law, or where you have given your explicit consent.

2.2 Criminal Conviction Data

We may process information relating to criminal convictions and offences where this is authorised by applicable law — for example, in connection with pre-employment screening or regulatory obligations. In the UK, such processing is carried out in accordance with the conditions set out in Schedule 1 of the DPA 2018. We will not process criminal conviction data on the basis of consent alone.

2.3 Aggregated Data

We may collect, use and share aggregated or statistical data derived from your personal data. Aggregated data is not considered personal data in law where it does not directly or indirectly reveal your identity. However, if we combine aggregated data with your personal data so that it could identify you, we treat the combined data as personal data.

2.4 If You Fail to Provide Personal Data

Where we need to collect personal data by law or under the terms of a contract with you, and you do not provide that data when requested, we may be unable to perform the contract we have or are seeking to enter into with you. We will notify you if this is the case.

We collect personal data through the following means:

Direct Interactions

You may provide us with Identity, Contact, Financial and Employment Data by corresponding with us, entering into contracts with us, or applying for a position with us. This includes personal data you provide when you:

  • apply for employment or a crew position;
  • enter into a commercial relationship with us or your employer does so;
  • offer your services or your company’s services to us;
  • interact with us at industry events, in meetings or by other business communications.

Third parties and publicly available sources

We may receive personal data about you from recruitment agencies, your employer, credit reference agencies, fraud prevention agencies, regulatory bodies, third party service providers, publicly available registers and directories, and other Group entities.

Automated Technologies

When you interact with our website, we may automatically collect Technical Data about your equipment, browsing actions and patterns using cookies, server logs and similar technologies. Please see section 11 (Cookies) below for further details.

We will only process your personal data where we have a lawful basis to do so. The lawful bases we rely on most commonly are:

  • Contract: where processing is necessary for the performance of a contract with you (or to take steps at your request prior to entering into a contract).
  • Legal obligation: where processing is necessary for compliance with a legal or regulatory obligation to which we are subject.
  • Legitimate interests: where processing is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
  • Consent: in limited circumstances, where you have given your explicit consent to the processing. Where we rely on consent, you may withdraw it at any time (see section 9.7 below).
4.1 Purposes and Lawful Bases

The table below sets out the purposes for which we process personal data, the categories of data involved, and the lawful bases we rely on.

Purpose

Data Categories

Lawful Basis

Recruitment and onboarding of employees, contractors and crew

Identity, Contact, Employment, Special Category Data (where required by law)

Performance of contract; Legitimate interests (assessing suitability); Legal obligation (right to work checks)

Client and counterparty due diligence, including KYC, AML and sanctions screening

Identity, Contact, Financial,  Employment, Publicly available information

Legal obligation (AML/CTF regulations); Legitimate interests (risk management)

Entering into and performing contracts for the provision of shipping, chartering and related services

Identity, Contact, Financial, Transaction data

Performance of contract; Legitimate interests (managing our commercial operations)

Processing and receiving payments

Identity, Contact, Financial, Bank account details

Performance of contract

Managing insurance claims and P&I notifications

Identity, Contact, Transaction data, Incident details

Performance of contract; Legitimate interests (claims management); Legal obligation

Communicating with current and prospective clients, business partners and counterparties

Identity, Contact

Legitimate interests (relationship management); Performance of contract

Compliance with legal and regulatory obligations

All categories as required

Legal obligation

Defending or prosecuting legal claims

All categories as relevant to the claim

Legitimate interests (legal proceedings); Legal obligation

IT administration and website security

Technical data (IP address, browser type, device information)

Legitimate interests (network and information security)

Business development and marketing (where applicable)

Identity, Contact

Legitimate interests (promoting our services); Consent (where required)

We may process your personal data on the basis of more than one lawful ground depending on the specific purpose. Please contact us if you need details about the specific legal ground we are relying on.

4.2 Legitimate Interests

Where we rely on legitimate interests as a lawful basis, we have carried out a balancing assessment to ensure that our interests are not overridden by the impact on your rights and freedoms. You may request details of the balancing assessment by contacting us using the details in Section 1.4.

4.3 Change of Purpose

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and explain the legal basis for doing so.

We may process your personal data without your knowledge or consent where this is required or permitted by law.

We may share your personal data with the following categories of recipients:

  • Intra-Group: other companies within the Enesel Group, acting as controllers or processors in connection with the services and operations described in this notice
  • Professional advisers: lawyers, bankers, auditors, insurers and other professional advisers who provide consultancy, banking, tax, legal, insurance and accounting services to us
  • Service providers: third parties who provide IT and system administration services, document storage, back-office support, recruitment services, payroll and benefits administration, fund administrators, distribution and fund transfer agency service providers
  • Regulatory and public bodies: governmental, tax and regulatory authorities, including (as applicable) HMRC, the Financial Conduct Authority, the Information Commissioner’s Office, the Hellenic Data Protection Authority, port state control authorities, flag state registries, and other bodies to which we are required to report
  • Fraud prevention and credit agencies: credit reference agencies and fraud prevention agencies
  • Prospective buyers or investors: third parties to whom we may choose to sell, transfer or merge parts of our business or our assets. If a change happens to our business, the new owners may use your personal data in the same way as set out in this notice

We require all third-party recipients to respect the security of your personal data and to process it in accordance with applicable law. We do not allow our service providers to use your personal data for their own purposes and only permit them to process it for specified purposes in accordance with our instructions.

The Group operates internationally. Your personal data may be transferred to, stored in, and processed in countries other than the country in which it was collected, including countries outside the United Kingdom and the European Economic Area (“EEA”).

Transfers from the UK. Where Enesel Group Limited (or any other UK-established entity) transfers personal data outside the UK, we ensure that appropriate safeguards are in place as required by the UK GDPR. These may include:

  • transfers to countries that the UK Secretary of State has determined provide an adequate level of protection;
  • the UK International Data Transfer Agreement (“IDTA”) or the UK Addendum to the EU Standard Contractual Clauses; or
  • other appropriate safeguards recognised under UK data protection law

Transfers from the EU/EEA. Where our EU/EEA-established entities transfer personal data outside the EEA, we rely on:

  • transfers to countries that the European Commission has determined provide an adequate level of protection;
  • the EU Standard Contractual Clauses adopted by the European Commission; or
  • other appropriate safeguards recognised under the EU GDPR

Please contact us if you would like further information about the specific safeguards applied to any particular transfer.

We have put in place appropriate technical and organisational security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. We limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They process your personal data only on our instructions and are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable supervisory authority of a breach where we are legally required to do so.

We will only retain your personal data for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, regulatory or reporting requirements.

To determine the appropriate retention period, we consider:

  • the amount, nature and sensitivity of the personal data;
  • the potential risk of harm from unauthorised use or disclosure;
  • the purposes for which we process the data and whether we can achieve those purposes through other means; and
  • the applicable legal, regulatory and contractual requirements

Indicative retention periods. As a general guide:

  • contractual and transactional records are retained for 6 years following the end of the relevant contract or transaction (in line with applicable limitation periods);
  • recruitment records for unsuccessful candidates are retained for up to 12 months following the recruitment decision;
  • employment records are retained for 6 years following the end of employment; and
  • records required for tax purposes are retained in accordance with the requirements of the relevant tax authority

A detailed retention schedule is available on request. In some circumstances you may ask us to delete your data: see section 9.3 below.

We may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

Under applicable data protection laws, you may have some or all of the following rights in relation to your personal data. Not all rights apply in all circumstances, and some rights are subject to conditions and exceptions under applicable law.

9.1 Right of Access

You have the right to request a copy of the personal data we hold about you and to check that we are lawfully processing it (commonly known as a “data subject access request”).

9.2 Right to Rectification

You have the right to request correction of personal data that is inaccurate or incomplete.

9.3 Right to Erasure

You have the right to request deletion of your personal data where there is no good reason for us continuing to process it, where you have successfully exercised your right to object, where we may have processed your information unlawfully, or where we are required to erase it to comply with applicable law. We may not always be able to comply with your request for specific legal reasons, which will be explained to you at the time.

9.4 Right to Restrict Processing

You have the right to request that we suspend the processing of your personal data in certain circumstances — for example, if you want us to establish its accuracy, where our use of the data is unlawful but you do not want us to erase it, where you need us to hold the data for the purposes of a legal claim, or where you have objected to our use and we need to verify whether our legitimate grounds override yours.

9.5 Right to Data Portability

You have the right to request the transfer of your personal data to you or to a third party in a structured, commonly used, machine-readable format. This right applies only to automated information that you initially provided to us on the basis of consent or for the performance of a contract.

9.6 Right to Object

You have the right to object to the processing of your personal data where we are relying on a legitimate interest and there is something about your particular situation which makes you want to object. You also have the absolute right to object to processing for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.

9.7 Right to Withdraw Consent

Where we are relying on your consent to process personal data, you may withdraw that consent at any time by contacting us. Withdrawal of consent does not affect the lawfulness of any processing carried out before the date of withdrawal. If you withdraw your consent, we may not be able to provide certain services to you, and we will advise you if this is the case.

9.8 Right to Complain

You have the right to make a complaint at any time to the relevant supervisory authority for data protection matters. For Enesel Group Limited, the supervisory authority is the Information Commissioner’s Office (ICO). You can contact the ICO at:

We would, however, appreciate the opportunity to address your concerns before you approach a supervisory authority and would ask that you contact us in the first instance.

9.9 Exercising Your Rights

To exercise any of the above rights, please contact the relevant Group entity using the details set out in section 1.4.

No fee usually required. You will not have to pay a fee to exercise your rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive, or we may refuse to comply in such circumstances.

Identity verification. We may need to request specific information from you to confirm your identity before acting on your request. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.

Response time. We aim to respond to all legitimate requests within one month. If your request is complex or you have made a number of requests, it may take us longer, in which case we will notify you and keep you updated.

We do not use your personal data for automated decision-making (including profiling) that produces legal or similarly significant effects concerning you.

When you visit our website, we may use cookies and similar technologies to collect Technical Data about your equipment, browsing actions and patterns. A cookie is a small file placed on your device that enables certain features and functionality.

We use the following types of cookies:

  • Strictly necessary cookies: these are required for the operation of our website.
  • Analytics cookies: these allow us to recognise and count the number of visitors and to see how visitors move around our website, helping us to improve the way it works.

You can set your browser to refuse all or some cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, some parts of this website may become inaccessible or not function properly.

We may monitor communications (including calls, emails, messages and other correspondence) where permitted by law. We do so where the law requires it, to comply with regulatory obligations, to prevent or detect crime, to protect the security of our communications systems and procedures, and for quality control and staff training purposes. Any information obtained through monitoring may be shared for the purposes described in this notice.

If you have any questions about this privacy notice or wish to exercise any of your rights, please contact the relevant Group entity using the details in section 1.4 above.

For general data protection enquiries relating to the Group, you may write to: compliance@eneselgroup.com