Portavis Privacy Notice

Draft for operational and legal completion before production launch · Version 1.0 · 24 September 2026

Launch draft: James Maltby, trading as Portavis, must confirm the final email provider, Railway deployment region, international-transfer safeguards, and confirmed retention periods before relying on this notice in production.

Who is responsible for your information?

For incident reports, witness information, staff records, investigations, and safety-management records entered for a customer organisation, that organisation is normally the data controller. James Maltby, trading as Portavis, provides the software and processes that information on the controller's instructions.

James Maltby, trading as Portavis, is a controller for information needed to create and secure user accounts, administer subscriptions and customer relationships, maintain service security, meet legal obligations, and operate this website.

Information processed

Depending on how the service is used, information may include names, work roles, contact details, account identifiers, incident narratives, dates, locations, staff involvement, witness statements, photographs, uploaded documents, investigation findings, audit logs, device/network metadata, notification preferences, and support communications. Incident records may contain health, injury, alleged misconduct, or other sensitive information supplied by a controller or reporter.

Purposes and lawful bases

Customer controllers determine the lawful basis for their incident and safety processing. Common bases may include legal obligation, public task, legitimate interests, contract, or vital interests, with an additional condition required for special-category or criminal-offence data. James Maltby, trading as Portavis, processes customer data under contract and documented controller instructions.

For Portavis's controller activities, processing is undertaken where necessary to perform a contract, comply with law, protect service security and legitimate business interests, or where another lawful basis is identified. A required privacy acknowledgement records that information was presented; it is not necessarily the controller's lawful basis.

AI processing

External OpenAI incident analysis is disabled for each organisation until its Owner enables it. When enabled, the software removes explicit database identifiers and redacts known names, email addresses, phone numbers, addresses, and incident references where possible. OpenAI receives only the minimised incident fields needed to interpret and answer the question. Portavis configures applicable OpenAI API requests not to store responses for application-state purposes (store=false). OpenAI may nevertheless retain certain API content in abuse-monitoring logs for a limited period in accordance with its applicable API data controls. Free text may still contain information that cannot be reliably detected, so users should avoid unnecessary personal data in AI questions and narratives.

Local incident tagging does not use OpenAI.

Recipients and subprocessors

Expected service providers include Railway for application/database hosting, OpenAI where an organisation enables external AI, and OpenFreeMap/OpenStreetMap infrastructure for interactive map tiles. A transactional email provider has not yet been selected and must be added before production email is enabled. Customer controllers may also authorise their own recipients.

International transfers

Some providers may process information outside the UK. Before launch, James Maltby, trading as Portavis, will document provider locations and use an adequacy regulation or appropriate safeguards such as the UK International Data Transfer Agreement or UK Addendum where required.

Retention

Customer organisations set their incident-retention period and must consider maritime safety, regulatory, insurance, limitation, employment, and legal-hold requirements. When a period expires, Portavis places the record in an Owner review queue; no incident is deleted automatically. Legal hold blocks deletion. Portavis will retain its own account, security, contractual, and statutory records only for documented periods and will define backup deletion windows before launch.

Your rights

Depending on the circumstances, you may have rights of access, correction, erasure, restriction, objection, and data portability, and the right to complain to the UK Information Commissioner's Office. For customer incident data, contact the organisation named on the form or request first. Portavis will assist that controller as required by its data-processing agreement.

Security and incidents

Portavis uses tenant access controls, role-based permissions, audit histories, encrypted HTTPS transport in production, minimised AI payloads, and provider-storage controls. No internet service can guarantee absolute security. Where James Maltby, trading as Portavis, acts as a processor and becomes aware of a personal-data breach affecting customer data, Portavis will notify the relevant customer organisation as controller without undue delay. The controller is responsible for assessing the breach and determining whether notification to the Information Commissioner's Office or affected individuals is required.

Contact and complaints

Portavis privacy contact: [email protected]

You may complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint.